Skip to content

Feature: Root actions through a privileged pkexec helper - #98

Merged
MemerGamer merged 6 commits into
mainfrom
linux/root-helper
Oct 6, 2026
Merged

MemerGamer merged 6 commits into
mainfrom
linux/root-helper

Conversation

@MemerGamer

Copy link
Copy Markdown
Owner

Supersedes #61. Fd-relative AOT elevation helper, strict JSON protocol, helper-side verification, frozen confirmation plan, polkit policy; disabled in AppImage/Flatpak. Do not merge without a clean security review. Written by GPT-6.1-sol (Codex) on top of the #61 draft.

🤖 Generated with Claude Code

https://claude.ai/code/session_01LeKXJc3DnK3PzAqwgA72NY

MemerGamer and others added 6 commits October 6, 2026 08:37
Adds an AOT elevation helper with a strict JSON protocol, helper-side
verification, a frozen confirmation plan and a polkit policy. Portable
AppImage/Flatpak builds disable root actions.

Co-Authored-By: GPT-6.1-sol (OpenAI Codex) <noreply@openai.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LeKXJc3DnK3PzAqwgA72NY
- Pass a sanitized summary and the SHA-256 of the stdin request to the
  helper; the polkit message shows $(command_line) and the helper rejects
  any digest or summary mismatch (verified against polkit 0.105 and 127)
- Refuse protected top-level sources and /proc, /sys, /dev targets
- Wait for the real helper result when cancellation cannot kill root work
- Embed the policy and install from a verified private helper snapshot
- Hand verified copies in caller-owned destinations to the caller
- Drop symlinkat from the helper, use invariant globalization, treat
  pkexec 126/127 as dismissed, fail closed on unexpected exceptions and
  show non-ASCII paths readably in the preview

Co-Authored-By: GPT-6.1-sol (OpenAI Codex) <noreply@openai.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Reviewed-by: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LeKXJc3DnK3PzAqwgA72NY
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LeKXJc3DnK3PzAqwgA72NY
- Mask handed-over folders by the source mode & 0755 and files by & 0644;
  keep group bits only for the caller's own group and limit other bits to
  what a foreign source group had
- Clear group/other bits when the source has an access ACL or sat below a
  directory others could not search
- Refuse multiply-linked files before handover, since a link can alias
  data outside the approved tree
- Return name-free error text (no nested entry names or raw name bytes)
- Duplicate listing descriptors with F_DUPFD_CLOEXEC
- Document the handover rules and cover them with tests

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LeKXJc3DnK3PzAqwgA72NY
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LeKXJc3DnK3PzAqwgA72NY
- Remove the output's inherited access ACL before fchmod so the new mask
  cannot activate default-ACL named entries, and verify none remains
- Treat a source as reachable only when every ancestor grants owner, group
  and other search and has no access ACL, read through a verified
  read-only reopen of the pinned descriptor
- Pass fcntl's third argument as nint

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Reviewed-by: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LeKXJc3DnK3PzAqwgA72NY
@MemerGamer
MemerGamer merged commit 9739ee4 into main Oct 6, 2026
2 checks passed
@MemerGamer
MemerGamer deleted the linux/root-helper branch October 6, 2026 07:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant