# from Aristotle Pagaltzis
# on Monday 22 September 2008 21:53:

>> Don't run them as yourself either then!
>
>I don’t like my module library disappearing *either*.

Yes, but if you set your umask, then the arbitrary code in question is 
on the CPAN and can be taken down from there.  (That's the 'front door' 
to which Schwern was referring and we've all known about it for a long 
time.)

But yes, stowpan should probably have a per-file copy+chown+chmod before 
the stow so that the library isn't writable by the 'stowpan' user.

And anyway, having to reinstall something which is widely mirrored on 
the internet sure beats having to recover your own files (which, 
presumably are not.)

--Eric
-- 
But you can never get 3n from n, ever, and if you think you can, please
email me the stock ticker of your company so I can short it.
--Joel Spolsky
---------------------------------------------------
    http://scratchcomputing.com
---------------------------------------------------

Reply via email to