Re: Fwd: [leaf:bering-uclibc] New commit [42635b] by kapeka

KP Kirchdoerfer via leaf-devel <[email protected]> Sat, 24 Feb 2018 02:16:38 +0100
Newsgroups gmane.linux.leaf.devel
Message-ID <[email protected]>
Hi Erich;

On Fr, 2018-02-23 at 21:27 +0000, Erich Titl wrote:
> Hi KP
> 
> Am 23.02.2018 um 15:46 schrieb KP Kirchdoerfer via leaf-devel:
> > Hi Erich;
> > 
> > On Do, 2018-02-22 at 20:54 +0000, Erich Titl wrote:
> > > Hi KP
> > > 
> > > Am 22.02.2018 um 19:22 schrieb KP Kirchdoerfer via leaf-devel:
> > > > You see commit messages? I don't...
> > > > 
> > > > On Do, 2018-02-22 at 18:53 +0000, Erich Titl wrote:
> > > > > Hi KP
> > > > > 
> > > > > This is not a good method to handle .htpasswd. Now it will
> > > > > not be
> > > > > in
> > > > > webconf.local anymore and all is lost.
> > > > 
> > > > I think it works.
> > > > 
> > > > # cat /var/lib/lrpkg/webconf.local  
> > > > etc/webconf/webconf.conf
> > > > var/webconf/lib/filter
> > > > var/webconf/templates
> > > > var/webconf/www/.htpasswd
> > > > 
> > > 
> > > and tar tzf webconf.lrp?
> > > 
> > > If it is not there then buildconf is IMHO broken.
> > 
> > Why do have this opinion?
> 
> Because it has a source parameter and the source is not there, so
> this
> should IMHO generate an error.

> > 
> > It is a usual approach to save directories with user generated
> > content,
> > like openvpn keys, server client definitions, any conf.d that
> > includes
> > files we aren't aware when building a package and a lot more that
> > way.
> > 
> > We use that practice also for etc/ssl/private/lighttpd.pem and
> > we've
> > used that for years for etc/mini_httpd.pem. We do not provide
> > either of
> > these as real files, but we take care to save them once they are
> > there.
> > (see the buildtool.cfg for mini_httpd and lighttpd)
> 
> I just _believe_ that something _named_ in a config file as a _file_
> with a _source_ should exist. But this may be just a naming
> convention.

The definition in buildtool.cfg is like

<File>
Filename 	= etc/mini_httpd.pem
Type 		= local
</File>

You can read this as "There is no Source, but there may be Local File
named etc/mini_httpd.pem, which we shall save if it's there".


It is a convention.

My proposal is to go with an 6.1.2-rc2 with the changes in git and see,
igf it works as I do expect based on the experience with mini_httpd in
the past years and see if we need to come up with something better.
At least it will improve security.

> > 
> > It works as designed, see:
> > 
> > https://bering-uclibc.zetam.org/wiki/Bering-uClibc_5.x_-_Developer_
> > Guid
> > e_-_Building_a_Package#File
> 
> Indeed nowhere is it stated that the file _must_ exist, well...

regards kp


> cheers
> 
> ET
> 
> 
> -------------------------------------------------------------------
> -----------
> Check out the vibrant tech community on one of the world's most
> engaging tech sites, Slashdot.org! http://sdm.link/slashdot
> _______________________________________________
> leaf-devel mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/leaf-devel

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot