Re: ~/.login_conf disabling exact reasons wanted

From: Andrey A. Chernov (ache@nagual.pp.ru)
Date: 09/22/01


Date: Sat, 22 Sep 2001 16:44:48 +0400
From: "Andrey A. Chernov" <ache@nagual.pp.ru>
To: Alexander Langer <alex@big.endian.de>, security@FreeBSD.org, rwatson@FreeBSD.org, current@FreeBSD.org, developers@FreeBSD.org

On Sat, Sep 22, 2001 at 14:12:17 +0200, Alexander Langer wrote:
> Thus spake Andrey A. Chernov (ache@nagual.pp.ru):
>
> > Why it is hoax? One reason is simple, look at his examples:
>
> A hoax, that has been tested and verified by 10+ people on IRC, where he originally
> reported it.

Please, read me carefully. This bug not exist in -current, where it is
disabled by mistake via commit I complain. I not test other branches, I
mean -current. Proper fix will be to commit -current libutil/login_cap to
other branches, not disable it, especially in -current.

> > Only "me" class can be defined in ~/.login_conf, anything else ignored
> > there. And "me" class picked up only when permissions are set to user
> > mode, at the end of setusercontext(). And "copyright" and "welcome" are
> > not overwriteable from "me" class in any case.
>
> Yeah, now you know what is broken.

It is working in -current.

-- 
Andrey A. Chernov
http://ache.pp.ru/
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message