Security/Bug: Go server leaks auth_token to ps and leaves zombie processes
@jakubbortlik がすでに取り組んでいます。
2026年9月22日 から。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 46/100
調査の方向性
:h gitlab.nvim.troubleshooting から始め、次に vim.system() によるサーバー起動、Go の設定処理、VimLeavePre のライフサイクル処理を特定します。レポートにはソースファイルやテストの名前がなく、再現手順も不完全です。認証がトークンをプロセス引数に公開せずに引き続き機能し、報告されている高速終了や強制終了を含め、Neovim の終了後にサーバープロセスが残らなければ完了です。
索引モデルが issue の本文から書いたものです。
説明
Prerequsities
- I'm on the latest version of the plugin
- I've installed the required dependencies
- I've run
:h gitlab.nvim.troubleshootingand followed the steps there
Setup Configuration and Environment
NVIM v0.12.4
Build type: Release
LuaJIT 2.1.1784580905
Vim versions: 8.1, 8.2, 9.0, 9.1, 9.2
system vimrc file: "$VIM/sysinit.vim"
fall-back for $VIM: "/usr/local/Cellar/neovim/0.12.4/share/nvim"
Bug Description
Currently, gitlab.nvim passes its configuration JSON (which contains the auth_token) directly
to the Go server binary via a command-line argument when calling vim.system().
Because command-line arguments are globally visible on UNIX systems via ps or pgrep, any user
on the machine can easily read the GitLab API token just by listing running processes.
Additionally, if Neovim is closed forcefully or quickly (e.g. via scripts or aliases), the Go
server processes aren't killed and become orphaned zombies running in the background. Because
they pile up, it becomes very easy to accidentally spot the leaked token in pgrep -fl nvim outputs.
Reproduction Steps
- Check out the feature branch
- Open Neovim
- ...
Screenshots
➜ pgrep -fl nvim
2080 /Users/xxxxxxx/.local/share/nvim/gitlab.nvim/bin/server {"gitlab_url":"https://xxxxxxxxxxxxxxx.com","connection_settings":{"insecure":false,"proxy":"","remote":"origin"},"debug":{"response":false,"request":false,"gitlab_request":false,"gitlab_response":false},"port":54232,"chosen_mr_iid":0,"log_path":"/Users/xxxxxxx/.cache/nvim/gitlab.nvim.log","auth_token":"xxxxxxxxxxxxxxxxx"}
21519 nvim . .
21544 nvim --embed . .
66859 /Users/xxxxxxx/.local/share/nvim/gitlab.nvim/bin/server {"chosen_mr_iid":4143,"log_path":"/Users/xxxxxxx/.cache/nvim/gitlab.nvim.log","auth_token":"xxxxxxxxxxxxxxxxx","gitlab_url":"https://xxxxxxxxxxxxxxx.com","debug":{"request":false,"gitlab_request":false,"gitlab_response":false,"response":false},"connection_settings":{"proxy":"","remote":"origin","insecure":false},"port":51887}
83060 /Users/xxxxxxx/.local/share/nvim/gitlab.nvim/bin/server {"debug":{"gitlab_request":false,"gitlab_response":false,"response":false,"request":false},"connection_settings":{"remote":"origin","proxy":"","insecure":false},"port":0,"chosen_mr_iid":0,"log_path":"/Users/xxxxxxx/.cache/nvim/gitlab.nvim.log","auth_token":"xxxxxxxxxxxxxxxxx","gitlab_url":"https://xxxxxxxxxxxxxxx.com"}
84503 /Users/xxxxxxx/.local/share/nvim/gitlab.nvim/bin/server {"debug":{"gitlab_request":false,"gitlab_response":false,"response":false,"request":false},"connection_settings":{"remote":"origin","proxy":"","insecure":false},"port":0,"chosen_mr_iid":0,"log_path":"/Users/xxxxxxx/.cache/nvim/gitlab.nvim.log","auth_token":"xxxxxxxxxxxxxxxxx","gitlab_url":"https://xxxxxxxxxxxxxxx.com"}
91585 /Users/xxxxxxx/.local/share/nvim/gitlab.nvim/bin/server {"log_path":"/Users/xxxxxxx/.cache/nvim/gitlab.nvim.log","port":0,"gitlab_url":"https://xxxxxxxxxxxxxxx.com","debug":{"request":false,"gitlab_request":false,"gitlab_response":false,"response":false},"connection_settings":{"insecure":false,"proxy":"","remote":"origin"},"auth_token":"xxxxxxxxxxxxxxxxx","chosen_mr_iid":0}
95389 /Users/xxxxxxx/.local/share/nvim/gitlab.nvim/bin/server {"chosen_mr_iid":0,"log_path":"/Users/xxxxxxx/.cache/nvim/gitlab.nvim.log","auth_token":"xxxxxxxxxxxxxxxxx","debug":{"gitlab_response":false,"response":false,"request":false,"gitlab_request":false},"gitlab_url":"https://xxxxxxxxxxxxxxx.com","connection_settings":{"proxy":"","insecure":false,"remote":"origin"},"port":0}
97335 /Users/xxxxxxx/.local/share/nvim/gitlab.nvim/bin/server {"debug":{"response":false,"request":false,"gitlab_request":false,"gitlab_response":false},"chosen_mr_iid":0,"log_path":"/Users/xxxxxxx/.cache/nvim/gitlab.nvim.log","auth_token":"xxxxxxxxxxxxxxxxx","gitlab_url":"https://xxxxxxxxxxxxxxx.com","connection_settings":{"insecure":false,"remote":"origin","proxy":""},"port":0}
Suggested Fix
The configuration JSON (or at least the auth_token) should be passed to the Go server via stdin
or as an environment variable, rather than as a command-line argument. Additionally, it would
be great if the plugin ensured the server process is killed properly upon VimLeavePre.
- 主要言語
- Lua
- スター
- 401
- フォーク
- 64
- 平均マージ
- 7時間 17分
- マージ済み PR(30日)
- 4
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
harrisoncramer/gitlab.nvim のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
harrisoncramer/gitlab.nvim#585 · コメント 1 件 ·
-
feature request
難易度 4/5 3〜5日 初心者へのやさしさ 35/100
harrisoncramer/gitlab.nvim#516 · コメント 1 件 ·
-
Oauth Login the plugin再び着手できるかも @vamshi567bh が 254 日前に担当しましたが、オープン中のプルリクエストはありません。 オープンfeature request
harrisoncramer/gitlab.nvim#515 · コメント 2 件 · 担当者 1 名 ·
-
toggle_discussions() doesn't open new window - draft_notes error 404対応中かも このイシューにリンクされたプルリクエストがオープン中、またはマージ済みです。 オープン
難易度 4/5 3〜5日 初心者へのやさしさ 25/100
harrisoncramer/gitlab.nvim#507 · コメント 1 件 ·
-
feature request
難易度 3/5 1〜2日 初心者へのやさしさ 56/100
harrisoncramer/gitlab.nvim#505 · コメント 6 件 ·
harrisoncramer/gitlab.nvim の issue をすべて見る
似ている issue
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
jellyfin/jellyfin-mpv-shim#800 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 64/100
-
agent-research-finding bug
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
jordansmall/nixvim-config#99 ·
メンテナーはふだん 1 日以内に返信
-
enhancement
難易度 2/5 1〜3時間 初心者へのやさしさ 67/100
-
cl: has_flags() mistakes warning C5072 for an unsupported flag対応中かも このイシューにリンクされたプルリクエストがオープン中、またはマージ済みです。 オープンbug
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
xmake-io/xmake#7822 · コメント 3 件 ·
メンテナーはふだん 2 日以内に返信