#!/bin/sh
# Restore Debian's setuid/setgid/sticky modes (sudo, su, passwd, /tmp ...).
# Modes come from the package archives + maintainer scripts; only touches paths that exist.
# Usage: mood-fix-perms [ROOT]
R="${1:-}"
set_mode() {
  p="$R$4"
  [ -e "$p" ] && [ ! -L "$p" ] || return 0
  chown "$1:$2" "$p" 2>/dev/null || true
  chmod "$3" "$p"
}
while read -r own grp mode path; do
  set_mode "$own" "$grp" "$mode" "$path"
done <<'EOF'
root root 1777 /tmp
root root 1777 /var/tmp
root root 1777 /var/lock
root root 1777 /run/lock
root mail 2775 /var/mail
root staff 2775 /usr/local
root staff 2775 /usr/local/share
root staff 2775 /usr/local/share/man
root staff 2775 /usr/local/bin
root staff 2775 /usr/local/games
root staff 2775 /usr/local/lib
root staff 2775 /usr/local/libexec
root staff 2775 /usr/local/include
root staff 2775 /usr/local/sbin
root staff 2775 /usr/local/src
root staff 2775 /usr/local/etc
root staff 2775 /var/local
root root 4755 /usr/bin/sudo
root root 4755 /usr/bin/su
root root 4755 /usr/bin/passwd
root root 4755 /usr/bin/chfn
root root 4755 /usr/bin/chsh
root root 4755 /usr/bin/gpasswd
root root 4755 /usr/bin/newgrp
root root 4755 /usr/bin/mount
root root 4755 /usr/bin/umount
root root 4755 /usr/bin/newuidmap
root root 4755 /usr/bin/newgidmap
root root 4755 /usr/bin/ntfs-3g
root root 4755 /usr/bin/pkexec
root root 4755 /usr/bin/fusermount3
root root 4755 /usr/bin/fusermount
root root 4755 /usr/lib/polkit-1/polkit-agent-helper-1
root root 4755 /usr/lib/openssh/ssh-keysign
root root 4755 /usr/lib/xorg/Xorg.wrap
root root 4755 /usr/lib/x86_64-linux-gnu/gstreamer1.0/gstreamer-1.0/gst-ptp-helper
root messagebus 4754 /usr/lib/dbus-1.0/dbus-daemon-launch-helper
root shadow 2755 /usr/bin/chage
root shadow 2755 /usr/bin/expiry
root shadow 2755 /usr/sbin/unix_chkpwd
EOF
exit 0
