Found by the release review of main on #74 (#74 (comment)). It blocks the deploy of main onto prod.
bin/entrypoint.sh runs as root before the backend starts.
It runs mkdir -p "$DATA_DIR" before checking the path for symbolic links, so a start that is then refused has already created directories outside the data directory: with DATA_DIR=/data/x/reports and /data/x a link to /etc, root creates /etc/reports; reports or /data/../new create /reports or /new; a dangling link at /data/reports stops the start with a mkdir error that does not name DATA_DIR.
It accepts a DATA_DIR outside /data and gives that whole tree to the netwatch user: DATA_DIR=/etc leaves /etc/passwd and /etc/shadow owned by netwatch.
Definition of done
Before anything is created or any owner or mode changed, the entrypoint checks that DATA_DIR is /data or an absolute path below it, with no . or .. part, and that no existing part of the path, /data included, is a symbolic link; anything else stops the start with a message naming DATA_DIR. Only then does it create what is missing and set owner and mode.
Each case above stops the start naming DATA_DIR, with nothing created outside /data and no owner or mode changed; an empty root-owned host directory and one holding another uid's files still turn healthy with the backend running as netwatch.
The README section "Running under upaas" says which DATA_DIR values are accepted.
Root make check and script/cibuild pass; TODO.md updated in the same commit; commit title ends (closes #N).
Model: opus-5-5
Found by the release review of `main` on https://git.eeqj.de/sneak/netwatch/pulls/74 (https://git.eeqj.de/sneak/netwatch/pulls/74#issuecomment-107016). It blocks the deploy of `main` onto `prod`.
`bin/entrypoint.sh` runs as root before the backend starts.
1. It runs `mkdir -p "$DATA_DIR"` before checking the path for symbolic links, so a start that is then refused has already created directories outside the data directory: with `DATA_DIR=/data/x/reports` and `/data/x` a link to `/etc`, root creates `/etc/reports`; `reports` or `/data/../new` create `/reports` or `/new`; a dangling link at `/data/reports` stops the start with a `mkdir` error that does not name `DATA_DIR`.
2. It accepts a `DATA_DIR` outside `/data` and gives that whole tree to the `netwatch` user: `DATA_DIR=/etc` leaves `/etc/passwd` and `/etc/shadow` owned by `netwatch`.
## Definition of done
- Before anything is created or any owner or mode changed, the entrypoint checks that `DATA_DIR` is `/data` or an absolute path below it, with no `.` or `..` part, and that no existing part of the path, `/data` included, is a symbolic link; anything else stops the start with a message naming `DATA_DIR`. Only then does it create what is missing and set owner and mode.
- Each case above stops the start naming `DATA_DIR`, with nothing created outside `/data` and no owner or mode changed; an empty root-owned host directory and one holding another uid's files still turn healthy with the backend running as `netwatch`.
- The README section "Running under upaas" says which `DATA_DIR` values are accepted.
- Root `make check` and `script/cibuild` pass; `TODO.md` updated in the same commit; commit title ends ` (closes #N)`.
Model: opus-5-5
clawbot
self-assigned this 2026-09-29 12:39:19 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Found by the release review of
mainon #74 (#74 (comment)). It blocks the deploy ofmainontoprod.bin/entrypoint.shruns as root before the backend starts.mkdir -p "$DATA_DIR"before checking the path for symbolic links, so a start that is then refused has already created directories outside the data directory: withDATA_DIR=/data/x/reportsand/data/xa link to/etc, root creates/etc/reports;reportsor/data/../newcreate/reportsor/new; a dangling link at/data/reportsstops the start with amkdirerror that does not nameDATA_DIR.DATA_DIRoutside/dataand gives that whole tree to thenetwatchuser:DATA_DIR=/etcleaves/etc/passwdand/etc/shadowowned bynetwatch.Definition of done
DATA_DIRis/dataor an absolute path below it, with no.or..part, and that no existing part of the path,/dataincluded, is a symbolic link; anything else stops the start with a message namingDATA_DIR. Only then does it create what is missing and set owner and mode.DATA_DIR, with nothing created outside/dataand no owner or mode changed; an empty root-owned host directory and one holding another uid's files still turn healthy with the backend running asnetwatch.DATA_DIRvalues are accepted.make checkandscript/cibuildpass;TODO.mdupdated in the same commit; commit title ends(closes #N).Model: opus-5-5