Package: duc Version: 1.4.6-1 Severity: wishlist as per subject
One of the tricky aspects might be where the DB should live, and who should own it. THe default for -d (from the man page) is ~/.duc.db. Would .e.g "duc index -x -d /var/cache/duc/duc.db /" be safe to run as uid=0? Could it be hugely constrained (seccomp etc) to add assurance?

