Gentoo Archives: gentoo-user

From: Mick <michaelkintzios@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] net-mail/mailbase-1.1 and access rights of /var/spool/mail
Date: Tue, 29 Jan 2013 16:38:07
Message-Id: 201301291636.25822.michaelkintzios@gmail.com
In Reply to: Re: [gentoo-user] net-mail/mailbase-1.1 and access rights of /var/spool/mail by Alan McKinnon
1 On Tuesday 29 Jan 2013 10:19:16 Alan McKinnon wrote:
2 > On Tue, 29 Jan 2013 06:37:47 +0000
3 >
4 > Mick <michaelkintzios@×××××.com> wrote:
5 > > Hi All,
6 > >
7 > > I got this message when net-mail/mailbase-1.1 was emerged:
8 > >
9 > > * Messages for package net-mail/mailbase-1.1:
10 > > * Your //var/spool/mail/ directory permissions differ from
11 > > * those which mailbase wants to set it to (03775).
12 > > * If you did not change them on purpose, consider running:
13 > > *
14 > > * chown root:mail //var/spool/mail/
15 > > * chmod 03775 //var/spool/mail/
16 > >
17 > > Running this chmod changed access rights from:
18 > > drwxrwxr-x 2 root mail 4096 Jan 28 19:57 mail
19 > >
20 > > to a sticky-fied:
21 > > drwxrwsr-t 2 root mail 4096 Jan 28 19:57 mail
22 > >
23 > > Any idea why are the sticky bits for group and others required?
24 >
25 > sticky for group so that all sub-dirs and files in them are owned by
26 > the mail group. Without it, they would be owned by the user running
27 > "mailx" and the mail system can no longer manager them.
28 >
29 > sticky for others is so that you can't delete my mail but you can still
30 > create your own mail spool files. Identical logic to /tmp (assuming
31 > that you are in the mail group)
32
33 Thanks Alan, it makes sense now. No one other than mail are in the mail group
34 in this box (my laptop):
35
36 $ less /etc/group | grep mail
37 mail:x:12:mail
38
39 I have rkhunter and some cron jobs using ssmtp to email me log info, but they
40 have been running as root. That's why I hadn't experienced a problem with the
41 previous access rights. I wonder why this was picked up in the 1.1 version
42 and not previously - perhaps a test was added on purpose in the ebuild.
43 --
44 Regards,
45 Mick

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-user] net-mail/mailbase-1.1 and access rights of /var/spool/mail Alan McKinnon <alan.mckinnon@×××××.com>