This is the mail archive of the
cygwin
mailing list for the Cygwin project.
base-files: New files to fix permission issues (was Re: 1.7.10/1.7.11: .Net programs started from a cygwin console may fail.)
- From: Corinna Vinschen <corinna-cygwin at cygwin dot com>
- To: cygwin at cygwin dot com
- Date: Fri, 2 Mar 2012 11:46:05 +0100
- Subject: base-files: New files to fix permission issues (was Re: 1.7.10/1.7.11: .Net programs started from a cygwin console may fail.)
- References: <70952A932255A2489522275A628B97C3129F49F7@xmb-sjc-233.amer.cisco.com> <20120301100820.GC2257@calimero.vinschen.de>
- Reply-to: cygwin at cygwin dot com
On Mar 1 11:08, Corinna Vinschen wrote:
> # Fix a problem introduced by older versions of setup.exe
> [...]
David, ping? Can we add the below two files to base-files asap and
remove the tmp/temp workaround, please?
/etc/profile.d/1777fix.csh:
#!/bin/tcsh
# Fix a problem introduced by older versions of setup.exe
# Read comments in /etc/profile.d/1777fix.sh for more information.
set GUARDFILE = "/etc/.1777fix"
if ( ! -f "${GUARDFILE}" ) then
/bin/bash /etc/profile.d/1777fix.sh
endif
/etc/profile.d/1777fix.sh:
#!/bin/bash
# Fix a problem introduced by older versions of setup.exe
# Directories with 1777 permissions were erroneously created
# with 777 inheritable default permissions. This is a security
# problem for non-Cygwin apps using these folders. This is
# especially tragic in case of /tmp.
GUARDFILE="/etc/.1777fix"
DIRLIST="/home /tmp /usr/tmp /var/log /var/run"
if [ ! -f "${GUARDFILE}" ]
then
cnt=0
success=0
for file in ${DIRLIST}
do
# We test if the default group or other permissions are rwx.
# If so, it's dangerous and highly likely that these are still
# the permissions set by setup.exe
if getfacl "${file}" | grep -Eq 'default:(group:|other):rwx'
then
cnt=$(expr $cnt + 1)
setfacl -m d:g::r-x,d:o:r-x "${file}" 2>/dev/null \
&& success=$(expr $success + 1)
fi
done
# If no file needed treatment, or if all setfacl calls succeeded,
# create the
[ $cnt -eq $success ] && touch "${GUARDFILE}"
fi
Thanks,
Corinna
--
Corinna Vinschen Please, send mails regarding Cygwin to
Cygwin Project Co-Leader cygwin AT cygwin DOT com
Red Hat
--
Problem reports: http://cygwin.com/problems.html
FAQ: http://cygwin.com/faq/
Documentation: http://cygwin.com/docs.html
Unsubscribe info: http://cygwin.com/ml/#unsubscribe-simple