mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-09-30 22:11:59 -09:00
package/openssh: Set /var/empty permissions
The openssh privilege separation feature, enabled by default,
requires that the path /var/empty exists and has certain permissions
(not writable by the sshd user). Note that nothing ever gets writting
in this directory, so it works fine on a readonly rootfs.
See README.privsep included as part of the openssh distribution.
Signed-off-by: Chris Lesiak <chris.lesiak@licor.com>
Signed-off-by: Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
(cherry picked from commit f85665c585)
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
This commit is contained in:
committed by
Peter Korsgaard
parent
e715c9c3c5
commit
e417490427
@@ -22,6 +22,10 @@ define OPENSSH_USERS
|
|||||||
sshd -1 sshd -1 * - - - SSH drop priv user
|
sshd -1 sshd -1 * - - - SSH drop priv user
|
||||||
endef
|
endef
|
||||||
|
|
||||||
|
define OPENSSH_PERMISSIONS
|
||||||
|
/var/empty d 755 root root - - - - -
|
||||||
|
endef
|
||||||
|
|
||||||
ifeq ($(BR2_TOOLCHAIN_SUPPORTS_PIE),)
|
ifeq ($(BR2_TOOLCHAIN_SUPPORTS_PIE),)
|
||||||
OPENSSH_CONF_OPTS += --without-pie
|
OPENSSH_CONF_OPTS += --without-pie
|
||||||
endif
|
endif
|
||||||
|
|||||||
Reference in New Issue
Block a user