fix(backend): harden provider credential isolation
This commit is contained in:
@@ -1,6 +1,7 @@
|
||||
import { spawn as nodeSpawn, type ChildProcessWithoutNullStreams } from "node:child_process";
|
||||
import type { AppConfig } from "../config.js";
|
||||
import { RpcClient } from "../rpc/rpc-client.js";
|
||||
import { buildPiChildEnv } from "./provider-credentials.js";
|
||||
|
||||
export interface PiModel {
|
||||
provider: string;
|
||||
@@ -34,7 +35,10 @@ export function createPiModelLister(cfg: AppConfig, opts: Opts = {}): () => Prom
|
||||
return async function listModels(): Promise<PiModel[]> {
|
||||
if (cache && now() - cache.at < ttlMs) return cache.models;
|
||||
|
||||
const env: NodeJS.ProcessEnv = { ...process.env };
|
||||
const env = buildPiChildEnv({
|
||||
provider: cfg.defaults.provider,
|
||||
credentialFile: cfg.modelApiKeyFile,
|
||||
});
|
||||
delete env.THT_DATA_ROOT;
|
||||
if (cfg.dataRoot !== undefined) env.THT_DATA_ROOT = cfg.dataRoot;
|
||||
const child = spawnFn(cfg.piBin, ["--mode", "rpc"], { cwd: cfg.harnessDir, env });
|
||||
|
||||
@@ -1,9 +1,9 @@
|
||||
import { spawn as nodeSpawn, type ChildProcessWithoutNullStreams } from "node:child_process";
|
||||
import { closeSync, constants, fstatSync, lstatSync, openSync, readFileSync } from "node:fs";
|
||||
import type { AppConfig } from "../config.js";
|
||||
import { RpcClient } from "../rpc/rpc-client.js";
|
||||
import { SessionBridge } from "../bridge/session-bridge.js";
|
||||
import type { ThtRunner } from "../tht/tht-runner.js";
|
||||
import { buildPiChildEnv, canonicalPiProvider } from "./provider-credentials.js";
|
||||
|
||||
export interface SessionRuntime {
|
||||
rpc: RpcClient;
|
||||
@@ -18,51 +18,6 @@ type SpawnFn = (
|
||||
options: { cwd: string; env: NodeJS.ProcessEnv },
|
||||
) => ChildProcessWithoutNullStreams;
|
||||
|
||||
const PROVIDER_KEY_ENV: Readonly<Record<string, string>> = {
|
||||
anthropic: "ANTHROPIC_API_KEY",
|
||||
openai: "OPENAI_API_KEY",
|
||||
gemini: "GEMINI_API_KEY",
|
||||
google: "GEMINI_API_KEY",
|
||||
deepseek: "DEEPSEEK_API_KEY",
|
||||
zai: "ZAI_API_KEY",
|
||||
groq: "GROQ_API_KEY",
|
||||
mistral: "MISTRAL_API_KEY",
|
||||
openrouter: "OPENROUTER_API_KEY",
|
||||
xai: "XAI_API_KEY",
|
||||
cerebras: "CEREBRAS_API_KEY",
|
||||
cohere: "COHERE_API_KEY",
|
||||
};
|
||||
const LOCAL_PROVIDERS = new Set(["ollama", "lmstudio", "local", "aritmolab"]);
|
||||
const PROVIDER_ENV_NAMES = new Set(Object.values(PROVIDER_KEY_ENV));
|
||||
|
||||
function normalizedProvider(provider: string | undefined): string | undefined {
|
||||
const value = provider?.trim().toLowerCase();
|
||||
return value || undefined;
|
||||
}
|
||||
|
||||
function readModelCredential(file: string): string {
|
||||
let fd: number | undefined;
|
||||
try {
|
||||
const before = lstatSync(file);
|
||||
if (!before.isFile() || before.isSymbolicLink() || before.nlink !== 1) throw new Error();
|
||||
fd = openSync(file, constants.O_RDONLY | constants.O_NOFOLLOW);
|
||||
const info = fstatSync(fd);
|
||||
const mode = info.mode & 0o777;
|
||||
const ownedStrict = info.uid === process.getuid?.() && (mode === 0o400 || mode === 0o600);
|
||||
const dockerSecret = file.startsWith("/run/secrets/") && mode === 0o444;
|
||||
if (!info.isFile() || info.nlink !== 1 || (!ownedStrict && !dockerSecret) || info.size > 16_384) {
|
||||
throw new Error();
|
||||
}
|
||||
const value = readFileSync(fd, "utf8");
|
||||
if (!value || /\s/.test(value)) throw new Error();
|
||||
return value;
|
||||
} catch {
|
||||
throw new Error("model provider credential is unavailable");
|
||||
} finally {
|
||||
if (fd !== undefined) closeSync(fd);
|
||||
}
|
||||
}
|
||||
|
||||
export class PiProcessManager {
|
||||
private runtimes = new Map<string, SessionRuntime>();
|
||||
private spawnFn: (
|
||||
@@ -82,26 +37,13 @@ export class PiProcessManager {
|
||||
private spawnPi(
|
||||
spawnFn: SpawnFn, sessionId: string, author: string, provider: string | undefined,
|
||||
): ChildProcessWithoutNullStreams {
|
||||
const env: NodeJS.ProcessEnv = {
|
||||
...process.env,
|
||||
THT_SESSION: sessionId,
|
||||
THT_AUTHOR: author,
|
||||
};
|
||||
const env = buildPiChildEnv({
|
||||
provider,
|
||||
credentialFile: this.cfg.modelApiKeyFile,
|
||||
additions: { THT_SESSION: sessionId, THT_AUTHOR: author },
|
||||
});
|
||||
delete env.THT_DATA_ROOT;
|
||||
delete env.PI_PROVIDER_API_KEY;
|
||||
delete env.THT_MODEL_API_KEY_FILE;
|
||||
for (const name of PROVIDER_ENV_NAMES) delete env[name];
|
||||
if (this.cfg.dataRoot !== undefined) env.THT_DATA_ROOT = this.cfg.dataRoot;
|
||||
const normalized = normalizedProvider(provider);
|
||||
if (normalized && !LOCAL_PROVIDERS.has(normalized)) {
|
||||
const envName = PROVIDER_KEY_ENV[normalized];
|
||||
if (!envName || !this.cfg.modelApiKeyFile) {
|
||||
throw new Error("model provider credential is unavailable");
|
||||
}
|
||||
env[envName] = readModelCredential(this.cfg.modelApiKeyFile);
|
||||
} else if (this.cfg.modelApiKeyFile && !normalized) {
|
||||
throw new Error("model provider credential is unavailable");
|
||||
}
|
||||
// pi 0.73 removed `--approve`: rpc mode is headless and its argv is intentionally minimal.
|
||||
const child = spawnFn(this.cfg.piBin, ["--mode", "rpc"], {
|
||||
cwd: this.cfg.harnessDir,
|
||||
@@ -132,7 +74,7 @@ export class PiProcessManager {
|
||||
throw new Error("max Pi processes reached");
|
||||
}
|
||||
const author = o.author ?? "dev@local";
|
||||
const provider = o.provider ?? this.cfg.defaults.provider;
|
||||
const provider = canonicalPiProvider(o.provider ?? this.cfg.defaults.provider);
|
||||
const child = this.spawnFn(sessionId, author, provider);
|
||||
const rpc = new RpcClient(child);
|
||||
const bridge = new SessionBridge(rpc);
|
||||
|
||||
@@ -0,0 +1,120 @@
|
||||
import {
|
||||
closeSync, constants, fstatSync, lstatSync, openSync, readFileSync,
|
||||
type Stats,
|
||||
} from "node:fs";
|
||||
|
||||
/** Audited against @earendil-works/pi-ai 0.80.3 auth plus its locked AWS credential chain. */
|
||||
export const PI_0803_CREDENTIAL_ENV_NAMES = Object.freeze([
|
||||
"AI_GATEWAY_API_KEY", "ANTHROPIC_API_KEY", "ANTHROPIC_OAUTH_TOKEN", "ANT_LING_API_KEY",
|
||||
"AWS_ACCESS_KEY_ID", "AWS_BEARER_TOKEN_BEDROCK", "AWS_CONFIG_FILE",
|
||||
"AWS_CONTAINER_AUTHORIZATION_TOKEN", "AWS_CONTAINER_AUTHORIZATION_TOKEN_FILE",
|
||||
"AWS_CONTAINER_CREDENTIALS_FULL_URI", "AWS_CONTAINER_CREDENTIALS_RELATIVE_URI", "AWS_PROFILE",
|
||||
"AWS_ROLE_ARN", "AWS_ROLE_SESSION_NAME", "AWS_SECRET_ACCESS_KEY", "AWS_SESSION_TOKEN",
|
||||
"AWS_SHARED_CREDENTIALS_FILE", "AWS_WEB_IDENTITY_TOKEN_FILE", "AZURE_OPENAI_API_KEY",
|
||||
"CEREBRAS_API_KEY", "CLOUDFLARE_ACCOUNT_ID", "CLOUDFLARE_API_KEY",
|
||||
"CLOUDFLARE_GATEWAY_ID", "COPILOT_GITHUB_TOKEN", "DEEPSEEK_API_KEY", "FIREWORKS_API_KEY",
|
||||
"GCLOUD_PROJECT", "GEMINI_API_KEY", "GOOGLE_APPLICATION_CREDENTIALS", "GOOGLE_CLOUD_API_KEY",
|
||||
"GOOGLE_CLOUD_LOCATION", "GOOGLE_CLOUD_PROJECT", "GROQ_API_KEY", "HF_TOKEN",
|
||||
"KIMI_API_KEY", "MINIMAX_API_KEY", "MINIMAX_CN_API_KEY", "MISTRAL_API_KEY",
|
||||
"MOONSHOT_API_KEY", "NVIDIA_API_KEY", "OPENCODE_API_KEY", "OPENAI_API_KEY",
|
||||
"OPENROUTER_API_KEY", "TOGETHER_API_KEY", "XAI_API_KEY", "XIAOMI_API_KEY",
|
||||
"XIAOMI_TOKEN_PLAN_AMS_API_KEY", "XIAOMI_TOKEN_PLAN_CN_API_KEY",
|
||||
"XIAOMI_TOKEN_PLAN_SGP_API_KEY", "ZAI_API_KEY", "ZAI_CODING_CN_API_KEY",
|
||||
]);
|
||||
|
||||
const PROVIDER_KEY_ENV: Readonly<Record<string, string>> = {
|
||||
"amazon-bedrock": "AWS_BEARER_TOKEN_BEDROCK",
|
||||
"ant-ling": "ANT_LING_API_KEY",
|
||||
anthropic: "ANTHROPIC_API_KEY",
|
||||
"azure-openai-responses": "AZURE_OPENAI_API_KEY",
|
||||
cerebras: "CEREBRAS_API_KEY",
|
||||
"cloudflare-ai-gateway": "CLOUDFLARE_API_KEY",
|
||||
"cloudflare-workers-ai": "CLOUDFLARE_API_KEY",
|
||||
deepseek: "DEEPSEEK_API_KEY", fireworks: "FIREWORKS_API_KEY",
|
||||
"github-copilot": "COPILOT_GITHUB_TOKEN", google: "GEMINI_API_KEY",
|
||||
"google-vertex": "GOOGLE_CLOUD_API_KEY", groq: "GROQ_API_KEY", huggingface: "HF_TOKEN",
|
||||
"kimi-coding": "KIMI_API_KEY", minimax: "MINIMAX_API_KEY", "minimax-cn": "MINIMAX_CN_API_KEY",
|
||||
mistral: "MISTRAL_API_KEY", moonshotai: "MOONSHOT_API_KEY", "moonshotai-cn": "MOONSHOT_API_KEY",
|
||||
nvidia: "NVIDIA_API_KEY", openai: "OPENAI_API_KEY", opencode: "OPENCODE_API_KEY",
|
||||
"opencode-go": "OPENCODE_API_KEY", openrouter: "OPENROUTER_API_KEY", together: "TOGETHER_API_KEY",
|
||||
"vercel-ai-gateway": "AI_GATEWAY_API_KEY", xai: "XAI_API_KEY", xiaomi: "XIAOMI_API_KEY",
|
||||
"xiaomi-token-plan-ams": "XIAOMI_TOKEN_PLAN_AMS_API_KEY",
|
||||
"xiaomi-token-plan-cn": "XIAOMI_TOKEN_PLAN_CN_API_KEY",
|
||||
"xiaomi-token-plan-sgp": "XIAOMI_TOKEN_PLAN_SGP_API_KEY", zai: "ZAI_API_KEY",
|
||||
"zai-coding-cn": "ZAI_CODING_CN_API_KEY",
|
||||
};
|
||||
const LOCAL_PROVIDERS = new Set(["ollama", "lmstudio", "local", "aritmolab", "faux"]);
|
||||
|
||||
export function canonicalPiProvider(provider: string | undefined): string | undefined {
|
||||
const value = provider?.trim().toLowerCase();
|
||||
if (!value) return undefined;
|
||||
if (value === "gemini") return "google";
|
||||
return value;
|
||||
}
|
||||
|
||||
export interface CredentialFsOps {
|
||||
lstat(path: string): Stats;
|
||||
open(path: string, flags: number): number;
|
||||
fstat(fd: number): Stats;
|
||||
read(fd: number): string;
|
||||
close(fd: number): void;
|
||||
}
|
||||
const realFs: CredentialFsOps = {
|
||||
lstat: lstatSync, open: openSync, fstat: fstatSync,
|
||||
read: (fd) => readFileSync(fd, "utf8"), close: closeSync,
|
||||
};
|
||||
|
||||
function validSecretStat(info: Stats, docker: boolean): boolean {
|
||||
const mode = info.mode & 0o777;
|
||||
if (!info.isFile() || info.isSymbolicLink() || info.nlink !== 1 || info.size > 16_384) return false;
|
||||
if (docker) return info.uid === 0 && mode === 0o444;
|
||||
return info.uid === process.getuid?.() && (mode === 0o400 || mode === 0o600);
|
||||
}
|
||||
|
||||
function readCredential(file: string, fs: CredentialFsOps): string {
|
||||
let fd: number | undefined;
|
||||
try {
|
||||
const docker = file.startsWith("/run/secrets/") && !file.slice("/run/secrets/".length).includes("/");
|
||||
if (file.startsWith("/run/secrets/") && !docker) throw new Error();
|
||||
if (docker) {
|
||||
const parent = fs.lstat("/run/secrets");
|
||||
if (!parent.isDirectory() || parent.uid !== 0 || (parent.mode & 0o022) !== 0) throw new Error();
|
||||
}
|
||||
const before = fs.lstat(file);
|
||||
if (!validSecretStat(before, docker)) throw new Error();
|
||||
fd = fs.open(file, constants.O_RDONLY | constants.O_NOFOLLOW);
|
||||
const opened = fs.fstat(fd);
|
||||
if (!validSecretStat(opened, docker) || before.dev !== opened.dev || before.ino !== opened.ino) throw new Error();
|
||||
const value = fs.read(fd);
|
||||
if (!value || /\s/.test(value)) throw new Error();
|
||||
return value;
|
||||
} catch {
|
||||
throw new Error("model provider credential is unavailable");
|
||||
} finally {
|
||||
if (fd !== undefined) {
|
||||
try { fs.close(fd); } catch { /* sanitized by design */ }
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
export function buildPiChildEnv(opts: {
|
||||
ambient?: NodeJS.ProcessEnv;
|
||||
provider?: string;
|
||||
credentialFile?: string;
|
||||
additions?: NodeJS.ProcessEnv;
|
||||
fsOps?: CredentialFsOps;
|
||||
}): NodeJS.ProcessEnv {
|
||||
const env = { ...(opts.ambient ?? process.env), ...opts.additions };
|
||||
delete env.PI_PROVIDER_API_KEY;
|
||||
delete env.THT_MODEL_API_KEY_FILE;
|
||||
for (const name of PI_0803_CREDENTIAL_ENV_NAMES) delete env[name];
|
||||
const provider = canonicalPiProvider(opts.provider);
|
||||
if (provider && !LOCAL_PROVIDERS.has(provider)) {
|
||||
const envName = PROVIDER_KEY_ENV[provider];
|
||||
if (!envName || !opts.credentialFile) throw new Error("model provider credential is unavailable");
|
||||
env[envName] = readCredential(opts.credentialFile, opts.fsOps ?? realFs);
|
||||
} else if (opts.credentialFile && !provider) {
|
||||
throw new Error("model provider credential is unavailable");
|
||||
}
|
||||
return env;
|
||||
}
|
||||
Reference in New Issue
Block a user