Skip to content

fix(settings): create the identity key file with owner-only mode from the outset - #287

Open
kiwipaulrob wants to merge 1 commit into
Sendspin:mainfrom
kiwipaulrob:fix/identity-key-file-permissions
Open

kiwipaulrob wants to merge 1 commit into
Sendspin:mainfrom
kiwipaulrob:fix/identity-key-file-permissions

Conversation

@kiwipaulrob

Copy link
Copy Markdown
Contributor

Problem

_load_identity() persists the generated Noise identity private key with:

path.write_text(json.dumps({"private_key": b64url_encode(identity.private_bytes)}))
os.chmod(path, stat.S_IRUSR | stat.S_IWUSR)

The file is created with the process umask (commonly 0644) and only then restricted, so the private key is briefly readable by group/other — a write-then-chmod (TOCTOU) window. This key is the client's cryptographic identity and must stay stable across restarts, so an exposure is worth avoiding.

Fix

Create the file with os.open(..., 0o600) and write through the returned descriptor, so the restrictive mode applies atomically at creation. 0600 has no group/other bits for the umask to clear, so the result is owner-only on any normal umask.

Verification

  • New tests/test_settings.py:
    • the generated key file has no group/other permission bits (st_mode & 0o077 == 0);
    • the key still round-trips to the same peer_id on reload.
  • pytest — 148 passed; ruff check, ruff format --check, mypy sendspin clean.

… the outset

The Noise identity private key was written with Path.write_text() and only then
chmod-ed to 0600, leaving a window where it was readable by group/other under a
permissive umask. Create the file via os.open(..., 0o600) so the restrictive
mode applies from creation.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant