Skip Menu |
 

This queue is for tickets about the activitymail CPAN distribution.

Report information
The Basics
Id: 5733
Status: resolved
Priority: 0/
Queue: activitymail

People
Owner: dwheeler [...] cpan.org
Requestors: wkallander [...] quietwisdom.com
Cc:
AdminCc:

Bug Information
Severity: Normal
Broken in: 1.19
Fixed in: (no value)



Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
X-Mailer: MIME-tools 5.405 (Entity 5.404)
Subject: -g option can cause "Insecure dependency in open while running setgid" at line 134
X-RT-Original-Encoding: iso-8859-1
Content-Length: 932
Download (untitled) / with headers
text/plain 932b
This only happens under certain circumstances. We managed to get this error when we did the following: --CVSROOT/commitinfo has the following line: DEFAULT $CVSROOT/CVSROOT/activitymail -Q -lg --CVSROOT/loginfo has the following line: DEFAULT $CVSROOT/CVSROOT/activitymail -Q -cdagf %{sVv} -t user@example.com 1. checkout a module as root, edit files, and cvs update to make sure the files merge 2. su <user> 3. cvs commit the edited files When that procedure is followed, the pre-commit check fails saying: prompt$ cvs commit cvs commit: Examining . Insecure dependency in open while running setgid at /usr/local/cvs-rep/root/CVSROOT/activitymail line 134. cvs commit: Pre-commit check failed cvs [commit aborted]: correct above errors first! Now I know it is 'evil' to switch users, but we must, since only the root user may edit the CVSROOT, and root cannot commit to cvs... Its a strange setup, but we have to live w/ it.
Return-Path: <david [...] kineticode.com>
Delivered-To: cpan-bug+activitymail [...] pallas.eruditorum.org
Received: from geertz.kineticode.com (dsl092-190-153.sfo1.dsl.speakeasy.net [66.92.190.153]) by pallas.eruditorum.org (Postfix) with ESMTP id 1E865112E1 for <bug-activitymail [...] rt.cpan.org>; Sat, 20 Mar 2004 14:09:29 -0500 (EST)
Received: from [127.0.0.1] (localhost [127.0.0.1]) by geertz.kineticode.com (Postfix) with ESMTP id 401A91792F7 for <bug-activitymail [...] rt.cpan.org>; Sat, 20 Mar 2004 11:09:26 -0800 (PST)
MIME-Version: 1.0 (Apple Message framework v612)
In-Reply-To: <rt-5733-17045.6.00977043000768 [...] cpan.org>
References: <rt-5733-17045.6.00977043000768 [...] cpan.org>
Content-Type: text/plain; charset=US-ASCII; format=flowed
Message-Id: <1A821F7E-7AA2-11D8-8F14-000A95972D84 [...] kineticode.com>
Content-Transfer-Encoding: 7bit
From: David Wheeler <david [...] kineticode.com>
Subject: Re: [cpan #5733] -g option can cause "Insecure dependency in open while running setgid" at line 134
Date: Sat, 20 Mar 2004 11:09:25 -0800
To: bug-activitymail [...] rt.cpan.org
X-Mailer: Apple Mail (2.612)
RT-Send-Cc:
X-RT-Original-Encoding: us-ascii
Content-Length: 576
Download (untitled) / with headers
text/plain 576b
On Mar 19, 2004, at 11:48 AM, Guest via RT wrote: Show quoted text
> Insecure dependency in open while running setgid at > /usr/local/cvs-rep/root/CVSROOT/activitymail line 134. > cvs commit: Pre-commit check failed > cvs [commit aborted]: correct above errors first! > > Now I know it is 'evil' to switch users, but we must, since only the > root user may edit the CVSROOT, and root cannot commit to cvs... Its > a strange setup, but we have to live w/ it.
I don't know much about switching users and setgid mode. Can you run activitymail so it's not in setgid mode? Regards, David
MIME-Version: 1.0
X-Mailer: MIME-tools 5.418 (Entity 5.418)
Content-Disposition: inline
Message-Id: <rt-3.5.HEAD-28128-1144108676-1761.5733-0-0 [...] rt.cpan.org>
Content-Type: text/plain; charset="utf8"
Content-Transfer-Encoding: binary
X-RT-Original-Encoding: utf-8
X-RT-Original-Encoding: utf-8
Content-Length: 41
No reply after two years, so I'm closing.


This service is sponsored and maintained by Best Practical Solutions and runs on Perl.org infrastructure.

Please report any issues with rt.cpan.org to rt-cpan-admin@bestpractical.com.