juju deploy w/ local charm doesn't fail with non contained symlink

Bug #1227020 reported by Kapil Thangavelu
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
juju-core
Fix Released
Medium
Unassigned

Bug Description

a local charm had a symlink to a parent directory outside the charm.. and juju deploy of it succeeded... which it shouldn't have.. non local symlinks Should not be allowed in a charm, and should cause an appropriate error msg. 2 out of a classroom of 15 hit this..

Revision history for this message
John A Meinel (jameinel) wrote :

What if it is a symlink to a standard location like /etc/foobar ? I sort of agree, but I'm wondering if there is a genuine use case for symlinking a local name for a system entry.

Changed in juju-core:
importance: Undecided → High
status: New → Triaged
tags: added: papercut
Revision history for this message
Kapil Thangavelu (hazmat) wrote : Re: [Bug 1227020] [NEW] juju deploy w/ local charm doesn't fail with non contained symlink

Sym links to outside of the charm dir are verboten.. A standard outside is
just a slippery slope for little/no value

On Wednesday, September 18, 2013, John A Meinel wrote:

> What if it is a symlink to a standard location like /etc/foobar ? I sort
> of agree, but I'm wondering if there is a genuine use case for
> symlinking a local name for a system entry.
>
>
> ** Changed in: juju-core
> Importance: Undecided => High
>
> ** Changed in: juju-core
> Status: New => Triaged
>
> ** Tags added: papercut
>
> --
> You received this bug notification because you are subscribed to the bug
> report.
> https://bugs.launchpad.net/bugs/1227020
>
> Title:
> juju deploy w/ local charm doesn't fail with non contained symlink
>
> To manage notifications about this bug go to:
> https://bugs.launchpad.net/juju-core/+bug/1227020/+subscriptions
>

Curtis Hovey (sinzui)
tags: added: charms security
Changed in juju-core:
importance: High → Medium
Curtis Hovey (sinzui)
Changed in juju-core:
status: Triaged → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.