• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

m-lab / autojoin
72%

Build:
DEFAULT BRANCH: main
Repo Added 12 Feb 2024 04:25PM UTC
Files 19
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

LAST BUILD ON BRANCH main
branch: SELECT
CHANGE BRANCH
x
  • No branch selected
  • dependabot/github_actions/actions-3a1c37d3b7
  • dependabot/go_modules/github.com/googleapis/gax-go-2.0.2incompatible
  • dependabot/go_modules/golang.org/x/crypto-0.45.0
  • dependabot/go_modules/gomod-minor-patch-4a58ba8e14
  • dependabot/go_modules/gomod-minor-patch-4b732bdfc4
  • dependabot/go_modules/gomod-minor-patch-7678b51ea3
  • dependabot/go_modules/gomod-minor-patch-84a25a23f2
  • dependabot/go_modules/gomod-minor-patch-8c811e0a14
  • dependabot/go_modules/gomod-minor-patch-9998116421
  • dependabot/go_modules/gomod-minor-patch-fb4d939785
  • dependabot/go_modules/gomod-minor-patch-fcfb1189d2
  • fix-register-healthcheck-exit
  • fix/autofix-workflow-permissions
  • fix/key_perms
  • main
  • sandbox-kinkade
  • sandbox-roberto-consolidate
  • sandbox-roberto-dependabot
  • sandbox-roberto-fix
  • sandbox-roberto-fix-apikey
  • sandbox-roberto-fix-delete-auth
  • sandbox-roberto-fix-probability
  • sandbox-roberto-gc-error-metrics
  • sandbox-roberto-jwt
  • sandbox-roberto-key-verifier
  • sandbox-roberto-mandatory-ipv4
  • sandbox-roberto-minver
  • sandbox-roberto-probability
  • sandbox-roberto-security-fixes
  • sandbox-roberto-update-app-yaml
  • sandbox-roberto-update-iata-csv
  • sandbox-roberto-update-orgadm

24 Sep 2026 03:41PM UTC coverage: 71.535% (-0.6%) from 72.152%
36022004223

push

github

web-flow
fix(cmd/register): service account key permissions (#103)

The service account key is written with 0644 permissions. Because
it is a secret, it should instead be written with 0600.

I noticed this issue when analyzing `byos-debian` where the key is
written to `/var/lib/mlab/node`. The directory itself is `02750` and
this prevents users that are not in the `mlab-node` group from reading
the file. However, in that context, services such as `ndt-server` are
able to read the secret even though they do not need to. This patch
doesn't address that, but I am working on another set of patches
to privilege-separate core services and measurement services.

I did not spend time focusing on whether this was a security issue
for autonode. As regards autonode, my main focus has been trying
to understand whether changing the permissions could break it, and
I concluded that this is not the case (see below).

To address the permissions, this patch does the following:

1. call `os.WriteFile` with `0600`, which covers new files only
while existing files are just truncated w/o a `chmod`

2. `os.Chmod` with `0600` thus covering already existing files

Following the Boy Scout rule, this patch also changes the wording
and spelling of some comments and adds minor style tweaks.

Regarding why I am confident that autonode containers (and namely
`jostler` and `uuid-annotator`) run as root, this is why:

1. the three `Dockefile`s do not specify `USER`

2. there is no `user:` in the `docker-compose.yml`

As such, this change is safe. Even if the file was owned by
another user and had `0600`, root holds `CAP_DAC_OVERRIDE` so
it is able to read the service account key anyway.

0 of 22 new or added lines in 1 file covered. (0.0%)

1 existing line in 1 file now uncovered.

1254 of 1753 relevant lines covered (71.53%)

0.79 hits per line

Relevant lines Covered
Build:
Build:
1753 RELEVANT LINES 1254 COVERED LINES
0.79 HITS PER LINE
Source Files on main
  • Tree
  • List 19
  • Changed 1
  • Source Changed 0
  • Coverage Changed 1
Coverage ∆ File Lines Relevant Covered Missed Hits/Line

Recent builds

Builds Branch Commit Type Ran Committer Via Coverage
36022004223 main fix(cmd/register): service account key permissions (#103) The service account key is written with 0644 permissions. Because it is a secret, it should instead be written with 0600. I noticed this issue when analyzing `byos-debian` where the key i... push 24 Sep 2026 03:42PM UTC web-flow github
71.53
35609523615 fix/key_perms fix(cmd/register): service account key permissions The service account key is written with 0644 permissions. Because it is a secret, it should instead be written with 0600. I noticed this issue when analyzing `byos-debian` where the key is writt... Pull #103 21 Sep 2026 02:04PM UTC bassosimone github
71.53
30004511040 fix-register-healthcheck-exit fix(register): exit when the /ready healthcheck server fails Pull #102 23 Jul 2026 11:49AM UTC robertodauria github
72.07
29517296262 sandbox-kinkade Merge remote-tracking branch 'origin/main' into sandbox-kinkade Pull #101 16 Jul 2026 04:51PM UTC nkinkade github
72.18
24120010976 dependabot/go_modules/gomod-minor-patch-4b732bdfc4 Bump the gomod-minor-patch group across 1 directory with 6 updates Bumps the gomod-minor-patch group with 3 updates in the / directory: [cloud.google.com/go/datastore](https://github.com/googleapis/google-cloud-go), [cloud.google.com/go/secretman... Pull #99 08 Apr 2026 05:47AM UTC web-flow github
72.15
22229108368 main docs: add AGENTS.md with AI contribution guidelines push 20 Feb 2026 03:03PM UTC robertodauria github
72.15
22194920094 main fix(orgadm): add credentials-project flag and fix IAM policy version (#95) * fix(orgadm): add credentials-project flag and fix IAM policy version - Add -credentials-project flag for cross-project Datastore access - Set IAM policy version to 3 (r... push 19 Feb 2026 06:36PM UTC web-flow github
72.15
22194427121 sandbox-roberto-fix fix(orgadm): set default values for project flags Pull #95 19 Feb 2026 06:21PM UTC robertodauria github
72.15
22194268652 sandbox-roberto-fix fix(orgadm): add credentials-project flag and fix IAM policy version - Add -credentials-project flag for cross-project Datastore access - Set IAM policy version to 3 (required for conditional bindings) Pull #95 19 Feb 2026 06:17PM UTC robertodauria github
71.99
21894215233 dependabot/go_modules/gomod-minor-patch-fb4d939785 Bump the gomod-minor-patch group across 1 directory with 4 updates Bumps the gomod-minor-patch group with 3 updates in the / directory: [cloud.google.com/go/datastore](https://github.com/googleapis/google-cloud-go), [github.com/googleapis/gax-go/... Pull #93 11 Feb 2026 05:47AM UTC web-flow github
72.18
See All Builds (269)
  • Repo on GitHub
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc