From e95e5437a2367499534dfd4da5f3e1c25fa55b02 Mon Sep 17 00:00:00 2001 From: Ben Vincent Date: Sat, 8 Aug 2026 20:12:06 +1000 Subject: [PATCH] Harden kea socket dir to 0750 in the rendered entrypoints After v0.1.1 moved the socket dir to /var/run/kea, kea-dhcp4 and kea-ctrl-agent still crash-loop: DHCP4_PARSER_COMMIT_FAIL ... 'socket-name' is invalid: socket path:/var/run/kea does not exist or has more relaxed permissions than 750 Kea 2.6+ refuses a unix-socket directory whose mode is more relaxed than 0750. The shared emptyDir is mounted at /var/run/kea with the default 0777, so kea rejects it. The kea containers run as root, so the entrypoints can tighten it. - chmod 0750 the RunDir in both rendered entrypoints after mkdir. - Assert both entrypoints chmod the socket dir to 0750. Needs a v0.1.2 release so argocd-apps can bump the operator image. Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT --- internal/kea/agent.go | 2 ++ internal/kea/config_test.go | 12 ++++++++++++ 2 files changed, 14 insertions(+) diff --git a/internal/kea/agent.go b/internal/kea/agent.go index 45e6df4..273f1c3 100644 --- a/internal/kea/agent.go +++ b/internal/kea/agent.go @@ -35,6 +35,7 @@ func EntrypointDHCP4() string { set -e ORD="${HOSTNAME##*-}" mkdir -p %[1]s +chmod 0750 %[1]s sed "s/%[2]s/server${ORD}/g" %[3]s/kea-dhcp4.conf > %[4]s exec %[5]s -c %[4]s `, RunDir, ThisServerPlaceholder, ConfigDir, DHCP4ConfPath, DHCP4Bin) @@ -45,6 +46,7 @@ func EntrypointCtrlAgent() string { return fmt.Sprintf(`#!/bin/sh set -e mkdir -p %[1]s +chmod 0750 %[1]s cp %[2]s/kea-ctrl-agent.conf %[3]s exec %[4]s -c %[3]s `, RunDir, ConfigDir, CtrlAgentConfPath, CtrlAgentBin) diff --git a/internal/kea/config_test.go b/internal/kea/config_test.go index 8090cb6..47bc01a 100644 --- a/internal/kea/config_test.go +++ b/internal/kea/config_test.go @@ -237,6 +237,18 @@ func TestRenderCtrlAgent(t *testing.T) { } } +func TestEntrypointsHardenSocketDir(t *testing.T) { + // Kea 2.6+ rejects a socket dir "more relaxed than 750"; the emptyDir mount + // defaults to 0777, so the entrypoints must chmod it before exec'ing kea. + want := "chmod 0750 " + RunDir + if ep := EntrypointDHCP4(); !strings.Contains(ep, want) { + t.Errorf("dhcp4 entrypoint must %q, got:\n%s", want, ep) + } + if ep := EntrypointCtrlAgent(); !strings.Contains(ep, want) { + t.Errorf("ctrl-agent entrypoint must %q, got:\n%s", want, ep) + } +} + func TestControlSocketPathAllowedByKea(t *testing.T) { if !strings.HasPrefix(CtrlSocketPath, "/var/run/kea/") { t.Errorf("CtrlSocketPath %q must live under /var/run/kea (kea 2.6+ restriction)", CtrlSocketPath) -- 2.47.3