Digital Man around Wednesday, September 30th...
https://github.com/SynchronetBBS/sbbs/blob/master/docs/dropfile_ini.md
Not implemented anywhere yet (not even in Synchronet), purposely, so as to give the community time (mainly door and host/BBS/server authors) time to give feedback. I do plan to implement support for this format (once it's finalized) in Synchronet BBS software and some of my new doors.
I think this all could work quite well. Here is a long text of my review of draft 0.3:
SECURITY
--------
1. Key injection through Unicode line separators.
The control character list (C0, DEL, C1) leaves out U+2028 and
U+2029, so they can appear in UTF-8 text values. Python's
str.splitlines() and JavaScript multiline regex (/^KEY=(.*)$/m)
both treat them as line breaks; I tested both. With "first
occurrence wins", an alias of "A", U+2028, "USER_ROLE=sysop" is 19
bytes, so it fits a 25-byte alias. A door that reads the file that
way then thinks the user is a sysop. The same trick overrides
TIME_LEFT, PREF_* or vendor keys that come after [user]. The C,
Pascal and QBasic samples are safe; Python and JS doors are not.
Suggest: add U+2028 and U+2029 to the characters replaced with "?".
Consider the bidi overrides too (U+202A-U+202E, U+2066-U+2069),
which let a name pose as another on score lists.
2. USER_KEY isn't safe in file names.
The allowed characters let through ".", "..", and device names like
"NUL", "CON", "AUX", "PRN", "COM1" and "LPT1" ("CON.1" too, since
"." is allowed). A door that joins its data dir and USER_KEY gets a
path traversal or a write to a device.
Suggest: require a letter or digit first and ban DOS/Windows device
names with or without an extension, or tell doors to hash the key.
3. The file says who the user is.
"Grants no privileges" covers the OS. Inside a door, USER_KEY and
USER_ROLE decide whose saved game loads and who gets sysop
functions:
- A door that takes the path on its command line, and can also be
started directly (doors run over SSH, door servers), accepts a
forged file.
- The fallback to the current directory can pick up a stale file
from another session or node, so user B plays as user A.
FILE_TIME is only advisory.
- The spec says who may read the file, but not who may write it.
Suggest: say a door trusts the file only as far as it trusts
whoever could write it, and the host SHOULD make it writable only
by the host. Drop or discourage the current-directory fallback. A
SESSION_ID key, unique per launch, would help logs and let a door
spot a file it has already seen.
4. Windows handle inheritance (minor).
In a threaded multi-node host, an inheritable socket can leak into
another node's door started at the same moment. One line pointing
at PROC_THREAD_ATTRIBUTE_HANDLE_LIST would cover it; on POSIX,
close-on-exec everywhere and dup2 in the child.
5. Personal details by default.
The Synchronet notes write IP, birthdate, e-mail and caller ID
whenever the user record has them, so every door gets them,
including closed-source doors and inter-BBS doors that send data
off the system.
Suggest: recommend that personal keys are opt-in per door.
6. No COMM_TYPE for a door that connects to the host.
Every type is something the door is handed. A host where the door,
or an emulator's virtual COM port, connects back to a host TCP port
has no correct value to write. That setup has its own risk:
whatever connects first gets the caller's session.
Suggest: if a connect-back type is added, require a loopback-only
listener and a per-session token the door sends first.
7. Unknown token values.
Unknown keys are covered, unknown values are not. A door that sees
a USER_ROLE it doesn't know should treat it as "user", never as
cosysop or sysop.
Suggest: one general rule that an unknown token reads as the key's
default (TERM_TYPE, SYS_DATE_FORMAT, TERM_SIXEL_SCALE, ...), with
USER_ROLE called out.
COMPATIBILITY
-------------
8. FILE_UTF8 is yes/no, so any text that isn't UTF-8 must be CP437.
CP866 (Russian Fido), CP850/CP865 and Amiga Latin-1 doors can't be
served. Suggest a FILE_CHARSET key that uses the COMM_CHARSET names
and defaults to CP437.
9. TERM_TYPE has no "avatar" (AVT/0, still used by Fido-era doors) and
no "atascii" (the Atari 8-bit scene is active). COMM_CHARSET has no
ATASCII either.
10. No terminfo name. Native curses doors need the terminal type from
Telnet TTYPE or the SSH pty request (xterm-256color etc.).
TERM_NAME is "as the terminal reported it", but doesn't say which
report. Suggest TERM_TERMINFO, or naming TERM_NAME's source.
11. Screen size is a snapshot. A socket door never hears about a
Telnet NAWS or SSH window change during the session. Worth saying
so, and that a door can query the size again if it cares.
12. SYS_FTN_ADDR holds one "primary" address with no @domain.
Inter-BBS games on an othernet (fsxNet zone 21 and so on) need
that network's address. Suggest allowing @domain, and more than
one address (a comma list, or numbered keys).
13. File name case. Allowing lowercase dropfile.ini means every POSIX
door that searches a directory has to scan it case-insensitively.
Suggest: always DROPFILE.INI in caps, on every platform, and drop
the lowercase option.
14. Paths are "text". TEMP_DIR goes through CP437/UTF-8 conversion,
"?" replacement and the 222-byte cut. A cut or "?"-mangled path is
worse than none. Suggest a path type: file system bytes, never
converted, and left out (not cut) when it can't be written as is.
The same "leave out, don't cut" rule suits USER_EMAIL,
USER_NETMAIL and the host name keys.
15. CRLF on POSIX. It's the right call for DOS, but naive Linux
readers keep the trailing CR, and then COMM_TYPE == "socket" is
false. One sentence in the consumer rules would save some grief.
16. Test files. The Win32 profile API, Python's configparser and plain
line readers already disagree on some input. A key in the wrong
section is missed by a section lookup but found by a line reader.
A quoted value loses its quotes under Win32 and keeps them under
configparser. A few sample files with their expected values would
keep door kits in step.
Happy to discuss any of it, thanks again for posting up a spec for review!
--
|08 þ |12NuSkooler |06// |12Xibalba |08- |07"|06The place of fear|07"
|08 þ |03xibalba|08.|03vip |08(|0344510|08/|03telnet|08, |0344511|08/|03ssh|08) |08 þ |03ENiGMA 1/2 WHQ |08| |03Phenom |08| |0367 |08| |03iMPURE |08| |03ACiDic --- ENiGMA 1/2 v0.5.1-beta (linux; x64; 22.22.2)
* Origin: Xibalba -+- xibalba.vip:44510 (21:1/121)