about summary refs log tree commit diff
path: root/pkgs/development/compilers
diff options
context:
space:
mode:
authorAndreas Rammhold <andreas@rammhold.de>2020-09-28 19:43:54 +0200
committerAndreas Rammhold <andreas@rammhold.de>2020-09-28 22:55:20 +0200
commit9630d5c07fbdb264fec79f428b0c65366a356a72 (patch)
tree90dc6224c922ecf4937b9cd8ff648028adbdef61 /pkgs/development/compilers
parentcd7db06935196264f72d7b4041f22d46dce16ecb (diff)
downloadnixlib-9630d5c07fbdb264fec79f428b0c65366a356a72.tar
nixlib-9630d5c07fbdb264fec79f428b0c65366a356a72.tar.gz
nixlib-9630d5c07fbdb264fec79f428b0c65366a356a72.tar.bz2
nixlib-9630d5c07fbdb264fec79f428b0c65366a356a72.tar.lz
nixlib-9630d5c07fbdb264fec79f428b0c65366a356a72.tar.xz
nixlib-9630d5c07fbdb264fec79f428b0c65366a356a72.tar.zst
nixlib-9630d5c07fbdb264fec79f428b0c65366a356a72.zip
nixos/security/wrapper: ensure the tmpfs is not world writeable
The /run/wrapper directory is a tmpfs. Unfortunately, it's mounted with
its root directory has the standard (for tmpfs) mode: 1777 (world writeable,
sticky -- the standard mode of shared temporary directories). This means that
every user can create new files and subdirectories there, but can't
move/delete/rename files that belong to other users.
Diffstat (limited to 'pkgs/development/compilers')
0 files changed, 0 insertions, 0 deletions