Compare commits
18 Commits
0.2.2
...
db60b4e42b
| Author | SHA1 | Date | |
|---|---|---|---|
| db60b4e42b | |||
|
afc964a076
|
|||
| d42f6d5fe1 | |||
|
103d6159d1
|
|||
|
2ee9588fb9
|
|||
|
a2720e245f
|
|||
|
8e3404bd51
|
|||
|
5ff1e935a3
|
|||
|
7fafb1fa8e
|
|||
|
f87eb5f438
|
|||
|
1c3025b2d6
|
|||
|
4980903572
|
|||
|
a7183b3286
|
|||
|
984aeccfdd
|
|||
|
dc6e7840c7
|
|||
|
0464982b94
|
|||
| 4a4cb8183f | |||
|
20a0dca080
|
61
.gitea/workflows/trivy-scan.yml
Normal file
61
.gitea/workflows/trivy-scan.yml
Normal file
@@ -0,0 +1,61 @@
|
|||||||
|
---
|
||||||
|
name: Trivy Scan
|
||||||
|
on:
|
||||||
|
schedule:
|
||||||
|
- cron: 17 8 * * *
|
||||||
|
workflow_dispatch:
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
security-scan:
|
||||||
|
runs-on: running-man
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Trivy scan via Docker
|
||||||
|
id: trivy
|
||||||
|
continue-on-error: true
|
||||||
|
run: |
|
||||||
|
docker run --rm \
|
||||||
|
--volumes-from "$HOSTNAME" \
|
||||||
|
aquasec/trivy:latest \
|
||||||
|
fs /workspace/guardutils/chguard \
|
||||||
|
--scanners vuln \
|
||||||
|
--pkg-types library \
|
||||||
|
--include-dev-deps \
|
||||||
|
--severity MEDIUM,HIGH,CRITICAL \
|
||||||
|
--ignore-unfixed \
|
||||||
|
--format json \
|
||||||
|
--output /workspace/guardutils/chguard/trivy.json \
|
||||||
|
--exit-code 1
|
||||||
|
|
||||||
|
- name: Notify Node-RED on vulnerabilities
|
||||||
|
if: steps.trivy.outcome == 'failure'
|
||||||
|
run: |
|
||||||
|
jq -r '
|
||||||
|
{
|
||||||
|
repo: "guardutils/chguard",
|
||||||
|
summary: (
|
||||||
|
"Total: " +
|
||||||
|
((.Results[].Vulnerabilities | length) | tostring)
|
||||||
|
),
|
||||||
|
vulnerabilities: [
|
||||||
|
.Results[].Vulnerabilities[] | {
|
||||||
|
library: .PkgName,
|
||||||
|
cve: .VulnerabilityID,
|
||||||
|
severity: .Severity,
|
||||||
|
installed: .InstalledVersion,
|
||||||
|
fixed: .FixedVersion,
|
||||||
|
title: .Title,
|
||||||
|
url: .PrimaryURL
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
' trivy.json \
|
||||||
|
| curl -s -X POST https://nodered.sysmd.uk/trivy-alert \
|
||||||
|
-H "Content-Type: application/json" \
|
||||||
|
--data-binary @-
|
||||||
|
|
||||||
|
- name: Fail workflow if vulnerabilities found
|
||||||
|
if: steps.trivy.outcome == 'failure'
|
||||||
|
run: exit 1
|
||||||
36
README.md
36
README.md
@@ -30,6 +30,31 @@ A single confirmation prompt at the end of a restore (default: **No**).
|
|||||||
### Dry-run mode
|
### Dry-run mode
|
||||||
Preview restore operations without prompting or applying changes.
|
Preview restore operations without prompting or applying changes.
|
||||||
|
|
||||||
|
### Wrapper mode (automatic snapshots)
|
||||||
|
|
||||||
|
`chguard` can also run as a wrapper around ownership and permission commands.
|
||||||
|
In this mode, `chguard` automatically saves a snapshot before the command runs, so the user can easily restore the previous state if needed.
|
||||||
|
|
||||||
|
#### Supported commands
|
||||||
|
|
||||||
|
Wrapper mode is intentionally limited to commands that modify filesystem metadata only:
|
||||||
|
|
||||||
|
* `chown`
|
||||||
|
* `chmod`
|
||||||
|
* `chgrp`
|
||||||
|
|
||||||
|
Other commands are rejected to avoid giving a _false sense of protection_.
|
||||||
|
|
||||||
|
#### Automatic snapshot names
|
||||||
|
|
||||||
|
Snapshots created in wrapper mode are named automatically, for example:
|
||||||
|
|
||||||
|
```
|
||||||
|
auto-20251230-161301
|
||||||
|
```
|
||||||
|
|
||||||
|
Auto-generated snapshots are visually distinguished in the output so they are easy to identify.
|
||||||
|
|
||||||
### Scope control
|
### Scope control
|
||||||
Restore:
|
Restore:
|
||||||
* both ownership and permissions (default)
|
* both ownership and permissions (default)
|
||||||
@@ -55,7 +80,6 @@ Restore:
|
|||||||
|
|
||||||
It only concerns itself with **ownership** and **permissions**.
|
It only concerns itself with **ownership** and **permissions**.
|
||||||
|
|
||||||
|
|
||||||
## Installation
|
## Installation
|
||||||
|
|
||||||
### From GuardUtils package repo
|
### From GuardUtils package repo
|
||||||
@@ -179,6 +203,16 @@ chguard --restore app-baseline --permissions
|
|||||||
chguard --restore app-baseline --owner
|
chguard --restore app-baseline --owner
|
||||||
```
|
```
|
||||||
|
|
||||||
|
### Wrapper mode
|
||||||
|
|
||||||
|
Use `--` to separate `chguard` arguments from the wrapped command:
|
||||||
|
|
||||||
|
```
|
||||||
|
chguard -- chown user:group file
|
||||||
|
chguard -- chmod 755 file
|
||||||
|
chguard -- chgrp staff file
|
||||||
|
```
|
||||||
|
|
||||||
## Privilege model
|
## Privilege model
|
||||||
|
|
||||||
`chguard` never escalates privileges automatically
|
`chguard` never escalates privileges automatically
|
||||||
|
|||||||
139
chguard/cli.py
139
chguard/cli.py
@@ -8,6 +8,7 @@ import sys
|
|||||||
import stat
|
import stat
|
||||||
import pwd
|
import pwd
|
||||||
import grp
|
import grp
|
||||||
|
import subprocess
|
||||||
from collections import Counter, defaultdict
|
from collections import Counter, defaultdict
|
||||||
from pathlib import Path
|
from pathlib import Path
|
||||||
from datetime import datetime
|
from datetime import datetime
|
||||||
@@ -37,7 +38,6 @@ def get_version():
|
|||||||
|
|
||||||
|
|
||||||
def _uid_to_name(uid: int) -> str:
|
def _uid_to_name(uid: int) -> str:
|
||||||
"""Return username for uid, or uid as string if unknown."""
|
|
||||||
try:
|
try:
|
||||||
return pwd.getpwuid(uid).pw_name
|
return pwd.getpwuid(uid).pw_name
|
||||||
except KeyError:
|
except KeyError:
|
||||||
@@ -45,7 +45,6 @@ def _uid_to_name(uid: int) -> str:
|
|||||||
|
|
||||||
|
|
||||||
def _gid_to_name(gid: int) -> str:
|
def _gid_to_name(gid: int) -> str:
|
||||||
"""Return group name for gid, or gid as string if unknown."""
|
|
||||||
try:
|
try:
|
||||||
return grp.getgrgid(gid).gr_name
|
return grp.getgrgid(gid).gr_name
|
||||||
except KeyError:
|
except KeyError:
|
||||||
@@ -53,12 +52,10 @@ def _gid_to_name(gid: int) -> str:
|
|||||||
|
|
||||||
|
|
||||||
def _format_owner(uid: int, gid: int) -> str:
|
def _format_owner(uid: int, gid: int) -> str:
|
||||||
"""Format uid/gid as username:group."""
|
|
||||||
return f"{_uid_to_name(uid)}:{_gid_to_name(gid)}"
|
return f"{_uid_to_name(uid)}:{_gid_to_name(gid)}"
|
||||||
|
|
||||||
|
|
||||||
def _mode_to_rwx(mode: int) -> str:
|
def _mode_to_rwx(mode: int) -> str:
|
||||||
"""Convert numeric mode to rwx-style permissions."""
|
|
||||||
bits = (
|
bits = (
|
||||||
stat.S_IRUSR,
|
stat.S_IRUSR,
|
||||||
stat.S_IWUSR,
|
stat.S_IWUSR,
|
||||||
@@ -88,7 +85,6 @@ def _mode_to_rwx(mode: int) -> str:
|
|||||||
|
|
||||||
|
|
||||||
def _is_root() -> bool:
|
def _is_root() -> bool:
|
||||||
"""Return True if running as root."""
|
|
||||||
return os.geteuid() == 0
|
return os.geteuid() == 0
|
||||||
|
|
||||||
|
|
||||||
@@ -105,6 +101,17 @@ def complete_state_names(prefix, parsed_args, **kwargs):
|
|||||||
return []
|
return []
|
||||||
|
|
||||||
|
|
||||||
|
def _extract_paths_from_command(cmd: list[str]) -> list[Path]:
|
||||||
|
paths = []
|
||||||
|
for arg in cmd:
|
||||||
|
if arg.startswith("-"):
|
||||||
|
continue
|
||||||
|
p = Path(arg)
|
||||||
|
if p.exists():
|
||||||
|
paths.append(p.resolve())
|
||||||
|
return paths
|
||||||
|
|
||||||
|
|
||||||
def main() -> None:
|
def main() -> None:
|
||||||
"""
|
"""
|
||||||
Entry point for the CLI.
|
Entry point for the CLI.
|
||||||
@@ -116,12 +123,33 @@ def main() -> None:
|
|||||||
- Symlinks are skipped during scanning
|
- Symlinks are skipped during scanning
|
||||||
"""
|
"""
|
||||||
|
|
||||||
|
wrapper_cmd = None
|
||||||
|
if "--" in sys.argv:
|
||||||
|
idx = sys.argv.index("--")
|
||||||
|
wrapper_cmd = sys.argv[idx + 1 :]
|
||||||
|
sys.argv = sys.argv[:idx]
|
||||||
|
|
||||||
parser = argparse.ArgumentParser(
|
parser = argparse.ArgumentParser(
|
||||||
prog="chguard",
|
prog="chguard",
|
||||||
description="Snapshot and restore filesystem ownership and permissions.",
|
description="Snapshot and restore filesystem ownership and permissions.",
|
||||||
)
|
)
|
||||||
|
|
||||||
actions = parser.add_mutually_exclusive_group(required=True)
|
parser = argparse.ArgumentParser(
|
||||||
|
prog="chguard",
|
||||||
|
description="Snapshot and restore filesystem ownership and permissions.",
|
||||||
|
epilog=(
|
||||||
|
"Wrapper mode:\n"
|
||||||
|
" chguard -- chown [OPTIONS] PATH...\n"
|
||||||
|
" chguard -- chmod [OPTIONS] PATH...\n"
|
||||||
|
" chguard -- chgrp [OPTIONS] PATH...\n\n"
|
||||||
|
"In wrapper mode, chguard automatically saves a snapshot of ownership\n"
|
||||||
|
"and permissions for the affected paths before running the command.\n"
|
||||||
|
"Only chown, chmod, and chgrp are supported."
|
||||||
|
),
|
||||||
|
formatter_class=argparse.RawDescriptionHelpFormatter,
|
||||||
|
)
|
||||||
|
|
||||||
|
actions = parser.add_mutually_exclusive_group(required=wrapper_cmd is None)
|
||||||
|
|
||||||
parser.add_argument(
|
parser.add_argument(
|
||||||
"--version",
|
"--version",
|
||||||
@@ -216,11 +244,84 @@ def main() -> None:
|
|||||||
|
|
||||||
argcomplete.autocomplete(parser)
|
argcomplete.autocomplete(parser)
|
||||||
args = parser.parse_args()
|
args = parser.parse_args()
|
||||||
|
|
||||||
|
if wrapper_cmd is not None:
|
||||||
|
if not wrapper_cmd:
|
||||||
|
raise SystemExit("No command provided after '--'")
|
||||||
|
|
||||||
|
cmd = Path(wrapper_cmd[0]).name
|
||||||
|
|
||||||
|
if cmd not in ("chown", "chmod", "chgrp"):
|
||||||
|
raise SystemExit(
|
||||||
|
"Wrapper mode only supports chown, chmod, and chgrp"
|
||||||
|
)
|
||||||
|
|
||||||
console = Console()
|
console = Console()
|
||||||
|
|
||||||
conn = connect(Path(args.db).expanduser().resolve() if args.db else None)
|
conn = connect(Path(args.db).expanduser().resolve() if args.db else None)
|
||||||
init_db(conn)
|
init_db(conn)
|
||||||
|
|
||||||
|
if wrapper_cmd:
|
||||||
|
paths = _extract_paths_from_command(wrapper_cmd)
|
||||||
|
if paths:
|
||||||
|
auto_name = f"auto-{datetime.now().strftime('%Y%m%d-%H%M%S')}"
|
||||||
|
with conn:
|
||||||
|
root_path = str(Path(paths[0]).resolve())
|
||||||
|
state_id = create_state(
|
||||||
|
conn, auto_name, root_path, os.getuid(), commit=False
|
||||||
|
)
|
||||||
|
|
||||||
|
for path in paths:
|
||||||
|
if path.is_dir():
|
||||||
|
for entry in scan_tree(path):
|
||||||
|
if entry.uid == 0 and not _is_root():
|
||||||
|
raise SystemExit(
|
||||||
|
"This command affects root-owned files.\n"
|
||||||
|
"Please re-run with sudo."
|
||||||
|
)
|
||||||
|
conn.execute(
|
||||||
|
"""
|
||||||
|
INSERT INTO entries (state_id, path, type, mode, uid, gid)
|
||||||
|
VALUES (?, ?, ?, ?, ?, ?)
|
||||||
|
""",
|
||||||
|
(
|
||||||
|
state_id,
|
||||||
|
entry.path,
|
||||||
|
entry.type,
|
||||||
|
entry.mode,
|
||||||
|
entry.uid,
|
||||||
|
entry.gid,
|
||||||
|
),
|
||||||
|
)
|
||||||
|
else:
|
||||||
|
st = path.lstat()
|
||||||
|
if st.st_uid == 0 and not _is_root():
|
||||||
|
raise SystemExit(
|
||||||
|
"This command affects root-owned files.\n"
|
||||||
|
"Please re-run with sudo."
|
||||||
|
)
|
||||||
|
conn.execute(
|
||||||
|
"""
|
||||||
|
INSERT INTO entries (state_id, path, type, mode, uid, gid)
|
||||||
|
VALUES (?, ?, ?, ?, ?, ?)
|
||||||
|
""",
|
||||||
|
(
|
||||||
|
state_id,
|
||||||
|
str(path),
|
||||||
|
"file",
|
||||||
|
stat.S_IMODE(st.st_mode),
|
||||||
|
st.st_uid,
|
||||||
|
st.st_gid,
|
||||||
|
),
|
||||||
|
)
|
||||||
|
|
||||||
|
console.print(
|
||||||
|
f"Saved pre-command snapshot: [cyan]{auto_name}[/cyan]"
|
||||||
|
)
|
||||||
|
|
||||||
|
proc = subprocess.run(wrapper_cmd)
|
||||||
|
sys.exit(proc.returncode)
|
||||||
|
|
||||||
if args.list:
|
if args.list:
|
||||||
rows = conn.execute(
|
rows = conn.execute(
|
||||||
"SELECT name, root_path, created_at FROM states ORDER BY created_at DESC"
|
"SELECT name, root_path, created_at FROM states ORDER BY created_at DESC"
|
||||||
@@ -230,11 +331,31 @@ def main() -> None:
|
|||||||
console.print("No saved states.")
|
console.print("No saved states.")
|
||||||
return
|
return
|
||||||
|
|
||||||
|
table = Table(box=box.SIMPLE, header_style="bold")
|
||||||
|
|
||||||
|
table.add_column("State")
|
||||||
|
table.add_column("Root path")
|
||||||
|
table.add_column("Created")
|
||||||
|
|
||||||
for name, root, created in rows:
|
for name, root, created in rows:
|
||||||
dt = datetime.fromisoformat(created)
|
dt = datetime.fromisoformat(created)
|
||||||
ts = dt.strftime("%Y-%m-%d %H:%M:%S %z")
|
ts = dt.strftime("%Y-%m-%d %H:%M:%S %z")
|
||||||
console.print(f"{name}\t{root}\t[dim]{ts}[/dim]")
|
|
||||||
return
|
state_name = (
|
||||||
|
f"[bright_cyan]{name}[/bright_cyan]"
|
||||||
|
if name.startswith("auto-")
|
||||||
|
else name
|
||||||
|
)
|
||||||
|
root = f"[bright_magenta]{root}[/bright_magenta]"
|
||||||
|
ts = f"[bright_cyan]{created}[/bright_cyan]"
|
||||||
|
|
||||||
|
table.add_row(
|
||||||
|
state_name,
|
||||||
|
root,
|
||||||
|
ts,
|
||||||
|
)
|
||||||
|
|
||||||
|
console.print(table)
|
||||||
|
|
||||||
if args.delete:
|
if args.delete:
|
||||||
if delete_state(conn, args.delete) == 0:
|
if delete_state(conn, args.delete) == 0:
|
||||||
@@ -346,7 +467,7 @@ def main() -> None:
|
|||||||
] = f"{_format_owner(bu, bg)} → {_format_owner(au, ag)}"
|
] = f"{_format_owner(bu, bg)} → {_format_owner(au, ag)}"
|
||||||
counts["owner"] += 1
|
counts["owner"] += 1
|
||||||
|
|
||||||
if au != current_uid:
|
if ch.path.stat().st_uid != current_uid:
|
||||||
needs_root = True
|
needs_root = True
|
||||||
|
|
||||||
elif ch.kind == "mode" and restore_permissions:
|
elif ch.kind == "mode" and restore_permissions:
|
||||||
|
|||||||
16
poetry.lock
generated
16
poetry.lock
generated
@@ -38,13 +38,13 @@ files = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "filelock"
|
name = "filelock"
|
||||||
version = "3.20.1"
|
version = "3.20.3"
|
||||||
description = "A platform independent file lock."
|
description = "A platform independent file lock."
|
||||||
optional = false
|
optional = false
|
||||||
python-versions = ">=3.10"
|
python-versions = ">=3.10"
|
||||||
files = [
|
files = [
|
||||||
{file = "filelock-3.20.1-py3-none-any.whl", hash = "sha256:15d9e9a67306188a44baa72f569d2bfd803076269365fdea0934385da4dc361a"},
|
{file = "filelock-3.20.3-py3-none-any.whl", hash = "sha256:4b0dda527ee31078689fc205ec4f1c1bf7d56cf88b6dc9426c4f230e46c2dce1"},
|
||||||
{file = "filelock-3.20.1.tar.gz", hash = "sha256:b8360948b351b80f420878d8516519a2204b07aefcdcfd24912a5d33127f188c"},
|
{file = "filelock-3.20.3.tar.gz", hash = "sha256:18c57ee915c7ec61cff0ecf7f0f869936c7c30191bb0cf406f1341778d0834e1"},
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
@@ -267,18 +267,18 @@ files = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "virtualenv"
|
name = "virtualenv"
|
||||||
version = "20.35.4"
|
version = "20.36.1"
|
||||||
description = "Virtual Python Environment builder"
|
description = "Virtual Python Environment builder"
|
||||||
optional = false
|
optional = false
|
||||||
python-versions = ">=3.8"
|
python-versions = ">=3.8"
|
||||||
files = [
|
files = [
|
||||||
{file = "virtualenv-20.35.4-py3-none-any.whl", hash = "sha256:c21c9cede36c9753eeade68ba7d523529f228a403463376cf821eaae2b650f1b"},
|
{file = "virtualenv-20.36.1-py3-none-any.whl", hash = "sha256:575a8d6b124ef88f6f51d56d656132389f961062a9177016a50e4f507bbcc19f"},
|
||||||
{file = "virtualenv-20.35.4.tar.gz", hash = "sha256:643d3914d73d3eeb0c552cbb12d7e82adf0e504dbf86a3182f8771a153a1971c"},
|
{file = "virtualenv-20.36.1.tar.gz", hash = "sha256:8befb5c81842c641f8ee658481e42641c68b5eab3521d8e092d18320902466ba"},
|
||||||
]
|
]
|
||||||
|
|
||||||
[package.dependencies]
|
[package.dependencies]
|
||||||
distlib = ">=0.3.7,<1"
|
distlib = ">=0.3.7,<1"
|
||||||
filelock = ">=3.12.2,<4"
|
filelock = {version = ">=3.20.1,<4", markers = "python_version >= \"3.10\""}
|
||||||
platformdirs = ">=3.9.1,<5"
|
platformdirs = ">=3.9.1,<5"
|
||||||
typing-extensions = {version = ">=4.13.2", markers = "python_version < \"3.11\""}
|
typing-extensions = {version = ">=4.13.2", markers = "python_version < \"3.11\""}
|
||||||
|
|
||||||
@@ -289,4 +289,4 @@ test = ["covdefaults (>=2.3)", "coverage (>=7.2.7)", "coverage-enable-subprocess
|
|||||||
[metadata]
|
[metadata]
|
||||||
lock-version = "2.0"
|
lock-version = "2.0"
|
||||||
python-versions = ">=3.10,<4.0"
|
python-versions = ">=3.10,<4.0"
|
||||||
content-hash = "4a5c993fcc16fe3739c43eb00bed750ce0803d45e37c7a786aa0b83bb4930267"
|
content-hash = "8cfa38f4e2f17dba430ea08f7be3c91890a0c7a4535b69d9565b84d714f589bc"
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
[tool.poetry]
|
[tool.poetry]
|
||||||
name = "chguard"
|
name = "chguard"
|
||||||
version = "0.2.2"
|
version = "0.3.3"
|
||||||
description = "Safety-first tool to snapshot and restore filesystem ownership and permissions."
|
description = "Safety-first tool to snapshot and restore filesystem ownership and permissions."
|
||||||
authors = ["Marco D'Aleo <marco@marcodaleo.com>"]
|
authors = ["Marco D'Aleo <marco@marcodaleo.com>"]
|
||||||
license = "GPL-3.0-or-later"
|
license = "GPL-3.0-or-later"
|
||||||
@@ -12,8 +12,8 @@ repository = "https://git.sysmd.uk/guardutils/chguard"
|
|||||||
python = ">=3.10,<4.0"
|
python = ">=3.10,<4.0"
|
||||||
rich = ">=12"
|
rich = ">=12"
|
||||||
argcomplete = ">=2"
|
argcomplete = ">=2"
|
||||||
platformdirs = ">=4.5.1"
|
platformdirs = ">=4.2.2"
|
||||||
filelock = ">=3.20.1"
|
filelock = ">=3.15.4"
|
||||||
|
|
||||||
[tool.poetry.scripts]
|
[tool.poetry.scripts]
|
||||||
chguard = "chguard.cli:main"
|
chguard = "chguard.cli:main"
|
||||||
|
|||||||
Reference in New Issue
Block a user