From 0cd0e2ee1908a1432b06e637168f7fc8531643ec Mon Sep 17 00:00:00 2001 From: =?utf8?q?Zbigniew=20J=C4=99drzejewski-Szmek?= Date: Sat, 17 Jun 2017 12:41:08 -0400 Subject: [PATCH] basic/rm-rf: allow a symlink to / to be removed We open the target path with O_DIRECTORY|O_NOFOLLOW, and if that doesn't work, we call unlink() on the path. In neither case we will follow the symlink, so we can relax our check to also not follow symlinks. Fixes #5864. --- src/basic/rm-rf.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/basic/rm-rf.c b/src/basic/rm-rf.c index 225a21296..156366c7d 100644 --- a/src/basic/rm-rf.c +++ b/src/basic/rm-rf.c @@ -184,7 +184,7 @@ int rm_rf(const char *path, RemoveFlags flags) { /* We refuse to clean the root file system with this * call. This is extra paranoia to never cause a really * seriously broken system. */ - if (path_equal_or_files_same(path, "/", 0)) { + if (path_equal_or_files_same(path, "/", AT_SYMLINK_NOFOLLOW)) { log_error("Attempted to remove entire root file system, and we can't allow that."); return -EPERM; } -- 2.30.2