Files
securityonion/salt/libvirt/packages.sls
T
Josh Patterson 098699613e FIX: pip install wheels from a root-owned directory
Root ran `pip install --find-links` against directories under /opt/so/conf, which
is 939:939 mode 770. Hardening those directories would not have helped: renaming an
entry requires write permission on the parent, not on the entry, so uid 939 could
move the wheel tree aside and substitute its own between the file.recurse that
populates it and the pip install that reads it. clean: True plus the onchanges
requisite narrowed that to a race rather than a straight win, but the window is
real and the install runs as root.

Move both wheel trees to /opt/saltstack, which is created by the salt package and
is root-owned, and state the ownership explicitly rather than relying on the files
being new:

  /opt/so/conf/salt/module_packages/docker
    -> /opt/saltstack/module_packages/docker
  /opt/so/conf/libvirt/source-packages/libvirt-python
    -> /opt/saltstack/source-packages/libvirt-python

salt.python_modules is included by salt/salt/minion/init.sls, so the docker wheels
are staged on every minion in the grid, not just the manager.

Upgraded installs keep a now-unused wheel tree in the old socore-writable location,
so remove it -- nothing reads it after this change, but leaving a writable staging
directory behind serves no purpose.
2026-09-17 12:43:37 -04:00

96 lines
2.9 KiB
YAML+Jinja

# Copyright Security Onion Solutions LLC and/or licensed to Security Onion Solutions LLC under one
# or more contributor license agreements. Licensed under the Elastic License 2.0 as shown at
# https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0.
#
# Note: Per the Elastic License 2.0, the second limitation states:
#
# "You may not move, change, disable, or circumvent the license key functionality
# in the software, and you may not remove or obscure any functionality in the
# software that is protected by the license key."
{% from 'allowed_states.map.jinja' import allowed_states %}
{% if sls.split('.')[0] in allowed_states or sls in allowed_states %}
{% if 'vrt' in salt['pillar.get']('features', []) %}
# allows for creating vm images
# any node manipulating images needs this
# used on manager for setup_hypervisor runner
install_qemu-img:
pkg.installed:
- name: qemu-img
# used on manager for setup_hypervisor runner
install_xorriso:
pkg.installed:
- name: xorriso
install_libvirt-libs:
pkg.installed:
- name: libvirt-libs
# Root pip-installs these below, so they cannot live under /opt/so/conf (939:939 mode 770):
# write permission on that directory lets uid 939 swap the tree between this state and the
# install. /opt/saltstack is root-owned, so the same trick does not work there.
libvirt_python_wheel:
file.recurse:
- name: /opt/saltstack/source-packages/libvirt-python
- source: salt://libvirt/source-packages/libvirt-python
- user: root
- group: root
- dir_mode: 755
- file_mode: 644
- makedirs: True
- clean: True
old_libvirt_python_wheel:
file.absent:
- name: /opt/so/conf/libvirt/source-packages
libvirt_python_module:
cmd.run:
- name: /opt/saltstack/salt/bin/python3 -m pip install --no-index --find-links=/opt/saltstack/source-packages/libvirt-python libvirt-python
- onchanges:
- file: libvirt_python_wheel
{% if 'hype' in grains.id.split('_') | last %}
# provides virsh
install_libvirt-client:
pkg.installed:
- name: libvirt-client
install_guestfs-tools:
pkg.installed:
- name: guestfs-tools
install_virt-install:
pkg.installed:
- name: virt-install
# needed for for so-qcow2-modify-network - import guestfs
install_python3-libguestfs:
pkg.installed:
- name: python3-libguestfs
###
{% endif %}
{% else %}
{{sls}}_no_license_detected:
test.fail_without_changes:
- name: {{sls}}_no_license_detected
- comment:
- "Hypervisor nodes are a feature supported only for customers with a valid license.
Contact Security Onion Solutions, LLC via our website at https://securityonionsolutions.com
for more information about purchasing a license to enable this feature."
{% endif %}
{% else %}
{{sls}}_state_not_allowed:
test.fail_without_changes:
- name: {{sls}}_state_not_allowed
{% endif %}