Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: [security] cancel cap_dac_read_search #377

Merged
merged 1 commit into from
Nov 28, 2024

Conversation

jeffshuai
Copy link

cancel cap_dac_read_search

Log: cancel cap_dac_read_search

Bug: https://pms.uniontech.com/task-view-365257.html (cherry picked from commit 8aa68ab)

cancel cap_dac_read_search

Log:  cancel cap_dac_read_search

Bug: https://pms.uniontech.com/task-view-365257.html
(cherry picked from commit 8aa68ab)
@deepin-ci-robot
Copy link

deepin pr auto review

关键摘要:

  • setcap命令中移除了cap_dac_read_search权限,需要确认这一改动是否符合安全策略和功能需求。
  • chmod u-s /usr/bin/deepin-system-monitor命令在setcap失败时执行,这可能会导致权限问题,应该考虑在setcap成功后再执行。

是否建议立即修改:

  • 是,需要确保权限的移除和设置是经过充分评估的,并且不会引入新的安全问题。
  • 是,应该确保在setcap成功后再执行chmod命令,以避免潜在的权限问题。

@max-lvs max-lvs merged commit 9dc8b26 into linuxdeepin:release/105x Nov 28, 2024
7 checks passed
@deepin-ci-robot
Copy link

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: jeffshuai, max-lvs

The full list of commands accepted by this bot can be found here.

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants