fix: restrict EFI partition permissions with fmask/dmask=0077 (#4506)
* fix: restrict EFI partition permissions with fmask/dmask=0077 Mount the ESP with fmask=0077 and dmask=0077 to prevent world-readable files like /efi/loader/random-seed. Closes #4241 * fix(efi): collapse fmask/dmask dedup to dict.fromkeys one-liner Per @Torxed's review feedback. Same semantics as the previous loop (dedupe by exact-string match) but shorter. dict.fromkeys preserves insertion order, where set() would not. * fix(efi): drop defensive list wrap per review The list() copy on line 378 was load-bearing only if options were mutated downstream, but the EFI branch reassigns options via dict.fromkeys() (line 381) and the non-EFI branch passes through to mount() without mutating. Drop the copy.
This commit is contained in:
parent
dccd0c8ccf
commit
5fd2f9b627
|
|
@ -375,7 +375,12 @@ class Installer:
|
|||
# it would be none if it's btrfs as the subvolumes will have the mountpoints defined
|
||||
if part_mod.mountpoint:
|
||||
target = self.target / part_mod.relative_mountpoint
|
||||
mount(part_mod.dev_path, target, options=part_mod.mount_options)
|
||||
options = part_mod.mount_options
|
||||
|
||||
if part_mod.is_efi():
|
||||
options = list(dict.fromkeys(options + ['fmask=0077', 'dmask=0077']))
|
||||
|
||||
mount(part_mod.dev_path, target, options=options)
|
||||
elif part_mod.fs_type == FilesystemType.BTRFS:
|
||||
# Only mount BTRFS subvolumes that have mountpoints specified
|
||||
subvols_with_mountpoints = [sv for sv in part_mod.btrfs_subvols if sv.mountpoint is not None]
|
||||
|
|
|
|||
Loading…
Reference in New Issue