Skip to content

[security][medium] Improve temporary-file usage and avoid shell redirection with temporary filenames #3

Description

@upupwrite

Summary

Temporary file handling in src/search.cpp uses mkstemp to create a unique file, writes user-derived content into it, closes the descriptor, and then constructs a shell command string that uses shell redirection from the filename (< /tmp/pk_fzf_xxx) passed to popen. Although mkstemp reduces race conditions, closing the fd and then using the filename in a shell command without robust quoting or using an exec-style call exposes a small window for race replacement or filename-based shell interpretation issues.

Reproduction / evidence

  • src/search.cpp: char tmpname[] = "/tmp/pk_fzf_XXXXXX"; mkstemp(tmpname); write(fd, list.c_str(), list.size()); close(fd); then build command string "fzf ... < " + tmpname and call popen(cmd.c_str(), "r").

Risks

  • An attacker with permissions to create files in /tmp or manipulate the temporary file between close and popen could potentially cause unexpected behavior.
  • Using shell redirection with an unquoted filename may misbehave if the filename contains shell metacharacters (unlikely with mkstemp but still a best-practice gap).

Suggested fixes

  1. Keep the file descriptor open and pass it to the child process without shell redirection.

    • On POSIX, use fork/exec and dup2 to attach the fd to stdin of the child, or use posix_spawn_file_actions to set the child's stdin.
    • In Qt, consider using QProcess and setStandardInputFile with a QFile opened on the fd.
  2. If shell invocation is unavoidable, properly escape and quote filenames and avoid using the shell for redirection.

  3. Set FD_CLOEXEC on the fd and ensure the temporary file is created with restrictive permissions.

Files/places to review first

  • src/search.cpp

Severity: medium

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions