Harden CUPS printer discovery
Run cups-browsed as a locked service account with a dedicated cache and a focused systemd sandbox. Restrict automatic queues to driverless IPP printers, remove wheel from passwordless CUPS administration, replace cups-pdf with Polkit-backed setup, and migrate existing systems safely. Reported-By: Erik Hunstad (Bad Sector Labs) Co-Authored-By: Daybreak Blue <noreply@openai.com>
This commit is contained in:
co-authored by
Daybreak Blue
parent
946704f309
commit
5c336885d2
@@ -7,5 +7,6 @@ run_logged "$OMARCHY_INSTALL/config/ssh-keepalive.sh"
|
||||
run_logged "$OMARCHY_INSTALL/config/docker.sh"
|
||||
run_logged "$OMARCHY_INSTALL/config/snapper.sh"
|
||||
run_logged "$OMARCHY_INSTALL/config/locate.sh"
|
||||
run_logged "$OMARCHY_INSTALL/config/printing.sh"
|
||||
run_logged "$OMARCHY_INSTALL/config/enable-services.sh"
|
||||
run_logged "$OMARCHY_INSTALL/config/firewall.sh"
|
||||
|
||||
@@ -0,0 +1,83 @@
|
||||
# cups-browsed manages queues through CUPS and does not need Unix root. Give
|
||||
# only its locked service account passwordless CUPS administration; interactive
|
||||
# users go through cups-pk-helper and Polkit instead.
|
||||
cups_files_conf="${OMARCHY_CUPS_FILES_CONF:-/etc/cups/cups-files.conf}"
|
||||
cups_browsed_sysusers_conf="${OMARCHY_CUPS_BROWSED_SYSUSERS_CONF:-/etc/sysusers.d/omarchy-cups-browsed.conf}"
|
||||
|
||||
if [[ -f $cups_browsed_sysusers_conf ]]; then
|
||||
systemd-sysusers "$cups_browsed_sysusers_conf"
|
||||
fi
|
||||
|
||||
if [[ -L $cups_files_conf ]]; then
|
||||
echo "Refusing to rewrite symlinked CUPS authorization config: $cups_files_conf" >&2
|
||||
false
|
||||
elif [[ -f $cups_files_conf ]]; then
|
||||
staged_conf=$(mktemp --tmpdir="${cups_files_conf%/*}" ".${cups_files_conf##*/}.XXXXXX")
|
||||
|
||||
if ! awk '
|
||||
NR == FNR {
|
||||
if ($1 == "SystemGroup") {
|
||||
for (i = 2; i <= NF; i++) {
|
||||
if (substr($i, 1, 1) == "#")
|
||||
break
|
||||
if ($i != "wheel" && !seen_group[$i]) {
|
||||
system_groups[++system_group_count] = $i
|
||||
seen_group[$i] = 1
|
||||
}
|
||||
}
|
||||
}
|
||||
next
|
||||
}
|
||||
|
||||
$1 == "SystemGroup" {
|
||||
comment_start = index($0, "#")
|
||||
if (!wrote_system_group) {
|
||||
printf "SystemGroup"
|
||||
for (i = 1; i <= system_group_count; i++)
|
||||
printf " %s", system_groups[i]
|
||||
if (!seen_group["cups-browsed"])
|
||||
printf " cups-browsed"
|
||||
if (comment_start)
|
||||
printf " %s", substr($0, comment_start)
|
||||
print ""
|
||||
wrote_system_group = 1
|
||||
} else if (comment_start) {
|
||||
print substr($0, comment_start)
|
||||
}
|
||||
next
|
||||
}
|
||||
|
||||
$1 == "PeerCred" {
|
||||
comment_start = index($0, "#")
|
||||
if (!saw_peer_cred) {
|
||||
printf "PeerCred on"
|
||||
if (comment_start)
|
||||
printf " %s", substr($0, comment_start)
|
||||
print ""
|
||||
} else if (comment_start) {
|
||||
print substr($0, comment_start)
|
||||
}
|
||||
saw_peer_cred = 1
|
||||
next
|
||||
}
|
||||
|
||||
{ print }
|
||||
|
||||
END {
|
||||
if (!wrote_system_group)
|
||||
print "SystemGroup sys root cups-browsed"
|
||||
if (!saw_peer_cred)
|
||||
print "PeerCred on"
|
||||
}
|
||||
' "$cups_files_conf" "$cups_files_conf" >"$staged_conf"; then
|
||||
rm -f "$staged_conf"
|
||||
false
|
||||
fi
|
||||
|
||||
if ! chmod --reference="$cups_files_conf" "$staged_conf" ||
|
||||
! chown --reference="$cups_files_conf" "$staged_conf" ||
|
||||
! mv -f "$staged_conf" "$cups_files_conf"; then
|
||||
rm -f "$staged_conf"
|
||||
false
|
||||
fi
|
||||
fi
|
||||
@@ -19,7 +19,7 @@ cliamp
|
||||
cups
|
||||
cups-browsed
|
||||
cups-filters
|
||||
cups-pdf
|
||||
cups-pk-helper
|
||||
ddcutil
|
||||
docker
|
||||
docker-buildx
|
||||
|
||||
Reference in New Issue
Block a user