non-superuser chown(2)s considered harmful

Brandon S. Allbery KB8JRR allbery at NCoast.ORG
Sun Dec 16 14:48:26 AEST 1990


As quoted from <18687 at netcom.UUCP> by dsmythe at netcom.UUCP (Dave Smythe):
+---------------
| In article <1990Dec12.052114.2694 at athena.mit.edu> jfc at athena.mit.edu (John F Carr) writes:
| >In article <1990Dec10.231812.23634 at gjetor.geac.COM>
| >	adeboer at gjetor.geac.COM (Anthony DeBoer) writes:
| >
| >>Just for my $0.02 worth, if quotas are in effect, why not have a nightly
| >>daemon that goes through each user's directory and blows away anything he/she
| >>doesn't own?  This should take care of out-chowning files to bypass
| >>allocation.
| >
| >It is much more polite to chown the files to the owner of the directory,
| 
| Suppose there are multiple links to the file; who gets to own it?  The last
| person visited by your chown'ing utility?  Or do you only chown files with
| only a single link?
+---------------

The other problem is that the sysadmin is going to be in big trouble when I
come in the next day and discover that my latest development copy of qzt
(which is setuid uucp) has been blown away or un-permissioned....  Admitted,
group vectors are nice, but I'd need an infinitely sized group vector to cover
all the possibilities, so some things are still setuid instead of setgid.

++Brandon
-- 
Me: Brandon S. Allbery			    VHF/UHF: KB8JRR on 220, 2m, 440
Internet: allbery at NCoast.ORG		    Packet: KB8JRR @ WA8BXN
America OnLine: KB8JRR			    AMPR: KB8JRR.AmPR.ORG [44.70.4.88]
uunet!usenet.ins.cwru.edu!ncoast!allbery    Delphi: ALLBERY



More information about the Comp.unix.internals mailing list