Re: Unix Hackers please review: OpenPKG SetUID patch

2006-08-23 Thread Ralf S. Engelschall
On Wed, Aug 23, 2006, Thomas Lotterer wrote: > [...] > My ideas and lab resources are exhausted > [...] Hey, I've finally achieved it: "Mr. Testing" no longer finds a problem as he has no more possibilities to find a new problem. Woohooo, I really have to quote this in my cookie database in case

Re: Unix Hackers please review: OpenPKG SetUID patch

2006-08-22 Thread Thomas Lotterer
>>> On Saturday, 19. August 2006 at 10:56 am, Ralf S. Engelschall<[EMAIL >>> PROTECTED]> wrote: > One last word: the stuff is controlled by a > /etc/openpkg/managers file. Usually this shouldn't be changed. > But with great care one _can_ add a regular user to this configuration > file and this w

Re: Unix Hackers please review: OpenPKG SetUID patch

2006-08-19 Thread Ralf S. Engelschall
On Sat, Aug 19, 2006, Ralf S. Engelschall wrote: > Unix Hackers in our OpenPKG community, please review the following > security-sensitive patch to the OpenPKG bootstrap package. > [...] After the first feedbacks arrived I've further improved the patch. The latest version is appended. Please revi

Unix Hackers please review: OpenPKG SetUID patch

2006-08-19 Thread Ralf S. Engelschall
Unix Hackers in our OpenPKG community, please review the following security-sensitive patch to the OpenPKG bootstrap package. It wraps the /bin/openpkg command with a small SetUID program which executes the command under a particular user according to the following table: