strict netdata files permissions
Costa Tsaousis (ktsaou) committed
Jan 11, 2018 at 23:20 UTC
776c1e719645713b1cd828dc74d65fda657380c7
4 files changed
+90
-22
netdata-installer.sh
+23
-13
@@ -683,6 +683,7 @@ if [ "${UID}" = "0" ]
683
else
684
NETDATA_USER="${USER}"
685
fi
686
+NETDATA_GROUP="${NETDATA_USER}"
687
688
# the owners of the web files
689
NETDATA_WEB_USER="$( config_option "web" "web files owner" "${NETDATA_USER}" )"
@@ -720,9 +721,9 @@ do
721
run mkdir -p "${NETDATA_CONF_DIR}/${x}" || exit 1
722
fi
723
done
723
-run chown -R "${NETDATA_USER}:${NETDATA_USER}" "${NETDATA_CONF_DIR}"
724
-run find "${NETDATA_CONF_DIR}" -type f -exec chmod 0660 {} \;
725
-run find "${NETDATA_CONF_DIR}" -type d -exec chmod 0775 {} \;
724
+run chown -R "root:${NETDATA_GROUP}" "${NETDATA_CONF_DIR}"
725
+run find "${NETDATA_CONF_DIR}" -type f -exec chmod 0640 {} \;
726
+run find "${NETDATA_CONF_DIR}" -type d -exec chmod 0755 {} \;
727
728
# --- web dir ----
729
@@ -760,7 +761,7 @@ if [ ${UID} -eq 0 ]
761
admin_group=
762
test -z "${admin_group}" && getent group root >/dev/null 2>&1 && admin_group="root"
763
test -z "${admin_group}" && getent group daemon >/dev/null 2>&1 && admin_group="daemon"
763
- test -z "${admin_group}" && admin_group="${NETDATA_USER}"
764
+ test -z "${admin_group}" && admin_group="${NETDATA_GROUP}"
765
766
run chown "${NETDATA_USER}:${admin_group}" "${NETDATA_LOG_DIR}"
767
run chown -R root "${NETDATA_PREFIX}/usr/libexec/netdata"
@@ -774,6 +775,8 @@ if [ ${UID} -eq 0 ]
775
then
776
if [ ! -z "${setcap}" ]
777
then
778
+ run chown root:${NETDATA_GROUP} "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/apps.plugin"
779
+ run chmod 0750 "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/apps.plugin"
780
run setcap cap_dac_read_search,cap_sys_ptrace+ep "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/apps.plugin"
781
setcap_ret=$?
782
fi
@@ -791,25 +794,32 @@ if [ ${UID} -eq 0 ]
794
if [ ${setcap_ret} -ne 0 ]
795
then
796
# fix apps.plugin to be setuid to root
794
- run chown root "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/apps.plugin"
795
- run chmod 4755 "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/apps.plugin"
797
+ run chown root:${NETDATA_GROUP} "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/apps.plugin"
798
+ run chmod 4750 "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/apps.plugin"
799
fi
800
801
if [ -f "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/freeipmi.plugin" ]
802
then
800
- run chown root "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/freeipmi.plugin"
801
- run chmod 4755 "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/freeipmi.plugin"
803
+ run chown root:${NETDATA_GROUP} "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/freeipmi.plugin"
804
+ run chmod 4750 "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/freeipmi.plugin"
805
fi
806
807
if [ -f "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/cgroup-network" ]
808
then
806
- run chown root "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/cgroup-network"
807
- run chmod 4755 "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/cgroup-network"
809
+ run chown root:${NETDATA_GROUP} "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/cgroup-network"
810
+ run chmod 4750 "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/cgroup-network"
811
+ fi
812
+
813
+ if [ -f "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/cgroup-network-helper.sh" ]
814
+ then
815
+ run chown root "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/cgroup-network-helper.sh"
816
+ run chmod 0500 "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/cgroup-network-helper.sh"
817
fi
818
819
else
811
- run chown "${NETDATA_USER}:${NETDATA_USER}" "${NETDATA_LOG_DIR}"
812
- run chown -R "${NETDATA_USER}:${NETDATA_USER}" "${NETDATA_PREFIX}/usr/libexec/netdata"
820
+ # non-privileged user installation
821
+ run chown "${NETDATA_USER}:${NETDATA_GROUP}" "${NETDATA_LOG_DIR}"
822
+ run chown -R "${NETDATA_USER}:${NETDATA_GROUP}" "${NETDATA_PREFIX}/usr/libexec/netdata"
823
run find "${NETDATA_PREFIX}/usr/libexec/netdata" -type f -exec chmod 0755 {} \;
824
run find "${NETDATA_PREFIX}/usr/libexec/netdata" -type d -exec chmod 0755 {} \;
825
fi
@@ -937,7 +947,7 @@ either of the following sets of commands:
947
948
To run apps.plugin with escalated capabilities:
949
940
- ${TPUT_YELLOW}${TPUT_BOLD}sudo chown root:${NETDATA_USER} \"${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/apps.plugin\"${TPUT_RESET}
950
+ ${TPUT_YELLOW}${TPUT_BOLD}sudo chown root:${NETDATA_GROUP} \"${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/apps.plugin\"${TPUT_RESET}
951
${TPUT_YELLOW}${TPUT_BOLD}sudo chmod 0750 \"${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/apps.plugin\"${TPUT_RESET}
952
${TPUT_YELLOW}${TPUT_BOLD}sudo setcap cap_dac_read_search,cap_sys_ptrace+ep \"${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/apps.plugin\"${TPUT_RESET}
953
plugins.d/cgroup-network-helper.sh
-1
@@ -23,7 +23,6 @@
23
# -----------------------------------------------------------------------------
24
25
# the system path is cleared by cgroup-network
26
-export PATH="/bin:/usr/bin:/sbin:/usr/sbin:/usr/local/bin:/usr/local/sbin"
26
[ -x /etc/profile ] && source /etc/profile
27
28
export LC_ALL=C
src/cgroup-network.c
+43
-8
@@ -12,16 +12,18 @@ char *host_prefix = "";
12
char *pluginsdir = "";
13
char *configdir = "";
14
15
-char environment_variable1[FILENAME_MAX + 1] = "";
16
-char environment_variable2[FILENAME_MAX + 1] = "";
17
-char environment_variable3[FILENAME_MAX + 1] = "";
15
+char environment_variable2[FILENAME_MAX + 50] = "";
16
+char environment_variable3[FILENAME_MAX + 50] = "";
17
+char environment_variable4[FILENAME_MAX + 50] = "";
18
char *environment[] = {
19
- environment_variable1,
19
+ "PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin",
20
environment_variable2,
21
environment_variable3,
22
+ environment_variable4,
23
NULL
24
};
25
26
+
27
// ----------------------------------------------------------------------------
28
// callback required by fatal()
29
@@ -488,7 +490,7 @@ int verify_path(const char *path) {
490
char c;
491
const char *s = path;
492
while((c = *s++)) {
491
- if(c == '$' || c == '`') {
493
+ if(c == '$' || c == '`' || c == '<' || c == '>') {
494
error("invalid character in path '%s'", path);
495
return -1;
496
}
@@ -512,6 +514,39 @@ int verify_path(const char *path) {
514
return 0;
515
}
516
517
+/*
518
+char *fix_path_variable(void) {
519
+ const char *path = getenv("PATH");
520
+ if(!path || !*path) return 0;
521
+
522
+ char *p = strdupz(path);
523
+ char *safe_path = callocz(1, strlen(p) + strlen("PATH=") + 1);
524
+ strcpy(safe_path, "PATH=");
525
+
526
+ int added = 0;
527
+ char *ptr = p;
528
+ while(ptr && *ptr) {
529
+ char *s = strsep(&ptr, ":");
530
+ if(s && *s) {
531
+ if(verify_path(s) == -1) {
532
+ error("the PATH variable includes an invalid path '%s' - removed it.", s);
533
+ }
534
+ else {
535
+ info("the PATH variable includes a valid path '%s'.", s);
536
+ if(added) strcat(safe_path, ":");
537
+ strcat(safe_path, s);
538
+ added++;
539
+ }
540
+ }
541
+ }
542
+
543
+ info("unsafe PATH: '%s'.", path);
544
+ info(" safe PATH: '%s'.", safe_path);
545
+
546
+ freez(p);
547
+ return safe_path;
548
+}
549
+*/
550
551
// ----------------------------------------------------------------------------
552
// main
@@ -563,9 +598,9 @@ int main(int argc, char **argv) {
598
// ------------------------------------------------------------------------
599
// build a safe environment for our script
600
566
- snprintfz(environment_variable1, FILENAME_MAX, "NETDATA_HOST_PREFIX=%s", host_prefix);
567
- snprintfz(environment_variable2, FILENAME_MAX, "NETDATA_PLUGINS_DIR=%s", pluginsdir);
568
- snprintfz(environment_variable3, FILENAME_MAX, "NETDATA_CONFIG_DIR=%s", configdir);
601
+ snprintfz(environment_variable2, sizeof(environment_variable2) - 1, "NETDATA_HOST_PREFIX=%s", host_prefix);
602
+ snprintfz(environment_variable3, sizeof(environment_variable3) - 1, "NETDATA_PLUGINS_DIR=%s", pluginsdir);
603
+ snprintfz(environment_variable4, sizeof(environment_variable4) - 1, "NETDATA_CONFIG_DIR=%s", configdir);
604
605
// ------------------------------------------------------------------------
606
src/common.c
+24
@@ -904,6 +904,30 @@ void strreverse(char *begin, char *end) {
904
}
905
}
906
907
+char *strsep_on_1char(char **ptr, char c) {
908
+ if(unlikely(!ptr || !*ptr))
909
+ return NULL;
910
+
911
+ // remember the position we started
912
+ char *s = *ptr;
913
+
914
+ // skip separators in front
915
+ while(*s == c) s++;
916
+ char *ret = s;
917
+
918
+ // find the next separator
919
+ while(*s++) {
920
+ if(unlikely(*s == c)) {
921
+ *s++ = '\0';
922
+ *ptr = s;
923
+ return ret;
924
+ }
925
+ }
926
+
927
+ *ptr = NULL;
928
+ return ret;
929
+}
930
+
931
char *mystrsep(char **ptr, char *s) {
932
char *p = "";
933
while (p && !p[0] && *ptr) p = strsep(ptr, s);