diff --git a/secure-configuration-benchmark/baseline/OPENGAUSS.G_1/OPENGAUSS.O_6.G_1.R_4.md b/secure-configuration-benchmark/baseline/OPENGAUSS.G_1/OPENGAUSS.O_6.G_1.R_4.md index 4b159d1c14b89c1c2f41319bc30e4c4c7226967b..5ea244bd6dd40c97bd77230bc8ab79bef1c56196 100644 --- a/secure-configuration-benchmark/baseline/OPENGAUSS.G_1/OPENGAUSS.O_6.G_1.R_4.md +++ b/secure-configuration-benchmark/baseline/OPENGAUSS.G_1/OPENGAUSS.O_6.G_1.R_4.md @@ -31,7 +31,7 @@ OPENGAUSS.O_6.G_1.R_4 执行如下SQL语句检查是否存在不限制连接数的数据库: ```sql -SELECT datname FROM pg_database WHERE datistemplate = false AND datconnlimit = -1; +SELECT datname FROM pg_database WHERE datistemplate = false AND (datconnlimit = -1 OR datconnlimit > 1024); ``` **修复方法:** diff --git a/secure-configuration-benchmark/baseline/OPENGAUSS.G_2/OPENGAUSS.O_6.G_2.R_2.md b/secure-configuration-benchmark/baseline/OPENGAUSS.G_2/OPENGAUSS.O_6.G_2.R_2.md index 32264c96de736bb5d58f8e0c38fb390d16f455bf..eda2326b96d11ff4a2736b94d24b79026d5ce806 100644 --- a/secure-configuration-benchmark/baseline/OPENGAUSS.G_2/OPENGAUSS.O_6.G_2.R_2.md +++ b/secure-configuration-benchmark/baseline/OPENGAUSS.G_2/OPENGAUSS.O_6.G_2.R_2.md @@ -30,7 +30,7 @@ OPENGAUSS.O_6.G_2.R_2 执行如下 shell 命令,如果返回 `${GAUSSHOME}/share` 目录则失败。 ```bash -find ${GAUSSHOME}/share -prune -type d \( -perm -g=w -o -perm -o=w \) -exec ls -ld {} \; +find ${GAUSSHOME}/share -prune -perm /g=rwx,o=rwx ``` **修复方法:** diff --git "a/secure-configuration-benchmark/release/openGauss\345\256\211\345\205\250\351\205\215\347\275\256\345\237\272\347\272\277.md" "b/secure-configuration-benchmark/release/openGauss\345\256\211\345\205\250\351\205\215\347\275\256\345\237\272\347\272\277.md" index ec2b7af5c7961b36d960e21fae3d093be7020437..7fcc8a8394309e646d8d18298cafdfb421d17c02 100644 --- "a/secure-configuration-benchmark/release/openGauss\345\256\211\345\205\250\351\205\215\347\275\256\345\237\272\347\272\277.md" +++ "b/secure-configuration-benchmark/release/openGauss\345\256\211\345\205\250\351\205\215\347\275\256\345\237\272\347\272\277.md" @@ -181,7 +181,7 @@ OPENGAUSS.O_6.G_1.R_4 执行如下SQL语句检查是否存在不限制连接数的数据库: ```sql -SELECT datname FROM pg_database WHERE datistemplate = false AND datconnlimit = -1; +SELECT datname FROM pg_database WHERE datistemplate = false AND (datconnlimit = -1 OR datconnlimit > 1024); ``` **修复方法:** @@ -727,7 +727,7 @@ OPENGAUSS.O_6.G_2.R_2 执行如下 shell 命令,如果返回 `${GAUSSHOME}/share` 目录则失败。 ```bash -find ${GAUSSHOME}/share -prune -type d \( -perm -g=w -o -perm -o=w \) -exec ls -ld {} \; +find ${GAUSSHOME}/share -prune -perm /g=rwx,o=rwx ``` **修复方法:**