[fink:feature-requests] #12 Should not run as root

Hanspeter Niederstrasser via Fink-tracker <[email protected]> Sat, 08 Feb 2020 23:48:33 -0000
Newsgroups gmane.os.apple.fink.tracker
Message-ID </p/fink/feature-requests/12/4203bc7f877c963b0a602ef35d8fd92cbcad46ea.feature-requests@fink.p.sourceforge.net>
This is a multi-part message in MIME format.
--===============1631116553428819161==
Content-Type: multipart/related;
 boundary="===============4022260109480114130=="

This is a multi-part message in MIME format.
--===============4022260109480114130==
Content-Type: multipart/alternative;
 boundary="===============0079105764912528545=="
MIME-Version: 1.0

--===============0079105764912528545==
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit

- **status**: open --> closed-out-of-date
- **Group**:  --> 
- **Comment**:

Fink has long defaulted to using the 'fink-bld' user to build things unless explicitly required by a package.



---

** [feature-requests:#12] Should not run as root**

**Status:** closed-out-of-date
**Group:** 
**Created:** Tue Aug 28, 2001 11:10 PM UTC by Travis
**Last Updated:** Sat Sep 29, 2001 10:47 AM UTC
**Owner:** nobody


Hi folks,

I'm very leary that Fink needs to be run as root
\(euid=0 in any case\).

Previous to discovering fink, I've used a very similar
approach to your /sw approach to install a number of
open source programs from source.

My method has been to do this initially:

mkdir /x
sudo chown admin.wheel /x
sudo chmod 775 /x

Then, as an admin user \(member of wheel\), I can do this
as I build and install each package:
mkdir /x/xemacs-21.4.1
configure --prefix=/x/xemacs-21.4.1
and then 
make
make install

Yes, the admin user has more power than a normal user,
but not enough to install a root kit or mess with /etc
configuration files without my knowledge I hope. :-\)

We need not use an admin user actually.  I could make a
'fink' user who owns /sw \(chown fink.nobody\) and all
files within.  Then fink could only disturb the fink
install.  That sounds like a good solution to me for
minimizing risk.  

Running fink as root is just a huge security risk.  I
hope you will agree and find a way so that beyond a
setup of /sw, we can run fink without root.

Otherwise, fink looks very worthwhile and if this can
be resolved, I look forward to using it.

\(btw, I didn't see this issue discussed on the
fink-users mailing list in my browsing.  The search
feature does not work.  I searched for 'dpkg' -- the
subject of many recent messages -- and got no hits\)



---

Sent from sourceforge.net because [email protected] is subscribed to https://sourceforge.net/p/fink/feature-requests/

To unsubscribe from further messages, a project admin can change settings at https://sourceforge.net/p/fink/admin/feature-requests/options.  Or, if this is a mailing list, you can unsubscribe from the mailing list.
--===============0079105764912528545==
MIME-Version: 1.0
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: 7bit

<div class="markdown_content"><ul>
<li><strong>status</strong>: open --&gt; closed-out-of-date</li>
<li><strong>Group</strong>:  --&gt; </li>
<li><strong>Comment</strong>:</li>
</ul>
<p>Fink has long defaulted to using the 'fink-bld' user to build things unless explicitly required by a package.</p>
<hr/>
<p><strong> <a class="alink strikethrough" href="https://sourceforge.net/p/fink/feature-requests/12/">[feature-requests:#12]</a> Should not run as root</strong></p>
<p><strong>Status:</strong> closed-out-of-date<br/>
<strong>Group:</strong> <br/>
<strong>Created:</strong> Tue Aug 28, 2001 11:10 PM UTC by Travis<br/>
<strong>Last Updated:</strong> Sat Sep 29, 2001 10:47 AM UTC<br/>
<strong>Owner:</strong> nobody</p>
<p>Hi folks,</p>
<p>I'm very leary that Fink needs to be run as root<br/>
(euid=0 in any case).</p>
<p>Previous to discovering fink, I've used a very similar<br/>
approach to your /sw approach to install a number of<br/>
open source programs from source.</p>
<p>My method has been to do this initially:</p>
<p>mkdir /x<br/>
sudo chown admin.wheel /x<br/>
sudo chmod 775 /x</p>
<p>Then, as an admin user (member of wheel), I can do this<br/>
as I build and install each package:<br/>
mkdir /x/xemacs-21.4.1<br/>
configure --prefix=/x/xemacs-21.4.1<br/>
and then <br/>
make<br/>
make install</p>
<p>Yes, the admin user has more power than a normal user,<br/>
but not enough to install a root kit or mess with /etc<br/>
configuration files without my knowledge I hope. :-)</p>
<p>We need not use an admin user actually.  I could make a<br/>
'fink' user who owns /sw (chown fink.nobody) and all<br/>
files within.  Then fink could only disturb the fink<br/>
install.  That sounds like a good solution to me for<br/>
minimizing risk.  </p>
<p>Running fink as root is just a huge security risk.  I<br/>
hope you will agree and find a way so that beyond a<br/>
setup of /sw, we can run fink without root.</p>
<p>Otherwise, fink looks very worthwhile and if this can<br/>
be resolved, I look forward to using it.</p>
<p>(btw, I didn't see this issue discussed on the<br/>
fink-users mailing list in my browsing.  The search<br/>
feature does not work.  I searched for 'dpkg' -- the<br/>
subject of many recent messages -- and got no hits)</p>
<hr/>
<p>Sent from sourceforge.net because [email protected] is subscribed to <a href="https://sourceforge.net/p/fink/feature-requests/">https://sourceforge.net/p/fink/feature-requests/</a></p>
<p>To unsubscribe from further messages, a project admin can change settings at <a href="https://sourceforge.net/p/fink/admin/feature-requests/options.">https://sourceforge.net/p/fink/admin/feature-requests/options.</a>  Or, if this is a mailing list, you can unsubscribe from the mailing list.</p></div>
--===============0079105764912528545==--
--===============4022260109480114130==--


--===============1631116553428819161==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============1631116553428819161==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Fink-tracker mailing list
[email protected]
http://news.gmane.org/gmane.os.apple.fink.tracker
--===============1631116553428819161==--