Source: aide
Version: 0.19.2-3
Usertags: pidof-without-procps

Dear maintainer(s) of aide,

it appears that aide uses `pidof` in its testsuite, or that
at least one of its binary packages uses `pidof` at runtime.
Historically, `pidof` was provided by the Essential package
`sysvinit-tools`, making an explicit dependency unnecessary. However
`pidof` will soon be moved to `procps` and will no longer be part of
the Essential set.

Please add an explicit dependency on `procps`:

* via the `Depends:` field of all binary packages of aide
  that use `pidof` at runtime;
* via the `Build-Depends:` field of aide, if `pidof` is
  used in tests run at build-time;
* via the `Depends:` field of `debian/control/tests`, if `pidof` is
  used in autopkgtests.

To prevent any disruption for users of aide, please add
this dependency now, before `pidof` is moved from `sysvinit-utils` to
`procps`. Alternatively, you could remove all uses of `pidof`.

It is believed that aide uses `pidof` due to the following
code snippets:

```
path: aide_0.19.2-3/debian/bin/dailyaidecheck
    if [ -n "${LOCKED:-}" ]; then
        # we have the lock, 
        pidof aide | xargs --no-run-if-empty kill -9
    fi
    if type -t onexit >/dev/null; then


path: aide_0.19.2-3/debian/aide.conf.d/31_aide_torrus
CPID="$(pidof collector)"
if [ "${CPID}" ]; then
  printf "!/var/log/torrus/dbenv_errlog_%d$ f\\n" "$(pidof collector)"
fi
printf " /var/log/torrus$ d VarDir\\n"


path: aide_0.19.2-3/debian/aide.conf.d/31_aide_torrus
printf "!/var/lib/torrus/session_data/lock/Apache-Session-[0-9a-f]{32}\\.lock$ 
f\\n"
printf " /var/lib/torrus/session_data/(store|lock)$ d VarDir\\n"
CPID="$(pidof collector)"
if [ "${CPID}" ]; then
  printf "!/var/log/torrus/dbenv_errlog_%d$ f\\n" "$(pidof collector)"
```

Feel free to close this issue if this is a false positive (for example
if this code is in an unreachable code path).

Regards,

-- 
Gioele Barabucci

Reply via email to