Devuan bug report logs - #309
remove flag "-f" in pidof

Package: sysvinit-utils; Maintainer for sysvinit-utils is Devuan Developers <devuan-dev@lists.dyne.org>; Source for sysvinit-utils is src:sysvinit.

Reported by: KatolaZ <katolaz@freaknet.org>

Date: Tue, 19 Mar 2019 06:33:01 UTC

Severity: normal

Done: KatolaZ <katolaz@freaknet.org>

Full log


Message #5 received at submit@bugs.devuan.org (full text, mbox, reply):

Received: (at submit) by bugs.devuan.org; 19 Mar 2019 06:30:04 +0000
Return-Path: <katolaz@freaknet.org>
Delivered-To: devuanbugs@dyne.org
Received: from tupac3.dyne.org [195.169.149.119]
	by fulcanelli with IMAP (fetchmail-6.3.26)
	for <debbugs@localhost> (single-drop); Tue, 19 Mar 2019 07:30:04 +0100 (CET)
Received: from [127.0.0.1] (localhost [127.0.0.1])
	(Authenticated sender: katolaz@freaknet.org)
	with ESMTPSA id C36DDF60BD2
Date: Tue, 19 Mar 2019 07:29:11 +0100
From: KatolaZ <katolaz@freaknet.org>
To: submit@bugs.devuan.org
Subject: remove flag "-f" in pidof
Message-ID: <20190319062911.ffqz6ykwaihxrbe6@katolaz.homeunix.net>
MIME-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha1;
	protocol="application/pgp-signature"; boundary="5uvpalol52xldhbj"
Content-Disposition: inline
User-Agent: NeoMutt/20170113 (1.7.2)
X-Spam-Status: No, score=-1.0 required=5.0 tests=ALL_TRUSTED
	autolearn=disabled version=3.4.2
X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on tupac3.dyne.org
[Message part 1 (text/plain, inline)]
Package: sysvinit-utils
Version: 2.93-8
Severity: normal

I am opening this bug because I think the recently added flag '-f' in
pidof should be removed. It was intended to be used as a way to format
the PIDs according to printf-style formatters, but accepting
unsanitised input from the user is quite dangerous, as shown in
#924792. The proposed solution to #924792 was to let pidof -f
interpret only '%d' and '\n'.

This is at least an unnecessary complication. pidof is already
printing the PIDs as integers (!), and any formatting can (but I would
say should/must) be done downstream by sed/awk/whatever. We can't add
a formatter to any single CLI command :\

Please remove the unneded '-f' flag. Unix is much much better than
that.

KatolaZ
[signature.asc (application/pgp-signature, inline)]

Send a report that this bug log contains spam.


Devuan BTS -- Powered by Debian bug tracking system
Copyright (C) 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson,
2005-2017 Don Armstrong, and many other contributors.

Devuan Bugs Owner <owner@bugs.devuan.org>.
Last modified: Wed Apr 24 15:09:45 2024;