]> code.ossystems Code Review - openembedded-core.git/commit
busybox.inc: Add sanity check to test if the suid binary provides sh
authorNathan Rossi <nathan@nathanrossi.com>
Wed, 24 Jan 2018 12:59:28 +0000 (22:59 +1000)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Mon, 29 Jan 2018 08:49:42 +0000 (08:49 +0000)
commitb64807549569817c8f1921a0aad52c815af90731
treeaa2aeb3976d2d028416fde65eaf72385fdd73329
parent3d2c87c4f4115b01534ab198c27682c7e4c5f31f
busybox.inc: Add sanity check to test if the suid binary provides sh

Add a sanity check during the do_compile task to fail if the suid
busybox provides /bin/sh. This is considered as a hard fail since not
only is providing sh as suid problematic for security reasons but also
because the sh configured for suid is less functional than the nosuid
configured sh and breaks a number of required features (e.g. 64-bit
test).

Signed-off-by: Nathan Rossi <nathan@nathanrossi.com>
Signed-off-by: Ross Burton <ross.burton@intel.com>
meta/recipes-core/busybox/busybox.inc