From eddd8e89a6a5d105e366d53a626fc62b773b1665 Mon Sep 17 00:00:00 2001 From: Matthias Bernt Date: Fri, 30 Sep 2022 14:33:40 +0200 Subject: [PATCH 1/4] extend security docs by adding data referred by data tables --- doc/source/admin/security.md | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/doc/source/admin/security.md b/doc/source/admin/security.md index 564cd590f88..d32df20d719 100644 --- a/doc/source/admin/security.md +++ b/doc/source/admin/security.md @@ -3,9 +3,13 @@ ### Protect Galaxy against data loss due to misbehaving tools Tools have access to the paths of input and output data sets which are stored in -``file_path`` and by default the credentials used for running tools are the same -as for running Galaxy. Thus it is possible that a tool modifies data in Galaxy's -``file_path``. Examples of such potential changes are: +``file_path``. If tools use reference data stored in data tables also data in +``tool_data_path`` and ``shed_tool_data_path`` (plus data referred in hand +crafted data tables and refgenie configuration). + +By default the credentials used for running tools are the same as for running +Galaxy. Thus it is possible that a tool modifies data in Galaxy's ``file_path``. +Examples of such potential changes are: - Creation of additional files, e.g. indices, which is a problem for cleaning up data, because Galaxy does not know about these files. - Removal of tool input or output files. This will create problems with other tools using these datasets (note that most tool repositories use CI tests to to avoid this, but the problem may still occur). @@ -14,7 +18,7 @@ Note that a tool only knows the paths to its inputs and outputs, but if using th There are three approaches to protect Galaxy against these risks: -- Use different credentials for running tools. This can be configured using the ``real_system_username`` config variable. +- Use different credentials for running tools and make ``file_path``, ``tool_data_path`` writable only by the user running Galaxy. This can be configured using the ``real_system_username`` config variable. Note that this implies ``outputs_to_working_directory``. - Configure Galaxy to run jobs in a container and enable ``outputs_to_working_directory``. Then the tool will execute in an environment that allows write access only for the job working dir. All other paths will be accessible read only. - Use [Pulsar](https://pulsar.readthedocs.io/) to stage inputs and outputs. From 37594348f97bc4ee45b70cac6b3422d579c6d96a Mon Sep 17 00:00:00 2001 From: M Bernt Date: Fri, 30 Sep 2022 19:00:54 +0200 Subject: [PATCH 2/4] Update doc/source/admin/security.md --- doc/source/admin/security.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/doc/source/admin/security.md b/doc/source/admin/security.md index d32df20d719..ab20b14e91e 100644 --- a/doc/source/admin/security.md +++ b/doc/source/admin/security.md @@ -18,8 +18,8 @@ Note that a tool only knows the paths to its inputs and outputs, but if using th There are three approaches to protect Galaxy against these risks: -- Use different credentials for running tools and make ``file_path``, ``tool_data_path`` writable only by the user running Galaxy. This can be configured using the ``real_system_username`` config variable. Note that this implies ``outputs_to_working_directory``. - Configure Galaxy to run jobs in a container and enable ``outputs_to_working_directory``. Then the tool will execute in an environment that allows write access only for the job working dir. All other paths will be accessible read only. - Use [Pulsar](https://pulsar.readthedocs.io/) to stage inputs and outputs. +- If containers or pulsar are not an option the following strategy is suggested. Use different credentials for running tools which can be configured using the ``real_system_username`` config variable. Note that this implies ``outputs_to_working_directory``. Furthermore (in particular) ``file_path``, ``tool_data_path`` should be made writable only by the user running Galaxy. More information on pulsar configuration can be found in the [job configuration](jobs.md) documentation, and the other two are explained in [using a compute cluster](cluster.md). From e8adc1332404559837f0c5e36165ae4aea23c46c Mon Sep 17 00:00:00 2001 From: M Bernt Date: Fri, 30 Sep 2022 22:38:49 +0200 Subject: [PATCH 3/4] Apply suggestions from code review Co-authored-by: Nicola Soranzo --- doc/source/admin/security.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/doc/source/admin/security.md b/doc/source/admin/security.md index ab20b14e91e..00c9d56e178 100644 --- a/doc/source/admin/security.md +++ b/doc/source/admin/security.md @@ -3,9 +3,9 @@ ### Protect Galaxy against data loss due to misbehaving tools Tools have access to the paths of input and output data sets which are stored in -``file_path``. If tools use reference data stored in data tables also data in +``file_path``. If tools use reference data stored in data tables, they have access also to data in ``tool_data_path`` and ``shed_tool_data_path`` (plus data referred in hand -crafted data tables and refgenie configuration). +crafted loc files and refgenie configuration). By default the credentials used for running tools are the same as for running Galaxy. Thus it is possible that a tool modifies data in Galaxy's ``file_path``. @@ -20,6 +20,6 @@ There are three approaches to protect Galaxy against these risks: - Configure Galaxy to run jobs in a container and enable ``outputs_to_working_directory``. Then the tool will execute in an environment that allows write access only for the job working dir. All other paths will be accessible read only. - Use [Pulsar](https://pulsar.readthedocs.io/) to stage inputs and outputs. -- If containers or pulsar are not an option the following strategy is suggested. Use different credentials for running tools which can be configured using the ``real_system_username`` config variable. Note that this implies ``outputs_to_working_directory``. Furthermore (in particular) ``file_path``, ``tool_data_path`` should be made writable only by the user running Galaxy. +- If containers and Pulsar are not an option, it is possible to use different credentials for running tools. This can be configured using the ``real_system_username`` config variable. Note that this implies ``outputs_to_working_directory``. Furthermore, check that files in directories like ``file_path`` and ``tool_data_path`` are writable only by the user running Galaxy. More information on pulsar configuration can be found in the [job configuration](jobs.md) documentation, and the other two are explained in [using a compute cluster](cluster.md). From ffc26d5dddb60f0920b8dd696d20ce3b26943050 Mon Sep 17 00:00:00 2001 From: M Bernt Date: Thu, 13 Oct 2022 13:53:06 +0200 Subject: [PATCH 4/4] Update doc/source/admin/security.md Co-authored-by: Marius van den Beek --- doc/source/admin/security.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/doc/source/admin/security.md b/doc/source/admin/security.md index 00c9d56e178..3ff8aad21f9 100644 --- a/doc/source/admin/security.md +++ b/doc/source/admin/security.md @@ -20,6 +20,6 @@ There are three approaches to protect Galaxy against these risks: - Configure Galaxy to run jobs in a container and enable ``outputs_to_working_directory``. Then the tool will execute in an environment that allows write access only for the job working dir. All other paths will be accessible read only. - Use [Pulsar](https://pulsar.readthedocs.io/) to stage inputs and outputs. -- If containers and Pulsar are not an option, it is possible to use different credentials for running tools. This can be configured using the ``real_system_username`` config variable. Note that this implies ``outputs_to_working_directory``. Furthermore, check that files in directories like ``file_path`` and ``tool_data_path`` are writable only by the user running Galaxy. +- If containers and Pulsar are not an option, it is possible to use different credentials for running tools. This can be configured using the ``real_system_username`` config variable. Note that you also need to enable ``outputs_to_working_directory`` when enabling ``real_system_username``. Furthermore, check that files in directories like ``file_path`` and ``tool_data_path`` are writable only by the user running Galaxy. More information on pulsar configuration can be found in the [job configuration](jobs.md) documentation, and the other two are explained in [using a compute cluster](cluster.md).