aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMark Johnston <markj@FreeBSD.org>2025-01-28 14:23:06 +0000
committerMark Johnston <markj@FreeBSD.org>2025-01-29 17:27:37 +0000
commitc55000e7c233573bae396df6099dcfc564abdcb7 (patch)
tree739ee95ddf486e6a74cafc04f8353e5e4b025b7a
parentfaa47d299a0ed3af49989495bd1debd469dc54e2 (diff)
etcupdate: Restrict access to the conflicts directory
In the window during conflict resolution, copies of installed files with conflicts are added here with the default mode. Restrict access. Approved by: so Security: FreeBSD-SA-25:03.etcupdate PR: 277470 Reviewed by: philip, jhb, emaste Differential Revision: https://reviews.freebsd.org/D48576 (cherry picked from commit c43ae7ab4bf89c2b274c1cbefe663c456e9211d1) (cherry picked from commit 93836ff92be84a1d4e7611577ffe116a0e30d008)
-rwxr-xr-xusr.sbin/etcupdate/etcupdate.sh3
1 files changed, 3 insertions, 0 deletions
diff --git a/usr.sbin/etcupdate/etcupdate.sh b/usr.sbin/etcupdate/etcupdate.sh
index 39d1f9e56a54..7bddd6593b56 100755
--- a/usr.sbin/etcupdate/etcupdate.sh
+++ b/usr.sbin/etcupdate/etcupdate.sh
@@ -1611,6 +1611,9 @@ EOF
# Initialize conflicts and warnings handling.
rm -f $WARNINGS
mkdir -p $CONFLICTS
+ if ! chmod 0700 ${CONFLICTS}; then
+ panic "Unable to set permissions on conflicts directory"
+ fi
# Ignore removed files for the pre-world case. A pre-world
# update uses a stripped-down tree.