Merge: nixos/postgresql: extension based hardening relaxation (#355010)
This commit is contained in:
@@ -2,6 +2,7 @@
|
|||||||
|
|
||||||
let
|
let
|
||||||
inherit (lib)
|
inherit (lib)
|
||||||
|
any
|
||||||
attrValues
|
attrValues
|
||||||
concatMapStrings
|
concatMapStrings
|
||||||
concatStringsSep
|
concatStringsSep
|
||||||
@@ -9,6 +10,7 @@ let
|
|||||||
elem
|
elem
|
||||||
escapeShellArgs
|
escapeShellArgs
|
||||||
filterAttrs
|
filterAttrs
|
||||||
|
getName
|
||||||
isString
|
isString
|
||||||
literalExpression
|
literalExpression
|
||||||
mapAttrs
|
mapAttrs
|
||||||
@@ -31,19 +33,19 @@ let
|
|||||||
|
|
||||||
cfg = config.services.postgresql;
|
cfg = config.services.postgresql;
|
||||||
|
|
||||||
postgresql =
|
|
||||||
let
|
|
||||||
# ensure that
|
# ensure that
|
||||||
# services.postgresql = {
|
# services.postgresql = {
|
||||||
# enableJIT = true;
|
# enableJIT = true;
|
||||||
# package = pkgs.postgresql_<major>;
|
# package = pkgs.postgresql_<major>;
|
||||||
# };
|
# };
|
||||||
# works.
|
# works.
|
||||||
base = if cfg.enableJIT then cfg.package.withJIT else cfg.package.withoutJIT;
|
basePackage = if cfg.enableJIT
|
||||||
in
|
then cfg.package.withJIT
|
||||||
if cfg.extraPlugins == []
|
else cfg.package.withoutJIT;
|
||||||
then base
|
|
||||||
else base.withPackages cfg.extraPlugins;
|
postgresql = if cfg.extensions == []
|
||||||
|
then basePackage
|
||||||
|
else basePackage.withPackages cfg.extensions;
|
||||||
|
|
||||||
toStr = value:
|
toStr = value:
|
||||||
if true == value then "yes"
|
if true == value then "yes"
|
||||||
@@ -61,6 +63,8 @@ let
|
|||||||
|
|
||||||
groupAccessAvailable = versionAtLeast postgresql.version "11.0";
|
groupAccessAvailable = versionAtLeast postgresql.version "11.0";
|
||||||
|
|
||||||
|
extensionNames = map getName postgresql.installedExtensions;
|
||||||
|
extensionInstalled = extension: elem extension extensionNames;
|
||||||
in
|
in
|
||||||
|
|
||||||
{
|
{
|
||||||
@@ -69,6 +73,7 @@ in
|
|||||||
|
|
||||||
(mkRenamedOptionModule [ "services" "postgresql" "logLinePrefix" ] [ "services" "postgresql" "settings" "log_line_prefix" ])
|
(mkRenamedOptionModule [ "services" "postgresql" "logLinePrefix" ] [ "services" "postgresql" "settings" "log_line_prefix" ])
|
||||||
(mkRenamedOptionModule [ "services" "postgresql" "port" ] [ "services" "postgresql" "settings" "port" ])
|
(mkRenamedOptionModule [ "services" "postgresql" "port" ] [ "services" "postgresql" "settings" "port" ])
|
||||||
|
(mkRenamedOptionModule [ "services" "postgresql" "extraPlugins" ] [ "services" "postgresql" "extensions" ])
|
||||||
];
|
];
|
||||||
|
|
||||||
###### interface
|
###### interface
|
||||||
@@ -372,12 +377,12 @@ in
|
|||||||
'';
|
'';
|
||||||
};
|
};
|
||||||
|
|
||||||
extraPlugins = mkOption {
|
extensions = mkOption {
|
||||||
type = with types; coercedTo (listOf path) (path: _ignorePg: path) (functionTo (listOf path));
|
type = with types; coercedTo (listOf path) (path: _ignorePg: path) (functionTo (listOf path));
|
||||||
default = _: [];
|
default = _: [];
|
||||||
example = literalExpression "ps: with ps; [ postgis pg_repack ]";
|
example = literalExpression "ps: with ps; [ postgis pg_repack ]";
|
||||||
description = ''
|
description = ''
|
||||||
List of PostgreSQL plugins.
|
List of PostgreSQL extensions to install.
|
||||||
'';
|
'';
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -639,7 +644,7 @@ in
|
|||||||
PrivateTmp = true;
|
PrivateTmp = true;
|
||||||
ProtectHome = true;
|
ProtectHome = true;
|
||||||
ProtectSystem = "strict";
|
ProtectSystem = "strict";
|
||||||
MemoryDenyWriteExecute = lib.mkDefault (cfg.settings.jit == "off");
|
MemoryDenyWriteExecute = lib.mkDefault (cfg.settings.jit == "off" && (!any extensionInstalled [ "plv8" ]));
|
||||||
NoNewPrivileges = true;
|
NoNewPrivileges = true;
|
||||||
LockPersonality = true;
|
LockPersonality = true;
|
||||||
PrivateDevices = true;
|
PrivateDevices = true;
|
||||||
@@ -663,10 +668,12 @@ in
|
|||||||
RestrictRealtime = true;
|
RestrictRealtime = true;
|
||||||
RestrictSUIDSGID = true;
|
RestrictSUIDSGID = true;
|
||||||
SystemCallArchitectures = "native";
|
SystemCallArchitectures = "native";
|
||||||
SystemCallFilter = [
|
SystemCallFilter =
|
||||||
|
[
|
||||||
"@system-service"
|
"@system-service"
|
||||||
"~@privileged @resources"
|
"~@privileged @resources"
|
||||||
];
|
]
|
||||||
|
++ lib.optionals (any extensionInstalled [ "plv8" ]) [ "@pkey" ];
|
||||||
UMask = if groupAccessAvailable then "0027" else "0077";
|
UMask = if groupAccessAvailable then "0027" else "0077";
|
||||||
}
|
}
|
||||||
(mkIf (cfg.dataDir != "/var/lib/postgresql") {
|
(mkIf (cfg.dataDir != "/var/lib/postgresql") {
|
||||||
|
|||||||
@@ -227,7 +227,7 @@ in
|
|||||||
ensureClauses.login = true;
|
ensureClauses.login = true;
|
||||||
}
|
}
|
||||||
];
|
];
|
||||||
extraPlugins = ps: with ps; [ pgvecto-rs ];
|
extensions = ps: with ps; [ pgvecto-rs ];
|
||||||
settings = {
|
settings = {
|
||||||
shared_preload_libraries = [ "vectors.so" ];
|
shared_preload_libraries = [ "vectors.so" ];
|
||||||
search_path = "\"$user\", public, vectors";
|
search_path = "\"$user\", public, vectors";
|
||||||
|
|||||||
@@ -383,7 +383,7 @@ in
|
|||||||
ensureDBOwnership = false;
|
ensureDBOwnership = false;
|
||||||
}
|
}
|
||||||
];
|
];
|
||||||
extraPlugins = ps: with ps; [ postgis ];
|
extensions = ps: with ps; [ postgis ];
|
||||||
};
|
};
|
||||||
|
|
||||||
# Nginx config taken from support/nginx/mobilizon-release.conf
|
# Nginx config taken from support/nginx/mobilizon-release.conf
|
||||||
|
|||||||
@@ -20,7 +20,7 @@ let
|
|||||||
inherit package;
|
inherit package;
|
||||||
enable = true;
|
enable = true;
|
||||||
enableJIT = lib.hasInfix "-jit-" package.name;
|
enableJIT = lib.hasInfix "-jit-" package.name;
|
||||||
extraPlugins = ps: [ ps.anonymizer ];
|
extensions = ps: [ ps.anonymizer ];
|
||||||
settings.shared_preload_libraries = [ "anon" ];
|
settings.shared_preload_libraries = [ "anon" ];
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -24,7 +24,7 @@ let
|
|||||||
inherit package;
|
inherit package;
|
||||||
enable = true;
|
enable = true;
|
||||||
enableJIT = lib.hasInfix "-jit-" package.name;
|
enableJIT = lib.hasInfix "-jit-" package.name;
|
||||||
extraPlugins =
|
extensions =
|
||||||
ps: with ps; [
|
ps: with ps; [
|
||||||
pgjwt
|
pgjwt
|
||||||
pgtap
|
pgtap
|
||||||
|
|||||||
@@ -38,7 +38,7 @@ let
|
|||||||
inherit package;
|
inherit package;
|
||||||
enable = true;
|
enable = true;
|
||||||
enableJIT = lib.hasInfix "-jit-" package.name;
|
enableJIT = lib.hasInfix "-jit-" package.name;
|
||||||
extraPlugins =
|
extensions =
|
||||||
ps: with ps; [
|
ps: with ps; [
|
||||||
pgvecto-rs
|
pgvecto-rs
|
||||||
];
|
];
|
||||||
|
|||||||
@@ -14,7 +14,10 @@ let
|
|||||||
postgresql-clauses = makeEnsureTestFor package;
|
postgresql-clauses = makeEnsureTestFor package;
|
||||||
};
|
};
|
||||||
|
|
||||||
test-sql = pkgs.writeText "postgresql-test" ''
|
test-sql =
|
||||||
|
enablePLv8Test:
|
||||||
|
pkgs.writeText "postgresql-test" (
|
||||||
|
''
|
||||||
CREATE EXTENSION pgcrypto; -- just to check if lib loading works
|
CREATE EXTENSION pgcrypto; -- just to check if lib loading works
|
||||||
CREATE TABLE sth (
|
CREATE TABLE sth (
|
||||||
id int
|
id int
|
||||||
@@ -26,10 +29,26 @@ let
|
|||||||
INSERT INTO sth (id) VALUES (1);
|
INSERT INTO sth (id) VALUES (1);
|
||||||
CREATE TABLE xmltest ( doc xml );
|
CREATE TABLE xmltest ( doc xml );
|
||||||
INSERT INTO xmltest (doc) VALUES ('<test>ok</test>'); -- check if libxml2 enabled
|
INSERT INTO xmltest (doc) VALUES ('<test>ok</test>'); -- check if libxml2 enabled
|
||||||
'';
|
''
|
||||||
|
+ lib.optionalString enablePLv8Test ''
|
||||||
|
-- check if hardening gets relaxed
|
||||||
|
CREATE EXTENSION plv8;
|
||||||
|
-- try to trigger the V8 JIT, which requires MemoryDenyWriteExecute
|
||||||
|
DO $$
|
||||||
|
let xs = [];
|
||||||
|
for (let i = 0, n = 400000; i < n; i++) {
|
||||||
|
xs.push(Math.round(Math.random() * n))
|
||||||
|
}
|
||||||
|
console.log(xs.reduce((acc, x) => acc + x, 0));
|
||||||
|
$$ LANGUAGE plv8;
|
||||||
|
''
|
||||||
|
);
|
||||||
|
|
||||||
makeTestForWithBackupAll =
|
makeTestForWithBackupAll =
|
||||||
package: backupAll:
|
package: backupAll:
|
||||||
|
let
|
||||||
|
enablePLv8Check = !package.pkgs.plv8.meta.broken;
|
||||||
|
in
|
||||||
makeTest {
|
makeTest {
|
||||||
name = "postgresql${lib.optionalString backupAll "-backup-all"}-${package.name}";
|
name = "postgresql${lib.optionalString backupAll "-backup-all"}-${package.name}";
|
||||||
meta = with lib.maintainers; {
|
meta = with lib.maintainers; {
|
||||||
@@ -37,12 +56,17 @@ let
|
|||||||
};
|
};
|
||||||
|
|
||||||
nodes.machine =
|
nodes.machine =
|
||||||
{ ... }:
|
{ config, ... }:
|
||||||
{
|
{
|
||||||
services.postgresql = {
|
services.postgresql = {
|
||||||
inherit package;
|
inherit package;
|
||||||
enable = true;
|
enable = true;
|
||||||
enableJIT = lib.hasInfix "-jit-" package.name;
|
enableJIT = lib.hasInfix "-jit-" package.name;
|
||||||
|
# plv8 doesn't support postgresql with JIT, so we only run the test
|
||||||
|
# for the non-jit variant.
|
||||||
|
# TODO(@Ma27) split this off into its own VM test and move a few other
|
||||||
|
# extension tests to use postgresqlTestExtension.
|
||||||
|
extensions = lib.mkIf enablePLv8Check (ps: with ps; [ plv8 ]);
|
||||||
};
|
};
|
||||||
|
|
||||||
services.postgresqlBackup = {
|
services.postgresqlBackup = {
|
||||||
@@ -69,7 +93,7 @@ let
|
|||||||
|
|
||||||
with subtest("Postgresql is available just after unit start"):
|
with subtest("Postgresql is available just after unit start"):
|
||||||
machine.succeed(
|
machine.succeed(
|
||||||
"cat ${test-sql} | sudo -u postgres psql"
|
"cat ${test-sql enablePLv8Check} | sudo -u postgres psql"
|
||||||
)
|
)
|
||||||
|
|
||||||
with subtest("Postgresql survives restart (bug #1735)"):
|
with subtest("Postgresql survives restart (bug #1735)"):
|
||||||
|
|||||||
@@ -54,7 +54,7 @@ let
|
|||||||
inherit package;
|
inherit package;
|
||||||
enable = true;
|
enable = true;
|
||||||
enableJIT = lib.hasInfix "-jit-" package.name;
|
enableJIT = lib.hasInfix "-jit-" package.name;
|
||||||
extraPlugins =
|
extensions =
|
||||||
ps: with ps; [
|
ps: with ps; [
|
||||||
timescaledb
|
timescaledb
|
||||||
timescaledb_toolkit
|
timescaledb_toolkit
|
||||||
|
|||||||
@@ -21,7 +21,7 @@ let
|
|||||||
inherit package;
|
inherit package;
|
||||||
enable = true;
|
enable = true;
|
||||||
enableJIT = lib.hasInfix "-jit-" package.name;
|
enableJIT = lib.hasInfix "-jit-" package.name;
|
||||||
extraPlugins =
|
extensions =
|
||||||
ps: with ps; [
|
ps: with ps; [
|
||||||
tsja
|
tsja
|
||||||
];
|
];
|
||||||
|
|||||||
@@ -17,7 +17,7 @@ let
|
|||||||
inherit package;
|
inherit package;
|
||||||
enable = true;
|
enable = true;
|
||||||
enableJIT = lib.hasInfix "-jit-" package.name;
|
enableJIT = lib.hasInfix "-jit-" package.name;
|
||||||
extraPlugins = with package.pkgs; [ wal2json ];
|
extensions = with package.pkgs; [ wal2json ];
|
||||||
settings = {
|
settings = {
|
||||||
wal_level = "logical";
|
wal_level = "logical";
|
||||||
max_replication_slots = "10";
|
max_replication_slots = "10";
|
||||||
|
|||||||
@@ -315,26 +315,34 @@ let
|
|||||||
};
|
};
|
||||||
});
|
});
|
||||||
|
|
||||||
postgresqlWithPackages = { postgresql, buildEnv }: f: buildEnv {
|
postgresqlWithPackages = { postgresql, buildEnv }: f: let
|
||||||
|
installedExtensions = f postgresql.pkgs;
|
||||||
|
in buildEnv {
|
||||||
name = "${postgresql.pname}-and-plugins-${postgresql.version}";
|
name = "${postgresql.pname}-and-plugins-${postgresql.version}";
|
||||||
paths = f postgresql.pkgs ++ [
|
paths = installedExtensions ++ [
|
||||||
postgresql
|
postgresql
|
||||||
postgresql.man # in case user installs this into environment
|
postgresql.man # in case user installs this into environment
|
||||||
];
|
];
|
||||||
|
|
||||||
pathsToLink = ["/"];
|
pathsToLink = ["/"];
|
||||||
|
|
||||||
passthru.version = postgresql.version;
|
passthru = {
|
||||||
passthru.psqlSchema = postgresql.psqlSchema;
|
inherit installedExtensions;
|
||||||
passthru.withJIT = postgresqlWithPackages {
|
inherit (postgresql)
|
||||||
|
psqlSchema
|
||||||
|
version
|
||||||
|
;
|
||||||
|
|
||||||
|
withJIT = postgresqlWithPackages {
|
||||||
inherit buildEnv;
|
inherit buildEnv;
|
||||||
postgresql = postgresql.withJIT;
|
postgresql = postgresql.withJIT;
|
||||||
} f;
|
} f;
|
||||||
passthru.withoutJIT = postgresqlWithPackages {
|
withoutJIT = postgresqlWithPackages {
|
||||||
inherit buildEnv;
|
inherit buildEnv;
|
||||||
postgresql = postgresql.withoutJIT;
|
postgresql = postgresql.withoutJIT;
|
||||||
} f;
|
} f;
|
||||||
};
|
};
|
||||||
|
};
|
||||||
|
|
||||||
in
|
in
|
||||||
# passed by <major>.nix
|
# passed by <major>.nix
|
||||||
|
|||||||
Reference in New Issue
Block a user