On Mon, 28 Aug 2000, Nitebirdz wrote:
> On Sun, 27 Aug 2000, John Summerfield wrote:
> > I've chowned it to me and do not build as root (regulars will
> > have noticed I'm  reluctant to build anything as root; recent
> > news wrt pinstrip is Good).
> 
> Excuse me for the stupid question, but why wouldn't you build a package as
> root?  Security reasons?  Even if you trust the sources?  Just trying to
> learn something from you, guys.   :-)

"Never attribute to malice, that which may be ascribed to
stupidity."

... If one builds as root, and the designer of the spec file has
been lax, or less that 100 % perfect, all the time, one may
unintentionally over-write a live production file.

By building as non-root, the regular unix permissions system will
act as a backup to protect you.  A non-root user _cannot_
inadvertently overwrite properly protected installations.  Even if
_you_, the builder, turn out to be that spec file designer <grin>.

-- 
end
==================================
 .-- -... ---.. ... -.- -.--
Copyright (C) 2000 R P Herrold
      [EMAIL PROTECTED]  NIC: RPH5 (US)
   My words are not deathless prose, 
      but they are mine.

   Owl River Company  614 - 221 - 0695
   "The World is Open to Linux (tm)"
   ... Open Source LINUX solutions ...
      [EMAIL PROTECTED] 
         Columbus, OH



_______________________________________________
Redhat-devel-list mailing list
[EMAIL PROTECTED]
https://listman.redhat.com/mailman/listinfo/redhat-devel-list

Reply via email to