Gentoo Archives: gentoo-dev

From: Ciaran McCreesh <ciaran.mccreesh@××××××××××.com>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] [SECURITY] Minimizing the suid usage
Date: Sun, 23 Mar 2008 22:02:45
Message-Id: 20080323220230.68100477@googlemail.com
In Reply to: Re: [gentoo-dev] [SECURITY] Minimizing the suid usage by Alon Bar-Lev
1 On Sun, 23 Mar 2008 20:45:24 +0200
2 "Alon Bar-Lev" <alonbl@g.o> wrote:
3 > On 3/23/08, Ciaran McCreesh <ciaran.mccreesh@××××××××××.com> wrote:
4 > > > Why? A simple USE flag should be enough, if set use caps, if not
5 > > > use current.
6 > >
7 > >
8 > > A user turns the use flag on, the ebuild creates files using caps
9 > > rather than set*id, the package manager merges it by copying the
10 > > file and the installed file ends up with no caps and no set*id bit.
11 >
12 > File system attributes already supported for selinux. I also checked
13 > this with capabilities and it works with portage.
14
15 But they aren't upscaled.
16
17 --
18 Ciaran McCreesh

Attachments

File name MIME type
signature.asc application/pgp-signature