Skip to content

Commit 09054ee

Browse files
Set the suid_dumpable to the safe value of 2
See dev-sec/linux-baseline#52 for more details
1 parent 8ea782c commit 09054ee

File tree

2 files changed

+2
-2
lines changed

2 files changed

+2
-2
lines changed

recipes/sysctl.rb

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -105,7 +105,7 @@
105105
# Prevent core dumps with SUID. These are usually only needed by developers and
106106
# may contain sensitive information.
107107
node.default['sysctl']['params']['fs']['suid_dumpable'] =
108-
node['os-hardening']['security']['kernel']['enable_core_dump'] ? 1 : 0
108+
node['os-hardening']['security']['kernel']['enable_core_dump'] ? 2 : 0
109109

110110
# include sysctl recipe and set /etc/sysctl.d/99-chef-attributes.conf
111111
include_recipe 'sysctl::apply'

spec/recipes/sysctl_spec.rb

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -351,7 +351,7 @@
351351
let(:enable_core_dump) { true }
352352

353353
it 'should set suid_dumpable to safe value' do
354-
is_expected.to eq(1)
354+
is_expected.to eq(2)
355355
end
356356
end
357357

0 commit comments

Comments
 (0)