WelcomeWelcome | FAQFAQ | DownloadsDownloads | WikiWiki

Author Topic: seatd & copy2fs.flg  (Read 872 times)

Offline aus9

  • Full Member
  • ***
  • Posts: 114
Re: seatd & copy2fs.flg
« Reply #15 on: January 26, 2026, 05:36:00 PM »
M-A-X
Please provide evidence that seatd with SUID set reports vulnerabilities. I can find none.
But I wonder if your reasons are clear to me.

Anyone with access to the sudo command can do anything. You do understand this right?
Code: [Select]
file /usr/bin/sudo
/usr/bin/sudo: setuid executable, regular file, no read permission
ls -al /usr/bin/sudo
---s--x--x    1 root     root        148148 Jan 25 00:07 /usr/bin/sudo

If I understand your fear of SUID correctly then I suggest you create a root password and add it to persistence
(2) modify your rootfs and delete sudo from it so that
(3) any root power you need needs
Code: [Select]
su
<input intended command>

If Juanito or anyone else....when I submit my updated seatd....feels I am damaging the reputation of Tinycore
I will have to accept their judgement. I have a history of spitting the dummy that Rich knows too well.
I am the original packager of seatd, and feel your questioning on my lack of security is unfair when you are using sudo so freely.
« Last Edit: January 26, 2026, 05:37:37 PM by aus9 »

Offline Rich

  • Administrator
  • Hero Member
  • *****
  • Posts: 12514
Re: seatd & copy2fs.flg
« Reply #16 on: January 26, 2026, 08:52:34 PM »
Hi aus9
my bad that not how I made it ....it reads ...
That looks good.

M-A-X
Please provide evidence that seatd with SUID set reports vulnerabilities. I can find none. ...
He said nothing about vulnerabilities. Read his post again:
https://forum.tinycorelinux.net/index.php/topic,27984.msg181184.html#msg181184

He mentions a potential for bugs, which did occur and is being addressed by this thread.
And he basically said typing  sudo  is not a burden.

Offline M-A-X

  • Newbie
  • *
  • Posts: 4
Re: seatd & copy2fs.flg
« Reply #17 on: January 27, 2026, 05:30:40 AM »
... and feel your questioning on my lack of security is unfair when you are using sudo so freely.

My apologies, this was not my intention.

The manpage of seatd-launch gives the following statement:

Quote
seatd requires root privileges to perform its tasks. This can be achieved
through SUID of seatd-launch or by running seatd-launch as root. seatd-launch
will drop privileges from the effective user to the real user before running
the specified command. If the real user is root, this is simply a noop. You
should only run seatd-launch as root if you intend for the specified command to
run as root as well.

Now I understand why it makes sense to assign SUID permission to seatd-launch.

Offline aus9

  • Full Member
  • ***
  • Posts: 114
Re: seatd & copy2fs.flg
« Reply #18 on: January 27, 2026, 08:03:06 PM »
M-A-X
are you using the main repo or a mirror?
If you are using a mirror...and if my submission ....will take a while to process....lands....you could use your web browser to view the info and md5 contents
and clicking the TCE will download it

If using a member, and forgive me if you already know this but you are a new member bookmark this
http://tinycorelinux.net/16.x/x86_64/tcz/seatd.tcz.info
when that date changes....edit to strip .info and download magic should start

cheers

« Last Edit: January 27, 2026, 08:33:53 PM by aus9 »

Offline gadget42

  • Hero Member
  • *****
  • Posts: 1013
Re: seatd & copy2fs.flg
« Reply #19 on: January 28, 2026, 04:35:08 AM »
...
http://tinycorelinux.net/16.x/x86_64/tcz/seatd.tcz.info
when that date changes....edit to strip .info and download magic should start
wanted to confirm that the above quoted "when that date changes" was intended to be the word "date" as opposed to "data"
(yes, a date change would technically be a data change)

thanks
** WARNING: connection is not using a post-quantum kex exchange algorithm.
** This session may be vulnerable to "store now, decrypt later" attacks.
** The server may need to be upgraded. See https://openssh.com/pq.html
** Also see: post quantum internet 2025 - https://blog.cloudflare.com/pq-2025/

Offline aus9

  • Full Member
  • ***
  • Posts: 114
Re: seatd & copy2fs.flg
« Reply #20 on: January 28, 2026, 08:52:04 AM »
M-A-X
Update has landed for 16x and 17x  main repos.
If it works for you, can you reply that it does....and we can then ask Rich to mark as solved.

Altho I have tested it....I am not a coder....which is why I make more mistakes than I like
but yes I lacked imagination so did not design the older version for copy2fs members

Good luck testing