Package: vmdebootstrap Version: 1.7-1 Severity: important Hi,
squashfs filesystems produced by vmdebootstrap have no g+x or o+x permissions on the root of the filesystem which prevents non-root users from traversing any of the filesystem. In live-wrapper this is temporarily fixed by a chmod in the chroot during the customise.sh stage. Thanks, Iain. -- System Information: Debian Release: stretch/sid APT prefers testing APT policy: (500, 'testing') Architecture: amd64 (x86_64) Kernel: Linux 4.7.0-1-amd64 (SMP w/4 CPU cores) Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash Init: systemd (via /run/systemd/system) Versions of packages vmdebootstrap depends on: ii debootstrap 1.0.84 ii kpartx 0.6.3-2 ii libjs-sphinxdoc 1.4.8-1 ii parted 3.2-16+b1 ii python-cliapp 1.20160724-1 ii python-distro-info 0.14 ii python2.7 2.7.12-3+b1 pn python:any <none> ii qemu-utils 1:2.7+dfsg-3+b1 Versions of packages vmdebootstrap recommends: ii dosfstools 4.0-2 ii extlinux 3:6.03+dfsg-14 ii grub2-common 2.02~beta3-1 ii python-guestfs 1:1.32.7-1+b2 ii qemu-system 1:2.7+dfsg-3+b1 ii qemu-user-static 1:2.7+dfsg-3+b1 ii squashfs-tools 1:4.3-3 Versions of packages vmdebootstrap suggests: pn cmdtest <none> pn mbr <none> pn pandoc <none> pn u-boot:armhf <none> -- no debconf information

