From 7c34df633d6dd0d16538b1911694351b604104ef Mon Sep 17 00:00:00 2001 From: Simon McVittie Date: Sat, 24 Dec 2016 12:27:21 +0000 Subject: git_revert test: reinstate ikiwiki.setup, and make it work uninstalled Previously it was relying on running with an installed ikiwiki and being able to copy in recentchanges.mdwn and wikiicons/ from the underlay in /usr. The underlay in ./underlays/basewiki can't be used (yet) because ikiwiki doesn't allow following symlinks, even from underlays. I'd like to make ikiwiki follow symlinks whose destinations can be verified to be safe (for example making it willing to expose /usr/share/javascript to the web, but not /etc/passwd), at least from underlays, but this is security-sensitive so I'm not going to rush into it. --- debian/changelog | 1 + 1 file changed, 1 insertion(+) (limited to 'debian') diff --git a/debian/changelog b/debian/changelog index 031403830..4a84b28a6 100644 --- a/debian/changelog +++ b/debian/changelog @@ -1,6 +1,7 @@ ikiwiki (3.20161220) UNRELEASED; urgency=medium * Add CVE references for CVE-2016-10026 + * Add missing ikiwiki.setup for the manual test for CVE-2016-10026 -- Simon McVittie Wed, 21 Dec 2016 13:03:07 +0000 -- cgit v1.2.3