Distribution package has broken filesystem permissions
envgap__internetarchive__heritrix3-413
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
ea426306083e557272ee542d03366448c4b616a2- Manifest
contrib/pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
internetarchive/heritrix3 #413 · read the original issue
The filesystem permissions on some of the files in the distribution packages are the rather dangerous value 7777 (`rwsrwsrwt`). Not only is this annoying but it's also a local security vulnerability as it allows other users on the system to overwrite the contents of the jar files. ``` $ zipinfo heritrix-3.4.0-20210617-dist.zip | grep heritrix[^/]*.jar -rwsrwsrwt 2.0 unx 678617 b- defN 21-Jun-17 14:39 heritrix-3.4.0-20210617/lib/heritrix-engine-3.4.0-20210617.jar -rwsrwsrwt 2.0 unx 450517 b- defN 21-Jun-17 14:39 heritrix-3.4.0-20210617/lib/heritrix-modules-3.4.0-20210617.jar -rwsrwsrwt 2.0 unx 150258 b- defN 21-Jun-17 14:39 heritrix-3.4.0-20210617/lib/heritrix-commons-3.4.0-20210617.jar $ tar -ztvf heritrix-3.4.0-20210617-dist.tar.gz | grep heritrix[^/]*.jar -rwsrwsrwt 0/0 678617 2021-06-17 22:39 heritrix-3.4.0-20210617/lib/heritrix-engine-3.4.0-20210617.jar -rwsrwsrwt 0/0 450517 2021-06-17 22:39 heritrix-3.4.0-20210617/lib/heritrix-modules-3.4.0-20210617.jar -rwsrwsrwt 0/0 150258 2021-06-17 22:39 heritrix-3.4.0-20210617/lib/heritrix-commons-3.4.0-20210617.jar ``` This seems to be a bug in the old version of the maven-assembly-plugin we're using as the documentation states the default permission when `fileMode` is not specified in the assembly xml is supposed to be 0644.
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]