cockroachdb / cockroachdb/cockroach

jobs: ensure jobs execute using permissions of creator instead of root

Open
#101,501 0 comments 0 reactions 0 assignees View on GitHub
C-enhancement
Dominant language
Go
Stars
32.5k
Forks
4.1k
PR merge metrics
PR metrics pending

Description

As a follow up to the CDC pre-mortem: https://docs.google.com/document/d/1X2D64G_Jdb9S4MxrBYPH_fwKAP3dkUrhc7yUgZZNZAY/edit#

We're worried about a security vulnerability caused by introduced by the way jobs are executed partly as root/system instead of by the user. We should add testing/investigate to ensure that jobs execute using permissions of creator instead of root.

Jira issue: CRDB-26973

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.