[buildd-tools-devel] Bug#825991: sbuild: /etc/sbuild/sbuild.conf leaks the user home path

Aurelien Jarno aurel32 at debian.org
Wed Jun 1 07:53:37 UTC 2016


Package: sbuild
Version: 0.69.0-2
Severity: minor

Dear Maintainer,

The default sbuild.conf shipped with the sbuild package is generated
using the "sbuild-dumpconfig sbuild config" command. This causes the
stats_dir entry to contain the home path of the user who has build the
package:

| # STATS_DIR
| # Type: STRING
| # Directory for writing build statistics to
| # See also related command line options in sbuild(1):
| #   --stats-dir
| #$stats_dir = '/home/aurel32/stats';

Fortunately as sbuild is usually built on the build daemons,
/home/buildd/stats is used, which makes more sense.

Aurelien


-- System Information:
Debian Release: stretch/sid
  APT prefers testing
  APT policy: (990, 'testing'), (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.6.0-trunk-amd64 (SMP w/4 CPU cores)
Locale: LANG=fr_FR.UTF-8, LC_CTYPE=fr_FR.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages sbuild depends on:
ii  adduser         3.114
ii  apt-utils       1.2.12
ii  libsbuild-perl  0.69.0-2
ii  perl            5.22.2-1

Versions of packages sbuild recommends:
ii  debootstrap  1.0.81
ii  fakeroot     1.20.2-1

Versions of packages sbuild suggests:
ii  deborphan  1.7.28.8-0.3
ii  wget       1.17.1-2

-- no debconf information



More information about the Buildd-tools-devel mailing list