| @@ -0,0 +1,70 @@ | |||
| 1 | + | ||
| 2 | + | ### High | |
| 3 | + | ||
| 4 | + | - Unauthenticated API exposed on all interfaces. --serve/--listen defaults to 0.0.0.0, and authentication is skipped when no token is configured. This exposes host, mounts, devices, sensors, GPU, and network data. | |
| 5 | + | Evidence: src/main.cpp:56, src/api.cpp:1347 | |
| 6 | + | ||
| 7 | + | - Bearer tokens are sent over plaintext HTTP. HTTPS is explicitly rejected, while remote polling sends Authorization: Bearer ... over an unencrypted socket. Network observers can steal the token. | |
| 8 | + | Evidence: src/api.cpp:1045, src/api.cpp:1436 | |
| 9 | + | ||
| 10 | + | - Unhandled SIGPIPE can terminate the process. POSIX send() is used without MSG_NOSIGNAL, and the application never ignores SIGPIPE. A peer closing during response transmission can kill mmon. | |
| 11 | + | Evidence: src/api.cpp:177, src/main.cpp:2108 | |
| 12 | + | ||
| 13 | + | - Single-threaded HTTP server is vulnerable to slow-client denial of service. run() handles each connection synchronously. A client can hold the only server thread by slowly sending headers/body or refusing to read the response. | |
| 14 | + | Evidence: src/api.cpp:1234, src/api.cpp:1248 | |
| 15 | + | ||
| 16 | + | - Encrypted push frames have no replay protection. crypto::open() accepts any previously valid envelope, and returned commands are executed without timestamps, counters, or freshness checks. A captured quit, serve, connect, or key | |
| 17 | + | command can be replayed. | |
| 18 | + | Evidence: src/crypto.cpp:401, src/api.cpp:1652 | |
| 19 | + | ||
| 20 | + | - Unbounded decompression and response accumulation permit memory exhaustion. Gzip output has no maximum size, and close-delimited HTTP responses are accumulated without a limit. | |
| 21 | + | Evidence: src/api.cpp:333, /home/blackbeard/src/api.cpp:297 | |
| 22 | + | ||
| 23 | + | - CPU topology detection changes the application’s CPU affinity. cpuidGroups() pins the calling thread to each CPU but never restores the original affinity. The main thread and subsequently created threads can remain restricted to the | |
| 24 | + | final CPU. | |
| 25 | + | Evidence: src/sys_metrics.cpp:145, src/sys_metrics.cpp:157 | |
| 26 | + | ||
| 27 | + | - Windows build fetches an unpinned external dependency. build-win.sh clones PDCurses from the moving default branch, making builds non-reproducible and creating a supply-chain risk. | |
| 28 | + | Evidence: build-win.sh:12 | |
| 29 | + | ||
| 30 | + | ### Medium | |
| 31 | + | ||
| 32 | + | - Generated token/config files are not protected. ofstream creates files using the process umask. Under a permissive umask, --write-config produced mode 0666, exposing authentication tokens to other users. | |
| 33 | + | Evidence: src/main.cpp:2067 | |
| 34 | + | ||
| 35 | + | - Metric collection can block indefinitely. statvfs() on hung network mounts, zpool, nvidia-smi, and Windows WMI/PDH calls run synchronously in the main refresh path. | |
| 36 | + | Evidence: src/sys_metrics.cpp:393, src/sys_metrics.cpp:445 | |
| 37 | + | ||
| 38 | + | - JSON parser accepts invalid/non-finite numbers and does not validate trailing input. Inputs such as NaN, Inf, oversized integers, malformed trailing data, or deeply nested structures can cause undefined conversions, bad display | |
| 39 | + | values, or crashes. | |
| 40 | + | Evidence: src/api.cpp:536, src/api.cpp:773 | |
| 41 | + | ||
| 42 | + | - CPU counter decreases are not handled. Counter deltas use unsigned subtraction without validating each field. CPU hotplug/reset conditions can produce enormous percentages and undefined floating-to-integer conversions during | |
| 43 | + | rendering. | |
| 44 | + | Evidence: src/sys_metrics.cpp:947, src/main.cpp:412 | |
| 45 | + | ||
| 46 | + | - Windows disk throughput likely remains zero/unavailable. A new PDH query is created on every update and only one sample is collected; rate counters generally require two samples. | |
| 47 | + | Evidence: src/sys_metrics_windows.cpp:243 | |
| 48 | + | ||
| 49 | + | - GPU fallback order contradicts the documented order. The implementation selects DRM before trying nvidia-smi, contrary to the README/manual. | |
| 50 | + | Evidence: src/gpu_metrics.cpp:190 | |
| 51 | + | ||
| 52 | + | - nvidia-smi reports N/A temperature/power as valid zero values. Temperature and power flags are set solely based on column count. | |
| 53 | + | Evidence: src/gpu_metrics.cpp:295 | |
| 54 | + | ||
| 55 | + | - Selecting a named remote theme does not apply it. selectTheme() changes only the index; it does not call applyTheme(). | |
| 56 | + | Evidence: src/theme.cpp:416, src/main.cpp:1360 | |
| 57 | + | ||
| 58 | + | - The secondary Windows build script is broken from a clean checkout. It does not fetch PDCurses, while the CMake Windows target requires it. A clean configure reproduced No SOURCES given to target: pdcurses. | |
| 59 | + | Evidence: scripts/build-windows.sh:6, CMakeLists.txt:21 | |
| 60 | + | ||
| 61 | + | - IPv6 is unsupported. Both server and client force AF_INET; IPv6-only hosts, bind addresses, and bracketed IPv6 URLs fail. | |
| 62 | + | Evidence: src/api.cpp:130, src/api.cpp:1162 | |
| 63 | + | ||
| 64 | + | ### Low | |
| 65 | + | ||
| 66 | + | - Bar rendering ignores its bgPair argument, so custom themes can render incorrect bar-track backgrounds: src/ui.cpp:63 | |
| 67 | + | - ZFS pools with only one child cannot be expanded because expansion requires more than one part: src/main.cpp:656 | |
| 68 | + | - Mount paths from /proc/mounts are not unescaped (\040, \011), causing mounts containing spaces/tabs to be misread: src/sys_metrics.cpp:384 | |
| 69 | + | - SERVER.md is referenced throughout the documentation but is absent and explicitly ignored by Git: .gitignore:10 | |
| 70 | + | - There is no automated test suite for HTTP framing, authentication, replay, malformed JSON, resource limits, platform collectors, or UI behavior. | |
blackbeard420 / mmon luna audit
Last active 1 month ago
blackbeard420
revised this gist 1 month ago
·
e77e83f
1 file changed, 70 insertions