Do all the things like ++ or -- rants, post your own rants, comment on others' rants and build your customized dev avatarSign Up
IntrusionCM327557dPrivateTmp is insane.
I'd similar issues....
Voxera818656dAs its a breaking change it should come with a big warning and unless being actively exploited be default off.
IntrusionCM327556d@Aldar one lil thing: the _upstream_ maintainers (Apache) do provide via a module a system unit.
The _debian_ (or downstream) maintainers integrate (or create) this file with modifications.
The trouble stems from SystemD: Downstream doesn't want to deviate from default behaviour, since it is a maintainer burden (they'd need to d
decide and support every deviation, and there _will_ always be a negative backslash, since some will not like the decision made).
Upstream could make a decision, but it would require that SystemD becomes a dependency with a minimum version requirement - the version in which PrivateTmp was introduced.
I think SystemD is at fault here. While additional features might be nice, they shit on version compatibility / semantic versioning.
Such a breaking change by default might be security wise great. But it fucks downstream and upstream in the worst kind possible.
Fast-Nop2864456dSo you disabled that SystemD feature, right?
halfflat227056dFirst they came for the core files...
Aldar82956d@IntrusionCM if I understand you correctly, then it means private tmp is... On by default? And neither upstream (Apache Foundation), nor Downstream (Package maintainers) would dare to change it for reasons you put forth? It... Does make sense, but I didn't know this would be on, by default...
@Fast-Nop in a way, not by modifying the package's unit file, but by adding an override into /etc/systemd/system/apache2.service.d/no-private-tmp.conf
This way, the package's unit file may change yet this modification would remain.
Root6719256dHaving a web server depend on a particular init system is sheer madness.
"friday afternoon [...] have just migrated"
oh boiii, here we go again =D
jsPaysMyBills27When you have something in your clipboard but then press Ctrl+C instead of Ctrl+V and end up with a blank line...
Dacexi24When there are only 2 pages on Google you know you're in serious shit.
practiseSafeHex21Fixing a parents iPhone, episode 1. Problem: "Whatsapp is gone off my phone" Debugging: Me: *unlocks phone...