Hi Maxime,
Maxime Devos skribis:
> On Tue, 2021-02-23 at 16:30 +0100, Ludovic Courtès wrote:
>> Hi,
>>
>> Maxime Devos skribis:
>>
>> > Is all addressed now? (Aside from the TOCTTOU.)
>>
>> Yes, thank you!
>
> If all is addressed now, could you apply the patch?
> I don't see it in master
On Tue, 2021-02-23 at 16:30 +0100, Ludovic Courtès wrote:
> Hi,
>
> Maxime Devos skribis:
>
> > Is all addressed now? (Aside from the TOCTTOU.)
>
> Yes, thank you!
If all is addressed now, could you apply the patch?
I don't see it in master yet and I don't have commit access.
Greetings,
Hi,
Maxime Devos skribis:
> Is all addressed now? (Aside from the TOCTTOU.)
Yes, thank you!
Ludo’.
> Perhaps add a couple of lines explaining that this fixes a potential
> security issue, with a link to this thread.
Done. But since
> > Currently, there's a TOCTTOU race. This can be addressed
> > once guile has bindings for fstatat, openat and friends.
... I only
evos
> Date: Sun, 14 Feb 2021 12:57:32 +0100
> Subject: [PATCH] services: prevent following symlinks during activation
^
Nitpick: we usually capitalize here and in the commit log.
Perhaps add a couple of lines explaining that this fixes a potential
security iss
From 2c3968f658ada27d2062a960d229f3db9cfe208c Mon Sep 17 00:00:00 2001
From: Maxime Devos
Date: Sun, 14 Feb 2021 12:57:32 +0100
Subject: [PATCH] services: prevent following symlinks during activation
Currently, there's a TOCTTOU race. This can be addressed
once guile has bindings for fstatat, o
Hi Maxime,
Maxime Devos skribis:
> From ad10c577eb1f13b9b66ea387648671df33b869d7 Mon Sep 17 00:00:00 2001
> From: Maxime Devos
> Date: Sun, 14 Feb 2021 12:57:32 +0100
> Subject: [PATCH] services: prevent following symlinks during activation
>
> Currently, there's a TOCTT
Hi,
On +2021-02-14 13:29:29 +0100, Maxime Devos wrote:
> On Sat, 2021-02-06 at 22:26 +0100, Ludovic Courtès wrote:
> >
> > [...]
> > I understand the TOCTTOU race. However, activation code runs in two
> > situations: when booting the system (before shepherd takes
On Sat, 2021-02-06 at 22:26 +0100, Ludovic Courtès wrote:
>
> [...]
> I understand the TOCTTOU race. However, activation code runs in two
> situations: when booting the system (before shepherd takes over), and
> upon ‘guix system reconfigure’ completion.
>
> When bootin