[fink:feature-requests] #12 Should not run as root
Hanspeter Niederstrasser via Fink-tracker <[email protected]> Sat, 08 Feb 2020 23:48:33 -0000
| Newsgroups | gmane.os.apple.fink.tracker |
|---|---|
| Message-ID | </p/fink/feature-requests/12/4203bc7f877c963b0a602ef35d8fd92cbcad46ea.feature-requests@fink.p.sourceforge.net> |
This is a multi-part message in MIME format. --===============1631116553428819161== Content-Type: multipart/related; boundary="===============4022260109480114130==" This is a multi-part message in MIME format. --===============4022260109480114130== Content-Type: multipart/alternative; boundary="===============0079105764912528545==" MIME-Version: 1.0 --===============0079105764912528545== MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit - **status**: open --> closed-out-of-date - **Group**: --> - **Comment**: Fink has long defaulted to using the 'fink-bld' user to build things unless explicitly required by a package. --- ** [feature-requests:#12] Should not run as root** **Status:** closed-out-of-date **Group:** **Created:** Tue Aug 28, 2001 11:10 PM UTC by Travis **Last Updated:** Sat Sep 29, 2001 10:47 AM UTC **Owner:** nobody Hi folks, I'm very leary that Fink needs to be run as root \(euid=0 in any case\). Previous to discovering fink, I've used a very similar approach to your /sw approach to install a number of open source programs from source. My method has been to do this initially: mkdir /x sudo chown admin.wheel /x sudo chmod 775 /x Then, as an admin user \(member of wheel\), I can do this as I build and install each package: mkdir /x/xemacs-21.4.1 configure --prefix=/x/xemacs-21.4.1 and then make make install Yes, the admin user has more power than a normal user, but not enough to install a root kit or mess with /etc configuration files without my knowledge I hope. :-\) We need not use an admin user actually. I could make a 'fink' user who owns /sw \(chown fink.nobody\) and all files within. Then fink could only disturb the fink install. That sounds like a good solution to me for minimizing risk. Running fink as root is just a huge security risk. I hope you will agree and find a way so that beyond a setup of /sw, we can run fink without root. Otherwise, fink looks very worthwhile and if this can be resolved, I look forward to using it. \(btw, I didn't see this issue discussed on the fink-users mailing list in my browsing. The search feature does not work. I searched for 'dpkg' -- the subject of many recent messages -- and got no hits\) --- Sent from sourceforge.net because [email protected] is subscribed to https://sourceforge.net/p/fink/feature-requests/ To unsubscribe from further messages, a project admin can change settings at https://sourceforge.net/p/fink/admin/feature-requests/options. Or, if this is a mailing list, you can unsubscribe from the mailing list. --===============0079105764912528545== MIME-Version: 1.0 Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: 7bit <div class="markdown_content"><ul> <li><strong>status</strong>: open --> closed-out-of-date</li> <li><strong>Group</strong>: --> </li> <li><strong>Comment</strong>:</li> </ul> <p>Fink has long defaulted to using the 'fink-bld' user to build things unless explicitly required by a package.</p> <hr/> <p><strong> <a class="alink strikethrough" href="https://sourceforge.net/p/fink/feature-requests/12/">[feature-requests:#12]</a> Should not run as root</strong></p> <p><strong>Status:</strong> closed-out-of-date<br/> <strong>Group:</strong> <br/> <strong>Created:</strong> Tue Aug 28, 2001 11:10 PM UTC by Travis<br/> <strong>Last Updated:</strong> Sat Sep 29, 2001 10:47 AM UTC<br/> <strong>Owner:</strong> nobody</p> <p>Hi folks,</p> <p>I'm very leary that Fink needs to be run as root<br/> (euid=0 in any case).</p> <p>Previous to discovering fink, I've used a very similar<br/> approach to your /sw approach to install a number of<br/> open source programs from source.</p> <p>My method has been to do this initially:</p> <p>mkdir /x<br/> sudo chown admin.wheel /x<br/> sudo chmod 775 /x</p> <p>Then, as an admin user (member of wheel), I can do this<br/> as I build and install each package:<br/> mkdir /x/xemacs-21.4.1<br/> configure --prefix=/x/xemacs-21.4.1<br/> and then <br/> make<br/> make install</p> <p>Yes, the admin user has more power than a normal user,<br/> but not enough to install a root kit or mess with /etc<br/> configuration files without my knowledge I hope. :-)</p> <p>We need not use an admin user actually. I could make a<br/> 'fink' user who owns /sw (chown fink.nobody) and all<br/> files within. Then fink could only disturb the fink<br/> install. That sounds like a good solution to me for<br/> minimizing risk. </p> <p>Running fink as root is just a huge security risk. I<br/> hope you will agree and find a way so that beyond a<br/> setup of /sw, we can run fink without root.</p> <p>Otherwise, fink looks very worthwhile and if this can<br/> be resolved, I look forward to using it.</p> <p>(btw, I didn't see this issue discussed on the<br/> fink-users mailing list in my browsing. The search<br/> feature does not work. I searched for 'dpkg' -- the<br/> subject of many recent messages -- and got no hits)</p> <hr/> <p>Sent from sourceforge.net because [email protected] is subscribed to <a href="https://sourceforge.net/p/fink/feature-requests/">https://sourceforge.net/p/fink/feature-requests/</a></p> <p>To unsubscribe from further messages, a project admin can change settings at <a href="https://sourceforge.net/p/fink/admin/feature-requests/options.">https://sourceforge.net/p/fink/admin/feature-requests/options.</a> Or, if this is a mailing list, you can unsubscribe from the mailing list.</p></div> --===============0079105764912528545==-- --===============4022260109480114130==-- --===============1631116553428819161== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============1631116553428819161== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Fink-tracker mailing list [email protected] http://news.gmane.org/gmane.os.apple.fink.tracker --===============1631116553428819161==--