canonical/cloud-init
World writable /usr/lib/cloud-init/clouddir should not be left behind
オープン
#4,189 opened on 2023/06/15
buggood first issue
Repository metrics
- Stars
- (3,772 個のスター)
- PR merge metrics
- (PR metrics pending)
説明
Bug report
Work was done last year to ensure that when /tmp and /var/tmp are hardend with noexec, cloud-init will use an alternative path under /usr/lib/cloud-init
However, /usr/lib/cloud-init/clouddir is created as world writable and left behind after cloud-init has exited.
Steps to reproduce the problem
Run cloud-init with a /tmp and /var/tmp that are mounted with noexec
If possible, /usr/lib/cloud-init/clouddir should be created as non-world read/writable. But if that's not possible, at the least it should be removed when cloud-init exits.