SUSE Linux Default Permissions

Edit Package permissions

This package contains specifications for permissions of specific files,
directories, and devices depending on the local security settings. The
local security setting (easy, secure, or paranoid) can be configured in
/etc/sysconfig/security.

Refresh
Refresh
Source Files
Filename Size Changed
_service 0000000417 417 Bytes
_servicedata 0000000233 233 Bytes
fix_version.sh 0000000170 170 Bytes
permissions-20200228.tar.xz 0000036196 35.3 KB
permissions.changes 0000063209 61.7 KB
permissions.spec 0000004113 4.02 KB
Revision 132 (latest revision is 167)
Dominique Leuenberger's avatar Dominique Leuenberger (dimstar_suse) accepted request 780979 from Matthias Gerstner's avatar Matthias Gerstner (mgerstner) (revision 132)
- Update to version 20200228:
  * chkstat: fix readline() on platforms with unsigned char

- Update to version 20200227:
  * remove capability whitelisting for radosgw
  * whitelist ceph log directory (bsc#1150366)
  * adjust testsuite to post CVE-2020-8013 link handling
  * testsuite: add option to not mount /proc
  * do not follow symlinks that are the final path element: CVE-2020-8013
  * add a test for symlinked directories
  * fix relative symlink handling
  * include cpp compat headers, not C headers
  * Move permissions and permissions.* except .local to /usr/share/permissions
  * regtest: fix the static PATH list which was missing /usr/bin
  * regtest: also unshare the PID namespace to support /proc mounting
  * regtest: bindMount(): explicitly reject read-only recursive mounts
  * Makefile: force remove upon clean target to prevent bogus errors
  * regtest: by default automatically (re)build chkstat before testing
  * regtest: add test for symlink targets
  * regtest: make capability setting tests optional
  * regtest: fix capability assertion helper logic
  * regtests: add another test case that catches set*id or caps in world-writable sub-trees
  * regtest: add another test that catches when privilege bits are set for special files
  * regtest: add test case for user owned symlinks
  * regtest: employ subuid and subgid feature in user namespace
  * regtest: add another test case that covers unknown user/group config
  * regtest: add another test that checks rejection of insecure mixed-owner paths
  * regtest: add test that checks for rejection of world-writable paths
  * regtest: add test for detection of unexpected parent directory ownership
  * regtest: add further helper functions, allow access to main instance (forwarded request 780264 from mkraus)
Comments 0
openSUSE Build Service is sponsored by