Re: Cleaning /tmp regularly using bootclean.sh + crond



On Friday 17 February 2006 09:22, Joey Hess wrote:
Josep Serrano wrote:
Yes, tmpreaper does the job. But here I was preteding to simply reuse the
bootclean.sh by simply making a symlink. Why installing an addittional
package if you already have the stuff to the the job?

Maybe I am wrong and it is a bad idea using bootclean.sh in crond ?

bootclean.sh is not secure for use on multiuser systems. It is very easy
to trick it into deleting files that are not in /tmp.

Note that tmpreaper is also insecure for use on multiuser systems,
despite the protestations of its maintainer to the contrary.

Howso?

--
Paul Johnson
Email and IM (XMPP & Google Talk): baloo@xxxxxxxxx
Jabber: Because it's time to move forward http://ursine.ca/Ursine:Jabber


--
To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx
with a subject of "unsubscribe". Trouble? Contact listmaster@xxxxxxxxxxxxxxxx



Relevant Pages

  • Re: Iceweasel does not use JRE
    ... Just because it's not in a .deb package does not make it evilbadscary. ... What I meant to say is that installing sun-java5-plugin should do ... Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: manually purge .deb file
    ... installing the deb file i hit cancel, somehow i cannot remove this file, dpkg, aptitute or apt-get says that my firefox packet should be removed but no file related to my firefox packet, ... I wasn't able to locate a file for the firefox-1.5.en-us.linux package. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx with a subject of "unsubscribe". ...
    (Debian-User)
  • Re: Auditing free and non-free packages
    ... You are welcome to disagree and use a package ... fonts, firmware, and some other program data from main -- but the beauty ... wireless firmware was a few clicks away for me by simply installing the ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: Re: Re: Repost-No Response-Fwd: Another APT Issue-Where Are The Linux-Images
    ... After adding testing to my sorces.list, updating and installing, ... were left in the cache(not sid kernels) but 2.6.15 was removed. ... install a package not in the cache file but he didn't come back to my response; ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx with a subject of "unsubscribe". ...
    (Debian-User)
  • Re: sarge freezes after failure of raid disk, incurring fs corruption on unrelated disk
    ... while installing an etch system -- and eventually I came to suspect the ... Is it common, that a failure of a raid disk leads to a system freeze, ... client processes freeze next time they try to access the NFS volume. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)