canonical / canonical/cloud-init
World writable /usr/lib/cloud-init/clouddir should not be left behind
Open
bug
good first issue
- Dominant language
- Python
- Stars
- 3.8k
- Forks
- 1.1k
- Avg merge
- 2d 23h
- Merged PRs (30d)
- 18
Description
# Bug report
[Work](https://github.com/canonical/cloud-init/pull/1690) was done last year to ensure that when `/tmp` and `/var/tmp` are hardend with `noexec`, cloud-init will use an alternative path under `/usr/lib/cloud-init`
However, `/usr/lib/cloud-init/clouddir` is created as world writable and left behind after cloud-init has exited.
## Steps to reproduce the problem
Run cloud-init with a `/tmp` and `/var/tmp` that are mounted with `noexec`
If possible, `/usr/lib/cloud-init/clouddir` should be created as non-world read/writable. But if that's not possible, at the least it should be removed when cloud-init exits.
Contributor guide
Assessment
This issue has not been assessed yet.