fix: comment out exec options when importing OpenVPN configs (#197) #200
Loading…
Reference in a new issue
No description provided.
Delete branch "sanitize-imports"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
The root service runs imported OpenVPN configs verbatim, and a config can carry its own
script-security 2plusup/down/route-up/plugin/tls-verify/… — an import channel into root command execution, the same class #82 closed for the GUI (#197). WireGuard is already covered: wireguard.py rejects wg-quick extension keys, soPostUpnever executes.Fix
Sanitize-on-import, per the issue (matches the NetworkManager precedent of ignoring
PostUp/PreDownon wg import). The import already commented outup/downlines — this completes the set as anEXEC_OPTIONStuple (every option that names a command, plusscript-securityitself) and matches the line's first token instead ofstartswith, which also catches indented directives. Each disarmed line is logged and commented out rather than dropped, so the imported copy still shows what it arrived with.Ordering matters: the exec check runs before the
auth-user-passrewrite, whosestartswithmatch would otherwise claimauth-user-pass-verify— rewriting an exec option into the auth-file line and demanding credentials the config doesn't need.Deliberately import-time only: configs imported before this change are not re-scanned at connect time, consistent with keeping legacy-data handling out while the fork has no users (same call as #199).
Verification
remotesurvives untouched, that the import still succeeds, and theauth-user-pass-verifyordering trap (a cert-only config carrying it imports without credentials).ruff check --select E9,F63,F7,F82 .clean.🤖 Generated with Claude Code