mirror of
https://github.com/wnlen/clash-for-linux.git
synced 2026-10-10 12:13:04 +08:00
2511b1285b
Problem 1 - can_manage_tun_safely() missed setcap grants: - Add kernel_binary_has_cap_net_admin(): use getcap to detect file capability cap_net_admin on the kernel binary, so a user who ran 'setcap cap_net_admin,cap_net_raw+ep mihomo' is allowed through. - Extend can_manage_tun_safely() to call this check after the existing capsh (current-shell) check. - In cmd_tun_on(), add a process-level fallback via the existing tun_process_has_cap_net_admin() for cases where getcap is unavailable but the running process already holds the capability. Problem 2 - sudo clashctl corrupts runtime file ownership: - Add guard_sudo_on_user_install(): detects root + SUDO_USER + stored install scope == user, refuses with a clear message and instructs the user to run as the install user directly. - Call the guard at the entry of both cmd_tun_on() and cmd_tun_off() so neither write path can corrupt runtime/ file ownership.