On Mar 1 11:08, Corinna Vinschen wrote: > # Fix a problem introduced by older versions of setup.exe > [...]
David, ping? Can we add the below two files to base-files asap and remove the tmp/temp workaround, please? /etc/profile.d/1777fix.csh: #!/bin/tcsh # Fix a problem introduced by older versions of setup.exe # Read comments in /etc/profile.d/1777fix.sh for more information. set GUARDFILE = "/etc/.1777fix" if ( ! -f "${GUARDFILE}" ) then /bin/bash /etc/profile.d/1777fix.sh endif /etc/profile.d/1777fix.sh: #!/bin/bash # Fix a problem introduced by older versions of setup.exe # Directories with 1777 permissions were erroneously created # with 777 inheritable default permissions. This is a security # problem for non-Cygwin apps using these folders. This is # especially tragic in case of /tmp. GUARDFILE="/etc/.1777fix" DIRLIST="/home /tmp /usr/tmp /var/log /var/run" if [ ! -f "${GUARDFILE}" ] then cnt=0 success=0 for file in ${DIRLIST} do # We test if the default group or other permissions are rwx. # If so, it's dangerous and highly likely that these are still # the permissions set by setup.exe if getfacl "${file}" | grep -Eq 'default:(group:|other):rwx' then cnt=$(expr $cnt + 1) setfacl -m d:g::r-x,d:o:r-x "${file}" 2>/dev/null \ && success=$(expr $success + 1) fi done # If no file needed treatment, or if all setfacl calls succeeded, # create the [ $cnt -eq $success ] && touch "${GUARDFILE}" fi Thanks, Corinna -- Corinna Vinschen Please, send mails regarding Cygwin to Cygwin Project Co-Leader cygwin AT cygwin DOT com Red Hat -- Problem reports: http://cygwin.com/problems.html FAQ: http://cygwin.com/faq/ Documentation: http://cygwin.com/docs.html Unsubscribe info: http://cygwin.com/ml/#unsubscribe-simple