[Debian-med-packaging] Bug#689855: ensembl: configuration files in /usr/share/ensembl/**/conf
Ansgar Burchardt
ansgar at debian.org
Sun Oct 7 08:58:57 UTC 2012
Package: src:ensembl
Version: 63-1
Severity: serious
ensembl.postinst modifies
/usr/share/ensembl/conf/Plugins.pm
/usr/share/ensembl/public-plugins/mirror/conf/SiteDefs.pm
so these tiles seem to be configuration files and should not be located
in /usr.
I'm also not sure if the current use of debconf in ensembl.postinst
preserves changes to these files as it seems to unconditionally
overwrite database access information with values from debconf.
Also passwords are passed as command-line arguments in ensembl.postinst
which makes them visible in the process list.
Ansgar
More information about the Debian-med-packaging
mailing list