Provision and mount the spool WAL disk for producer instances - #3993
Conversation
|
|
||
| prepare_wal_dir() { | ||
| mkdir -p "${WAL_HOST_MOUNT}" | ||
| chmod 0777 "${WAL_HOST_MOUNT}" |
There was a problem hiding this comment.
⚪ Severity: LOW
chmod 0777 makes the host-backed WAL directory writable by every local user or process. A process with a local foothold can replace or delete WAL segments, or plant symlinks before RotatingWal opens them, corrupting queued production logs or causing writes to attacker-selected host paths.
Helpful? Add 👍 / 👎
💡 Fix Suggestion
Suggestion: Replace chmod 0777 with chmod 0700 to restrict the WAL directory to the owning user (root, since this is a GCE startup script) only. World-writable and group-writable bits are unnecessary because the Docker container is launched with --privileged and runs as root, so it has full access to a root-owned 0700 directory via the bind-mount. This eliminates the risk of any other local user or process tampering with, replacing, or planting symlinks inside the WAL directory.
⚠️ Experimental Feature: This code suggestion is automatically generated. Please review carefully.
| chmod 0777 "${WAL_HOST_MOUNT}" | |
| chmod 0700 "${WAL_HOST_MOUNT}" |
4f0fad2 to
0ba4a4a
Compare
0ba4a4a to
c2e91ab
Compare
Adds GCE startup/deploy plumbing to attach and mount a persistent disk for the spool producer's local WAL directory, and wires SPOOL_MODE/ instance-type substitutions through the staging deploy targets. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
c2e91ab to
bc607d5
Compare
Adds GCE startup/deploy plumbing to attach and mount a persistent disk for the spool producer's local WAL directory, and wires SPOOL_MODE/ instance-type substitutions through the staging deploy targets.