From owner-freebsd-current Thu Jan 4 18:47: 8 2001 From owner-freebsd-current@FreeBSD.ORG Thu Jan 4 18:47:07 2001 Return-Path: Delivered-To: freebsd-current@freebsd.org Received: from rover.village.org (unknown [204.144.255.66]) by hub.freebsd.org (Postfix) with ESMTP id 3135E37B400 for ; Thu, 4 Jan 2001 18:47:05 -0800 (PST) Received: from harmony.village.org (harmony.village.org [10.0.0.6]) by rover.village.org (8.11.1/8.11.0) with ESMTP id f052l2l09731; Thu, 4 Jan 2001 19:47:03 -0700 (MST) (envelope-from imp@harmony.village.org) Received: from harmony.village.org (localhost.village.org [127.0.0.1]) by harmony.village.org (8.11.1/8.8.3) with ESMTP id f052l2149361; Thu, 4 Jan 2001 19:47:02 -0700 (MST) Message-Id: <200101050247.f052l2149361@harmony.village.org> To: Will Andrews Subject: Re: cvs commit: src/usr.bin/apply apply.c Cc: Garrett Wollman , current@FreeBSD.ORG In-reply-to: Your message of "Thu, 04 Jan 2001 18:25:46 EST." <20010104182546.T86630@argon.firepipe.net> References: <20010104182546.T86630@argon.firepipe.net> <20010104172004.P86630@argon.firepipe.net> <200101041905.f04J5ou82617@freefall.freebsd.org> <200101041909.OAA61522@khavrinen.lcs.mit.edu> <20010104172004.P86630@argon.firepipe.net> <200101042320.f04NKm147924@harmony.village.org> Date: Thu, 04 Jan 2001 19:47:02 -0700 From: Warner Losh Sender: imp@harmony.village.org Sender: owner-freebsd-current@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.ORG In message <20010104182546.T86630@argon.firepipe.net> Will Andrews writes: : > I'm still not sure about the shell environment actually buying : > anything, but I could see how it might help. : : I'm not understanding what you're saying here. I'm saying I agree with Garrett in that I don't see what checking for valid shells buys us in the general case. I'm saying that maybe we might save some sloppy cgi/shell progarmmer from him/her self when the script kidz attack that script. But that's sucha large stretch that I don't see that as a win. Eg, it doesn't buy us much in real situations. Warner To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-current" in the body of the message