Re: [pacman-dev] [PATCH] Set "secure" $HOME

2019-08-12 Thread Eli Schwartz
On August 12, 2019 12:45:40 PM EDT, Jonathon Fernyhough wrote: > By default, $HOME is that of the build user. This is usually not a > problem in ephemeral build containers/chroots but can allow some files > to escape into the filesystem where `makepkg` is run outside of a > chroot. > > There can

Re: [pacman-dev] [PATCH] Set "secure" $HOME

2019-08-12 Thread Levente Polyak
On August 12, 2019 6:45:40 PM GMT+02:00, Jonathon Fernyhough wrote: >By default, $HOME is that of the build user. This is usually not a >problem in ephemeral build containers/chroots but can allow some files >to escape into the filesystem where `makepkg` is run outside of a >chroot. > >There can

[pacman-dev] [PATCH] Set "secure" $HOME

2019-08-12 Thread Jonathon Fernyhough
By default, $HOME is that of the build user. This is usually not a problem in ephemeral build containers/chroots but can allow some files to escape into the filesystem where `makepkg` is run outside of a chroot. There can also be instances of generated files (e.g. cache, precompiled bytecode) bein