From owner-freebsd-bugs@FreeBSD.ORG Tue Apr 25 22:00:39 2006 Return-Path: X-Original-To: freebsd-bugs@hub.freebsd.org Delivered-To: freebsd-bugs@hub.freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 2B43516A446 for ; Tue, 25 Apr 2006 22:00:39 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id E6BA343D49 for ; Tue, 25 Apr 2006 22:00:38 +0000 (GMT) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.13.4/8.13.4) with ESMTP id k3PM0cQG086998 for ; Tue, 25 Apr 2006 22:00:38 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.13.4/8.13.4/Submit) id k3PM0cY4086997; Tue, 25 Apr 2006 22:00:38 GMT (envelope-from gnats) Date: Tue, 25 Apr 2006 22:00:38 GMT Message-Id: <200604252200.k3PM0cY4086997@freefall.freebsd.org> To: freebsd-bugs@FreeBSD.org From: Alex Kozlov Cc: Subject: Re: bin/96248: vipw fail on RO /etc X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: Alex Kozlov List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 25 Apr 2006 22:00:39 -0000 The following reply was made to PR bin/96248; it has been noted by GNATS. From: Alex Kozlov To: Maxim Konovalov Cc: bug-followup@freebsd.org Subject: Re: bin/96248: vipw fail on RO /etc Date: Wed, 26 Apr 2006 00:57:56 +0300 On Tue, Apr 25, 2006 at 08:40:14PM +0000, Maxim Konovalov wrote: > > > > I believe a simple script could solve the problem in your environment. > > Almost any missing features can be done with wrapper script. > > But programs continue to improve. > > Yes, in a way they don't break POLA. I'd be really surprised if > eventually vipw(8) run 'more' instead of 'vi' :-) > > > Also I don't want script in sudo case. > > I know nothing about your environment but if you trust users to run > vipw(8) from which they can easily change root password, create a > priv. account, jump to root shell, why don't trust them to run a > script? Ok. I take your point. > > P.S. Btw, lib/libutil don't respect NO_INET6 knob. Fix is simple. > > Shall I fill another PR? > Yes, sure. Done. -- Adios