[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: /etc/init.d scripts WAS: Re: start-stop-daemon on Debian (fwd)



On Sun, 18 Apr 1999, Raul Miller wrote:

> In general it's safer to fully specify root's $PATH rather than trust
> what was inherited from the parent.

And this policy changes what? The parents PATH would be inherited anyhow,
wouldn't it? So we're doing what to it that reduces security?

> If we could come up with a single canonical root path that was adequate
> for all packages that might be a good thing.  But even there you'd have
> to be very careful of edge conditions.

And that's why each script should set what it needs, in addition to what
it inherits. It inherits what it inherits now anyhow -- so why should that
be any problem (it's certainly not a change) for this?

-- 
Brock Rozen                                              brozen@torah.org
Director of Technical Services                              (410)358-9800
Project Genesis                                     http://www.torah.org/ 



Reply to: