mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-09-30 11:37:16 +02:00
Root ran `pip install --find-links` against directories under /opt/so/conf, which
is 939:939 mode 770. Hardening those directories would not have helped: renaming an
entry requires write permission on the parent, not on the entry, so uid 939 could
move the wheel tree aside and substitute its own between the file.recurse that
populates it and the pip install that reads it. clean: True plus the onchanges
requisite narrowed that to a race rather than a straight win, but the window is
real and the install runs as root.
Move both wheel trees to /opt/saltstack, which is created by the salt package and
is root-owned, and state the ownership explicitly rather than relying on the files
being new:
/opt/so/conf/salt/module_packages/docker
-> /opt/saltstack/module_packages/docker
/opt/so/conf/libvirt/source-packages/libvirt-python
-> /opt/saltstack/source-packages/libvirt-python
salt.python_modules is included by salt/salt/minion/init.sls, so the docker wheels
are staged on every minion in the grid, not just the manager.
Upgraded installs keep a now-unused wheel tree in the old socore-writable location,
so remove it -- nothing reads it after this change, but leaving a writable staging
directory behind serves no purpose.
96 lines
2.9 KiB
YAML+Jinja
96 lines
2.9 KiB
YAML+Jinja
# Copyright Security Onion Solutions LLC and/or licensed to Security Onion Solutions LLC under one
|
|
# or more contributor license agreements. Licensed under the Elastic License 2.0 as shown at
|
|
# https://securityonion.net/license; you may not use this file except in compliance with the
|
|
# Elastic License 2.0.
|
|
#
|
|
# Note: Per the Elastic License 2.0, the second limitation states:
|
|
#
|
|
# "You may not move, change, disable, or circumvent the license key functionality
|
|
# in the software, and you may not remove or obscure any functionality in the
|
|
# software that is protected by the license key."
|
|
|
|
{% from 'allowed_states.map.jinja' import allowed_states %}
|
|
{% if sls.split('.')[0] in allowed_states or sls in allowed_states %}
|
|
{% if 'vrt' in salt['pillar.get']('features', []) %}
|
|
|
|
# allows for creating vm images
|
|
# any node manipulating images needs this
|
|
# used on manager for setup_hypervisor runner
|
|
install_qemu-img:
|
|
pkg.installed:
|
|
- name: qemu-img
|
|
|
|
# used on manager for setup_hypervisor runner
|
|
install_xorriso:
|
|
pkg.installed:
|
|
- name: xorriso
|
|
|
|
install_libvirt-libs:
|
|
pkg.installed:
|
|
- name: libvirt-libs
|
|
|
|
# Root pip-installs these below, so they cannot live under /opt/so/conf (939:939 mode 770):
|
|
# write permission on that directory lets uid 939 swap the tree between this state and the
|
|
# install. /opt/saltstack is root-owned, so the same trick does not work there.
|
|
libvirt_python_wheel:
|
|
file.recurse:
|
|
- name: /opt/saltstack/source-packages/libvirt-python
|
|
- source: salt://libvirt/source-packages/libvirt-python
|
|
- user: root
|
|
- group: root
|
|
- dir_mode: 755
|
|
- file_mode: 644
|
|
- makedirs: True
|
|
- clean: True
|
|
|
|
old_libvirt_python_wheel:
|
|
file.absent:
|
|
- name: /opt/so/conf/libvirt/source-packages
|
|
|
|
libvirt_python_module:
|
|
cmd.run:
|
|
- name: /opt/saltstack/salt/bin/python3 -m pip install --no-index --find-links=/opt/saltstack/source-packages/libvirt-python libvirt-python
|
|
- onchanges:
|
|
- file: libvirt_python_wheel
|
|
|
|
{% if 'hype' in grains.id.split('_') | last %}
|
|
|
|
# provides virsh
|
|
install_libvirt-client:
|
|
pkg.installed:
|
|
- name: libvirt-client
|
|
|
|
install_guestfs-tools:
|
|
pkg.installed:
|
|
- name: guestfs-tools
|
|
|
|
install_virt-install:
|
|
pkg.installed:
|
|
- name: virt-install
|
|
|
|
# needed for for so-qcow2-modify-network - import guestfs
|
|
install_python3-libguestfs:
|
|
pkg.installed:
|
|
- name: python3-libguestfs
|
|
###
|
|
|
|
{% endif %}
|
|
|
|
{% else %}
|
|
{{sls}}_no_license_detected:
|
|
test.fail_without_changes:
|
|
- name: {{sls}}_no_license_detected
|
|
- comment:
|
|
- "Hypervisor nodes are a feature supported only for customers with a valid license.
|
|
Contact Security Onion Solutions, LLC via our website at https://securityonionsolutions.com
|
|
for more information about purchasing a license to enable this feature."
|
|
{% endif %}
|
|
|
|
{% else %}
|
|
|
|
{{sls}}_state_not_allowed:
|
|
test.fail_without_changes:
|
|
- name: {{sls}}_state_not_allowed
|
|
|
|
{% endif %}
|