Gentoo Archives: gentoo-user

From: Mick <michaelkintzios@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] logrotate: /var/log/portage/elog "insecure permissions"?
Date: Sun, 28 Aug 2011 11:14:41
Message-Id: 201108281214.16339.michaelkintzios@gmail.com
In Reply to: Re: [gentoo-user] logrotate: /var/log/portage/elog "insecure permissions"? by Florian Philipp
1 On Sunday 07 Aug 2011 16:20:18 Florian Philipp wrote:
2 > Am 07.08.2011 02:22, schrieb Mick:
3 > > On Friday 05 Aug 2011 23:08:38 Neil Bothwick wrote:
4 > >> On Fri, 05 Aug 2011 17:59:00 +0200, Florian Philipp wrote:
5 > >>> Yes, this was introduced in 3.8.0 to fix security issues [1]. Change
6 > >>> your config to look like this:
7 > >>> /var/log/portage/elog/summary.log {
8 > >>> su portage portage
9 > >>> ...
10 > >>> }
11 > >>>
12 > >>> Disclaimer: I've not really tried this (yet) but I think I'm able to
13 > >>> read changelogs and man-pages. ;-)
14 > >>
15 > >> Yes that fixes it. The latest portage ebuilds include an updated config
16 > >> file.
17 > >
18 > > Hmm ... it still complains here!
19 > >
20 > > error: error setting owner of
21 > > /var/log/portage/elog/summary.log-20110801.gz: Operation not permitted
22 > >
23 > >
24 > > This is my /etc/logrotate.d/elog-save-summary:
25 > > ===================================
26 > > /var/log/portage/elog/summary.log {
27 > >
28 > > su portage portage
29 > >
30 > > missingok
31 > > nocreate
32 > > delaycompress
33 > >
34 > > }
35 > > ===================================
36 > >
37 > > # ls -la /var/log/portage/elog/summary.log
38 > > -rw-rw-r-- 1 root portage 4326 Aug 6 09:44
39 > > /var/log/portage/elog/summary.log
40 > >
41 > > Can you see anything amiss?
42 >
43 > At least on my system, /var/log/portage has the following permissions:
44 > drwxr-xr-x root root
45 >
46 > Only root can write, therefore the config must read
47 >
48 > /var/log/portage/elog/summary.log {
49 > su root portage
50 > missingok
51 > nocreate
52 > delaycompress
53 > }
54
55 The latest logrotate update wanted to change the above line from su root
56 portage to su portage portage ...
57
58 Should I be changing the ownership of /var/log/portage and /var/log/portage
59 elog?
60 --
61 Regards,
62 Mick

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-user] logrotate: /var/log/portage/elog "insecure permissions"? Florian Philipp <lists@×××××××××××.net>