|
Bugzilla – Full Text Bug Listing |
| Summary: | aegis: permissions | ||
|---|---|---|---|
| Product: | [openSUSE] openSUSE 10.3 | Reporter: | Ludwig Nussel <lnussel> |
| Component: | Security | Assignee: | Susanne Oberhauser-Hirschoff <froh> |
| Status: | RESOLVED FIXED | QA Contact: | E-mail List <qa-bugs> |
| Severity: | Normal | ||
| Priority: | P5 - None | CC: | security-team |
| Version: | Beta 1 | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| Whiteboard: | |||
| Found By: | Other | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
|
Description
Ludwig Nussel
2005-02-23 13:33:11 UTC
pardon, setuid aegis, not root. Nevertheless the question remains. Yes this is not obvious. However there is an Appendix D in the user guide
describing why, and how the setuid is isolated to make the code
audit-friendly. The basic reason is that eagis is something like clearcase or
cvs with process support, and that it protects the shared repository with unix
file permissions. for details, please see:
/usr/share/doc/packages/aegis/en/user-guide.{ps,txt,dvi}
btw, the currently checked-in version got an audit. I plan on an update for
code10.
does this answer your question?
Fine, thanks. Moving the permissions file with the next update is fine. So, this can be closed, right? the permissions.d file is not migrated yet, so keep open until fixed. no changes to aegis package for two years. setting package to frozen to prevent shipment in future distros. closing |