From 69cee6f711ab355cfec4a788a0b0d2122b4603ec082e8653221af13031457aed Mon Sep 17 00:00:00 2001 From: Marcus Rueckert Date: Fri, 20 Oct 2017 11:02:37 +0000 Subject: [PATCH] - actually try to find the real path to bash and don't hardcode /usr/bin/bash OBS-URL: https://build.opensuse.org/package/show/security:dehydrated/dehydrated?expand=0&rev=19 --- dehydrated.changes | 5 +++++ dehydrated.service.in | 3 +-- 2 files changed, 6 insertions(+), 2 deletions(-) diff --git a/dehydrated.changes b/dehydrated.changes index 532aab0..c77f508 100644 --- a/dehydrated.changes +++ b/dehydrated.changes @@ -1,3 +1,8 @@ +------------------------------------------------------------------- +Fri Oct 20 11:02:24 UTC 2017 - mrueckert@suse.de + +- revert accidental change to the service file + ------------------------------------------------------------------- Fri Oct 20 10:55:26 UTC 2017 - mrueckert@suse.de diff --git a/dehydrated.service.in b/dehydrated.service.in index bf4121f..6038ab0 100644 --- a/dehydrated.service.in +++ b/dehydrated.service.in @@ -7,8 +7,7 @@ Wants=acmeresponder.socket [Service] Type=oneshot ExecStartPost=-/usr/bin/find -L @POSTRUNHOOKS_DIR@ -maxdepth 1 -executable -type f -exec {} \; -EnvironmentFile=/etc/dehydrated/config -ExecStart=/usr/bin/su -s /bin/bash -c "/usr/bin/dehydrated --cron" -g $DEHYDRATED_GROUP $DEHYDRATED_USER +ExecStart=/usr/bin/dehydrated --cron # dehydrated --cron will drop permissions and run critical code as dehydrated user. User=root