Project

General

Profile

Actions

Bug #7060

closed

cfengine stops processing a promise on symlinks

Added by Benoît PECCATTE over 9 years ago. Updated about 8 years ago.

Status:
Released
Priority:
N/A
Category:
Agent
Target version:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
Name check:
Fix check:
Regression:

Description

When a symbolic link isn't owned by the same user as its tagrget, cfengine stops processing file promises.
This can stop an attack on code where there is a race condition, but in practice, ther should not be race conditions and there is a lot of legitimate systems with links that don't have the same owner as their target.
We should disable this behavior


Subtasks 2 (0 open2 closed)

Bug #9026: cfengine stops processing a promise on symlinksReleasedAlexis Mousset2016-09-13Actions
Bug #9043: Malformed patch in 7060ReleasedBenoît PECCATTE2016-09-14Actions

Related issues 1 (0 open1 closed)

Related to Rudder - Bug #6953: The agent refuses to work on files with symlink in their pathRejected2015-07-10Actions
Actions

Also available in: Atom PDF