setup: tighten ownership checks post CVE-2022-24765