-
Notifications
You must be signed in to change notification settings - Fork 44
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
save_y2logs stores log as rw only for root #978
Comments
@coogor sadly I worry this won't be accepted by security guys as it contain many info that can be abused by potential attacker, like configuration of services, firewall configuration, etc. We filter out passwords, but there are more sensitive informations like content of journal to which common user does not have access and many others. |
I see....but maybe issue a sentence that the file is rw only for root, and you may not be able to upload it if working under a different user? |
Hi @coogor! Sorry for the delay, too much stuff in the TODO queue :) Actually, that is already mentioned in https://en.opensuse.org/openSUSE:Report_a_YaST_bug#I_attached_.2Fvar.2Flog.2FYaST2.2Fy2log_to_a_YaST2_bug.2C_and_still_I_am_asked_to_attach_y2logs._Why.3F I'm not sure if it worth adding such information in the command output. Let's wait for more feedback and see what we finally decide. Thanks. |
Well, we do have a contradiction:
|
I believe the link you had in mind is We simply cannot use more liberal permissions. That you get an 'internal server error' would indicate more an issue with the web page. A short notice about the need to adjust the permissions when you are going to upload the file might be a solution. I would nobody expect to find that cited paragraph. |
You're right. Wrong copy&paste. Thanks @wfeldt
Which is exactly the same than @coogor requested, right? |
I started a discussion in yast-devel mailing list. |
I created a corresponding card to track this in the private trello board used by the YaST Team at SUSE to coordinate and prioritize: https://trello.com/c/uqSvbtGh/4599-improvements-in-savey2logs |
This has the lovely consequence, once you want to attach a saved log file to bugzilla you get an 'internal server error' , as no other user can read the log file! (and of course, you are not completely working as root, so this is a daily issue)
Maybe a chmod 666 saved_file.tat.xz as last step would fix this
The text was updated successfully, but these errors were encountered: