package/openssh: Set /var/empty permissions
The openssh privilege separation feature, enabled by default, requires that the path /var/empty exists and has certain permissions (not writable by the sshd user). Note that nothing ever gets writting in this directory, so it works fine on a readonly rootfs. See README.privsep included as part of the openssh distribution. Signed-off-by: Chris Lesiak <chris.lesiak@licor.com> Signed-off-by: Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
This commit is contained in:
parent
122089adf6
commit
f85665c585
@ -23,6 +23,10 @@ define OPENSSH_USERS
|
||||
sshd -1 sshd -1 * - - - SSH drop priv user
|
||||
endef
|
||||
|
||||
define OPENSSH_PERMISSIONS
|
||||
/var/empty d 755 root root - - - - -
|
||||
endef
|
||||
|
||||
ifeq ($(BR2_TOOLCHAIN_SUPPORTS_PIE),)
|
||||
OPENSSH_CONF_OPTS += --without-pie
|
||||
endif
|
||||
|
Loading…
Reference in New Issue
Block a user