* Joachim Breitner:

>> I think mounting the file system no-exec covers that.  IIRC,
>> Subversion directly executes the hook scripts, and this will fail in
>> that case.
>
> Then this should be mentioned in the file. I also think that this is
> quite a high hurdle: Admins that want that can surely re-compile
> scponly.

It's mentioned in the file (item 7), but I agree that this is not the
target group of the Debian package.

> For the rest, the debian package should come without svn
> support. The README.Debian could describe the disabled features, and
> under what circumstances they are save, and how best to recompile
> scponly.

The package could create two binaries, one that supports just
scp/sftp, and another one for the rest.

For the stable security update, it's probably best to just disable
Subversion/Unison/rsync.


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to