Security: adversarial testing and threat model

#25 · open · 0 comments

View on GitHub ↗

vdemeester

Praetorian is a security boundary, so it should be actively attacked, not just unit-tested for the happy path. This issue tracks a threat model + concrete abuse cases to test against (and harden where needed). Several are likely real gaps today. ## Structural / injection (should already hold — prove it) - [ ] Shell metacharacters inert: `;`, `|`, `&&`, `$(...)`, backticks, newlines, `>` — literal argv, never interpreted. - [ ] Quoting asymmetry: `google/shlex` tokenization matches how the target binary receives argv. - [ ] Unicode / NUL / control-char tricks in `SSH_ORIGINAL_COMMAND`. ## Argument injection (likely real gaps) - [ ] **rsync** `-e`/`--rsh`/`--server` + pre-xfer exec can run arbitrary commands — `allow "rsync"` with only `any_arg` is probably exploitable. - [ ] **git** transports: `ext::`/`fd::` helpers, `--upload-pack=`, alias abuse. - [ ] **scp** `-S program` runs an arbitrary program. - [ ] **nc** alternate flags (`-e`/`-c`) for command execution. - [ ] Policy: add a "deny these flags" narrowing constraint, or document that `any_arg`-only rules are dangerous. ## PATH / exec resolution (likely real gap) - [ ] `exec.LookPath(tokens[0])` resolves against inherited `$PATH`. If the client influences env (`SetEnv`/`AcceptEnv`/`PermitUserEnvironment`), they could point `PATH` at a malicious binary. Consider requiring absolute command paths, or pin/sanitize `PATH`. ## Environment injection (likely real gap) - [ ] We exec with full `os.Environ()`. Attacker-influenced env (`LD_PRELOAD`, `GIT_*`, `BORG_*`, `IFS`, `PATH`) can change exec'd binary behavior even when argv is constrained. Consider scrubbing the environment passed to `syscall.Exec`. ## Path / glob semantics - [ ] Traversal: does `glob = "/srv/git/*"` admit `/srv/git/..` (no `/`, so `*` matches)? `path.Match` does not normalize. - [ ] `path.Match` error/edge behavior (malformed/empty patterns, case sensitivity). ## Config / TOCTOU - [ ] Symlink swap of config file between stat (lookup) and read. - [ ] Confirm "what is validated is exactly what is exec'd" — no re-tokenization gap. ## Deliverables - [ ] Documented threat model (`SECURITY.md`). - [ ] Adversarial test suite encoding the cases above (extends #24 where a real binary is needed). - [ ] Harden confirmed gaps (env scrub, PATH handling, arg-injection guidance/constraints). Related: #24 (e2e SSH).

Comments