T06 · System Persistence
- Location
scripts/install_local.sh:21- Finding
Persistent Automatically Restarting User Service
- Content
View full analysis
Vulnerability Details
File Location:
scripts/install_local.sh:21-39
Vulnerability Type: Persistent systemd user service
Risk Level: HighVulnerable Code
bash cat >"$SERVICE_PATH" <<EOF [Unit] Description=Knods Iris Bridge (OpenClaw) After=network-online.target Wants=network-online.target [Service] Type=simple WorkingDirectory=$HOME EnvironmentFile=$ENV_FILE Environment=PYTHONUNBUFFERED=1 Environment=PATH=$HOME/.npm-global/bin:$HOME/.local/bin:/usr/local/bin:/usr/bin:/bin Environment=OPENCLAW_BIN=$OPENCLAW_BIN_DETECTED ExecStart=/usr/bin/python3 $BRIDGE_DST Restart=always RestartSec=2 [Install] WantedBy=default.target EOF systemctl --user daemon-reload systemctl --user enable --now "$SERVICE_NAME"Technical Analysis
The installer creates a systemd user unit, enables it for future sessions, starts it immediately, and configures it to restart indefinitely. This persistence is disclosed and supports the polling bridge's intended operation, but it causes code to continue executing across sessions without requiring another explicit user action.
The persistent process runs with the user's privileges, imports an environment file, invokes the local OpenClaw agent, and maintains continuous network access. No systemd sandboxing directives are applied to restrict filesystem, process, device, or privilege access.
Attack Path
- The user runs
scripts/install_local.sh. - The script copies the bridge into
~/.openclaw/scripts. - A systemd user service is created and enabled.
- The bridge starts immediately and starts again in later user sessions.
- If the bridge, its configuration, the gateway, or the invoked agent is compromised, the service provides a durable execution and network channel.
Restart=alwayscauses the process to return after crashes or termination attempts unless the service is explicitly disabled.
Impact Assessment
Th ...[truncated 357 chars]
- The user runs
- Remediation
View remediation
Remediation Suggestions
- Separate file installation from service activation.
- Do not execute
systemctl --user enable --nowautomatically. Require an explicit, documented opt-in command. - Provide an uninstall operation that stops, disables, and removes the unit and copied bridge.
- Ask for confirmation before enabling cross-session execution.
- Add systemd hardening controls where compatible, including:
NoNewPrivileges=truePrivateTmp=trueProtectSystem=strictProtectHome=read-onlyor a narrowly scoped allowlistRestrictSUIDSGID=trueLockPersonality=trueRestrictAddressFamilies=AF_INET AF_INET6
- Use bounded restart behavior and systemd start-rate limits rather than unrestricted automatic restarts.
- Document the service's execution scope, environment access, network access, and removal procedure prominently before installation.
