Entrypoint acts as root on nothing outside /data (closes #80)
check / check (push) Successful in 1m58s
check / check (push) Successful in 1m58s
`bin/entrypoint.sh` now runs `netwatch-server prepare-data-dir`, which refuses a `DATA_DIR` that is not `/data` or a path below it written in full, then creates `DATA_DIR`, gives `/data` and everything in it to `netwatch`, and sets mode 750 on `/data` and `DATA_DIR`. Every step goes through a Go `os.Root` opened on `/data`, and the modes are set on the opened directories rather than by name, so neither a symbolic link already there nor one a host process swaps in while the container starts can make root create or change anything outside `/data`. The README says which `DATA_DIR` values are accepted. Model: opus-5-5
This commit was merged in pull request #81.
This commit is contained in:
@@ -23,6 +23,16 @@ latest run passes.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-03: root no longer acts outside `/data` when it prepares `DATA_DIR`
|
||||
(issue #80): `bin/entrypoint.sh` runs `netwatch-server prepare-data-dir`,
|
||||
which refuses a `DATA_DIR` that is not `/data` or a path below it written in
|
||||
full, then creates `DATA_DIR`, gives `/data` and everything in it to
|
||||
`netwatch` and sets the modes, all through a Go `os.Root` opened on `/data`.
|
||||
That refuses any path leading out of `/data`, so neither a symbolic link
|
||||
already there nor one a host process swaps in during the start can make root
|
||||
create or change anything elsewhere, and `DATA_DIR=/etc` no longer gives
|
||||
`/etc` to `netwatch`. The `README.md` section "Running under upaas" says which
|
||||
values are accepted
|
||||
- 2026-10-03: `DATA_DIR_MAX_BYTES` is now how much of the report files is kept
|
||||
(issue #54): when a report would take them past it, the oldest report files
|
||||
are deleted to make room, each deletion logged, and at start files already
|
||||
|
||||
Reference in New Issue
Block a user