In theory, someone who explots a hacked bopm could then use it to
attack root owned processes.
This puts the bopm-written PID file into a disposable junk directory
and lets start-stop-daemon do all the grunt work.
Bug: https://bugs.gentoo.org/631882
Closes: https://github.com/gentoo/gentoo/pull/5924
PATCHES=(
"${FILESDIR}"/${P}-remove-njabl.patch
"${FILESDIR}"/${P}-autotools.patch
+ "${FILESDIR}"/${P}-quarantine-bad-pid-file.patch
)
pkg_setup() {
# If anybody wants libopm, please install net-libs/libopm
rm -r "${ED}"usr/$(get_libdir) "${ED}"usr/include || die
- newinitd "${FILESDIR}"/bopm.init.d-r1 ${PN}
+ newinitd "${FILESDIR}"/bopm.init.d-r2 ${PN}
newconfd "${FILESDIR}"/bopm.conf.d-r1 ${PN}
dodir /var/log/bopm
--- /dev/null
+Bopm writes its own pid file, but this is handled by the init script via
+openrc-run.
+---
+diff --git a/bopm.conf.sample b/bopm.conf.sample
+index e26dc17..fa5ce1d 100644
+--- a/bopm.conf.sample
++++ b/bopm.conf.sample
+@@ -9,7 +9,7 @@ options {
+ * Full path and filename for storing the process ID of the running
+ * BOPM.
+ */
+- pidfile = "/run/bopm/bopm.pid";
++ pidfile = "/run/bopm/junk/bopm.pid";
+
+ /*
+ * How many seconds to store the IP address of hosts which are
}
start_pre() {
- checkpath -o ${BOPM_UID} -d "$(dirname "${PIDFILE}")"
+ checkpath -o 0:0 -d /run/bopm
+ checkpath -o ${BOPM_UID} -d /run/bopm/junk
+ checkpath -o ${BOPM_UID} -f /run/bopm/junk/bopm.pid
}