unofficial mirror of guile-devel@gnu.org 
 help / color / mirror / Atom feed
From: Mark H Weaver <mhw@netris.org>
To: Eli Zaretskii <eliz@gnu.org>
Cc: wingo@pobox.com, "Ludovic Courtès" <ludo@gnu.org>, guile-devel@gnu.org
Subject: Re: Support open-process and friends on MS-Windows
Date: Sat, 02 Jul 2016 19:02:08 -0400	[thread overview]
Message-ID: <87inwn3aq7.fsf@netris.org> (raw)
In-Reply-To: <83r3blz96w.fsf@gnu.org> (Eli Zaretskii's message of "Sat, 25 Jun 2016 16:31:35 +0300")

Eli Zaretskii <eliz@gnu.org> writes:
> +# define getuid()              (500) /* Local Administrator */
> +# define getgid()              (513) /* None */
> +# define setuid(u)             (0)
> +# define setgid(g)             (0)

As I've said before, I'm not comfortable with these definitions.  These
are not operations that can be safely ignored.  If we cannot do a job
that's requested of us, we should raise an exception.  We should not
make numbers up out of thin air and pass them off as fact, nor should we
claim to have successfully done a job that we are unable to do.

More to the point, we should not assume that the caller's requests are
unimportant.  Feigning success on ignored requests and fabricating
misinformation might be okay in some cases, but in other cases it is
likely to lead to security holes and other bugs.  For example, a common
pattern is to use 'setuid' to drop privileges before running some
untrusted code.  We must not silently ignore such requests.

      Mark



  parent reply	other threads:[~2016-07-02 23:02 UTC|newest]

Thread overview: 22+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2016-06-24  9:51 Support open-process and friends on MS-Windows Eli Zaretskii
2016-06-24 10:45 ` Andy Wingo
2016-06-24 13:20   ` Eli Zaretskii
2016-06-24 11:49 ` Ludovic Courtès
2016-06-24 13:25   ` Eli Zaretskii
2016-06-25  9:11     ` Eli Zaretskii
2016-06-25  9:51       ` Andy Wingo
2016-06-25 10:22         ` Eli Zaretskii
2016-06-25 13:02           ` Ludovic Courtès
2016-06-25 13:20             ` Eli Zaretskii
2016-06-25 13:31             ` Eli Zaretskii
2016-06-25 14:43               ` Andy Wingo
2016-06-25 15:01                 ` Eli Zaretskii
2016-07-02 23:02               ` Mark H Weaver [this message]
2016-07-03  3:47                 ` Eli Zaretskii
2016-07-03 17:36                   ` Eli Zaretskii
2016-07-05  7:44                   ` Mark H Weaver
2016-07-05  8:04                     ` Ludovic Courtès
2016-07-05 15:56                       ` Eli Zaretskii
2016-07-11  8:09                         ` Ludovic Courtès
2016-07-11 14:49                           ` Eli Zaretskii
2016-07-05 15:51                     ` Eli Zaretskii

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

  List information: https://www.gnu.org/software/guile/

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87inwn3aq7.fsf@netris.org \
    --to=mhw@netris.org \
    --cc=eliz@gnu.org \
    --cc=guile-devel@gnu.org \
    --cc=ludo@gnu.org \
    --cc=wingo@pobox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).