• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

m-lab / autojoin / 35609523615
72%
main: 72%

Build:
Build:
LAST BUILD BRANCH: fix/key_perms
DEFAULT BRANCH: main
Ran 21 Sep 2026 02:04PM UTC
Jobs 1
Files 19
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

21 Sep 2026 01:59PM UTC coverage: 71.535% (-0.6%) from 72.152%
35609523615

Pull #103

github

bassosimone
fix(cmd/register): service account key permissions

The service account key is written with 0644 permissions. Because
it is a secret, it should instead be written with 0600.

I noticed this issue when analyzing `byos-debian` where the key is
written to `/var/lib/mlab/node`. The directory itself is `02750` and
this prevents users that are not in the `mlab-node` group from reading
the file. However, in that context, services such as `ndt-server` are
able to read the secret even though they do not need to. This patch
doesn't address that, but I am working on another set of patches
to privilege-separate core services and measurement services.

I did not spend time focusing on whether this was a security issue
for autonode. As regards autonode, my main focus has been trying
to understand whether changing the permissions could break it, and
I concluded that this is not the case (see below).

To address the permissions, this patch does the following:

1. call `os.WriteFile` with `0600`, which covers new files only
while existing files are just truncated w/o a `chmod`

2. `os.Chmod` with `0600` thus covering already existing files

Following the Boy Scout rule, this patch also changes the wording
and spelling of some comments and adds minor style tweaks.

Regarding why I am confident that autonode containers (and namely
`jostler` and `uuid-annotator`) run as root, this is why:

1. the three `Dockefile`s do not specify `USER`

2. there is no `user:` in the `docker-compose.yml`

As such, this change is safe. Even if the file was owned by
another user and had `0600`, root holds `CAP_DAC_OVERRIDE` so
it is able to read the service account key anyway.
Pull Request #103: fix(cmd/register): service account key permissions

0 of 22 new or added lines in 1 file covered. (0.0%)

1 existing line in 1 file now uncovered.

1254 of 1753 relevant lines covered (71.53%)

0.79 hits per line

Uncovered Changes

Lines Coverage ∆ File
22
0.0
0.0% cmd/register/main.go

Coverage Regressions

Lines Coverage ∆ File
1
0.0
0.0% cmd/register/main.go
Jobs
ID Job ID Ran Files Coverage
1 0 - 35609523615.1 21 Sep 2026 02:04PM UTC 19
71.53
GitHub Action Run
Source Files on build 35609523615
  • Tree
  • List 19
  • Changed 1
  • Source Changed 0
  • Coverage Changed 1
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Pull Request #103
  • PR Base - main (#22229108368)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc