Gentoo Logo
Gentoo Spaceship

Installation:
Gentoo Handbook
Installation Docs

Documentation:
Home
Listing
About Gentoo
Philosophy
Social Contract

Resources:
Bug Tracker
Developer List
Discussion Forums
Gentoo BitTorrents
Gentoo Linux Enhancement Proposals
IRC Channels
Mailing Lists
Mirrors
Name and Logo Guidelines
Online Package Database
Security Announcements
Staffing Needs
Supporting Vendors
View our CVS

Graphics:
Logos and themes
Icons
ScreenShots

Miscellaneous Resources:
Gentoo Linux Store
Gentoo-hosted projects
IBM dW/Intel article archive




List Archive: gentoo-dev
Navigation:
Lists: gentoo-dev: < Prev By Thread Next > < Prev By Date Next >
Headers:
To: gentoo-dev@g.o
From: Robert Buchholz <rbu@g.o>
Subject: EAPI change: Call ebuild functions from trusted working directory
Date: Thu, 9 Oct 2008 21:03:29 +0200
Hello,

currently, PMS section 10.1 states:

  Some functions may assume that their initial working directory is
  set to a particular location; these are noted below.
  If no initial working directory is mandated, it may be set to
  anything and the ebuild must not rely upon a particular location
  for it.

Please consider the following addition to this paragraph:

  The ebuild can rely that the chosen initial working direcotry is
  a trusted location that is not world-writable and owned by
  a privileged user and group.

This change affects all pkg_ functions.

Rationale:
This feature presents a security hardening to work around 
vulnerabilities in ebuilds and applications called by ebuilds, and the 
Gentoo Security Team considers this the official solution to
bug 239560 / GLSA 200810-02.

I would like:
 * everyone to comment on the change and propose changes to the wording
 * council to vote on this change to EAPI-0, -1 and -2.

Portage implements this in 2.1.4.5 and 2.2_rc12, Paludis in 0.30.2.
I have not heard back from Brian on pkgcore (because this issue has been 
disclosed to him on a really short notice).

Thanks,
Robert
Attachment:
signature.asc (This is a digitally signed message part.)
Replies:
Re: EAPI change: Call ebuild functions from trusted working directory
-- Donnie Berkholz
Navigation:
Lists: gentoo-dev: < Prev By Thread Next > < Prev By Date Next >
Previous by thread:
EAPI 2 is brokened :(
Next by thread:
Re: EAPI change: Call ebuild functions from trusted working directory
Previous by date:
Re: Monthly Gentoo Council Reminder for October
Next by date:
Re: Monthly Gentoo Council Reminder for October


Updated Jun 17, 2009

Donate to support our development efforts.

Gentoo Centric Hosting: vr.org

VR Hosted

Tek Alchemy

Tek Alchemy

SevenL.net

SevenL.net

php|architect

php|architect

Copyright 2001-2007 Gentoo Foundation, Inc. Questions, Comments? Email www@gentoo.org.