On Wed, Dec 10, 2008 at 18:49, James Y Knight <[EMAIL PROTECTED]> wrote: > > On Dec 10, 2008, at 5:55 AM, Lennart Regebro wrote: > >> Turns out, I created an empty time.py in /tmp, just to see the error >> message. By buildout will when creating eggs from checked out modules, >> copy them to a directory under /tmp, and evidently run python from >> /tmp to create the eggs. So that process finds the time.pyc, created >> from the empty time.py, which I hadn't deleted, and breaks! > > Sounds like a security hole in zc.buildout. Imagine someone *else* made a > time.py in /tmp...
Yup. Adam Olsen also reminded me of this, and I have filed a bug report. -- Lennart Regebro: Zope and Plone consulting. http://www.colliberty.com/ +33 661 58 14 64 _______________________________________________ Python-Dev mailing list Python-Dev@python.org http://mail.python.org/mailman/listinfo/python-dev Unsubscribe: http://mail.python.org/mailman/options/python-dev/archive%40mail-archive.com