apache / apache/cloudstack

World Writable Mounts Need Sticky Bit

Đang mở
#6,867 5 bình luận 0 reaction 0 người được giao Xem trên GitHub
no-issue-activity Severity:Minor status:needs-investigation status:stale
Ngôn ngữ chính
Java
Star
3.1k
Fork
1.4k
Merge trung bình
6 ngày 19 giờ
Pull request đã merge (30 ngày)
32

Mô tả

##### ISSUE TYPE
* Bug Report

##### COMPONENT NAME
component:api

##### CLOUDSTACK VERSION
~~~
4.17
4.18
~~~

##### OS / ENVIRONMENT
Ubuntu
Rocky Linux 8

##### SUMMARY
In java code, NFS mounts are not consistently set to 1777 to prevent world writable issues.

References to correct setting
```
./server/src/main/java/org/apache/cloudstack/storage/NfsMountManagerImpl.java: script.add("1777", mountPoint);
./plugins/hypervisors/vmware/src/main/java/com/cloud/hypervisor/vmware/manager/VmwareManagerImpl.java: script.add("1777", mountPoint);

```

#### Change 777 to 1777

#### ./services/secondary-storage/server/src/main/java/org/apache/cloudstack/storage/resource/LocalNfsSecondaryStorageResource.java
```java
@Override
protected void mount(String localRootPath, String remoteDevice, URI uri, String nfsVersion) {
ensureLocalRootPathExists(localRootPath, uri);

if (mountExists(localRootPath, uri)) {
return;
}

attemptMount(localRootPath, remoteDevice, uri, nfsVersion);

// Change permissions for the mountpoint - seems to bypass authentication
Script script = new Script(true, "chmod", _timeout, s_logger);
script.add("777", localRootPath);
String result = script.execute();
if (result != null) {
String errMsg = "Unable to set permissions for " + localRootPath + " due to " + result;
s_logger.error(errMsg);
throw new CloudRuntimeException(errMsg);
}
s_logger.debug("Successfully set 777 permission for " + localRootPath);

// XXX: Adding the check for creation of snapshots dir here. Might have
// to move it somewhere more logical later.
checkForSnapshotsDir(localRootPath);
checkForVolumesDir(localRootPath);
}

```
#### ./plugins/hypervisors/hyperv/src/main/java/com/cloud/hypervisor/hyperv/manager/HypervManagerImpl.java
```java
protected String mount(String path, String parent, String scheme, String query) {
String mountPoint = setupMountPoint(parent);
if (mountPoint == null) {
s_logger.warn("Unable to create a mount point");
return null;
}

Script script = null;
String result = null;
if (scheme.equals("cifs")) {
String user = System.getProperty("user.name");
Script command = new Script(true, "mount", _timeout, s_logger);
command.add("-t", "cifs");
command.add(path);
command.add(mountPoint);

if (user != null) {
command.add("-o", "uid=" + user + ",gid=" + user);
}

if (query != null) {
query = query.replace('&', ',');
command.add("-o", query);
}

result = command.execute();
}

if (result != null) {
s_logger.warn("Unable to mount " + path + " due to " + result);
File file = new File(mountPoint);
if (file.exists()) {
file.delete();
}
return null;
}

// Change permissions for the mountpoint
script = new Script(true, "chmod", _timeout, s_logger);
script.add("-R", "777", mountPoint);
result = script.execute();
if (result != null) {
s_logger.warn("Unable to set permissions for " + mountPoint + " due to " + result);
}
return mountPoint;
}

```

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Bắt đầu với LocalNfsSecondaryStorageResource.java và HypervManagerImpl.java, sau đó so sánh cách xử lý quyền mount của chúng với các tham chiếu NfsMountManagerImpl.java và VmwareManagerImpl.java. Cập nhật các thiết lập mount có quyền ghi cho mọi người không nhất quán để sử dụng sticky bit và xác minh rằng các đường dẫn mount bị ảnh hưởng không còn sử dụng 777.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
java
Lĩnh vực
api, cloud, infrastructure
Loại issue
Lỗi
Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức độ hoạt động
Đình trệ
Độ rõ ràng
Đặc tả rõ ràng
Mức phù hợp với người mới
35/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.