3 ms·
You just need to be root to install whack-run, since whack-run requires the setuid flag. Once you've installed whack-run, you can install the applications as an
by mwilliamson 13y ago
You just need to be root to install whack-run, since whack-run requires the setuid flag. Once you've installed whack-run, you can install the applications as an ordinary user.
- mh- 13y ago(yes)
- asveikau 13y agoHow complex is whack-run? A setuid binary should be sure to minimize its attack surface. It's just a quick look but when I see your shit-ton of .py files and then you say there is setuid involved it does not fill me with lots of confidence.
- mwilliamson 13y agowhack-run is a separate C binary for this very reason: https://github.com/mwilliamson/whack-run https://github.com/mwilliamson/whack-run Whack itself is run with normal privileges.
- deleted 13y ago[deleted]
- mwilliamson 13y agoI'm no Linux security expert, so any advice on that front is hugely appreciated. whack-run is supposed to drop any privileges it holds when it runs "setgid(getgid())" and "setuid(getuid())", and it exits early if either of those calls fail. Is there any reason why that wouldn't work?
- asveikau 13y agoI deleted the comment shortly seemingly before you replied, because I saw the setuid syscall. So I may have been overly paranoid.