On Mon, 25 Mar 2019, Emmanuel Bourg wrote: > We've got two serious security issues in the Tomcat init script in the
You told me this. I replied by: • I’m active and willing to maintain it • if I don’t realise there’s a bug you can ping me • if even that fails, you can *still* remove it You never replied to these. > past. I'm not a big fan of systemd but this convinced me that a 40 lines > declarative service file was much more maintainable than a 300 lines > init script, and I'm unlikely to maintain one anymore. Perhaps, but thankfully Policy prescribes the existence of one. I’ll provide one and team-upload. You need not personally maintain it, just don’t break it. That’s what a team is for. > systemd brought other important benefits for the tomcat9 package and I > don't want to go back on these features. You don’t need to. The sysvinit script is not optional, but systemd users need not use it. We already realised (in that thread on d-java) that they will most likely behave slightly differently, but that’s okay. (It can be documented.) > > To recall the justification I posted to the list that were, > > IIRC, never replied: > > I made the suggestion to package the init script in a separate package > under your control, but you didn't follow up. I’ve replied saying that such tiny packages aren’t liked by ftpmasters and mirror admins. Anyway, Policy solved the issue for us, the initscript will be in the main tomcat9 package where it belongs. (Do note that the option of removing it (from above) is no longer pertinent, as one is required if a startup script for another init system is present. However, I’ll do my best, and even if that fails, I know at least one other DD at my employer’s who’s capable enough to maintain complex shell scripts and fixing RC bugs.) bye, //mirabilos -- tarent solutions GmbH Rochusstraße 2-4, D-53123 Bonn • http://www.tarent.de/ Tel: +49 228 54881-393 • Fax: +49 228 54881-235 HRB 5168 (AG Bonn) • USt-ID (VAT): DE122264941 Geschäftsführer: Dr. Stefan Barth, Kai Ebenrett, Boris Esser, Alexander Steeg ************************************************* **!!! NEU !!!** Mit der **tarent Academy** bieten wir ab sofort auch Trainings und Schulungen in den Bereichen Softwareentwicklung, Agiles Arbeiten und Zukunftstechnologien an. Besuchen Sie uns auf [www.tarent.de/academy](http://www.tarent.de/academy). Wir freuen uns auf Ihren Kontakt. *************************************************