From gerald.lurker@sysmatrix.net Mon Sep 21 17:12:11 2009
Received: from sfi-mx-4.v28.ch3.sourceforge.com ([172.29.28.124]
	helo=mx.sourceforge.net)
	by 3yr0jf1.ch3.sourceforge.com with esmtp (Exim 4.69)
	(envelope-from <gerald.lurker@sysmatrix.net>) id 1MpmQt-0002MY-TO
	for lurker-users@lists.sourceforge.net; Mon, 21 Sep 2009 17:12:11 +0000
X-ACL-Warn: 
Received: from mail-yw0-f103.google.com ([209.85.211.103])
	by 1b2kzd1.ch3.sourceforge.com with esmtp (Exim 4.69)
	id 1MpmQo-0003sg-DJ
	for lurker-users@lists.sourceforge.net; Mon, 21 Sep 2009 17:12:11 +0000
Received: by ywh1 with SMTP id 1so355780ywh.23
	for <lurker-users@lists.sourceforge.net>;
	Mon, 21 Sep 2009 10:11:54 -0700 (PDT)
Received: by 10.90.211.6 with SMTP id j6mr3418453agg.86.1253553114183;
	Mon, 21 Sep 2009 10:11:54 -0700 (PDT)
Received: from buffy.phorce1.net (adsl-99-152-174-36.dsl.bumttx.sbcglobal.net
	[99.152.174.36])
	by mx.google.com with ESMTPS id 9sm8186agc.11.2009.09.21.10.11.52
	(version=SSLv3 cipher=RC4-MD5); Mon, 21 Sep 2009 10:11:53 -0700 (PDT)
Date: Mon, 21 Sep 2009 12:10:50 -0500
From: Gerald Livingston <gerald.lurker@sysmatrix.net>
To: lurker-users@lists.sourceforge.net
Message-ID: <20090921121050.22b934fb@buffy.phorce1.net>
In-Reply-To: <162de7480909210643x69bd7c78k1e0a2f3687d401d4@mail.gmail.com>
References: <20090918121221.32fb0bf2@buffy.phorce1.net>
	<4AB3D47B.40405@email.it>
	<20090918200132.754e488a@buffy.phorce1.net>
	<162de7480909191249v20605529vdf911a545a32e651@mail.gmail.com>
	<20090920174711.52f4e8eb@buffy.phorce1.net>
	<162de7480909210643x69bd7c78k1e0a2f3687d401d4@mail.gmail.com>
X-Mailer: Claws Mail 3.5.0 (GTK+ 2.12.12; i486-pc-linux-gnu)
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
X-Spam-Score: 0.0 (/)
X-Spam-Report: Spam Filtering performed by mx.sourceforge.net.
	See http://spamassassin.org/tag/ for more details. _SUMMARY_
X-Headers-End: 1MpmQo-0003sg-DJ
Subject: Re: [Lurker-users] Permissions errors
X-BeenThere: lurker-users@lists.sourceforge.net
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Lurker Project Support <lurker-users.lists.sourceforge.net>
List-Unsubscribe: <https://lists.sourceforge.net/lists/listinfo/lurker-users>, 
	<mailto:lurker-users-request@lists.sourceforge.net?subject=unsubscribe>
List-Archive: <http://sourceforge.net/mailarchive/forum.php?forum_name=lurker-users>
List-Post: <mailto:lurker-users@lists.sourceforge.net>
List-Help: <mailto:lurker-users-request@lists.sourceforge.net?subject=help>
List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/lurker-users>,
	<mailto:lurker-users-request@lists.sourceforge.net?subject=subscribe>
X-List-Received-Date: Mon, 21 Sep 2009 17:12:12 -0000

On Mon, 21 Sep 2009 15:43:05 +0200
"Wesley W. Terpstra" <wesley@terpstra.ca> wrote:

> On Mon, Sep 21, 2009 at 12:47 AM, Gerald Livingston <
> gerald.lurker@sysmatrix.net> wrote:
> 
> > > A better test would be to make your sell script:
> > > "touch /tmp/test-file". Then run it and see who
> > > created/owns /tmp/test-file.
> >
> > nobody:nogroup
> >
> 
> Well that would explain why you can't write to the lurker database.
> 
> LDA's like procmail require a local user so they can get around the
> > chroot.
> 
> 
> I'm not sure what you mean here. chroot has nothing to do with user
> accounts; it just changes the root directory.
> 
> 
> > I'm using ecartis as a mailing list manager and it "just works"
> > with nothing but aliases.
> > list1: "|/usr/lib/ecartis/ecartis -s list1"
> >
> 
> Interesting. Perhaps it's setuid? Or perhaps there is a setting
> somewhere else that instructs the MDA to setuid for it.


I'll be danged. I was so concentrated on lurker NOT working "out of the
box" that I failed to look at the things that DO work.

-rwsr-xr-x 1 ecartis daemon 199880 2006-04-14
18:36 /usr/lib/ecartis/ecartis

Is there a security reason that lurker is not setuid?

Gerald

P.S. Please reply to the list so answers are archived. No Cc: to me is
necessary. 



