OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: pretendroot

From: Nikolay Sturm (sturmsec.informatik.tu-darmstadt.de)
Date: Fri Jan 02 2004 - 01:32:40 CST


* Han Boetes [2004-01-02]:
> For users yes. For packagers no. Some packages install in / instead of
> in the fakedir. And that's what this library prevents because you
> don't get real root-permissions.

For the record, this is only true for people creating a new port of
misbehaving software.

> To prevent this using systrace has been used but IMHO that was not
> such a great success.

Huh? All my local builds are systrace'd, except for those <10 ports
that have problems. Whenever I test new ports, they are systrace'd and
several bugs where and are found this way. Your point being?

> Perhaps it is possible to solve this problem in another way, for
> examples a packager-fake-install target which ignores the chmod calls,
> so you can at least make sure the fake target installs in the right
> location.

How is this supposed to work if all that fake does, is call "make
install" in WRKSRC? What would it change?
 
Nikolay

--
OpenPGP: 0x2036A3A7 - 64E4 7D77 F5C0 EA47 A901 51EF 6E54 6E4F 2036 A3A7
"The XFS you see in the kernel is not SGI-XFS but the X Font Server."
some user on miscopenbsd.org