ruby-changes:58684
From: Nobuyoshi <ko1@a...>
Date: Sat, 9 Nov 2019 22:45:22 +0900 (JST)
Subject: [ruby-changes:58684] a68205c5c1 (master): Specify the permission
https://git.ruby-lang.org/ruby.git/commit/?id=a68205c5c1 From a68205c5c19277e9ece8409b1f6af7e226989dff Mon Sep 17 00:00:00 2001 From: Nobuyoshi Nakada <nobu@r...> Date: Sat, 9 Nov 2019 22:40:14 +0900 Subject: Specify the permission To make the temporary directory non-writable by group and others. diff --git a/spec/ruby/security/cve_2018_6914_spec.rb b/spec/ruby/security/cve_2018_6914_spec.rb index 997f4c5..f1bd2c6 100644 --- a/spec/ruby/security/cve_2018_6914_spec.rb +++ b/spec/ruby/security/cve_2018_6914_spec.rb @@ -7,7 +7,7 @@ describe "CVE-2018-6914 is resisted by" do https://github.com/ruby/ruby/blob/trunk/spec/ruby/security/cve_2018_6914_spec.rb#L7 before :each do @tmpdir = ENV['TMPDIR'] @dir = tmp("CVE-2018-6914") - Dir.mkdir(@dir) + Dir.mkdir(@dir, 0700) ENV['TMPDIR'] = @dir # Make sure that ENV["TMPDIR"] is used by Dir.tmpdir -- cgit v0.10.2 -- ML: ruby-changes@q... Info: http://www.atdot.net/~ko1/quickml/