Re: [zones-discuss] Supported way to get setuid/setgid in inherit-pkg-dir filesystems?

2007-03-11 Thread Stephen Hahn
* Dan Price <[EMAIL PROTECTED]> [2007-03-11 14:23]:
> On Sun 11 Mar 2007 at 02:05PM, Stephen Hahn wrote:
> > 
> >I couldn't find this in the FAQ, and don't want to experiment with
> >mixing fs and inherit-pkg-dir directives.  Is there a way to get the
> >inherit-pkg-dir filesystems to preserve the setuid/setgid bits (so
> >that /usr/lib/sendmail is setgid to smmsp)?  The zone already exists,
> >so removing the inherit-pkg-dir would be... inconvenient.
> 
> I'm confused-- Since an inherit-pkg-dir is really just a read-only
> lofs mount, /usr/lib/sendmail should be setgid or setuid or whatever.
> 
> At least on my box, you can see that the mount allows setuid:
> 
> /pl/zones/tz2/root/usr on /usr read only/setuid/nodevices/nosub/dev=80
>  ^^
> 
> But I suspect you know that, and that I'm not understanding the
> question...?

  No, that's the answer I needed--thanks.  It looks as if the mail setup
  on my global zone has been modified substantially, which I hadn't
  assumed.

  - Stephen

-- 
Stephen Hahn, PhD  Solaris Kernel Development, Sun Microsystems
[EMAIL PROTECTED]  http://blogs.sun.com/sch/
___
zones-discuss mailing list
zones-discuss@opensolaris.org


Re: [zones-discuss] Supported way to get setuid/setgid in inherit-pkg-dir filesystems?

2007-03-11 Thread Dan Price
On Sun 11 Mar 2007 at 02:05PM, Stephen Hahn wrote:
> 
>I couldn't find this in the FAQ, and don't want to experiment with
>mixing fs and inherit-pkg-dir directives.  Is there a way to get the
>inherit-pkg-dir filesystems to preserve the setuid/setgid bits (so
>that /usr/lib/sendmail is setgid to smmsp)?  The zone already exists,
>so removing the inherit-pkg-dir would be... inconvenient.

I'm confused-- Since an inherit-pkg-dir is really just a read-only
lofs mount, /usr/lib/sendmail should be setgid or setuid or whatever.

At least on my box, you can see that the mount allows setuid:

/pl/zones/tz2/root/usr on /usr read only/setuid/nodevices/nosub/dev=80
 ^^

But I suspect you know that, and that I'm not understanding the
question...?

-dp

-- 
Daniel Price - Solaris Kernel Engineering - [EMAIL PROTECTED] - blogs.sun.com/dp
___
zones-discuss mailing list
zones-discuss@opensolaris.org