Files
esh-pfi-infrastructure/persistent-memory.d/2026-09-23-elway-ownership-fix-fleet-audit.md
T

34 lines
2.0 KiB
Markdown

# `[2026-09-23]` elway sudo uploads land root:root; fleet ownership audit; 33 files fixed
elway's sudo upload was scp-as-user then `sudo mv`, and mv keeps the owner, so
every file it installed as root (systemd units, `/etc` configs, root-run
scripts) landed owned by infra-ops or lkraven. A sudoers drop-in installed that
way would break sudo outright. Commit `466f7aa`:
- sudo uploads chown to `root:root` by default; `upload.owner:` / `--owner`
override; owner refused on non-sudo uploads.
- chown+chmod act on the STAGED file, then one `mv` publishes it, so a failed
chown cannot leave the live path mis-owned. A trap removes the staged file on
every exit. A directory dest is refused before anything moves.
- `mode` was spliced unquoted into the remote root shell; now octal-validated
and quoted. `mode`/`owner` must be quoted YAML strings (bare `0644` → 420).
- `preflight()` resolves every step before any remote action.
- 24 unit tests; heid bug-hunt "Puck" (Gróa + seat) folded.
`scripts/fleet-ownership-audit.sh` (read-only; exit 0/4/5): tier A root-parsed
paths (symlinks judged by target), tier X root-run unit Exec paths incl.
drop-ins, tier B /opt summary. Unprivileged or partial hosts report INCOMPLETE,
never clean; completion is nonce-marked. Positive controls on nh3-dev fired for
each tier. **Six hosts have no infra-ops identity** (ana-wg, nh3-nas, pbs-ana,
pbs-nh3, pfi-postgres, vm-esh-nas) and audit unprivileged.
**33 files chowned to root on 10 hosts** with Prime's approval (the first
attempt was blocked by the permission classifier): 31 elway-placed (beszel
agent trio on 6 hosts, esh-vm-db/ana-docker restic hooks and retry drop-ins,
irv-ml1 units, nh3-dev alert bridge, fv-ml1 retired file) plus 2 non-elway
root-exec holes (ana-docker `/usr/local/bin/resticprofile` owned by llmuser;
esh-pve-nas `/usr/local/lib/libigdgmm.so.11.3.1343` uid 1000). Re-audit: 0 of
the 33 remain; all affected services still active. Left as low-risk and
reported: ana-docker `/root/.nvm` (lkraven), irv-ml1 `uv`/`uvx`, fv-ml1
`btop` and a root uv-cache python.