Merge: nixos/postgresql: extension based hardening relaxation (#355010)

This commit is contained in:
Maximilian Bosch
2024-11-16 22:29:36 +01:00
committed by GitHub
11 changed files with 93 additions and 54 deletions

View File

@@ -2,6 +2,7 @@
let let
inherit (lib) inherit (lib)
any
attrValues attrValues
concatMapStrings concatMapStrings
concatStringsSep concatStringsSep
@@ -9,6 +10,7 @@ let
elem elem
escapeShellArgs escapeShellArgs
filterAttrs filterAttrs
getName
isString isString
literalExpression literalExpression
mapAttrs mapAttrs
@@ -31,19 +33,19 @@ let
cfg = config.services.postgresql; cfg = config.services.postgresql;
postgresql =
let
# ensure that # ensure that
# services.postgresql = { # services.postgresql = {
# enableJIT = true; # enableJIT = true;
# package = pkgs.postgresql_<major>; # package = pkgs.postgresql_<major>;
# }; # };
# works. # works.
base = if cfg.enableJIT then cfg.package.withJIT else cfg.package.withoutJIT; basePackage = if cfg.enableJIT
in then cfg.package.withJIT
if cfg.extraPlugins == [] else cfg.package.withoutJIT;
then base
else base.withPackages cfg.extraPlugins; postgresql = if cfg.extensions == []
then basePackage
else basePackage.withPackages cfg.extensions;
toStr = value: toStr = value:
if true == value then "yes" if true == value then "yes"
@@ -61,6 +63,8 @@ let
groupAccessAvailable = versionAtLeast postgresql.version "11.0"; groupAccessAvailable = versionAtLeast postgresql.version "11.0";
extensionNames = map getName postgresql.installedExtensions;
extensionInstalled = extension: elem extension extensionNames;
in in
{ {
@@ -69,6 +73,7 @@ in
(mkRenamedOptionModule [ "services" "postgresql" "logLinePrefix" ] [ "services" "postgresql" "settings" "log_line_prefix" ]) (mkRenamedOptionModule [ "services" "postgresql" "logLinePrefix" ] [ "services" "postgresql" "settings" "log_line_prefix" ])
(mkRenamedOptionModule [ "services" "postgresql" "port" ] [ "services" "postgresql" "settings" "port" ]) (mkRenamedOptionModule [ "services" "postgresql" "port" ] [ "services" "postgresql" "settings" "port" ])
(mkRenamedOptionModule [ "services" "postgresql" "extraPlugins" ] [ "services" "postgresql" "extensions" ])
]; ];
###### interface ###### interface
@@ -372,12 +377,12 @@ in
''; '';
}; };
extraPlugins = mkOption { extensions = mkOption {
type = with types; coercedTo (listOf path) (path: _ignorePg: path) (functionTo (listOf path)); type = with types; coercedTo (listOf path) (path: _ignorePg: path) (functionTo (listOf path));
default = _: []; default = _: [];
example = literalExpression "ps: with ps; [ postgis pg_repack ]"; example = literalExpression "ps: with ps; [ postgis pg_repack ]";
description = '' description = ''
List of PostgreSQL plugins. List of PostgreSQL extensions to install.
''; '';
}; };
@@ -639,7 +644,7 @@ in
PrivateTmp = true; PrivateTmp = true;
ProtectHome = true; ProtectHome = true;
ProtectSystem = "strict"; ProtectSystem = "strict";
MemoryDenyWriteExecute = lib.mkDefault (cfg.settings.jit == "off"); MemoryDenyWriteExecute = lib.mkDefault (cfg.settings.jit == "off" && (!any extensionInstalled [ "plv8" ]));
NoNewPrivileges = true; NoNewPrivileges = true;
LockPersonality = true; LockPersonality = true;
PrivateDevices = true; PrivateDevices = true;
@@ -663,10 +668,12 @@ in
RestrictRealtime = true; RestrictRealtime = true;
RestrictSUIDSGID = true; RestrictSUIDSGID = true;
SystemCallArchitectures = "native"; SystemCallArchitectures = "native";
SystemCallFilter = [ SystemCallFilter =
[
"@system-service" "@system-service"
"~@privileged @resources" "~@privileged @resources"
]; ]
++ lib.optionals (any extensionInstalled [ "plv8" ]) [ "@pkey" ];
UMask = if groupAccessAvailable then "0027" else "0077"; UMask = if groupAccessAvailable then "0027" else "0077";
} }
(mkIf (cfg.dataDir != "/var/lib/postgresql") { (mkIf (cfg.dataDir != "/var/lib/postgresql") {

View File

@@ -227,7 +227,7 @@ in
ensureClauses.login = true; ensureClauses.login = true;
} }
]; ];
extraPlugins = ps: with ps; [ pgvecto-rs ]; extensions = ps: with ps; [ pgvecto-rs ];
settings = { settings = {
shared_preload_libraries = [ "vectors.so" ]; shared_preload_libraries = [ "vectors.so" ];
search_path = "\"$user\", public, vectors"; search_path = "\"$user\", public, vectors";

View File

@@ -383,7 +383,7 @@ in
ensureDBOwnership = false; ensureDBOwnership = false;
} }
]; ];
extraPlugins = ps: with ps; [ postgis ]; extensions = ps: with ps; [ postgis ];
}; };
# Nginx config taken from support/nginx/mobilizon-release.conf # Nginx config taken from support/nginx/mobilizon-release.conf

View File

@@ -20,7 +20,7 @@ let
inherit package; inherit package;
enable = true; enable = true;
enableJIT = lib.hasInfix "-jit-" package.name; enableJIT = lib.hasInfix "-jit-" package.name;
extraPlugins = ps: [ ps.anonymizer ]; extensions = ps: [ ps.anonymizer ];
settings.shared_preload_libraries = [ "anon" ]; settings.shared_preload_libraries = [ "anon" ];
}; };
}; };

View File

@@ -24,7 +24,7 @@ let
inherit package; inherit package;
enable = true; enable = true;
enableJIT = lib.hasInfix "-jit-" package.name; enableJIT = lib.hasInfix "-jit-" package.name;
extraPlugins = extensions =
ps: with ps; [ ps: with ps; [
pgjwt pgjwt
pgtap pgtap

View File

@@ -38,7 +38,7 @@ let
inherit package; inherit package;
enable = true; enable = true;
enableJIT = lib.hasInfix "-jit-" package.name; enableJIT = lib.hasInfix "-jit-" package.name;
extraPlugins = extensions =
ps: with ps; [ ps: with ps; [
pgvecto-rs pgvecto-rs
]; ];

View File

@@ -14,7 +14,10 @@ let
postgresql-clauses = makeEnsureTestFor package; postgresql-clauses = makeEnsureTestFor package;
}; };
test-sql = pkgs.writeText "postgresql-test" '' test-sql =
enablePLv8Test:
pkgs.writeText "postgresql-test" (
''
CREATE EXTENSION pgcrypto; -- just to check if lib loading works CREATE EXTENSION pgcrypto; -- just to check if lib loading works
CREATE TABLE sth ( CREATE TABLE sth (
id int id int
@@ -26,10 +29,26 @@ let
INSERT INTO sth (id) VALUES (1); INSERT INTO sth (id) VALUES (1);
CREATE TABLE xmltest ( doc xml ); CREATE TABLE xmltest ( doc xml );
INSERT INTO xmltest (doc) VALUES ('<test>ok</test>'); -- check if libxml2 enabled INSERT INTO xmltest (doc) VALUES ('<test>ok</test>'); -- check if libxml2 enabled
''; ''
+ lib.optionalString enablePLv8Test ''
-- check if hardening gets relaxed
CREATE EXTENSION plv8;
-- try to trigger the V8 JIT, which requires MemoryDenyWriteExecute
DO $$
let xs = [];
for (let i = 0, n = 400000; i < n; i++) {
xs.push(Math.round(Math.random() * n))
}
console.log(xs.reduce((acc, x) => acc + x, 0));
$$ LANGUAGE plv8;
''
);
makeTestForWithBackupAll = makeTestForWithBackupAll =
package: backupAll: package: backupAll:
let
enablePLv8Check = !package.pkgs.plv8.meta.broken;
in
makeTest { makeTest {
name = "postgresql${lib.optionalString backupAll "-backup-all"}-${package.name}"; name = "postgresql${lib.optionalString backupAll "-backup-all"}-${package.name}";
meta = with lib.maintainers; { meta = with lib.maintainers; {
@@ -37,12 +56,17 @@ let
}; };
nodes.machine = nodes.machine =
{ ... }: { config, ... }:
{ {
services.postgresql = { services.postgresql = {
inherit package; inherit package;
enable = true; enable = true;
enableJIT = lib.hasInfix "-jit-" package.name; enableJIT = lib.hasInfix "-jit-" package.name;
# plv8 doesn't support postgresql with JIT, so we only run the test
# for the non-jit variant.
# TODO(@Ma27) split this off into its own VM test and move a few other
# extension tests to use postgresqlTestExtension.
extensions = lib.mkIf enablePLv8Check (ps: with ps; [ plv8 ]);
}; };
services.postgresqlBackup = { services.postgresqlBackup = {
@@ -69,7 +93,7 @@ let
with subtest("Postgresql is available just after unit start"): with subtest("Postgresql is available just after unit start"):
machine.succeed( machine.succeed(
"cat ${test-sql} | sudo -u postgres psql" "cat ${test-sql enablePLv8Check} | sudo -u postgres psql"
) )
with subtest("Postgresql survives restart (bug #1735)"): with subtest("Postgresql survives restart (bug #1735)"):

View File

@@ -54,7 +54,7 @@ let
inherit package; inherit package;
enable = true; enable = true;
enableJIT = lib.hasInfix "-jit-" package.name; enableJIT = lib.hasInfix "-jit-" package.name;
extraPlugins = extensions =
ps: with ps; [ ps: with ps; [
timescaledb timescaledb
timescaledb_toolkit timescaledb_toolkit

View File

@@ -21,7 +21,7 @@ let
inherit package; inherit package;
enable = true; enable = true;
enableJIT = lib.hasInfix "-jit-" package.name; enableJIT = lib.hasInfix "-jit-" package.name;
extraPlugins = extensions =
ps: with ps; [ ps: with ps; [
tsja tsja
]; ];

View File

@@ -17,7 +17,7 @@ let
inherit package; inherit package;
enable = true; enable = true;
enableJIT = lib.hasInfix "-jit-" package.name; enableJIT = lib.hasInfix "-jit-" package.name;
extraPlugins = with package.pkgs; [ wal2json ]; extensions = with package.pkgs; [ wal2json ];
settings = { settings = {
wal_level = "logical"; wal_level = "logical";
max_replication_slots = "10"; max_replication_slots = "10";

View File

@@ -315,26 +315,34 @@ let
}; };
}); });
postgresqlWithPackages = { postgresql, buildEnv }: f: buildEnv { postgresqlWithPackages = { postgresql, buildEnv }: f: let
installedExtensions = f postgresql.pkgs;
in buildEnv {
name = "${postgresql.pname}-and-plugins-${postgresql.version}"; name = "${postgresql.pname}-and-plugins-${postgresql.version}";
paths = f postgresql.pkgs ++ [ paths = installedExtensions ++ [
postgresql postgresql
postgresql.man # in case user installs this into environment postgresql.man # in case user installs this into environment
]; ];
pathsToLink = ["/"]; pathsToLink = ["/"];
passthru.version = postgresql.version; passthru = {
passthru.psqlSchema = postgresql.psqlSchema; inherit installedExtensions;
passthru.withJIT = postgresqlWithPackages { inherit (postgresql)
psqlSchema
version
;
withJIT = postgresqlWithPackages {
inherit buildEnv; inherit buildEnv;
postgresql = postgresql.withJIT; postgresql = postgresql.withJIT;
} f; } f;
passthru.withoutJIT = postgresqlWithPackages { withoutJIT = postgresqlWithPackages {
inherit buildEnv; inherit buildEnv;
postgresql = postgresql.withoutJIT; postgresql = postgresql.withoutJIT;
} f; } f;
}; };
};
in in
# passed by <major>.nix # passed by <major>.nix