From owner-cvs-all@FreeBSD.ORG Mon Mar 12 16:54:12 2007 Return-Path: X-Original-To: cvs-all@FreeBSD.org Delivered-To: cvs-all@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 6CD8216A402; Mon, 12 Mar 2007 16:54:12 +0000 (UTC) (envelope-from trhodes@FreeBSD.org) Received: from chipmunk.ai.net (axe.ai.net [205.134.161.26]) by mx1.freebsd.org (Postfix) with ESMTP id 3271113C455; Mon, 12 Mar 2007 16:54:11 +0000 (UTC) (envelope-from trhodes@FreeBSD.org) Received: from localhost (ip70-177-190-239.dc.dc.cox.net [70.177.190.239]) by chipmunk.ai.net (8.13.4/8.13.4) with SMTP id l2CGsDv9014178; Mon, 12 Mar 2007 11:54:14 -0500 (EST) (envelope-from trhodes@FreeBSD.org) Date: Mon, 12 Mar 2007 11:53:59 -0500 From: Tom Rhodes To: Pawel Jakub Dawidek Message-Id: <20070312115359.4c0ae0bf.trhodes@FreeBSD.org> In-Reply-To: <20070310024946.GC1246@garage.freebsd.pl> References: <200703090933.l299XJAP094201@repoman.freebsd.org> <20070310024946.GC1246@garage.freebsd.pl> Organization: The FreeBSD Project X-Mailer: Sylpheed version 1.0.6 (GTK+ 1.2.10; i386-portbld-freebsd7.0) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Cc: cvs-src@FreeBSD.org, src-committers@FreeBSD.org, cvs-all@FreeBSD.org Subject: Re: cvs commit: src/usr.sbin/daemon daemon.8 daemon.c X-BeenThere: cvs-all@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: CVS commit messages for the entire tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 12 Mar 2007 16:54:12 -0000 On Sat, 10 Mar 2007 03:49:46 +0100 Pawel Jakub Dawidek wrote: > On Fri, Mar 09, 2007 at 09:33:19AM +0000, Tom Rhodes wrote: > > trhodes 2007-03-09 09:33:19 UTC > > > > FreeBSD src repository > > > > Modified files: > > usr.sbin/daemon daemon.8 daemon.c > > Log: > > Add support for dropping privileges to a specified user and/or group. > > > > PR: 108523 > > Submitted by: Dmitri Alenitchev (original version) > > Reviewed by: mpp (first reply to PR) > [...] > > + if (user || group) { > > + if (getuid() != 0) > > + errx(1, "only root user is allowed to chroot " > > + "and change UID/GID"); > > + restrict_process(user, group); > > + } > > chroot? Typo, of course. And I'm sorry for the lateness in my reply here, and figured you should get a follow up. I've implemented the changes Robert has requested and sent him a patch for review. He's busy, but promised me he would look over it soon. Thanks, -- Tom Rhodes