Gentoo Archives: gentoo-amd64

From: Duncan <1i5t5.duncan@×××.net>
To: gentoo-amd64@l.g.o
Subject: [gentoo-amd64] Re: Secure chroot (was: Re: Wine with no-multilib on AMD64)
Date: Wed, 17 Mar 2010 00:04:53
Message-Id: pan.2010.03.16.23.38.49@cox.net
In Reply to: Re: [gentoo-amd64] Re: Secure chroot (was: Re: Wine with no-multilib on AMD64) by "Sebastian Beßler"
1 Sebastian Beßler posted on Tue, 16 Mar 2010 17:24:55 +0100 as excerpted:
2
3 > Your way looks quite nice, I will look into it when I am back home. Btw.
4 > the ubuntu manpage of chroot (at work I use ubuntu) does not mention
5 > --userspec (or maybe I am still to dumb to use man ;-)
6
7 It's possible the --userspec option is relatively new to chroot, tho I'd
8 not expect so. FWIW I'm using ~amd64, so have never versions of a lot of
9 packages than stable will.
10
11 It's also possible that ubuntu is using an old (or possibly POSIX-only)
12 manpage. What does chroot --help list? Here, --userspec is the first
13 option listed (the other one besides help and version being --groups,
14 which takes a list of supplementary groups that the user will appear in,
15 while in the chroot).
16
17 One thing that's unclear to me is whether the userspec and groups
18 parameters use the IDs from the running system or the chroot, tho I
19 suspect it's the running system (I started with the same passwd, etc files
20 in both, here, because as I said I need a full config for my usage and
21 that was most convenient).
22
23 I did notice that I had to use the actual UID:GID numbers, altho the
24 manpage said names should work too. I figured that was due to some
25 vagaries of configuration, but finding and using the numbers was no big
26 deal, so I didn't worry about it.
27
28 --
29 Duncan - List replies preferred. No HTML msgs.
30 "Every nonfree program has a lord, a master --
31 and if you use the program, he is your master." Richard Stallman

Replies