fix(hardening-basic): reclaim the dirty-page ratio twins that zero the bytes keys #9

Merged
claudiomaradonna merged 1 commit from fix/hardening-sysctl-dirty-twins into main 2026-09-25 18:31:10 +02:00

Why

7aaae88 added fixed dirty-page ceilings (vm.dirty_bytes,
vm.dirty_background_bytes) to 99-hardening.conf. The kernel treats
each *_bytes/*_ratio pair as one limit and zeroes one when the other is
written. So a vm.dirty_ratio or vm.dirty_background_ratio line in
/etc/sysctl.conf, which is read after every drop-in, leaves the
*_bytes keys at 0. The read-back assert then failed with advice that
couldn't work: it said to grep for a *_bytes line that doesn't exist,
and hardening_sysctl_edit_sysctl_conf had nothing to comment out,
because no line names the lost key.

What changed

  • The sysctl block knows the two dirty pairs. The failure message, and the
    --check report, name the *_ratio key to look for. With
    hardening_sysctl_edit_sysctl_conf on, the reclaim comments out that
    line as well.
  • Fixed a bug in the reclaim that predates this change. Its pattern began
    with \s*, which in multiline mode let ^ anchor on a blank line above
    the key: the marker was written onto the blank line and the key stayed
    live. The pattern now matches spaces and tabs only.
  • Under --check with the flag on, the report no longer says the reclaim
    failed, since check mode never attempts it. It points at the diff
    instead.

Non-goal: the net.ipv4.ip_forward alias still refuses and says why.
Reclaiming it can cut routing on a gateway, and the README keeps that
choice.

Verification

  • make check: exit 0, ansible-lint at production with 0 warnings.
  • The sysctl gate's stub now zeroes the paired key the way the kernel
    does. Cases 18–19 cover the message and the reclaim. The blank-line
    assertion fails when the old pattern is restored.
  • On a live host: --check --diff showed only the drop-in values and the
    two *_ratio lines being commented out. The real run ended with
    "52 sysctl keys hold the values this role set", failed=0.
  • Not run: make test / make verify (no podman where this was built;
    molecule doesn't exercise this block anyway) and a second live run to
    confirm idempotence (gate case 19 covers it).
## Why 7aaae88 added fixed dirty-page ceilings (`vm.dirty_bytes`, `vm.dirty_background_bytes`) to `99-hardening.conf`. The kernel treats each `*_bytes`/`*_ratio` pair as one limit and zeroes one when the other is written. So a `vm.dirty_ratio` or `vm.dirty_background_ratio` line in `/etc/sysctl.conf`, which is read after every drop-in, leaves the `*_bytes` keys at 0. The read-back assert then failed with advice that couldn't work: it said to grep for a `*_bytes` line that doesn't exist, and `hardening_sysctl_edit_sysctl_conf` had nothing to comment out, because no line names the lost key. ## What changed - The sysctl block knows the two dirty pairs. The failure message, and the `--check` report, name the `*_ratio` key to look for. With `hardening_sysctl_edit_sysctl_conf` on, the reclaim comments out that line as well. - Fixed a bug in the reclaim that predates this change. Its pattern began with `\s*`, which in multiline mode let `^` anchor on a blank line above the key: the marker was written onto the blank line and the key stayed live. The pattern now matches spaces and tabs only. - Under `--check` with the flag on, the report no longer says the reclaim failed, since check mode never attempts it. It points at the diff instead. Non-goal: the `net.ipv4.ip_forward` alias still refuses and says why. Reclaiming it can cut routing on a gateway, and the README keeps that choice. ## Verification - `make check`: exit 0, ansible-lint at `production` with 0 warnings. - The sysctl gate's stub now zeroes the paired key the way the kernel does. Cases 18–19 cover the message and the reclaim. The blank-line assertion fails when the old pattern is restored. - On a live host: `--check --diff` showed only the drop-in values and the two `*_ratio` lines being commented out. The real run ended with "52 sysctl keys hold the values this role set", `failed=0`. - Not run: `make test` / `make verify` (no podman where this was built; molecule doesn't exercise this block anyway) and a second live run to confirm idempotence (gate case 19 covers it).
vm.dirty_bytes/vm.dirty_ratio and vm.dirty_background_bytes/
vm.dirty_background_ratio are one kernel limit each in two units, and
writing one of a pair zeroes the other. A *_ratio line in
/etc/sysctl.conf, read after every drop-in, therefore left the *_bytes
keys from 7aaae88 at 0. The assert blamed a *_bytes line that does not
exist, and hardening_sysctl_edit_sysctl_conf could not reclaim anything
because no line spells the lost key.

The sysctl block now knows the two pairs: the failure names the *_ratio
twin to look for, and the reclaim comments that line out as well. The
ip_forward alias keeps refusing, since reclaiming it can cut routing.

Two bugs in the reclaim itself, found by --check --diff on a live host:
- its pattern began with \s*, which in multiline mode let ^ anchor on a
  blank line above the key; the marker landed there and the key stayed
  live. It now matches blanks only.
- under --check with the flag on, the report said the reclaim had
  failed, although check mode never attempts it. It now points at the
  diff instead.

The sysctl gate's stub models the twin zeroing, and cases 18-19 plus
the blank-line and check-mode assertions cover all three.
claudiomaradonna deleted branch fix/hardening-sysctl-dirty-twins 2026-09-25 18:31:14 +02:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
claudiomaradonna/castrum!9
No description provided.