Gentoo Archives: gentoo-user

From: Dale <rdalek1967@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Re: Heads up if you start X with startx; xorg-server suid flag
Date: Mon, 31 Dec 2012 12:39:48
Message-Id: 50E1872F.7030200@gmail.com
In Reply to: Re: [gentoo-user] Re: Heads up if you start X with startx; xorg-server suid flag by kwkhui@hkbn.net
1 kwkhui@××××.net wrote:
2 > On Mon, 31 Dec 2012 10:03:40 +0200
3 > Alan McKinnon <alan.mckinnon@×××××.com> wrote:
4 >
5 >> It's not in the profile, the xorg-server ebuild sets USE="suid" on by
6 >> default.
7 >>
8 >> Most likely is that Walter has USE="-suid" in his make.conf and sets
9 >> it back on for things he's checked out personally. Meaning that in
10 >> this case one slipped through.
11 >
12 > I suspect it is a USE="-* (blah)" rather than an explicit USE="-suid"
13 > in the make.conf file.
14 >
15 > One question though --- should the xorg-server ebuild be such that
16 > IUSE="(blah) +suid" when using a hardened-profile? Also, checking
17 > my PORTDIR, given the global description in use.desc (suid - Enable
18 > setuid root program, with potential security risks), shouldn't the suid
19 > use flag entries (net-analyzer/nagios-plugins:suid and
20 > net-wireless/kismet:suid) be deleted from use.local.desc?
21 >
22 > Kerwin.
23
24
25 I think you are right. I seem to recall that Walter is one of few that
26 does USE="-* blah" in make.conf. Seems he may have asked for this one.
27
28 Dale
29
30 :-) :-)
31
32 --
33 I am only responsible for what I said ... Not for what you understood or
34 how you interpreted my words!