NetBSD Problem Report #51071

From dholland@macaran.eecs.harvard.edu  Fri Apr 15 17:06:06 2016
Return-Path: <dholland@macaran.eecs.harvard.edu>
Received: from mail.netbsd.org (mail.netbsd.org [199.233.217.200])
	(using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
	(Client CN "mail.netbsd.org", Issuer "Postmaster NetBSD.org" (verified OK))
	by mollari.NetBSD.org (Postfix) with ESMTPS id D38F87A46B
	for <gnats-bugs@gnats.NetBSD.org>; Fri, 15 Apr 2016 17:06:05 +0000 (UTC)
Message-Id: <20160415170516.3EB7D6E264@macaran.eecs.harvard.edu>
Date: Fri, 15 Apr 2016 13:05:16 -0400 (EDT)
From: dholland@eecs.harvard.edu
Reply-To: dholland@netbsd.org
To: gnats-bugs@NetBSD.org
Subject: www/seamonkey-2.40nb1 uses fixed path in /tmp
X-Send-Pr-Version: 3.95

>Number:         51071
>Category:       pkg
>Synopsis:       www/seamonkey-2.40nb1 uses fixed path in /tmp
>Confidential:   no
>Severity:       serious
>Priority:       medium
>Responsible:    pkg-manager
>State:          open
>Class:          sw-bug
>Submitter-Id:   net
>Arrival-Date:   Fri Apr 15 17:10:00 +0000 2016
>Last-Modified:  Mon Apr 18 07:55:00 +0000 2016
>Originator:     David A. Holland
>Release:        NetBSD 7.99.26 (20160304) pkgsrc 20160411
>Organization:
>Environment:
System: NetBSD macaran 7.99.26 NetBSD 7.99.26 (MACARAN) #35: Fri Mar 4 23:43:26 EST 2016 dholland@macaran:/usr/src/sys/arch/amd64/compile/MACARAN amd64
Architecture: x86_64
Machine: amd64
>Description:

seamonkey leaves behind a directory /tmp/mozilla_mozillaUser0 that it
apparently uses for download staging.

The problem is, it belongs to the first uid who downloads something in
seamonkey and then no other users can until it's removed.

>How-To-Repeat:

As above. Noticing it requires a desktop with more that one user,
which is perhaps uncommon these days.

>Fix:

It should probably have the abcdef123.profile-name string in it, or at
least the current username or uid. Failing that, use mkdtemp(3).

>Audit-Trail:
From: Patrick Welche <prlw1@cam.ac.uk>
To: gnats-bugs@NetBSD.org
Cc: 
Subject: Re: pkg/51071: www/seamonkey-2.40nb1 uses fixed path in /tmp
Date: Mon, 18 Apr 2016 08:50:17 +0100

 I am sure that a recent version of firefox had the exact same problem,
 which triggered a fix and release - I can't find the reference...

NetBSD Home
NetBSD PR Database Search

(Contact us) $NetBSD: query-full-pr,v 1.39 2013/11/01 18:47:49 spz Exp $
$NetBSD: gnats_config.sh,v 1.8 2006/05/07 09:23:38 tsutsui Exp $
Copyright © 1994-2014 The NetBSD Foundation, Inc. ALL RIGHTS RESERVED.