From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mailman by lists.gnu.org with archive (Exim 4.43) id 1Mlowz-0000zL-Cw for mharc-grub-devel@gnu.org; Thu, 10 Sep 2009 15:04:57 -0400 Received: from mailman by lists.gnu.org with tmda-scanned (Exim 4.43) id 1Mlowx-0000wo-ML for grub-devel@gnu.org; Thu, 10 Sep 2009 15:04:55 -0400 Received: from exim by lists.gnu.org with spam-scanned (Exim 4.43) id 1Mlowt-0000rx-5H for grub-devel@gnu.org; Thu, 10 Sep 2009 15:04:55 -0400 Received: from [199.232.76.173] (port=46122 helo=monty-python.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1Mlows-0000rg-Lo for grub-devel@gnu.org; Thu, 10 Sep 2009 15:04:50 -0400 Received: from moutng.kundenserver.de ([212.227.17.9]:55724) by monty-python.gnu.org with esmtp (Exim 4.60) (envelope-from ) id 1Mlowr-0007z6-VY for grub-devel@gnu.org; Thu, 10 Sep 2009 15:04:50 -0400 Received: from [85.180.61.118] (e180061118.adsl.alicedsl.de [85.180.61.118]) by mrelayeu.kundenserver.de (node=mrbap0) with ESMTP (Nemesis) id 0MKsym-1Mlowq3XZL-000lKo; Thu, 10 Sep 2009 21:04:49 +0200 From: Felix Zielcke To: The development of GRUB 2 In-Reply-To: <20090910185652.GA18736@thorin> References: <1252240143.3895.18.camel@fz.local> <20090906133818.GI13423@riva.ucam.org> <20090908144817.GC13674@thorin> <1252421501.2872.5.camel@fz.local> <20090910185652.GA18736@thorin> Content-Type: text/plain; charset="UTF-8" Date: Thu, 10 Sep 2009 21:04:47 +0200 Message-Id: <1252609487.2908.42.camel@fz.local> Mime-Version: 1.0 X-Mailer: Evolution 2.27.92 Content-Transfer-Encoding: 7bit X-Provags-ID: V01U2FsdGVkX19YufaG8SrtbS6WxuZYO83Czv/g5ynWe5qZNKs VgK/M6D1fPLJS3yQkg1p+ihLgL5kpfP9QsRCl9jtz6WOf9pxAi ZZXIb47TeVhHPGiASTkhEMY25/ru6Sh X-detected-operating-system: by monty-python.gnu.org: Genre and OS details not recognized. Subject: Re: chmod of generated grub.cfg X-BeenThere: grub-devel@gnu.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: The development of GRUB 2 List-Id: The development of GRUB 2 List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 10 Sep 2009 19:04:56 -0000 Am Donnerstag, den 10.09.2009, 20:56 +0200 schrieb Robert Millan: > On Tue, Sep 08, 2009 at 04:51:41PM +0200, Felix Zielcke wrote: > > Am Dienstag, den 08.09.2009, 16:48 +0200 schrieb Robert Millan: > > > On Sun, Sep 06, 2009 at 07:22:36PM +0200, Vladimir 'phcoder' Serbinenko wrote: > > > > On Sun, Sep 6, 2009 at 3:38 PM, Colin Watson wrote: > > > > > On Sun, Sep 06, 2009 at 02:29:03PM +0200, Felix Zielcke wrote: > > > > >> Currently grub-mkconfig uses chmod 444 on the newly generated grub.cfg > > > > >> Wouldn't it be better to use 400 now that we have plaintext password > > > > >> support? > > > > >> Or should we add support for a GRUB_CHMOD variable so users can override > > > > >> this setting as they please? > > > > > > > > > > I'd prefer to see this done only if they set a password. A GRUB_CHMOD > > > > > variable seems overkill, though. > > > > Is there a reason a non-root would like to look at grub.cfg on > > > > production system? Developers can always override chmod. If there is > > > > no real reason for non-root to look into grub.cfg I would follow the > > > > best friend in security considerations called "paranoia" and just use > > > > mode 400 > > > > > > I like the idea of using 0400 right away, for simplicity. > > > > > > OTOH, world-readable grub.cfg is useful, at least in Debian, because > > > reportbug includes this file in bug reports. > > > > > > But if it's only useful for Debian, we shouldn't let this change our > > > agenda (ah, the conflict of wearing two hats...). > > > > > > > So in upstream we change it to 400 + warning and for Debian we use my > > last patch? > > Ok. > Ok commited. -- Felix Zielcke Proud Debian Maintainer