]> git.dujemihanovic.xyz Git - u-boot.git/commit
sandbox: use sane access rights for files
authorHeinrich Schuchardt <heinrich.schuchardt@canonical.com>
Wed, 10 Apr 2024 08:38:28 +0000 (10:38 +0200)
committerSimon Glass <sjg@chromium.org>
Wed, 3 Jul 2024 06:36:32 +0000 (07:36 +0100)
commitd1fffbe3c808a9012a05b048560e17ce43f8ef9e
tree4aed92f329fbdedb7f30c7e07ad335d825a9cbf6
parent65fbdab27224ee3943a89496b21862db83c34da2
sandbox: use sane access rights for files

When writing an executable, allowing other users to modify it introduces
a security issue.

Generally we should avoid giving other users write access to our files by
default.

Replace chmod(777) by chmod(755) and chmod(644).

Fixes: 47f5fcfb4169 ("sandbox: Add os_jump_to_image() to run another executable")
Fixes: d9165153caea ("sandbox: add flags for open() call")
Fixes: 5c2859cdc302 ("sandbox: Allow reading/writing of RAM buffer")
Signed-off-by: Heinrich Schuchardt <heinrich.schuchardt@canonical.com>
Reviewed-by: Sean Anderson <seanga2@gmail.com>
arch/sandbox/cpu/os.c