Clear setgid when hardening Windows VM directories

A numeric chmod keeps setuid/setgid on a directory, so a setgid ~/Windows
stayed 2700 and failed the exact 700 privacy check, aborting the launch.
dockur marks an initially empty /shared setgid (chmod 2777) on first boot,
so this hits fresh installs the next time the bind anchors are recreated.
This commit is contained in:
Atos Lins committed 2026-09-17 17:44:26 -03:00
1 parent 9c5482c58d
commit bce0f512e0
3 files changed
+23 -2

No files matched your search

+2
View File
@@ -112,6 +112,8 @@ pass "pkexec target is only the canonical packaged regular file, never a PATH sy
reset_case
external_shared="$TMPDIR/external-shared"
mkdir -m 0755 -p "$HOME/.windows" "$external_shared" "$HOME/.config/windows"
# dockur leaves an initially empty share setgid, which a numeric chmod keeps.
chmod 2777 "$external_shared"
ln -s "$external_shared" "$HOME/Windows"
touch "$HOME/.windows/existing-disk" "$external_shared/existing-shared-file"
LEGACY_COMPOSE_FILE="$HOME/.config/windows/docker-compose.yml"