Commit Graph
18772 Commits
Author SHA1 Message Date
Mike Reeves 47fe0758d0 Merge pull request #16255 from Security-Onion-Solutions/mreeves/fix-so-user-stdin-drain
Fix user creation failing with a valid password
2026-09-18 17:12:09 -04:00
Mike Reeves b71fd93f9d Stop docker exec from consuming so-user's piped password
Adding a user failed with "Password does not meet the minimum requirements"
for passwords that were well over the eight character minimum.

so-user reads the password from stdin in updatePassword, but verifyEnvironment
runs first and calls kratosCurl, which ran docker exec with -i. That attaches
stdin and drains the pipe the caller sent the password on, so the later
read -rs saw EOF, password was empty, and expr length "" tripped the minimum
length check.

No kratosCurl or hydraCurl call sends a body on stdin; every one passes it as
a -d argument, so -i was never needed. Dropping it leaves the admin API
responses unchanged.

so-client had the same wrapper for the Hydra admin API. It does not currently
read stdin, but the flag drains its caller's pipe just the same, so it is
dropped there too.
2026-09-18 17:04:17 -04:00
Mike Reeves d9eff9aa9e Merge pull request #16253 from Security-Onion-Solutions/mreeves/fix-docker-networks-setting-conflict
Fix config tree error from the docker.networks setting
2026-09-18 15:41:25 -04:00
Mike Reeves d8884dbd99 Document sobridge alongside the soauth network settings
sobridge carries most containers but held no annotation, so it was absent from
the config tree entirely. Its pillar entry is an empty map, so annotating it
adds a setting with no children for docker.networks.soauth.range to collide
with, and the tree still builds.

docker.map.jinja fills in sobridge's range and gateway at render time from
docker.range and docker.gateway, and resets the entry when it is not a mapping,
so nothing writes keys underneath it.

The sentence about sobridge is dropped from the soauth range description now
that sobridge documents itself.
2026-09-18 14:37:11 -04:00
Mike Reeves 6c0d4c15e8 Annotate the soauth network leaves instead of the networks map
SOC reported "Malformed config setting (docker.networks.soauth.range): Setting
name 'networks' conflicts with another similarly named setting" and refused to
render the config tree.

soc_docker.yaml annotated docker.networks itself, and every key in that block
was a scalar, so FlattenAnnotations registered docker.networks as a setting.
defaults.yaml holds a nested map there, so FlattenPillar separately registered
docker.networks.soauth.range, .gateway and .manager_only, and
HydrateAnnotations unions the two sets. The config tree gives each id segment
either a value or children, never both, so addToNode pushed docker.networks as
a childless leaf and then threw when docker.networks.soauth.range tried to
descend through it.

The annotations move down to the three leaves that actually carry values, so
docker.networks is a plain branch. This matches docker.containers, which is
nested the same way and has never carried annotations of its own.

docker.ulimits and the per-container networks list are unaffected: their pillar
values are lists rather than maps, so they stay single settings.
2026-09-18 13:42:41 -04:00
Jason Ertel 2e2f62f265 Merge pull request #16252 from Security-Onion-Solutions/jertel/wip
store in db
2026-09-18 12:47:32 -04:00
Jason Ertel b7a11a525c store in db 2026-09-18 12:41:35 -04:00
Mike Reeves 8eef95ea3e Merge pull request #16221 from Security-Onion-Solutions/mreeves/kratos-soauth-network
Isolate the Kratos admin API on a dedicated soauth docker network
2026-09-18 10:24:00 -04:00
Mike Reeves 65e261475d Mention Hydra in the soauth network description
The description was written alongside the Kratos change and named only the
Kratos admin API, but so-hydra now sits on soauth too.

The trailing note about rebuilding the firewall is dropped, since the setting
is readonly and cannot be changed from SOC in the first place.
2026-09-18 10:17:20 -04:00
Mike Reeves bbc28c88b7 Isolate the Hydra admin API on the soauth docker network
The Hydra admin API creates OAuth clients and introspects tokens without
authentication, relying on network isolation the same way Kratos does, but
so-hydra published 0.0.0.0:4445:4445 and sat on sobridge. With userland-proxy
left at its default of true, Docker ran a proxy listener on the host, so any
container reached the admin API through the manager IP or the bridge gateway
regardless of its docker network.

so-hydra now sits alone on soauth and no longer publishes 4445. 4444 is still
published, so the nginx proxy for /oauth2/token and the well-known endpoints is
unchanged. so-soc is already dual homed from the Kratos change and reaches the
admin API over soauth, so only its hostUrl moves. wait_for_hydra polls the
container address instead of the host port.

so-client reaches the admin API through docker exec, mirroring so-user. Exit
codes still propagate, so the --fail-with-body error handling is unchanged.

so-hydra is removed in up_to_3.4.0 alongside so-kratos and so-soc so the
highstate recreates it with the correct network membership. The auth network
range is already handled by set_soauth_range.
2026-09-17 16:58:49 -04:00
Jason Ertel edaacf79a7 Merge pull request #16251 from Security-Onion-Solutions/jertel/wip
notification annotations
2026-09-17 15:37:04 -04:00
Jason Ertel ecc643cd33 fix typo 2026-09-17 15:34:29 -04:00
Jason Ertel 08aaf7948e Merge branch '3/dev' into jertel/wip 2026-09-17 15:32:35 -04:00
Jason Ertel bb57545d08 new annotations for notifications 2026-09-17 15:32:21 -04:00
Josh Brower 0f7adbbecc Merge pull request #16247 from Security-Onion-Solutions/esql-fixes
Refactor for ESQL
2026-09-17 09:56:19 -04:00
Josh Patterson aeb4fe8f50 Merge pull request #16250 from Security-Onion-Solutions/fix/root-own-sbin-and-salt-tree
FIX: root-own /usr/sbin management scripts and the Salt default tree
2026-09-17 09:44:47 -04:00
defensivedepth f3aa39c5a4 Tweak name 2026-09-17 09:43:44 -04:00
Doug Burks 24077ba974 Merge pull request #16249 from Security-Onion-Solutions/dougburks/fix-eval-suricata-file-drops
FIX: suricata.fileinfo maps boolean gaps into long file.bytes.missing
2026-09-17 09:42:27 -04:00
Doug Burks b3567405f9 FIX: suricata.fileinfo maps boolean gaps into long file.bytes.missing 2026-09-17 07:57:44 -04:00
defensivedepth 1fc5bb7afa Refactor for ESQL 2026-09-17 07:56:42 -04:00
Josh Patterson 1f1d3ded41 FIX: root-own the Salt default tree so a SOC file-write cannot reach root code
/opt/so/saltstack/default holds the source for every root-executed script --
/usr/sbin, the reactors, _runners/_modules/_beacons, the master engines and
salt-relay.sh -- plus every state the root master renders. SOC mounts
/opt/so/saltstack rw as uid 939, so root-owning /usr/sbin alone was not
enough: the next highstate would copy attacker-controlled bytes out of the
tree into the root-owned destination and run them.

SOC never writes under default/, it only reads it. Every SOC write targets
local/, which stays socore-owned, as does /opt/so/state. No mode is enforced
on default/ -- SOC reads that tree, and 750/640 would break its config load.

Also stops copy_new_files(), so-saltstack-update and setup from chowning the
tree back to socore, and replaces preserve: True in soup_scripts.sls, which
carried uid/gid in from the /tmp staging tree and would have undone the
ownership before the first post-soup highstate.
2026-09-16 10:34:21 -04:00
Josh Patterson 1e86be11b2 FIX: install /usr/sbin management scripts as root
Salt installed the so-* scripts into /usr/sbin owned by unprivileged service
UIDs (939/socore, plus 930-960 per service) at mode 755, while root executes
those same files from cron, systemd and state cmd.run. Any file-write
primitive as one of those UIDs was therefore root.

Two mechanisms behind this are not visible in the diff:

file.recurse also manages the destination directory, so /usr/sbin itself was
chowned to whichever service UID ran last. A directory's owner may always
chmod it, so that UID could replace even the scripts already declared
user: root -- so-config-backup, so-suricata-eve-clean, so-nsm-mount-nvme.
usr_sbin_perms now pins the directory to root:root 555, the mode the
filesystem RPM ships.

Omitting user:/group: is a no-op on files that already exist, because
check_perms only chowns when a user is named. Explicit user: root is what
lets upgraded grids self-heal on the next highstate, and what makes a
revert chown back rather than silently do nothing.
2026-09-16 10:34:20 -04:00
Josh Patterson f4518e2620 Merge pull request #16246 from Security-Onion-Solutions/fix/so-minion-install-vars
Fix/so minion install vars
2026-09-16 09:06:01 -04:00
Josh Patterson a9f7ffc3fe FIX: validate MAINIP without so-common during setup
setup runs so-minion -o=setup before /usr/sbin/so-common is installed, so
valid_ip4 was undefined, every MAINIP was rejected, and no minion pillar
was written. Pillar compile then failed for the new manager and setup gave
up waiting for the salt master. Use an inline IPv4 regex instead.
2026-09-15 13:10:33 -04:00
Josh Patterson b018277d68 FIX: prevent joining minion from executing code as root on the manager
so-minion exported every line of the minion-controlled /opt/so/install.txt
into its root shell and wrote the values unescaped into a Jinja-rendered
pillar, allowing a rogue node to redefine PILLARFILE or run code on the
master at the next pillar compile. pcapspace also fed minion-returned
disk.usage output into bash arithmetic, which evaluates array subscripts.

- Parse install.txt against an allowlist of known keys; never export
- Validate MINION_ID before building pillar paths; make them readonly
- Validate node type, IP, interface, hostname, heap and core values
  before any pillar is written; strip braces and control chars from
  the free-text node description
- Require a numeric disk size before pcapspace arithmetic
- Refuse manager node types on add/addVM so a remote node cannot
  rewrite the CA pillar; only setup may create them
2026-09-15 09:58:38 -04:00
Josh Patterson 3be603e203 Merge pull request #16243 from Security-Onion-Solutions/fix/so-sensor-clean
FIX: prevent so-sensor-clean runaway loop and concurrent instances
2026-09-14 14:53:12 -04:00
Josh Patterson 84cd966736 FIX: prevent so-sensor-clean runaway loop and concurrent instances
The cleanup loop had no progress check or pass limit, so once /nsm was over
threshold with nothing left to reclaim it spun at full speed, writing 1.1 GB /
12.5M lines to sensor_clean.log in five hours. Stop when a pass removes
nothing, when a pass frees no space, or at MAX_PASSES, and drop the per-pass
"no old files" logging in favor of one actionable line.

Replace the pgrep guard with flock -n. A find|while read subshell inherits the
parent's argv, so pgrep -cf counted one instance as hundreds; it was also
check-then-act, which let cron stack up overlapping runs.

Paths now derive from SENSOR_DIR with env-overridable LOG/LOCK so the
over-threshold path can be tested against a scratch filesystem.
2026-09-14 12:14:13 -04:00
Josh Patterson fee401a912 Merge pull request #16242 from Security-Onion-Solutions/zeekrestart
stop Zeek gracefully preventing post-terminate logs
2026-09-14 08:54:08 -04:00
Mike Reeves 496b61966f Merge pull request #16240 from Security-Onion-Solutions/clear-hotfix-3dev
Remove outdated HOTFIX version number
2026-09-11 16:48:01 -04:00
Mike Reeves 52037314be Remove outdated HOTFIX version number 2026-09-11 16:47:13 -04:00
Mike Reeves 9c12c10f96 Merge pull request #16239 from Security-Onion-Solutions/hotfix/3.3.0
Hotfix/3.3.0
2026-09-11 16:46:56 -04:00
Mike Reeves 9fc9be2cc9 Merge pull request #16237 from Security-Onion-Solutions/hf33
3.3.0 hotfix
2026-09-11 16:20:23 -04:00
Mike Reeves 7245843a3c 3.3.0 hotfix 2026-09-11 16:17:34 -04:00
Mike Reeves a1d17417ea 3.3.0 hotfix 2026-09-11 16:16:01 -04:00
Mike Reeves bee03d5bae 3.3.0 hotfix 2026-09-11 16:13:09 -04:00
Josh Patterson 56e3e44d04 Merge remote-tracking branch 'origin/3/dev' into zeekrestart 2026-09-11 15:06:28 -04:00
coreyogburn 32d1274b80 Merge pull request #16236 from Security-Onion-Solutions/cogburn/move-fields
filterEventFields
2026-09-11 11:23:03 -06:00
Corey Ogburn 1624e8c094 filterEventFields
Previously hard coded array of fields is now a config option with the hard coded value as the default value.
2026-09-11 10:54:20 -06:00
Mike Reeves 3f3f091a7f Merge pull request #16235 from Security-Onion-Solutions/soup-x86-64-v3-check
Add x86-64-v3 CPU pre-flight check to soup
2026-09-11 11:00:34 -04:00
Mike Reeves cb48909578 Add x86-64-v3 CPU pre-flight check to soup
Upstream Elastic now ships binaries built for the x86-64-v3
micro-architecture level. This is not a Security Onion choice: nodes whose
CPUs predate x86-64-v3 can no longer run Elastic's own builds, so those
nodes break once they are upgraded.

Check for support before soup modifies anything, and require the operator
to type "override" to proceed when a node is unsupported or offline.

Runs after upgrade_check so a grid that is already current exits without
prompting. Targets only the roles that run a container built from the
so-elastic-agent image, using the role lists already maintained in
salt/reactor/pillar_push_map.yaml. Adds --skip-cpu-check to bypass the gate
for automation, and exit code 162 when the operator declines to override.
2026-09-11 10:51:25 -04:00
Mike Reeves 3057775770 Merge pull request #16234 from Security-Onion-Solutions/TOoSmOotH-patch-3
Update version number in HOTFIX file
2026-09-11 09:04:04 -04:00
Mike Reeves e4e8b90b9c Update version number in HOTFIX file 2026-09-11 09:03:24 -04:00
Mike Reeves 223ace6ff3 Merge pull request #16233 from Security-Onion-Solutions/TOoSmOotH-patch-2
Update HOTFIX version to 3.3.0-20260911
2026-09-11 08:57:31 -04:00
Mike Reeves 66e7863336 Update HOTFIX version to 3.3.0-20260911 2026-09-11 08:56:00 -04:00
Corey Ogburn 8f253d17a6 Default Memory to Disabled
Gives users a chance to reconfigure embed model before messages they send to the OnionAI get sent to SOAI by default.
2026-09-10 15:18:35 -06:00
Josh Patterson 9652a2053b Stop the Zeek container gracefully
zeekctl's post-terminate archives the final logs in the background and returns
immediately unless StopWait is set, so the container exits and takes the archiving
with it, stranding unarchived logs in /nsm/zeek/spool/tmp on every restart. Docker's
default 10s grace is also too tight for the entrypoint's SIGTERM trap; overrunning it
means SIGKILL and crash directories on the next start.

Both are needed. StopWait alone gives the stop more work to do inside the same 10s
window, which was measured ending in SIGKILL with logs stranded in the spool.

disabled.sls used docker rm -f, which never delivers SIGTERM, so stop the container
before removing it.

Reported in discussion #16174.
2026-09-10 13:20:20 -04:00
Jason Ertel 191ee159ef Merge pull request #16229 from Security-Onion-Solutions/jertel/wip
fix location typo
2026-09-10 07:36:32 -04:00
Jason Ertel a8bfe955a5 fix location typo 2026-09-10 07:27:25 -04:00
Jason Ertel bd354abe83 Merge pull request #16225 from Security-Onion-Solutions/jertel/wip
/login is showing an nginx failure
2026-09-09 16:54:44 -04:00
Jason Ertel 37782fb45c /login is showing an nginx failure 2026-09-09 16:44:27 -04:00