GNU bug report logs - #40922
gnu: udevil: Fix loading of setuid-programs.

Previous Next

Package: guix-patches;

Reported by: Raghav Gururajan <raghavgururajan <at> disroot.org>

Date: Tue, 28 Apr 2020 07:02:02 UTC

Severity: normal

Done: Danny Milosavljevic <dannym <at> scratchpost.org>

Bug is archived. No further changes may be made.

Full log


View this message in rfc822 format

From: Raghav Gururajan <raghavgururajan <at> disroot.org>
To: Danny Milosavljevic <dannym <at> scratchpost.org>
Cc: 40922 <at> debbugs.gnu.org
Subject: [bug#40922] gnu: udevil: Fix loading of setuid-programs.
Date: Fri, 1 May 2020 10:05:06 -0400
Hi Danny!

> Why are both needed at the same time?  If udevil is setuid root, then the
> other tools are invoked as root anyway, right?  Or does udevil drop root
> privileges?  (short look into src/udevil.c suggests yes)

Yes, both are needed at same time. I tried them alternatively, did not work.
As you mentioned, it drops previleges (file:src/udevil.c ; line:5061).

> Is there a description from upstream how all that is supposed to work?

There is some description in "Set SUID" section of README file
(https://github.com/IgnorantGuru/udevil/blob/master/README).

> Remainder OK.

Thanks!

Regards,
RG.




This bug report was last modified 5 years and 100 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.