Skip to content

fix(init): .env is never readable by other users - #171

Merged
catinspace-au merged 1 commit into
mainfrom
fix/dotenv-mode-600
Sep 28, 2026
Merged

catinspace-au merged 1 commit into
mainfrom
fix/dotenv-mode-600

Conversation

@catinspace-au

Copy link
Copy Markdown
Contributor

.env holds every secret make init generates, and all five writers opened it under the umask. On the standing devex VM (umask 002) it was 664, so any local user could read the stack's passwords.

  • One helper in _common.py, write_private, creates the file at its mode and reasserts that mode on rewrite. init, dev_posture, render_dial and stack write .env through it. The .env backup and the access summary (already 0600) now use it too.
  • .env is 0640, not 0600. A daemon install shares the checkout through its group (the VM's ubuntu user reads .env via group dfe), and env/ is already group-shared on purpose.
  • make init closes an EXISTING .env to others (o-rwx) and leaves the owner and group bits alone, so upgraded installs get fixed on their next init.
  • post.py's forced-password rewrite already keeps the file's mode via mkstemp, so it needs no change.

make check-python and check-tests: 462 passed. check-docs is clean. Done when a new or upgraded install's .env has no permission bits for others.

.env carries every secret init generates, and every writer opened it under the umask, so a checkout with umask 002 left it 664 -- readable by any local user on the host. All five writers now go through one helper that creates the file at its mode and reasserts it on rewrite: .env at 0640, since a daemon install shares it through the checkout's group, and the backup and access summary at 0600 as before. make init also closes an existing .env to others without touching its owner or group bits.
@catinspace-au
catinspace-au merged commit 47e6529 into main Sep 28, 2026
7 checks passed
@catinspace-au
catinspace-au deleted the fix/dotenv-mode-600 branch September 28, 2026 03:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant