fix(install): 重跑安装时撤销旧版本为世界根目录授予 uid 1000 的 ACL 与 o+x 遍历权限

This commit is contained in:
Lemon-miaow committed 2026-09-25 03:46:53 +08:00
1 parent 0770a4d676
commit 074bd1783c
2 files changed
+58

No files matched your search

+30
View File
@@ -3401,6 +3401,34 @@ EOF
ok "off-site copy: secrets in ${OFFSITE_ENV}"
}
# Releases before the reaper ran as root granted uid 1000 traverse on the worlds root: an
# ACL entry, or o+x where the host had no setfacl. uid 1000 is now the game servers' uid,
# and the per-volume directories below that root are 0777, so the grant let a game process
# (and, for o+x, every local account) reach any world by its directory name. Every run
# takes it back: the ACL entry from any worlds root, the other-bits only from k3s's storage
# root, which k3s ships 0700 root:root. A custom root keeps its mode, which may be the
# operator's own.
revoke_worlds_root_grant() {
local dir
for dir in "$K3S_STORAGE_ROOT" "$FELIS_WORLDS_HOST_PATH"; do
[ -n "$dir" ] && [ -d "$dir" ] || continue
if command -v getfacl >/dev/null 2>&1 && getfacl -cpn "$dir" 2>/dev/null | grep -q '^user:1000:'; then
if setfacl -x u:1000 "$dir"; then
log "revoked the old uid-1000 traverse grant on ${dir}"
else
warn "could not revoke the old uid-1000 traverse grant on ${dir}; remove it with: setfacl -x u:1000 ${dir}"
fi
fi
done
if [ -d "$K3S_STORAGE_ROOT" ] && [ -n "$(find "$K3S_STORAGE_ROOT" -maxdepth 0 -perm -o=x)" ]; then
if chmod o-rwx "$K3S_STORAGE_ROOT"; then
log "revoked the old world-traversable mode on ${K3S_STORAGE_ROOT} (back to k3s's 0700)"
else
warn "could not restore ${K3S_STORAGE_ROOT} to 0700; any local account can reach the world volumes below it: chmod o-rwx ${K3S_STORAGE_ROOT}"
fi
fi
}
deploy_bundle() {
local prev_api prev_operator prev_gate
export KUBECONFIG=/etc/rancher/k3s/k3s.yaml
@@ -3445,6 +3473,8 @@ deploy_bundle() {
--key="$PANEL_TLS_KEY" \
--dry-run=client -o yaml | kube apply -f -
revoke_worlds_root_grant
log "rendering + applying the control-plane bundle"
local -a manifest_args=(
--felis-image "$FELIS_IMAGE"
+28
View File
@@ -1022,6 +1022,34 @@ case "$out" in
*SETFACL*|*CHMOD*|*WARN*) echo "FAIL: an existing worlds root must get no grant and no warning: $out"; fails=$((fails + 1)) ;;
esac
# data-durability-18: an older release's traverse grant on the worlds root is taken back on
# every run -- the ACL entry from any root, the other-bits only from k3s's own storage root.
rvblock="$(awk '/^revoke_worlds_root_grant\(\) \{/,/^}/' "$BS")"
[ -n "$rvblock" ] || { echo "FAIL: no revoke_worlds_root_grant found in $BS"; exit 1; }
run_revoke() { # k3s-root worlds-root acl-dir
K3S_STORAGE_ROOT="$1" FELIS_WORLDS_HOST_PATH="$2" ACL_DIR="$3" bash -c '
log() { printf "LOG %s\n" "$*"; }
warn() { printf "WARN %s\n" "$*"; }
getfacl() { case "$*" in *"$ACL_DIR") printf "user::rwx\nuser:1000:--x\ngroup::---\n" ;; *) printf "user::rwx\ngroup::---\n" ;; esac; }
setfacl() { printf "SETFACL %s\n" "$*"; }
'"$rvblock"'
revoke_worlds_root_grant' 2>&1
}
k3sroot="$(mktemp -d)"; custom="$(mktemp -d)"
command chmod 0701 "$k3sroot"; command chmod 0755 "$custom"
out="$(run_revoke "$k3sroot" "$custom" "$custom")"
expect "the old ACL grant is revoked from a custom worlds root" "SETFACL -x u:1000 $custom" "$out"
expect "the old o+x on k3s's storage root is revoked" "LOG revoked the old world-traversable mode on $k3sroot" "$out"
mode_of() { stat -c %a "$1" 2>/dev/null || stat -f %Lp "$1"; }
if [ "$(mode_of "$k3sroot")" = 700 ]; then echo "PASS k3s's storage root is back to 0700"; else echo "FAIL k3s's storage root is $(mode_of "$k3sroot"), want 700"; fails=$((fails + 1)); fi
if [ "$(mode_of "$custom")" = 755 ]; then echo "PASS a custom worlds root keeps its own mode"; else echo "FAIL a custom worlds root was changed to $(mode_of "$custom")"; fails=$((fails + 1)); fi
out="$(run_revoke "$k3sroot" "" "/nowhere")"
case "$out" in
*SETFACL*|*LOG*|*WARN*) echo "FAIL: a root with no old grant must be left alone: $out"; fails=$((fails + 1)) ;;
*) echo "PASS a root with no old grant is left alone" ;;
esac
command rm -rf "$k3sroot" "$custom"
# --- the registry mirror writer -----------------------------------------------------------
# k3s only consults registries.yaml at agent start, so a CONTENT change must restart k3s and
# an identical file (every re-run) must restart nothing. The k3s restart is the expensive,