mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-09-19 14:19:49 +02:00
/opt/so/saltstack/default holds the source for every root-executed script -- /usr/sbin, the reactors, _runners/_modules/_beacons, the master engines and salt-relay.sh -- plus every state the root master renders. SOC mounts /opt/so/saltstack rw as uid 939, so root-owning /usr/sbin alone was not enough: the next highstate would copy attacker-controlled bytes out of the tree into the root-owned destination and run them. SOC never writes under default/, it only reads it. Every SOC write targets local/, which stays socore-owned, as does /opt/so/state. No mode is enforced on default/ -- SOC reads that tree, and 750/640 would break its config load. Also stops copy_new_files(), so-saltstack-update and setup from chowning the tree back to socore, and replaces preserve: True in soup_scripts.sls, which carried uid/gid in from the /tmp staging tree and would have undone the ownership before the first post-soup highstate.
141 lines
4.0 KiB
YAML+Jinja
141 lines
4.0 KiB
YAML+Jinja
# Copyright Security Onion Solutions LLC and/or licensed to Security Onion Solutions LLC under one
|
|
# or more contributor license agreements. Licensed under the Elastic License 2.0 as shown at
|
|
# https://securityonion.net/license; you may not use this file except in compliance with the
|
|
# Elastic License 2.0.
|
|
|
|
{% import_yaml '/opt/so/saltstack/local/pillar/global/soc_global.sls' as SOC_GLOBAL %}
|
|
{% if SOC_GLOBAL.global.airgap %}
|
|
{% set UPDATE_DIR='/tmp/soagupdate/SecurityOnion' %}
|
|
{% else %}
|
|
{% set UPDATE_DIR='/tmp/sogh/securityonion' %}
|
|
{% endif %}
|
|
{% set SOVERSION = salt['file.read']('/etc/soversion').strip() %}
|
|
|
|
# This section is used to put the scripts in place in the Salt file system
|
|
# in case a state run tries to overwrite what we do in the next section.
|
|
copy_so-common_common_tools_sbin:
|
|
file.copy:
|
|
- name: /opt/so/saltstack/default/salt/common/tools/sbin/so-common
|
|
- source: {{UPDATE_DIR}}/salt/common/tools/sbin/so-common
|
|
- force: True
|
|
- user: root
|
|
- group: root
|
|
- mode: 755
|
|
|
|
copy_so-image-common_common_tools_sbin:
|
|
file.copy:
|
|
- name: /opt/so/saltstack/default/salt/common/tools/sbin/so-image-common
|
|
- source: {{UPDATE_DIR}}/salt/common/tools/sbin/so-image-common
|
|
- force: True
|
|
- user: root
|
|
- group: root
|
|
- mode: 755
|
|
|
|
copy_soup_manager_tools_sbin:
|
|
file.copy:
|
|
- name: /opt/so/saltstack/default/salt/manager/tools/sbin/soup
|
|
- source: {{UPDATE_DIR}}/salt/manager/tools/sbin/soup
|
|
- force: True
|
|
- user: root
|
|
- group: root
|
|
- mode: 755
|
|
|
|
copy_so-firewall_manager_tools_sbin:
|
|
file.copy:
|
|
- name: /opt/so/saltstack/default/salt/manager/tools/sbin/so-firewall
|
|
- source: {{UPDATE_DIR}}/salt/manager/tools/sbin/so-firewall
|
|
- force: True
|
|
- user: root
|
|
- group: root
|
|
- mode: 755
|
|
|
|
copy_so-yaml_manager_tools_sbin:
|
|
file.copy:
|
|
- name: /opt/so/saltstack/default/salt/manager/tools/sbin/so-yaml.py
|
|
- source: {{UPDATE_DIR}}/salt/manager/tools/sbin/so-yaml.py
|
|
- force: True
|
|
- user: root
|
|
- group: root
|
|
- mode: 755
|
|
|
|
copy_so-repo-sync_manager_tools_sbin:
|
|
file.copy:
|
|
- name: /opt/so/saltstack/default/salt/manager/tools/sbin/so-repo-sync
|
|
- source: {{UPDATE_DIR}}/salt/manager/tools/sbin/so-repo-sync
|
|
- user: root
|
|
- group: root
|
|
- mode: 755
|
|
|
|
copy_bootstrap-salt_manager_tools_sbin:
|
|
file.copy:
|
|
- name: /opt/so/saltstack/default/salt/salt/scripts/bootstrap-salt.sh
|
|
- source: {{UPDATE_DIR}}/salt/salt/scripts/bootstrap-salt.sh
|
|
- user: root
|
|
- group: root
|
|
- mode: 644
|
|
|
|
# This section is used to put the new script in place so that it can be called during soup.
|
|
# It is faster than calling the states that normally manage them to put them in place.
|
|
copy_so-common_sbin:
|
|
file.copy:
|
|
- name: /usr/sbin/so-common
|
|
- source: {{UPDATE_DIR}}/salt/common/tools/sbin/so-common
|
|
- force: True
|
|
- user: root
|
|
- group: root
|
|
- mode: 755
|
|
|
|
copy_so-image-common_sbin:
|
|
file.copy:
|
|
- name: /usr/sbin/so-image-common
|
|
- source: {{UPDATE_DIR}}/salt/common/tools/sbin/so-image-common
|
|
- force: True
|
|
- user: root
|
|
- group: root
|
|
- mode: 755
|
|
|
|
copy_soup_sbin:
|
|
file.copy:
|
|
- name: /usr/sbin/soup
|
|
- source: {{UPDATE_DIR}}/salt/manager/tools/sbin/soup
|
|
- force: True
|
|
- user: root
|
|
- group: root
|
|
- mode: 755
|
|
|
|
copy_so-firewall_sbin:
|
|
file.copy:
|
|
- name: /usr/sbin/so-firewall
|
|
- source: {{UPDATE_DIR}}/salt/manager/tools/sbin/so-firewall
|
|
- force: True
|
|
- user: root
|
|
- group: root
|
|
- mode: 755
|
|
|
|
copy_so-yaml_sbin:
|
|
file.copy:
|
|
- name: /usr/sbin/so-yaml.py
|
|
- source: {{UPDATE_DIR}}/salt/manager/tools/sbin/so-yaml.py
|
|
- force: True
|
|
- user: root
|
|
- group: root
|
|
- mode: 755
|
|
|
|
copy_so-repo-sync_sbin:
|
|
file.copy:
|
|
- name: /usr/sbin/so-repo-sync
|
|
- source: {{UPDATE_DIR}}/salt/manager/tools/sbin/so-repo-sync
|
|
- force: True
|
|
- user: root
|
|
- group: root
|
|
- mode: 755
|
|
|
|
copy_bootstrap-salt_sbin:
|
|
file.copy:
|
|
- name: /usr/sbin/bootstrap-salt.sh
|
|
- source: {{UPDATE_DIR}}/salt/salt/scripts/bootstrap-salt.sh
|
|
- force: True
|
|
- user: root
|
|
- group: root
|
|
- mode: 755
|