OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Demo patch - run telnetd as non-root and chroot()'ed
From: Peter Todd (retep2home.com)
Date: Sun Jul 23 2000 - 08:57:22 CDT


On Sun, 23 Jul 2000, you wrote:
> Second, GPL => autoconf => compile-time feature selection. We would need to
> ensure that EVERY combination of compile-time options produced a system as
> secure as the standard version. Doable; the danger is we won't do that.

If you don't have the time to test every little combination of
compile-time options with autoconf one possibility would be to use
autoconf as a tool designed to check *if* a system supports your
program. So have autoconf do all the tests but then instead of using
those compile time #defines to change how code is compiled simply set
things up so that unless you have a specific configuration
./configure will die.

Some of my programs do that, though because of lazyness instead of
security. :)

-- 
reteppenguinpowered.com http://retep.tripod.com