>>>> "Ville" == Ville Skyttä
<ville.skytta(a)xemacs.org> writes:
Ville> When installing packages with the package UI as root
Ville> (21.4.6 on RedHat 7.2), the extracted files get their
Ville> ownerships from the tarballs, which is not nice. Nowadays
Ville> the files seem to have 103/100 as their owner. Some may
Ville> consider it as a security hole, not?
I suppose. This is always an issue with root.
I guess Steve could (1) make sure there are no set-id binaries in the
packages, and (2) force the ownership with tar --owner=0 --group=0 (I
believe this should work fine for Steve's ordinary user).
--
Institute of Policy and Planning Sciences
http://turnbull.sk.tsukuba.ac.jp
University of Tsukuba Tennodai 1-1-1 Tsukuba 305-8573 JAPAN
Don't ask how you can "do" free software business;
ask what your business can "do for" free software.