aboutsummaryrefslogtreecommitdiffstats
path: root/chapter07/changingowner.xml
blob: 2bc57d3045750974d5f81176774dc12c524bdaff (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
<?xml version="1.0" encoding="ISO-8859-1"?>
<!DOCTYPE sect1 PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
  "http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
  <!ENTITY % general-entities SYSTEM "../general.ent">
  %general-entities;
]>

<sect1 id="ch-tools-changingowner">
  <?dbhtml filename="changingowner.html"?>

  <title>Changing Ownership</title>

  <note>
    <para>The commands in the remainder of this book must be performed while
    logged in as user <systemitem class="username">root</systemitem> and no
    longer as user <systemitem class="username">lfs</systemitem>. Also, double
    check that <envar>$LFS</envar> is set in <systemitem
    class="username">root</systemitem>'s environment.</para>
  </note>

  <para>Currently, the whole directory hierarchy in <filename
  class="directory">$LFS</filename>
  is owned by the user <systemitem class="username">lfs</systemitem>, a user
  that exists only on the host system. If the directories and files under <filename
  class="directory">$LFS</filename> are kept as they are, they will be
  owned by a user ID without a corresponding account. This is dangerous because
  a user account created later could get this same user ID and would own all
  the files under <filename class="directory">$LFS</filename>, thus exposing
  these files to possible malicious manipulation.</para>

  <para>To address this issue, change the
  ownership of the <filename class="directory">$LFS/*</filename> directories to
  user <systemitem class="username">root</systemitem> by running the following
  command:</para>

<screen><userinput>chown -R root:root $LFS/{usr,lib,var,etc,bin,sbin,tools}
case $(uname -m) in
  x86_64) chown -R root:root $LFS/lib64 ;;
esac</userinput></screen>

  <para arch="ml_32,ml_x32,ml_all">Some more directories exists for
  multilib support. Change their ownership, too:</para>
<screen arch="ml_32,ml_x32,ml_all"><userinput arch="ml_32,ml_all">chown -R root:root $LFS/lib32</userinput>
<userinput arch="ml_x32,ml_all">chown -R root:root $LFS/libx32</userinput></screen>
  
</sect1>