From: Adrian Freihofer <[email protected]>

pseudo inverted its path-matching logic some time ago: when set,
PSEUDO_INCLUDE_PATHS acts as an ownership-tracking allowlist, and
anything outside it silently falls through to real chown()/chmod()
instead of being recorded by pseudo. This script never set it, so an
inherited restrictive value could leave files touched by unfsd on
behalf of NFS clients with wrong ownership. Since this script only
ever touches NFS_EXPORT_DIR, setting PSEUDO_INCLUDE_PATHS to it is
enough.

Signed-off-by: Adrian Freihofer <[email protected]>
---
 scripts/runqemu-export-rootfs | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/scripts/runqemu-export-rootfs b/scripts/runqemu-export-rootfs
index 6a8acd0d5a..150513bc50 100755
--- a/scripts/runqemu-export-rootfs
+++ b/scripts/runqemu-export-rootfs
@@ -56,6 +56,8 @@ MOUNTPID=~/.runqemu-sdk/mount$NFS_INSTANCE.pid
 PSEUDO_OPTS="-P $OECORE_NATIVE_SYSROOT/usr"
 PSEUDO_LOCALSTATEDIR="$NFS_EXPORT_DIR/../$(basename 
$NFS_EXPORT_DIR).pseudo_state"
 export PSEUDO_LOCALSTATEDIR
+PSEUDO_INCLUDE_PATHS="$NFS_EXPORT_DIR"
+export PSEUDO_INCLUDE_PATHS
 
 if [ ! -d "$PSEUDO_LOCALSTATEDIR" ]; then
        echo "Error: $PSEUDO_LOCALSTATEDIR does not exist."
-- 
2.55.0

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#245232): 
https://lists.openembedded.org/g/openembedded-core/message/245232
Mute This Topic: https://lists.openembedded.org/mt/121125160/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to