Commit message (Collapse) | Author | Age | |
---|---|---|---|
* | pam_namespace: secure tmp-inst directories | Topi Miettinen | 2020-02-18 |
When using polyinstantiation for /tmp and/or /var/tmp, pam_namespace creates subdirectories with fixed name tmp-inst. These paths should be secured as early as possible to avoid that somehow these directories could created and controlled by for example a malicious user or service. Ship a systemd service, which creates the directories early in boot sequence with correct permissions and ownership. Closes #111. Signed-off-by: Topi Miettinen <toiwoton@gmail.com> |