GNU bug report logs

#40405 System log files are world readable

PackageSource(s)Maintainer(s)
guix PTS Buildd Popcon
Full log

Message #5 received at submit@debbugs.gnu.org (full text, mbox, reply):

Received: (at submit) by debbugs.gnu.org; 3 Apr 2020 13:19:44 +0000
From debbugs-submit-bounces@debbugs.gnu.org Fri Apr 03 09:19:44 2020
Received: from localhost ([127.0.0.1]:41388 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces@debbugs.gnu.org>)
	id 1jKMEZ-00086a-Tk
	for submit@debbugs.gnu.org; Fri, 03 Apr 2020 09:19:44 -0400
Received: from lists.gnu.org ([209.51.188.17]:38087)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <dnbarbato@posteo.de>) id 1jKMEY-00086J-2A
 for submit@debbugs.gnu.org; Fri, 03 Apr 2020 09:19:42 -0400
Received: from eggs.gnu.org ([2001:470:142:3::10]:60690)
 by lists.gnu.org with esmtp (Exim 4.90_1)
 (envelope-from <dnbarbato@posteo.de>) id 1jKMEW-00005L-QJ
 for bug-guix@gnu.org; Fri, 03 Apr 2020 09:19:41 -0400
X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on eggs.gnu.org
X-Spam-Level: 
X-Spam-Status: No, score=-4.2 required=5.0 tests=BAYES_00,RCVD_IN_DNSWL_MED,
 URIBL_BLOCKED autolearn=disabled version=3.3.2
Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71)
 (envelope-from <dnbarbato@posteo.de>) id 1jKMEV-0000gI-Qe
 for bug-guix@gnu.org; Fri, 03 Apr 2020 09:19:40 -0400
Received: from mout02.posteo.de ([185.67.36.66]:42605)
 by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32)
 (Exim 4.71) (envelope-from <dnbarbato@posteo.de>) id 1jKMEV-0000dr-BN
 for bug-guix@gnu.org; Fri, 03 Apr 2020 09:19:39 -0400
Received: from submission (posteo.de [89.146.220.130]) 
 by mout02.posteo.de (Postfix) with ESMTPS id AF2E02400FC
 for <bug-guix@gnu.org>; Fri,  3 Apr 2020 15:19:36 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=posteo.de; s=2017;
 t=1585919976; bh=UM+B9+dDQ8ZEbl+tsHQrINA0+xoHV4xBDOjnVbnI+Jk=;
 h=From:To:Subject:Date:From;
 b=RGls2t0pMbqMsBMfPudJ8nMKR3E/yhyquUp3h2AzyMi57wD/BQlvJJzYw+OElCeLh
 51qniEQnuDCwwl+KI/pS1BoWkJB0Q69zmDdoOzLyBvbR7cIYzq2rGEmwZv29h9cd1u
 WYD1xDqJpMe99zHsk8Rjo4vJGJEPS/blkIXHuUm3WrJvfYxkf7ZSvzayIEKXi+Cobq
 oSsQTsFmPRuAEfbLZk0vEWiZLVVsq90vz5ud/SQsDNxzGwIwnZczZqc5PJWDGm7SGk
 Zb2Ju3OY4cZyC9HkOcEPY2Rt3rtoGlOYW9fh1fwHDugtZSqoVHo+peMsEF/ALPzX4i
 DtDI6NdOhnFgg==
Received: from customer (localhost [127.0.0.1])
 by submission (posteo.de) with ESMTPSA id 48v0s4193Lz9rxl
 for <bug-guix@gnu.org>; Fri,  3 Apr 2020 15:19:35 +0200 (CEST)
From: Diego Nicola Barbato <dnbarbato@posteo.de>
To: bug-guix@gnu.org
Subject: System log files are world readable
Date: Fri, 03 Apr 2020 15:19:34 +0200
Message-ID: <87v9mg1zbt.fsf@GlaDOS.home>
User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/26.3 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain
X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic]
 [fuzzy]
X-Received-From: 185.67.36.66
X-Spam-Score: 0.3 (/)
X-Debbugs-Envelope-To: submit
X-BeenThere: debbugs-submit@debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit@debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request@debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces@debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces@debbugs.gnu.org>
X-Spam-Score: -0.7 (/)
Hey Guix,

On Guix System the log files (in /var/log) generated by syslogd are
currently (commit 151f3d4) world readable.  They should probably only be
readable by root (for the same reason that dmesg can only be run by
root).

It isn't possible to set the umask with fork-exec-constructor, is it?
Otherwise that might have been a simple solution.

Regards,

Diego




Send a report that this bug log contains spam.


debbugs.gnu.org maintainers <help-debbugs@gnu.org>. Last modified: Sun Dec 22 11:14:04 2024; Machine Name: wallace-server

GNU bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.