mirror of
https://github.com/CyberMind-FR/secubox-deb.git
synced 2026-07-29 13:59:40 +00:00
docs: record #623 systemic shared-parent clobber fix (PR #648)
Some checks are pending
License Headers / check (push) Waiting to run
Some checks are pending
License Headers / check (push) Waiting to run
This commit is contained in:
parent
9950e9ec3e
commit
ab8822e3f4
|
|
@ -3,6 +3,29 @@
|
|||
|
||||
---
|
||||
|
||||
## 2026-06-18 — #623 systemic shared-parent clobber resolved at source (PR #648)
|
||||
|
||||
- **Root cause corrected.** The recurring `/var/{lib,log,cache,…}/secubox` parent
|
||||
clobber was NOT the `install -d -m 0750 /parent/leaf` leaf form (empirically
|
||||
proven harmless: GNU `install -d -m` modes only the final component). It was the
|
||||
scaffold boilerplate `install -d -m 750 /var/lib/secubox` + `/run/secubox` (BARE
|
||||
parents) in ~56 module postinsts — written `-m 750` (3-digit), which is why prior
|
||||
greps/sweeps (#511/#627/#631) missed it.
|
||||
- **Source-wide fix.** Scripted rewrite of all bare-parent targets → `/run/secubox`
|
||||
1777 root:root, `/var/lib|log|cache|etc|usr/share/secubox` 0755; 6 multi-arg
|
||||
lines split per-parent (4 were setting `/var/lib/secubox` world-writable 1777 —
|
||||
a security regression); 3 `chmod 750 /var/log/secubox` (soc-gateway/soc-agent/
|
||||
ui-manager) → 0755. Module-private leaves (`/var/lib/secubox/<mod>` 0750) left
|
||||
untouched. Scaffold `new-package.sh` + `.claude/PATTERNS.md` fixed so new
|
||||
packages don't reintroduce it. secubox-core 1.1.8 tmpfiles.d now declares all 5
|
||||
shared parents at 0755 (mode-only) for boot/install-time self-heal.
|
||||
- **Verified:** all 64 changed maintainer scripts `bash -n` clean; zero bare-parent
|
||||
restrictive lines remain (install-d + chmod forms); saas-relay + core rebuilt and
|
||||
packaged postinst/tmpfiles confirmed. Two-stage review (found + closed 2 gaps:
|
||||
the chmod-form clobbers + tmpfiles coverage). NOT mass-deployed (60-pkg restart =
|
||||
thundering-herd risk); live covered by `secubox-dirs-guard.timer`; lands at next
|
||||
CI image build / reflash.
|
||||
|
||||
## 2026-06-18 — perf sprint (hub latency, R3 tunnel encoding) + crowdsec unblock
|
||||
|
||||
- **Hub dashboard latency (#644, PR #645, hub `1.4.6`).** The hub runs mounted in
|
||||
|
|
|
|||
|
|
@ -22,13 +22,20 @@ Tout mergé sur master + déployé sur gk2. Détail dans HISTORY 2026-06-18.
|
|||
CSP-strict tirées décompressées via le worker R3 GIL-bound. **toolbox 2.6.53**.
|
||||
- ✅ **crowdsec** réparé (403 transitoire CDN → `dpkg --configure` RC=0, audit clean).
|
||||
|
||||
- ✅ **#623 (PR #648, merged 9950e9ec)** — clobber systémique RÉSOLU au source.
|
||||
La vraie cause : boilerplate scaffold `install -d -m 750 /var/lib/secubox` +
|
||||
`/run/secubox` (parents NUS) dans ~56 postinsts — écrit `-m 750` (3 chiffres),
|
||||
d'où le ratage des sweeps précédents. Empiriquement prouvé que le form
|
||||
`install -d -m 750 /parent/leaf` NE clobbe PAS le parent (seuls les targets
|
||||
parents-nus). Fix : tous → 1777 (/run) / 0755 ; 6 lignes multi-arg splittées
|
||||
(4 mettaient /var/lib en world-writable 1777) ; 3 `chmod 750 /var/log` ;
|
||||
scaffold `new-package.sh` + `PATTERNS.md` ; core 1.1.8 tmpfiles.d déclare les 5
|
||||
parents 0755. **PAS de mass-deploy** (60 paquets = mass-restart = risque
|
||||
thundering-herd) ; live couvert par `dirs-guard.timer` ; arrive au prochain
|
||||
build CI / reflash.
|
||||
|
||||
### ⬜ Next Up
|
||||
|
||||
- **#623 (P0 bug)** — clobber systémique des modes parents `/var/{lib,log,cache}/
|
||||
secubox` sur ~12 paquets (postinsts `install -d -m 0750` multi-arg que le sweep
|
||||
#623 a manqués). Couvert par `secubox-dirs-guard.timer` mais la cause-racine
|
||||
reste ouverte paquet par paquet → casse la traversée non-`secubox` (kbin/toolbox
|
||||
500). **Prochain actionnable propre** (PR bornée).
|
||||
- **Anti-Track v2 ARMING** (décision USER, gated) — soak observe-only puis flip
|
||||
`privacy_enforce=true` ; régénérer `data/cdn-allowlist.txt` depuis les plages
|
||||
publiques avant `privacy_ip_drop` ; `unbound-checkconf` avant `privacy_dns_feed`.
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user