Skip to content

client: disallow unprivileged users to escalate root privileges#62025

Merged
vshankar merged 1 commit intoceph:mainfrom
vshankar:wip-client-secfix-1
May 13, 2025
Merged

client: disallow unprivileged users to escalate root privileges#62025
vshankar merged 1 commit intoceph:mainfrom
vshankar:wip-client-secfix-1

Conversation

@vshankar
Copy link
Contributor

An unprivileged user can chmod 777 a directory owned by root and gain access. Fix this bug and also add a test case for the same.

Contribution Guidelines

  • To sign and title your commits, please refer to Submitting Patches to Ceph.

  • If you are submitting a fix for a stable branch (e.g. "quincy"), please refer to Submitting Patches to Ceph - Backports for the proper workflow.

  • When filling out the below checklist, you may click boxes directly in the GitHub web UI. When entering or editing the entire PR message in the GitHub web UI editor, you may also select a checklist item by adding an x between the brackets: [x]. Spaces and capitalization matter when checking off items this way.

Checklist

  • Tracker (select at least one)
    • References tracker ticket
    • Very recent bug; references commit where it was introduced
    • New feature (ticket optional)
    • Doc update (no ticket needed)
    • Code cleanup (no ticket needed)
  • Component impact
    • Affects Dashboard, opened tracker ticket
    • Affects Orchestrator, opened tracker ticket
    • No impact that needs to be tracked
  • Documentation (select at least one)
    • Updates relevant documentation
    • No doc update is appropriate
  • Tests (select at least one)
Show available Jenkins commands
  • jenkins retest this please
  • jenkins test classic perf
  • jenkins test crimson perf
  • jenkins test signed
  • jenkins test make check
  • jenkins test make check arm64
  • jenkins test submodules
  • jenkins test dashboard
  • jenkins test dashboard cephadm
  • jenkins test api
  • jenkins test docs
  • jenkins render docs
  • jenkins test ceph-volume all
  • jenkins test ceph-volume tox
  • jenkins test windows
  • jenkins test rook e2e

@vshankar vshankar marked this pull request as ready for review February 27, 2025 07:51
@github-actions github-actions bot added cephfs Ceph File System tests labels Feb 27, 2025
@vshankar
Copy link
Contributor Author

This PR is under test in https://tracker.ceph.com/issues/70201.

@vshankar vshankar force-pushed the wip-client-secfix-1 branch from eb1111e to 4591302 Compare February 28, 2025 05:29
@vshankar
Copy link
Contributor Author

vshankar commented Mar 3, 2025

Tests did not run over the weekend. Trigerred it again.

@vshankar
Copy link
Contributor Author

vshankar commented Apr 7, 2025

This PR is under test in https://tracker.ceph.com/issues/70820.

@vshankar
Copy link
Contributor Author

Test runs looks fine. Preparing run wiki and this should get merged soon.

@vshankar
Copy link
Contributor Author

jenkins retest this please

@vshankar
Copy link
Contributor Author

jenkins test make check

@vshankar
Copy link
Contributor Author

jenkins retest this please

@vshankar
Copy link
Contributor Author

vshankar commented May 6, 2025

@vshankar
Copy link
Contributor Author

vshankar commented May 6, 2025

jenkins retest this please

1 similar comment
@vshankar
Copy link
Contributor Author

vshankar commented May 7, 2025

jenkins retest this please

An unprivileged user can `chmod 777` a directory owned by root
and gain access. Fix this bug and also add a test case for the
same.

Signed-off-by: Xiubo Li <xiubli@redhat.com>
Signed-off-by: Venky Shankar <vshankar@redhat.com>
@vshankar vshankar force-pushed the wip-client-secfix-1 branch from 4591302 to fb1b72d Compare May 8, 2025 21:31
@vshankar
Copy link
Contributor Author

jenkins test make check

@vshankar
Copy link
Contributor Author

Copy link
Contributor

@mchangir mchangir left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@vshankar vshankar merged commit 9cd1d6f into ceph:main May 13, 2025
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cephfs Ceph File System tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants