checkupdates: use $UID in temporary directory path if $USER is not set

Message ID 20191120143312.26400-1-nl6720@gmail.com
State Superseded, archived
Headers show
Series checkupdates: use $UID in temporary directory path if $USER is not set | expand

Commit Message

nl6720 Nov. 20, 2019, 2:33 p.m. UTC
If $USER is not set when running checkupdates, the temporary directory's
name will be "checkup-db-". This will cause issues if multiple users run
checkupdates. A common situation where $USER is not set is when a command
is executed with systemd-run, e.g. from a systemd unit.
See https://github.com/systemd/systemd/pull/8227 for details.

Fall back to $UID so that the temporary directory is isolated per-user.

Signed-off-by: nl6720 <nl6720@gmail.com>
---
 src/checkupdates.sh.in | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

Comments

Eli Schwartz Nov. 20, 2019, 3:56 p.m. UTC | #1
On 11/20/19 9:33 AM, nl6720 wrote:
> If $USER is not set when running checkupdates, the temporary directory's
> name will be "checkup-db-". This will cause issues if multiple users run
> checkupdates. A common situation where $USER is not set is when a command
> is executed with systemd-run, e.g. from a systemd unit.
> See https://github.com/systemd/systemd/pull/8227 for details.
> 
> Fall back to $UID so that the temporary directory is isolated per-user.

Interesting issue. $UID is guaranteed to exist because bash sets it,
$USER is set by the program which implements logging in to the system.

> Signed-off-by: nl6720 <nl6720@gmail.com>
> ---
>  src/checkupdates.sh.in | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/src/checkupdates.sh.in b/src/checkupdates.sh.in
> index 52f8899..f2c468c 100644
> --- a/src/checkupdates.sh.in
> +++ b/src/checkupdates.sh.in
> @@ -85,7 +85,7 @@ if ! type -P fakeroot >/dev/null; then
>  fi
>  
>  if [[ -z $CHECKUPDATES_DB ]]; then
> -	CHECKUPDATES_DB="${TMPDIR:-/tmp}/checkup-db-${USER}/"
> +	CHECKUPDATES_DB="${TMPDIR:-/tmp}/checkup-db-${USER:-$UID}/"

This means that if users use checkupdates via a non-login session and
then via a login session, we'll end up with two directories. Please
either use $UID consistently, or fallback on $(id -un).

>  fi
>  
>  trap 'rm -f $CHECKUPDATES_DB/db.lck' INT TERM EXIT
>

Patch

diff --git a/src/checkupdates.sh.in b/src/checkupdates.sh.in
index 52f8899..f2c468c 100644
--- a/src/checkupdates.sh.in
+++ b/src/checkupdates.sh.in
@@ -85,7 +85,7 @@  if ! type -P fakeroot >/dev/null; then
 fi
 
 if [[ -z $CHECKUPDATES_DB ]]; then
-	CHECKUPDATES_DB="${TMPDIR:-/tmp}/checkup-db-${USER}/"
+	CHECKUPDATES_DB="${TMPDIR:-/tmp}/checkup-db-${USER:-$UID}/"
 fi
 
 trap 'rm -f $CHECKUPDATES_DB/db.lck' INT TERM EXIT