Skip to content

security: enforce TLS cert validation and harden console temp files - #6

Merged
pQu4k3r merged 6 commits into
mainfrom
develop
Sep 14, 2026
Merged

pQu4k3r merged 6 commits into
mainfrom
develop

Conversation

@pQu4k3r

@pQu4k3r pQu4k3r commented Sep 14, 2026

Copy link
Copy Markdown
Contributor

Restore certificate validation for every wget download the plugin
performs (installer.sh, plugin.py's addon installers, and the bundled
stalker-portal scripts) by dropping --no-check-certificate. All target
hosts (GitHub, GitLab, raw.githubusercontent.com) present valid certs,
so this only closes a MITM vector that could otherwise inject
arbitrary shell code piped straight into /bin/sh.

Also harden lsConsole's script-runner: temp scripts were written to a
predictable /tmp/.lsconsole_.sh path with mode 0755 and never
cleaned up, which is exploitable as a symlink/race attack on a shared
/tmp and leaked executed commands indefinitely. Now uses
tempfile.mkstemp for a unique, exclusively-created file (mode 0700)
and removes it once the console closes or is cancelled.

pQu4k3r and others added 6 commits August 19, 2026 21:15
Restore certificate validation for every wget download the plugin
performs (installer.sh, plugin.py's addon installers, and the bundled
stalker-portal scripts) by dropping --no-check-certificate. All target
hosts (GitHub, GitLab, raw.githubusercontent.com) present valid certs,
so this only closes a MITM vector that could otherwise inject
arbitrary shell code piped straight into /bin/sh.

Also harden lsConsole's script-runner: temp scripts were written to a
predictable /tmp/.lsconsole_<n>.sh path with mode 0755 and never
cleaned up, which is exploitable as a symlink/race attack on a shared
/tmp and leaked executed commands indefinitely. Now uses
tempfile.mkstemp for a unique, exclusively-created file (mode 0700)
and removes it once the console closes or is cancelled.
Reconciles develop (TLS cert-validation fix + lsConsole temp-file
hardening from the security audit) with main, which had moved forward
independently with the Commit History viewer, commit cache/update
flow, and the ipk publish workflow.

Conflicts were all in auto-generated translation artifacts
(locale/*.po/.mo, messages.mo, translation_cache.json); resolved by
taking main's regenerated versions.

Also:
- main's newer self-update path (_update_confirmed) had reintroduced
  --no-check-certificate on its wget call; removed it to match the
  rest of the codebase.
- fixed _save_commits_to_cache() writing str(commits) (a Python repr)
  while _load_commits_from_cache() reads it back with json.loads(),
  which silently failed on every load and defeated the cache; now
  uses json.dumps().
- lcnScan() never returns a value, but both LcnXX() callers (in
  ScriptInstaller and addInstall) treated the result as a Screen to
  open, so self.session.open(LCN) was dead code and a spurious
  "Error: LCN scan did not return a valid screen." was logged even on
  success. Drop the dead check; the scan already runs synchronously
  and the existing "scan finished" MessageBox gives user feedback.
- readE2Services() left refstr unassigned for any serviceType other
  than "TV"/"RADIO", risking UnboundLocalError; add an else branch.
- The per-service medium dispatch (C/S/A/T) left lcnCache/serviceLCNs
  unassigned or stale for an unrecognized medium code, risking
  UnboundLocalError or silently filing a service under the wrong
  medium; add an else that logs and skips the row.
- add_skin_fonts() indexed font_config by HALIGN but only defined a
  RT_HALIGN_LEFT entry, unlike its twin load_custom_fonts(); would
  raise KeyError for RTL/Arabic locales. Add the missing
  RT_HALIGN_RIGHT entry so it matches load_custom_fonts().
- addons/NewOeSk.py: drop a verbatim duplicate of patterns_to_remove.
- Remove translate_utils.py: a Google-Translate helper for a
  different plugin ("Foreca One"), never imported anywhere in this
  package. Also drop the DEBUG/HEADERS/SYSTEM_DIR globals in
  __init__.py that existed solely for it.
- addons/checkskin.py: writes to fixed, predictable /tmp paths
  (merged_<skin>.xml, my_debug.log) using plain open("w"/"a"), which
  follows a symlink another local user could plant at that path.
  Add a _safe_open() helper (O_NOFOLLOW + O_CREAT) and use it for all
  six read/write sites, matching the hardening already applied to
  lsConsole.py's temp scripts.
@pQu4k3r
pQu4k3r merged commit f82093d into main Sep 14, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants