HomeFreeBSD

portsnap: only move expected snapshot contents from snap/ to files/

Description

portsnap: only move expected snapshot contents from snap/ to files/

Previously it was possible to smuggle in addional files that would
be used by later portsnap runs. Now we only move those files expected
to be in the snapshot into files/ and require that there are no
unexpected files.

This was used by portsnap attacks 2, 3, and 4 in the "non-cryptanalytic
attacks against FreeBSD update components" anonymous gist.

Reported by: anonymous gist
Reviewed by: allanjude, delphij
MFC after: ASAP
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D8052

Details

Provenance
emasteAuthored on
Reviewer
allanjude
Differential Revision
D8052: portsnap: only move expected snapshot contents from snap/ to files/
Parents
rS306416: MFC r306075,r306109
Branches
Unknown
Tags
Unknown