Uploaded image for project: 'MariaDB Server'
  1. MariaDB Server
  2. MDEV-36229

MariaDB effectively running as root CAP_DAC_OVERRIDE

    XMLWordPrintable

Details

    Description

      Hi,

      I tried to figure out why mariadbd actually can write in paths where only root has permissions and then I found

      https://github.com/MariaDB/server/blob/main/support-files/mariadb.service.in#L54

      Setting `AmbientCapabilities=CAP_DAC_OVERRIDE` is just as effective as running mariadbd as root.

      You can test it by changing permissions on /var/lib/mysql to root:root. Mariadbd can still write in that folder even though it should not have permissions

      Attachments

        Issue Links

          Activity

            People

              cvicentiu Vicențiu Ciorbaru
              Desdic Kim Gert Nielsen
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Git Integration

                  Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.