diff --git a/0001-crontab-Fix-backup-failure-when-cache-directory-mis.patch b/0001-crontab-Fix-backup-failure-when-cache-directory-mis.patch index 793b9d3..b547110 100644 --- a/0001-crontab-Fix-backup-failure-when-cache-directory-mis.patch +++ b/0001-crontab-Fix-backup-failure-when-cache-directory-mis.patch @@ -28,7 +28,7 @@ index c11dc81..f6fae67 100644 + if (parent_len < sizeof(parent_dir)) { + strncpy(parent_dir, backup_dir, parent_len); + parent_dir[parent_len] = '\0'; -+ mkdir(parent_dir, 0755); ++ mkdir(parent_dir, 0700); + } + } + diff --git a/0001-ensure-crontab-backup-file-has-strict-permssions.patch b/0001-ensure-crontab-backup-file-has-strict-permssions.patch new file mode 100644 index 0000000..0126706 --- /dev/null +++ b/0001-ensure-crontab-backup-file-has-strict-permssions.patch @@ -0,0 +1,40 @@ +From d126d394122b38a08456a54c2906ec3395145fd1 Mon Sep 17 00:00:00 2001 +From: Johannes Segitz +Date: Thu, 18 Jan 2024 10:51:15 +0100 +Subject: [PATCH] ensure crontab backup file has strict permssions + +--- + src/crontab.c | 6 ++++++ + 1 file changed, 6 insertions(+) + +diff --git a/src/crontab.c b/src/crontab.c +index 5318e71..5a86740 100644 +--- a/src/crontab.c ++++ b/src/crontab.c +@@ -504,6 +504,7 @@ static int backup_crontab(const char *crontab_path) { + FILE *backup_file; + struct stat sb; + int retval = 0; ++ mode_t old_umask; + + /* create backup directory */ + if ((env_value = getenv("XDG_CACHE_HOME")) != NULL) { +@@ -588,6 +589,9 @@ static int backup_crontab(const char *crontab_path) { + } + } + ++ /* ensure backup file has strict permssions. Crontabs are not readable for ++ other users and might contain sensitive information */ ++ old_umask = umask(0077); + if ((backup_file = fopen(backup_path, "w+")) == NULL) { + fprintf(stderr, "Failed to write to the backup file: "); + perror(backup_path); +@@ -596,6 +600,8 @@ static int backup_crontab(const char *crontab_path) { + } + + swapback: ++ umask(old_umask); ++ + if (swap_uids_back() < OK) { + perror("swapping uids back"); + if (backup_file != NULL) { diff --git a/cronie.spec b/cronie.spec index 8c711a3..f683345 100644 --- a/cronie.spec +++ b/cronie.spec @@ -33,6 +33,9 @@ Patch: 0001-crontab-Fix-backup-failure-when-cache-directory-mis.patch # https://github.com/cronie-crond/cronie/pull/210 Patch: forward-XDG_SESSION_CLASS-to-PAM-for-session-classification.patch +# https://github.com/cronie-crond/cronie/pull/172 +Patch: 0001-ensure-crontab-backup-file-has-strict-permssions.patch + # https://github.com/cronie-crond/cronie/issues/166 # two of these patches touched configure.ac, so we need 'automake'as a BuildRequires # it is safe to remove it once these patches are part of the upstream release