Re: Bug#388399: FTBFS problems on alpha, mips[el]: Please help debugging
- To: Thiemo Seufer <ths@networkno.de>, 388399@bugs.debian.org
- Cc: Frank Küster <frank@kuesterei.ch>, alpha@buildd.debian.org, debian-alpha@lists.debian.org, mipsel@buildd.debian.org, debian-mips@lists.debian.org, mips@buildd.debian.org, Alex Owen <r.alex.owen@gmail.com>, Cyril Bouthors <cyb@debian.org>
- Subject: Re: Bug#388399: FTBFS problems on alpha, mips[el]: Please help debugging
- From: Ralf Stubner <ralf.stubner@web.de>
- Date: Sat, 30 Sep 2006 20:19:22 +0200
- Message-id: <[🔎] 20060930181922.GC4508@thinkpad>
- In-reply-to: <[🔎] 20060930171240.GC30302@networkno.de>
- References: <20060923102215.GC8904@thinkpad> <86bqp3f0w5.fsf_-_@alhambra.kuesterei.ch> <[🔎] 86r6xvgiib.fsf@alhambra.kuesterei.ch> <20060929103700.GD21205@mauritius.dodds.net> <[🔎] 86wt7mgb2l.fsf@alhambra.kuesterei.ch> <[🔎] 20060930055438.GG4726@mauritius.dodds.net> <[🔎] 86irj5r999.fsf@alhambra.kuesterei.ch> <[🔎] 20060930160554.GB30302@networkno.de> <[🔎] 861wptp9m0.fsf@alhambra.kuesterei.ch> <[🔎] 20060930171240.GC30302@networkno.de>
On Sat, Sep 30, 2006 at 18:12 +0100, Thiemo Seufer wrote:
> Frank Küster wrote:
> > Thiemo Seufer <ths@networkno.de> wrote:
> > >
> > > So, if I understand that correctly, the bug was fixed by running mktexmf
> > > as non-root, and the change of the cache location is only a collateral.
> >
> > No, or I do not understand what you mean.
>
> I meant the the earlier security bug you mentioned. To me, the solution
> for the earlier bug as well as the current one looks like keeping the
> font cache in /var but maintaining it via a mktexmf user.
The problem is that mktexmf is a shell script (=no suid possible) that
is started with the rights of the user. So the former solution required
all users that wanted to use TeX to have write access below
/var/cache/fonts. In addition for buildds the default now-questions-
asked installation had to have directories below /var/cache/fonts with
world write access. We had a system to restrict these rights to some
group, but the debconf question and code were quite complicated and
confused many users.
cheerio
ralf
Reply to: