Skip to content

Harden SQLite db.php handling against spoofed markers and filesystem blockers #4355

Description

@chubes4

Summary

The initial adversarial db.php state-machine campaign found four distinct hardening gaps in SqliteIntegrationProvider. The import-engine classification contract from #3993 passed across all 16 destination artifact combinations, including intentional-MySQL non-mutation.

Findings

  • High: installSqliteIntegration() writes through an external wp-content/db.php symlink, modifying the symlink target outside the site and leaving the symlink in place.
  • Medium: Any comment, string, or prefixed identifier containing SQLITE_DB_DROPIN_VERSION is treated as a compatible custom drop-in even though it does not define the constant. Generated variants reproduce this in both classification and installation.
  • Medium: A file blocking wp-content/database/ causes installation to fail with EEXIST.
  • Medium: A directory blocking wp-content/db.php causes installation to fail with EISDIR.

Reproduction

Candidate rig commit: df0b03d1f

git fetch origin fuzz/db-php-state-machine
git switch --detach df0b03d1f
node --experimental-strip-types scripts/fuzz-sqlite-dropin.ts

The deterministic seed is 3692. The runner executes 84 isolated filesystem cases and writes replay data, a JSONL case log, coverage summary, and campaign envelope under artifacts/db-dropin-fuzz/3692/.

Homeboy command:

homeboy fuzz run studio --path "$PWD" --workload component-script-1 \
  --tracker-ref "github-pr:Automattic/studio#3692" \
  --tracker-ref "github-issue:Automattic/studio#3518" \
  --seed 3692 --run-id studio-db-dropin-3692 \
  --gate-profile strict --require-case-log --require-coverage-summary \
  --require-result-envelope --isolation isolated --max-duration 2m

Initial evidence: homeboy://run/studio-db-dropin-3692. The strict run passed case-evidence, target-coverage, and operation-coverage gates; it failed only the expected zero-open-findings gate.

Coverage dimensions

  • Destination SQLite artifact combinations
  • Drop-in content spoofing
  • Custom drop-in preservation
  • Filesystem blocker recovery
  • Symlink containment
  • Intentional-MySQL non-mutation

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions