Gentoo Archives: gentoo-portage-dev

From: Ulrich Mueller <ulm@g.o>
To: gentoo-portage-dev@l.g.o
Subject: Re: [gentoo-portage-dev] [PATCH 1/2] bin/install-qa-check.d: add new 90bad-bin-owner QA check.
Date: Sun, 29 Jul 2018 19:43:52
Message-Id: 23390.6385.139637.655344@a1i15.kph.uni-mainz.de
In Reply to: [gentoo-portage-dev] [PATCH 1/2] bin/install-qa-check.d: add new 90bad-bin-owner QA check. by Michael Orlitzky
1 >>>>> On Sun, 29 Jul 2018, Michael Orlitzky wrote:
2
3 > System executables that are not owned by root pose a security
4 > risk. The owner of the executable is free to modify it at any time;
5 > so, for example, he can change a daemon's behavior to make it
6 > malicious before the next time the service is started (usually by
7 > root).
8
9 > On a "normal" system, there is no good reason why the superuser should
10 > not own every system executable. This commit adds a new install-time
11 > check that reports any such binaries with a QA warning. To avoid false
12 > positives, non-"normal" systems (like prefix) are skipped at the moment.
13
14 Shouldn't this check for setuid binaries like /usr/bin/mandb (which is
15 owned by man:man)? I think these are legitimate usage case.
16
17 Ulrich

Replies