[arch-general] Why is it dangerous to run makepkg as root?

Roland Tapken ml at lalamuhkuh.de
Sat May 17 10:22:32 EDT 2014


> A good idea is to automatically change to a much more restricted user, used
> just for building (no shells, logins, etc.). 

What do you think about patching yaourt to that it, if executed as root, runs 
makepkg as a special user? Or changing makepkg to drop it's own privileges if 
executed as root?


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 490 bytes
Desc: This is a digitally signed message part.
URL: <http://mailman.archlinux.org/pipermail/arch-general/attachments/20140517/13a2021d/attachment-0001.asc>

More information about the arch-general mailing list