Uploaded image for project: 'MariaDB Server'
  1. MariaDB Server
  2. MDEV-35415

systemd CAP_DAC_OVERRIDE possibly overkill

    XMLWordPrintable

Details

    Description

      systemd unit claims:

      # CAP_DAC_OVERRIDE To allow auth_pam_tool (which is SUID root) to read /etc/shadow when it's chmod 0
      #   does nothing for non-root, not needed if /etc/shadow is u+r
      

      It may be possible to reduce this to CAP_DAC_READ_SEARCH without breaking anything else, to prevent `SELECT INTO OUTFILE` from creating files in unexpected locations (those not prevented by ProtectSystem)

      Attachments

        Activity

          People

            Unassigned Unassigned
            mg MG
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:

              Git Integration

                Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.