Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion jobs/loggr-system-metrics-agent/templates/ctl.erb
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,8 @@ mkdir -p $LOG_DIR
case $1 in

start)
source /var/vcap/packages/system-metrics-agent/scripts/privdrop_utils.sh

set +e
killall -15 system-metrics-agent
killall -9 system-metrics-agent
Expand All @@ -40,7 +42,7 @@ case $1 in
CA_CERT_PATH="/var/vcap/jobs/loggr-system-metrics-agent/config/certs/system_metrics_agent_ca.crt" \
CERT_PATH="/var/vcap/jobs/loggr-system-metrics-agent/config/certs/system_metrics_agent.crt" \
KEY_PATH="/var/vcap/jobs/loggr-system-metrics-agent/config/certs/system_metrics_agent.key" \
chpst -u vcap:vcap /var/vcap/packages/system-metrics-agent/system-metrics-agent &
run_as_vcap /var/vcap/packages/system-metrics-agent/system-metrics-agent &

echo $! > $PIDFILE

Expand Down
4 changes: 4 additions & 0 deletions packages/system-metrics-agent/packaging
Original file line number Diff line number Diff line change
Expand Up @@ -4,3 +4,7 @@ source /var/vcap/packages/golang-1.27-linux/bosh/compile.env
export GOPATH=/var/vcap

go build -mod=vendor -o ${BOSH_INSTALL_TARGET}/system-metrics-agent ./cmd/system-metrics-agent

mkdir -p ${BOSH_INSTALL_TARGET}/scripts
cp scripts/privdrop_utils.sh ${BOSH_INSTALL_TARGET}/scripts/privdrop_utils.sh
chmod +x ${BOSH_INSTALL_TARGET}/scripts/privdrop_utils.sh
1 change: 1 addition & 0 deletions packages/system-metrics-agent/spec
Original file line number Diff line number Diff line change
Expand Up @@ -9,3 +9,4 @@ files:
- vendor/**/*
- go.mod
- go.sum
- scripts/**/*
15 changes: 15 additions & 0 deletions spec/jobs/loggr_system_metrics_agent_spec.rb
Original file line number Diff line number Diff line change
Expand Up @@ -64,6 +64,21 @@ def render_system_metrics_monit(properties = {})
describe 'bin/ctl' do
let(:template) { job.template('bin/ctl') }

it 'sources privdrop_utils.sh from the system-metrics-agent package' do
rendered = template.render({})
expect(rendered).to include('source /var/vcap/packages/system-metrics-agent/scripts/privdrop_utils.sh')
end

it 'runs system-metrics-agent using run_as_vcap' do
rendered = template.render({})
expect(rendered).to match(/run_as_vcap \/var\/vcap\/packages\/system-metrics-agent\/system-metrics-agent &/)
end

it 'does not use chpst' do
rendered = template.render({})
expect(rendered).not_to include('chpst')
end

it 'defaults CLOCK_DRIFT_ENABLED to false' do
rendered = template.render({})
expect(rendered).to include('CLOCK_DRIFT_ENABLED=false')
Expand Down
8 changes: 8 additions & 0 deletions src/scripts/privdrop_utils.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
#!/usr/bin/env bash

# run_as_vcap
#
# Exec-style replacement for `chpst -u vcap:vcap "$@"`.
function run_as_vcap() {
setpriv --reuid=vcap --regid=vcap --clear-groups --no-new-privs -- "$@"
}
30 changes: 30 additions & 0 deletions src/scripts/privdrop_utils_test.bats
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
#!/usr/bin/env bats

setup() {
source ./privdrop_utils.sh
}

@test "run_as_vcap runs the given command as the vcap user" {
run run_as_vcap id -un
[ "$status" -eq 0 ]
[ "$output" = "vcap" ]
}

@test "run_as_vcap runs the given command as the vcap group" {
run run_as_vcap id -gn
[ "$status" -eq 0 ]
[ "$output" = "vcap" ]
}

@test "run_as_vcap preserves multiple arguments without re-quoting" {
run run_as_vcap echo one two three
[ "$status" -eq 0 ]
[ "$output" = "one two three" ]
}

@test "run_as_vcap preserves exported environment variables" {
export PRIVDROP_TEST_VAR="some_value"
run run_as_vcap sh -c 'echo "$PRIVDROP_TEST_VAR"'
[ "$status" -eq 0 ]
[ "$output" = "some_value" ]
}
Loading