Skip to content

guardrails: block-root-delete-target does not unwrap runuser, taskset or the launcher family #4468

Description

@kyle-sexton

Problem

plugins/guardrails/hooks/block-root-delete-target.sh resolves the command word through a fixed table of launchers. A launcher missing from that table ends the walk, and the launcher's own name is read as the command word. So a recursive delete of a root passes when a launcher that is not in the table wraps it.

Payloads fed to the guard on stdin at 49dac96 exit 0, both direct and through run-guards.sh:

  • runuser -c 'rm -rf /'
  • taskset 1 rm -rf /

The same holds for runuser -u bob -- rm -rf /, chrt 10 rm -rf /, flock /tmp/l rm -rf /, flock /tmp/l -c 'rm -rf /', unshare rm -rf /, nsenter -t 1 -m rm -rf /, chroot / rm -rf / and numactl -l rm -rf /. The guard header already names runuser and taskset as a declared gap.

Ask

Unwrap each launcher whose grammar fits the guard's launcher model, and declare the rest as gaps. Pin a suite case either way.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-triageNot yet classified. Floor until a type and one priority tier are set.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions