diff options
author | Lee Chang Yeon <cyeon.lee@samsung.com> | 2014-04-08 19:25:34 +0900 |
---|---|---|
committer | Lee Chang Yeon <cyeon.lee@samsung.com> | 2014-04-08 19:25:34 +0900 |
commit | d5a674d26d1b4ed377fe98c403f77f3f21bbb473 (patch) | |
tree | bf5b9e185e8663c28bbe614ff72f96ad3119e4da /launchd/privileged_startx/10-tmpdirs.cpp | |
parent | 1d888804982d06910f10c1b6a9b29e7b9a23f550 (diff) | |
download | xinit-d5a674d26d1b4ed377fe98c403f77f3f21bbb473.tar.gz xinit-d5a674d26d1b4ed377fe98c403f77f3f21bbb473.tar.bz2 xinit-d5a674d26d1b4ed377fe98c403f77f3f21bbb473.zip |
Imported Upstream version 1.3.3upstream/1.3.3upstream
Diffstat (limited to 'launchd/privileged_startx/10-tmpdirs.cpp')
-rwxr-xr-x | launchd/privileged_startx/10-tmpdirs.cpp | 34 |
1 files changed, 28 insertions, 6 deletions
diff --git a/launchd/privileged_startx/10-tmpdirs.cpp b/launchd/privileged_startx/10-tmpdirs.cpp index 8012597..4366696 100755 --- a/launchd/privileged_startx/10-tmpdirs.cpp +++ b/launchd/privileged_startx/10-tmpdirs.cpp @@ -1,5 +1,5 @@ XCOMM!/bin/sh -XCOMM Copyright (c) 2008 Apple Inc. +XCOMM Copyright (c) 2008-2012 Apple Inc. XCOMM XCOMM Permission is hereby granted, free of charge, to any person XCOMM obtaining a copy of this software and associated documentation files @@ -36,11 +36,33 @@ else MKTEMP=mktemp fi +STAT=/usr/bin/stat + for dir in /tmp/.ICE-unix /tmp/.X11-unix /tmp/.font-unix ; do - XCOMM Use mktemp rather than mkdir to avoid possible security issue - XCOMM if $dir exists and is a symlink - if ${MKTEMP} -d ${dir} >& /dev/null ; then - chmod 1777 $dir - chown root:wheel $dir + success=0 + for attempt in 1 2 3 4 5 ; do + check=`${STAT} -f '%#p %u %g' ${dir} 2> /dev/null` + if [ "${check}" = "041777 0 0" ] ; then + success=1 + break + elif [ -n "${check}" ] ; then + saved=$(${MKTEMP} -d ${dir}-XXXXXXXX) + mv ${dir} ${saved} + echo "${dir} exists but is insecure. It has been moved into ${saved}" >&2 + fi + + # Use mktemp rather than mkdir to avoid possible security issue + # if $dir exists and is a symlink (ie protect against a race + # against the above check) + if ${MKTEMP} -d ${dir} >& /dev/null ; then + chmod 1777 $dir + chown root:wheel $dir + success=1 + break + fi + done + + if [ "${success}" -eq 0 ] ; then + echo "Could not successfully create ${dir}" >&2 fi done |