jenkinsci / jenkinsci/workflow-basic-steps-plugin

[JENKINS-52750] dir step creates a <dirname>@tmp directory at <dirname> level.

Offen
#464 18 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
component:workflow-basic-steps-plugin imported-jira-issue jira-type:task pipeline priority:major resolution:unresolved
Vorherrschende Sprache
Java
Sterne
73
Forks
129
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

In order to install some internal tools within /opt/tools through a Jenkins job, I have created a /opt/tools directory belonging to jenkins:jenkins and where user jenkins only (the user running the slave) has rwx rights.

Trying something like :

stages {

steps('xyz') {
dir('/opt/tools') {
sh "pwd"
}
}
}

Fails with an exception ending with :

java.nio.file.AccessDeniedException: /opt/tools@​tmp

at sun.nio.fs.UnixException.translateToIOException(UnixException.java:84)
at sun.nio.fs.UnixException.rethrowAsIOException(UnixException.java:102)
at sun.nio.fs.UnixException.rethrowAsIOException(UnixException.java:107)
at sun.nio.fs.UnixFileSystemProvider.createDirectory(UnixFileSystemProvider.java:384)
at java.nio.file.Files.createDirectory(Files.java:674)
at java.nio.file.Files.createAndCheckIsDirectory(Files.java:781)
at java.nio.file.Files.createDirectories(Files.java:767)
at hudson.FilePath.mkdirs(FilePath.java:3098)
at hudson.FilePath.access$900(FilePath.java:209)
at hudson.FilePath$Mkdirs.invoke(FilePath.java:1216)
at hudson.FilePath$Mkdirs.invoke(FilePath.java:1212)
at hudson.FilePath$FileCallableWrapper.call(FilePath.java:2913)
at hudson.remoting.UserRequest.perform(UserRequest.java:212)
at hudson.remoting.UserRequest.perform(UserRequest.java:54)
at hudson.remoting.Request$2.run(Request.java:369)
at hudson.remoting.InterceptingExecutorService$1.call(InterceptingExecutorService.java:72)
at java.util.concurrent.FutureTask.run(FutureTask.java:266)
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
at java.lang.Thread.run(Thread.java:748)

It appears that Jenkins tries to create a tools@​tmp directory at the same level as tools. Yet, there is absolutely no reason for the tools root directory to be writable for any user.

And as far as /opt is concerned here, for sure it must not be writable for anybody else than root.

Additionnally, such @​tmp directory is not removed once the build is achieved. Even though it seems that the directory is empty, I think that Jenkins should remove it to give back a clean environment.

 

---
Originally reported by jlpinardon, imported from: dir step creates a @tmp directory at level.


  • status: Open
  • priority: Major
  • component(s): workflow-basic-steps-plugin
  • label(s): pipeline, pipeline-triaged
  • resolution: Unresolved
  • votes: 16
  • watchers: 22
  • imported: 20251215-220547

Raw content of original issue

In order to install some internal tools within /opt/tools through a Jenkins job, I have created a /opt/tools directory belonging to jenkins:jenkins and where user jenkins only (the user running the slave) has rwx rights.
Trying something like :



stages {

steps('xyz') {
dir('/opt/tools') {
sh "pwd"
}
}
}


Fails with an exception ending with :



java.nio.file.AccessDeniedException: /opt/tools@tmp

at sun.nio.fs.UnixException.translateToIOException(UnixException.java:84)
at sun.nio.fs.UnixException.rethrowAsIOException(UnixException.java:102)
at sun.nio.fs.UnixException.rethrowAsIOException(UnixException.java:107)
at sun.nio.fs.UnixFileSystemProvider.createDirectory(UnixFileSystemProvider.java:384)
at java.nio.file.Files.createDirectory(Files.java:674)
at java.nio.file.Files.createAndCheckIsDirectory(Files.java:781)
at java.nio.file.Files.createDirectories(Files.java:767)
at hudson.FilePath.mkdirs(FilePath.java:3098)
at hudson.FilePath.access$900(FilePath.java:209)
at hudson.FilePath$Mkdirs.invoke(FilePath.java:1216)
at hudson.FilePath$Mkdirs.invoke(FilePath.java:1212)
at hudson.FilePath$FileCallableWrapper.call(FilePath.java:2913)
at hudson.remoting.UserRequest.perform(UserRequest.java:212)
at hudson.remoting.UserRequest.perform(UserRequest.java:54)
at hudson.remoting.Request$2.run(Request.java:369)
at hudson.remoting.InterceptingExecutorService$1.call(InterceptingExecutorService.java:72)
at java.util.concurrent.FutureTask.run(FutureTask.java:266)
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
at java.lang.Thread.run(Thread.java:748)


It appears that Jenkins tries to create a tools@tmp directory at the same level as tools. Yet, there is absolutely no reason for the tools root directory to be writable for any user.
And as far as /opt is concerned here, for sure it must not be writable for anybody else than root.

Additionnally, such @tmp directory is not removed once the build is achieved. Even though it seems that the directory is empty, I think that Jenkins should remove it to give back a clean environment.

 

  • environment: Jenkins 2.121.2 on a CentOS 7

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Beginnen Sie mit der Implementierung des dir-Schritts in workflow-basic-steps-plugin und reproduzieren Sie das /opt/tools-Beispiel in der angegebenen Jenkins- und CentOS-Umgebung. Verfolgen Sie die gezeigte Erstellung von @tmp über hudson.FilePath.mkdirs und prüfen Sie anschließend, ob das temporäre Verzeichnis nach dem Build bereinigt wird; definieren Sie den Abschluss als Vermeidung des Berechtigungsfehlers, ohne ein unerwünschtes Verzeichnis zu hinterlassen.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
java
Bereich
devtools
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
42/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.