Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 158339 - www-apps/dspam-web chgrps everything in the cgi-bin to dspam
Summary: www-apps/dspam-web chgrps everything in the cgi-bin to dspam
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Other
: High major
Assignee: Alin Năstac (RETIRED)
Depends on:
Reported: 2006-12-16 19:11 UTC by Lisa Seelye (RETIRED)
Modified: 2006-12-19 02:39 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Lisa Seelye (RETIRED) gentoo-dev 2006-12-16 19:11:44 UTC
in $FILES/setperms why is everything done blindly without checking if the files within cgi-bin actually belong to dspam-web? This will silently break all permissions a user may have set (and applications which rely on them).
Comment 1 Alin Năstac (RETIRED) gentoo-dev 2006-12-16 22:34:51 UTC
I usually install web applications in their own virtual host, especially those needing a cgi-bin dir.
How do you propose to check if a file belongs to dspam-web or not?
Comment 2 Lisa Seelye (RETIRED) gentoo-dev 2006-12-17 07:45:59 UTC
Not everyone has virtual hosts or wants to set them up.

Equery can get a list of files that belong to a given package. Or, hardcode the list of things in setperms.
Comment 3 Alin Năstac (RETIRED) gentoo-dev 2006-12-18 00:14:57 UTC
I will still have to change owner:group of the cgi-bin directory to dspam:dspam, otherwise apache will not be able to run dspam CGI scripts under this identity.

Are you OK with that? I can't imagine how you'll be able to run the other CGI scripts since both cgi-bin directory and CGI script must have the same owner:group when suexec is involved.
Comment 4 Alin Năstac (RETIRED) gentoo-dev 2006-12-19 02:39:28 UTC
After a long discussion on IRC, we both agreed it is currently impossible to install dspam-web on a site that has other cgi scripts.

I've added a warning about this in postinst. 

Bug closed as CANTFIX.