f293239d5b
It's at least removing the very obvious user->root attack through (maliciously) modifying bin/tar2fs and waiting for it to be run; if mkimage-profiles is installed system-wide as a package, the script from /usr/share/mkimage-profiles will be tried so those willing to allow vm/* build to themselves can provide for a passwordless sudo (as described in doc/vm.txt) to run a root-only writable script, not user-writable. Still not perfect but a step away from the abyss. |
||
---|---|---|
.. | ||
image-scripts.d | ||
lib | ||
config.mk | ||
generate.mk | ||
README |
Эта фича конфигурирует создание образа виртуальной машины (VM). Дополняет финальную стадию сборки (lib/, image-scripts.d/). Требует для работы sudo(8) -- см. тж. doc/vm.txt