On Fri, Jun 23, 2006 at 11:19:57AM -0500, Graham Wilson wrote: > On Fri, Jun 23, 2006 at 10:13:42AM -0500, Richard A. Smith wrote: > > Newer darcs appear to have a predictable temp filename on record. Isn't > > this a security problem? > > Is it actually a file in a sticky directory (e.g. tmp), or is it in the > _darcs directory? The former is perfectly fine (unless you don't trust > yourself), but the latter is certainly a problem.
How would having it in /tmp be a problem, as long as your permissions are sane? (And assuming that darcs is smart about how it creates files and sets permissions, which I think it is) -- Zachary P. Landau <[EMAIL PROTECTED]> GPG: gpg --recv-key 0xC9F82052 | http://divineinvasion.net/kapheine.asc
signature.asc
Description: Digital signature
_______________________________________________ darcs-users mailing list [email protected] http://www.abridgegame.org/mailman/listinfo/darcs-users
