Commit Graph
6142 Commits
Author SHA1 Message Date
Josh Hawkins 0f733b5ee5 tweak docs 2026-08-29 17:30:28 -05:00
Josh Hawkins 46c189fced harden against symlink attacks
/config is owned by the unprivileged runtime user after the ownership sweep, so root operations on files there could be redirected by a planted symlink.

- go2rtc HomeKit setup: replace the root yq/jq normalization and chown with an O_NOFOLLOW helper (prepare_homekit.py), so a symlink at go2rtc_homekit.yml can't redirect a root write or chown onto another file
- go2rtc binary override: ignore /config/go2rtc whenever the service runs as root, so a planted binary can't exec as root under FRIGATE_ROOT_SERVICES
- sweep sentinel: read and write it through safe-sentinel, which trusts only a root-owned regular file and never follows a symlink, so it can't be forged to skip the migration or symlinked to clobber a root file
- ownership sweep: chown with -execdir so a parent directory swapped for a symlink mid-walk can't redirect the chown out of the volume
- validate inputs: restrict DEVICE_ACL_PATHS to /dev, require nonzero numeric EXTRA_GROUPS, and reject PUID/PGID that collide with the go2rtc ids
- docs: correct the TLS key ownership note to match what actually happens
2026-08-29 17:26:17 -05:00
Josh Hawkins baa00147b4 group the manual device setup under one section 2026-08-29 16:41:43 -05:00
Josh Hawkins 24411fc4ab link the migration script to the repo 2026-08-29 16:38:05 -05:00
Josh Hawkins 92c4aae7d7 clarify the non-root docs 2026-08-29 16:31:10 -05:00
Josh Hawkins 496327985a stop telling users device access needs host side setup 2026-08-29 16:16:11 -05:00
Josh Hawkins 3f86876630 document automatic device access grants 2026-08-29 15:59:23 -05:00
Josh Hawkins 3c9e77ffb5 assert device access grants in CI 2026-08-29 15:59:23 -05:00
Josh Hawkins d5eca09797 grant runtime users access to mapped device nodes at boot 2026-08-29 15:59:23 -05:00
Josh Hawkins 49f520d3e5 install acl for device access grants 2026-08-29 15:59:23 -05:00
Josh Hawkins b9ce2988d8 clean up 2026-08-29 15:59:23 -05:00
Josh Hawkins 39d2883a87 clarify granular root services docs 2026-08-29 15:59:23 -05:00
Josh Hawkins a572936d91 skip missing media paths in the per-boot ownership sweep 2026-08-29 15:59:23 -05:00
Josh Hawkins 208f606d5a clear the cached runtime ids when ownership tests finish 2026-08-29 15:59:23 -05:00
Josh Hawkins 0c366aeace own every directory level created for a recording segment 2026-08-29 15:59:23 -05:00
Josh Hawkins 9b089c4bcb document FRIGATE_ROOT_SERVICES 2026-08-29 15:59:23 -05:00
Josh Hawkins f873933aab assert granular root services in CI 2026-08-29 15:59:23 -05:00
Josh Hawkins 576949f7c3 recommend FRIGATE_ROOT_SERVICES in the bandwidth stats warning 2026-08-29 15:59:23 -05:00
Josh Hawkins a2883a6509 chown the database files after init 2026-08-29 15:59:23 -05:00
Josh Hawkins 2f450ea661 chown recordings, previews, and exports to the runtime user at create 2026-08-29 15:59:23 -05:00
Josh Hawkins e8b2e06323 cache the runtime ids in the ownership helper 2026-08-29 15:59:23 -05:00
Josh Hawkins 903c59ff8c record the root-services mode in the sentinel and sweep small trees each boot 2026-08-29 15:59:23 -05:00
Josh Hawkins 9d3a38d234 let services listed in FRIGATE_ROOT_SERVICES skip the privilege drop 2026-08-29 15:59:23 -05:00
Josh Hawkins 53ffa72e28 validate FRIGATE_ROOT_SERVICES and fail fast on unknown names 2026-08-29 15:59:23 -05:00
Josh Hawkins dda3730a76 add a service-runs-as-root helper for granular root services 2026-08-29 15:59:23 -05:00
Josh Hawkins d2c9f18d49 collapse the duplicated sentinel comment 2026-08-29 15:59:23 -05:00
Josh Hawkins bc62eb4adc harden root writes into unprivileged-owned paths
Restrict the sweep sentinel to a mount at or below /media/frigate so a
parent /media mount cannot bless a later-shadowed volume. Rebuild
/tmp/nginx root-owned each start so root's cp and tempio writes cannot
follow a symlink an unprivileged nginx planted in the previous run.
2026-08-29 15:59:23 -05:00
Josh Hawkins 17b37a08a9 reload nginx by signaling the master instead of parsing its config as root 2026-08-29 15:59:23 -05:00
Josh Hawkins 2cd51a31a8 make bundled models readable by the runtime user 2026-08-29 15:59:23 -05:00
Josh Hawkins 93470c4ea5 hand /tmp/cache to the runtime user before services start 2026-08-29 15:59:23 -05:00
Josh Hawkins 9e356f1d3f skip lost+found during the ownership sweep 2026-08-29 15:59:23 -05:00
Josh Hawkins 890cd751ae document network storage ownership and the remaining detector hardware 2026-08-29 15:59:23 -05:00
Josh Hawkins 69e30ac3b6 expand the non-root device access docs with diagnosis steps and udev rules 2026-08-29 15:59:23 -05:00
Josh Hawkins 11db4a2756 document EXTRA_GROUPS as the only device access path for dropped services 2026-08-29 15:59:23 -05:00
Josh Hawkins 7f175e1a17 report progress during the ownership sweep 2026-08-29 15:59:23 -05:00
Josh Hawkins f776fffb9e unwrap hard-wrapped prose in the installation docs 2026-08-29 15:59:23 -05:00
Josh Hawkins e8987fc22c discard stdout for the unprivileged smoke nginx -t 2026-08-29 15:59:23 -05:00
Josh Hawkins 04bb2f4ed1 re-own the nginx shm cache on service restart 2026-08-29 15:59:23 -05:00
Josh Hawkins ab393c2cb2 run smoke nginx -t and the write probe as the runtime user 2026-08-29 15:59:23 -05:00
Josh Hawkins 1f68ba0cd4 set HOME to /config for non-root services 2026-08-29 15:59:23 -05:00
Josh Hawkins e7a0743ec0 chown the s6 log pipe so non-root nginx can reopen /dev/stdout 2026-08-29 15:59:23 -05:00
Josh Hawkins 8f5c441239 tolerate homekit config chown failures in the go2rtc run script 2026-08-29 15:59:23 -05:00
Josh Hawkins 8119bea0b3 only write the sweep sentinel when a media volume is mounted 2026-08-29 15:59:23 -05:00
Josh Hawkins b07e36237a Assert non-root services, JWT migration, and escape hatch in CI 2026-08-29 15:59:23 -05:00
Josh Hawkins 55a8672896 Create /media/frigate after the ownership sweep 2026-08-29 15:59:23 -05:00
Josh Hawkins cb5bfe1bd7 Document non-root operation and per-hardware device access 2026-08-29 15:59:23 -05:00
Josh Hawkins 944541f41c Hand TensorRT model cache ownership to the runtime user 2026-08-29 15:59:23 -05:00
Josh Hawkins 5d9f715c35 Disable bandwidth stats gracefully when not running as root 2026-08-29 15:59:23 -05:00
Josh Hawkins b7368197a2 Run nginx as the frigate user with writable state in /tmp/nginx 2026-08-29 15:59:23 -05:00
Josh Hawkins 7530590066 Run go2rtc as its own restricted user 2026-08-29 15:59:23 -05:00