Details
-
Bug
-
Status: Closed (View Workflow)
-
Blocker
-
Resolution: Fixed
-
10.5.25
Description
Hi,
I tried to figure out why mariadbd actually can write in paths where only root has permissions and then I found
https://github.com/MariaDB/server/blob/main/support-files/mariadb.service.in#L54
Setting `AmbientCapabilities=CAP_DAC_OVERRIDE` is just as effective as running mariadbd as root.
You can test it by changing permissions on /var/lib/mysql to root:root. Mariadbd can still write in that folder even though it should not have permissions
Attachments
Issue Links
- causes
-
MDEV-36591 RHEL 8 (and compatible) + Ubuntu 20.04 cannot start systemd servce (EXIT_CAPABILTIES/218)
-
- Closed
-
- is caused by
-
MDEV-33301 memlock with systemd still not working even with MDEV-9095 fix
-
- Closed
-
- relates to
-
MDEV-33301 memlock with systemd still not working even with MDEV-9095 fix
-
- Closed
-
eworm, not necessarily, but worry not, being a blocker it will, definitely, be in the next release. There's still time.