Skip to content

fix(security): bind the local Postgres port to loopback only - #423

Open
HusseinAdeiza wants to merge 1 commit into
genlayerlabs:v0.40-devfrom
HusseinAdeiza:fix/postgres-port-loopback-only
Open

HusseinAdeiza wants to merge 1 commit into
genlayerlabs:v0.40-devfrom
HusseinAdeiza:fix/postgres-port-loopback-only

Conversation

@HusseinAdeiza

@HusseinAdeiza HusseinAdeiza commented Sep 28, 2026 •

Copy link
Copy Markdown

Fixes #1603.

On v0.40-dev, docker-compose.yml:106 published Postgres as "${DBPORT:-5432}:5432" with no host IP, so Docker bound 0.0.0.0. .env.example ships DBUSER=postgres / DBPASSWORD=postgres as the defaults, so a stock genlayer init on a host with a public IP exposed a superuser Postgres on 5432, which is enough for RCE via CREATE FUNCTION + libc.so.6.

The localnet only reaches Postgres over the compose network as postgres:5432 (database-migration's DB_URL), so the published port isn't needed for the stack to work. Binding to 127.0.0.1 keeps psql and other host-side tooling working while removing the public exposure.

Verified with docker compose config, before and after:

# before
ports:
  - mode: ingress
    default: null
    target: 5432
    published: "5432"

# after
ports:
  - mode: ingress
    host_ip: 127.0.0.1
    target: 5432
    published: "5432"

tests/docker-compose-ports.test.ts guards the binding so it can't silently regress. Both tests fail against the pre-fix compose file:

× publishes postgres on loopback only
  → expected [ '${DBPORT:-5432}:5432' ] to deeply equal [ '127.0.0.1:${DBPORT:-5432}:5432' ]
× binds every published postgres port to an explicit host address
  → expected '${DBPORT:-5432}:5432' to match /^127\.0\.0\.1:/

Full suite: 814 passed. The one failing suite (keychainManager.test.ts) is a missing libsecret-1.so.0 system library on this machine, which CI installs explicitly; it is unrelated to this change.

The same line exists in genlayer-studio at v0.123-dev:278, already covered by #1715. This PR is scoped to the CLI, which is where this report is filed and where no fix exists yet.

@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 33a2e9eb-42bc-423a-bb81-963b07ccafc0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

docker-compose.yml published Postgres as ${DBPORT:-5432}:5432 with no
host IP, so Docker bound 0.0.0.0 and the container was reachable from any
interface. .env.example ships DBUSER=postgres / DBPASSWORD=postgres as the
defaults, so a stock `genlayer init` on a host with a public IP exposed a
superuser Postgres on 5432, which is enough for RCE via CREATE FUNCTION
plus libc.so.6.

The localnet only ever reaches Postgres over the compose network as
postgres:5432, so the published port is not needed for the stack to work.
Binding it to 127.0.0.1 keeps psql and other host-side tooling working
while removing the public exposure. Fixes #1603.
@HusseinAdeiza
HusseinAdeiza force-pushed the fix/postgres-port-loopback-only branch from 8cd0cb6 to acd7be3 Compare September 28, 2026 20:21

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant