From b490c84f49c5544be98aceba321431f305ffcba4 Mon Sep 17 00:00:00 2001 From: Daniel Hast Date: Mon, 28 Sep 2026 10:38:47 -0400 Subject: [PATCH] Create directories for extraction with mode 0700 If `APPIMAGE_EXTRACT_AND_RUN` is set, the AppImage will be extracted to a directory in `/tmp`, which is world-readable. If the extraction directory is created with mode 0755, this means all users on the system can read the extracted AppImage contents, which is an unnecessary information disclosure on multi-user systems. Creating the directory with mode 0700 avoids this. --- src/runtime/runtime.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/runtime/runtime.c b/src/runtime/runtime.c index 2ebb3c8..a073f60 100644 --- a/src/runtime/runtime.c +++ b/src/runtime/runtime.c @@ -645,7 +645,7 @@ mkdir_p(const char* const path) { /* Temporarily truncate */ *p = '\0'; - if (mkdir(_path, 0755) != 0) { + if (mkdir(_path, 0700) != 0) { if (errno != EEXIST) return -1; } @@ -654,7 +654,7 @@ mkdir_p(const char* const path) { } } - if (mkdir(_path, 0755) != 0) { + if (mkdir(_path, 0700) != 0) { if (errno != EEXIST) return -1; }