You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
ddev-dbserver has sudo and uses it. A fair bit. And it has a writeable .ddev mount in /mnt/ddev_config, so a break-in might be able to use sudo to make a setuid file on the host.
It's unlikely that shell-access to the dbserver would be obtained, but it would sure be better if we could just get sudo off of here.
A related technique (leaving sudo here) would be to share only the .ddev/db_snapshots directory as writeable, and share the .ddev directory as read-only. Might be easier and better.
To Reproduce
Steps to reproduce the behavior:
Go to '...'
Click on '....'
Scroll down to '....'
See error
Expected behavior
A clear and concise description of what you expected to happen.
Screenshots
If applicable, add screenshots to help explain your problem.
Version and configuration information (please complete the following information):
Host computer OS and Version: [e.g. Windows 10, macOS Catalina]
Docker Desktop version if on macOS or Windows (from "About Docker Desktop")
ddev version information (use ddev version)
config.yaml contents for the misbehaving project
Do you have any custom configuration (nginx, php, mysql) in the .ddev folder? If so, have you tried without them?
Additional context
Add any other context about the problem here. Thanks!
The text was updated successfully, but these errors were encountered:
Describe the bug
ddev-dbserver has sudo and uses it. A fair bit. And it has a writeable .ddev mount in /mnt/ddev_config, so a break-in might be able to use sudo to make a setuid file on the host.
It's unlikely that shell-access to the dbserver would be obtained, but it would sure be better if we could just get sudo off of here.
A related technique (leaving sudo here) would be to share only the .ddev/db_snapshots directory as writeable, and share the .ddev directory as read-only. Might be easier and better.
To Reproduce
Steps to reproduce the behavior:
Expected behavior
A clear and concise description of what you expected to happen.
Screenshots
If applicable, add screenshots to help explain your problem.
Version and configuration information (please complete the following information):
ddev version
)Additional context
Add any other context about the problem here. Thanks!
The text was updated successfully, but these errors were encountered: