mirror of
https://github.com/Lakr233/vphone-cli.git
synced 2026-10-02 08:04:32 +08:00
A repo-wide security review found issues in the root CFW install, the Launchpad helper, VM bundle handling and the guest boundary. This fixes them and applies swift format. - cfw install mounts guest volumes nosuid,nodev,nobrowse in a root-only temp folder and does every guest read and write through an open folder handle, never following links. BuildManifest cryptex paths must stay in the restore folder, and only a private copy is attached. - Root no longer chowns or chmods the whole VM folder after an install. The shared walk skips hard links, symlinks, special files and other volumes. - Every Launchpad helper action needs administrator authorization. Only the user who started a CFW install can cancel it. The helper refuses setuid, hard-linked, special or escaping-symlink entries in a bundle. - Manifest file names must be single names in the bundle and point to regular files. vm import refuses links that leave the bundle. - Guest file names from the file browser, QuickLook, drag-out and crash logs are validated and written exclusively, without overwriting, and are quarantined. - The guest HTTP client no longer traps on a bare Content-Length, caps bodies and enforces a per-request deadline. - The --api-listen proxy needs a per-launch token. vphoned refuses browser-origin and non-local Host requests. - vphoned stops following links when it sets up Irisin and the camera files. Thanks to fresh-fx59 for reporting the guest file name, HTTP parsing, cfw install and manifest path issues in #469. Co-authored-by: Aleksey Aksenov <5788874+fresh-fx59@users.noreply.github.com> Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>