[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Setuid



>I propose that we institute a stricter policy regarding setuid-root
>code.

I agree, but along with this policy needs to be a standard set of methods
(or suggestions) of how people can do the things that are currently being
handled by having the suid bit set.

For example:

The Apple ][ emulator I uploaded use svgalib.  Access to that library
requires root privileges.  Therefore, the "apple2" binary must either
be "suid root" or can only be run as root.

This same thing applied to all packages linked against svgalib, including
ghostscript.

                                          Brian
                                 ( bcwhite@verisim.com )
                                             
-------------------------------------------------------------------------------
 the difference between theory and practice is less in theory than in practice


--
TO UNSUBSCRIBE FROM THIS MAILING LIST: e-mail the word "unsubscribe" to
debian-devel-REQUEST@lists.debian.org . Trouble? e-mail to Bruce@Pixar.com


Reply to: