Skip to content

security: audit per-user temporary path handling for #778 - #844

Closed
MisterTea wants to merge 1 commit into
masterfrom
issue-778-cve-2023-23558
Closed

MisterTea wants to merge 1 commit into
masterfrom
issue-778-cve-2023-23558

Conversation

@MisterTea

@MisterTea MisterTea commented Sep 20, 2026 •

Copy link
Copy Markdown
Owner

Problem

See #778 for the original report.

Changes

Adds audit notes covering telemetry configuration, FIFO paths, PID-file permissions, and possible symlink races.

Resolution status

The files are documentation/placeholders rather than executable security tests, and no hardening change is included. This PR does not establish that CVE-2023-23558 is fixed.

Verification

Reviewed against current master. Run the repository-required formatting and unit-test commands after any follow-up code changes.

- TelemetryService uses sago::getConfigHome() (per-user)
- ServerFifoPath uses XDG_RUNTIME_DIR or /var/run with 0700/owner checks
- DaemonCreator uses 0600 pidfile
- Added audit docs and secure-temp tests (symlink/race behavior)
@codecov

codecov Bot commented Sep 20, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 79.18%. Comparing base (db4f6f6) to head (e34389e).

Additional details and impacted files
@@            Coverage Diff             @@
##           master     #844      +/-   ##
==========================================
- Coverage   79.26%   79.18%   -0.08%     
==========================================
  Files         118      118              
  Lines       12633    12633              
  Branches     8143     8143              
==========================================
- Hits        10014    10004      -10     
- Misses       1552     1569      +17     
+ Partials     1067     1060       -7     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@MisterTea MisterTea changed the title Issue: issue-778-cve-2023-23558 security: audit per-user temporary path handling for #778 Sep 20, 2026
@MisterTea

Copy link
Copy Markdown
Owner Author

Superseded by the security hardening and regression coverage merged in #784. This branch contains audit notes and non-executable placeholders only, so it should not remain open as a competing security fix.

@MisterTea MisterTea closed this Sep 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant