Repository navigation
fix(roles/aide): stop reporting /boot/efi and fwupd.conf on unchanged hosts - #418
Merged
Merged
Conversation
vfat stores no inode numbers. fat_build_inode() assigns one with iunique() whenever a file is read in again, so once the inodes below /boot/efi had been evicted from the cache, every check reported all files there as changed (seen on a Rocky 9 host). /boot/efi now uses DATAONLY, like /etc/ld.so.cache, which still reports changes of content, permissions and ownership. The aide scenario drops the page cache before the clean check, asserts that the probe file below /boot/efi got a new inode number, and that a content change there is still reported. Verified on Debian 13, Rocky 8, Rocky 9 and Ubuntu 24.04.
fwupd 1.9.1 and later sets its config to 0640 whenever the daemon starts (fu_config_ensure_permissions() in libfwupdplugin/fu-config.c), while the package ships it with 0644. The catch-all `/etc PERMS` checks the mode and its ACL, so the first daemon start after `aide --init` or after an update of fwupd failed the check. The file is now checked with PERMS minus the mode and the ACL. The aide scenario resets the file to 0644, restarts fwupd, asserts that the daemon set it to 0640, and requires the check to stay clean. Verified on Rocky 9, Ubuntu 24.04 and Ubuntu 26.04.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
On a Rocky 9 host,
aidecheck.servicefailed with findings on files that had not changed. Two of them are false positives of the role's default rules.Changes
/boot/efi: checked withDATAONLYinstead ofNORMAL. The EFI system partition is vfat, which stores no inode numbers:fat_build_inode()assigns a new one withiunique()whenever a file is read in again (fs/fat/inode.c), so once the inodes were evicted from the cache, every file below/boot/efiwas reported as changed. Content, permissions and ownership are still checked, as for/etc/ld.so.cache./etc/fwupd/fwupd.conf: checked withftype+u+g+selinux+xattrs, i.e. the catch-allPERMSwithout the mode and its ACL. fwupd 1.9.1 and later sets the file to 0640 whenever its daemon starts (fu_config_ensure_permissions()inlibfwupdplugin/fu-config.c), while the package ships it with 0644, so the first daemon start afteraide --initor after an update of fwupd failed the check.prepare.ymldeploys a probe file to/boot/efi.verify.ymldrops the page cache and asserts that the probe got a new inode number, resetsfwupd.confto 0644, restarts fwupd and asserts it set 0640, and then requires the check to run clean. A content change below/boot/efiis still reported.Tests
molecule test --scenario-name aide, full sequence (verify, idempotence, verify), green on Debian 13, Rocky 8, Rocky 9, Ubuntu 24.04 and Ubuntu 26.04 (Ubuntu 24.04 and 26.04 in the run with the fwupd rule; Ubuntu 24.04 failed onfwupd.confbefore it).echo 2 > /proc/sys/vm/drop_cachesleaves the inode number as it is on Debian 13, Rocky 9 and Ubuntu 24.04, since the kernel keeps an inode that still has cached pages; the probe usesecho 3.VM creation in Molecule failed at first in the ARP-based address discovery, as in #416:
virsh domifaddr --source arpreads only the first netlink datagram of the neighbour dump (virNetlinkCommand()in libvirt), so VMs whose entry lands in a later datagram are not found once the host's neighbour cache is large. Flushing the stale entries (ip neigh flush dev <bridge>) made it work.