Control: severity -1 wishlist
Control: tags -1 +wontfix

Hi,

I don't think this is a good idea. The defaults should be secure, but wide 
enough.

> This is obviously problematic when storing session files in /home/, which is 
> not uncommon.

I would actually dispute this. I don't think this is common at all. If you 
change the defaults
where the session files are stored, you might as well change the systemd unit 
that cleans
the session files.

Cheers,
Ondrej
--
Ondřej Surý (He/Him)
[email protected]

A gentle nudge is always appreciated if I take a little longer to reply.

> On 30. 7. 2026, at 15:36, William David Edwards <[email protected]> 
> wrote:
> 
> Package: php-common
> Version: 2:96
> 
> `phpsessionclean.service` (which runs `/usr/lib/php/sessionclean`) contains 
> `ProtectHome=true`. This is obviously problematic when storing session files 
> in /home/, which is not uncommon. Due to systemd's implementation details 
> (exposing /home/ but simply returning an empty directory listing), this 
> causes session files to not be cleaned up. The cleanup process effectively 
> fails silently.
> 
> I therefore urge the package maintainers to re-consider the default 
> ProtectHome behaviour, especially seeing as how I'm unsure why this setting 
> is necessary (protecting against too broad `find -delete`s)?
> 
> Met vriendelijke groeten,
> 
> William David Edwards

Reply via email to