Page MenuHomeFreeBSD

comsat: Use initgroups and setgid not just setuid
ClosedPublic

Authored by emaste on Nov 28 2024, 4:56 PM.
Tags
None
Referenced Files
F156882537: D47828.id147125.diff
Sun, May 17, 1:39 AM
F156882501: D47828.id147332.diff
Sun, May 17, 1:39 AM
F156881198: D47828.diff
Sun, May 17, 1:32 AM
Unknown Object (File)
Wed, Apr 29, 8:52 PM
Unknown Object (File)
Tue, Apr 28, 12:05 AM
Unknown Object (File)
Mon, Apr 27, 11:58 PM
Unknown Object (File)
Mon, Apr 20, 11:10 AM
Unknown Object (File)
Sun, Apr 19, 4:16 PM
Subscribers

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

emaste created this revision.
jlduran added inline comments.
libexec/comsat/comsat.c
214–215

I would suggest also updating this comment

This revision is now accepted and ready to land.Nov 29 2024, 10:21 PM

One thing I've noticed is that NetBSD moved the setting of groups/uid/gid earlier to inside notify() (https://github.com/NetBSD/src/commit/46b017828cee516770586497237aed6182b1decf). I think failing earlier is also a good move.

One thing I've noticed is that NetBSD moved the setting of groups/uid/gid earlier to inside notify() (https://github.com/NetBSD/src/commit/46b017828cee516770586497237aed6182b1decf). I think failing earlier is also a good move.

Not a bad idea, can follow up with that (and check for any other improvements from NetBSD or OpenBSD)