diff options
| author | Mark Johnston <markj@FreeBSD.org> | 2025-01-28 14:23:06 +0000 |
|---|---|---|
| committer | Mark Johnston <markj@FreeBSD.org> | 2025-01-28 16:07:26 +0000 |
| commit | 17e935f1f327d7d4464e53f4f3d2347a51623f82 (patch) | |
| tree | 207d84d40db1e0901a82a45c351a556348ee767e | |
| parent | 477403117f06ce5b1de006925fc35d1fbec8dc76 (diff) | |
etcupdate: Restrict access to the conflicts directory
In the window during conflict resolution, copies of installed files with
conflicts are added here with the default mode. Restrict access.
PR: 277470
Reviewed by: philip, jhb, emaste
Differential Revision: https://reviews.freebsd.org/D48576
(cherry picked from commit c43ae7ab4bf89c2b274c1cbefe663c456e9211d1)
| -rwxr-xr-x | usr.sbin/etcupdate/etcupdate.sh | 3 |
1 files changed, 3 insertions, 0 deletions
diff --git a/usr.sbin/etcupdate/etcupdate.sh b/usr.sbin/etcupdate/etcupdate.sh index 6d8f58d39c54..ed259da7420f 100755 --- a/usr.sbin/etcupdate/etcupdate.sh +++ b/usr.sbin/etcupdate/etcupdate.sh @@ -1561,6 +1561,9 @@ EOF # Initialize conflicts and warnings handling. rm -f $WARNINGS mkdir -p $CONFLICTS + if ! chmod 0700 ${CONFLICTS}; then + panic "Unable to set permissions on conflicts directory" + fi # Ignore removed files for the pre-world case. A pre-world # update uses a stripped-down tree. |
