mirror of
https://github.com/clearlinux/swupd-client.git
synced 2026-10-03 23:38:25 +00:00
As the state_dir (normally /var/lib/swupd) contains things like the downloaded bundles, it is important that there is no access to non-root users who could potentially explot races to replace files between them being checked and them being installed. Ensure that the state_dir is root owned, and mode 0700, as well as the critical directories below it. Note that a proper fix would involve using chdir to move into the directory and only use relative paths. This would prevent faulty permissions higher up the directory tree being exploited. It *might* be possible to use openat(2) to prevent this exploitation. Add a test to ensure that the enforcement is taking place. Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>