Comment 123 for bug 13795

Revision history for this message
In , Russ Allbery (rra-debian) wrote : Re: Bug#299007: Insecure PATH in /root/.profile

package debian-policy
user <email address hidden>
usertag 299007 ctte
thanks

This proposal asks that directories in /usr/local no longer be writable by
group staff.

There clearly was not consensus in this bug discussion for making this
change, but neither am I comfortable as a Policy delegate with simply
closing it, in part because those in favor of this change felt very
strongly about it and in part because Ubuntu has made a different decision
and implemented this change. Debian need not follow Ubuntu, but where
Ubuntu has decided to diverge, we should look at their rationale and
consider it seriously.

I'm therefore going to delegate this decision to the tech-ctte under
points 1 and 3 of section 6.1 of the Debian Constitution. I'm filing the
bug against tech-ctte now.

--
Russ Allbery (<email address hidden>) <http://www.eyrie.org/~eagle/>