canonical/cloud-init

World writable /usr/lib/cloud-init/clouddir should not be left behind

Open

#4,189 opened on Jun 15, 2023

 (5 comments) (1 reaction) (0 assignees)Python (1,108 forks)auto 404
buggood first issue

Repository metrics

Stars
 (3,772 stars)
PR merge metrics
 (PR metrics pending)

Description

Bug report

Work was done last year to ensure that when /tmp and /var/tmp are hardend with noexec, cloud-init will use an alternative path under /usr/lib/cloud-init

However, /usr/lib/cloud-init/clouddir is created as world writable and left behind after cloud-init has exited.

Steps to reproduce the problem

Run cloud-init with a /tmp and /var/tmp that are mounted with noexec

If possible, /usr/lib/cloud-init/clouddir should be created as non-world read/writable. But if that's not possible, at the least it should be removed when cloud-init exits.

Contributor guide