From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from lists.gentoo.org (pigeon.gentoo.org [208.92.234.80]) by finch.gentoo.org (Postfix) with ESMTP id 4E3B31381F3 for ; Fri, 12 Apr 2013 20:03:46 +0000 (UTC) Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id A5443E092C; Fri, 12 Apr 2013 20:03:43 +0000 (UTC) Received: from smtp.gentoo.org (smtp.gentoo.org [140.211.166.183]) (using TLSv1 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by pigeon.gentoo.org (Postfix) with ESMTPS id B3A07E0920 for ; Fri, 12 Apr 2013 20:03:42 +0000 (UTC) Received: from vapier.localnet (localhost [127.0.0.1]) by smtp.gentoo.org (Postfix) with ESMTP id E11F633E090 for ; Fri, 12 Apr 2013 20:03:41 +0000 (UTC) From: Mike Frysinger Organization: wh0rd.org To: gentoo-dev@lists.gentoo.org Subject: Re: [gentoo-dev] Re: glibc: pt_chown setuid going away by default Date: Fri, 12 Apr 2013 16:05:12 -0400 User-Agent: KMail/1.13.7 (Linux/3.8.3; KDE/4.6.5; x86_64; ; ) References: <201304100115.53431.vapier@gentoo.org> <201304111249.01381.vapier@gentoo.org> In-Reply-To: Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-dev@lists.gentoo.org Reply-to: gentoo-dev@lists.gentoo.org MIME-Version: 1.0 Content-Type: multipart/signed; boundary="nextPart35035554.zXBx5a7b1Z"; protocol="application/pgp-signature"; micalg=pgp-sha1 Content-Transfer-Encoding: 7bit Message-Id: <201304121605.13008.vapier@gentoo.org> X-Archives-Salt: d09fb402-374e-420d-9791-7ab3dc921b93 X-Archives-Hash: a93a619b091b95cd8aec37d728fbf3cd --nextPart35035554.zXBx5a7b1Z Content-Type: Text/Plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable On Thursday 11 April 2013 22:19:40 Duncan wrote: > Mike Frysinger posted on Thu, 11 Apr 2013 12:49:00 -0400 as excerpted: > > On Thursday 11 April 2013 11:43:59 James Cloos wrote: > >> >>>>> "MF" =3D=3D Mike Frysinger writes: > >> MF> this should impact very few (if any) > >> MF> users, so i don't think a news item makes sense. > >>=20 > >> It will impact everyone who has /dev/pts in fstab(5). > >=20 > > don't do that. delete the line. >=20 > I wonder if I added my devpts fstab entry (if as you say it wasn't an > automated add) some time ago, when there was some security related hubbub > over it, as significantly, my fstab entry has nosuid, noexec, while the > default for it in /etc/init.d/devfs does not. >=20 > My fstab devpts entry also has noauto, but that's likely simply due to it > being an fstab entry... >=20 > Regardless, that's at least two gentooers with installations dating from > the early 00s that have reported having the (GID-less) entry in fstab > now, so I strongly suspect it's going to affect more users, at least long- > time users, than you thought. It may in fact affect the majority of > users from that era... anyone who hasn't manually removed that entry from > fstab over the years. >=20 > You mention it wasn't in the old baselayout/openrc tarballs. What about > the early stages? Perhaps that's where it came from? Anyone with 2004.x > vintage stage tarballs around to check? stages get their files from baselayout/openrc. they don't generate them=20 themselves. Robin found even older baselayout releases for me. baselayout-1.8.6.12=20 (released Nov 2011) and newer don't contain any mention of devpts. i don't know about 2004 releases, but i have stage tarballs i built in Oct= =20 2005 using gcc-2.95 and they're exactly what i expect -- they match the=20 baselayout install. =2Dmike --nextPart35035554.zXBx5a7b1Z Content-Type: application/pgp-signature; name=signature.asc Content-Description: This is a digitally signed message part. -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.17 (GNU/Linux) iQIcBAABAgAGBQJRaGj4AAoJEEFjO5/oN/WB/3sQANLghRVoBbwtdBu2z3269SVL E2z7yfVqQ+TnIFSVZ5ANqolGJ+GJntItea8P4RTYnz4UkgZ9YaNmefRW8u1IAwkJ qJBpT5J7eNtKI0jl/GtYToH+gKYbAkUnoJTheOWJvLTAcJ02jhnKcy82X0K4Ske+ o2nlYrkkvCQg56WFi0QofWQ78yKeox68b6g/O16fq9N+wPETIsjPMUZjbwmhKbkm OZrwQSOp2u6rnOzSobn/NYK/goxh3pzgCItG2F4e+9ByVAOoyZV29xeBYl07K2vu MbPa+AeZl1npGDRClG3NvzHCcn24Y+BimdbZk6UU/ItvDgA0ufkzxgQgiqevAULJ zVZ6E515N7h1pdpJQXMapZgAjqk1tN4Gpg3XxgsBnD4MmUyidjOJbkL/D1tRqWsW em/k2F/xrX41TDHgR2159YN0KVV16ApHT1hwA0HBxjAxMIPhTM/F0iNu6+w07ATB f8k/+sMYMspoofQm2XS2q5UAacK+McaWKFDatXCOBLZw+DJQ6MzOFiTJ4FYHZvs6 IQ6Rsja905wnA5WmKFZcFbRZFG4Ms8mgi2ViXkd90D4B6jAKR0Tx3rC8BNEdUY60 d9UJNeBb677OLUGxwDcOph3SEBgmlwLOFAmt6SHE2XssAgNXMKhZYVzPIjeFfpm1 YSH19HooyELm44pyfdaV =QVNq -----END PGP SIGNATURE----- --nextPart35035554.zXBx5a7b1Z--