1 |
On Fri, 09 Dec 2005 18:29:22 +0100 |
2 |
"Spider (D.m.D. Lj.)" <spider@g.o> wrote: |
3 |
|
4 |
> On Fri, 2005-12-09 at 18:21 +0100, Jesús García Crespo wrote: |
5 |
> > Hi! I thought that GCC could means a risk if all of the users of my |
6 |
> > system are able to run it! I talked this with a friend and he |
7 |
> > propossed to create a new group, "compiler", for example, where all |
8 |
> > the users who will be able to run gcc must belong to it! |
9 |
> > |
10 |
> > Wouldn't be interesting to implement this into Gentoo gcc ebuild as |
11 |
> > an USE? |
12 |
> |
13 |
> |
14 |
> Exactly what risk is there from an end-user running a compiler? A |
15 |
> compiler doesn't access any kind of restricted environment, doesn't |
16 |
> auytomatically create binaries with other rights than its own and is |
17 |
> about as "safe" a product as there can be. |
18 |
|
19 |
I meant something like: |
20 |
for (;;) malloc(1000); |
21 |
|
22 |
> If you're really paranoid about execution and so on, start reading the |
23 |
> SELinux FAQ and create a ruleset.. The default one is probably more |
24 |
> lenient than you want it ;) |
25 |
|
26 |
Yes, I understand. I will read about it. |
27 |
|
28 |
Thanks a lot! |
29 |
|
30 |
|
31 |
-- |
32 |
Jesús García Crespo (aka Sevein) |
33 |
http://www.sevein.com |
34 |
correo@××××××.com |
35 |
|
36 |
GnuPG key ID: E2DB17E8 (pgp.escomposlinux.org) |