Skip to content

Allowing external feeds into the server #1668

Description

@efahl

With @a-gave 's recent additions to owut (efahl/owut@2fab581), we are almost in position to do transparent ASU upgrades using "foreign" feeds. The one blocker is ASU's allowlist in config.repository_allow_list, which does an extra check to only allow repos in that we deem proper.

Here's an example scenario. User wants to use AmnezaWG, so they add the entry to customfeeds.dist, download the keys, etc. Basically, go through the instructions at:

https://slava-shchipunov.github.io/awg-openwrt/25.12.5/x86/64/

They can then use apk to transparently install the packages from that feed:

$ apk update
 [https://slava-shchipunov.github.io/awg-openwrt/25.12.5/x86/64/packages.adb]
...

$ apk query --format yaml --fields name --match origin '*amneziawg*'
# 4 items
- name: amneziawg-tools
- name: kmod-amneziawg
- name: luci-i18n-amneziawg-ru
- name: luci-proto-amneziawg

$ apk add luci-proto-amneziawg
... it just works ...

But, then when the user tries to upgrade, they are blocked by the server, even though they've given the server everything it needs (feed+keys) in the request, and it is apparent the user already trusts the feed.

$ owut upgrade
...
Request:
  Version 25.12.5 r33051-f5dae5ece4 (kernel 6.12.94)
--
Status:   Repository not allowed: https://slava-shchipunov.github.io/awg-openwrt/25.12.5/x86/64/packages.adb
Progress:   0s total =   0s in queue +   0s in build

Build failed in   0s total =   0s in queue +   0s to build:
ERROR: Build failed with status 400 (--version-to 25.12.5 --device x86/64:generic:squashfs)

So...

  • What are the risks of allowing non-official feeds?
  • Malicious package init scripts might run in the build container from the apk add step; I'm not clear on what the attack surface is here.
  • Are the build containers sufficiently jailed that we could just get rid of the allow list, let everything through?
  • What else could go wrong?
  • Do we want to let users request adding certain feeds, and after review, manually add them to the asu.toml in the repository_allow_list? (That seems like a lot of extra work and not particularly scalable.)
  • Or do we want to just say, "this is your problem, set up your own ASU server configured as you like"?

Note that this ties into openwrt/packages#30356, if we want to start pointing people to external package feeds.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions