public inbox for development@lists.ipfire.org
 help / color / mirror / Atom feed
From: "Peter Müller" <peter.mueller@ipfire.org>
To: development@lists.ipfire.org
Subject: [PATCH] backup: Set owner of {ex,in}clude{,.user} files to "root"
Date: Mon, 26 Sep 2022 18:50:08 +0000	[thread overview]
Message-ID: <b1ba905d-db6b-3bce-08b1-0d4763bb1576@ipfire.org> (raw)

[-- Attachment #1: Type: text/plain, Size: 2597 bytes --]

Since these files are static, there is no legitimate reason why they
should be owned (hence writable) by "nobody". Also, according to
configroot's LFS file, this is the intended behaviour for the *.user
files, which is then overwritten by the backup LFS file. Therefore, set
the file mode of these statically - configroot does not feature other
files in /var/ipfire/backup/ anyway.

Signed-off-by: Peter Müller <peter.mueller(a)ipfire.org>
---
 lfs/backup     | 6 +++---
 lfs/configroot | 2 +-
 2 files changed, 4 insertions(+), 4 deletions(-)

diff --git a/lfs/backup b/lfs/backup
index 6f686bf22..cf1e58c7e 100644
--- a/lfs/backup
+++ b/lfs/backup
@@ -1,7 +1,7 @@
 ###############################################################################
 #                                                                             #
 # IPFire.org - A linux based firewall                                         #
-# Copyright (C) 2007-2021  IPFire Team  <info(a)ipfire.org>                     #
+# Copyright (C) 2007-2022  IPFire Team  <info(a)ipfire.org>                     #
 #                                                                             #
 # This program is free software: you can redistribute it and/or modify        #
 # it under the terms of the GNU General Public License as published by        #
@@ -61,10 +61,10 @@ $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects))
 	@$(PREBUILD)
 	-mkdir -p /var/ipfire/backup/bin
 	install -v -m 755 -o root $(DIR_SRC)/config/backup/backup.pl /var/ipfire/backup/bin
-	install -v -m 644 $(DIR_SRC)/config/backup/include /var/ipfire/backup/
-	install -v -m 644 $(DIR_SRC)/config/backup/exclude /var/ipfire/backup/
 	chown nobody:nobody -R /var/ipfire/backup/
 	chown root:root -R /var/ipfire/backup/bin/
+	install -v -m 644 $(DIR_SRC)/config/backup/include /var/ipfire/backup/
+	install -v -m 644 $(DIR_SRC)/config/backup/exclude /var/ipfire/backup/
 	-mkdir -p /var/ipfire/backup/addons
 	-mkdir -p /var/ipfire/backup/addons/includes
 	-mkdir -p /var/ipfire/backup/addons/backup
diff --git a/lfs/configroot b/lfs/configroot
index 31b9a9463..f09307274 100644
--- a/lfs/configroot
+++ b/lfs/configroot
@@ -169,7 +169,7 @@ $(TARGET) :
 	# Configroot permissions
 	chown -R nobody:nobody $(CONFIG_ROOT)
 	chown      root:root   $(CONFIG_ROOT)
-	for i in backup/ *.pl addon-lang/ langs/ ; do \
+	for i in backup/exclude.user backup/include.user *.pl addon-lang/ langs/ ; do \
             chown -R root:root $(CONFIG_ROOT)/$$i; \
 	done
 	chown -Rv root:root $(CONFIG_ROOT)/*/bin
-- 
2.35.3

             reply	other threads:[~2022-09-26 18:50 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2022-09-26 18:50 Peter Müller [this message]
2022-09-27 10:03 ` [PATCH] backup: Set owner of {ex, in}clude{, .user} " Michael Tremer

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=b1ba905d-db6b-3bce-08b1-0d4763bb1576@ipfire.org \
    --to=peter.mueller@ipfire.org \
    --cc=development@lists.ipfire.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox