NetBSD-Users archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: "Real programs dump core"



On Tue, Sep 06, 2011 at 03:12:14PM +0200, Hauke Fath wrote:
> At 6:39 Uhr +0000 06.09.2011, Michael van Elst wrote:
> >>>I wonder if we should have an equivalent for kern.coredump.setid.path for
> >>>non-setid images.
> >
> >There is:
> >kern.defcorename = %n.core
> >proc.curproc.corename = %n.core
> 
> The latter is for the current process only, while kern.coredump.setid.path
> is global.
> 
> The Amanda planner binary runs setuid root to open a privileged port, then
> reuurns to unprivileged mode. As such it apparently cannot write a core to
> the CWD. I guess I'd have to set proc.curproc.corename from the planner
> process, then.

Why not fix the planner binary to not run setuid root?  It's not hard to
do.

Thor


Home | Main Index | Thread Index | Old Index