Blame SOURCES/scap-security-guide-0.1.55-update_nodev_nonroot_mount_option-PR_6606.patch

d10e36
From cbede36c7a4e35cb882c35892cff72f9f190cbf9 Mon Sep 17 00:00:00 2001
d10e36
From: Milan Lysonek <mlysonek@redhat.com>
d10e36
Date: Mon, 8 Feb 2021 15:57:43 +0100
d10e36
Subject: [PATCH 1/5] Add nodev,nosuid,noexec options to /boot in ANSSI
d10e36
 kickstart
d10e36
d10e36
---
d10e36
 rhel7/kickstart/ssg-rhel7-anssi_nt28_enhanced-ks.cfg     | 2 +-
d10e36
 rhel7/kickstart/ssg-rhel7-anssi_nt28_high-ks.cfg         | 2 +-
d10e36
 rhel7/kickstart/ssg-rhel7-anssi_nt28_intermediary-ks.cfg | 2 +-
d10e36
 rhel8/kickstart/ssg-rhel8-anssi_bp28_enhanced-ks.cfg     | 2 +-
d10e36
 rhel8/kickstart/ssg-rhel8-anssi_bp28_high-ks.cfg         | 2 +-
d10e36
 rhel8/kickstart/ssg-rhel8-anssi_bp28_intermediary-ks.cfg | 2 +-
d10e36
 6 files changed, 6 insertions(+), 6 deletions(-)
d10e36
d10e36
diff --git a/rhel7/kickstart/ssg-rhel7-anssi_nt28_enhanced-ks.cfg b/rhel7/kickstart/ssg-rhel7-anssi_nt28_enhanced-ks.cfg
d10e36
index 1d35bedb91..c381512476 100644
d10e36
--- a/rhel7/kickstart/ssg-rhel7-anssi_nt28_enhanced-ks.cfg
d10e36
+++ b/rhel7/kickstart/ssg-rhel7-anssi_nt28_enhanced-ks.cfg
d10e36
@@ -99,7 +99,7 @@ zerombr
d10e36
 clearpart --linux --initlabel
d10e36
 
d10e36
 # Create primary system partitions (required for installs)
d10e36
-part /boot --fstype=xfs --size=512
d10e36
+part /boot --fstype=xfs --size=512 --fsoptions="nodev,nosuid,noexec"
d10e36
 part pv.01 --grow --size=1
d10e36
 
d10e36
 # Create a Logical Volume Management (LVM) group (optional)
d10e36
diff --git a/rhel7/kickstart/ssg-rhel7-anssi_nt28_high-ks.cfg b/rhel7/kickstart/ssg-rhel7-anssi_nt28_high-ks.cfg
d10e36
index 73225c2fab..a672b38b83 100644
d10e36
--- a/rhel7/kickstart/ssg-rhel7-anssi_nt28_high-ks.cfg
d10e36
+++ b/rhel7/kickstart/ssg-rhel7-anssi_nt28_high-ks.cfg
d10e36
@@ -103,7 +103,7 @@ zerombr
d10e36
 clearpart --linux --initlabel
d10e36
 
d10e36
 # Create primary system partitions (required for installs)
d10e36
-part /boot --fstype=xfs --size=512
d10e36
+part /boot --fstype=xfs --size=512 --fsoptions="nodev,nosuid,noexec"
d10e36
 part pv.01 --grow --size=1
d10e36
 
d10e36
 # Create a Logical Volume Management (LVM) group (optional)
d10e36
diff --git a/rhel7/kickstart/ssg-rhel7-anssi_nt28_intermediary-ks.cfg b/rhel7/kickstart/ssg-rhel7-anssi_nt28_intermediary-ks.cfg
d10e36
index 20c4c59a78..88a7cee8ab 100644
d10e36
--- a/rhel7/kickstart/ssg-rhel7-anssi_nt28_intermediary-ks.cfg
d10e36
+++ b/rhel7/kickstart/ssg-rhel7-anssi_nt28_intermediary-ks.cfg
d10e36
@@ -99,7 +99,7 @@ zerombr
d10e36
 clearpart --linux --initlabel
d10e36
 
d10e36
 # Create primary system partitions (required for installs)
d10e36
-part /boot --fstype=xfs --size=512
d10e36
+part /boot --fstype=xfs --size=512 --fsoptions="nodev,nosuid,noexec"
d10e36
 part pv.01 --grow --size=1
d10e36
 
d10e36
 # Create a Logical Volume Management (LVM) group (optional)
d10e36
diff --git a/rhel8/kickstart/ssg-rhel8-anssi_bp28_enhanced-ks.cfg b/rhel8/kickstart/ssg-rhel8-anssi_bp28_enhanced-ks.cfg
d10e36
index 728946ecb7..6f66a3774b 100644
d10e36
--- a/rhel8/kickstart/ssg-rhel8-anssi_bp28_enhanced-ks.cfg
d10e36
+++ b/rhel8/kickstart/ssg-rhel8-anssi_bp28_enhanced-ks.cfg
d10e36
@@ -90,7 +90,7 @@ zerombr
d10e36
 clearpart --linux --initlabel
d10e36
 
d10e36
 # Create primary system partitions (required for installs)
d10e36
-part /boot --fstype=xfs --size=512
d10e36
+part /boot --fstype=xfs --size=512 --fsoptions="nodev,nosuid,noexec"
d10e36
 part pv.01 --grow --size=1
d10e36
 
d10e36
 # Create a Logical Volume Management (LVM) group (optional)
d10e36
diff --git a/rhel8/kickstart/ssg-rhel8-anssi_bp28_high-ks.cfg b/rhel8/kickstart/ssg-rhel8-anssi_bp28_high-ks.cfg
d10e36
index cd0eff2625..b5c09253a5 100644
d10e36
--- a/rhel8/kickstart/ssg-rhel8-anssi_bp28_high-ks.cfg
d10e36
+++ b/rhel8/kickstart/ssg-rhel8-anssi_bp28_high-ks.cfg
d10e36
@@ -94,7 +94,7 @@ zerombr
d10e36
 clearpart --linux --initlabel
d10e36
 
d10e36
 # Create primary system partitions (required for installs)
d10e36
-part /boot --fstype=xfs --size=512
d10e36
+part /boot --fstype=xfs --size=512 --fsoptions="nodev,nosuid,noexec"
d10e36
 part pv.01 --grow --size=1
d10e36
 
d10e36
 # Create a Logical Volume Management (LVM) group (optional)
d10e36
diff --git a/rhel8/kickstart/ssg-rhel8-anssi_bp28_intermediary-ks.cfg b/rhel8/kickstart/ssg-rhel8-anssi_bp28_intermediary-ks.cfg
d10e36
index 3a241b06f4..fb785e0c11 100644
d10e36
--- a/rhel8/kickstart/ssg-rhel8-anssi_bp28_intermediary-ks.cfg
d10e36
+++ b/rhel8/kickstart/ssg-rhel8-anssi_bp28_intermediary-ks.cfg
d10e36
@@ -90,7 +90,7 @@ zerombr
d10e36
 clearpart --linux --initlabel
d10e36
 
d10e36
 # Create primary system partitions (required for installs)
d10e36
-part /boot --fstype=xfs --size=512
d10e36
+part /boot --fstype=xfs --size=512 --fsoptions="nodev,nosuid,noexec"
d10e36
 part pv.01 --grow --size=1
d10e36
 
d10e36
 # Create a Logical Volume Management (LVM) group (optional)
d10e36
d10e36
From 15be64cc2d6c21b0351bb8d3d1b55b1924be99ca Mon Sep 17 00:00:00 2001
d10e36
From: Milan Lysonek <mlysonek@redhat.com>
d10e36
Date: Tue, 9 Feb 2021 12:45:34 +0100
d10e36
Subject: [PATCH 2/5] Add mount_option_nodev_nonroot_local_partitions bash
d10e36
 remediation
d10e36
d10e36
---
d10e36
 .../bash/shared.sh                             | 18 ++++++++++++++++++
d10e36
 1 file changed, 18 insertions(+)
d10e36
 create mode 100644 linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/bash/shared.sh
d10e36
d10e36
diff --git a/linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/bash/shared.sh b/linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/bash/shared.sh
d10e36
new file mode 100644
d10e36
index 0000000000..7e2b3bd76b
d10e36
--- /dev/null
d10e36
+++ b/linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/bash/shared.sh
d10e36
@@ -0,0 +1,18 @@
d10e36
+# platform = multi_platform_all
d10e36
+. /usr/share/scap-security-guide/remediation_functions
d10e36
+
d10e36
+include_mount_options_functions
d10e36
+
d10e36
+MOUNT_OPTION="nodev"
d10e36
+# Create array of local non-root partitions
d10e36
+readarray -t partitions_records < <(findmnt --mtab --raw --evaluate | grep "^/\w" | grep "\s/dev/\w")
d10e36
+
d10e36
+for partition_record in "${partitions_records[@]}"; do
d10e36
+    # Get all important information for fstab
d10e36
+    mount_point="$(echo ${partition_record} | cut -d " " -f1)"
d10e36
+    device="$(echo ${partition_record} | cut -d " " -f2)"
d10e36
+    device_type="$(echo ${partition_record} | cut -d " " -f3)"
d10e36
+    # device and device_type will be used only in case when the device doesn't have fstab record
d10e36
+    ensure_mount_option_in_fstab "$mount_point" "$MOUNT_OPTION" "$device" "$device_type"
d10e36
+    ensure_partition_is_mounted "$mount_point"
d10e36
+done
d10e36
d10e36
From 36958b72896a69cb580f00a986673c8ae99cb011 Mon Sep 17 00:00:00 2001
d10e36
From: Milan Lysonek <mlysonek@redhat.com>
d10e36
Date: Tue, 9 Feb 2021 12:45:54 +0100
d10e36
Subject: [PATCH 3/5] Add mount_option_nodev_nonroot_local_partitions test
d10e36
 scenarios
d10e36
d10e36
---
d10e36
 .../tests/correct.pass.sh                     | 23 +++++++++++++++++
d10e36
 .../local_mounted_during_runtime.fail.sh      | 19 ++++++++++++++
d10e36
 .../tests/missing_multiple_nodev.fail.sh      | 23 +++++++++++++++++
d10e36
 .../tests/missing_one_nodev.fail.sh           | 23 +++++++++++++++++
d10e36
 .../tests/remote_without_nodev.pass.sh        | 25 +++++++++++++++++++
d10e36
 5 files changed, 113 insertions(+)
d10e36
 create mode 100644 linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/tests/correct.pass.sh
d10e36
 create mode 100644 linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/tests/local_mounted_during_runtime.fail.sh
d10e36
 create mode 100644 linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/tests/missing_multiple_nodev.fail.sh
d10e36
 create mode 100644 linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/tests/missing_one_nodev.fail.sh
d10e36
 create mode 100644 linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/tests/remote_without_nodev.pass.sh
d10e36
d10e36
diff --git a/linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/tests/correct.pass.sh b/linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/tests/correct.pass.sh
d10e36
new file mode 100644
d10e36
index 0000000000..8bfac4b80f
d10e36
--- /dev/null
d10e36
+++ b/linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/tests/correct.pass.sh
d10e36
@@ -0,0 +1,23 @@
d10e36
+#!/bin/bash
d10e36
+
d10e36
+. $SHARED/partition.sh
d10e36
+
d10e36
+# Add nodev option to all records in fstab to ensure that test will
d10e36
+# run on environment where everything is set correctly for rule check.
d10e36
+cp /etc/fstab /etc/fstab.backup
d10e36
+sed -e 's/\bnodev\b/,/g' -e 's/,,//g' -e 's/\s,\s/defaults/g' /etc/fstab.backup
d10e36
+awk '{$4 = $4",nodev"; print}' /etc/fstab.backup > /etc/fstab
d10e36
+# Remount all partitions. (--all option can't be used because it doesn't
d10e36
+# mount e.g. /boot partition
d10e36
+declare -a partitions=( $(awk '{print $2}' /etc/fstab | grep "^/\w") )
d10e36
+for partition in ${partitions[@]}; do
d10e36
+    mount -o remount "$partition"
d10e36
+done
d10e36
+
d10e36
+PARTITION="/dev/new_partition1"; create_partition
d10e36
+make_fstab_given_partition_line "/tmp/partition1" ext2 nodev
d10e36
+mount_partition "/tmp/partition1"
d10e36
+
d10e36
+PARTITION="/dev/new_partition2"; create_partition
d10e36
+make_fstab_given_partition_line "/tmp/partition2" ext2 nodev
d10e36
+mount_partition "/tmp/partition2"
d10e36
diff --git a/linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/tests/local_mounted_during_runtime.fail.sh b/linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/tests/local_mounted_during_runtime.fail.sh
d10e36
new file mode 100644
d10e36
index 0000000000..84cadd6f73
d10e36
--- /dev/null
d10e36
+++ b/linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/tests/local_mounted_during_runtime.fail.sh
d10e36
@@ -0,0 +1,19 @@
d10e36
+#!/bin/bash
d10e36
+
d10e36
+. $SHARED/partition.sh
d10e36
+
d10e36
+# Add nodev option to all records in fstab to ensure that test will
d10e36
+# run on environment where everything is set correctly for rule check.
d10e36
+cp /etc/fstab /etc/fstab.backup
d10e36
+sed -e 's/\bnodev\b/,/g' -e 's/,,//g' -e 's/\s,\s/defaults/g' /etc/fstab.backup
d10e36
+awk '{$4 = $4",nodev"; print}' /etc/fstab.backup > /etc/fstab
d10e36
+# Remount all partitions. (--all option can't be used because it doesn't
d10e36
+# mount e.g. /boot partition
d10e36
+declare -a partitions=( $(awk '{print $2}' /etc/fstab | grep "^/\w") )
d10e36
+for partition in ${partitions[@]}; do
d10e36
+    mount -o remount "$partition"
d10e36
+done
d10e36
+
d10e36
+PARTITION="/dev/new_partition1"; create_partition
d10e36
+mkdir /tmp/test_dir
d10e36
+mount $PARTITION /tmp/test_dir
d10e36
diff --git a/linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/tests/missing_multiple_nodev.fail.sh b/linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/tests/missing_multiple_nodev.fail.sh
d10e36
new file mode 100644
d10e36
index 0000000000..7a09093f46
d10e36
--- /dev/null
d10e36
+++ b/linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/tests/missing_multiple_nodev.fail.sh
d10e36
@@ -0,0 +1,23 @@
d10e36
+#!/bin/bash
d10e36
+
d10e36
+. $SHARED/partition.sh
d10e36
+
d10e36
+# Add nodev option to all records in fstab to ensure that test will
d10e36
+# run on environment where everything is set correctly for rule check.
d10e36
+cp /etc/fstab /etc/fstab.backup
d10e36
+sed -e 's/\bnodev\b/,/g' -e 's/,,//g' -e 's/\s,\s/defaults/g' /etc/fstab.backup
d10e36
+awk '{$4 = $4",nodev"; print}' /etc/fstab.backup > /etc/fstab
d10e36
+# Remount all partitions. (--all option can't be used because it doesn't
d10e36
+# mount e.g. /boot partition
d10e36
+declare -a partitions=( $(awk '{print $2}' /etc/fstab | grep "^/\w") )
d10e36
+for partition in ${partitions[@]}; do
d10e36
+    mount -o remount "$partition"
d10e36
+done
d10e36
+
d10e36
+PARTITION="/dev/new_partition1"; create_partition
d10e36
+make_fstab_given_partition_line "/tmp/partition1" ext2
d10e36
+mount_partition "/tmp/partition1"
d10e36
+
d10e36
+PARTITION="/dev/new_partition2"; create_partition
d10e36
+make_fstab_given_partition_line "/tmp/partition2" ext2
d10e36
+mount_partition "/tmp/partition2"
d10e36
diff --git a/linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/tests/missing_one_nodev.fail.sh b/linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/tests/missing_one_nodev.fail.sh
d10e36
new file mode 100644
d10e36
index 0000000000..c20a98bdcc
d10e36
--- /dev/null
d10e36
+++ b/linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/tests/missing_one_nodev.fail.sh
d10e36
@@ -0,0 +1,23 @@
d10e36
+#!/bin/bash
d10e36
+
d10e36
+. $SHARED/partition.sh
d10e36
+
d10e36
+# Add nodev option to all records in fstab to ensure that test will
d10e36
+# run on environment where everything is set correctly for rule check.
d10e36
+cp /etc/fstab /etc/fstab.backup
d10e36
+sed -e 's/\bnodev\b/,/g' -e 's/,,//g' -e 's/\s,\s/defaults/g' /etc/fstab.backup
d10e36
+awk '{$4 = $4",nodev"; print}' /etc/fstab.backup > /etc/fstab
d10e36
+# Remount all partitions. (--all option can't be used because it doesn't
d10e36
+# mount e.g. /boot partition
d10e36
+declare -a partitions=( $(awk '{print $2}' /etc/fstab | grep "^/\w") )
d10e36
+for partition in ${partitions[@]}; do
d10e36
+    mount -o remount "$partition"
d10e36
+done
d10e36
+
d10e36
+PARTITION="/dev/new_partition1"; create_partition
d10e36
+make_fstab_given_partition_line "/tmp/partition1" ext2 nodev
d10e36
+mount_partition "/tmp/partition1"
d10e36
+
d10e36
+PARTITION="/dev/new_partition2"; create_partition
d10e36
+make_fstab_given_partition_line "/tmp/partition2" ext2
d10e36
+mount_partition "/tmp/partition2"
d10e36
diff --git a/linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/tests/remote_without_nodev.pass.sh b/linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/tests/remote_without_nodev.pass.sh
d10e36
new file mode 100644
d10e36
index 0000000000..a95410526f
d10e36
--- /dev/null
d10e36
+++ b/linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/tests/remote_without_nodev.pass.sh
d10e36
@@ -0,0 +1,25 @@
d10e36
+#!/bin/bash
d10e36
+# packages = nfs-utils
d10e36
+
d10e36
+. $SHARED/partition.sh
d10e36
+
d10e36
+# Add nodev option to all records in fstab to ensure that test will
d10e36
+# run on environment where everything is set correctly for rule check.
d10e36
+cp /etc/fstab /etc/fstab.backup
d10e36
+sed -e 's/\bnodev\b/,/g' -e 's/,,//g' -e 's/\s,\s/defaults/g' /etc/fstab.backup
d10e36
+awk '{$4 = $4",nodev"; print}' /etc/fstab.backup > /etc/fstab
d10e36
+# Remount all partitions. (--all option can't be used because it doesn't
d10e36
+# mount e.g. /boot partition
d10e36
+declare -a partitions=( $(awk '{print $2}' /etc/fstab | grep "^/\w") )
d10e36
+for partition in ${partitions[@]}; do
d10e36
+    mount -o remount "$partition"
d10e36
+done
d10e36
+
d10e36
+mkdir /tmp/testdir
d10e36
+mkdir /tmp/testmount
d10e36
+chown 2 /tmp/testdir
d10e36
+chmod 777 /tmp/testdir
d10e36
+
d10e36
+echo '/tmp/testdir localhost(rw)' > /etc/exports
d10e36
+systemctl restart nfs-server
d10e36
+mount.nfs localhost:/tmp/testdir /tmp/testmount
d10e36
d10e36
From b7bec83d7a3ad186413777f70fe2b5d20e01e56b Mon Sep 17 00:00:00 2001
d10e36
From: Watson Sato <wsato@redhat.com>
d10e36
Date: Wed, 10 Feb 2021 18:32:26 +0100
d10e36
Subject: [PATCH 4/5] Add Ansible for
d10e36
 mount_option_nodev_nonroot_local_partitions
d10e36
d10e36
The remediation metadata were inspired by the template mount_options
d10e36
---
d10e36
 .../ansible/shared.yml                         | 18 ++++++++++++++++++
d10e36
 1 file changed, 18 insertions(+)
d10e36
 create mode 100644 linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/ansible/shared.yml
d10e36
d10e36
diff --git a/linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/ansible/shared.yml b/linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/ansible/shared.yml
d10e36
new file mode 100644
d10e36
index 0000000000..8530604308
d10e36
--- /dev/null
d10e36
+++ b/linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/ansible/shared.yml
d10e36
@@ -0,0 +1,18 @@
d10e36
+# platform = multi_platform_all
d10e36
+# reboot = false
d10e36
+# strategy = configure
d10e36
+# complexity = low
d10e36
+# disruption = high
d10e36
+
d10e36
+- name: Ensure non-root local partitions are mounted with nodev option
d10e36
+  mount:
d10e36
+    path: "{{ item.mount }}"
d10e36
+    src: "{{ item.device}}"
d10e36
+    opts: "{{ item.options }},nodev"
d10e36
+    state: "mounted"
d10e36
+    fstype: "{{ item.fstype }}"
d10e36
+  when:
d10e36
+    - "item.mount is match('/\\w')"
d10e36
+    - "item.options is not search('nodev')"
d10e36
+  with_items:
d10e36
+    - "{{ ansible_facts.mounts }}"
d10e36
d10e36
From dab22894ca0798dde27c77704a7fd34d62d77f8f Mon Sep 17 00:00:00 2001
d10e36
From: Watson Sato <wsato@redhat.com>
d10e36
Date: Wed, 10 Feb 2021 20:29:32 +0100
d10e36
Subject: [PATCH 5/5] Add space before and after variable
d10e36
d10e36
---
d10e36
 .../ansible/shared.yml                                          | 2 +-
d10e36
 1 file changed, 1 insertion(+), 1 deletion(-)
d10e36
d10e36
diff --git a/linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/ansible/shared.yml b/linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/ansible/shared.yml
d10e36
index 8530604308..2aa9a53e4d 100644
d10e36
--- a/linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/ansible/shared.yml
d10e36
+++ b/linux_os/guide/system/permissions/partitions/mount_option_nodev_nonroot_local_partitions/ansible/shared.yml
d10e36
@@ -7,7 +7,7 @@
d10e36
 - name: Ensure non-root local partitions are mounted with nodev option
d10e36
   mount:
d10e36
     path: "{{ item.mount }}"
d10e36
-    src: "{{ item.device}}"
d10e36
+    src: "{{ item.device }}"
d10e36
     opts: "{{ item.options }},nodev"
d10e36
     state: "mounted"
d10e36
     fstype: "{{ item.fstype }}"