Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

NAS-130198 / 24.04.3 / Remove check for whether localhost connection is root (by anodos325) #14082

Merged
merged 1 commit into from
Jul 25, 2024

Conversation

bugclerk
Copy link
Contributor

We don't use this functionality internally and it's a potential security liability if someone decides to set up their own internal proxy to middlewared socket that's running as root, or if an application allows root account and has access to host networking.

Original PR: #14068
Jira URL: https://ixsystems.atlassian.net/browse/NAS-130198

We don't use this functionality internally and it's a potential
security liability if someone decides to set up their own internal
proxy to middlewared socket that's running as root.

(cherry picked from commit 0673f0d)
@anodos325 anodos325 merged commit 5100ff4 into stable/dragonfish Jul 25, 2024
1 of 2 checks passed
@anodos325 anodos325 deleted the NAS-130198-24.04.3 branch July 25, 2024 13:24
@bugclerk
Copy link
Contributor Author

This PR has been merged and conversations have been locked.
If you would like to discuss more about this issue please use our forums or raise a Jira ticket.

@truenas truenas locked as resolved and limited conversation to collaborators Jul 25, 2024
@yocalebo
Copy link
Contributor

yocalebo commented Sep 3, 2024

backport

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants