From d10bd4fb5336c3a7aa24059e2554c3737c3522b9 Mon Sep 17 00:00:00 2001 From: wangkang101 <873229877@qq.com> Date: Wed, 2 Sep 2020 12:38:59 +0800 Subject: [PATCH] update vendor package, make log file permissions more restrictive Signed-off-by: wangkang101 <873229877@qq.com> --- Makefile | 2 +- go.mod | 2 +- go.sum | 2 ++ license/Third_Party_Open_Source_Software_Notice.md | 2 +- vendor/gopkg.in/natefinch/lumberjack.v2/lumberjack.go | 6 +++--- vendor/modules.txt | 2 +- 6 files changed, 9 insertions(+), 7 deletions(-) diff --git a/Makefile b/Makefile index c255abd..d394fed 100644 --- a/Makefile +++ b/Makefile @@ -30,7 +30,7 @@ bin: bep .PHONY: install install: - install -m 0750 ./bin/isula-transform /usr/bin/isula-transform + install -m 0550 ./bin/isula-transform /usr/bin/isula-transform .PHONY: binclean binclean: diff --git a/go.mod b/go.mod index 04df1f8..7c494a4 100644 --- a/go.mod +++ b/go.mod @@ -32,7 +32,7 @@ require ( google.golang.org/grpc v1.29.0 google.golang.org/protobuf v1.21.0 gopkg.in/check.v1 v1.0.0-20180628173108-788fd7840127 // indirect - gopkg.in/natefinch/lumberjack.v2 v2.0.0 + gopkg.in/natefinch/lumberjack.v2 v2.0.1-0.20190411184413-94d9e492cc53 gotest.tools v2.2.0+incompatible // indirect ) diff --git a/go.sum b/go.sum index 84d09f2..c22c194 100644 --- a/go.sum +++ b/go.sum @@ -161,6 +161,8 @@ gopkg.in/check.v1 v1.0.0-20180628173108-788fd7840127 h1:qIbj1fsPNlZgppZ+VLlY7N33 gopkg.in/check.v1 v1.0.0-20180628173108-788fd7840127/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= gopkg.in/natefinch/lumberjack.v2 v2.0.0 h1:1Lc07Kr7qY4U2YPouBjpCLxpiyxIVoxqXgkXLknAOE8= gopkg.in/natefinch/lumberjack.v2 v2.0.0/go.mod h1:l0ndWWf7gzL7RNwBG7wST/UCcT4T24xpD6X8LsfU/+k= +gopkg.in/natefinch/lumberjack.v2 v2.0.1-0.20190411184413-94d9e492cc53 h1:3sU6EgF8Xi+t59u4g5ALV5dHlPMujDJ1EtnRtGJ7W4E= +gopkg.in/natefinch/lumberjack.v2 v2.0.1-0.20190411184413-94d9e492cc53/go.mod h1:l0ndWWf7gzL7RNwBG7wST/UCcT4T24xpD6X8LsfU/+k= gopkg.in/yaml.v2 v2.2.2 h1:ZCJp+EgiOT7lHqUV2J862kp8Qj64Jo6az82+3Td9dZw= gopkg.in/yaml.v2 v2.2.2/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI= gotest.tools v2.2.0+incompatible h1:VsBPFP1AI068pPrMxtb/S8Zkgf9xEmTLJjfM+P5UIEo= diff --git a/license/Third_Party_Open_Source_Software_Notice.md b/license/Third_Party_Open_Source_Software_Notice.md index 588f924..a676791 100644 --- a/license/Third_Party_Open_Source_Software_Notice.md +++ b/license/Third_Party_Open_Source_Software_Notice.md @@ -513,7 +513,7 @@ License: BSD-2-Clause Please see above. Software: -gopkg.in/natefinch/lumberjack.v2 v2.0.0 +gopkg.in/natefinch/lumberjack.v2 v2.0.1-0.20190411184413-94d9e492cc53 Copyright notice: Copyright (c) 2014 Nate Finch License: MIT diff --git a/vendor/gopkg.in/natefinch/lumberjack.v2/lumberjack.go b/vendor/gopkg.in/natefinch/lumberjack.v2/lumberjack.go index 46d97c5..a47b7f0 100644 --- a/vendor/gopkg.in/natefinch/lumberjack.v2/lumberjack.go +++ b/vendor/gopkg.in/natefinch/lumberjack.v2/lumberjack.go @@ -206,13 +206,13 @@ func (l *Logger) rotate() error { // openNew opens a new log file for writing, moving any old log file out of the // way. This methods assumes the file has already been closed. func (l *Logger) openNew() error { - err := os.MkdirAll(l.dir(), 0744) + err := os.MkdirAll(l.dir(), 0755) if err != nil { return fmt.Errorf("can't make directories for new logfile: %s", err) } name := l.filename() - mode := os.FileMode(0644) + mode := os.FileMode(0600) info, err := os_Stat(name) if err == nil { // Copy the mode off the old logfile. @@ -288,7 +288,7 @@ func (l *Logger) openExistingOrNew(writeLen int) error { return nil } -// genFilename generates the name of the logfile from the current time. +// filename generates the name of the logfile from the current time. func (l *Logger) filename() string { if l.Filename != "" { return l.Filename diff --git a/vendor/modules.txt b/vendor/modules.txt index 8ec97c8..1d8f5e8 100644 --- a/vendor/modules.txt +++ b/vendor/modules.txt @@ -170,5 +170,5 @@ google.golang.org/protobuf/runtime/protoimpl google.golang.org/protobuf/types/known/anypb google.golang.org/protobuf/types/known/durationpb google.golang.org/protobuf/types/known/timestamppb -# gopkg.in/natefinch/lumberjack.v2 v2.0.0 +# gopkg.in/natefinch/lumberjack.v2 v2.0.1-0.20190411184413-94d9e492cc53 gopkg.in/natefinch/lumberjack.v2 -- GitLab