[kernel] r18695 - in dists/trunk/linux-2.6/debian: . patches/bugfix/all patches/series

Ben Hutchings benh at alioth.debian.org
Wed Feb 15 15:36:59 UTC 2012


Author: benh
Date: Wed Feb 15 15:36:57 2012
New Revision: 18695

Log:
builddeb: Don't create files in /tmp with predictable names

Added:
   dists/trunk/linux-2.6/debian/patches/bugfix/all/builddeb-Don-t-create-files-in-tmp-with-predictable-.patch
Modified:
   dists/trunk/linux-2.6/debian/changelog
   dists/trunk/linux-2.6/debian/patches/series/base

Modified: dists/trunk/linux-2.6/debian/changelog
==============================================================================
--- dists/trunk/linux-2.6/debian/changelog	Wed Feb 15 15:08:07 2012	(r18694)
+++ dists/trunk/linux-2.6/debian/changelog	Wed Feb 15 15:36:57 2012	(r18695)
@@ -29,6 +29,7 @@
   * Change linux-image dependencies to allow kmod as an alternative to
     module-init-tools
   * relay: prevent integer overflow in relay_open()
+  * builddeb: Don't create files in /tmp with predictable names
 
  -- Bastian Blank <waldi at debian.org>  Mon, 06 Feb 2012 11:22:07 +0100
 

Added: dists/trunk/linux-2.6/debian/patches/bugfix/all/builddeb-Don-t-create-files-in-tmp-with-predictable-.patch
==============================================================================
--- /dev/null	00:00:00 1970	(empty, because file is newly added)
+++ dists/trunk/linux-2.6/debian/patches/bugfix/all/builddeb-Don-t-create-files-in-tmp-with-predictable-.patch	Wed Feb 15 15:36:57 2012	(r18695)
@@ -0,0 +1,41 @@
+From b27be705aaeb527613e1b7ee2964c52453ebc337 Mon Sep 17 00:00:00 2001
+From: Ben Hutchings <ben at decadent.org.uk>
+Date: Tue, 14 Feb 2012 02:19:04 +0000
+Subject: [PATCH] builddeb: Don't create files in /tmp with predictable names
+
+The current use of /tmp is insecure.
+
+Signed-off-by: Ben Hutchings <ben at decadent.org.uk>
+Cc: stable at vger.kernel.org
+---
+ scripts/package/builddeb |   12 ++++++------
+ 1 files changed, 6 insertions(+), 6 deletions(-)
+
+diff --git a/scripts/package/builddeb b/scripts/package/builddeb
+index f6cbc3d..3c6c0b1 100644
+--- a/scripts/package/builddeb
++++ b/scripts/package/builddeb
+@@ -238,14 +238,14 @@ EOF
+ fi
+ 
+ # Build header package
+-(cd $srctree; find . -name Makefile -o -name Kconfig\* -o -name \*.pl > /tmp/files$$)
+-(cd $srctree; find arch/$SRCARCH/include include scripts -type f >> /tmp/files$$)
+-(cd $objtree; find .config Module.symvers include scripts -type f >> /tmp/objfiles$$)
++(cd $srctree; find . -name Makefile -o -name Kconfig\* -o -name \*.pl > "$objtree/debian/hdrsrcfiles")
++(cd $srctree; find arch/$SRCARCH/include include scripts -type f >> "$objtree/debian/hdrsrcfiles")
++(cd $objtree; find .config Module.symvers include scripts -type f >> "$objtree/debian/hdrobjfiles")
+ destdir=$kernel_headers_dir/usr/src/linux-headers-$version
+ mkdir -p "$destdir"
+-(cd $srctree; tar -c -f - -T /tmp/files$$) | (cd $destdir; tar -xf -)
+-(cd $objtree; tar -c -f - -T /tmp/objfiles$$) | (cd $destdir; tar -xf -)
+-rm -f /tmp/files$$ /tmp/objfiles$$
++(cd $srctree; tar -c -f - -T "$objtree/debian/hdrsrcfiles") | (cd $destdir; tar -xf -)
++(cd $objtree; tar -c -f - -T "$objtree/debian/hdrobjfiles") | (cd $destdir; tar -xf -)
++rm -f "$objtree/debian/hdrsrcfiles" "$objtree/debian/hdrobjfiles"
+ arch=$(dpkg --print-architecture)
+ 
+ cat <<EOF >> debian/control
+-- 
+1.7.9
+

Modified: dists/trunk/linux-2.6/debian/patches/series/base
==============================================================================
--- dists/trunk/linux-2.6/debian/patches/series/base	Wed Feb 15 15:08:07 2012	(r18694)
+++ dists/trunk/linux-2.6/debian/patches/series/base	Wed Feb 15 15:36:57 2012	(r18695)
@@ -78,3 +78,4 @@
 + bugfix/arm/ARM-ixp4xx-mtd-oops.patch
 
 + bugfix/all/relay-prevent-integer-overflow-in-relay_open.patch
++ bugfix/all/builddeb-Don-t-create-files-in-tmp-with-predictable-.patch



More information about the Kernel-svn-changes mailing list