Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CASMCMS-9040 - change permissions on image config files after recipe build. #85

Merged
merged 1 commit into from
Aug 29, 2024

Conversation

dlaine-hpe
Copy link
Contributor

Summary and Scope

When recipes are built with kiwi-ng, some of the config files are built into the resulting image with global read permissions. There are times these files contain sensitive information. This change makes the directory and the files only accessible by the root user.

Issues and Related PRs

Testing

Tested on:

  • Tyr

Test description:

Built the barebones recipe on Tyr with the installed 1.6.0 system. I verified that the config files are present in the resulting image and are globally readable. I updated the ims-utils image and rebuilt the image. This time I was able to verify that the files still exist, but both the directory and file permissions are set in such a way that only the root user can see them.

  • Were the install/upgrade-based validation checks/tests run (goss tests/install-validation doc)? N
  • Were continuous integration tests run? If not, why? N
  • Was upgrade tested? If not, why? N
  • Was downgrade tested? If not, why? N
  • Were new tests (or test issues/Jiras) created for this change? N

Risks and Mitigations

This is a low risk change. If the files are present they have the permissions modified. If they don't exist nothing happens.

Pull Request Checklist

  • Version number(s) incremented, if applicable
  • Copyrights updated
  • License file intact
  • Target branch correct
  • CHANGELOG.md updated
  • Testing is appropriate and complete, if applicable

@dlaine-hpe dlaine-hpe requested a review from a team as a code owner August 27, 2024 21:49
@dlaine-hpe dlaine-hpe merged commit 368da78 into develop Aug 29, 2024
6 checks passed
@dlaine-hpe dlaine-hpe deleted the CASMCMS-9040 branch August 29, 2024 14:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants