Bug 459336 - Alliance incorrectly mungs your path and adds the cwd to the path
Summary: Alliance incorrectly mungs your path and adds the cwd to the path
Keywords:
Status: CLOSED NEXTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: alliance
Version: 9
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Chitlesh GOORAH
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2008-08-16 19:48 UTC by Bruno Wolff III
Modified: 2008-09-16 23:23 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2008-09-16 23:22:36 UTC
Type: ---


Attachments (Terms of Use)
Modified alc_env.csh (3.06 KB, application/octet-stream)
2008-09-11 13:08 UTC, Bruno Wolff III
no flags Details
Modified alc_env.sh (3.70 KB, text/plain)
2008-09-11 13:12 UTC, Bruno Wolff III
no flags Details

Description Bruno Wolff III 2008-08-16 19:48:16 UTC
Description of problem:
If you install alliance, profile.d/alc_env.csh gets created and in it it modifies your path using:
setenv PATH "${PATH}:${ALLIANCE_TOP}/bin:"
This ends up putting in a :: into your path.
This is a minor security issue as it is easy to run a program unexpectedly when the current working directory is being searched.
profile.d/alc_env.sh also has a similar problem.

Version-Release number of selected component (if applicable):
alliance-5.0-16.20070718snap.fc9.x86_64

How reproducible:
100%

Steps to Reproduce:
1. Install alliance
2. login again
3. echo $PATH
  
Actual results:
Path with :: in it

Expected results:
Path without :: in it

Additional info:

Comment 1 Bruno Wolff III 2008-09-11 13:08:53 UTC
Created attachment 316432 [details]
Modified alc_env.csh

This is a modified rawhide version of alc_env.csh that doesn't add the current working directory to the path. I also tweaked the manpath to include the defaults in the case that manpath wasn't already set.

Comment 2 Bruno Wolff III 2008-09-11 13:12:25 UTC
Created attachment 316433 [details]
Modified alc_env.sh

This is a similarly changed alc_env.sh.

Comment 3 Fedora Update System 2008-09-15 21:11:43 UTC
alliance-5.0-21.20070718snap.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/alliance-5.0-21.20070718snap.fc9

Comment 4 Fedora Update System 2008-09-15 21:11:48 UTC
alliance-5.0-21.20070718snap.fc8 has been submitted as an update for Fedora 8.
http://admin.fedoraproject.org/updates/alliance-5.0-21.20070718snap.fc8

Comment 5 Fedora Update System 2008-09-16 23:22:31 UTC
alliance-5.0-21.20070718snap.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 6 Fedora Update System 2008-09-16 23:23:56 UTC
alliance-5.0-21.20070718snap.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.