Repository navigation
Commit 2930998
authored
security(gpg): pipe private key via stdin instead of writing to /tmp (#798)
## Summary
Eliminates the TOCTOU / information-disclosure hazard in
`importGPGKey()`: the private key is now piped to \`gpg --batch
--import\` via stdin instead of being written to a fixed, predictable
path in `os.tmpdir()`.
## Motivation
The previous implementation:
```ts
const PRIVATE_KEY_FILE = path.join(tmpdir(), 'private-key.asc');
await fsPromises.writeFile(PRIVATE_KEY_FILE, privateKey);
await spawnProcess('gpg', ['--batch', '--import', PRIVATE_KEY_FILE]);
await fsPromises.unlink(PRIVATE_KEY_FILE);
```
On Linux, `/tmp` is mode 1777 (world-writable, with the sticky bit). The
path is deterministic, so:
1. **Read race**: any co-resident process on the runner can read the key
between `writeFile` and `unlink`.
2. **Write redirect via symlink**: an attacker who wins a race to `ln -s
/some/target /tmp/private-key.asc` before the `writeFile` call causes
Craft to overwrite \`/some/target\` with the private key.
3. **Crash persistence**: an unexpected exit between `writeFile` and
`unlink` leaves the key on disk indefinitely.
## Fix
Pass the key via stdin. `gpg --batch --import` reads a key from stdin
when no file argument is given. `spawnProcess` already supports a
`stdin` option — no new infrastructure needed.
```ts
await spawnProcess('gpg', ['--batch', '--import'], {}, { stdin: privateKey });
```
Benefits vs. `mkdtemp(0o700)` alternative:
- Zero filesystem contact — no dir creation, no file write, no cleanup
path to get wrong.
- Key no longer appears in `argv` either, so it doesn't show up in `ps`
/ `/proc/<pid>/cmdline`.
## Tests
`src/utils/__tests__/gpg.test.ts` is rewritten to assert the new
invariants:
- `spawnProcess` is called with `['--batch', '--import']` and `{ stdin:
KEY }`.
- No `fs.writeFile` / `fs.unlink` happens.
- The key is not embedded in any argv entry (regression guard against
future reintroduction).
`pnpm test src/utils/__tests__/gpg.test.ts` → 3 tests pass. Full lint /
build clean.
## Callers
Only `src/targets/maven.ts:271` calls `importGPGKey`. The signature is
unchanged (`importGPGKey(privateKey: string): Promise<void>`) — no
caller updates needed.1 parent e56aa0f commit 2930998
2 files changed
Lines changed: 53 additions & 26 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
| 1 | + | |
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
| |||
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
| 13 | + | |
13 | 14 | | |
14 | | - | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
15 | 18 | | |
16 | 19 | | |
17 | 20 | | |
18 | 21 | | |
19 | 22 | | |
20 | 23 | | |
21 | | - | |
22 | 24 | | |
23 | | - | |
24 | | - | |
25 | | - | |
26 | | - | |
27 | | - | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
28 | 39 | | |
29 | 40 | | |
30 | 41 | | |
31 | | - | |
32 | | - | |
33 | | - | |
34 | | - | |
35 | | - | |
36 | | - | |
37 | | - | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
38 | 49 | | |
39 | 50 | | |
40 | | - | |
41 | | - | |
42 | | - | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
43 | 60 | | |
44 | 61 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
2 | | - | |
3 | | - | |
4 | 1 | | |
5 | 2 | | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
6 | 20 | | |
7 | | - | |
8 | | - | |
9 | | - | |
10 | | - | |
11 | | - | |
| 21 | + | |
12 | 22 | | |
0 commit comments