[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [Debian-med-packaging] Bug#924128: prokka: creates world writable directory tree /var/lib/prokka/*



On Tue, Dec 10, 2019 at 07:46:29AM +0100, Olivier Sallou wrote:
> 
> > > Is making a "prokka" group to own this directory the only option?
> 
> Can't location be specified at runtime?

No.  Its a patch anyway.

> If yes, either user is root and there is no pb, either he should copy var/lib/prokka to a writable dir and specify location at runtime.
> 
> For a multi user env, it would be weird for a tool to allow anyone on server to modify a central db.
> Creating a group may not be enough. For reading, ok, but to modify a file (db) created by an other user, it depends on software, if filebus created in mode 77x ou 75x. If file is created in 75x even bein in group will not allow for modification

I perfectly agree.  What about approaching upstream about this?

Kind regards

   Andreas. 

-- 
http://fam-tille.de


Reply to: