Drop privileges when seeding Dell haptic config (#497)

The root-run package hook changed ownership of paths below a
user-controlled home directory. A config symlink could redirect chown to
an arbitrary root-owned file during installation or upgrade.

Run the config writer as the target desktop user and remove the privileged
ownership changes. This also prevents the missing-config path from writing
through a user-controlled pathname as root. Add regression coverage and
bump the package release.

Reported-by: piratemoo (Esther) <22439214+piratemoo@users.noreply.github.com>
Link: https://github.com/piratemoo/Arbitrary-File-Ownership-Change-via-Symlink-LPE
This commit is contained in:
Basti authored and GitHub committed 2026-09-18 15:24:41 +02:00
1 parent 5cccebaa17
commit b422d37fa2
4 files changed
+58 -8

No files matched your search

+1
View File
@@ -45,6 +45,7 @@ jobs:
./bin/sync-rebuilds --self-test
./bin/omarchy-pkgs self-test
./bin/omarchy-release self-test
./tests/dell-xps-touchpad-haptics-install.sh
./tests/partial-release.sh
./tests/published-build-plan.sh
'
+1 -1
View File
@@ -2,7 +2,7 @@
pkgname=dell-xps-touchpad-haptics
pkgver=1.0.0
pkgrel=3
pkgrel=4
pkgdesc="Synaptics haptic touchpad presets for Dell XPS on Omarchy"
arch=('x86_64')
url="https://github.com/omacom-io/omarchy-pkgs"
@@ -3,6 +3,7 @@ _default_level="high"
_env_path="/etc/dell-xps-touchpad-haptics.env"
_legacy_env_path="/etc/omarchy-dell-haptic-touchpad.env"
_legacy_override_dir="/etc/systemd/system/dell-xps-haptic-touchpad.service.d"
_runuser_path="/usr/bin/runuser"
_existing_home() {
local line value
@@ -124,18 +125,13 @@ _ensure_user_config() {
local config_dir="$home/.config/omarchy"
local config_path="$config_dir/dell-haptic.conf"
if [[ ! -f $config_path ]] && ! env HOME="$home" USER="$user" LOGNAME="$user" \
if [[ ! -f $config_path ]] && ! "$_runuser_path" --user "$user" -- \
/usr/bin/env HOME="$home" USER="$user" LOGNAME="$user" \
/usr/bin/dell-xps-touchpad-haptics set "$_default_level"; then
echo ":: Failed to create ${config_path} for user '$user'." >&2
return 1
fi
if [[ -f $config_path ]]; then
chown "$user:$user" "$home/.config" 2>/dev/null || true
chown "$user:$user" "$config_dir" 2>/dev/null || true
chown "$user:$user" "$config_path" 2>/dev/null || true
fi
return 0
}
+53
View File
@@ -0,0 +1,53 @@
#!/bin/bash
set -euo pipefail
REPO_ROOT=$(realpath "${BASH_SOURCE[0]%/*}/..")
INSTALL_SCRIPT="$REPO_ROOT/pkgbuilds/dell-xps-touchpad-haptics/dell-xps-touchpad-haptics.install"
TEST_ROOT=$(mktemp -d)
trap 'rm -rf "$TEST_ROOT"' EXIT
# shellcheck source=/dev/null
source "$INSTALL_SCRIPT"
home="$TEST_ROOT/home"
config_dir="$home/.config/omarchy"
config_path="$config_dir/dell-haptic.conf"
protected_file="$TEST_ROOT/protected"
runuser_call="$TEST_ROOT/runuser-call"
chown_call="$TEST_ROOT/chown-call"
runuser_stub="$TEST_ROOT/runuser"
mkdir -p "$config_dir"
printf 'must remain unchanged\n' >"$protected_file"
ln -s "$protected_file" "$config_path"
chown() {
printf '%s\n' "$*" >>"$chown_call"
}
_ensure_user_config test-user "$home"
[[ ! -e $chown_call ]]
[[ ! -e $runuser_call ]]
[[ $(cat "$protected_file") == 'must remain unchanged' ]]
rm "$config_path"
printf '%s\n' \
'#!/bin/bash' \
'set -euo pipefail' \
'[[ $1 == --user && $2 == test-user && $3 == -- && $4 == /usr/bin/env ]]' \
'[[ $5 == "HOME=$EXPECTED_HOME" && $6 == USER=test-user && $7 == LOGNAME=test-user ]]' \
'[[ $8 == /usr/bin/dell-xps-touchpad-haptics && $9 == set && ${10} == high ]]' \
'printf "%s\n" "$*" >>"$RUNUSER_CALL"' \
'printf "INTENSITY=100\n" >"$EXPECTED_CONFIG"' >"$runuser_stub"
chmod +x "$runuser_stub"
export EXPECTED_HOME="$home"
export EXPECTED_CONFIG="$config_path"
export RUNUSER_CALL="$runuser_call"
_runuser_path="$runuser_stub"
_ensure_user_config test-user "$home"
[[ ! -e $chown_call ]]
[[ -f $config_path && ! -L $config_path ]]
[[ $(cat "$config_path") == 'INTENSITY=100' ]]
grep -q '^--user test-user -- /usr/bin/env ' "$runuser_call"
echo 'PASS: user config creation drops privileges and never chowns symlink targets'