* Peter Moulder 

| I believe that the reason for this is so that no `nobody'-owned process
| can read/write non-world-accessible files other than its own.  The above
| approach does achieve this result even though it does literally create a
| file as `nobody': no other non-root process can access the file.

That's not strictly true.  Another process running as nobody could
ptrace the wget process and do harm.

I'm going to make it download as nobody and check the md5sums as root
and throw a big warning if the md5sum doesn't match.  This should make
everybody happy, I just need the get a round tuit first.

-- 
Tollef Fog Heen                                                        ,''`.
UNIX is user friendly, it's just picky about who its friends are      : :' :
                                                                      `. `' 
                                                                        `-  


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to