34 lines
2.0 KiB
Markdown
34 lines
2.0 KiB
Markdown
# `[2026-09-23]` elway sudo uploads land root:root; fleet ownership audit; 33 files fixed
|
|
|
|
elway's sudo upload was scp-as-user then `sudo mv`, and mv keeps the owner, so
|
|
every file it installed as root (systemd units, `/etc` configs, root-run
|
|
scripts) landed owned by infra-ops or lkraven. A sudoers drop-in installed that
|
|
way would break sudo outright. Commit `466f7aa`:
|
|
|
|
- sudo uploads chown to `root:root` by default; `upload.owner:` / `--owner`
|
|
override; owner refused on non-sudo uploads.
|
|
- chown+chmod act on the STAGED file, then one `mv` publishes it, so a failed
|
|
chown cannot leave the live path mis-owned. A trap removes the staged file on
|
|
every exit. A directory dest is refused before anything moves.
|
|
- `mode` was spliced unquoted into the remote root shell; now octal-validated
|
|
and quoted. `mode`/`owner` must be quoted YAML strings (bare `0644` → 420).
|
|
- `preflight()` resolves every step before any remote action.
|
|
- 24 unit tests; heid bug-hunt "Puck" (Gróa + seat) folded.
|
|
|
|
`scripts/fleet-ownership-audit.sh` (read-only; exit 0/4/5): tier A root-parsed
|
|
paths (symlinks judged by target), tier X root-run unit Exec paths incl.
|
|
drop-ins, tier B /opt summary. Unprivileged or partial hosts report INCOMPLETE,
|
|
never clean; completion is nonce-marked. Positive controls on nh3-dev fired for
|
|
each tier. **Six hosts have no infra-ops identity** (ana-wg, nh3-nas, pbs-ana,
|
|
pbs-nh3, pfi-postgres, vm-esh-nas) and audit unprivileged.
|
|
|
|
**33 files chowned to root on 10 hosts** with Prime's approval (the first
|
|
attempt was blocked by the permission classifier): 31 elway-placed (beszel
|
|
agent trio on 6 hosts, esh-vm-db/ana-docker restic hooks and retry drop-ins,
|
|
irv-ml1 units, nh3-dev alert bridge, fv-ml1 retired file) plus 2 non-elway
|
|
root-exec holes (ana-docker `/usr/local/bin/resticprofile` owned by llmuser;
|
|
esh-pve-nas `/usr/local/lib/libigdgmm.so.11.3.1343` uid 1000). Re-audit: 0 of
|
|
the 33 remain; all affected services still active. Left as low-risk and
|
|
reported: ana-docker `/root/.nvm` (lkraven), irv-ml1 `uv`/`uvx`, fv-ml1
|
|
`btop` and a root uv-cache python.
|