From: Eric Hodel Date: 2006-09-01T14:11:45+09:00 Subject: Re: Insecure word writable dir? On Aug 31, 2006, at 6:17 PM, Yukihiro Matsumoto wrote: > In message "Re: Insecure word writable dir?" > on Fri, 1 Sep 2006 05:18:32 +0900, "Joe Van Dyk" > writes: > > |When I exec another program from inside Ruby, I get this warning: > |"warning: Insecure world writable dir /tmp, mode 041777" > | > |Here's /tmp > |drwxrwxrwt 17 root root 4096 Aug 31 13:16 /tmp/ > | > |Any ideas? It's sort of annoying. I thought /tmp had to be world > writable. > > That means you have world writable directory in your load path ($PATH) > when you call external program (probably by using "system"). If you > know what you are doing, you can shut the warning up by > > $VERBOSE=nil > > as Ara told in [ruby-talk:211832]. Index: file.c =================================================================== RCS file: /src/ruby/file.c,v retrieving revision 1.246 diff -p -u -r1.246 file.c --- file.c 31 Aug 2006 11:24:44 -0000 1.246 +++ file.c 1 Sep 2006 05:09:38 -0000 @@ -4073,7 +4073,7 @@ path_check_0(VALUE path, int loadpath) && (loadpath || !(st.st_mode & S_ISVTX)) #endif && !access(p0, W_OK)) { - rb_warn("Insecure world writable dir %s, mode 0%o", p0, st.st_mode); + rb_warn("Insecure world writable dir %s, mode 0%o in $LOAD_PATH", p0, st.st_mode); if (p) *p = '/'; return 0; } -- Eric Hodel - drbrain@segment7.net - http://blog.segment7.net This implementation is HODEL-HASH-9600 compliant http://trackmap.robotcoop.com