make-initrd-ng: fix file permissions (#405190)
This commit is contained in:
@@ -1296,7 +1296,7 @@ in
|
||||
systemd-initrd-luks-unl0kr = handleTest ./systemd-initrd-luks-unl0kr.nix { };
|
||||
systemd-initrd-modprobe = handleTest ./systemd-initrd-modprobe.nix { };
|
||||
systemd-initrd-shutdown = handleTest ./systemd-shutdown.nix { systemdStage1 = true; };
|
||||
systemd-initrd-simple = handleTest ./systemd-initrd-simple.nix { };
|
||||
systemd-initrd-simple = runTest ./systemd-initrd-simple.nix;
|
||||
systemd-initrd-swraid = handleTest ./systemd-initrd-swraid.nix { };
|
||||
systemd-initrd-vconsole = handleTest ./systemd-initrd-vconsole.nix { };
|
||||
systemd-initrd-networkd = handleTest ./systemd-initrd-networkd.nix { };
|
||||
|
||||
@@ -1,17 +1,17 @@
|
||||
import ./make-test-python.nix (
|
||||
{ lib, pkgs, ... }:
|
||||
{
|
||||
name = "systemd-initrd-simple";
|
||||
{
|
||||
name = "systemd-initrd-simple";
|
||||
|
||||
nodes.machine =
|
||||
{ pkgs, ... }:
|
||||
{
|
||||
testing.initrdBackdoor = true;
|
||||
boot.initrd.systemd.enable = true;
|
||||
virtualisation.fileSystems."/".autoResize = true;
|
||||
};
|
||||
nodes.machine =
|
||||
{ pkgs, ... }:
|
||||
{
|
||||
testing.initrdBackdoor = true;
|
||||
boot.initrd.systemd.enable = true;
|
||||
virtualisation.fileSystems."/".autoResize = true;
|
||||
};
|
||||
|
||||
testScript = ''
|
||||
testScript =
|
||||
# python
|
||||
''
|
||||
import subprocess
|
||||
|
||||
with subtest("testing initrd backdoor"):
|
||||
@@ -50,6 +50,8 @@ import ./make-test-python.nix (
|
||||
newAvail = machine.succeed("df --output=avail / | sed 1d")
|
||||
|
||||
assert int(oldAvail) < int(newAvail), "File system did not grow"
|
||||
|
||||
with subtest("no warnings from systemd about write permissions"):
|
||||
machine.fail("journalctl -b 0 | grep 'is marked world-writable, which is a security risk as it is executed with privileges'")
|
||||
'';
|
||||
}
|
||||
)
|
||||
}
|
||||
|
||||
@@ -212,7 +212,7 @@ fn copy_file<
|
||||
}
|
||||
|
||||
// Remove writable permissions
|
||||
permissions.set_mode(permissions.mode() ^ 0o222);
|
||||
permissions.set_mode(permissions.mode() & 0o555);
|
||||
fs::set_permissions(&target, permissions)
|
||||
.wrap_err_with(|| format!("failed to remove writable permissions for {:?}", target))?;
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user