<table><tr><td style="">jtamate added inline comments.
</td><a style="text-decoration: none; padding: 4px 8px; margin: 0 8px 8px; float: right; color: #464C5C; font-weight: bold; border-radius: 3px; background-color: #F7F7F9; background-image: linear-gradient(to bottom,#fff,#f1f0f1); display: inline-block; border: 1px solid rgba(71,87,120,.2);" href="https://phabricator.kde.org/D15180">View Revision</a></tr></table><br /><div><strong>INLINE COMMENTS</strong><div><div style="margin: 6px 0 12px 0;"><div style="border: 1px solid #C7CCD9; border-radius: 3px;"><div style="padding: 0; background: #F7F7F7; border-color: #e3e4e8; border-style: solid; border-width: 0 0 1px 0; margin: 0;"><div style="color: #74777d; background: #eff2f4; padding: 6px 8px; overflow: hidden;"><a style="float: right; text-decoration: none;" href="https://phabricator.kde.org/D15180#inline-82059">View Inline</a><span style="color: #4b4d51; font-weight: bold;">elvisangelaccio</span> wrote in <span style="color: #4b4d51; font-weight: bold;">kioexecd.cpp:65</span></div>
<div style="margin: 8px 0; padding: 0 12px; color: #74777D;"><p style="padding: 0; margin: 8px;">The problem with using <tt style="background: #ebebeb; font-size: 13px;">QDir::removeRecursively()</tt> is that the folder we are going to delete recursively is an input from dbus. What happens if some malicious software calls <tt style="background: #ebebeb; font-size: 13px;">watch("~/dummy.txt")</tt> ?</p>
<p style="padding: 0; margin: 8px;">At the very least we need to check whether this folder starts with <tt style="background: #ebebeb; font-size: 13px;">QStandardPaths::writableLocation(QStandardPaths::CacheLocation) + QStringLiteral("/krun")</tt> (the path used by <tt style="background: #ebebeb; font-size: 13px;">kioexec</tt>).</p></div></div>
<div style="margin: 8px 0; padding: 0 12px;"><p style="padding: 0; margin: 8px;">There is a slightly problem: QStandardPaths::CacheLocation is application dependent, and their values doesn't match here:<br />
kioexec: /home/jtorres/.cache/kioexec/<br />
kioexecd: /home/jtorres/.cache/kiod5/<br />
Can we assume that replacing kiod5 by kioexec will always work?</p>
<p style="padding: 0; margin: 8px;">We could use QStandardPaths::GenericCacheLocation instead, but this is not guaranteed to be non empty.</p>
<p style="padding: 0; margin: 8px;">Or another solution: keep it as it was (delete only the file and the directory if it is possible).</p></div></div><br /><div style="border: 1px solid #C7CCD9; border-radius: 3px;"><div style="padding: 0; background: #F7F7F7; border-color: #e3e4e8; border-style: solid; border-width: 0 0 1px 0; margin: 0;"><div style="color: #74777d; background: #eff2f4; padding: 6px 8px; overflow: hidden;"><a style="float: right; text-decoration: none;" href="https://phabricator.kde.org/D15180#inline-81921">View Inline</a><span style="color: #4b4d51; font-weight: bold;">anthonyfieroni</span> wrote in <span style="color: #4b4d51; font-weight: bold;">kioexecd.cpp:85-88</span></div>
<div style="margin: 8px 0; padding: 0 12px; color: #74777D;"><p style="padding: 0; margin: 8px;">Now it's not needed 'remove' will do the work</p></div></div>
<div style="margin: 8px 0; padding: 0 12px;"><p style="padding: 0; margin: 8px;">You're right. In this case it isn't possible to be notified of a file creation unless it has been deleted first.</p></div></div></div></div></div><br /><div><strong>REPOSITORY</strong><div><div>R241 KIO</div></div></div><br /><div><strong>REVISION DETAIL</strong><div><a href="https://phabricator.kde.org/D15180">https://phabricator.kde.org/D15180</a></div></div><br /><div><strong>To: </strong>jtamate, Frameworks, broulik, ngraham, dfaure, elvisangelaccio<br /><strong>Cc: </strong>anthonyfieroni, elvisangelaccio, kde-frameworks-devel, michaelh, ngraham, bruns<br /></div>