Merge pull request #5033 from Ricardo-binZzz/fix/sub2api-no-new-privileges

fix(deploy): prevent application privilege gains
This commit is contained in:
Wesley Liddick
2026-07-31 11:44:28 +08:00
committed by GitHub
6 changed files with 53 additions and 0 deletions
+1
View File
@@ -16,6 +16,7 @@ jobs:
run: |
/bin/bash -n deploy/apple-container.sh
/bin/bash deploy/tests/apple-container-test.sh
/bin/sh deploy/tests/docker-compose-security-test.sh
/bin/sh deploy/test-caddyfile-cache.sh
test:
+2
View File
@@ -17,6 +17,8 @@ services:
NPM_CONFIG_REGISTRY: ${NPM_CONFIG_REGISTRY:-https://registry.npmmirror.com}
container_name: sub2api-dev
restart: unless-stopped
security_opt:
- no-new-privileges:true
ports:
- "${BIND_HOST:-127.0.0.1}:${SERVER_PORT:-8080}:8080"
volumes:
+2
View File
@@ -27,6 +27,8 @@ services:
image: weishaw/sub2api:latest
container_name: sub2api
restart: unless-stopped
security_opt:
- no-new-privileges:true
ulimits:
nofile:
soft: 100000
+2
View File
@@ -15,6 +15,8 @@ services:
image: weishaw/sub2api:latest
container_name: sub2api
restart: unless-stopped
security_opt:
- no-new-privileges:true
ulimits:
nofile:
soft: 100000
+2
View File
@@ -19,6 +19,8 @@ services:
image: weishaw/sub2api:latest
container_name: sub2api
restart: unless-stopped
security_opt:
- no-new-privileges:true
ulimits:
nofile:
soft: 100000
+44
View File
@@ -0,0 +1,44 @@
#!/bin/sh
set -eu
repo_root=$(CDPATH= cd -- "$(dirname -- "$0")/../.." && pwd)
cd "$repo_root"
check_application_security_opt() {
file=$1
count=$(
awk '
$0 == " sub2api:" {
in_application = 1
next
}
in_application && $0 ~ /^ [A-Za-z0-9_-]+:$/ {
in_application = 0
}
in_application && $0 == " security_opt:" {
in_security_opt = 1
next
}
in_application && in_security_opt && $0 == " - no-new-privileges:true" {
count++
}
END { print count + 0 }
' "$file"
)
if [ "$count" -ne 1 ]; then
printf '%s must enable no-new-privileges exactly once for the sub2api service\n' "$file" >&2
exit 1
fi
}
for compose_file in \
deploy/docker-compose.yml \
deploy/docker-compose.local.yml \
deploy/docker-compose.standalone.yml \
deploy/docker-compose.dev.yml
do
check_application_security_opt "$compose_file"
done
printf 'docker compose security test passed\n'