[Top][All Lists]
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Gnu-arch-users] Arch hooks
From: |
Tobias C. Rittweiler |
Subject: |
Re: [Gnu-arch-users] Arch hooks |
Date: |
Wed, 1 Oct 2003 14:47:13 +0200 |
On Tuesday, September 30, 2003 at 9:30:05 PM,
Stephen J. Turnbull <address@hidden> wrote:
>>>>>> "Tom" == Tom Lord <address@hidden> writes:
> > > From: "Stephen J. Turnbull" <address@hidden>
>
> > > Realistically, hook scripts in project trees are only mildly
> > > dangerous.
>
> Tom> That's a very context-specific assertion. In general, they
> Tom> are a nightmare.
>
> Oh, I see your point, but ... compared to arbitrary code executing as
> root? I think not. Arch hook scripts are going to be executing as
> unprivileged users, unlike "make install". Any damage you could do
> with a hook script you could do with a Makefile patch, and then some.
But when there's a checkout hook-script you have almost zero chances
looking at the code in question before it's already too late.
-- tcr (address@hidden) ``Ho chresim'eidos uch ho poll'eidos sophos''
- Re: [Gnu-arch-users] Arch hooks,
Tobias C. Rittweiler <=
- Re: [Gnu-arch-users] Arch hooks, Stephen J. Turnbull, 2003/10/01
- [Gnu-arch-users] Re: Arch hooks, Miles Bader, 2003/10/02
- [Gnu-arch-users] Re: Arch hooks, Stephen J. Turnbull, 2003/10/02
- Re: [Gnu-arch-users] Re: Arch hooks, Andrew Suffield, 2003/10/02
- Re: [Gnu-arch-users] Re: Arch hooks, Stephen J. Turnbull, 2003/10/02
- Re: [Gnu-arch-users] Re: Arch hooks, Andrew Suffield, 2003/10/02
- Re: [Gnu-arch-users] Re: Arch hooks, Stephen J. Turnbull, 2003/10/02
- Re: [Gnu-arch-users] Re: Arch hooks, Tom Lord, 2003/10/02
- [OT] Re: [Gnu-arch-users] Re: Arch hooks, Andrew Suffield, 2003/10/02
- Re: [OT] Re: [Gnu-arch-users] Re: Arch hooks, Stephen J. Turnbull, 2003/10/02