fix: harden system dirs at install; keep sudo attribution without passwd

Address remaining review comments:

- shim: force root:root 0755 on the managed system dirs (shim tree and
  profile.d) after MkdirAll. A pre-created dir with weaker ownership,
  possible under Debian's group-writable /usr/local/lib, would let a
  non-root user replace the shims every account executes.

- audit: when SUDO_USER has no passwd entry (minimal containers),
  attribute cloud events from sudo's recorded SUDO_USER/SUDO_UID env
  instead of falling back to root. Still gated on euid 0.

- setup: reword the root-without---system warning; alias/shim install
  follows HOME, so claiming it configures only root's home was wrong.

- shim: skip the non-root-owner validation test on Windows, where file
  ownership is not resolvable.
This commit is contained in:
Sahilb315
2026-07-14 13:24:08 +05:30
parent 4b2a25a378
commit 748d40c14f
6 changed files with 51 additions and 1 deletions
+4
View File
@@ -3,6 +3,7 @@ package shim
import (
"os"
"path/filepath"
"runtime"
"testing"
"github.com/stretchr/testify/assert"
@@ -151,6 +152,9 @@ func TestValidateSystemExecutableRejectsGroupWritable(t *testing.T) {
}
func TestValidateSystemExecutableRejectsNonRootOwner(t *testing.T) {
if runtime.GOOS == "windows" {
t.Skip("file ownership is not resolvable on Windows")
}
if os.Geteuid() == 0 {
t.Skip("running as root: temp file is root-owned, so the owner check passes")
}