2.0 KiB
[2026-09-23] elway sudo uploads land root:root; fleet ownership audit; 33 files fixed
elway's sudo upload was scp-as-user then sudo mv, and mv keeps the owner, so
every file it installed as root (systemd units, /etc configs, root-run
scripts) landed owned by infra-ops or lkraven. A sudoers drop-in installed that
way would break sudo outright. Commit 466f7aa:
- sudo uploads chown to
root:rootby default;upload.owner:/--owneroverride; owner refused on non-sudo uploads. - chown+chmod act on the STAGED file, then one
mvpublishes it, so a failed chown cannot leave the live path mis-owned. A trap removes the staged file on every exit. A directory dest is refused before anything moves. modewas spliced unquoted into the remote root shell; now octal-validated and quoted.mode/ownermust be quoted YAML strings (bare0644→ 420).preflight()resolves every step before any remote action.- 24 unit tests; heid bug-hunt "Puck" (Gróa + seat) folded.
scripts/fleet-ownership-audit.sh (read-only; exit 0/4/5): tier A root-parsed
paths (symlinks judged by target), tier X root-run unit Exec paths incl.
drop-ins, tier B /opt summary. Unprivileged or partial hosts report INCOMPLETE,
never clean; completion is nonce-marked. Positive controls on nh3-dev fired for
each tier. Six hosts have no infra-ops identity (ana-wg, nh3-nas, pbs-ana,
pbs-nh3, pfi-postgres, vm-esh-nas) and audit unprivileged.
33 files chowned to root on 10 hosts with Prime's approval (the first
attempt was blocked by the permission classifier): 31 elway-placed (beszel
agent trio on 6 hosts, esh-vm-db/ana-docker restic hooks and retry drop-ins,
irv-ml1 units, nh3-dev alert bridge, fv-ml1 retired file) plus 2 non-elway
root-exec holes (ana-docker /usr/local/bin/resticprofile owned by llmuser;
esh-pve-nas /usr/local/lib/libigdgmm.so.11.3.1343 uid 1000). Re-audit: 0 of
the 33 remain; all affected services still active. Left as low-risk and
reported: ana-docker /root/.nvm (lkraven), irv-ml1 uv/uvx, fv-ml1
btop and a root uv-cache python.