Repository navigation
Conversation
Restore certificate validation for every wget download the plugin performs (installer.sh, plugin.py's addon installers, and the bundled stalker-portal scripts) by dropping --no-check-certificate. All target hosts (GitHub, GitLab, raw.githubusercontent.com) present valid certs, so this only closes a MITM vector that could otherwise inject arbitrary shell code piped straight into /bin/sh. Also harden lsConsole's script-runner: temp scripts were written to a predictable /tmp/.lsconsole_<n>.sh path with mode 0755 and never cleaned up, which is exploitable as a symlink/race attack on a shared /tmp and leaked executed commands indefinitely. Now uses tempfile.mkstemp for a unique, exclusively-created file (mode 0700) and removes it once the console closes or is cancelled.
Reconciles develop (TLS cert-validation fix + lsConsole temp-file hardening from the security audit) with main, which had moved forward independently with the Commit History viewer, commit cache/update flow, and the ipk publish workflow. Conflicts were all in auto-generated translation artifacts (locale/*.po/.mo, messages.mo, translation_cache.json); resolved by taking main's regenerated versions. Also: - main's newer self-update path (_update_confirmed) had reintroduced --no-check-certificate on its wget call; removed it to match the rest of the codebase. - fixed _save_commits_to_cache() writing str(commits) (a Python repr) while _load_commits_from_cache() reads it back with json.loads(), which silently failed on every load and defeated the cache; now uses json.dumps().
- lcnScan() never returns a value, but both LcnXX() callers (in ScriptInstaller and addInstall) treated the result as a Screen to open, so self.session.open(LCN) was dead code and a spurious "Error: LCN scan did not return a valid screen." was logged even on success. Drop the dead check; the scan already runs synchronously and the existing "scan finished" MessageBox gives user feedback. - readE2Services() left refstr unassigned for any serviceType other than "TV"/"RADIO", risking UnboundLocalError; add an else branch. - The per-service medium dispatch (C/S/A/T) left lcnCache/serviceLCNs unassigned or stale for an unrecognized medium code, risking UnboundLocalError or silently filing a service under the wrong medium; add an else that logs and skips the row.
- add_skin_fonts() indexed font_config by HALIGN but only defined a
RT_HALIGN_LEFT entry, unlike its twin load_custom_fonts(); would
raise KeyError for RTL/Arabic locales. Add the missing
RT_HALIGN_RIGHT entry so it matches load_custom_fonts().
- addons/NewOeSk.py: drop a verbatim duplicate of patterns_to_remove.
- Remove translate_utils.py: a Google-Translate helper for a
different plugin ("Foreca One"), never imported anywhere in this
package. Also drop the DEBUG/HEADERS/SYSTEM_DIR globals in
__init__.py that existed solely for it.
- addons/checkskin.py: writes to fixed, predictable /tmp paths
(merged_<skin>.xml, my_debug.log) using plain open("w"/"a"), which
follows a symlink another local user could plant at that path.
Add a _safe_open() helper (O_NOFOLLOW + O_CREAT) and use it for all
six read/write sites, matching the hardening already applied to
lsConsole.py's temp scripts.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Restore certificate validation for every wget download the plugin
performs (installer.sh, plugin.py's addon installers, and the bundled
stalker-portal scripts) by dropping --no-check-certificate. All target
hosts (GitHub, GitLab, raw.githubusercontent.com) present valid certs,
so this only closes a MITM vector that could otherwise inject
arbitrary shell code piped straight into /bin/sh.
Also harden lsConsole's script-runner: temp scripts were written to a
predictable /tmp/.lsconsole_.sh path with mode 0755 and never
cleaned up, which is exploitable as a symlink/race attack on a shared
/tmp and leaked executed commands indefinitely. Now uses
tempfile.mkstemp for a unique, exclusively-created file (mode 0700)
and removes it once the console closes or is cancelled.