On Tue, 2004-04-06 at 22:40, Michael A. Peters wrote: > > And of course - root's path should NOT have /usr/contrib/bin in it - for > obvious reasons - since root isn't required to install there (which is > another reason to not allow the contrib stuff to satisfy the distro > rpm's - as you could end up with a distro binary using a tainted shared > library from contrib when run as root) > > -- And of course suid bits should not be allowed in /contrib either. RPM would most likely fail to install with an suid bit anyway if wasn't being run as root, but still. -- Cheap Linux CD's - http://mpeters.us/linux/