Package: tor Version: 0.2.6.10-1 Severity: normal Hi,
When looking at the capabilities that are granted by the .service file compared to the upstream one (in the contrib directory), I'm wondering if it couldn't be reduced. -CapabilityBoundingSet=CAP_SETUID CAP_SETGID CAP_NET_BIND_SERVICE +CapabilityBoundingSet=CAP_SETUID CAP_SETGID CAP_NET_BIND_SERVICE CAP_DAC_OVERRIDE CAP_CHOWN CAP_FOWNER The dac_override one could atleast be dropped if root also had access to the /var/log/tor /var/lib/tor directories (giving access to the root group?). Not too sure about the other ones. I'm also wondering about: ReadWriteDirectories=-/var/run, shouldn't this be removed and shouldn't /var/run/tor be created by tmpfiles mechanism (or the RuntimeDirectory= option) instead of using the install command? Also, shouldn't "NoNewPrivileges=yes" be added like in the upstream one? Cheers, Laurent Bigonville -- System Information: Debian Release: stretch/sid APT prefers unstable APT policy: (500, 'unstable'), (1, 'experimental') Architecture: amd64 (x86_64) Foreign Architectures: i386 Kernel: Linux 4.1.0-2-amd64 (SMP w/8 CPU cores) Locale: LANG=fr_BE.utf8, LC_CTYPE=fr_BE.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash Init: systemd (via /run/systemd/system) Versions of packages tor depends on: ii adduser 3.113+nmu3 ii init-system-helpers 1.23 ii libc6 2.19-22 ii libevent-2.0-5 2.0.21-stable-2 ii libseccomp2 2.2.3-2 ii libssl1.0.0 1.0.2d-1 ii libsystemd0 226-3 ii lsb-base 9.20150917 ii zlib1g 1:1.2.8.dfsg-2+b1 Versions of packages tor recommends: ii logrotate 3.8.7-2 ii tor-geoipdb 0.2.6.10-1 ii torsocks 2.1.0-1 Versions of packages tor suggests: pn apparmor-utils <none> pn mixmaster <none> pn obfs4proxy <none> pn obfsproxy <none> pn socat <none> pn tor-arm <none> pn torbrowser-launcher <none> -- no debconf information

