Gentoo Archives: gentoo-dev

From: Wolfram Schlich <wschlich@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] net-mail/mailman-2.1.9-r2: Request for testing
Date: Tue, 27 Nov 2007 01:31:24
Message-Id: 20071127012704.GA16769@bla.fasel.org
In Reply to: Re: [gentoo-dev] net-mail/mailman-2.1.9-r2: Request for testing by Wolfram Schlich
1 * Wolfram Schlich <wschlich@g.o> [2007-11-27 02:24]:
2 > * Hanno Böck <hanno@g.o> [2007-11-26 15:39]:
3 > > [...]
4 > > So I'd like to unmask it soon. Please, if you're using mailman test it, tell
5 > > me if it suits your needs or just give me feedback like "worksforme", I
6 > > actually don't have a clue how many people really use this ebuild.
7 >
8 > I get this using hardened-sources with activated grsecurity
9 > trusted path execution feature:
10 >
11 > 2007-11-27 02:15:47 +01:00; alpha; kern.alert; kernel: grsec: From 127.0.0.6: \
12 > denied untrusted exec of /usr/lib/mailman/bin/mmsitepass by \
13 > /bin/bash[bash:14178] uid/euid:280/280 gid/egid:280/280, \
14 > parent /bin/bash[bash:14173] uid/euid:280/280 gid/egid:280/280
15 >
16 > That's because /usr/lib/mailman/bin/ is group-writable.
17
18 Ok, that's not true :]
19
20 Using this configuration...
21 --8<--
22 CONFIG_GRKERNSEC_TPE=y
23 # CONFIG_GRKERNSEC_TPE_ALL is not set
24 CONFIG_GRKERNSEC_TPE_INVERT=y
25 CONFIG_GRKERNSEC_TPE_GID=1005
26 --8<--
27 ...I have to add 'mailman' to group 1005.
28 --
29 Regards,
30 Wolfram Schlich <wschlich@g.o>
31 Gentoo Linux * http://dev.gentoo.org/~wschlich/
32 --
33 gentoo-dev@g.o mailing list

Replies

Subject Author
Re: [gentoo-dev] net-mail/mailman-2.1.9-r2: Request for testing Wolfram Schlich <wschlich@g.o>