canonical/cloud-init
World writable /usr/lib/cloud-init/clouddir should not be left behind
Offen
#4.189 geöffnet am 15.06.2023
buggood first issue
Repository-Metriken
- Stars
- (3.772 Sterne)
- PR-Merge-Metriken
- (PR-Metriken ausstehend)
Beschreibung
Bug report
Work was done last year to ensure that when /tmp and /var/tmp are hardend with noexec, cloud-init will use an alternative path under /usr/lib/cloud-init
However, /usr/lib/cloud-init/clouddir is created as world writable and left behind after cloud-init has exited.
Steps to reproduce the problem
Run cloud-init with a /tmp and /var/tmp that are mounted with noexec
If possible, /usr/lib/cloud-init/clouddir should be created as non-world read/writable. But if that's not possible, at the least it should be removed when cloud-init exits.