Re: [gentoo-dev] Abusing RESTRICT={no,}userpriv (was [RFC] ACCEPT_RESTRICT for questionable values of RESTRICT)

2007-01-16 Thread Paul de Vrieze
On Friday 12 January 2007 22:35, Chris Gianelloni wrote: It has nothing to do with the sandbox. It's because /usr/games/lib isn't readable to people outside the games group. Isn't that a rather silly restriction. What is there in /usr/games/lib that may not be seen by people outside the

Re: [gentoo-dev] Abusing RESTRICT={no,}userpriv (was [RFC] ACCEPT_RESTRICT for questionable values of RESTRICT)

2007-01-16 Thread Paul de Vrieze
On Sunday 14 January 2007 18:46, Chris Gianelloni wrote: On Fri, 2007-01-12 at 22:46 +, Stephen Bennett wrote: On Fri, 12 Jan 2007 19:36:06 + Tristan Heaven [EMAIL PROTECTED] wrote: On Sat, 2007-01-13 at 00:53 +0900, Georgi Georgiev wrote: They have to be able to read

Re: [gentoo-dev] Abusing RESTRICT={no,}userpriv (was [RFC] ACCEPT_RESTRICT for questionable values of RESTRICT)

2007-01-14 Thread Chris Gianelloni
On Fri, 2007-01-12 at 22:46 +, Stephen Bennett wrote: On Fri, 12 Jan 2007 19:36:06 + Tristan Heaven [EMAIL PROTECTED] wrote: On Sat, 2007-01-13 at 00:53 +0900, Georgi Georgiev wrote: They have to be able to read /usr/games/lib. In which case adding the portage user to the games

[gentoo-dev] Abusing RESTRICT={no,}userpriv (was [RFC] ACCEPT_RESTRICT for questionable values of RESTRICT)

2007-01-12 Thread Georgi Georgiev
Ciaran pointed out that there are a small number of occasions where it [the userpriv FEATURE] really does need to be disabled. I consequently decided to see what these legitimate reasons are but it appears that RESTRICT=userpriv is not needed in a lot of cases. Here is a list of all packages that

Re: [gentoo-dev] Abusing RESTRICT={no,}userpriv (was [RFC] ACCEPT_RESTRICT for questionable values of RESTRICT)

2007-01-12 Thread Brian Harring
On Sat, Jan 13, 2007 at 12:53:35AM +0900, Georgi Georgiev wrote: RESTRICT=userpriv or RESTRICT=nouserpriv (no idea why there are both). no.* is the old form for restricts; the 'no' chunk of it when seen, should be removed. ~harring pgpieaR6Z50In.pgp Description: PGP signature

Re: [gentoo-dev] Abusing RESTRICT={no,}userpriv (was [RFC] ACCEPT_RESTRICT for questionable values of RESTRICT)

2007-01-12 Thread Chris Gianelloni
On Sat, 2007-01-13 at 00:53 +0900, Georgi Georgiev wrote: # no idea about the following three, input appreciated app-admin/gps media-gfx/maya This one doesn't need RESTRICT=userpriv (at least my 8.0 ebuild in my overlay doesn't) from my testing. # These are games... no idea why, input

Re: [gentoo-dev] Abusing RESTRICT={no,}userpriv (was [RFC] ACCEPT_RESTRICT for questionable values of RESTRICT)

2007-01-12 Thread Tristan Heaven
On Sat, 2007-01-13 at 00:53 +0900, Georgi Georgiev wrote: # These are games... no idea why, input appreciated games-board/ggz-txt-client games-board/ggz-sdl-games games-board/ggz-gtk-games games-board/ggz-kde-games games-board/gnuchess-book games-board/ggz-kde-client

Re: [gentoo-dev] Abusing RESTRICT={no,}userpriv (was [RFC] ACCEPT_RESTRICT for questionable values of RESTRICT)

2007-01-12 Thread Drake Wyrm
Tristan Heaven [EMAIL PROTECTED] wrote: On Sat, 2007-01-13 at 00:53 +0900, Georgi Georgiev wrote: # These are games... no idea why, input appreciated games-board/ggz-txt-client games-board/ggz-sdl-games games-board/ggz-gtk-games games-board/ggz-kde-games games-board/gnuchess-book

Re: [gentoo-dev] Abusing RESTRICT={no,}userpriv (was [RFC] ACCEPT_RESTRICT for questionable values of RESTRICT)

2007-01-12 Thread Stephen Bennett
On Fri, 12 Jan 2007 19:36:06 + Tristan Heaven [EMAIL PROTECTED] wrote: On Sat, 2007-01-13 at 00:53 +0900, Georgi Georgiev wrote: They have to be able to read /usr/games/lib. In which case adding the portage user to the games group seems overall to be a better solution than requiring root

Re: [gentoo-dev] Abusing RESTRICT={no,}userpriv (was [RFC] ACCEPT_RESTRICT for questionable values of RESTRICT)

2007-01-12 Thread Robin H. Johnson
On Fri, Jan 12, 2007 at 10:46:36PM +, Stephen Bennett wrote: On Sat, 2007-01-13 at 00:53 +0900, Georgi Georgiev wrote: They have to be able to read /usr/games/lib. In which case adding the portage user to the games group seems overall to be a better solution than requiring root

Re: [gentoo-dev] Abusing RESTRICT={no,}userpriv (was [RFC] ACCEPT_RESTRICT for questionable values of RESTRICT)

2007-01-12 Thread Stephen Bennett
On Fri, 12 Jan 2007 15:08:15 -0800 Robin H. Johnson [EMAIL PROTECTED] wrote: Putting the portage user into the special group would mean that somebody could steal the MySQL password - so do you RESTRICT=userpriv, or fail the build? If someone can subvert Portage's build process they can root

Re: [gentoo-dev] Abusing RESTRICT={no,}userpriv (was [RFC] ACCEPT_RESTRICT for questionable values of RESTRICT)

2007-01-12 Thread Georgi Georgiev
maillog: 12/01/2007-15:08:15(-0800): Robin H. Johnson types The vpopmail stuff has/has a similar issue (upstream is working on solving it via a different avenue at which point the problem will go away). But I tried emerge vpopmail on a clean system... the /var/vpopmail/lib and include