https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=25481

--- Comment #6 from David Cook <dc...@prosentient.com.au> ---
(In reply to Jonathan Druart from comment #2)
> Since D10, the behaviour of start-stop-daemon changed, see from its
> manual:
> """
> Warning:  using this match option with a world-writable pidfile or using it
> alone with a daemon that writes the pidfile as an unprivileged (non-root)
> user will be refused with an error (since
> version 1.19.3) as this is a security risk, because either any user can
> write to it, or if the daemon gets compromised, the contents of the pidfile
> cannot be trusted, and  then  a  privileged
> runner (such as an init script executed as root) would end up acting on any
> system process.  Using /dev/null is exempt from these checks.
> """

Oh right... that makes sense. Nevermind me... 😓

-- 
You are receiving this mail because:
You are watching all bug changes.
_______________________________________________
Koha-bugs mailing list
Koha-bugs@lists.koha-community.org
https://lists.koha-community.org/cgi-bin/mailman/listinfo/koha-bugs
website : http://www.koha-community.org/
git : http://git.koha-community.org/
bugs : http://bugs.koha-community.org/

Reply via email to