mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
fix: harden system dirs at install; keep sudo attribution without passwd
Address remaining review comments: - shim: force root:root 0755 on the managed system dirs (shim tree and profile.d) after MkdirAll. A pre-created dir with weaker ownership, possible under Debian's group-writable /usr/local/lib, would let a non-root user replace the shims every account executes. - audit: when SUDO_USER has no passwd entry (minimal containers), attribute cloud events from sudo's recorded SUDO_USER/SUDO_UID env instead of falling back to root. Still gated on euid 0. - setup: reword the root-without---system warning; alias/shim install follows HOME, so claiming it configures only root's home was wrong. - shim: skip the non-root-owner validation test on Windows, where file ownership is not resolvable.
This commit is contained in:
+1
-1
@@ -60,7 +60,7 @@ func install(system bool) error {
|
||||
|
||||
if setupGeteuid() == 0 {
|
||||
fmt.Printf("%s %s\n", ui.Colors.Yellow("⚠"),
|
||||
"Running as root without --system configures only root's home. Use `pmg setup install --system` so all users are covered.")
|
||||
"Running as root without --system does not protect other users. Use `pmg setup install --system` so all users are covered.")
|
||||
}
|
||||
|
||||
if err := config.WriteTemplateConfig(); err != nil {
|
||||
|
||||
Reference in New Issue
Block a user