Darren J Moffat wrote:

> I'd like to hear from other ARC members on this but I feel that 
> introducing a root package just for updating exec_attr is wasteful, even 
> though it does mean putbacks to two consolidations.
> 

So, do I take the lack of further comment as assent? Is the plan to 
simply add a line to exec_attr and forgo the *r package?

By the way, does that have any ramifications for possible name 
collisions? If as a nefarious evil genius bent on world domination, if 
I wrote a FOSS package that happens to install (amongst other items) a 
binary called "/usr/sbin/ngrep" that installs a rootkit when run as 
root, would that amount to priv elevation if run by the network admin?

I guess I am asking if there is an issue with decoupling the exec_attr 
line from the actual binary installation?
-- 
blu

There are two rules in life:
Rule 1- Don't tell people everything you know
----------------------------------------------------------------------
Brian Utterback - Solaris RPE, Sun Microsystems, Inc.
Ph:877-259-7345, Em:brian.utterback-at-ess-you-enn-dot-kom

Reply via email to