From owner-freebsd-security@FreeBSD.ORG Sun Mar 15 23:50:18 2009 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 012D51065670 for ; Sun, 15 Mar 2009 23:50:18 +0000 (UTC) (envelope-from freebsd001@pc.jgr.de) Received: from pc.jgr.de (pc.jgr.de [194.233.111.194]) by mx1.freebsd.org (Postfix) with ESMTP id 60A1C8FC14 for ; Sun, 15 Mar 2009 23:50:16 +0000 (UTC) (envelope-from freebsd001@pc.jgr.de) Received: from pc.jgr.de (localhost [127.0.0.1]) by pc.jgr.de (8.13.6/8.13.6) with ESMTP id n2FNoHJ9006602 for ; Mon, 16 Mar 2009 00:50:17 +0100 (CET) (envelope-from freebsd001@pc.jgr.de) Received: (from root@localhost) by pc.jgr.de (8.13.6/8.13.6/Submit) id n2FNoGnk006601 for freebsd-security@freebsd.org; Mon, 16 Mar 2009 00:50:16 +0100 (CET) (envelope-from freebsd001@pc.jgr.de) Date: Mon, 16 Mar 2009 00:50:16 +0100 (CET) From: freebsd001@pc.jgr.de Message-Id: <200903152350.n2FNoGnk006601@pc.jgr.de> To: Subject: Re: emacs installs a lot of 777 directories X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 15 Mar 2009 23:50:18 -0000 March 16, 2009 Dear Giorgos, thank you for coming back to the emacs issue. I deinstalled emacs by means of pkg_delete -v -d, deleted by hand /usr/local/share/emacs to make sure that nothing is left, logged in as user "nutzer", and did su to root: > id uid=1006(nutzer) gid=1000(user) groups=1000(user),0(wheel) > su Password: >id uid=0(root) gid=0(wheel) groups=0(wheel),5(operator) > Then, I did cd to /usr/ports/editors/emacs and did make and make install. The result is as follows: >pwd /usr/local/share/emacs/22.3 >ll total 22 drwxrwxrwx 5 nutzer wheel 3072 Mar 15 23:52 etc drwxr-xr-x 4 nutzer wheel 512 Mar 15 23:53 leim drwxrwxrwx 20 nutzer wheel 13312 Mar 15 23:53 lisp drwxr-xr-x 2 root wheel 512 Mar 15 23:52 site-lisp > There are some rwx directories as originally mentioned in the thread, and several directories as well as the files in these directories are not owned by root, but by nutzer. If I log in as another user in the group wheel, do su, and repeat the procedure, the files are owned by the other user I log in. As I have only limited console access or find the console access inconvenient, I have installed many ports by logging in as a user in the group wheel and doing su to root. But only emacs related files are owned by somebody else than expected. With best regards Joachim Griesche freebsd001@pc.jgr.de