diff --git a/usr/bin/remount-secure b/usr/bin/remount-secure index ab25e33..130042c 100755 --- a/usr/bin/remount-secure +++ b/usr/bin/remount-secure @@ -180,7 +180,7 @@ _tmp() { _var() { mount_folder="$NEWROOT/var" ## noexec: Not possible. Reason: - ## Debian stores executable maintainer scripts in /var/lib/dpkg/info/ folder. + ## Debian stores executable maintainer scripts in /var/lib/dpkg/info folder. intended_mount_options="nosuid,nodev" remount_secure "$@" } diff --git a/usr/share/lintian/overrides/security-misc b/usr/share/lintian/overrides/security-misc index b18ab3b..a82ad23 100644 --- a/usr/share/lintian/overrides/security-misc +++ b/usr/share/lintian/overrides/security-misc @@ -9,3 +9,6 @@ security-misc: no-manual-page [usr/bin/pkexec.security-misc] ## Non-ideal but still a good solution. security-misc: file-in-unusual-dir [var/cache/security-misc/state-files/placeholder] + +## False-positive. Just a comment mentioning dpkg's folder. +security-misc: uses-dpkg-database-directly [usr/bin/remount-secure]