Re: [dev] [slock] patch for avoiding hardcoded root-check

From: Stephen Paul Weber <singpolyma_AT_singpolyma.net>
Date: Mon, 23 Jan 2012 13:58:51 +0000

Somebody claiming to be Kurt H Maier wrote:
>On Mon, Jan 23, 2012 at 01:33:35PM +0100, Michael Stummvoll wrote:
>> so I patched slock to not demant root-rights, but just checks,
>> if the password-query commands are successfull.
>> I also patched the Makefile to do not setuid root but setgid shadow instead.
>Not all distributions even have a shadow group.

I wouldn't take the Makefile patch, but checking if the tool has permission
for what it wants to do, instead of checking if it ts root, seems
preferrable to me.

-- 
Stephen Paul Weber, _AT_singpolyma
See <http://singpolyma.net> for how I prefer to be contacted
edition right joseph
Received on Mon Jan 23 2012 - 14:58:51 CET

This archive was generated by hypermail 2.3.0 : Mon Jan 23 2012 - 15:00:07 CET