Skip to content

remove test environment variables from installed prolog and housekeeping scripts - #35

Merged
mergify[bot] merged 4 commits into
flux-framework:mainfrom
grondo:harden-test-hooks
Oct 3, 2026
Merged

mergify[bot] merged 4 commits into
flux-framework:mainfrom
grondo:harden-test-hooks

Conversation

@grondo

@grondo grondo commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Problem: The flux-pam tests use FLUX_PAM_TEST_* environment variables to invoke mock systemctl and loginctl commands to get better coverage. These variables survive into the final installed scripts, and the prefix matches the suggested allow-environment glob in tbe IMP config: FLUX_*. While users probably can't influence the environment here, defense-in-depth dictates that these overrides are an open security hole.

This PR renames the test env vars with a leading _ (_FLUX_PAM_TEST_*) and additionally removes support for the variables entirely in the installed scripts. This closes the hole even in the case non-stripped scripts get inadvertently installed.

@grondo
grondo force-pushed the harden-test-hooks branch 3 times, most recently from 95ca4e5 to 9c01f92 Compare October 2, 2026 22:54

@garlick garlick left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@grondo

grondo commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

Excellent. Thanks for all the quick reviews.

@grondo grondo added the merge-when-passing mergify will merge this PR once all tests are passing label Oct 3, 2026
@mergify mergify Bot added the queued label Oct 3, 2026
@mergify

mergify Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Merge Queue Status

  • ✅ Entered queue — 2026-10-03 00:23 UTC · Rule: default · triggered by rule default
  • ✅ Checks passed · in-place
  • ✅ Merged — 2026-10-03 00:31 UTC · at 3dd083808cc451a333a4191f00c86a4a11073467 · merge

This pull request spent 8 minutes 28 seconds in the queue, including 4 minutes 13 seconds running CI.

Required conditions to merge

grondo added 4 commits October 3, 2026 00:27
Problem: flux-pam tests use FLUX_PAM_TEST_* environment variables
to point prolog and housekeeping to mock systemctl and loginctl
programs. This introduces an unnecessary risk since the documented
allowed-environment glob for prolog and housekeeping is FLUX_*,
which allows these environment variables to leak inadvertently in
production. While there is no way these variables could be set by
an untrusted user, defense-in-depth dictates that these test-only
variables should not share the same prefix as actual Flux environment
variables.

Rename the test environment variables with a leading underscore
`_FLUX_PAM_TEST_*` so they don't match the standard pattern.

Update affected tests.

Assisted-by: Claude:Opus-5
Problem: The installed prolog and housekeeping scripts carry the
_FLUX_PAM_TEST_* lookups that redirect systemctl and loginctl at a mock.
Renaming them out of the FLUX_* namespace keeps flux-imp from passing
them through, but the mechanism is still present in code that runs as
root, where it has no use: the testsuite runs the scripts from the build
tree, never the installed copies.

Generate an .inst copy of each script at build time with every lookup
replaced by the path found by configure. Install this version so it
has no possibility of overriding paths of programs run as root.

Assisted-by: Claude:Opus-5
Problem: The generated prolog and housekeeping scripts show up as
untracked, and the .inst copies built alongside them now do too.

Add all three patterns to .gitignore.

Assisted-by: Claude:Opus-5
Problem: Nothing verifies that the installed prolog and housekeeping
scripts have the test path overrides stripped.

Add checks against the generated scripts in inst/ to ensure the
environment overrides have been stripped and they are still valid
Python.

Assisted-by: Claude:Opus-5
@mergify
mergify Bot force-pushed the harden-test-hooks branch from 9c01f92 to 1d9d5b0 Compare October 3, 2026 00:27
@mergify
mergify Bot merged commit 3dd0838 into flux-framework:main Oct 3, 2026
11 of 12 checks passed
@mergify mergify Bot removed the queued label Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

merge-when-passing mergify will merge this PR once all tests are passing

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants