mirror of
https://github.com/blakeblackshear/frigate.git
synced 2026-09-28 10:56:52 +03:00
* Run the frigate service as the frigate user * Run go2rtc as its own restricted user * Run nginx as the frigate user with writable state in /tmp/nginx * Disable bandwidth stats gracefully when not running as root * Hand TensorRT model cache ownership to the runtime user * Document non-root operation and per-hardware device access * Create /media/frigate after the ownership sweep * Assert non-root services, JWT migration, and escape hatch in CI * only write the sweep sentinel when a media volume is mounted * tolerate homekit config chown failures in the go2rtc run script * chown the s6 log pipe so non-root nginx can reopen /dev/stdout * set HOME to /config for non-root services * run smoke nginx -t and the write probe as the runtime user * re-own the nginx shm cache on service restart * discard stdout for the unprivileged smoke nginx -t * unwrap hard-wrapped prose in the installation docs * report progress during the ownership sweep * document EXTRA_GROUPS as the only device access path for dropped services * expand the non-root device access docs with diagnosis steps and udev rules * document network storage ownership and the remaining detector hardware * skip lost+found during the ownership sweep * hand /tmp/cache to the runtime user before services start * make bundled models readable by the runtime user * reload nginx by signaling the master instead of parsing its config as root * harden root writes into unprivileged-owned paths Restrict the sweep sentinel to a mount at or below /media/frigate so a parent /media mount cannot bless a later-shadowed volume. Rebuild /tmp/nginx root-owned each start so root's cp and tempio writes cannot follow a symlink an unprivileged nginx planted in the previous run. * collapse the duplicated sentinel comment * add a service-runs-as-root helper for granular root services * validate FRIGATE_ROOT_SERVICES and fail fast on unknown names * let services listed in FRIGATE_ROOT_SERVICES skip the privilege drop * record the root-services mode in the sentinel and sweep small trees each boot * cache the runtime ids in the ownership helper * chown recordings, previews, and exports to the runtime user at create * chown the database files after init * recommend FRIGATE_ROOT_SERVICES in the bandwidth stats warning * assert granular root services in CI * document FRIGATE_ROOT_SERVICES * own every directory level created for a recording segment * clear the cached runtime ids when ownership tests finish * skip missing media paths in the per-boot ownership sweep * clarify granular root services docs * clean up * install acl for device access grants * grant runtime users access to mapped device nodes at boot * assert device access grants in CI * document automatic device access grants * stop telling users device access needs host side setup * clarify the non-root docs * link the migration script to the repo * group the manual device setup under one section * harden against symlink attacks /config is owned by the unprivileged runtime user after the ownership sweep, so root operations on files there could be redirected by a planted symlink. - go2rtc HomeKit setup: replace the root yq/jq normalization and chown with an O_NOFOLLOW helper (prepare_homekit.py), so a symlink at go2rtc_homekit.yml can't redirect a root write or chown onto another file - go2rtc binary override: ignore /config/go2rtc whenever the service runs as root, so a planted binary can't exec as root under FRIGATE_ROOT_SERVICES - sweep sentinel: read and write it through safe-sentinel, which trusts only a root-owned regular file and never follows a symlink, so it can't be forged to skip the migration or symlinked to clobber a root file - ownership sweep: chown with -execdir so a parent directory swapped for a symlink mid-walk can't redirect the chown out of the volume - validate inputs: restrict DEVICE_ACL_PATHS to /dev, require nonzero numeric EXTRA_GROUPS, and reject PUID/PGID that collide with the go2rtc ids - docs: correct the TLS key ownership note to match what actually happens * tweak docs * stop the ownership sweep chasing entries other mechanisms own * keep custom binaries out of root services only under granular root
78 lines
3.1 KiB
Python
78 lines
3.1 KiB
Python
"""Tests for runtime ownership helpers."""
|
|
|
|
import unittest
|
|
from unittest.mock import patch
|
|
|
|
from frigate.util import ownership
|
|
|
|
|
|
class FakePwEntry:
|
|
pw_uid = 1500
|
|
pw_gid = 1500
|
|
|
|
|
|
# The devcontainer image exports FRIGATE_RUN_AS_ROOT, so any test that has to
|
|
# reach past the escape-hatch check pins the variable instead of inheriting it.
|
|
class TestGetRuntimeIds(unittest.TestCase):
|
|
def setUp(self) -> None:
|
|
ownership.get_runtime_ids.cache_clear()
|
|
# a value cached under this test's patches must not leak into later modules
|
|
self.addCleanup(ownership.get_runtime_ids.cache_clear)
|
|
|
|
@patch("frigate.util.ownership.os.geteuid", return_value=1000)
|
|
def test_returns_none_when_not_root(self, _):
|
|
assert ownership.get_runtime_ids() is None
|
|
|
|
@patch.dict("os.environ", {"FRIGATE_RUN_AS_ROOT": "true"})
|
|
@patch("frigate.util.ownership.os.geteuid", return_value=0)
|
|
def test_returns_none_with_escape_hatch(self, _):
|
|
assert ownership.get_runtime_ids() is None
|
|
|
|
@patch.dict("os.environ", {"FRIGATE_RUN_AS_ROOT": "false"})
|
|
@patch("frigate.util.ownership.pwd.getpwnam", side_effect=KeyError)
|
|
@patch("frigate.util.ownership.os.geteuid", return_value=0)
|
|
def test_returns_none_outside_frigate_image(self, *_):
|
|
assert ownership.get_runtime_ids() is None
|
|
|
|
@patch.dict("os.environ", {"FRIGATE_RUN_AS_ROOT": "false"})
|
|
@patch("frigate.util.ownership.pwd.getpwnam", return_value=FakePwEntry())
|
|
@patch("frigate.util.ownership.os.geteuid", return_value=0)
|
|
def test_returns_frigate_ids_as_root(self, *_):
|
|
assert ownership.get_runtime_ids() == (1500, 1500)
|
|
|
|
@patch.dict("os.environ", {"FRIGATE_RUN_AS_ROOT": "false"})
|
|
@patch("frigate.util.ownership.pwd.getpwnam", return_value=FakePwEntry())
|
|
@patch("frigate.util.ownership.os.geteuid", return_value=0)
|
|
def test_caches_lookup(self, _geteuid, getpwnam):
|
|
assert ownership.get_runtime_ids() == (1500, 1500)
|
|
assert ownership.get_runtime_ids() == (1500, 1500)
|
|
getpwnam.assert_called_once()
|
|
|
|
|
|
class TestChownToRuntime(unittest.TestCase):
|
|
def setUp(self) -> None:
|
|
ownership.get_runtime_ids.cache_clear()
|
|
# a value cached under this test's patches must not leak into later modules
|
|
self.addCleanup(ownership.get_runtime_ids.cache_clear)
|
|
|
|
@patch("frigate.util.ownership.os.chown")
|
|
@patch("frigate.util.ownership.get_runtime_ids", return_value=None)
|
|
def test_noop_when_no_runtime_ids(self, _, chown):
|
|
ownership.chown_to_runtime("/config/test")
|
|
chown.assert_not_called()
|
|
|
|
@patch("frigate.util.ownership.os.chown")
|
|
@patch("frigate.util.ownership.get_runtime_ids", return_value=(1500, 1500))
|
|
def test_chowns_to_runtime_ids(self, _, chown):
|
|
ownership.chown_to_runtime("/config/test")
|
|
chown.assert_called_once_with("/config/test", 1500, 1500)
|
|
|
|
@patch("frigate.util.ownership.os.chown", side_effect=OSError("ro fs"))
|
|
@patch("frigate.util.ownership.get_runtime_ids", return_value=(1500, 1500))
|
|
def test_swallows_oserror(self, *_):
|
|
ownership.chown_to_runtime("/config/test") # must not raise
|
|
|
|
|
|
if __name__ == "__main__":
|
|
unittest.main()
|