Verified Commit 5a97ba07 authored by ma1's avatar ma1
Browse files

Bug 41050: Improve disk leak sanitization on startup.

parent 982dcc78
Loading
Loading
Loading
Loading
+19 −5
Changes for projects/browser/RelativeLink/start-browser: 19 added lines, 5 removed lines.
Original line number Diff line number Diff line
@@ -258,18 +258,32 @@ HOME="${PWD}"
export HOME

# Prevent disk leaks in $HOME/.local/share (tor-browser#17560)
function erase_leaky() {
	local leaky="$1"
	[ -e "$leaky" ] &&
	( srm -r "$leaky" ||
	  wipe -r "$leaky" ||
	  find "$leaky" -type f -exec shred -u {} \; ;
	  rm -rf "$leaky"
	) > /dev/null 2>&1
}
local_dir="$HOME/.local/"
share_dir="$local_dir/share"
# We don't want to mess with symlinks, possibly pointing outside the
# Browser directory (tor-browser-build#41050).
# We're not using realpath/readlink for consistency with the (possibly
# outdated) availability assumptions made elsewhere in this script.
if ! [ -L "$local_dir" -o -L "$share_dir" ]; then
	if [ -d "$share_dir" ]; then
    ( srm -r "$share_dir" ||
      wipe -r "$share_dir" ||
      find "$share_dir" -type f -exec shred -u {} \; ;
      rm -rf "$share_dir"
    ) > /dev/null 2>&1
		for leaky_path in "gvfs-metadata" "recently-used.xbel"; do
			erase_leaky "$share_dir/$leaky_path"
		done
	else
		mkdir -p "$local_dir"
	fi
	ln -fs /dev/null "$share_dir"
fi
[ -L "$HOME/.cache" ] || erase_leaky "$HOME/.cache/nvidia"

[% IF c("var/tor-browser") -%]
SYSARCHITECTURE=$(getconf LONG_BIT)