[Debconf-devel] Bug#511893: ucf stores diff (of private files) in debconf (world readable)

Joey Hess joeyh at debian.org
Thu Jan 22 18:31:38 UTC 2009


Colin Watson wrote:
> Joey, what do you think of this? I'd rather not add a new database
> unilaterally.

I don't like special casing ucf in debconf. I suppose we could add a
Sensative: true field and filter questions with that set to a separate
database.

I think I prefer the approach of ucf ensuring the data is cleared out of
debconf before it has a chance to store it to disk. The only risk in
that approach is that it's possible to write a DbDriver that stores
the data after every set, rather than at the end -- but none of the
existing ones do.

Changing ucf seems like the quickest fix also.

-- 
see shy jo
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: Digital signature
Url : http://lists.alioth.debian.org/pipermail/debconf-devel/attachments/20090122/92b6bc72/attachment.pgp 


More information about the Debconf-devel mailing list