[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Why is root write permission necessary for installed files?



-----BEGIN PGP SIGNED MESSAGE-----

Kevin Dalley, in an immanent manifestation of deity, wrote:
>Manoj Srivastava <srivasta@datasync.com> writes:
>> Policy:
>> 3.3.8. Permissions and owners
>> 
>>      Files should be owned by `root.root', and made writable only by the
>>      owner and universally readable (and executable, if appropriate).
>> 
>Actually, I asked why it is a policy, not where it is documented.  I
>haven't received on answer on the reason yet.

It's convenience for the admin.  If you're root, you can edit the files 
anyway, so the permissions should reflect this capability.  This is
similar to why suid-root is installed 4755 instead of the common 4711.

Darren
- -- 
<torin@daft.com> <http://www.daft.com/~torin> <torin@debian.org> <torin@io.com>
Darren Stalder/2608 Second Ave, @282/Seattle, WA 98121-1212/USA/+1-800-921-4996
@ Sysadmin, webweaver, postmaster for hire.  C/Perl/CGI programmer and tutor. @
@		     Make a little hot-tub in your soul.		      @

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3a
Charset: noconv
Comment: Processed by Mailcrypt 3.4, an Emacs/PGP interface

iQCVAwUBNQ5LFo4wrq++1Ls5AQECpAP+JkIhdeQ9xhcwXoLEKEYEhSk/I3a7q+Uh
qeKSXqagPB1NspAmYw/rdqpdzVw/8GuHLxU5fjOkb1zP9wS2+RzO3k4O5F/9PSDu
zr7aQEhG0GAIZWgizh39Ty+qk5Qlcnkm2WKpgqcS3OiarSmFeMhKgPyhWqrpzy25
sw0atiO0THk=
=7ai9
-----END PGP SIGNATURE-----


--
To UNSUBSCRIBE, email to debian-devel-request@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org


Reply to: