Bug 1989544

Summary: coreos-installer: Backport install: restrict access permissions on /boot/ignition{,/config.ign} [rhel-8]
Product: Red Hat Enterprise Linux 8 Reporter: Cedric Buissart <cbuissar>
Component: coreos-installerAssignee: Antonio Murdaca <amurdaca>
Status: CLOSED DEFERRED QA Contact: Xiaofeng Wang <xiaofwan>
Severity: low Docs Contact:
Priority: low    
Version: 8.5CC: bgilbert, jlebon
Target Milestone: betaKeywords: Security, SecurityTracking, Triaged
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-10-29 11:08:50 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2018478    

Description Cedric Buissart 2021-08-03 12:46:19 UTC
This upstream commit looks like a potential security fix, it is
currently not part of the package:
    + https://github.com/fedora-iot/coreos-installer/commit/2a36405339c87b16ed6c76e91ad5b76638fbdb0c


Would it be feasible to integrate it before GA ?

Comment 1 Antonio Murdaca 2021-10-13 11:48:04 UTC
I'm going to rebuild and bump coreos-installer for 8.5 - this will land there as part of the bump