diff --git a/etc/permission-hardening.d/30_default.conf b/etc/permission-hardening.d/30_default.conf index a70b6e5..fa77fdc 100644 --- a/etc/permission-hardening.d/30_default.conf +++ b/etc/permission-hardening.d/30_default.conf @@ -14,6 +14,7 @@ ## argument. ## SUID whitelist. +## TODO: white spaces inside file name untested /usr/bin/sudo whitelist /bin/sudo whitelist /usr/bin/bwrap whitelist diff --git a/usr/lib/security-misc/permission-hardening b/usr/lib/security-misc/permission-hardening index b2500dc..a58ffdf 100755 --- a/usr/lib/security-misc/permission-hardening +++ b/usr/lib/security-misc/permission-hardening @@ -176,6 +176,7 @@ set_file_perms() { fso_without_trailing_slash="${fso%/}" if [ "$mode_from_config" = "whitelist" ]; then + ## TODO: test/add white spaces inside file name support whitelist+="$fso_without_trailing_slash " continue fi