Gentoo Archives: gentoo-user

From: Jeremi Piotrowski <jeremi.piotrowski@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] setuid/setgid binaries, man-db security fix
Date: Tue, 13 Dec 2016 07:52:03
Message-Id: 20161213072026.GA29206@gentoo-tp.home
In Reply to: [gentoo-user] setuid/setgid binaries, man-db security fix by Ian Zimmerman
1 On Mon, Dec 12, 2016 at 02:46:31PM -0800, Ian Zimmerman wrote:
2 > More generally, I'm wondering about set*id binaries in gentoo. If I
3 > don't want/need the particular feature thus provided, can I simply turn
4 > off the set*id bit?
5
6 Most of the time packages will not work correctly (as defined by upstream)
7 and will require you to run them as root explicitly (e.g. through sudo).
8
9 But maybe the right solution for you is to mount your root partition
10 nosuid. You could see how that works out first before doing anything more
11 permanent - or maybe that will be enough.

Replies

Subject Author
[gentoo-user] Re: setuid/setgid binaries, man-db security fix Ian Zimmerman <itz@×××××××.net>