GNU bug report logs -
#38422
.png files in /gnu/store with executable permissions (555)
Previous Next
Reported by: Bengt Richter <bokr <at> bokr.com>
Date: Fri, 29 Nov 2019 08:01:01 UTC
Severity: normal
Tags: notabug
Done: zimoun <zimon.toutoune <at> gmail.com>
Bug is archived. No further changes may be made.
Full log
Message #47 received at 38422 <at> debbugs.gnu.org (full text, mbox):
Dear Bengt,
The bug report [1] points out files with unexpected permission; based
on extension filename.
[1] https://debbugs.gnu.org/cgi/bugreport.cgi?bug=38422
It is not an security issue or the Guix packager did not carefully
check the validity of these files.
If you are security paranoid, you *have to* check by yourself all the
files using "guix build -S" because in paranoid mode you cannot trust
Guix packagers (and Guix committers neither).
In normal mode, 2 options:
a- propose a patch to change the permission for each offending package
b- report upstream
Well, at least these 3 packages docbook-xsl, faba-icon-theme, and
moka-icon-theme comes with unexpected .png file permission.
On the long term, I am not convinced that adding automatic check and
permission change based on filename extension would really add Quality
Assurance. Because we are speaking about quality, not security.
I am inclined to close this bug. What do you think?
All the best,
simon
This bug report was last modified 5 years and 111 days ago.
Previous Next
GNU bug tracking system
Copyright (C) 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd,
1994-97 Ian Jackson.