Message172709
Alternatively, one could fix distutils.util.byte_compile() to execute the script in safe, empty temp directory. Running scripts in /tmp remains, as it has always been, a bad idea.
Trying to determine if an import is "safe" can be arbitrarily complicated (e.g. what if the group-write bit is set, but you're the only member of that group, or there are special allow or deny ACLs for other users that aren't detected here). What notion of safeness belongs in the spec? |
|
Date |
User |
Action |
Args |
2012-10-11 23:06:32 | robertwb | set | recipients:
+ robertwb, christian.heimes, schmir, jdemeyer, Alan.Williams |
2012-10-11 23:06:32 | robertwb | set | messageid: <1349996792.76.0.78675053323.issue16202@psf.upfronthosting.co.za> |
2012-10-11 23:06:32 | robertwb | link | issue16202 messages |
2012-10-11 23:06:32 | robertwb | create | |
|