Description
When using @@include <dir> <regex> to load drop-in config files, neither the directory nor the individual files are checked for safe ownership or permissions. By contrast, @@x_include already enforces these checks (owned by current user or root, not group/world-writable).
What is checked for @@include dir regex
- File exists and is a regular file
- Filename matches the provided regex
- Nesting depth ≤ 16
What is NOT checked
- Directory ownership or write permissions
- File ownership or write permissions
- Symlinks — they are silently followed; it is unclear whether this is intentional
Expected behavior
@@include with a directory argument should apply the same ownership and permission checks that @@x_include already applies, to both the directory itself and each included file. The symlink behavior should be explicitly decided: if symlinks are not a supported use case, they should be rejected; if they are, the ownership and permission checks must also be applied to the symlink target.
Description
When using
@@include <dir> <regex>to load drop-in config files, neither the directory nor the individual files are checked for safe ownership or permissions. By contrast,@@x_includealready enforces these checks (owned by current user or root, not group/world-writable).What is checked for
@@include dir regexWhat is NOT checked
Expected behavior
@@includewith a directory argument should apply the same ownership and permission checks that@@x_includealready applies, to both the directory itself and each included file. The symlink behavior should be explicitly decided: if symlinks are not a supported use case, they should be rejected; if they are, the ownership and permission checks must also be applied to the symlink target.