This commit is contained in:
Patrick Schleizer 2025-01-14 04:13:39 -05:00
parent 6d282226ef
commit eec2e2c8ee
No known key found for this signature in database
GPG Key ID: CB8D50BB77BB3C48

View File

@ -12,10 +12,13 @@
## qfile-unpacker allows unprivileged users in VMs to gain root privileges
## https://github.com/QubesOS/qubes-issues/issues/8633
##
## match both:
## matches both:
## - /usr/lib/qubes/qfile-unpacker whitelist
## - Not bit-for-bit identical to /usr/lib/qubes/qfile-unpacker.
## - Stripping SUID from this does *not* break file copying.
## - TODO: further reserach required on its purpose
## - /usr/bin/qfile-unpacker
## - Appears to be an integral part of file transfer between qubes, stripping
## SUID from this in an AppVM results in that AppVM being unable to receive
## files any longer. (It can still send files to other qubes though.)
qfile-unpacker matchwhitelist