From nobody Sun Jul 19 12:46:25 2026 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4h33LH1Gknz6m9kL for ; Sun, 19 Jul 2026 12:46:31 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR1" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4h33LG6HJ3z3WmY for ; Sun, 19 Jul 2026 12:46:30 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1784465190; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=CI7sB+cNekmMrFwPadHvRV13tZjpLvv14AgBJOuxjfc=; b=qXteozdq/K1XEHs4ttzO4iPLtNtGR2JuwomI2hheE5o2mRR3UMX+UM1qDoVrECanId+YCj QSD0N64mt08AzmqTSTlAegRGVcPjtefFGBDms/rwRFDI6gfBPH8HGnBi8T3rZOhxW1Eura 8/GMfQ1PLQMByHsDqhblkwHYbihvV3zjdVwZI2HZU1aTgIXqFRZoW06NQQO42PPnfXXzFM hZVXQDpj5Y4qr/4BK3EccQTridW/7HH6mhBl9qNroW4FpiWZgxmf8aIRUe3ZCSpYr+1Arq wHNXWK17+7w57HcG3BPhBGQRLOhx1eqwNy0Tt3GDC766kq+hXfuE4VTMIMih8w== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1784465190; a=rsa-sha256; cv=none; b=auxWG5j4S0gk+ES3xh378cEhPlP/qkli2BpPya6go5vv6U31UA3hcI2H98UIeIP3clGiFM JyxeuLeV/sGIuBHST1z480zCBp1ecz/iXH+BtEgAvANhY3xAFHZpuH4xRSTkMVsGLuvVKP MsjsGd7eSun5Q3wouN5PF0FbRAspyO27j7LAH+aW0Q6tOKkvLToJw4BzYMnuct0uOolLlB CmP4dN5Njw/PW/VAXKUDDkcdTV8sJy94XPeU0Mi61sPTfQghEgVcWASL2TNa5wJLrjNwzQ aK8CmeoQmv5EcOYf1pCFhtysbZj+Me2ZiDU8jW/bn3BwGZE8IDWGpwlNGAsubA== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1784465190; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=CI7sB+cNekmMrFwPadHvRV13tZjpLvv14AgBJOuxjfc=; b=bEPYqNU+zGORXimEUbjAwfYZGuac195IEKYuynPiSd2C0n6tBuf6nN8fcX8fEmpCI3pGSI fRoiON9/CsRiiNtL3O+yDERsLuPdXwYHcpfBIEqNQlpQiDB6pyjQXFNBEqcaufiBqOI+cF JKM7WN3pAE0iBuRXOoETbaq7UGxpSynUuVpplIe0C8XG/BKl59Og7hGGaJLLWj9W01g0m4 +5MLfytPu6o8PzWlqPBXKIjQDJW1GWYfCbpXoHp1CogG6WtoljeIBSRz0didNEcB163Jlt O64pZEvJnzAvfelQ2OIALEmVS45/UGGVDljO3DaDuHMDhL/zAaTWBIRAIEl/OA== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4h33LG4DsKzwr for ; Sun, 19 Jul 2026 12:46:30 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 37bee by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Sun, 19 Jul 2026 12:46:25 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Lexi Winter Subject: git: 02f174179a53 - main - certctl: Enforce 0444 mode on new files List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: ivy X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 02f174179a538f89185d275b4e64277baf3acc50 Auto-Submitted: auto-generated Date: Sun, 19 Jul 2026 12:46:25 +0000 Message-Id: <6a5cc721.37bee.3c8025e0@gitrepo.freebsd.org> The branch main has been updated by ivy: URL: https://cgit.FreeBSD.org/src/commit/?id=02f174179a538f89185d275b4e64277baf3acc50 commit 02f174179a538f89185d275b4e64277baf3acc50 Author: Lexi Winter AuthorDate: 2026-07-19 12:45:43 +0000 Commit: Lexi Winter CommitDate: 2026-07-19 12:45:43 +0000 certctl: Enforce 0444 mode on new files When writing to a file, call fchmod() to ensure the file mode matches the intended mode, which is 0444. This was already done when replacing an existing file, but not when creating a new file, which meant if the process umask was 077, the resulting certificates and bundle would be unreadable by unprivileged users. MFC after: 1 week Reviewed by: des Differential Revision: https://reviews.freebsd.org/D58304 --- usr.sbin/certctl/certctl.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/usr.sbin/certctl/certctl.c b/usr.sbin/certctl/certctl.c index 462f6c1730a9..5c2b83b89d57 100644 --- a/usr.sbin/certctl/certctl.c +++ b/usr.sbin/certctl/certctl.c @@ -523,6 +523,8 @@ write_certs(const char *dir, struct cert_tree *tree) tmppath = xasprintf(".%s", path); fd = openat(d, tmppath, O_CREAT | O_WRONLY | O_EXCL, mode); + if (!unprivileged && fd >= 0) + (void)fchmod(fd, mode); } } /* write the certificate */ @@ -594,6 +596,8 @@ write_bundle(const char *dir, const char *file, struct cert_tree *tree) } else { tmpfile = xasprintf(".%s", file); fd = openat(d, tmpfile, O_WRONLY | O_CREAT | O_EXCL, mode); + if (!unprivileged && fd >= 0) + (void)fchmod(fd, mode); } if (fd < 0 || (f = fdopen(fd, "w")) == NULL) { if (tmpfile != NULL && fd >= 0) {