Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 488530

Summary: x11-misc/slock could use capabilities instead of SUID root
Product: Gentoo Linux Reporter: Mira Ressel <aranea>
Component: Current packagesAssignee: Jeroen Roovers (RETIRED) <jer>
Status: RESOLVED FIXED    
Severity: enhancement CC: desktop-misc
Priority: Normal Keywords: PATCH
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard:
Package list:
Runtime testing required: ---
Attachments: Patch for x11-misc/slock-1.1.ebuild introducing capability usage

Description Mira Ressel 2013-10-18 21:49:05 UTC
Created attachment 361270 [details, diff]
Patch for x11-misc/slock-1.1.ebuild introducing capability usage

x11-misc/slock currently installs a SUID root binary in order to be able to read /etc/shadow. For that, granting CAP_DAC_READ_SEARCH would also suffice. The attached patch does that, using fcaps.eclass: If the new USE "filecaps" is disabled, nothing changes. If it's enabled however, only the capability is granted.
Comment 1 Jeroen Roovers (RETIRED) gentoo-dev 2013-10-19 15:27:26 UTC
Thanks for the patch. Committed in -r1.