1 |
* Wolfram Schlich <wschlich@g.o> [2007-11-27 02:24]: |
2 |
> * Hanno Böck <hanno@g.o> [2007-11-26 15:39]: |
3 |
> > [...] |
4 |
> > So I'd like to unmask it soon. Please, if you're using mailman test it, tell |
5 |
> > me if it suits your needs or just give me feedback like "worksforme", I |
6 |
> > actually don't have a clue how many people really use this ebuild. |
7 |
> |
8 |
> I get this using hardened-sources with activated grsecurity |
9 |
> trusted path execution feature: |
10 |
> |
11 |
> 2007-11-27 02:15:47 +01:00; alpha; kern.alert; kernel: grsec: From 127.0.0.6: \ |
12 |
> denied untrusted exec of /usr/lib/mailman/bin/mmsitepass by \ |
13 |
> /bin/bash[bash:14178] uid/euid:280/280 gid/egid:280/280, \ |
14 |
> parent /bin/bash[bash:14173] uid/euid:280/280 gid/egid:280/280 |
15 |
> |
16 |
> That's because /usr/lib/mailman/bin/ is group-writable. |
17 |
|
18 |
Ok, that's not true :] |
19 |
|
20 |
Using this configuration... |
21 |
--8<-- |
22 |
CONFIG_GRKERNSEC_TPE=y |
23 |
# CONFIG_GRKERNSEC_TPE_ALL is not set |
24 |
CONFIG_GRKERNSEC_TPE_INVERT=y |
25 |
CONFIG_GRKERNSEC_TPE_GID=1005 |
26 |
--8<-- |
27 |
...I have to add 'mailman' to group 1005. |
28 |
-- |
29 |
Regards, |
30 |
Wolfram Schlich <wschlich@g.o> |
31 |
Gentoo Linux * http://dev.gentoo.org/~wschlich/ |
32 |
-- |
33 |
gentoo-dev@g.o mailing list |