fix: keep the mirror readable under a umask that masks the owner's read bit
Build and publish container / build (pull_request) Successful in 15m16s
Build and publish container / build (pull_request) Successful in 15m16s
The umask handling added for group access cleared only the group bits and left owner and other to the environment. A container whose umask carries 0400 then produces mirror directories of mode 0300: writable and enterable, unreadable to the very run that created them, and unreadable to anything serving the share. Clear the owner read and execute bits from the umask as well. The `other` bits stay where the environment puts them, because whether the mirror is world-readable is a real policy question; being able to read a directory the process itself just created is not. Files were never exposed to this: mkstemp sets 0600 outright and copy2 takes the source file's mode, both ignoring the umask.
This commit is contained in:
@@ -63,9 +63,14 @@ Everything written into the mirror is made group-readable, and its directories
|
||||
group-traversable, so the mirror can be read back by whatever serves it. Neither
|
||||
writer does that unaided: the temporary file an encode renames into place is
|
||||
created `0600` regardless of the umask, and a straight copy of an existing MP3
|
||||
inherits the mode of a source file in a library this tool does not own. Only the
|
||||
group bits are touched; whether the mirror is world-readable stays with the
|
||||
umask, as does the ownership.
|
||||
inherits the mode of a source file in a library this tool does not own.
|
||||
|
||||
Directories are handled by clearing the owner and group read/execute bits from
|
||||
the process umask, once, at startup. Owner as well as group, because a umask
|
||||
carrying `0400` produces directories of mode `0300` — writable and enterable,
|
||||
unreadable to the very run that created them. The `other` bits are left where
|
||||
the umask puts them: whether the mirror is world-readable is a genuine policy
|
||||
question, and so is its ownership.
|
||||
|
||||
Mirror files written before this existed are topped up on the next pass. Their
|
||||
mtimes are correct, so nothing else would revisit them — and they are not
|
||||
|
||||
Reference in New Issue
Block a user