Bugzilla – Bug 1143659
AUDIT-FIND: obs-service-extract_file: calls cpio instead of bsdtar
Last modified: 2020-11-25 09:28:15 UTC
should probably use bsdtar instead of cpio
not sure that bsdtar is that much better, but passing --no-absolute-filenames to cpio would be a good idea. A generic solution of sandboxing the operation no matter which tool is used would be my preferred solution
added that parameter