builddeb: Don't create files in /tmp with predictable names

svn path=/dists/trunk/linux-2.6/; revision=18695
This commit is contained in:
Ben Hutchings 2012-02-15 15:36:57 +00:00
parent e44fa8a4b3
commit 951b4546d2
3 changed files with 43 additions and 0 deletions

1
debian/changelog vendored
View File

@ -29,6 +29,7 @@ linux-2.6 (3.2.6-1) UNRELEASED; urgency=low
* Change linux-image dependencies to allow kmod as an alternative to
module-init-tools
* relay: prevent integer overflow in relay_open()
* builddeb: Don't create files in /tmp with predictable names
-- Bastian Blank <waldi@debian.org> Mon, 06 Feb 2012 11:22:07 +0100

View File

@ -0,0 +1,41 @@
From b27be705aaeb527613e1b7ee2964c52453ebc337 Mon Sep 17 00:00:00 2001
From: Ben Hutchings <ben@decadent.org.uk>
Date: Tue, 14 Feb 2012 02:19:04 +0000
Subject: [PATCH] builddeb: Don't create files in /tmp with predictable names
The current use of /tmp is insecure.
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
Cc: stable@vger.kernel.org
---
scripts/package/builddeb | 12 ++++++------
1 files changed, 6 insertions(+), 6 deletions(-)
diff --git a/scripts/package/builddeb b/scripts/package/builddeb
index f6cbc3d..3c6c0b1 100644
--- a/scripts/package/builddeb
+++ b/scripts/package/builddeb
@@ -238,14 +238,14 @@ EOF
fi
# Build header package
-(cd $srctree; find . -name Makefile -o -name Kconfig\* -o -name \*.pl > /tmp/files$$)
-(cd $srctree; find arch/$SRCARCH/include include scripts -type f >> /tmp/files$$)
-(cd $objtree; find .config Module.symvers include scripts -type f >> /tmp/objfiles$$)
+(cd $srctree; find . -name Makefile -o -name Kconfig\* -o -name \*.pl > "$objtree/debian/hdrsrcfiles")
+(cd $srctree; find arch/$SRCARCH/include include scripts -type f >> "$objtree/debian/hdrsrcfiles")
+(cd $objtree; find .config Module.symvers include scripts -type f >> "$objtree/debian/hdrobjfiles")
destdir=$kernel_headers_dir/usr/src/linux-headers-$version
mkdir -p "$destdir"
-(cd $srctree; tar -c -f - -T /tmp/files$$) | (cd $destdir; tar -xf -)
-(cd $objtree; tar -c -f - -T /tmp/objfiles$$) | (cd $destdir; tar -xf -)
-rm -f /tmp/files$$ /tmp/objfiles$$
+(cd $srctree; tar -c -f - -T "$objtree/debian/hdrsrcfiles") | (cd $destdir; tar -xf -)
+(cd $objtree; tar -c -f - -T "$objtree/debian/hdrobjfiles") | (cd $destdir; tar -xf -)
+rm -f "$objtree/debian/hdrsrcfiles" "$objtree/debian/hdrobjfiles"
arch=$(dpkg --print-architecture)
cat <<EOF >> debian/control
--
1.7.9

View File

@ -78,3 +78,4 @@
+ bugfix/arm/ARM-ixp4xx-mtd-oops.patch
+ bugfix/all/relay-prevent-integer-overflow-in-relay_open.patch
+ bugfix/all/builddeb-Don-t-create-files-in-tmp-with-predictable-.patch