Files
frigate/docker/main/rootfs/etc/s6-overlay/s6-rc.d/nginx
Josh Hawkins 126cc0ba31 harden root writes into unprivileged-owned paths
Restrict the sweep sentinel to a mount at or below /media/frigate so a
parent /media mount cannot bless a later-shadowed volume. Rebuild
/tmp/nginx root-owned each start so root's cp and tempio writes cannot
follow a symlink an unprivileged nginx planted in the previous run.
2026-08-28 07:28:47 -05:00
..
2024-06-01 10:29:46 -05:00