X-Original-To: alpine-devel@mail.alpinelinux.org Delivered-To: alpine-devel@mail.alpinelinux.org Received: from mail.alpinelinux.org (dallas-a1.alpinelinux.org [127.0.0.1]) by mail.alpinelinux.org (Postfix) with ESMTP id 0F836DC13E8 for ; Wed, 27 May 2015 20:19:15 +0000 (UTC) Received: from mail-pa0-f48.google.com (mail-pa0-f48.google.com [209.85.220.48]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by mail.alpinelinux.org (Postfix) with ESMTPS id CB595DC1269 for ; Wed, 27 May 2015 20:19:09 +0000 (UTC) Received: by paza2 with SMTP id a2so5802657paz.3 for ; Wed, 27 May 2015 13:19:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=date:from:to:subject:message-id:in-reply-to:references:mime-version :content-type; bh=Taz8kFfNp/GXCbTNTuz47NVfKbQWCw6GT6QJf7j1sQk=; b=ooFZ4kyDsr/lO1AMXvZNKf6BXIm9nyL/5swbo/Xe5wjlpXmcCPQevqGVCzmdTZX63j 7mH6zaK2GH1YnaRDGtkUHoepVMHBJtG9KuXVcSxqVV/lu/UAfp+LLU/AlWihDQm5wbIV iRlcif2ulmzqlxcBfVgrDdDkvwpB7W7cAnmYVww7cwJJGR6MZmlo7O/uZxYCJ0iwSC7G BLGKZy13vOdALoAy2xyilDNquUbyN6q95hS8uWpKVjSP5eq+et3C/B6MMTwPP5lvfOWE ljdahQ5vZ+yslCwgEw0MCPG0lePu3b4IsNhyvGaU7GIMAXQJjCX6hw3uRjvns56jQC2U uF3w== X-Received: by 10.68.136.134 with SMTP id qa6mr62386874pbb.66.1432757948294; Wed, 27 May 2015 13:19:08 -0700 (PDT) Received: from twinpeaks.my.domain ([74.82.134.59]) by mx.google.com with ESMTPSA id ux6sm26950pab.24.2015.05.27.13.19.07 for (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 27 May 2015 13:19:07 -0700 (PDT) Date: Wed, 27 May 2015 13:19:01 -0700 From: Orion To: alpine-devel@lists.alpinelinux.org Subject: Re: [alpine-devel] 3.3 proposal: reduce number of SUID binaries as much as possible Message-ID: <20150527131901.790405cc@twinpeaks.my.domain> In-Reply-To: References: X-Mailer: Claws Mail 3.11.1 (GTK+ 2.24.25; x86_64-alpine-linux-musl) X-Mailinglist: alpine-devel Precedence: list List-Id: Alpine Development List-Unsubscribe: List-Post: List-Help: List-Subscribe: MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; boundary="Sig_/s5U64DAwy0JZIK61t7dijtS"; protocol="application/pgp-signature" X-Virus-Scanned: ClamAV using ClamSMTP --Sig_/s5U64DAwy0JZIK61t7dijtS Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: quoted-printable On Tue, 26 May 2015 04:32:01 -0500 William Pitcock wrote: > I would like to see a general reduction of SUID binaries where > possible. For example, a lot of APKBUILDs have options=3Dsuid when > there's probably no real reason for it. I fully support this endeavor! :D I will gladly help out and maintain this project. However, I would prefer that we start with the base system before we move onto other packages. So I think a great first attempt would be removing as many SUIDs/SGIDs from a bare bones alpine-mini install. --=20 keybase.io/systmkor --Sig_/s5U64DAwy0JZIK61t7dijtS Content-Type: application/pgp-signature Content-Description: OpenPGP digital signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCAAGBQJVZia2AAoJEPM7NuFpB6Q++FQP/2Ye32vOGwawnpekLHSwsNZ3 QPa4b0qvXcqA97jxGrw2l1idgOOs3ut8ehd6Sgafz/wv2pT9xqJW1qpViKlxmppt Tsn/gU6CdXDZJx7NC2SZ0R0zHoM92hFde7glvRDSfWrA79e2tdr2PfgKbvxmWcsg zBsViO+67Ci5DmnSMbls7huUx5v5QKRPnfw41vL+zGxhEfHyhn0t0Ojj69owUHGM WoJYNdvmAEX1Bii7+VC6E4wgOQPuf06byFRMK3b9IlwvdiZQVSuvKjBQQ85cIju1 PkbOMuLH9IhdMvFBA2ZV2fR9yS17gkyG6CX4fWio7aoLoiufjok/u09Pv5dk9ehi AhR9VAwbT0GZRjYKZG54MQ2+Vv1V9Jb5b0Mju0eYNw7St+Z9Gd6EEsESXWg+ILGk B29O5RCNjsFkYwz8kafzsW3IxPXF0PEBfMBnOpLHWOVjkNwDS76J1CY4YyDXj8VI ktSBenOAWZNwnge9WoeLqftLG770Tp+ZdO05UgkLgu4hQWWsDZr3IiGPy34jJLFz VAGAb33aI1zy9m5IcAM1x4E1ccgDwgn/ErGIor3aj7GLsJ9WE1cTFsWd6dPMdOOL KCjH7J6ef6Tc2amVhdeoQvUMq346uD5UhLjQX7nm4M453y3tCkIUWbcDRZIcePyH yOZIaM42appJJK3ItESi =SJr6 -----END PGP SIGNATURE----- --Sig_/s5U64DAwy0JZIK61t7dijtS-- --- Unsubscribe: alpine-devel+unsubscribe@lists.alpinelinux.org Help: alpine-devel+help@lists.alpinelinux.org ---