Project

General

Profile

Actions

Optimization #2373

closed

unix domain socket owner stays root when priviledges dropped

Added by Richard Sailer over 7 years ago. Updated 4 days ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

related: https://github.com/OISF/suricata/pull/3052

macpas suggest to solve this via extending the permissions on the socket
from rw-r-----
to rw-rw---- .

I think the nicer way to solve the problem is by setting the socket owner to the new user before we drop priviledges


Related issues 1 (1 open0 closed)

Related to Suricata - Bug #2337: give warning if permissions won't allow log reopen after dropping privsAssignedOISF DevActions
Actions #1

Updated by Richard Sailer over 7 years ago

  • Status changed from New to Feedback
  • Assignee set to Richard Sailer
Actions #2

Updated by Richard Sailer over 7 years ago

  • Subject changed from unix domain socket owner not updated when priviledges dropped to unix domain socket owner stays root when priviledges dropped
  • Description updated (diff)
Actions #3

Updated by Richard Sailer over 7 years ago

  • Related to Bug #2337: give warning if permissions won't allow log reopen after dropping privs added
Actions #4

Updated by Andreas Herz over 7 years ago

  • Target version set to TBD
Actions #5

Updated by Andreas Herz over 6 years ago

  • Assignee changed from Richard Sailer to OISF Dev
Actions #6

Updated by Philippe Antoine 4 days ago

  • Tracker changed from Bug to Optimization
Actions #7

Updated by Jason Ish 4 days ago

  • Status changed from Feedback to Closed

Closing. Looks like this was fixed in 2017 (commit: babe8a299e?). Anyways, it has not been an issue since at least 6.0.

Actions

Also available in: Atom PDF