Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 233862

Summary: mail-filter/spamassassin ebuilds all disable perl taint mode
Product: Gentoo Linux Reporter: Wormo (RETIRED) <wormo>
Component: [OLD] ServerAssignee: Gentoo Perl team <perl>
Status: RESOLVED FIXED    
Severity: normal CC: bugs+gentoo
Priority: High    
Version: unspecified   
Hardware: All   
OS: All   
Whiteboard:
Package list:
Runtime testing required: ---
Attachments: spamassassin-3.2.5-r1.ebuild

Description Wormo (RETIRED) gentoo-dev 2008-08-04 01:05:12 UTC
There is a well-written comment in the spamassassin ebuilds that explains why taint mode was disabled:

    # If you are going to enable taint mode, make sure that the bug where
    # spamd doesn't start when the PATH contains . is addressed, and make
    # sure you deal with versions of razor <2.36-r1 not being taint-safe.
    # <http://bugzilla.spamassassin.org/show_bug.cgi?id=2511> and
    # <http://spamassassin.org/released/Razor2.patch>.

Neither of these problems apply any more: the oldest razor release in the tree is 2.77, and the bug with spamd and '.' in the PATH was fixed back in 2003 (not to mention hopefully people are not using '.' in the first place...)

So, we should take out this workaround and let spamassassin run in taint mode.

Reproducible: Always
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2008-08-04 07:32:54 UTC
Reassigning to maintainer.
Comment 2 David Abbott (RETIRED) gentoo-dev 2009-11-12 15:38:40 UTC
Created attachment 210034 [details]
spamassassin-3.2.5-r1.ebuild

Should let spamassassin run in taint mode.
Comment 3 David Abbott (RETIRED) gentoo-dev 2010-04-20 13:35:34 UTC
fixed in 3.3.1-r1