[Debian-med-packaging] Bug#689855: ensembl: configuration files in /usr/share/ensembl/**/conf

Ansgar Burchardt ansgar at debian.org
Sun Oct 7 08:58:57 UTC 2012


Package: src:ensembl
Version: 63-1
Severity: serious

ensembl.postinst modifies

  /usr/share/ensembl/conf/Plugins.pm
  /usr/share/ensembl/public-plugins/mirror/conf/SiteDefs.pm

so these tiles seem to be configuration files and should not be located
in /usr.

I'm also not sure if the current use of debconf in ensembl.postinst
preserves changes to these files as it seems to unconditionally
overwrite database access information with values from debconf.
Also passwords are passed as command-line arguments in ensembl.postinst
which makes them visible in the process list.

Ansgar



More information about the Debian-med-packaging mailing list