web commit by JeremyReed: noticed bug running ikiwiki right after upgrading to 2...
authorJoey Hess <joey@kitenet.net>
Sun, 24 Feb 2008 01:58:30 +0000 (20:58 -0500)
committerJoey Hess <joey@kitenet.net>
Sun, 24 Feb 2008 01:58:30 +0000 (20:58 -0500)
doc/bugs/Insecure_dependency_in_utime.mdwn [new file with mode: 0644]

diff --git a/doc/bugs/Insecure_dependency_in_utime.mdwn b/doc/bugs/Insecure_dependency_in_utime.mdwn
new file mode 100644 (file)
index 0000000..a721da2
--- /dev/null
@@ -0,0 +1,9 @@
+ikiwiki.setup: Insecure dependency in utime while running with -T switch at /usr/pkg/lib/perl5/vendor_perl/5.8.0/IkiWiki/Plugin/recentchanges.pm line 158.
+BEGIN failed--compilation aborted at (eval 5) line 164.
+
+This was in ikiwiki_2.32.3.
+
+I worked-around this by doing:
+
+        utime IkiWiki::possibly_foolish_untaint($change->{when}), IkiWiki::possi
+bly_foolish_untaint($change->{when}), "$config{srcdir}/$file