[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

utmp group proposal



Now that we have working Unix98 ptys for all systems (except m68k,
which doesn't want to move to glibc2.1 for some reason?) we no longer
need to make a process setuid root just to create a new pty. This
includes programs like xterm.

There is a slight problem though: utmp. Currently only root can update
the utmp. To solve this I propose we create an utmp group and put in
policy that programs that want to modify the utmp should be setgid utmp
instead of setuid root (unless root is needed for other purposes of
course).

Wichert.

-- 
==============================================================================
This combination of bytes forms a message written to you by Wichert Akkerman.
E-Mail: wichert@cs.leidenuniv.nl
WWW: http://www.wi.leidenuniv.nl/~wichert/

Attachment: pgplc9sVQvxCn.pgp
Description: PGP signature


Reply to: