Gentoo Archives: gentoo-user

From: kwkhui@××××.net
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Re: Heads up if you start X with startx; xorg-server suid flag
Date: Mon, 31 Dec 2012 08:55:27
Message-Id: 20121231165347.063414d3@gentoo-main.kwkh-home
In Reply to: Re: [gentoo-user] Re: Heads up if you start X with startx; xorg-server suid flag by Alan McKinnon
1 On Mon, 31 Dec 2012 10:03:40 +0200
2 Alan McKinnon <alan.mckinnon@×××××.com> wrote:
3
4 > It's not in the profile, the xorg-server ebuild sets USE="suid" on by
5 > default.
6 >
7 > Most likely is that Walter has USE="-suid" in his make.conf and sets
8 > it back on for things he's checked out personally. Meaning that in
9 > this case one slipped through.
10
11 I suspect it is a USE="-* (blah)" rather than an explicit USE="-suid"
12 in the make.conf file.
13
14 One question though --- should the xorg-server ebuild be such that
15 IUSE="(blah) +suid" when using a hardened-profile? Also, checking
16 my PORTDIR, given the global description in use.desc (suid - Enable
17 setuid root program, with potential security risks), shouldn't the suid
18 use flag entries (net-analyzer/nagios-plugins:suid and
19 net-wireless/kismet:suid) be deleted from use.local.desc?
20
21 Kerwin.

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies