HomeFreeBSD

sysutils/iocage-devel: Add hardening measures on untar

Description

sysutils/iocage-devel: Add hardening measures on untar

This adds hardening measures while untaring archives fetched
over the network (including FreeBSD tarballs and iocage plugins),
as implemented by TrueNAS.

This reduces the impact of intentionally malicious or accidentally
broken archives.

Please note that users are still advised to only fetch from
trusted sources and make use of TLS to prevent MITM attacks.

While there, add patch to store man pages in the correct location.

Obtained from: https://github.com/truenas/iocage/pull/358

(cherry picked from commit a4b2dd46482c6a039f9ca296fa738b83752b1457)

Details

Provenance
gremboAuthored on Nov 23 2024, 6:11 PM
Parents
R11:48716a2641e3: sysutils/iocage: Add hardening measures on untar
Branches
Unknown
Tags
Unknown