diff --git a/meta-openeuler/recipes-core/audit/files/audit.rules b/meta-openeuler/recipes-core/audit/files/audit.rules index 09ccf53281ea06209e832ebcc1650951afed2669..8b8f2e598282cba27c04da7034719dfa634f547e 100644 --- a/meta-openeuler/recipes-core/audit/files/audit.rules +++ b/meta-openeuler/recipes-core/audit/files/audit.rules @@ -27,8 +27,8 @@ -w /etc/issue.net -p wa -k system-locale -w /etc/hosts -p wa -k system-locale -w /etc/network -p wa -k system-locale --w /etc/sysconfig/network -p wa -k system-locale --w /etc/sysconfig/network-scripts -p wa -k system-locale +#-w /etc/sysconfig/network -p wa -k system-locale +#-w /etc/sysconfig/network-scripts -p wa -k system-locale -w /etc/selinux/ -p wa -k MAC-policy -w /var/log/lastlog -p wa -k logins -w /var/log/tallylog -p wa -k logins diff --git a/meta-openeuler/recipes-core/lxc/lxc/check_only_rootfs_as_filesystem_type.patch b/meta-openeuler/recipes-core/lxc/lxc/check_only_rootfs_as_filesystem_type.patch new file mode 100644 index 0000000000000000000000000000000000000000..c37318d330883edd0f7ebb75c036d342fd5f2b6e --- /dev/null +++ b/meta-openeuler/recipes-core/lxc/lxc/check_only_rootfs_as_filesystem_type.patch @@ -0,0 +1,21 @@ +commit 4f16f60b4ad67a11da4cf7a38391a28724e49f18 +Author: lisimin +Date: Thu Sep 23 11:10:59 2021 +0800 + + check only rootfs as filesytem type + + Signed-off-by: lisimin + +diff --git a/src/lxc/utils.c b/src/lxc/utils.c +index 95c00cf..46e9d35 100644 +--- a/src/lxc/utils.c ++++ b/src/lxc/utils.c +@@ -730,7 +730,7 @@ bool detect_ramfs_rootfs(void) + if (strcmp(p + 1, "/") == 0) { + /* This is '/'. Is it the ramfs? */ + p = strchr(p2 + 1, '-'); +- if (p && strncmp(p, "- rootfs rootfs ", 16) == 0) ++ if (p && strncmp(p, "- rootfs ", 9) == 0) + return true; + } + } diff --git a/meta-openeuler/recipes-core/lxc/lxc_4.0.3.bb b/meta-openeuler/recipes-core/lxc/lxc_4.0.3.bb index 9d7ba8c13786a811e45e478e844ef4f3ba99de14..6d4b3fc82f7eb5249a119bb266b84e407d6ee635 100644 --- a/meta-openeuler/recipes-core/lxc/lxc_4.0.3.bb +++ b/meta-openeuler/recipes-core/lxc/lxc_4.0.3.bb @@ -33,6 +33,7 @@ SRC_URI = "file://lxc/lxc-4.0.3.tar.gz \ file://lxc/0025-get-cgroup-data-len-first-and-malloc-read-buff-by-le.patch \ file://lxc/0026-coredump-fix-coredump-when-cgroup-get-return-error.patch \ file://support_arm32.patch \ + file://check_only_rootfs_as_filesystem_type.patch \ " FILESPATH_prepend += "${LOCAL_FILES}/${BPN}:" diff --git a/meta-openeuler/recipes-core/os-base/os-base/shadow b/meta-openeuler/recipes-core/os-base/os-base/shadow index 21dbde6ce925b445e9d542a78713b1ca51703214..988556e4555633662b176964cf3ede461683522a 100644 --- a/meta-openeuler/recipes-core/os-base/os-base/shadow +++ b/meta-openeuler/recipes-core/os-base/os-base/shadow @@ -1,2 +1,2 @@ -root:$6$sHTXIVQU$r8zE6YB6fyJfbvTzEUl3R1tVlY7L/3R1G8Gf4c9dvJx3E4hMv8GS.IN3naMh2bfL7RBd1JlnnfGcru3Ko9gkQ.:16056:0:99999:7::: +root:$6$WthYamqr$nkDUajqkYZ0HWYLY93LOa79W0Bgoc1sNY357EXjsJ4d/VtZBIZGQHAP3/GJ42.QvEwTy7LCwWn0FQ.QRyfkjW/:0:0:99999:7::: sshd:!:11880:0:90:7:-1:-1:0