Skip to content

Fix permissions on sources and keys - #85

Open
sir-ragna wants to merge 2 commits into
saltstack-formulas:masterfrom
FraudBuster:rvdg/fix-permissions3
Open

sir-ragna wants to merge 2 commits into
saltstack-formulas:masterfrom
FraudBuster:rvdg/fix-permissions3

Conversation

@sir-ragna

Copy link
Copy Markdown

PR progress checklist (to be filled in by reviewers)

  • Changes to documentation are appropriate (or tick if not required)
  • Changes to tests are appropriate (or tick if not required)
  • Reviews completed

What type of PR is this?

Primary type

  • [build] Changes related to the build system
  • [chore] Changes to the build process or auxiliary tools and libraries such as documentation generation
  • [ci] Changes to the continuous integration configuration
  • [feat] A new feature
  • [fix] A bug fix
  • [perf] A code change that improves performance
  • [refactor] A code change that neither fixes a bug nor adds a feature
  • [revert] A change used to revert a previous commit
  • [style] Changes that do not affect the meaning of the code (white-space, formatting, missing semi-colons, etc.)

Secondary type

  • [docs] Documentation changes
  • [test] Adding missing or correcting existing tests

Does this PR introduce a BREAKING CHANGE?

No.

If you currently rely on umask to keep your files unreadable for unprivileged users on your system, you will need to reconfigure the default in the pillar. See apt:mode_sources_list.

Describe the changes you're proposing

We had issues in our environment due to a restrictive umask causing the keys not to be readable. This breaks apt because apt drops privileges when doing key verifications. The keys need to have the permissions 0644.

In our environment we also want to keep our sources files set to 0644. We recognized that some people might not like this, due to embeded credentials in their sources files. Hence an option was added, so that the rest of our changes could get upstreamed.

Pillar / config required to test the proposed changes

The option apt:mode_sources_list was added to set the mode of all sources files.

Debug log showing how the proposed changes work

Documentation checklist

  • Updated the README (e.g. Available states).
  • Updated pillar.example.

Testing checklist

  • Included in Kitchen (i.e. under state_top).
  • Covered by new/existing tests (e.g. InSpec, Serverspec, etc.).
  • Updated the relevant test pillar.

Additional context

Somewhat related to the pkgrepo.managed feature request to get a mode property.

We figured it'd take too long to actually implement and upstream such request, that we'd be better off doing these things in the formula for now.

@sir-ragna
sir-ragna force-pushed the rvdg/fix-permissions3 branch 3 times, most recently from bc659c9 to 63752d3 Compare September 10, 2026 12:23
@sir-ragna
sir-ragna requested a review from a team as a code owner September 10, 2026 12:23
@dafyddj

dafyddj commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Please rebase on the latest CI changes.

@sir-ragna
sir-ragna force-pushed the rvdg/fix-permissions3 branch 2 times, most recently from 11f49bb to 95966d4 Compare October 1, 2026 11:09
@sir-ragna

Copy link
Copy Markdown
Author

I rebased and removed my Gemfile.lock changes.

I did consider adding additional tests to confirm that these fixes really deal with a restrictive umask. No matter what I did, however the process that Salt executes under these tests does not seem to take into account a umask the same way that the salt-minion process does.

We have been running our own fork with these fixes for a while now. After this is merged we can switch back to the upstream version.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants