summaryrefslogtreecommitdiff
path: root/sys
diff options
context:
space:
mode:
authorTheo de Raadt <deraadt@cvs.openbsd.org>2023-06-19 13:05:26 +0000
committerTheo de Raadt <deraadt@cvs.openbsd.org>2023-06-19 13:05:26 +0000
commitcf3d7ad102765a8579b2d976211f0e5f84c954c0 (patch)
tree841ada908696e8f01849c6202be2aeb8b04767fb /sys
parent85e4055f57fbb482af35cefee27ffc0fc3a93ebb (diff)
The group "operator" gatekeeps a few superuser abilities (dumping disks,
manipulating tape drives -> means gid operator on device nodes). This group is also used with group-access bit on the setuid-root shutdown command (mode ug+x,u+s). Some people use this to shutdown/reboot their machines, but use of that group is giving them disk read access also, which is wrong. It would be a pain to re-gid all the device nodes, so instead let's renumber the operator execution gid into group "_shutdown". Users using this shutdown/reboot functionality will notice it no longer works, and move themselves to the correct group. Various choices discussed at large, this seems our best choice. ok sthen
Diffstat (limited to 'sys')
0 files changed, 0 insertions, 0 deletions