Re: Security issue: $PATH _is_ set in pre-lock hook (Subversion 1.7)

2014-07-25 Thread Philip Martin
Julian Ruhe writes: > All of the sudden, starting somewhere prior to 1.7.13, the $PATH variable > is set, although the svnbook states > "For security reasons, the Subversion repository executes hook programs > with an empty environment—that is, no environment variables are set at all, > not even

Security issue: $PATH _is_ set in pre-lock hook (Subversion 1.7)

2014-07-24 Thread Julian Ruhe
All of the sudden, starting somewhere prior to 1.7.13, the $PATH variable is set, although the svnbook states "For security reasons, the Subversion repository executes hook programs with an empty environment—that is, no environment variables are set at all, not even $PATH (or %PATH%, under Windows)