summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authoremaste <emaste@FreeBSD.org>2016-09-28 21:33:35 +0000
committeremaste <emaste@FreeBSD.org>2016-09-28 21:33:35 +0000
commitc57a25c7a19b2dc6292bce631239d7930ebfc01d (patch)
tree46b81cf1701a5e86d92c4c4f2d11297780f7000c
parent7f3b434135c0226b3f1247c2cd4d3ce472a406fc (diff)
downloadFreeBSD-src-c57a25c7a19b2dc6292bce631239d7930ebfc01d.zip
FreeBSD-src-c57a25c7a19b2dc6292bce631239d7930ebfc01d.tar.gz
MFC r306417: portsnap: only move expected snapshot contents from snap/ to files/
Previously it was possible to smuggle in addional files that would be used by later portsnap runs. Now we only move those files expected to be in the snapshot into files/ and require that there are no unexpected files. This was used by portsnap attacks 2, 3, and 4 in the "non-cryptanalytic attacks against FreeBSD update components" anonymous gist. Approved by: re (gjb)
-rw-r--r--usr.sbin/portsnap/portsnap/portsnap.sh7
1 files changed, 7 insertions, 0 deletions
diff --git a/usr.sbin/portsnap/portsnap/portsnap.sh b/usr.sbin/portsnap/portsnap/portsnap.sh
index 3dcf618..501c530 100644
--- a/usr.sbin/portsnap/portsnap/portsnap.sh
+++ b/usr.sbin/portsnap/portsnap/portsnap.sh
@@ -691,6 +691,13 @@ fetch_snapshot() {
fetch_index_sanity || return 1
# Verify the snapshot contents
cut -f 2 -d '|' INDEX.new | fetch_snapshot_verify || return 1
+ cut -f 2 -d '|' tINDEX.new INDEX.new | sort -u > files.expected
+ find snap -mindepth 1 | sed -E 's^snap/(.*)\.gz^\1^' | sort > files.snap
+ if ! cmp -s files.expected files.snap; then
+ echo "unexpected files in snapshot."
+ return 1
+ fi
+ rm files.expected files.snap
echo "done."
# Move files into their proper locations
OpenPOWER on IntegriCloud