Installing a plugin fetches its dependencies from PyPI, unsigned and unpinned #61
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo#61
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What is and is not checked today
The plugin chain is careful about the plugin itself, and that part is good:
install_wheelrefuses a wheel that does not match;check()refuses anything that would change what Postulo itself depends on, enforcedwith a constraint file passed to the installer.
Then
run_installbuilds:No
--no-deps. No--only-binary. No hashes for anything but the plugin's own wheel. Soinstalling a signed, checksummed plugin resolves its requirements from PyPI and
installs whatever is served — and a source distribution among them runs its own build code
during the install, as the maintainer's user, inside Postulo's container.
Why this is worth an issue rather than a shrug
It is not a flaw in the signing; it is the edge of what the signing covers, and the
documentation does not currently say where that edge is. An administrator reading
"signature verified, checksum verified" in the interface reasonably concludes that
everything installed was verified. What was verified is one file out of however many
arrive.
The constraint file is a real protection and should be credited: a dependency cannot
downgrade Django or swap out cryptography. It says nothing about a package Postulo has
never heard of.
Shape, in the order that helps most per unit of work
its dependencies from PyPI, and that trusting a plugin means trusting its dependency
list. The confirmation before installing shows the requirements the wheel declares.
--only-binary :all:, so nothing executes a build script during installation. Aplugin that genuinely needs a source build is a plugin an operator should install by
hand, deliberately.
dependencies that came with it and list them on the plugin's page. Then an operator can
see what is in their instance without a shell.
hashes, and the install could be
--require-hashes. That is the real fix, it is achange to the catalogue format, and it should not hold up the three above.
Classification
Security and enhancement. Not breaking;
--only-binarycould refuse a plugin thatinstalls today, which is the point, and the message should say what to do about it.