From 3fc515f48d63b3b3d051ed9185452561b44a847f Mon Sep 17 00:00:00 2001 From: HanifKoh <76276251+HanifKoh@users.noreply.github.com> Date: Thu, 8 Oct 2026 13:52:09 +0800 Subject: [PATCH] Prompt for Permission When a Plugin Calls os.exec (#16254) * Prompt for Permission When a Plugin Calls os.exec * Add a ProcessReplace Audit Category for os.exec --- src/slic3r/plugin/PluginAuditManager.cpp | 7 +++++++ src/slic3r/plugin/PluginAuditManager.hpp | 1 + 2 files changed, 8 insertions(+) diff --git a/src/slic3r/plugin/PluginAuditManager.cpp b/src/slic3r/plugin/PluginAuditManager.cpp index 1fe8837c5c..f3bd6c1636 100644 --- a/src/slic3r/plugin/PluginAuditManager.cpp +++ b/src/slic3r/plugin/PluginAuditManager.cpp @@ -115,6 +115,9 @@ static const std::unordered_map audit_event_cat {"subprocess.Popen", AuditEventCategory::ProcessCreate}, {"_winapi.CreateProcess", AuditEventCategory::ProcessCreate}, {"_posixsubprocess.fork_exec", AuditEventCategory::ProcessCreate}, + + // processreplace: exec* replaces the current process image rather than spawning a child + {"os.exec", AuditEventCategory::ProcessReplace}, }; // Returns the category event_name belongs to, or AuditEventCategory::None when it isn't audited. @@ -708,6 +711,7 @@ static const std::unordered_map> audit_targ {"pty.spawn", {0}}, {"_winapi.CreateProcess", {1, 0}}, {"_posixsubprocess.fork_exec", {0}}, + {"os.exec", {0}}, }; AuditEventCategory open_category(PyObject* args) @@ -761,6 +765,7 @@ std::vector* permission_list_for(AuditEventCategory category, Plugi case AuditEventCategory::Http: return &permissions.network_http; case AuditEventCategory::Socket: return &permissions.network_socket; case AuditEventCategory::ProcessCreate: return &permissions.process; + case AuditEventCategory::ProcessReplace: return &permissions.process; default: return nullptr; } } @@ -832,6 +837,8 @@ wxString audit_message(AuditEventCategory category, const wxString& plugin_name, return wxString::Format(_L("Plugin \"%s\" is requesting to open a network connection to:\n%s"), plugin_name, target_list); case AuditEventCategory::ProcessCreate: return wxString::Format(_L("Plugin \"%s\" is requesting to run the following command(s):\n%s"), plugin_name, target_list); + case AuditEventCategory::ProcessReplace: + return wxString::Format(_L("Plugin \"%s\" is requesting to replace the running application with:\n%s"), plugin_name, target_list); default: return wxString::Format(_L("Plugin \"%s\" is requesting permission for the Python audit event \"%s\"."), plugin_name, event_name); } diff --git a/src/slic3r/plugin/PluginAuditManager.hpp b/src/slic3r/plugin/PluginAuditManager.hpp index 76ac5cdd18..49866d2fa9 100644 --- a/src/slic3r/plugin/PluginAuditManager.hpp +++ b/src/slic3r/plugin/PluginAuditManager.hpp @@ -45,6 +45,7 @@ enum class AuditEventCategory { Http, Socket, ProcessCreate, + ProcessReplace, Threading, };