From 72f444ffc511eccdb02ee5cd9744e1c8d8f0687f Mon Sep 17 00:00:00 2001 From: Bruno Herbelin Date: Fri, 10 Jan 2025 23:47:44 +0100 Subject: [PATCH] Fixed Manual review requested. AnalyzeReviewTask.on_manual_review: Found files with executable stack. This adds PROT_EXEC to mmap(2) during mediation which may cause security denials. Either adjust your program to not require an executable stack, strip it with 'execstack --clear-execstack ...' or remove the affected file from your snap. Affected files: usr/lib/arm-linux-gnueabihf/libdirect-1.7.so.7.0.0 --- snap/snapcraft.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/snap/snapcraft.yaml b/snap/snapcraft.yaml index 3c58159..61bad10 100644 --- a/snap/snapcraft.yaml +++ b/snap/snapcraft.yaml @@ -110,7 +110,7 @@ parts: override-prime: | craftctl default # try remove execstack on armhf - for f in usr/lib/arm-linux-gnueabihf/libde265.so.0.1.1 usr/lib/arm-linux-gnueabihf/libmpeg2.so.0.1.0; do + for f in usr/lib/arm-linux-gnueabihf/libde265.so.0.1.8 usr/lib/arm-linux-gnueabihf/libmpeg2.so.0.1.0 usr/lib/arm-linux-gnueabihf/libdirect-1.7.so.7.0.0; do if [ -f $f ]; then execstack -c $f fi