Project

General

Profile

Bug #7060

cfengine stops processing a promise on symlinks

Added by Benoît PECCATTE over 5 years ago. Updated over 4 years ago.

Status:
Released
Priority:
N/A
Category:
Agent
Target version:
Severity:
User visibility:
Effort required:
Priority:

Description

When a symbolic link isn't owned by the same user as its tagrget, cfengine stops processing file promises.
This can stop an attack on code where there is a race condition, but in practice, ther should not be race conditions and there is a lot of legitimate systems with links that don't have the same owner as their target.
We should disable this behavior


Subtasks

Bug #9026: cfengine stops processing a promise on symlinksReleasedAlexis MOUSSET2016-09-13Actions
Bug #9043: Malformed patch in 7060ReleasedBenoît PECCATTE2016-09-14Actions

Related issues

Related to Rudder - Bug #6953: The agent refuses to work on files with symlink in their pathRejected2015-07-10Actions
#1

Updated by Vincent MEMBRÉ over 5 years ago

  • Target version changed from 2.11.13 to 2.11.14
#2

Updated by Vincent MEMBRÉ over 5 years ago

  • Target version changed from 2.11.14 to 2.11.15
#3

Updated by Vincent MEMBRÉ over 5 years ago

  • Target version changed from 2.11.15 to 2.11.16
#4

Updated by Vincent MEMBRÉ over 5 years ago

  • Target version changed from 2.11.16 to 2.11.17
#5

Updated by Vincent MEMBRÉ about 5 years ago

  • Target version changed from 2.11.17 to 2.11.18
#6

Updated by Vincent MEMBRÉ about 5 years ago

  • Target version changed from 2.11.18 to 2.11.19
#7

Updated by Vincent MEMBRÉ almost 5 years ago

  • Target version changed from 2.11.19 to 2.11.20
#8

Updated by Vincent MEMBRÉ almost 5 years ago

  • Target version changed from 2.11.20 to 2.11.21
#9

Updated by Vincent MEMBRÉ almost 5 years ago

  • Target version changed from 2.11.21 to 2.11.22
#10

Updated by Vincent MEMBRÉ over 4 years ago

  • Target version changed from 2.11.22 to 2.11.23
#11

Updated by Vincent MEMBRÉ over 4 years ago

  • Target version changed from 2.11.23 to 2.11.24
#12

Updated by Vincent MEMBRÉ over 4 years ago

  • Target version changed from 2.11.24 to 308
#13

Updated by François ARMAND over 4 years ago

  • Related to Bug #6953: The agent refuses to work on files with symlink in their path added
#14

Updated by Vincent MEMBRÉ over 4 years ago

  • Target version changed from 308 to 3.1.14
#15

Updated by Benoît PECCATTE over 4 years ago

  • Status changed from New to In progress
  • Assignee set to Benoît PECCATTE
#16

Updated by Benoît PECCATTE over 4 years ago

  • Status changed from In progress to Pending technical review
  • Assignee changed from Benoît PECCATTE to Alexis MOUSSET
  • Pull Request set to https://github.com/Normation/rudder-packages/pull/1050
#17

Updated by Benoît PECCATTE over 4 years ago

  • Status changed from Pending technical review to Pending release
  • % Done changed from 0 to 100
#18

Updated by Alexis MOUSSET over 4 years ago

  • Related to deleted (Bug #6953: The agent refuses to work on files with symlink in their path)
#19

Updated by Alexis MOUSSET over 4 years ago

  • Related to Bug #6953: The agent refuses to work on files with symlink in their path added
#20

Updated by Vincent MEMBRÉ over 4 years ago

  • Category changed from System integration to Agent
#21

Updated by Vincent MEMBRÉ over 4 years ago

  • Status changed from Pending release to Released

This bug has been fixed in Rudder 3.1.15/14 and 3.2.8/7 which were released today.

Also available in: Atom PDF