1 |
Hi, |
2 |
|
3 |
You may wish to specify the --user parameter. As this tool is for system |
4 |
daemons (therefore located in /sbin), it seems obvious it starts daemons |
5 |
as root by default. I checked on my system and I don't have a setuid bit |
6 |
on this program, no more it starts any program when my wheel user |
7 |
executes the command. I've no error code, but no process is spawned. |
8 |
|
9 |
If your non root user escalates privileges and is able to spawn a root |
10 |
process, *and* there is no setuid bit on /sbin/start-stop-daemon, you |
11 |
may fill a bug, if you have a procedure to reproduce it ;) Honestly, as |
12 |
it is a quite old debian tool, I don't think it's buggy ;) |
13 |
|
14 |
Sincerely, |
15 |
Jil |
16 |
|
17 |
Erik Hahn a écrit : |
18 |
> I'm using start-stop-daemon for making sure rc.wmii runs only once (If |
19 |
> you don't know wmii's way of handling configs: it doesn't matter). |
20 |
> Although I run it as user, it sets USER=root and HOME=/root. Is this |
21 |
> behaviour expected or should I file a bug? |
22 |
> |
23 |
> -Erik |