Re: World writable tarballs



On 4/29/06, Alistair John Strachan <s0348365@xxxxxxxxxxxx> wrote:
On Sunday 30 April 2006 01:18, Mark Rosenstand wrote:
> Hi,
>
> It seems that at least the content of the 2.6.16 tarball is world
> writable if extracted with GNU tar as an privileged user.
>
> Is this on purpose in order to prove some point?

Read this thread:

http://marc.theaimsgroup.com/?l=linux-kernel&m=113304241100330&w=2

This REALLY needs fixing. If it weren't so late right now I might have written
a filter that takes a tarball and sanitizes the permissions. I've got
good reasons
for compiling the kernel as root (when in the make, install, reboot, test loop
it's quite a timesaver).

Yes, I'm the guy who keeps trying to log in as root on ftp.kernel.org over ftp
with no password. For some bone-headed reason I keep thinking the default
username for ftp is anonymous, not the user's.
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/



Relevant Pages

  • Re: Seeking Wisdom Concerning Backups
    ... I have a Barracuda Terastation Pro backup server sitting right next to ... I'd go with FTP ... pipe the tarball through OpenSSL's enc before sending it via FTP. ... openssl encryption ...
    (Debian-User)
  • Re: Seeking Wisdom Concerning Backups
    ... Windows Fileshare, Apple Filesharing, and FTP). ... First decide if you want to have a local tarball on the box and then ... I'd prefer to not have to create the tarball locally first, but rather the create it on the fly as it's being transferred to the backup server. ... Then if you want to encrypt the tarball, ...
    (Debian-User)
  • Re: Tar option to NOT specify UID or GID?
    ... When a tarball is extracted by `root' on ... a production system, it would be a bit useless to get files owned by ... You can restore a backup. ...
    (comp.unix.programmer)
  • Re: Tar option to NOT specify UID or GID?
    ... When a tarball is extracted by `root' on ... Tar is just one of them. ... You can restore a backup. ...
    (comp.unix.programmer)
  • Re: Re: [KERNEL 2.6.15] All files have -rw-rw-rw- permission.
    ... >Don't untar the tarball as root and this won't happen. ... > tar tvjf linux-2.6.15.tar.bz2 ...
    (Linux-Kernel)