@cryptotaxi247 / netdata-1 / commits / 776c1e719

strict netdata files permissions

Costa Tsaousis (ktsaou) committed Jan 11, 2018 at 23:20 UTC 776c1e719645713b1cd828dc74d65fda657380c7
4 files changed +90 -22
netdata-installer.sh
+23 -13
@@ -683,6 +683,7 @@ if [ "${UID}" = "0" ]
683 else
684 NETDATA_USER="${USER}"
685 fi
686 +NETDATA_GROUP="${NETDATA_USER}"
687
688 # the owners of the web files
689 NETDATA_WEB_USER="$( config_option "web" "web files owner" "${NETDATA_USER}" )"
@@ -720,9 +721,9 @@ do
721 run mkdir -p "${NETDATA_CONF_DIR}/${x}" || exit 1
722 fi
723 done
723 -run chown -R "${NETDATA_USER}:${NETDATA_USER}" "${NETDATA_CONF_DIR}"
724 -run find "${NETDATA_CONF_DIR}" -type f -exec chmod 0660 {} \;
725 -run find "${NETDATA_CONF_DIR}" -type d -exec chmod 0775 {} \;
724 +run chown -R "root:${NETDATA_GROUP}" "${NETDATA_CONF_DIR}"
725 +run find "${NETDATA_CONF_DIR}" -type f -exec chmod 0640 {} \;
726 +run find "${NETDATA_CONF_DIR}" -type d -exec chmod 0755 {} \;
727
728 # --- web dir ----
729
@@ -760,7 +761,7 @@ if [ ${UID} -eq 0 ]
761 admin_group=
762 test -z "${admin_group}" && getent group root >/dev/null 2>&1 && admin_group="root"
763 test -z "${admin_group}" && getent group daemon >/dev/null 2>&1 && admin_group="daemon"
763 - test -z "${admin_group}" && admin_group="${NETDATA_USER}"
764 + test -z "${admin_group}" && admin_group="${NETDATA_GROUP}"
765
766 run chown "${NETDATA_USER}:${admin_group}" "${NETDATA_LOG_DIR}"
767 run chown -R root "${NETDATA_PREFIX}/usr/libexec/netdata"
@@ -774,6 +775,8 @@ if [ ${UID} -eq 0 ]
775 then
776 if [ ! -z "${setcap}" ]
777 then
778 + run chown root:${NETDATA_GROUP} "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/apps.plugin"
779 + run chmod 0750 "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/apps.plugin"
780 run setcap cap_dac_read_search,cap_sys_ptrace+ep "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/apps.plugin"
781 setcap_ret=$?
782 fi
@@ -791,25 +794,32 @@ if [ ${UID} -eq 0 ]
794 if [ ${setcap_ret} -ne 0 ]
795 then
796 # fix apps.plugin to be setuid to root
794 - run chown root "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/apps.plugin"
795 - run chmod 4755 "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/apps.plugin"
797 + run chown root:${NETDATA_GROUP} "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/apps.plugin"
798 + run chmod 4750 "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/apps.plugin"
799 fi
800
801 if [ -f "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/freeipmi.plugin" ]
802 then
800 - run chown root "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/freeipmi.plugin"
801 - run chmod 4755 "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/freeipmi.plugin"
803 + run chown root:${NETDATA_GROUP} "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/freeipmi.plugin"
804 + run chmod 4750 "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/freeipmi.plugin"
805 fi
806
807 if [ -f "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/cgroup-network" ]
808 then
806 - run chown root "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/cgroup-network"
807 - run chmod 4755 "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/cgroup-network"
809 + run chown root:${NETDATA_GROUP} "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/cgroup-network"
810 + run chmod 4750 "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/cgroup-network"
811 + fi
812 +
813 + if [ -f "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/cgroup-network-helper.sh" ]
814 + then
815 + run chown root "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/cgroup-network-helper.sh"
816 + run chmod 0500 "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/cgroup-network-helper.sh"
817 fi
818
819 else
811 - run chown "${NETDATA_USER}:${NETDATA_USER}" "${NETDATA_LOG_DIR}"
812 - run chown -R "${NETDATA_USER}:${NETDATA_USER}" "${NETDATA_PREFIX}/usr/libexec/netdata"
820 + # non-privileged user installation
821 + run chown "${NETDATA_USER}:${NETDATA_GROUP}" "${NETDATA_LOG_DIR}"
822 + run chown -R "${NETDATA_USER}:${NETDATA_GROUP}" "${NETDATA_PREFIX}/usr/libexec/netdata"
823 run find "${NETDATA_PREFIX}/usr/libexec/netdata" -type f -exec chmod 0755 {} \;
824 run find "${NETDATA_PREFIX}/usr/libexec/netdata" -type d -exec chmod 0755 {} \;
825 fi
@@ -937,7 +947,7 @@ either of the following sets of commands:
947
948 To run apps.plugin with escalated capabilities:
949
940 - ${TPUT_YELLOW}${TPUT_BOLD}sudo chown root:${NETDATA_USER} \"${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/apps.plugin\"${TPUT_RESET}
950 + ${TPUT_YELLOW}${TPUT_BOLD}sudo chown root:${NETDATA_GROUP} \"${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/apps.plugin\"${TPUT_RESET}
951 ${TPUT_YELLOW}${TPUT_BOLD}sudo chmod 0750 \"${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/apps.plugin\"${TPUT_RESET}
952 ${TPUT_YELLOW}${TPUT_BOLD}sudo setcap cap_dac_read_search,cap_sys_ptrace+ep \"${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/apps.plugin\"${TPUT_RESET}
953
plugins.d/cgroup-network-helper.sh
-1
@@ -23,7 +23,6 @@
23 # -----------------------------------------------------------------------------
24
25 # the system path is cleared by cgroup-network
26 -export PATH="/bin:/usr/bin:/sbin:/usr/sbin:/usr/local/bin:/usr/local/sbin"
26 [ -x /etc/profile ] && source /etc/profile
27
28 export LC_ALL=C
src/cgroup-network.c
+43 -8
@@ -12,16 +12,18 @@ char *host_prefix = "";
12 char *pluginsdir = "";
13 char *configdir = "";
14
15 -char environment_variable1[FILENAME_MAX + 1] = "";
16 -char environment_variable2[FILENAME_MAX + 1] = "";
17 -char environment_variable3[FILENAME_MAX + 1] = "";
15 +char environment_variable2[FILENAME_MAX + 50] = "";
16 +char environment_variable3[FILENAME_MAX + 50] = "";
17 +char environment_variable4[FILENAME_MAX + 50] = "";
18 char *environment[] = {
19 - environment_variable1,
19 + "PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin",
20 environment_variable2,
21 environment_variable3,
22 + environment_variable4,
23 NULL
24 };
25
26 +
27 // ----------------------------------------------------------------------------
28 // callback required by fatal()
29
@@ -488,7 +490,7 @@ int verify_path(const char *path) {
490 char c;
491 const char *s = path;
492 while((c = *s++)) {
491 - if(c == '$' || c == '`') {
493 + if(c == '$' || c == '`' || c == '<' || c == '>') {
494 error("invalid character in path '%s'", path);
495 return -1;
496 }
@@ -512,6 +514,39 @@ int verify_path(const char *path) {
514 return 0;
515 }
516
517 +/*
518 +char *fix_path_variable(void) {
519 + const char *path = getenv("PATH");
520 + if(!path || !*path) return 0;
521 +
522 + char *p = strdupz(path);
523 + char *safe_path = callocz(1, strlen(p) + strlen("PATH=") + 1);
524 + strcpy(safe_path, "PATH=");
525 +
526 + int added = 0;
527 + char *ptr = p;
528 + while(ptr && *ptr) {
529 + char *s = strsep(&ptr, ":");
530 + if(s && *s) {
531 + if(verify_path(s) == -1) {
532 + error("the PATH variable includes an invalid path '%s' - removed it.", s);
533 + }
534 + else {
535 + info("the PATH variable includes a valid path '%s'.", s);
536 + if(added) strcat(safe_path, ":");
537 + strcat(safe_path, s);
538 + added++;
539 + }
540 + }
541 + }
542 +
543 + info("unsafe PATH: '%s'.", path);
544 + info(" safe PATH: '%s'.", safe_path);
545 +
546 + freez(p);
547 + return safe_path;
548 +}
549 +*/
550
551 // ----------------------------------------------------------------------------
552 // main
@@ -563,9 +598,9 @@ int main(int argc, char **argv) {
598 // ------------------------------------------------------------------------
599 // build a safe environment for our script
600
566 - snprintfz(environment_variable1, FILENAME_MAX, "NETDATA_HOST_PREFIX=%s", host_prefix);
567 - snprintfz(environment_variable2, FILENAME_MAX, "NETDATA_PLUGINS_DIR=%s", pluginsdir);
568 - snprintfz(environment_variable3, FILENAME_MAX, "NETDATA_CONFIG_DIR=%s", configdir);
601 + snprintfz(environment_variable2, sizeof(environment_variable2) - 1, "NETDATA_HOST_PREFIX=%s", host_prefix);
602 + snprintfz(environment_variable3, sizeof(environment_variable3) - 1, "NETDATA_PLUGINS_DIR=%s", pluginsdir);
603 + snprintfz(environment_variable4, sizeof(environment_variable4) - 1, "NETDATA_CONFIG_DIR=%s", configdir);
604
605 // ------------------------------------------------------------------------
606
src/common.c
+24
@@ -904,6 +904,30 @@ void strreverse(char *begin, char *end) {
904 }
905 }
906
907 +char *strsep_on_1char(char **ptr, char c) {
908 + if(unlikely(!ptr || !*ptr))
909 + return NULL;
910 +
911 + // remember the position we started
912 + char *s = *ptr;
913 +
914 + // skip separators in front
915 + while(*s == c) s++;
916 + char *ret = s;
917 +
918 + // find the next separator
919 + while(*s++) {
920 + if(unlikely(*s == c)) {
921 + *s++ = '\0';
922 + *ptr = s;
923 + return ret;
924 + }
925 + }
926 +
927 + *ptr = NULL;
928 + return ret;
929 +}
930 +
931 char *mystrsep(char **ptr, char *s) {
932 char *p = "";
933 while (p && !p[0] && *ptr) p = strsep(ptr, s);