Skip to content

Support running as a non-root user (firebird or any UID with GID 0) - #51

Open
fdcastel wants to merge 1 commit into
FirebirdSQL:masterfrom
fdcastel:feat/issue-46-non-root
Open

fdcastel wants to merge 1 commit into
FirebirdSQL:masterfrom
fdcastel:feat/issue-46-non-root

Conversation

@fdcastel

Copy link
Copy Markdown
Member

Refs #46.

The image still runs as root by default, so nothing changes for existing users. It can now also run fully as the firebird user (UID 84) or as any UID with GID 0, which is how OpenShift's restricted SCC runs containers (random UID, no /etc/passwd entry). This is option B from the discussion in #46. Switching the default to USER firebird is left for a major release.

I'm not using "Fixes #46", so the issue stays open until the reporter confirms it works on OKD/MicroShift.

Problem

Measured on the current 5.0.4 image:

  • --user 84:84 starts the server, but the entrypoint fails as soon as it has to write:
    • FIREBIRD_CONF_* / FIREBIRD_USE_LEGACY_AUTH: sed -i cannot create its temporary file in the root:root 0755 directory /opt/firebird.
    • FIREBIRD_ROOT_PASSWORD: rm of the root:root 0400 file SYSDBA.password fails.
    • FIREBIRD_DATABASE: writing /opt/firebird/.firebird_env fails.
  • An arbitrary UID with GID 0 fails even earlier. fb_guard, firebird.log, security*.fdb, the data directory and the installer's leftover files in /tmp/firebird are owned by firebird:firebird.
  • Local (embedded) isql connections take the OS user name as the Firebird user. root maps to SYSDBA, but UID 84 becomes FIREBIRD, and a random UID has no name at all. As a result:
    • CREATE USER for FIREBIRD_USER fails with no permission for INSERT access to TABLE PLG$SRP_VIEW.
    • Without FIREBIRD_USER, databases and init-script objects end up owned by FIREBIRD instead of SYSDBA.

Fix

  • src/Dockerfile.template:
    • Runtime-writable paths are owned by firebird:0 with g=u: /opt/firebird itself, SYSDBA.password, firebird.conf, firebird.log, fb_guard, replication.log, security*.fdb, /tmp/firebird and $FIREBIRD_DATA.
    • Owner firebird keeps --user firebird working, and group 0 covers any UID in the root group.
    • Binaries, libraries and plugins stay owned by root.
    • $FIREBIRD_DATA is a VOLUME, so its ownership is set in the image layer.
    • The installer's stale lock, shared-memory and trace files in /tmp/firebird (~6 MB, one of them root-only) are removed. Firebird recreates them at startup.
  • src/entrypoint.sh:
    • Every local isql connection names its user explicitly: -user SYSDBA in create_user and create_db. process_sql uses -u SYSDBA when FIREBIRD_USER is not set.
    • Nothing changes for root, which was already SYSDBA.
    • New check_permissions: a non-root user that cannot write to /opt/firebird or the data directory gets a clear warning that lists the supported users.
  • src/image.tests.ps1:
    • The test data tmpfs now has the same ownership and mode as the image layer (firebird:0, 0775). Previously it was root-owned and hid the image's ownership.
    • New tests:
      • Runtime_paths_are_owned_by_firebird_and_group_root (binaries stay root-owned).
      • Can_run_as_firebird_user (84:84) and Can_run_as_arbitrary_uid_with_group_root (12345:0). Each runs the whole initialization: FIREBIRD_CONF_*, SYSDBA password change, FIREBIRD_USER, FIREBIRD_DATABASE and an init script. It then checks the server's UID, remote logins, removal of SYSDBA.password, and object ownership.
      • Without_FIREBIRD_USER_database_is_owned_by_SYSDBA_for_any_user, for 0:0, 84:84 and 12345:0.
      • Unsupported_user_shows_permission_warning.
  • README.md / src/README.md.template: new "Running as a non-root user" section. It covers Docker, Kubernetes securityContext and OpenShift, and notes that databases created as root need chown -R 84:0 before a non-root container can open them.
  • DECISIONS.md: D-020. This will conflict trivially with Fix SYSDBA.password not working in Firebird 3 images #49's D-019, since both append at the end. Keep both entries.
  • generated/: regenerated with Invoke-Build Prepare.

Test plan

  • Local, 5.0.4 / trixie: Invoke-Build Build + Invoke-Build Test, 34/34 green. That's the 28 existing tests, which run as root and are unchanged, plus the new ones.
  • Local manual runs with named volumes as 0:0, 84:84 and 12345:0, with all variables set. For all three: the server runs as the requested UID, alice and SYSDBA can log in remotely, the init script ran, and SYSDBA.password was removed. 1000:1000 shows the warning.
  • Fork CI, workflow_dispatch with distro-filter=trixie, all versions: 36271557110 passed.
    • 24 images: 3.0.9 → 3.0.14, 4.0.0 → 4.0.7 and 5.0.0 → 5.0.4 on amd64, plus 5.0.0 → 5.0.4 on arm64.
    • The full suite, including each new test, passed on all 24.
  • The push-triggered CI run fails only on Debian bullseye, whose security packages now return 404 after its end of life. That affects master and every branch and is tracked in Debian bullseye images can no longer be built (bullseye reached end of life); proposal: stop building them #50.

The image still runs as root by default, but it now also runs as the
'firebird' user (UID 84) or as any UID with GID 0, which is how
OpenShift's restricted SCC runs containers.

- Dockerfile: runtime-writable paths (/opt/firebird itself,
  firebird.conf, SYSDBA.password, firebird.log, fb_guard,
  replication.log, security*.fdb, /tmp/firebird and the data
  directory) are owned by firebird:0 with g=u. Binaries, libraries
  and plugins stay owned by root. The installer's stale lock files in
  /tmp/firebird are removed.
- entrypoint: every local isql connection names its user explicitly.
  Local connections otherwise take the OS user name, which is SYSDBA
  only for root: UID 84 became 'FIREBIRD' and a random UID failed to
  create FIREBIRD_USER.
- entrypoint: warn on startup when a non-root user cannot write to
  /opt/firebird or the data directory.
- tests: test tmpfs mirrors the image's data directory ownership; new
  tests for file ownership, full initialization as 84:84 and 12345:0,
  database ownership without FIREBIRD_USER, and the warning.
- README: new "Running as a non-root user" section.
- DECISIONS.md: D-020.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Change default user in container image

1 participant