diff options
| author | Mark Johnston <markj@FreeBSD.org> | 2025-01-28 14:23:06 +0000 |
|---|---|---|
| committer | Mark Johnston <markj@FreeBSD.org> | 2025-01-28 16:07:11 +0000 |
| commit | 93836ff92be84a1d4e7611577ffe116a0e30d008 (patch) | |
| tree | 2afe623d6f67285ce23b370376d2e6575ae98442 | |
| parent | cd1f435f4819935155d660aca97b6967d7992846 (diff) | |
etcupdate: Restrict access to the conflicts directory
In the window during conflict resolution, copies of installed files with
conflicts are added here with the default mode. Restrict access.
PR: 277470
Reviewed by: philip, jhb, emaste
Differential Revision: https://reviews.freebsd.org/D48576
(cherry picked from commit c43ae7ab4bf89c2b274c1cbefe663c456e9211d1)
| -rwxr-xr-x | usr.sbin/etcupdate/etcupdate.sh | 3 |
1 files changed, 3 insertions, 0 deletions
diff --git a/usr.sbin/etcupdate/etcupdate.sh b/usr.sbin/etcupdate/etcupdate.sh index 39d1f9e56a54..7bddd6593b56 100755 --- a/usr.sbin/etcupdate/etcupdate.sh +++ b/usr.sbin/etcupdate/etcupdate.sh @@ -1611,6 +1611,9 @@ EOF # Initialize conflicts and warnings handling. rm -f $WARNINGS mkdir -p $CONFLICTS + if ! chmod 0700 ${CONFLICTS}; then + panic "Unable to set permissions on conflicts directory" + fi # Ignore removed files for the pre-world case. A pre-world # update uses a stripped-down tree. |
