From: Daniel Kahn Gillmor Date: Fri, 24 Jul 2009 17:25:40 +0000 (-0400) Subject: shoring up known_hosts creation with proper umask and with multi-level directory... X-Git-Tag: monkeysphere_0.26~23^2 X-Git-Url: https://codewiz.org/gitweb?p=monkeysphere.git;a=commitdiff_plain;h=ee5e8c8c627a9175a142f2a6381bbd50b7810d49 shoring up known_hosts creation with proper umask and with multi-level directory creation. --- diff --git a/src/share/common b/src/share/common index 37e31a1..27e088a 100644 --- a/src/share/common +++ b/src/share/common @@ -887,6 +887,7 @@ update_known_hosts() { local nHostsBAD local fileCheck local host + local newUmask # the number of hosts specified on command line nHosts="$#" @@ -897,8 +898,11 @@ update_known_hosts() { # touch the known_hosts file so that the file permission check # below won't fail upon not finding the file if [ ! -f "$KNOWN_HOSTS" ]; then - [ -d $(dirname "$KNOWN_HOSTS") ] || mkdir -m 0700 $(dirname "$KNOWN_HOSTS") || failure "Could not create path to known_hosts file '$KNOWN_HOSTS'" - touch "$KNOWN_HOSTS" || failure "Unable to create known_hosts file '$KNOWN_HOSTS'" + # make sure to create any files or directories with the appropriate write bits turned off: + newUmask=$(printf "%04o" $(( 0$(umask) | 0022 )) + [ -d $(dirname "$KNOWN_HOSTS") ] || (umask "$newUmask" && mkdir -p -m 0700 $(dirname "$KNOWN_HOSTS") ) || failure "Could not create path to known_hosts file '$KNOWN_HOSTS'" + # make sure to create this file with the appropriate bits turned off: + (umask "$newUmask" && touch "$KNOWN_HOSTS") || failure "Unable to create known_hosts file '$KNOWN_HOSTS'" fi # check permissions on the known_hosts file path