Skip to content

reef: client: disallow unprivileged users to escalate root privileges#61379

Merged
vshankar merged 1 commit intoceph:reeffrom
vshankar:wip-reef-client-secfix
Mar 10, 2025
Merged

reef: client: disallow unprivileged users to escalate root privileges#61379
vshankar merged 1 commit intoceph:reeffrom
vshankar:wip-reef-client-secfix

Conversation

@vshankar
Copy link
Contributor

An unprivileged user can chmod 777 a directory owned by root and gain access. Fix this bug and also add a test case for the same.

Contribution Guidelines

  • To sign and title your commits, please refer to Submitting Patches to Ceph.

  • If you are submitting a fix for a stable branch (e.g. "quincy"), please refer to Submitting Patches to Ceph - Backports for the proper workflow.

  • When filling out the below checklist, you may click boxes directly in the GitHub web UI. When entering or editing the entire PR message in the GitHub web UI editor, you may also select a checklist item by adding an x between the brackets: [x]. Spaces and capitalization matter when checking off items this way.

Checklist

  • Tracker (select at least one)
    • References tracker ticket
    • Very recent bug; references commit where it was introduced
    • New feature (ticket optional)
    • Doc update (no ticket needed)
    • Code cleanup (no ticket needed)
  • Component impact
    • Affects Dashboard, opened tracker ticket
    • Affects Orchestrator, opened tracker ticket
    • No impact that needs to be tracked
  • Documentation (select at least one)
    • Updates relevant documentation
    • No doc update is appropriate
  • Tests (select at least one)
Show available Jenkins commands
  • jenkins retest this please
  • jenkins test classic perf
  • jenkins test crimson perf
  • jenkins test signed
  • jenkins test make check
  • jenkins test make check arm64
  • jenkins test submodules
  • jenkins test dashboard
  • jenkins test dashboard cephadm
  • jenkins test api
  • jenkins test docs
  • jenkins render docs
  • jenkins test ceph-volume all
  • jenkins test ceph-volume tox
  • jenkins test windows
  • jenkins test rook e2e

An unprivileged user can `chmod 777` a directory owned by root
and gain access. Fix this bug and also add a test case for the
same.

Signed-off-by: Xiubo Li <xiubli@redhat.com>
Signed-off-by: Venky Shankar <vshankar@redhat.com>
@github-actions github-actions bot added cephfs Ceph File System tests labels Jan 15, 2025
@github-actions github-actions bot added this to the reef milestone Jan 15, 2025
@mchangir
Copy link
Contributor

mchangir commented Feb 7, 2025

jenkins test api

1 similar comment
@mchangir
Copy link
Contributor

mchangir commented Feb 7, 2025

jenkins test api

@mchangir
Copy link
Contributor

This PR is under test in https://tracker.ceph.com/issues/69881.

@mchangir
Copy link
Contributor

This PR is under test in https://tracker.ceph.com/issues/70178.

@mchangir
Copy link
Contributor

mchangir commented Mar 3, 2025

This PR is under test in https://tracker.ceph.com/issues/70261.

@vshankar vshankar modified the milestones: reef, v18.2.5 Mar 3, 2025
@vshankar
Copy link
Contributor Author

Copy link
Contributor

@mchangir mchangir left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@vshankar vshankar merged commit 16b9de4 into ceph:reef Mar 10, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cephfs Ceph File System tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants