Skip to content

Don't follow symlinks in file_permission_user_init_files(_root) - #15138

Open
Mab879 wants to merge 1 commit into
ComplianceAsCode:masterfrom
Mab879:fix_init_root_users
Open

Mab879 wants to merge 1 commit into
ComplianceAsCode:masterfrom
Mab879:fix_init_root_users

Conversation

@Mab879

@Mab879 Mab879 commented Sep 22, 2026

Copy link
Copy Markdown
Member

Description:

  • Don't follow symlinks in file_permission_user_init_files(_root)

Rationale:

Follow up to #14808

@Mab879 Mab879 added this to the 0.1.83 milestone Sep 22, 2026
@Mab879 Mab879 added Ansible Ansible remediation update. Bash Bash remediation update. labels Sep 22, 2026
@github-actions

github-actions Bot commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

This datastream diff is auto generated by the check Compare DS/Generate Diff

Click here to see the full diff
ansible remediation for rule 'xccdf_org.ssgproject.content_rule_file_permission_user_init_files' differs.
--- xccdf_org.ssgproject.content_rule_file_permission_user_init_files
+++ xccdf_org.ssgproject.content_rule_file_permission_user_init_files
@@ -46,6 +46,7 @@
   ansible.builtin.file:
     path: '{{ item.1.path }}'
     mode: u-s,g-wxs,o=
+    follow: false
   loop: '{{ q(''ansible.builtin.subelements'', found_init_files.results, ''files'',
     {''skip_missing'': True}) }}'
   tags:

bash remediation for rule 'xccdf_org.ssgproject.content_rule_file_permission_user_init_files_root' differs.
--- xccdf_org.ssgproject.content_rule_file_permission_user_init_files_root
+++ xccdf_org.ssgproject.content_rule_file_permission_user_init_files_root
@@ -12,7 +12,7 @@
     if ! grep -qP "$USERS_IGNORED_REGEX" <<< "${interactive_users[$i]}" && \
         [ "${interactive_users_shell[$i]}" != "/sbin/nologin" ]; then
 
-        readarray -t init_files < <(find "${interactive_users_home[$i]}" -maxdepth 1 \
+        readarray -t init_files < <(find "${interactive_users_home[$i]}" -type f -maxdepth 1 \
             -exec basename {} \; | grep -P "$var_user_initialization_files_regex")
         for file in "${init_files[@]}"; do
             chmod u-s,g-wxs,o= "${interactive_users_home[$i]}/$file"

ansible remediation for rule 'xccdf_org.ssgproject.content_rule_file_permission_user_init_files_root' differs.
--- xccdf_org.ssgproject.content_rule_file_permission_user_init_files_root
+++ xccdf_org.ssgproject.content_rule_file_permission_user_init_files_root
@@ -46,6 +46,7 @@
   ansible.builtin.file:
     path: '{{ item.1.path }}'
     mode: u-s,g-wxs,o=
+    follow: false
   loop: '{{ q(''ansible.builtin.subelements'', found_init_files.results, ''files'',
     {''skip_missing'': True}) }}'
   tags:

@macko1

macko1 commented Sep 24, 2026

Copy link
Copy Markdown
Collaborator

@Mab879 any idea why CaC have both file_permission_user_init_files and file_permission_user_init_files_root ? the file_permission_user_init_files_root seems to duplicate the former + adds /root/<init files>

@Mab879

Mab879 commented Sep 24, 2026 •

Copy link
Copy Markdown
Member Author

@Mab879 any idea why CaC have both file_permission_user_init_files and file_permission_user_init_files_root ? the file_permission_user_init_files_root seems to duplicate the former + adds /root/<init files>

Looks like Jan add this rule little over 2 years ago. Seems like CIS and STIG benchmark split.

@macko1 macko1 self-assigned this Sep 24, 2026
@macko1

macko1 commented Sep 24, 2026

Copy link
Copy Markdown
Collaborator

Ansible fix seems fine.
Bash can be sketchy - there is a very slight chance of race condition (toctou) before looking for the file (is not symlink) and changing permissions on it. Maybe using chmod --no-dereference would be safer?

@Mab879

@Mab879
Mab879 force-pushed the fix_init_root_users branch from f2b39bb to d245442 Compare September 24, 2026 20:22
@Mab879

Mab879 commented Sep 25, 2026

Copy link
Copy Markdown
Member Author

chmod --no-dereference

That is RHEL 10+ only. Reverting.

@Mab879
Mab879 force-pushed the fix_init_root_users branch from d245442 to dbd5e9e Compare September 25, 2026 02:12
@openshift-ci

openshift-ci Bot commented Sep 25, 2026

Copy link
Copy Markdown

@Mab879: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/4.12-images dbd5e9e link true /test 4.12-images

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Ansible Ansible remediation update. Bash Bash remediation update.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants