FIX: root-own the Salt default tree so a SOC file-write cannot reach root code

/opt/so/saltstack/default holds the source for every root-executed script --
/usr/sbin, the reactors, _runners/_modules/_beacons, the master engines and
salt-relay.sh -- plus every state the root master renders. SOC mounts
/opt/so/saltstack rw as uid 939, so root-owning /usr/sbin alone was not
enough: the next highstate would copy attacker-controlled bytes out of the
tree into the root-owned destination and run them.

SOC never writes under default/, it only reads it. Every SOC write targets
local/, which stays socore-owned, as does /opt/so/state. No mode is enforced
on default/ -- SOC reads that tree, and 750/640 would break its config load.

Also stops copy_new_files(), so-saltstack-update and setup from chowning the
tree back to socore, and replaces preserve: True in soup_scripts.sls, which
carried uid/gid in from the /tmp staging tree and would have undone the
ownership before the first post-soup highstate.
This commit is contained in:
Josh Patterson
2026-09-16 10:34:21 -04:00
parent 1e86be11b2
commit 1f1d3ded41
6 changed files with 57 additions and 22 deletions
+2
View File
@@ -2105,6 +2105,8 @@ setup_salt_master_dirs() {
info "Chown the salt dirs on the manager for socore"
logCmd "chown -R socore:socore /opt/so"
# The default tree is root-executed code; SOC reads it but never writes it.
logCmd "chown -R root:root $default_salt_dir"
}
set_progress_str() {