Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | pam_namespace: secure tmp-inst directories | Topi Miettinen | 2020-02-18 | 1 | -0/+11 |
When using polyinstantiation for /tmp and/or /var/tmp, pam_namespace creates subdirectories with fixed name tmp-inst. These paths should be secured as early as possible to avoid that somehow these directories could created and controlled by for example a malicious user or service. Ship a systemd service, which creates the directories early in boot sequence with correct permissions and ownership. Closes #111. Signed-off-by: Topi Miettinen <toiwoton@gmail.com> |