Bug#764814: freecad downloads and executes code

Anton Gladky gladk at debian.org
Thu Oct 23 19:13:24 UTC 2014


Hi Yorik,

thanks for the patch! I tried to adopt it for the current
Debian freecad version, but you are right, there is a problem
to patch Draft_rc.py. Are there really necessary changes in this file
which needs to be done to fix the issue?

I am considering now to upload the latest git-version of FreeCAD, but
I have doubts whether it is a right solution. We are several days before freeze.
If I upload it with some problems, we do have again a chance not to
get FreeCAD in the stable Debian version. I would avoid that if
it is possible,

Thanks again

Anton


2014-10-18 19:27 GMT+02:00 Yorik van Havre <yorik at uncreated.net>:
> Hi Anton,
>
> I just committed[1] a fix to this problem. From now on, downloads are
> disabled by default. The fist time you want to use the DXF import or
> export feature, the user receives a message explaining him that
> he needs either to enable automatic downloads, via the freecad
> preferences settings, or to download the files himself.
>
> I think this will solve both debian's concerns (no download will
> ever happen without the user's explicit command, he will need to tick
> a checkbox) and the ease of the users (be able to use the DXF stuff
> without being bothered by this).
>
> The commit in question has been applied to the master branch
> of FreeCAD, which will become version 0.15. It won't be easily
> applied to the current 0.14 branch I'm afraid, because it
> modifies the resource file, which is always hard to patch.
>
> So I'm not sure what is neede for you, is it sufficient the
> way it is now? Or do you need to patch the version currently
> in debian too? If yes please tell me because  I'll need to issue
> a patch specific to that version...
>
> Cheers
> Yorik
>
> [1]
> http://github.com/FreeCAD/FreeCAD_sf_master/commit/bd1bbff874f5e5a86f4308aa2f840cbd64a77b77
>
>
>
>
>
> --
> debian-science-maintainers mailing list
> debian-science-maintainers at lists.alioth.debian.org
> http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/debian-science-maintainers



More information about the debian-science-maintainers mailing list