• Open Menu Close Menu
  • Apple
  • Shopping Bag
  • Apple
  • Mac
  • iPad
  • iPhone
  • Watch
  • TV
  • Music
  • Support
  • Search apple.com
  • Shopping Bag

Lists

Open Menu Close Menu
  • Terms and Conditions
  • Lists hosted on this site
  • Email the Postmaster
  • Tips for posting to public mailing lists
Re: setuid for priv sockets?
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: setuid for priv sockets?


  • Subject: Re: setuid for priv sockets?
  • From: Damien Sorresso <email@hidden>
  • Date: Mon, 27 Oct 2008 11:19:47 -0700

On Oct 27, 2008, at 11:11 AM, Brad Parker wrote:
If I have a app which wants to open a "privileged" socket (AF_NDRV) for
direct ethernet access,


Is the right thing to make the app setuid root and do seteuid()?

This is (currently) a command line application.  I suspect I should
ultimately add a UI and have it pop up a window asking for
authentication... (but I'm trying to avoid a UI for now)

Brad,

We're strongly (and I do mean strongly) trying to move people off of setuid binaries. If it's a command line application, you can just require that the user run it as root or with sudo if performing actions that require access to this privileged port.
--
Damien Sorresso
BSD Engineering
Apple Inc.


Attachment: smime.p7s
Description: S/MIME cryptographic signature

 _______________________________________________
Do not post admin requests to the list. They will be ignored.
Darwin-dev mailing list      (email@hidden)
Help/Unsubscribe/Update your Subscription:

This email sent to email@hidden

References: 
 >setuid for priv sockets? (From: Brad Parker <email@hidden>)

  • Prev by Date: setuid for priv sockets?
  • Next by Date: SOL_NDRVPROTO
  • Previous by thread: setuid for priv sockets?
  • Next by thread: Re: setuid for priv sockets?
  • Index(es):
    • Date
    • Thread