Make setuid/setgid file exceptions more robust.
This commit is contained in:
parent
25b2d55175
commit
23c10bf98c
2 changed files with 2 additions and 2 deletions
|
@ -22,7 +22,7 @@ RUN dnf5 -y autoremove
|
|||
|
||||
# Remove setuid/setgid binaries
|
||||
# Except for polkit-agent-helper-1, it's currently required for interactive authentication with polkit.
|
||||
RUN find /usr -mindepth 1 -type f -perm /6000 -regextype posix-extended -not -regex '/usr/lib/polkit-1/polkit-agent-helper-1|/usr/sbin/unix_chkpwd|/usr/bin/fusermount|/usr/bin/fusermount3' -exec sh -c "chmod ug-s '{}' && echo \"Removed setuid/setgid bit(s) from '{}'\"" \;
|
||||
RUN find /usr -mindepth 1 -type f -perm /6000 -regextype posix-extended -not -regex '^/usr/lib/polkit-1/polkit-agent-helper-1$|^/usr/sbin/unix_chkpwd$|^/usr/bin/fusermount[0-9]?$' -exec sh -c "chmod ug-s '{}' && echo \"Removed setuid/setgid bit(s) from '{}'\"" \;
|
||||
|
||||
# https://github.com/ostreedev/ostree-rs-ext/issues/159
|
||||
RUN ostree container commit
|
||||
|
|
|
@ -22,7 +22,7 @@ RUN dnf5 -y autoremove
|
|||
|
||||
# Remove setuid/setgid binaries
|
||||
# Except for polkit-agent-helper-1, it's currently required for interactive authentication with polkit.
|
||||
RUN find /usr -mindepth 1 -type f -perm /6000 -regextype posix-extended -not -regex '/usr/lib/polkit-1/polkit-agent-helper-1|/usr/sbin/unix_chkpwd|/usr/bin/fusermount|/usr/bin/fusermount3' -exec sh -c "chmod ug-s '{}' && echo \"Removed setuid/setgid bit(s) from '{}'\"" \;
|
||||
RUN find /usr -mindepth 1 -type f -perm /6000 -regextype posix-extended -not -regex '^/usr/lib/polkit-1/polkit-agent-helper-1$|^/usr/sbin/unix_chkpwd$|^/usr/bin/fusermount[0-9]?$' -exec sh -c "chmod ug-s '{}' && echo \"Removed setuid/setgid bit(s) from '{}'\"" \;
|
||||
|
||||
# https://github.com/ostreedev/ostree-rs-ext/issues/159
|
||||
RUN ostree container commit
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue