non-superuser chown(2)s considered harmful
Brandon S. Allbery KB8JRR
allbery at NCoast.ORG
Sun Dec 16 14:48:26 AEST 1990
As quoted from <18687 at netcom.UUCP> by dsmythe at netcom.UUCP (Dave Smythe):
+---------------
| In article <1990Dec12.052114.2694 at athena.mit.edu> jfc at athena.mit.edu (John F Carr) writes:
| >In article <1990Dec10.231812.23634 at gjetor.geac.COM>
| > adeboer at gjetor.geac.COM (Anthony DeBoer) writes:
| >
| >>Just for my $0.02 worth, if quotas are in effect, why not have a nightly
| >>daemon that goes through each user's directory and blows away anything he/she
| >>doesn't own? This should take care of out-chowning files to bypass
| >>allocation.
| >
| >It is much more polite to chown the files to the owner of the directory,
|
| Suppose there are multiple links to the file; who gets to own it? The last
| person visited by your chown'ing utility? Or do you only chown files with
| only a single link?
+---------------
The other problem is that the sysadmin is going to be in big trouble when I
come in the next day and discover that my latest development copy of qzt
(which is setuid uucp) has been blown away or un-permissioned.... Admitted,
group vectors are nice, but I'd need an infinitely sized group vector to cover
all the possibilities, so some things are still setuid instead of setgid.
++Brandon
--
Me: Brandon S. Allbery VHF/UHF: KB8JRR on 220, 2m, 440
Internet: allbery at NCoast.ORG Packet: KB8JRR @ WA8BXN
America OnLine: KB8JRR AMPR: KB8JRR.AmPR.ORG [44.70.4.88]
uunet!usenet.ins.cwru.edu!ncoast!allbery Delphi: ALLBERY
More information about the Comp.unix.internals
mailing list