Bug#407678: boinc-client: /etc/boinc-client files should be 640 root:boinc (passwd leakage)

Frank S. Thomas frank at thomas-alfeld.de
Mon Jan 29 18:52:24 CET 2007


On Tuesday 23 January 2007, Thibaut VARENE wrote:
> On 1/23/07, Steffen Moeller <moeller at inb.uni-luebeck.de> wrote:

> > I did not like so much that you did your own customised boinc-clients
> > rather than spending your energy on this Alioth project's code base.
> > Wouldn't you
> I don't think my changes are of any interest to anyone else. What my
> bastardized package does is installing boinc-client with customized
> configuration files so that it automagically connects to my BAM
> account through http proxy and fetches it's preference there. It's
> intended for mass deployment over a specific network of machines,
> certainly not something of use to anyone else :)

What does it take to mass deploy BOINC clients which use the same account? We 
could maybe add instructions for this to boinc-client's README.Debian and/or 
tweak the package to make this procedure easier.

> > like to join in as a developer? This smallish patch could be your first
> > action.
> If you need more hands I could probably give you some help, though my
> free time is gonna drop anytime soon (I'm in the process of finding a
> job, in an area that has nothing to do with IT/Computer Science and
> that is very time consumming) :)

Help is really much appreciated! I'm currently in a situation where I can't 
invest as much time as I'd like in maintaining the BOINC packages. And that 
is also the reason why I didn't answer most of your recent emails for which 
I'm sorry, especially if this let you feel like an annoying punk. :-)   

BTW: I'm ok with changing the permission of gui_rpc_auth.cfg but I'm not so 
sure about the other files. IIRC there were plans to let the BOINC Manager 
(or other BOINC monitoring/controlling tools) edit the contents of these 
files and I want to ensure that this is possible for users without to much 
hassle. Maybe 640 root:boinc for the gui_rpc_auth.cfg file and 660 
boinc:boinc for the other files would be a good choice.

"Die beiden Männer sonnten sich in dem herrlichen Gefühl, weitaus
weniger zu wissen als gewöhnliche Leute, die nur von gewöhnlichen
Dingen nichts wußten."
                   -- Terry Pratchett in "Das Erbe des Zauberers"
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
Url : http://lists.alioth.debian.org/pipermail/pkg-boinc-devel/attachments/20070129/a0802ab9/attachment.pgp

More information about the pkg-boinc-devel mailing list