3 ms·
I have always found the daemons that come (or don't come) with linux rather odd. I suppose it is a quirk of how it is developed and who is responsible for what?
by robohamburger 9y ago
I have always found the daemons that come (or don't come) with linux rather odd. I suppose it is a quirk of how it is developed and who is responsible for what?
I agree that ping should probably not use setuid. Setuid seems like a hack to me though I am sure it is a necessary one.
- deathanatos 9y agoI can't think why ping should need setuid; having the capability for opening a raw socket would be enough, I think. (Unless I misunderstand how capabilities work, but this seems to suffice for Wireshark.)
- wolfgang42 9y agoMy Ubuntu Xenial system has /bin/ping as '-rwsr-xr-x' and getcap reports nothing. On the other hand raw(7) says "Only processes with an effective user ID of 0 or the CAP_NET_RAW capability are allowed to open raw sockets" so I would expect setuid to not be needed any more. I assume Canonical has a reason for setting it up this way though I've no idea what that reason is. UNIX-derived systems tend to have a habit of requiring root for anything that even remotely might want to be restricted: the example that comes to mind is reserving ports 0-1024 for root, thus requiring that most daemons to start as root instead of an unprivileged user.
- girvo 9y agoThere's a nice capability that allows non-root binaries to use low ports, too!