This Bugzilla instance is a read-only archive of historic NetBeans bug reports. To report a bug in NetBeans please follow the project's instructions for reporting issues.
org.netbeans.CLIHandler in the trunk does a chmod go-rwx $userdir/lock, when chmod is available (in /bin or /usr/bin). This is useful so that even if $userdir is world-readable (which is often the case), other users will not be able to read the lock file and so connect to the NB instance (e.g. to open some file maliciously?). On Windows running e.g. a Hydra terminal server, it would be useful to do something similar. Yarda suggested that the ATTRIB command would do something like this. I have no Windows machine to test it on, however.
Trung, do we have any plans with this for promoD? It would make the architecture a bit more secure...
won't work on windows. It has quite advanced ACL system but I doubt we can access it from java without JNI
Looks like we can easily live without it until a real security issue is found.