From owner-cvs-all Wed Oct 17 9:49:34 2001 Delivered-To: cvs-all@freebsd.org Received: from nothing-going-on.demon.co.uk (pc-62-31-42-140-hy.blueyonder.co.uk [62.31.42.140]) by hub.freebsd.org (Postfix) with ESMTP id 3799E37B407; Wed, 17 Oct 2001 09:49:24 -0700 (PDT) Received: (from nik@localhost) by nothing-going-on.demon.co.uk (8.11.3/8.11.3) id f9HGJ1b82818; Wed, 17 Oct 2001 17:19:01 +0100 (BST) (envelope-from nik) Date: Wed, 17 Oct 2001 17:19:01 +0100 From: Nik Clayton To: Robert Watson Cc: "Andrey A. Chernov" , cvs-committers@FreeBSD.org, cvs-all@FreeBSD.org Subject: Re: cvs commit: src/etc group master.passwd Message-ID: <20011017171901.C88453@clan.nothing-going-on.org> References: <200110171321.f9HDLrP93078@freefall.freebsd.org> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-md5; protocol="application/pgp-signature"; boundary="GYkYyJI7bObpCn+O" Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: ; from rwatson@FreeBSD.org on Wed, Oct 17, 2001 at 10:11:34AM -0400 Organization: FreeBSD Project Sender: owner-cvs-all@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG --GYkYyJI7bObpCn+O Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Wed, Oct 17, 2001 at 10:11:34AM -0400, Robert Watson wrote: > This is good to see -- the whole nobody:nobody thing has worried me for a > while, as it's used by a number of daemons to create a shared sandbox, and > a failure of one daemon can lead to the failure of all others, as well as > potential privilege escalation due to poor sandboxing techniques by any of > those daemons. Can we get all this documented somewhere? Is there a canonical list of what user names various ports expect and/or create? If not, we should have one (probably in the main Handbook, with a pointer to it in the Porter's Handbook). N --=20 FreeBSD: The Power to Serve http://www.freebsd.org/ FreeBSD Documentation Project http://www.freebsd.org/docproj/ --- 15B8 3FFC DDB4 34B0 AA5F 94B7 93A8 0764 2C37 E375 --- --GYkYyJI7bObpCn+O Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (FreeBSD) Comment: For info see http://www.gnupg.org iEYEARECAAYFAjvNr3UACgkQk6gHZCw343WnpgCfel6PN2UNSEGnkKeTq/BrjoPU poEAnR6+bDD0To1aBSl75o45BcR8lDwu =Ior3 -----END PGP SIGNATURE----- --GYkYyJI7bObpCn+O-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe cvs-all" in the body of the message