AI 编程 4.0 · 优秀 2026-08-28 · 文章

Omarchy: Any User Process Can Escalate to Root

DHH 的 Arch 发行版 Omarchy 曾把默认用户加进 docker 组,使桌面会话里几乎任何进程都能无密码无 sudo无提权提示地获得 root:daemon 以 root 运行并监听 /var/run/docker.sock,能与此 socket 通信即可让 root 进程挂载宿主任意路径真正的问题在 Linux 补充组被子进程继承顺着 systemd --user 走进程树,会话中几乎所有普通进程(浏览器编辑器npm 脚本,以及越来越常驻的 AI 编码 agent 与 harness)都带着 docker 组,任何一个普通应用被攻破都直接等于整机沦陷...

打开原文回到归档

Omarchy: Any User Process Can Escalate to Root

摘要中文导览(来自条目评分时的双语摘要,基于原文提炼):
  • DHH 的 Arch 发行版 Omarchy 曾把默认用户加进 docker 组,使桌面会话里几乎任何进程都能无密码、无 sudo、无提权提示地获得 root:daemon 以 root 运行并监听 /var/run/docker.sock,能与此 socket 通信即可让 root 进程挂载宿主任意路径。真正的问题在 Linux 补充组被子进程继承——顺着 systemd --user 走进程树,会话中几乎所有普通进程(浏览器、编辑器、npm 脚本,以及越来越常驻的 AI 编码 agent 与 harness)都带着 docker 组,任何一个普通应用被攻破都直接等于整机沦陷;这是 opt-out 的默认配置,不使用 Docker 的用户照样中招,且文档措辞读起来像已配置 rootless 模式。时间线:2025-06-01 引入、2026-08-24 从默认配置移除,影响 4.0.1 之前所有版本;作者建议换用无守护进程、以用户命名空间子进程运行的 Podman。

文章信息

原文摘录(开头)

A security issue in Omarchy’s default Docker configuration meant that essentially every program running in the user’s desktop session could escalate to root without a password, sudo, or a privilege prompt.

If you use Omarchy, the most important takeaway is simple: update to 4.0.1.

I reported this issue privately through the project’s responsible-disclosure process. The underlying configuration has since been patched, so I’m publishing the details now to explain what the issue is and let users know to update their systems.

Omarchy configured its default user as a member of the Linux docker group.

That allows users to run commands such as:


docker run ...

without typing sudo.

On arch the Docker daemon runs as root and listens on:


/var/run/docker.sock

Members of the docker group can communicate with that socket. Docker itself explicitly warns that the docker group grants root-level privileges to the user.

A process with access to the Docker socket can ask the root-owned Docker daemon to launch a container as root, mount arbitrary portions of the host filesystem into it, operate on those files as root, and run code as root.

Summary (EN)

Omarchy (DHH's Arch distribution) shipped its default user in the docker group, letting essentially any process in the desktop session escalate to root without password, sudo, or a prompt: the root daemon listening on /var/run/docker.sock can mount arbitrary host paths. Because Linux supplementary groups are inherited by child processes, nearly every ordinary process in the session — browsers, editors, npm scripts, and increasingly the resident AI coding agents and harnesses — carried the group, making any compromised app a full machine compromise. The opt-out default affected all versions before 4.0.1 (introduced 2025-06-01, removed 2026-08-24); the author recommends daemon-less Podman.

Obsidian 证据摘录

入选自 Obsidian《ClawFeed 24小时高价值一览 · 2026-08-31》第3篇:docker 组默认配置导致的无提示 root 提权。