From owner-freebsd-commit Wed Apr 12 02:22:39 1995 Return-Path: commit-owner Received: (from majordom@localhost) by freefall.cdrom.com (8.6.10/8.6.6) id CAA05358 for commit-outgoing; Wed, 12 Apr 1995 02:22:39 -0700 Received: (from majordom@localhost) by freefall.cdrom.com (8.6.10/8.6.6) id CAA05345 for cvs-libexec-outgoing; Wed, 12 Apr 1995 02:22:36 -0700 Received: from precipice.shockwave.com (precipice.shockwave.com [171.69.108.33]) by freefall.cdrom.com (8.6.10/8.6.6) with ESMTP id CAA05339 ; Wed, 12 Apr 1995 02:22:30 -0700 Received: from localhost (localhost [127.0.0.1]) by precipice.shockwave.com (8.6.11/8.6.9) with SMTP id CAA22741; Wed, 12 Apr 1995 02:21:42 -0700 Message-Id: <199504120921.CAA22741@precipice.shockwave.com> To: "Andrey A. Chernov, Black Mage" cc: CVS-commiters@freefall.cdrom.com, cvs-libexec@freefall.cdrom.com Subject: Re: cvs commit: src/libexec/atrun atrun.man Makefile atrun.c atrun.8 atrun.h In-reply-to: Your message of "Wed, 12 Apr 1995 12:50:05 +0400." Date: Wed, 12 Apr 1995 02:21:42 -0700 From: Paul Traina Sender: commit-owner@FreeBSD.org Precedence: bulk OK, thanks. From: "Andrey A. Chernov, Black Mage" Subject: Re: cvs commit: src/libexec/atrun atrun.man Makefile atrun.c atrun.8 atrun.h In message <199504120314.UAA02122@precipice.shockwave.com> Paul Traina writes: >Did you just upgrade to 2.7a? 2.7a does not actually fix the security hole, >at least according to my examination of the distribution source code. Yes, with my own more stronger checking (followed to author). Original 2.7a still have hole on FreeBSD because setreuid() don't change real uid. >Also, I was a little concerned to see pathnames.h et al go away. Has this >program suddently gotten much less bsd-like in nature? Less BSD-like, but more compatible with original version and its future releases, it makes upgrade process more easy. Really, Makefile.inc replace pathnames.h with defines for original version. -- Andrey A. Chernov : And I rest so composedly, /Now, in my bed, ache@astral.msk.su : That any beholder /Might fancy me dead - FidoNet: 2:5020/230.3 : Might start at beholding me, /Thinking me dead. RELCOM Team,FreeBSD Team : E.A.Poe From "For Annie" 1849