public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
From: "Robin H. Johnson" <robbat2@gentoo.org>
To: gentoo-dev@lists.gentoo.org
Subject: Re: [gentoo-dev] Abuse by gentoo developer
Date: Tue, 19 Jul 2005 19:43:34 -0700	[thread overview]
Message-ID: <20050720024334.GA26639@curie-int.orbis-terrarum.net> (raw)
In-Reply-To: <200507200132.30745.lists@seattleserver.com>

[-- Attachment #1: Type: text/plain, Size: 2505 bytes --]

I'm not going to address Jory's behaviour here, but I would like to
look at the actual development stuff, namely the SUID status of vchkpw,
as I took care of vpopmail before Jory came on board.

On Wed, Jul 20, 2005 at 01:32:30AM +0000, Casey Allen Shobe wrote:
> > I would strongly recommend doing chmod +s /var/vpopmail/bin/vchkpw 
> > in the ebuild, and then if the end user doesn't want it SUID, then 
> > that's what FEATURES=suidctl is for.
> 
> Umm, no it's not, and it's not useless info.  I reported the bug to 
> the gentoo-dev list some months ago, but should have probably used 
> bugs.gentoo.org instead.  In any case, it's certainly not installed 
> setuid by default:
> 
> # emerge -va vpopmail && ls -l /var/vpopmail/bin/vchkpw
> 
> These are the packages that I would merge, in order:
> 
> Calculating dependencies ...done!
> [ebuild   R   ] net-mail/vpopmail-5.4.6-r1  +clearpasswd -ipalias 
> -mysql -postgres 0 kB [1]
> [...]
> >>> net-mail/vpopmail-5.4.6-r1 merged.
> [...]
> -rwx--x--x  1 root root 85036 Jul 19 23:53 /var/vpopmail/bin/vchkpw*
> 
> So stop telling me my info is useless, when it's obviously not.
> > This is not how we can handle this the user should have already
> > read up on how to setup vpopmail before ever installing it, which
> > means they would already know that SUID is required.
> As SUID is required for qmail-smtpd, vchkpw should indeed be 
> installed SUID by default unless overridden by using suidctl.  This 
> is NOT the case now.

This problem IS fixed in ~arch:

line 190 of both vpopmail-5.4.10.ebuild and vpopmail-5.4.9-r2.ebuild:
	chmod 4711 ${D}${VPOP_HOME}/bin/vchkpw

So if this is still a problem in arch, but works in ~arch, you SHOULD
file a bug report.

However the original reasoning for vchkpw NOT being setuid was that
setuid is NOT always needed depending on which backend you are using.

And as I've mentioned before I'd like MORE reports of packages working
well before they are moved to stable arch. Without those stable working
reports I don't have any means to judge just how much testing has been
done on a package, other than my own use of a package (and as such I do
leave things longer than the 30 days, because I don't entirely trust
them).

-- 
Robin Hugh Johnson
E-Mail     : robbat2@orbis-terrarum.net
Home Page  : http://www.orbis-terrarum.net/?l=people.robbat2
ICQ#       : 30269588 or 41961639
GnuPG FP   : 11AC BA4F 4778 E3F6 E4ED  F38E B27B 944E 3488 4E85

[-- Attachment #2: Type: application/pgp-signature, Size: 241 bytes --]

  parent reply	other threads:[~2005-07-20  2:45 UTC|newest]

Thread overview: 21+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-07-20  1:32 [gentoo-dev] Abuse by gentoo developer Casey Allen Shobe
2005-07-20  1:41 ` Mauricio Lima PIlla
2005-07-20  1:42 ` Mike Frysinger
2005-07-20  2:21 ` Nathan L. Adams
2005-07-20  2:20   ` Mike Frysinger
2005-07-20  2:35     ` Allen Parker
2005-07-20  2:17       ` Daniel Goller
2005-07-20  5:43       ` Casey Allen Shobe
2005-07-20  2:43 ` Robin H. Johnson [this message]
2005-07-20  5:37   ` [gentoo-dev] VPopmail - SUID vchkpw Casey Allen Shobe
2005-07-20  5:43     ` [gentoo-dev] QA feedback Mike Frysinger
2005-07-20 13:47       ` Chris Gianelloni
2005-07-23  8:06         ` Stuart Longland
2005-07-20  7:04     ` [gentoo-dev] VPopmail - SUID vchkpw Robin H. Johnson
2005-07-20 10:13       ` [gentoo-dev] " Duncan
2005-07-21  0:28       ` [gentoo-dev] " Casey Allen Shobe
2005-07-21  2:59         ` Robin H. Johnson
2005-07-21  0:32       ` Mike Frysinger
2005-07-21  5:15         ` Casey Allen Shobe
2005-07-22  8:45           ` [gentoo-dev] " Duncan
2005-07-20  9:54 ` [gentoo-dev] Re: Abuse by gentoo developer Duncan

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20050720024334.GA26639@curie-int.orbis-terrarum.net \
    --to=robbat2@gentoo.org \
    --cc=gentoo-dev@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox