Re: Bug#388399: FTBFS problems on alpha, mips[el]: Please help debugging
- To: Ralf Stubner <email@example.com>
- Cc: firstname.lastname@example.org, Frank Küster <email@example.com>, firstname.lastname@example.org, email@example.com, firstname.lastname@example.org, email@example.com, firstname.lastname@example.org, Alex Owen <email@example.com>, Cyril Bouthors <firstname.lastname@example.org>
- Subject: Re: Bug#388399: FTBFS problems on alpha, mips[el]: Please help debugging
- From: Thiemo Seufer <email@example.com>
- Date: Sat, 30 Sep 2006 23:56:30 +0100
- Message-id: <20060930225630.GD30302@networkno.de>
- In-reply-to: <20060930181922.GC4508@thinkpad>
- References: <firstname.lastname@example.org> <email@example.com> <20060929103700.GD21205@mauritius.dodds.net> <firstname.lastname@example.org> <20060930055438.GG4726@mauritius.dodds.net> <email@example.com> <20060930160554.GB30302@networkno.de> <firstname.lastname@example.org> <20060930171240.GC30302@networkno.de> <20060930181922.GC4508@thinkpad>
Ralf Stubner wrote:
> On Sat, Sep 30, 2006 at 18:12 +0100, Thiemo Seufer wrote:
> > Frank Küster wrote:
> > > Thiemo Seufer <email@example.com> wrote:
> > > >
> > > > So, if I understand that correctly, the bug was fixed by running mktexmf
> > > > as non-root, and the change of the cache location is only a collateral.
> > >
> > > No, or I do not understand what you mean.
> > I meant the the earlier security bug you mentioned. To me, the solution
> > for the earlier bug as well as the current one looks like keeping the
> > font cache in /var but maintaining it via a mktexmf user.
> The problem is that mktexmf is a shell script (=no suid possible) that
> is started with the rights of the user. So the former solution required
> all users that wanted to use TeX to have write access below
Then I fail to understand
a) why the old solution was a security problem when it does something
similiar to e.g. /var/mail, and leaves the root-reserved part of
the filesystem free,
b) why moving the cache to $HOME or /tmp fixed the problem, given
that all three probably reside on the same partition.