apache / apache/cloudstack

World Writable Mounts Need Sticky Bit

Open
#6,867 5 comments 0 reactions 0 assignees View on GitHub
no-issue-activity Severity:Minor status:needs-investigation status:stale
Dominant language
Java
Stars
3.1k
Forks
1.4k
Avg merge
6d 19h
Merged PRs (30d)
32

Description

##### ISSUE TYPE
* Bug Report

##### COMPONENT NAME
component:api

##### CLOUDSTACK VERSION
~~~
4.17
4.18
~~~

##### OS / ENVIRONMENT
Ubuntu
Rocky Linux 8

##### SUMMARY
In java code, NFS mounts are not consistently set to 1777 to prevent world writable issues.

References to correct setting
```
./server/src/main/java/org/apache/cloudstack/storage/NfsMountManagerImpl.java: script.add("1777", mountPoint);
./plugins/hypervisors/vmware/src/main/java/com/cloud/hypervisor/vmware/manager/VmwareManagerImpl.java: script.add("1777", mountPoint);

```

#### Change 777 to 1777

#### ./services/secondary-storage/server/src/main/java/org/apache/cloudstack/storage/resource/LocalNfsSecondaryStorageResource.java
```java
@Override
protected void mount(String localRootPath, String remoteDevice, URI uri, String nfsVersion) {
ensureLocalRootPathExists(localRootPath, uri);

if (mountExists(localRootPath, uri)) {
return;
}

attemptMount(localRootPath, remoteDevice, uri, nfsVersion);

// Change permissions for the mountpoint - seems to bypass authentication
Script script = new Script(true, "chmod", _timeout, s_logger);
script.add("777", localRootPath);
String result = script.execute();
if (result != null) {
String errMsg = "Unable to set permissions for " + localRootPath + " due to " + result;
s_logger.error(errMsg);
throw new CloudRuntimeException(errMsg);
}
s_logger.debug("Successfully set 777 permission for " + localRootPath);

// XXX: Adding the check for creation of snapshots dir here. Might have
// to move it somewhere more logical later.
checkForSnapshotsDir(localRootPath);
checkForVolumesDir(localRootPath);
}

```
#### ./plugins/hypervisors/hyperv/src/main/java/com/cloud/hypervisor/hyperv/manager/HypervManagerImpl.java
```java
protected String mount(String path, String parent, String scheme, String query) {
String mountPoint = setupMountPoint(parent);
if (mountPoint == null) {
s_logger.warn("Unable to create a mount point");
return null;
}

Script script = null;
String result = null;
if (scheme.equals("cifs")) {
String user = System.getProperty("user.name");
Script command = new Script(true, "mount", _timeout, s_logger);
command.add("-t", "cifs");
command.add(path);
command.add(mountPoint);

if (user != null) {
command.add("-o", "uid=" + user + ",gid=" + user);
}

if (query != null) {
query = query.replace('&', ',');
command.add("-o", query);
}

result = command.execute();
}

if (result != null) {
s_logger.warn("Unable to mount " + path + " due to " + result);
File file = new File(mountPoint);
if (file.exists()) {
file.delete();
}
return null;
}

// Change permissions for the mountpoint
script = new Script(true, "chmod", _timeout, s_logger);
script.add("-R", "777", mountPoint);
result = script.execute();
if (result != null) {
s_logger.warn("Unable to set permissions for " + mountPoint + " due to " + result);
}
return mountPoint;
}

```

Contributor guide

Open the contributing guide

Research direction

Start with LocalNfsSecondaryStorageResource.java and HypervManagerImpl.java, then compare their mount permission handling with the NfsMountManagerImpl.java and VmwareManagerImpl.java references. Update the inconsistent world-writable mount settings to use the sticky bit and verify the affected mount paths no longer use 777.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
api, cloud, infrastructure
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.