From a7629b98cf4e7f86bab07c2b75fa712adcd63ee5 Mon Sep 17 00:00:00 2001 From: Patrick Schleizer Date: Sun, 22 Oct 2023 15:40:49 -0400 Subject: [PATCH] fix --- usr/bin/remount-secure | 2 +- usr/share/lintian/overrides/security-misc | 3 +++ 2 files changed, 4 insertions(+), 1 deletion(-) diff --git a/usr/bin/remount-secure b/usr/bin/remount-secure index ab25e33..130042c 100755 --- a/usr/bin/remount-secure +++ b/usr/bin/remount-secure @@ -180,7 +180,7 @@ _tmp() { _var() { mount_folder="$NEWROOT/var" ## noexec: Not possible. Reason: - ## Debian stores executable maintainer scripts in /var/lib/dpkg/info/ folder. + ## Debian stores executable maintainer scripts in /var/lib/dpkg/info folder. intended_mount_options="nosuid,nodev" remount_secure "$@" } diff --git a/usr/share/lintian/overrides/security-misc b/usr/share/lintian/overrides/security-misc index b18ab3b..a82ad23 100644 --- a/usr/share/lintian/overrides/security-misc +++ b/usr/share/lintian/overrides/security-misc @@ -9,3 +9,6 @@ security-misc: no-manual-page [usr/bin/pkexec.security-misc] ## Non-ideal but still a good solution. security-misc: file-in-unusual-dir [var/cache/security-misc/state-files/placeholder] + +## False-positive. Just a comment mentioning dpkg's folder. +security-misc: uses-dpkg-database-directly [usr/bin/remount-secure]