da395c583770b466b5ba83c37d313a7b1c0024c9

Author
leycec <leycec@gmail.com>
Committer
leycec <leycec@gmail.com>
Date

Message

Secure umask enforced during installation.

For safety, a umask of 022 prohibiting both group and other writability is now
enforced during OMZ installation. In theory, this should reduce the likelihood
of subsequent compinit() failures due to insecure directory permissions under
all platforms except for default Cygwin installations (in which Windows ACLs
override POSIX umasks).

Diff

 1diff --git a/tools/install.sh b/tools/install.sh
 2index c83a6f23d0776abec9a189f90d0846d8d3036ab0..405f461e9288020b40d2fef468077b21fe319492 100755
 3--- a/tools/install.sh
 4+++ b/tools/install.sh
 5@@ -9,6 +9,13 @@ if [ -d "$ZSH" ]; then
 6   exit
 7 fi
 8 
 9+# Prevent the cloned repository from having insecure permissions. Failing to do
10+# so causes compinit() calls to fail with "command not found: compdef" errors
11+# for users with insecure umasks (e.g., "002", allowing group writability). Note
12+# that this will be ignored under Cygwin by default, as Windows ACLs take
13+# precedence over umasks except for filesystems mounted with option "noacl".
14+umask g-w,o-w
15+
16 echo "\033[0;34mCloning Oh My Zsh...\033[0m"
17 hash git >/dev/null 2>&1 && env git clone --depth=1 https://github.com/robbyrussell/oh-my-zsh.git $ZSH || {
18   echo "git not installed"