Hi,

Quoting Christian Seiler (2016-02-15 16:30:26)
>  - the other services that use ExecStart=/bin/sh bin/$NAME start
>    and ExecStop=/bin/sh bin/$NAME stop are problematic, because
>    in the systemd service file you declare PIDFile to be in
>    /run/gitlab, while the configuration that's read by the gitlab
>    scripts assumes the path is in /usr/share/gitlab/tmp/pids
>    (which btw. violates Debian policy, /usr should never be
>    modified during normal program execution [1]).
> 
> [...]
> 
> [1] I also noted that all files in /usr/share/gitlab belong to the
> gitlab user, which means that gitlab could in principle replace the
> code there. This is problematic from a Debian policy point of view.

this problem (violation of policy ยง9.1.1 aka FHS 2.3 compliance) is tracked in
bug #814476

Thanks!

cheers, josch

Attachment: signature.asc
Description: signature

Reply via email to