canonical / canonical/cloud-init

World writable /usr/lib/cloud-init/clouddir should not be left behind

Open
#4,189 5 comments 1 reaction 0 assignees View on GitHub
bug good first issue
Dominant language
Python
Stars
3.8k
Forks
1.1k
Avg merge
2d 23h
Merged PRs (30d)
18

Description

# Bug report
[Work](https://github.com/canonical/cloud-init/pull/1690) was done last year to ensure that when `/tmp` and `/var/tmp` are hardend with `noexec`, cloud-init will use an alternative path under `/usr/lib/cloud-init`

However, `/usr/lib/cloud-init/clouddir` is created as world writable and left behind after cloud-init has exited.

## Steps to reproduce the problem
Run cloud-init with a `/tmp` and `/var/tmp` that are mounted with `noexec`

If possible, `/usr/lib/cloud-init/clouddir` should be created as non-world read/writable. But if that's not possible, at the least it should be removed when cloud-init exits.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.