Entrypoint acts as root on DATA_DIR before checking it: creates outside /data, accepts paths outside /data #80

Open
opened 2026-09-29 12:39:19 +02:00 by clawbot · 0 comments
Collaborator

Found by the release review of main on #74 (#74 (comment)). It blocks the deploy of main onto prod.

bin/entrypoint.sh runs as root before the backend starts.

  1. It runs mkdir -p "$DATA_DIR" before checking the path for symbolic links, so a start that is then refused has already created directories outside the data directory: with DATA_DIR=/data/x/reports and /data/x a link to /etc, root creates /etc/reports; reports or /data/../new create /reports or /new; a dangling link at /data/reports stops the start with a mkdir error that does not name DATA_DIR.
  2. It accepts a DATA_DIR outside /data and gives that whole tree to the netwatch user: DATA_DIR=/etc leaves /etc/passwd and /etc/shadow owned by netwatch.

Definition of done

  • Before anything is created or any owner or mode changed, the entrypoint checks that DATA_DIR is /data or an absolute path below it, with no . or .. part, and that no existing part of the path, /data included, is a symbolic link; anything else stops the start with a message naming DATA_DIR. Only then does it create what is missing and set owner and mode.
  • Each case above stops the start naming DATA_DIR, with nothing created outside /data and no owner or mode changed; an empty root-owned host directory and one holding another uid's files still turn healthy with the backend running as netwatch.
  • The README section "Running under upaas" says which DATA_DIR values are accepted.
  • Root make check and script/cibuild pass; TODO.md updated in the same commit; commit title ends (closes #N).

Model: opus-5-5

Found by the release review of `main` on https://git.eeqj.de/sneak/netwatch/pulls/74 (https://git.eeqj.de/sneak/netwatch/pulls/74#issuecomment-107016). It blocks the deploy of `main` onto `prod`. `bin/entrypoint.sh` runs as root before the backend starts. 1. It runs `mkdir -p "$DATA_DIR"` before checking the path for symbolic links, so a start that is then refused has already created directories outside the data directory: with `DATA_DIR=/data/x/reports` and `/data/x` a link to `/etc`, root creates `/etc/reports`; `reports` or `/data/../new` create `/reports` or `/new`; a dangling link at `/data/reports` stops the start with a `mkdir` error that does not name `DATA_DIR`. 2. It accepts a `DATA_DIR` outside `/data` and gives that whole tree to the `netwatch` user: `DATA_DIR=/etc` leaves `/etc/passwd` and `/etc/shadow` owned by `netwatch`. ## Definition of done - Before anything is created or any owner or mode changed, the entrypoint checks that `DATA_DIR` is `/data` or an absolute path below it, with no `.` or `..` part, and that no existing part of the path, `/data` included, is a symbolic link; anything else stops the start with a message naming `DATA_DIR`. Only then does it create what is missing and set owner and mode. - Each case above stops the start naming `DATA_DIR`, with nothing created outside `/data` and no owner or mode changed; an empty root-owned host directory and one holding another uid's files still turn healthy with the backend running as `netwatch`. - The README section "Running under upaas" says which `DATA_DIR` values are accepted. - Root `make check` and `script/cibuild` pass; `TODO.md` updated in the same commit; commit title ends ` (closes #N)`. Model: opus-5-5
clawbot self-assigned this 2026-09-29 12:39:19 +02:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/netwatch#80