Skip to content

Commit 03e7c24

Browse files
committed
fix(install): make the snap install opt-in
The snap gateway runs as root on plaintext loopback without client authentication, so any local user can operate it. Stop selecting the snap automatically when the snap command is available; Linux installs now default to the Debian or RPM package with the per-user mTLS gateway. The snap path remains available with OPENSHELL_INSTALL_SNAP=1, and hosts that already have the OpenShell snap keep refreshing it rather than gaining a second gateway on the same port. The snap path now warns about unauthenticated local access. Signed-off-by: Drew Newberry <anewberry@nvidia.com>
1 parent 496ebba commit 03e7c24

3 files changed

Lines changed: 49 additions & 18 deletions

File tree

‎.github/workflows/release-canary.yml‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -193,6 +193,8 @@ jobs:
193193
194194
ubuntu-snap-system-docker:
195195
name: Ubuntu Snap with system Docker
196+
env:
197+
OPENSHELL_INSTALL_SNAP: "1"
196198
if: ${{ github.event_name == 'workflow_dispatch' || github.event.workflow_run.conclusion == 'success' }}
197199
runs-on: ubuntu-latest
198200
timeout-minutes: 20
@@ -260,6 +262,8 @@ jobs:
260262
261263
ubuntu-snap-docker-preflight:
262264
name: Ubuntu Snap Docker preflight
265+
env:
266+
OPENSHELL_INSTALL_SNAP: "1"
263267
if: ${{ github.event_name == 'workflow_dispatch' || github.event.workflow_run.conclusion == 'success' }}
264268
runs-on: ubuntu-latest
265269
timeout-minutes: 20

‎install.sh‎

Lines changed: 22 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -61,21 +61,24 @@ ENVIRONMENT VARIABLES:
6161
OPENSHELL_ACK_BREAKING_UPGRADE
6262
Set to 1 only after backing up and cleaning up a
6363
pre-v0.0.37 or non-snap installation.
64+
OPENSHELL_INSTALL_SNAP
65+
Set to 1 to install the OpenShell snap on Linux. The
66+
snap gateway allows unauthenticated local access.
6467
6568
NOTES:
6669
When OPENSHELL_VERSION is unset, this resolves the latest tagged release
6770
from ${GITHUB_URL}/releases/latest.
6871
69-
On Linux, the installer uses the OpenShell snap when the snap command is
70-
available and OPENSHELL_VERSION is unset or dev. Snap installs use
71-
latest/stable by default and latest/edge for dev. Explicit release tags
72-
and prereleases use Debian or RPM packages. The OpenShell snap requires a
72+
Linux installs the Debian package on amd64/arm64 or the RPM packages on
73+
x86_64/aarch64, depending on the host package manager.
74+
75+
The installer uses the OpenShell snap only when OPENSHELL_INSTALL_SNAP=1 is
76+
set or an OpenShell snap is already installed, the snap command is
77+
available, and OPENSHELL_VERSION is unset or dev. Snap installs use
78+
latest/stable by default and latest/edge for dev. The snap gateway allows
79+
unauthenticated access from any local user. The OpenShell snap requires a
7380
running Docker Engine installed from a system package or Docker's package
7481
repository. The Docker snap is not currently compatible with OpenShell.
75-
76-
For explicit versions or without snap, Linux installs the Debian package
77-
on amd64/arm64 or the RPM packages on x86_64/aarch64, depending on the
78-
host package manager.
7982
macOS installs the release Homebrew formula on Apple Silicon and starts a
8083
brew services-backed local gateway.
8184
EOF
@@ -657,10 +660,18 @@ local_gateway_endpoint() {
657660
esac
658661
}
659662

663+
openshell_snap_installed() {
664+
snap list openshell >/dev/null 2>&1
665+
}
666+
667+
# The snap gateway runs as root without client authentication, so new installs
668+
# use it only on explicit opt-in. Existing snap installs keep refreshing rather
669+
# than gaining a second gateway on the same port.
660670
linux_package_method() {
661671
case "${OPENSHELL_VERSION:-}" in
662672
'' | dev)
663-
if has_cmd snap; then
673+
if has_cmd snap \
674+
&& { [ "${OPENSHELL_INSTALL_SNAP:-0}" = "1" ] || openshell_snap_installed; }; then
664675
echo "snap"
665676
return 0
666677
fi
@@ -1340,6 +1351,8 @@ Install Docker Engine from a system package or Docker's package repository, then
13401351
info "using existing Docker installation"
13411352
wait_for_docker_daemon
13421353

1354+
warn "the OpenShell snap gateway allows unauthenticated access from any local user or process"
1355+
13431356
_channel="$(openshell_snap_channel)"
13441357
if snap list openshell >/dev/null 2>&1; then
13451358
info "refreshing OpenShell snap from ${_channel}..."

‎tasks/scripts/test-install-sh.sh‎

Lines changed: 23 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -103,22 +103,30 @@ assert_glibc_preflight_fails \
103103
assert_linux_package_method() {
104104
local name=$1
105105
local requested_version=$2
106-
local snap_present=$3
106+
local snap_mode=$3
107107
local dpkg_present=$4
108108
local rpm_present=$5
109109
local expected=$6
110110
local actual
111111

112+
# snap_mode: 0 = no snap command, 1 = snap command only,
113+
# optin = OPENSHELL_INSTALL_SNAP=1, existing = OpenShell snap installed.
112114
actual="$(
113115
export OPENSHELL_VERSION="$requested_version"
116+
if [ "$snap_mode" = "optin" ]; then
117+
export OPENSHELL_INSTALL_SNAP=1
118+
else
119+
unset OPENSHELL_INSTALL_SNAP
120+
fi
114121
has_cmd() {
115122
case "$1" in
116-
snap) [ "$snap_present" = "1" ] ;;
123+
snap) [ "$snap_mode" != "0" ] ;;
117124
dpkg) [ "$dpkg_present" = "1" ] ;;
118125
rpm) [ "$rpm_present" = "1" ] ;;
119126
*) return 1 ;;
120127
esac
121128
}
129+
openshell_snap_installed() { [ "$snap_mode" = "existing" ]; }
122130
linux_package_method
123131
)"
124132
if [ "$actual" != "$expected" ]; then
@@ -127,13 +135,19 @@ assert_linux_package_method() {
127135
fi
128136
}
129137

130-
assert_linux_package_method "snap takes precedence over deb and rpm" "" 1 1 1 snap
131-
assert_linux_package_method "dev uses snap" dev 1 1 1 snap
132-
assert_linux_package_method "pre uses deb despite snap" pre 1 1 1 deb
133-
assert_linux_package_method "numbered prerelease uses deb despite snap" v0.1.0-pre.3 1 1 1 deb
134-
assert_linux_package_method "pre uses rpm despite snap" pre 1 0 1 rpm
135-
assert_linux_package_method "pinned stable uses deb despite snap" v1.2.3 1 1 1 deb
136-
assert_linux_package_method "pinned stable uses rpm despite snap" v1.2.3 1 0 1 rpm
138+
assert_linux_package_method "deb is the default despite snap" "" 1 1 1 deb
139+
assert_linux_package_method "rpm is the default despite snap" "" 1 0 1 rpm
140+
assert_linux_package_method "dev uses deb despite snap" dev 1 1 1 deb
141+
assert_linux_package_method "opt-in selects snap" "" optin 1 1 snap
142+
assert_linux_package_method "opt-in dev selects snap" dev optin 1 1 snap
143+
assert_linux_package_method "existing snap install keeps refreshing" "" existing 1 1 snap
144+
assert_linux_package_method "existing snap install keeps refreshing dev" dev existing 1 1 snap
145+
assert_linux_package_method "opt-in without snap uses deb" "" 0 1 1 deb
146+
assert_linux_package_method "pre uses deb despite snap opt-in" pre optin 1 1 deb
147+
assert_linux_package_method "numbered prerelease uses deb despite snap opt-in" v0.1.0-pre.3 optin 1 1 deb
148+
assert_linux_package_method "pre uses rpm despite snap opt-in" pre optin 0 1 rpm
149+
assert_linux_package_method "pinned stable uses deb despite existing snap" v1.2.3 existing 1 1 deb
150+
assert_linux_package_method "pinned stable uses rpm despite existing snap" v1.2.3 existing 0 1 rpm
137151
assert_linux_package_method "deb is selected without snap" "" 0 1 1 deb
138152
assert_linux_package_method "dev uses deb without snap" dev 0 1 1 deb
139153
assert_linux_package_method "rpm is selected without snap or deb" "" 0 0 1 rpm

0 commit comments

Comments
 (0)