DerootificationStatus
DerootificationStatus
The following programs/processes were already successfully "derooted", i. e. the process does not run as root any more, or got its suid root bit removed:
- hald (accepted in Debian, accepted upstream)
- smbmount/smbumount (trivial packaging change, not really appropriate for Debian)
- jackd (Ubuntu patch effectively disables realtime feature by installing it non-suid)
gpg/gnupg (patch sent to Debian BTS); completely non-suid in Ubuntu, kernel 2.6.8+ supports mlock() as user
- hplip (accepted in Debian)
The following processes still appear to run with too many privileges by default and should be investigated:
- udevd
- power management daemons
- X
- arpwatch
- vsftpd
The following programs/processes were at one point "derooted" but now run as root:
DerootificationStatus (last edited 2011-03-05 06:08:39 by d1b)