Skip to content

Create directories for extraction with mode 0700 - #152

Merged
TheAssassin merged 1 commit into
AppImage:mainfrom
HastD:mkdir-700
Sep 28, 2026
Merged

TheAssassin merged 1 commit into
AppImage:mainfrom
HastD:mkdir-700

Conversation

@HastD

@HastD HastD commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

If APPIMAGE_EXTRACT_AND_RUN is set, the AppImage will be extracted to a directory in /tmp, which is world-readable. If the extraction directory is created with mode 0755, this means all users on the system can read the extracted AppImage contents, which is an unnecessary information disclosure on multi-user systems. Creating the directory with mode 0700 avoids this.

If `APPIMAGE_EXTRACT_AND_RUN` is set, the AppImage will be extracted to
a directory in `/tmp`, which is world-readable. If the extraction
directory is created with mode 0755, this means all users on the system
can read the extracted AppImage contents, which is an unnecessary
information disclosure on multi-user systems. Creating the directory
with mode 0700 avoids this.
@github-actions

Copy link
Copy Markdown

Build for testing:
artifacts x86_64
artifacts aarch64
artifacts i686
artifacts armhf
Use at your own risk.

@TheAssassin TheAssassin left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@TheAssassin
TheAssassin merged commit 8f39b89 into AppImage:main Sep 28, 2026
9 checks passed
@HastD
HastD deleted the mkdir-700 branch September 28, 2026 19:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants