docs: state the unlink mechanism precisely (write bit, not sticky bit)
Both the gateway doc and the tmpfiles comment said "a directory without the sticky bit lets any user unlink files in it". True of the old 0777, but it names the wrong lever: write permission on a directory is what confers the right to unlink its entries, and the sticky bit is only a restraint on that -- it was never set here, so it is not what 0751 changes. Dropping o=w removes the permission outright. The fix is unchanged; this is so a future reader doesn't go looking for a sticky bit that was never there. Caught in review by argus.
This commit is contained in:
parent
3fc1588e83
commit
c5cd8f2ac4
2 changed files with 15 additions and 8 deletions
|
|
@ -2430,11 +2430,15 @@ async fn sync_agent_tmpfiles(agents: &[AgentTmpfilesEntry]) -> Result<(String, S
|
|||
// (dials web.sock, and has all of /run/hive-agent bind-mounted in).
|
||||
// Both sockets are 0666, so traversal is all they need.
|
||||
//
|
||||
// 0751 rather than the historical 0777 is a fix, not a tidy-up: a
|
||||
// directory without the sticky bit lets *any* user unlink files in it,
|
||||
// so world-writable here means anything that can reach the path could
|
||||
// delete an agent's socket, bind its own, and receive that agent's
|
||||
// todos. Declaring the owner here also ends the tug-of-war with the
|
||||
// 0751 rather than the historical 0777 is a fix, not a tidy-up:
|
||||
// write permission on a *directory* is what confers the right to
|
||||
// unlink its entries, whoever owns them — the sticky bit is the only
|
||||
// thing that would restrain that, and it was never set here. So the
|
||||
// old world-writable mode let anything able to reach the path delete
|
||||
// an agent's socket, bind its own, and receive that agent's todos.
|
||||
// Dropping `o=w` removes that permission outright rather than
|
||||
// qualifying it. Declaring the owner here also ends the tug-of-war
|
||||
// with the
|
||||
// old ChownSocketDir: `d` re-applies on every sync, so a chown made
|
||||
// afterwards was reset by the next agent's spawn.
|
||||
if let (Some(uid), Some(gid)) = (entry.uid, entry.gid) {
|
||||
|
|
|
|||
Loading…
Reference in a new issue