All of lore.kernel.org
 help / color / mirror / Atom feed
From: Saul Wold <saul.wold@intel.com>
To: Xiaofeng Yan <xiaofeng.yan@windriver.com>
Cc: poky@yoctoproject.org
Subject: Re: [PATCH 1/1] sudo: Modify ownership for directory	"/var/lib"
Date: Sat, 21 May 2011 20:16:22 -0700	[thread overview]
Message-ID: <4DD88006.6040309@intel.com> (raw)
In-Reply-To: <4DD87348.2070700@windriver.com>

On 05/21/2011 07:22 PM, Xiaofeng Yan wrote:
> On 2011年05月22日 02:48, Wolfgang Denk wrote:
>> Dear Xiaofeng Yan,
>>
>> In message<d448b57c57fec346230d40fadc08625bd8c83224.1305972143.git.xiaofeng.yan@windriver.com>  you wrote:
>>> From: Xiaofeng Yan<xiaofeng.yan@windriver.com>
>>>
>>> [YOCTO #1092]
>>> Solve access permission for directory "/var/lib".
>>> Makefile from package sudo change the ownership incorrectly.
>>>
>>> Signed-off-by: Xiaofeng Yan<xiaofeng.yan@windriver.com>
>>> ---
>>>   meta/recipes-extended/sudo/sudo.inc |    1 +
>>>   1 files changed, 1 insertions(+), 0 deletions(-)
>>>
>>> diff --git a/meta/recipes-extended/sudo/sudo.inc b/meta/recipes-extended/sudo/sudo.inc
>>> index 6a04a9c..5ea089c 100644
>>> --- a/meta/recipes-extended/sudo/sudo.inc
>>> +++ b/meta/recipes-extended/sudo/sudo.inc
>>> @@ -30,4 +30,5 @@ pkg_postinst_${PN} () {
>>>
>>>   	chmod 4111 /usr/bin/sudo
>>>   	chmod 0440 /etc/sudoers
>>> +	chmod 0755 /var/lib
>> Sorry, but this commit message is misleading.  You don't change the
>> ownership here, but the file permissions.
>>
> Hi Wolfgang Denk,
> Thanks for your reply. I am make lsb test to pass LSB certification. LSB
> Test suite check /vat/lib, but failed with the following information.
> /tset/LSB.fhs/var/lib/lib-tc 1 	failed 	
>
>
>         Message from the test:
>
> Reference 5.8-1(A)
> The /var/lib directory exists and is searchable
> Unexpected output written to stdout, as shown below:
> stdout:lsb_test_dir: expected be able to search directory /var/lib, got an error
> stdout:ls: cannot open directory /var/lib: Permission denied
>

Xiaofeng,

This issue is that some other recipe or package is changing the 
permissions of /var/lib.  If you build a minimal image, the permissions 
are correct.  So some recipe is breaking them.

We need to investigate the cause, not just fix the problem.

Sau!

>
>
> emenlow$ls /var/lib -l
> drwx------ 10 root root 4096 May 20 19:21 lib
>
> For general machine, the ownership of this directory is as follow:
> ubuntu$ls /var/lib -l
> drwxr-xr-x 67 root root 4096 2010-12-15 23:30 lib
>
> In fact, many packages make a operation to directory "/var/lib". I find
> the Makefile from package "sudo" change the ownership. Please review the
> following patch.
>
> --- Makefile.orj 2011-05-21 16:32:35.392833427 +0800
> +++ Makefile 2011-05-21 16:36:47.979380106 +0800
> @@ -482,7 +482,7 @@
> $(DESTDIR)$(visudodir) $(DESTDIR)$(noexecdir) \
> $(DESTDIR)$(sudoersdir) $(DESTDIR)$(docdir) \
> $(DESTDIR)$(mandirsu) $(DESTDIR)$(mandirform)
> - $(SHELL) $(srcdir)/mkinstalldirs -m 0700 $(DESTDIR)$(timedir)
> + $(SHELL) $(srcdir)/mkinstalldirs -m 0755 $(DESTDIR)$(timedir)
>
> install-binaries: install-dirs $(PROGS)
> $(INSTALL) -b~ -O $(install_uid) -G $(install_gid) -M 04111 sudo
> $(DESTDIR)$(sudodir)/sudo
>
> So "0700" make this directory without access permission. Perhaps it
> could not be right method, I think you have a better method to solve
> this problem. If you have, Please share with me.
> Thanks for your suggestion again.
>
> Thanks
> Yan
>> Best regards,
>>
>> Wolfgang Denk
>>
>
>
>
> _______________________________________________
> poky mailing list
> poky@yoctoproject.org
> https://lists.yoctoproject.org/listinfo/poky



  reply	other threads:[~2011-05-22  3:16 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-05-21 10:11 [PATCH 0/1] sudo: Modify ownership for dircetory "/var/lib" Xiaofeng Yan
2011-05-21 10:12 ` [PATCH 1/1] sudo: Modify ownership for directory "/var/lib" Xiaofeng Yan
2011-05-21 18:48   ` Wolfgang Denk
2011-05-22  2:22     ` Xiaofeng Yan
2011-05-22  3:16       ` Saul Wold [this message]
2011-05-22 15:49       ` Wolfgang Denk
2011-05-22 21:54       ` Saul Wold
2011-05-23 12:36         ` Xiaofeng Yan

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4DD88006.6040309@intel.com \
    --to=saul.wold@intel.com \
    --cc=poky@yoctoproject.org \
    --cc=xiaofeng.yan@windriver.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.