Control: severity -1 wishlist Control: tags -1 +wontfix Hi,
I don't think this is a good idea. The defaults should be secure, but wide enough. > This is obviously problematic when storing session files in /home/, which is > not uncommon. I would actually dispute this. I don't think this is common at all. If you change the defaults where the session files are stored, you might as well change the systemd unit that cleans the session files. Cheers, Ondrej -- Ondřej Surý (He/Him) [email protected] A gentle nudge is always appreciated if I take a little longer to reply. > On 30. 7. 2026, at 15:36, William David Edwards <[email protected]> > wrote: > > Package: php-common > Version: 2:96 > > `phpsessionclean.service` (which runs `/usr/lib/php/sessionclean`) contains > `ProtectHome=true`. This is obviously problematic when storing session files > in /home/, which is not uncommon. Due to systemd's implementation details > (exposing /home/ but simply returning an empty directory listing), this > causes session files to not be cleaned up. The cleanup process effectively > fails silently. > > I therefore urge the package maintainers to re-consider the default > ProtectHome behaviour, especially seeing as how I'm unsure why this setting > is necessary (protecting against too broad `find -delete`s)? > > Met vriendelijke groeten, > > William David Edwards

