Skip to content

Security: JustVicinity/omagato

Security

SECURITY.md

Security

Please report suspected vulnerabilities privately through GitHub's private vulnerability reporting. If this feature is unavailable, contact the repository owner through their GitHub profile and request a private reporting channel; do not include tokens or exploit details in a public issue. Private reporting must be enabled by the repository owner in GitHub settings.

Security fixes target the latest release. Version 0.7.0 and earlier contain unbounded light HTTP response reads; upgrade to 0.7.1 or later when available.

Trust boundaries and limits

  • OmaGato runs as your user. Configured commands, macros, executable scripts and installed desktop applications are trusted code with your user permissions. Do not load configurations or run scripts from sources you do not trust. Commands use argument lists; this is not a sandbox.
  • Device HTTP requests are direct, ignore proxy environment variables, never follow redirects and reject compressed responses. Light responses are limited to 64 KiB, OpenXLR responses to 1 MiB. A killable worker enforces a three-second deadline including DNS and all response reads. JSON nesting is limited to 32 levels and schemas are checked before use. Up to four requests run concurrently per helper/controller. Periodic probes back off failed lights for 15 seconds; explicit actions try immediately.
  • Light addresses must be canonical IP addresses (including IPv6) or valid .local names. Loopback, unspecified, multicast and reserved addresses are rejected. .local results must be local addresses and are pinned for the connection. Explicit global IP addresses remain permitted for deliberately configured routed devices. Discovery does not register devices automatically. Light HTTP is unencrypted and the devices do not offer authentication here: use a trusted LAN or isolated device network.
  • OpenXLR is contacted only at 127.0.0.1:37890. Before sending its token, Linux's established TCP peer entry must belong to your UID; unavailable ownership information fails closed. Tokens must be regular, non-symlink files owned by you, with no group/other access (typically 0600). They are bounded to 512 ASCII characters and passed to the request worker through a pipe. They are not included in process arguments, output, UI state or errors. This checks UID, not executable identity: another program running as your user can still impersonate OpenXLR and can ordinarily read your files. /proc/net/tcp must be accessible. A protected Unix socket would require an OpenXLR API change and is not assumed.
  • The Stream Deck controller uses one action worker and at most 32 queued entries. Dial movements coalesce; rapid repeated key events are debounced. It tracks at most 32 directly launched child processes and limits starts to 20 per second. Programs and scripts may themselves create children; trusted actions are not a process sandbox. Error history is bounded and repeated journal errors are rate-limited.
  • Configurations are limited to 512 KiB, 16 pages, 64 keys per page, 8 dial settings and 16 lights. Teleprompter scripts are limited to 60 KiB and 64 files. Invalid configurations are rejected without overwriting them. Managed directories use 0700, atomic data writes use 0600. Symlink configuration/secret files and managed installation paths are refused. User-selected images and the current wallpaper may be symlinks, but are read as one bounded regular-file snapshot.
  • Imported PNG/JPEG/WebP images, system raster icons and rendered wallpaper tiles are limited to 10 MiB, 8192 pixels per dimension and 16 megapixels before decoding. Imported icons are converted to PNG with a maximum 512×512 size. SVG app icons render from a bounded stdin snapshot at 256×256, with a five-second deadline, 512 MiB address-space limit and three-second CPU limit.
  • The installer uses a separate venv, fixed package versions and published SHA-256 hashes, binary wheels only, and the explicit PyPI index. Installation intentionally fails on platforms without matching wheels. Only the optional USB-rule installation requests sudo. The rule permits supported Stream Deck product IDs, not all Elgato devices.
  • The user service sets UMask=0077, a 384 MiB soft / 512 MiB hard memory limit, 256 tasks and a restart-rate limit. Started actions can inherit the service's resource limits. The CLI's request, parsing and image limits apply independently. Blanket filesystem/IPC restrictions and NoNewPrivileges are not enabled because user-configured application/script actions may require those capabilities.

Python 3.11–3.14 on Linux is the supported test matrix. Update system Python, libusb, librsvg, Pillow and optional OpenXLR when security fixes become available. Scheduled CI checks the pinned Python packages against public advisories; a clean result does not cover system packages or unknown vulnerabilities.

There aren't any published security advisories