T09 · Insecure Skill Coding Practices
- Location
scripts/openclaw-backup.sh:457- Finding
Predictable Backup Files Permit Symbolic-Link File Modification
- Content
View full analysis
> "$log_path" printf '[openclaw-backup] Resolved workspace: %s\n' "$WORKSPACE" >> "$log_path" enable_log_tee "$log_path" log "Backup mode: $backup_mode_label" # Stage backup contents in a temporary directory before packing the archive. staging_dir="$(mktemp -d "${TMPDIR:-/tmp}/openclaw-backup.XXXXXXXX")" ``` ```bash log "Creating temporary archive: $temp_archive_path" tar -C "$staging_dir" -czf "$temp_archive_path" "$archive_basename" [[ -s "$temp_archive_path" ]] || fail "Temporary archive was created but is empty: $temp_archive_path" log "Verifying temporary archive readability" tar -tzf "$temp_archive_path" >/dev/null log "Finalizing archive: $final_archive_path" mv -- "$temp_archive_path" "$final_archive_path" ``` ### Technical Analysis The staging directory is securely generated with `mktemp`, and `umask 077` protects newly created files. However, the log and temporary archive paths are derived from a UTC timestamp with one-second precision and predictable suffixes: - `openclaw-light-backup-.log` - `openclaw-light-backup-.tar.gz.part` The script does not create these files exclusively and does not reject existing files or symbolic links. An explicitly supplied output directory is only checked for existence; its ownership and write permissions are not validated. The ...[truncated 2744 chars]- Remediation
View remediation
