Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Non-root owned symlink causes install failure #3283

Open
ffesti opened this issue Sep 6, 2024 · 0 comments
Open

Non-root owned symlink causes install failure #3283

ffesti opened this issue Sep 6, 2024 · 0 comments
Labels

Comments

@ffesti
Copy link
Contributor

ffesti commented Sep 6, 2024

This is a continuation of #3100. Unsafe symlinks are detected during installation and create a failure. This is the right thing to do in case we encounter such things at this phase. But we really need to check for this in advance during the transaction check and not even start the transaction if such symlinks are found. The failure during the transaction is only acceptable if someone tries to escalate their privileges exploiting a race condition.

@ffesti ffesti added the bug label Sep 6, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
Status: Todo
Development

No branches or pull requests

1 participant