bug-tar
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Bug-tar] [PATCH] add --ignore-missing to ignore missing input files


From: Stefan Tomanek
Subject: Re: [Bug-tar] [PATCH] add --ignore-missing to ignore missing input files
Date: Sat, 21 Apr 2012 00:30:12 +0200
User-agent: Mutt/1.5.21 (2010-09-15)

Dies schrieb Paul Eggert (address@hidden):

> In the longer run, Joerg's suggestion of using libfind, or something like
> that, may be a better one -- then 'tar' could do anything that 'find' can
> do, without further ado.  However, libfind (or whatever) would have to be
> audited for security holes....

Sure, in the long run this might be a better alternative. But what until then?
Is there any argument against the original patch, which is already present and 
does
scratch an existing itch by just changing the exit code for some specific 
issues?

> > I also spoke to many different people that are in fact using the 
> > combination of
> > find and tar
> 
> This combination is safe in environments where only trusted users can
> modify the file system.  But it's not safe in general, which is why
> I have qualms about supporting it.

Can you elaborate on the possible attack scenario?
I'm genuinely interested...



reply via email to

[Prev in Thread] Current Thread [Next in Thread]