Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

make clamav read-only #2813

Merged
merged 1 commit into from
Jun 19, 2023
Merged

make clamav read-only #2813

merged 1 commit into from
Jun 19, 2023

Conversation

szaimen
Copy link
Collaborator

@szaimen szaimen commented Jun 19, 2023

Address part of #2506

@szaimen szaimen added 3. to review Waiting for reviews enhancement New feature or request labels Jun 19, 2023
@szaimen szaimen added this to the next milestone Jun 19, 2023
@szaimen szaimen marked this pull request as draft June 19, 2023 12:59
@szaimen
Copy link
Collaborator Author

szaimen commented Jun 19, 2023

This does not work currently as tmpfs is set to 755 by default inside the container IIRC. See docker/compose#3425 (comment) for a workaround. However we might need to switch to mount syntax internally in order to specify the permission mode. See https://docs.docker.com/storage/tmpfs/

However this does not work with docker-compose. So not sure how to proceed here.

@szaimen szaimen added 2. developing Work in progress and removed 3. to review Waiting for reviews labels Jun 19, 2023
@szaimen
Copy link
Collaborator Author

szaimen commented Jun 19, 2023

After testing, it appears ownership is not kept but permissions are.

Containers/clamav/Dockerfile Outdated Show resolved Hide resolved
Containers/clamav/Dockerfile Outdated Show resolved Hide resolved
Signed-off-by: Simon L <szaimen@e.mail.de>
@szaimen szaimen added 3. to review Waiting for reviews and removed 2. developing Work in progress labels Jun 19, 2023
@szaimen szaimen marked this pull request as ready for review June 19, 2023 13:31
@szaimen szaimen merged commit 97e2927 into main Jun 19, 2023
8 checks passed
@delete-merged-branch delete-merged-branch bot deleted the enh/noid/clamav-read-only branch June 19, 2023 13:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
3. to review Waiting for reviews enhancement New feature or request
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant