Hi Ondřej,

Ondřej Surý schreef op 2026-07-30 16:46:
Control: severity -1 wishlist
Control: tags -1 +wontfix

Hi,

I don't think this is a good idea. The defaults should be secure, but wide enough.

Not to be rebellious, but out of genuine interest: what 'security' does `ProtectHome` provide in the sessionclean scenario?


This is obviously problematic when storing session files in /home/, which is not uncommon.

I would actually dispute this. I don't think this is common at all. If you change the defaults where the session files are stored, you might as well change the systemd unit that cleans
the session files.

Fair enough. I guess 'common in the web hosting space' does not equate to 'common'. And yes, creating an override is not a problem at all.


Cheers,
Ondrej
--
Ondřej Surý (He/Him)
[email protected]

A gentle nudge is always appreciated if I take a little longer to reply.

On 30. 7. 2026, at 15:36, William David Edwards <[email protected]> wrote:

Package: php-common
Version: 2:96

`phpsessionclean.service` (which runs `/usr/lib/php/sessionclean`) contains `ProtectHome=true`. This is obviously problematic when storing session files in /home/, which is not uncommon. Due to systemd's implementation details (exposing /home/ but simply returning an empty directory listing), this causes session files to not be cleaned up. The cleanup process effectively fails silently.

I therefore urge the package maintainers to re-consider the default ProtectHome behaviour, especially seeing as how I'm unsure why this setting is necessary (protecting against too broad `find -delete`s)?

Met vriendelijke groeten,

William David Edwards

Met vriendelijke groeten,

William David Edwards

Reply via email to