[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: horse carcas flogging (was: traceroute in /usr/bin, not /usr/sbin)



On Sun, Jun 17, 2001 at 03:22:58PM -0800, Ethan Benson wrote:
> i disagree with your statement that the maintainer has NO discretion,
> i think rusty's remarks make that clear:  `assuming traceroute is
> setuid' the maintainer decides whats setuid in his package.  debian
> has shipped many traditionally setuid binaries non-setuid for a long
> time (dump and restore for example).  

Yes, but in this case, it's impossible because traceroute needs to be suid.
It needs to set certain socket parameters that can only be set by root.

The only way around this is by using something like LIDS and giving
traceroute extra capabilities.

Personally, I wouldn't mind seeing us ship a traceroute that looks like this:

-rwsr-x---    1 root     adm        17500 May 23 01:50 /usr/sbin/traceroute

But that's just my two cents.

--Adam

-- 
Adam McKenna  <adam@debian.org>  <adam@flounder.net>



Reply to: