Bug 204777

Summary: [maintainer update][patch] www/rssroll: update to 0.5
Product: Ports & Packages Reporter: Nikola Kolev <koue>
Component: Individual Port(s)Assignee: Martin Wilke <miwi>
Status: Closed FIXED    
Severity: Affects Only Me Keywords: needs-qa, patch
Priority: ---    
Version: Latest   
Hardware: Any   
OS: Any   
Attachments:
Description Flags
rssroll 0.5 patch
none
new rssroll 0.5 patch
none
rssroll 0.5 patch fixed pkg-plist removed www ownership
none
rssroll 0.5 patch fixed pkg-plist; removed www ownership; remove PLIST_SUB; koue: maintainer-approval+

Comment 1 Martin Wilke freebsd_committer freebsd_triage 2015-11-26 16:15:59 UTC
Take.
Comment 2 Martin Wilke freebsd_committer freebsd_triage 2015-12-01 05:58:24 UTC
Hi,

I don't think there's any need for all those files to be owned by www:www.
WWWOWN is a user it can't be part of a path. Also, this should install itself into WWWDIR, not www directly.

Can you please rework this patch?
Comment 3 Nikola Kolev 2015-12-03 13:35:03 UTC
Created attachment 163812 [details]
new rssroll 0.5 patch

New patch with fixed pkg-plist.
Files are still owned by WWW user. I think its better if web files are not owned by root.

http://rein.chaosophia.net/poudriere/rssroll-0.5-102x386.log.txt
http://rein.chaosophia.net/poudriere/rssroll-0.5-102x64.log.txt
http://rein.chaosophia.net/poudriere/rssroll-0.5-93x386.log.txt
http://rein.chaosophia.net/poudriere/rssroll-0.5-93x64.log.txt
Comment 4 Baptiste Daroussin freebsd_committer freebsd_triage 2015-12-15 10:04:54 UTC
It is better if files are not owned by www users as the app will be run as www user. If the app gets rooted then you will be happy that the www user is not allowed to overwrite the files.

Only the files supposed to be accessed (write mode) by the application when running should be owned by the www user like cache files, temp files etc. all other files should not be owned by www user.
Comment 5 Martin Wilke freebsd_committer freebsd_triage 2015-12-21 17:08:15 UTC
back to pool
Comment 6 Nikola Kolev 2015-12-23 11:09:36 UTC
Created attachment 164540 [details]
rssroll 0.5 patch fixed pkg-plist removed www ownership

Update previous patch by removing www user ownership of the files.
Comment 7 Kubilay Kocak freebsd_committer freebsd_triage 2016-01-07 08:51:47 UTC
Can't be In Progress without an Assignee.

@Martin, Nikola has provided an updated patch. If you can't take care of this issue, please reset to 'Open'

@Nikola

 * Please confirm this updated change passes QA (portlint, poudriere)
 * Please set maintainer-approval to "+" on attachments for ports you are MAINTAINER of to ensure they get seen.
Comment 8 Martin Wilke freebsd_committer freebsd_triage 2016-01-07 09:05:11 UTC
(In reply to Kubilay Kocak from comment #7)
thanks ;) I'll take care of it.
Comment 10 commit-hook freebsd_committer freebsd_triage 2016-01-16 17:22:07 UTC
A commit references this bug:

Author: miwi
Date: Sat Jan 16 17:21:18 UTC 2016
New revision: 406245
URL: https://svnweb.freebsd.org/changeset/ports/406245

Log:
  - Update to 0.5

  PR:		204777
  Submitted by:	maintainer

Changes:
  head/www/rssroll/Makefile
  head/www/rssroll/distinfo
  head/www/rssroll/pkg-plist