mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-09-20 06:40:44 +02:00
FIX: root-own the Salt default tree so a SOC file-write cannot reach root code
/opt/so/saltstack/default holds the source for every root-executed script -- /usr/sbin, the reactors, _runners/_modules/_beacons, the master engines and salt-relay.sh -- plus every state the root master renders. SOC mounts /opt/so/saltstack rw as uid 939, so root-owning /usr/sbin alone was not enough: the next highstate would copy attacker-controlled bytes out of the tree into the root-owned destination and run them. SOC never writes under default/, it only reads it. Every SOC write targets local/, which stays socore-owned, as does /opt/so/state. No mode is enforced on default/ -- SOC reads that tree, and 750/640 would break its config load. Also stops copy_new_files(), so-saltstack-update and setup from chowning the tree back to socore, and replaces preserve: True in soup_scripts.sls, which carried uid/gid in from the /tmp staging tree and would have undone the ownership before the first post-soup highstate.
This commit is contained in:
@@ -240,7 +240,8 @@ copy_new_files() {
|
||||
cd $UPDATE_DIR
|
||||
rsync -a salt $DEFAULT_SALT_DIR/ --delete "${EXCLUDE_ARGS[@]}"
|
||||
rsync -a pillar $DEFAULT_SALT_DIR/ --delete "${EXCLUDE_ARGS[@]}"
|
||||
chown -R socore:socore $DEFAULT_SALT_DIR/
|
||||
# Root-executed code; SOC only needs to read it. Local dirs stay socore-owned.
|
||||
chown -R root:root $DEFAULT_SALT_DIR/
|
||||
cd /tmp
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user