Josh Hawkins
46c189fced
harden against symlink attacks
...
/config is owned by the unprivileged runtime user after the ownership sweep, so root operations on files there could be redirected by a planted symlink.
- go2rtc HomeKit setup: replace the root yq/jq normalization and chown with an O_NOFOLLOW helper (prepare_homekit.py), so a symlink at go2rtc_homekit.yml can't redirect a root write or chown onto another file
- go2rtc binary override: ignore /config/go2rtc whenever the service runs as root, so a planted binary can't exec as root under FRIGATE_ROOT_SERVICES
- sweep sentinel: read and write it through safe-sentinel, which trusts only a root-owned regular file and never follows a symlink, so it can't be forged to skip the migration or symlinked to clobber a root file
- ownership sweep: chown with -execdir so a parent directory swapped for a symlink mid-walk can't redirect the chown out of the volume
- validate inputs: restrict DEVICE_ACL_PATHS to /dev, require nonzero numeric EXTRA_GROUPS, and reject PUID/PGID that collide with the go2rtc ids
- docs: correct the TLS key ownership note to match what actually happens
2026-08-29 17:26:17 -05:00
Josh Hawkins
baa00147b4
group the manual device setup under one section
2026-08-29 16:41:43 -05:00
Josh Hawkins
24411fc4ab
link the migration script to the repo
2026-08-29 16:38:05 -05:00
Josh Hawkins
92c4aae7d7
clarify the non-root docs
2026-08-29 16:31:10 -05:00
Josh Hawkins
496327985a
stop telling users device access needs host side setup
2026-08-29 16:16:11 -05:00
Josh Hawkins
3f86876630
document automatic device access grants
2026-08-29 15:59:23 -05:00
Josh Hawkins
3c9e77ffb5
assert device access grants in CI
2026-08-29 15:59:23 -05:00
Josh Hawkins
d5eca09797
grant runtime users access to mapped device nodes at boot
2026-08-29 15:59:23 -05:00
Josh Hawkins
49f520d3e5
install acl for device access grants
2026-08-29 15:59:23 -05:00
Josh Hawkins
b9ce2988d8
clean up
2026-08-29 15:59:23 -05:00
Josh Hawkins
39d2883a87
clarify granular root services docs
2026-08-29 15:59:23 -05:00
Josh Hawkins
a572936d91
skip missing media paths in the per-boot ownership sweep
2026-08-29 15:59:23 -05:00
Josh Hawkins
208f606d5a
clear the cached runtime ids when ownership tests finish
2026-08-29 15:59:23 -05:00
Josh Hawkins
0c366aeace
own every directory level created for a recording segment
2026-08-29 15:59:23 -05:00
Josh Hawkins
9b089c4bcb
document FRIGATE_ROOT_SERVICES
2026-08-29 15:59:23 -05:00
Josh Hawkins
f873933aab
assert granular root services in CI
2026-08-29 15:59:23 -05:00
Josh Hawkins
576949f7c3
recommend FRIGATE_ROOT_SERVICES in the bandwidth stats warning
2026-08-29 15:59:23 -05:00
Josh Hawkins
a2883a6509
chown the database files after init
2026-08-29 15:59:23 -05:00
Josh Hawkins
2f450ea661
chown recordings, previews, and exports to the runtime user at create
2026-08-29 15:59:23 -05:00
Josh Hawkins
e8b2e06323
cache the runtime ids in the ownership helper
2026-08-29 15:59:23 -05:00
Josh Hawkins
903c59ff8c
record the root-services mode in the sentinel and sweep small trees each boot
2026-08-29 15:59:23 -05:00
Josh Hawkins
9d3a38d234
let services listed in FRIGATE_ROOT_SERVICES skip the privilege drop
2026-08-29 15:59:23 -05:00
Josh Hawkins
53ffa72e28
validate FRIGATE_ROOT_SERVICES and fail fast on unknown names
2026-08-29 15:59:23 -05:00
Josh Hawkins
dda3730a76
add a service-runs-as-root helper for granular root services
2026-08-29 15:59:23 -05:00
Josh Hawkins
d2c9f18d49
collapse the duplicated sentinel comment
2026-08-29 15:59:23 -05:00
Josh Hawkins
bc62eb4adc
harden root writes into unprivileged-owned paths
...
Restrict the sweep sentinel to a mount at or below /media/frigate so a
parent /media mount cannot bless a later-shadowed volume. Rebuild
/tmp/nginx root-owned each start so root's cp and tempio writes cannot
follow a symlink an unprivileged nginx planted in the previous run.
2026-08-29 15:59:23 -05:00
Josh Hawkins
17b37a08a9
reload nginx by signaling the master instead of parsing its config as root
2026-08-29 15:59:23 -05:00
Josh Hawkins
2cd51a31a8
make bundled models readable by the runtime user
2026-08-29 15:59:23 -05:00
Josh Hawkins
93470c4ea5
hand /tmp/cache to the runtime user before services start
2026-08-29 15:59:23 -05:00
Josh Hawkins
9e356f1d3f
skip lost+found during the ownership sweep
2026-08-29 15:59:23 -05:00
Josh Hawkins
890cd751ae
document network storage ownership and the remaining detector hardware
2026-08-29 15:59:23 -05:00
Josh Hawkins
69e30ac3b6
expand the non-root device access docs with diagnosis steps and udev rules
2026-08-29 15:59:23 -05:00
Josh Hawkins
11db4a2756
document EXTRA_GROUPS as the only device access path for dropped services
2026-08-29 15:59:23 -05:00
Josh Hawkins
7f175e1a17
report progress during the ownership sweep
2026-08-29 15:59:23 -05:00
Josh Hawkins
f776fffb9e
unwrap hard-wrapped prose in the installation docs
2026-08-29 15:59:23 -05:00
Josh Hawkins
e8987fc22c
discard stdout for the unprivileged smoke nginx -t
2026-08-29 15:59:23 -05:00
Josh Hawkins
04bb2f4ed1
re-own the nginx shm cache on service restart
2026-08-29 15:59:23 -05:00
Josh Hawkins
ab393c2cb2
run smoke nginx -t and the write probe as the runtime user
2026-08-29 15:59:23 -05:00
Josh Hawkins
1f68ba0cd4
set HOME to /config for non-root services
2026-08-29 15:59:23 -05:00
Josh Hawkins
e7a0743ec0
chown the s6 log pipe so non-root nginx can reopen /dev/stdout
2026-08-29 15:59:23 -05:00
Josh Hawkins
8f5c441239
tolerate homekit config chown failures in the go2rtc run script
2026-08-29 15:59:23 -05:00
Josh Hawkins
8119bea0b3
only write the sweep sentinel when a media volume is mounted
2026-08-29 15:59:23 -05:00
Josh Hawkins
b07e36237a
Assert non-root services, JWT migration, and escape hatch in CI
2026-08-29 15:59:23 -05:00
Josh Hawkins
55a8672896
Create /media/frigate after the ownership sweep
2026-08-29 15:59:23 -05:00
Josh Hawkins
cb5bfe1bd7
Document non-root operation and per-hardware device access
2026-08-29 15:59:23 -05:00
Josh Hawkins
944541f41c
Hand TensorRT model cache ownership to the runtime user
2026-08-29 15:59:23 -05:00
Josh Hawkins
5d9f715c35
Disable bandwidth stats gracefully when not running as root
2026-08-29 15:59:23 -05:00
Josh Hawkins
b7368197a2
Run nginx as the frigate user with writable state in /tmp/nginx
2026-08-29 15:59:23 -05:00
Josh Hawkins
7530590066
Run go2rtc as its own restricted user
2026-08-29 15:59:23 -05:00
Josh Hawkins
9ce146fd99
Run the frigate service as the frigate user
2026-08-29 15:59:23 -05:00