mirror of
https://git.savannah.gnu.org/git/guix.git
synced 2026-04-06 21:20:33 +02:00
services: urandom-seed: Set umask to 077 while shutting down.
* gnu/services/base.scm (urandom-seed-shepherd-service): Call 'umask'.
This commit is contained in:
@@ -460,10 +460,12 @@ stopped before 'kill' is called."
|
||||
(let ((buf (make-bytevector 512)))
|
||||
(call-with-input-file "/dev/urandom"
|
||||
(lambda (urandom)
|
||||
(get-bytevector-n! urandom buf 0 512)
|
||||
(call-with-output-file #$%random-seed-file
|
||||
(lambda (seed)
|
||||
(put-bytevector seed buf)))
|
||||
(let ((previous-umask (umask #o077)))
|
||||
(get-bytevector-n! urandom buf 0 512)
|
||||
(call-with-output-file #$%random-seed-file
|
||||
(lambda (seed)
|
||||
(put-bytevector seed buf)))
|
||||
(umask previous-umask))
|
||||
#t)))))
|
||||
(modules `((rnrs bytevectors)
|
||||
(rnrs io ports)
|
||||
|
||||
Reference in New Issue
Block a user