Entrypoint acts as root on nothing outside /data (closes #80)
check / check (push) Successful in 1m58s
check / check (push) Successful in 1m58s
`bin/entrypoint.sh` now runs `netwatch-server prepare-data-dir`, which refuses a `DATA_DIR` that is not `/data` or a path below it written in full, then creates `DATA_DIR`, gives `/data` and everything in it to `netwatch`, and sets mode 750 on `/data` and `DATA_DIR`. Every step goes through a Go `os.Root` opened on `/data`, and the modes are set on the opened directories rather than by name, so neither a symbolic link already there nor one a host process swaps in while the container starts can make root create or change anything outside `/data`. The README says which `DATA_DIR` values are accepted. Model: opus-5-5
This commit was merged in pull request #81.
This commit is contained in:
@@ -4,6 +4,7 @@ package main
|
||||
import (
|
||||
"fmt"
|
||||
"os"
|
||||
"os/user"
|
||||
|
||||
"sneak.berlin/go/netwatch/internal/config"
|
||||
"sneak.berlin/go/netwatch/internal/globals"
|
||||
@@ -37,6 +38,26 @@ func main() {
|
||||
return
|
||||
}
|
||||
|
||||
// "netwatch-server prepare-data-dir DATA_DIR" gets DATA_DIR ready
|
||||
// for the netwatch user, or exits 1 with the error; see
|
||||
// reportbuf.PrepareDataDir. bin/entrypoint.sh runs it as root
|
||||
// before it starts this server as that user.
|
||||
if len(os.Args) == 3 && os.Args[1] == "prepare-data-dir" {
|
||||
netwatch, err := user.Lookup("netwatch")
|
||||
if err != nil {
|
||||
fmt.Fprintln(os.Stderr, err)
|
||||
os.Exit(1)
|
||||
}
|
||||
|
||||
err = reportbuf.PrepareDataDir("/data", os.Args[2], netwatch)
|
||||
if err != nil {
|
||||
fmt.Fprintf(os.Stderr, "DATA_DIR '%s': %v\n", os.Args[2], err)
|
||||
os.Exit(1)
|
||||
}
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
globals.Appname = Appname
|
||||
globals.Version = Version
|
||||
|
||||
|
||||
Reference in New Issue
Block a user