[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#144571: dpkg-source invokes tar without --no-same-owner

On Fri, Apr 26, 2002 at 02:41:27AM +0200, Marcus Brinkmann wrote:
> Package: dpkg-dev
> Version: 1.9.20
> Hi,
> when extracting tar files, --no-same-owner is the default for everyone
> except root.  This means that dpkg-source -x used as root will produce
> more or less random uids/gids on the files and directories it extracts.

Not random, as marcus points out in his next email to the bug.

It's a bit weird, I concede, but surely dpkg-source is not the kind of
command you should be running as root anyhow?  Running arbitrary
commands as root often leads to security problems...


To UNSUBSCRIBE, email to debian-dpkg-request@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org

Reply to: