Change file permissions for some setuid executables so they are "o+r".
The executable itself doesn't contain any privileged information. An example of where this is useful is when makefs(8) is creating an image that includes /sbin/shutdown. This can now be done without root privileges. Reviewed by: delphij Discussed with: delphij, des CR: https://reviews.freebsd.org/D662
This commit is contained in:
parent
c6e1a98786
commit
f518456fdb
@ -10,9 +10,9 @@ WARNS?= 2
|
||||
CFLAGS+=-I${.CURDIR}/../mount
|
||||
|
||||
.if defined(NOSUID)
|
||||
BINMODE=550
|
||||
BINMODE=554
|
||||
.else
|
||||
BINMODE=4550
|
||||
BINMODE=4554
|
||||
BINOWN= root
|
||||
.endif
|
||||
BINGRP= operator
|
||||
|
@ -8,6 +8,6 @@ MLINKS= shutdown.8 poweroff.8
|
||||
|
||||
BINOWN= root
|
||||
BINGRP= operator
|
||||
BINMODE=4550
|
||||
BINMODE=4554
|
||||
|
||||
.include <bsd.prog.mk>
|
||||
|
@ -33,9 +33,9 @@ PPP_NO_PAM=
|
||||
.endif
|
||||
|
||||
.if defined(PPP_NO_SUID)
|
||||
BINMODE=550
|
||||
BINMODE=554
|
||||
.else
|
||||
BINMODE=4550
|
||||
BINMODE=4554
|
||||
BINOWN= root
|
||||
.endif
|
||||
BINGRP= network
|
||||
|
Loading…
Reference in New Issue
Block a user