Gentoo Archives: gentoo-amd64

From: "Sebastian Beßler" <sebastian@××××××××××××.de>
To: gentoo-amd64@l.g.o
Subject: [gentoo-amd64] Secure chroot (was: Re: Wine with no-multilib on AMD64)
Date: Tue, 16 Mar 2010 13:04:55
Message-Id: 201003161327.47162.sebastian@darkmetatron.de
In Reply to: Re: [gentoo-amd64] Re: Wine with no-multilib on AMD64 by Alex Alexander
1 Am Dienstag, 16. März 2010 12:22:56 schrieb Alex Alexander:
2 > On Tue, Mar 16, 2010 at 10:23:06AM +0100, Sebastian Beßler wrote:
3 > > Am 16.03.2010 02:56, schrieb Duncan:
4 > > > I posted the link to the guide in the doomsday thread pretty much
5 > > > concurrently to the discussion here, but for convenience, here's the
6 > > > link:
7 > > >
8 > > > http://www.gentoo.org/proj/en/base/amd64/howtos/index.xml?part=1&chap=2
9 > >
10 > > What I don't like with this guide is that you have to be root to chroot
11 > > into and run the applications as root inside of the chroot.
12 >
13 > You don't need to be root in the chroot to run applications. Just create
14 > a user in the chroot and switch:
15 >
16 > su - youruser
17
18 That is not really a solution, because all it need to be root again is a
19 simple exit. And chroot-root can break out of the chroot without problem.
20
21 And you still need to be root to enter the chroot so you must always type in
22 your root password to start a simple app, even if you drop root inside the
23 chroot. So this is nothing more then a really fragile hack, to me at last.
24
25 Greetings
26
27 Sebastian

Replies