On 2019-02-12 Brian May <b...@debian.org> wrote:
> On Thu, Feb 07, 2019 at 06:53:18PM +0100, Andreas Metzler wrote:
>>> I was planning a new upload during this week (the version in sid, will
>>> not migrate as is due to a regression in dgit's autopkgtests), but can
>>> postpone it a few days until you've uploaded exim.

>> Thanks for the offer, I have just uploaded a fix for exim, so it will
>> not be necessary.

> How did you fix the problem for exim?

> I have a suspicion that amavisd-new drops privileges immediately (isn't
> this considered good behaviour?) so cannot write the pid file as root.

> As a result, I don't know how to fix #921016.

Hello,
You will need to limit the processes that s-s-d in considering for
killing, otherwise the amasvis user could kill arbitrary processes by
listing them in the pid file. For exim I am now passing --exec
/path/to/daemon as argument to s-s-d

https://salsa.debian.org/exim-team/exim4/commit/7d69adc64e5006ce1d033acbd51681dc8aa3640d

Alternatively (or additionally) setting --user should also work.

hth, cu Andreas
-- 
`What a good friend you are to him, Dr. Maturin. His other friends are
so grateful to you.'
`I sew his ears on from time to time, sure'

Reply via email to