From: "H. Peter Anvin" <hpa@zytor.com>
To: Linus Torvalds <torvalds@osdl.org>
Cc: Junio C Hamano <junkio@cox.net>, Git Mailing List <git@vger.kernel.org>
Subject: Re: git-daemon --inetd
Date: Fri, 16 Sep 2005 11:23:19 -0700 [thread overview]
Message-ID: <432B0D97.2030903@zytor.com> (raw)
In-Reply-To: <Pine.LNX.4.58.0509161027460.26803@g5.osdl.org>
Linus Torvalds wrote:
>
> Well, the symbolic names are much nicer and more readable. So it would be
> better to do the uid/gid translation early, and change the "chroot" thing
> to be done after all that.
>
> It gets a bit messy.. Easy enough to just save a "const char *new_root",
> but then you have to split up the "set_user_group()" to be two functions,
> around the actual chroot(), since the chroot needs to be done while we're
> still root.
>
Actually, initgroups() and setgroups(), and setgid() for that matter,
can be done before the chroot(). The only thing that needs to remain
until the end is setuid().
At one time I played around in tftp-hpa with trying to get Linux to keep
only CAP_SYS_CHROOT around, but I think I gave up on it. The way Linux
capabilities play with the rest of the permission system isn't very
useful :(
-hpa
prev parent reply other threads:[~2005-09-16 18:23 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2005-09-15 6:04 git-daemon --inetd H. Peter Anvin
2005-09-15 16:03 ` Linus Torvalds
2005-09-15 18:30 ` H. Peter Anvin
2005-09-15 18:47 ` Linus Torvalds
2005-09-15 19:19 ` H. Peter Anvin
2005-09-15 19:40 ` Linus Torvalds
2005-09-15 21:44 ` Martin Langhoff
2005-10-22 13:45 ` Jon Seymour
2005-10-22 21:05 ` Linus Torvalds
2005-09-15 19:57 ` Junio C Hamano
2005-09-16 6:23 ` Junio C Hamano
2005-09-16 7:51 ` Junio C Hamano
2005-09-16 16:54 ` H. Peter Anvin
2005-09-16 17:30 ` Linus Torvalds
2005-09-16 18:23 ` H. Peter Anvin [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=432B0D97.2030903@zytor.com \
--to=hpa@zytor.com \
--cc=git@vger.kernel.org \
--cc=junkio@cox.net \
--cc=torvalds@osdl.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).