Xref: utzoo comp.bugs.sys5:1380 comp.unix.internals:1626 Path: utzoo!utgpu!news-server.csri.toronto.edu!cs.utexas.edu!tut.cis.ohio-state.edu!att!cbnewsl!cbnewsk!pegasus!hansen From: hansen@pegasus.att.com (Tony L. Hansen) Newsgroups: comp.bugs.sys5,comp.unix.internals Subject: Re: empty mailbox deletion and /bin/mail forwarding bug Summary: SVr4 mail gets it right Keywords: chown, mail Message-ID: <1990Dec23.041949.24642@cbnewsk.att.com> Date: 23 Dec 90 04:19:49 GMT References: <1990Dec16.221025.24838@chinet.chi.il.us> <1990Dec20.182455.17753@eci386.uucp> <1990Dec21.165501.27889@chinet.chi.il.us> Sender: hansen@cbnewsk.att.com (tony.l.hansen) Organization: AT&T Bell Laboratories Lines: 15 < But wait - there's more! < At least one of the replacement mailers will: < (A) allow forwarding to programs when "|command" is found in the < forwarding file. < (B) run the program under the uid of the recipient of the message. < (C) perform a security check before doing (B), based on the ownership < of the forwarding file. The SVr4 mail program gets it right. It does the right thing in setting up mailboxes, setting up forwarding (including forwarding to |command), and does it all with chown() enabled on the system. Tony Hansen att!pegasus!hansen, attmail!tony hansen@pegasus.att.com