import fs from "node:fs"; import path from "node:path"; import { getWindowsInstallRoots, getWindowsProgramFilesRoots } from "./windows-install-roots.js";
// Unix directories where OS-managed or system-installed binaries live. // User-writable or package-manager-managed directories are excluded so that // attacker-planted binaries cannot shadow legitimate system executables. const UNIX_BASE_TRUSTED_DIRS = ["/usr/bin", "/bin", "/usr/sbin", "/sbin"] as const;
// Package-manager directories appended in "standard" trust on macOS. // These come after strict dirs so OS binaries always take priority. // Could be acceptable for tooling binaries like ffmpeg but NOT for // security-critical ones like openssl — callers needing higher // assurance should stick with "strict". const DARWIN_STANDARD_DIRS = ["/opt/homebrew/bin", "/usr/local/bin"] as const; const LINUX_STANDARD_DIRS = ["/usr/local/bin"] as const;
// Windows extensions to probe when searching for executables. const WIN_PATHEXT = [".exe", ".cmd", ".bat", ".com"] as const;
const resolvedCacheStrict = new Map<string, string>(); const resolvedCacheStandard = new Map<string, string>();
for (const programFilesRoot of getWindowsProgramFilesRoots()) { // Trust the machine's validated Program Files roots rather than assuming C:.
dirs.push(path.win32.join(programFilesRoot, "OpenSSL-Win64", "bin"));
dirs.push(path.win32.join(programFilesRoot, "OpenSSL", "bin"));
dirs.push(path.win32.join(programFilesRoot, "ffmpeg", "bin"));
}
if (platform === "linux") { // Fixed NixOS system profile path. Never derive trust from NIX_PROFILES: // env-controlled Nix store/profile entries can be attacker-selected. // Callers that intentionally rely on non-default Nix paths must opt in via extraDirs.
dirs.push("/run/current-system/sw/bin");
dirs.push("/snap/bin");
}
// "standard" trust widens the search for non-security-critical tools in // common local-admin/package-manager directories, while keeping strict dirs // first so OS binaries always take priority. if (trust === "standard") { if (platform === "darwin") {
dirs.push(...DARWIN_STANDARD_DIRS);
} elseif (platform === "linux") {
dirs.push(...LINUX_STANDARD_DIRS);
}
}
return dirs;
}
let trustedDirsStrict: readonly string[] | null = null;
let trustedDirsStandard: readonly string[] | null = null;
function getTrustedDirs(trust: SystemBinTrust): readonly string[] { if (process.platform === "win32") { // Windows does not currently widen "standard" beyond the registry-backed // system roots; both trust levels intentionally share the same set today.
trustedDirsStrict ??= buildWindowsTrustedDirs(); return trustedDirsStrict;
} if (trust === "standard") {
trustedDirsStandard ??= buildUnixTrustedDirs("standard"); return trustedDirsStandard;
}
trustedDirsStrict ??= buildUnixTrustedDirs("strict"); return trustedDirsStrict;
}
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.