mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-10-07 23:14:48 +02:00
Root ran `pip install --find-links` against directories under /opt/so/conf, which
is 939:939 mode 770. Hardening those directories would not have helped: renaming an
entry requires write permission on the parent, not on the entry, so uid 939 could
move the wheel tree aside and substitute its own between the file.recurse that
populates it and the pip install that reads it. clean: True plus the onchanges
requisite narrowed that to a race rather than a straight win, but the window is
real and the install runs as root.
Move both wheel trees to /opt/saltstack, which is created by the salt package and
is root-owned, and state the ownership explicitly rather than relying on the files
being new:
/opt/so/conf/salt/module_packages/docker
-> /opt/saltstack/module_packages/docker
/opt/so/conf/libvirt/source-packages/libvirt-python
-> /opt/saltstack/source-packages/libvirt-python
salt.python_modules is included by salt/salt/minion/init.sls, so the docker wheels
are staged on every minion in the grid, not just the manager.
Upgraded installs keep a now-unused wheel tree in the old socore-writable location,
so remove it -- nothing reads it after this change, but leaving a writable staging
directory behind serves no purpose.