[Bug 455654] Review Request: pads - Passive Asset Detection System

bugzilla at redhat.com bugzilla at redhat.com
Fri Aug 8 18:47:53 UTC 2008


Please do not reply directly to this email. All additional
comments should be made in the comments box of this bug.


https://bugzilla.redhat.com/show_bug.cgi?id=455654





--- Comment #3 from Steve Grubb <sgrubb at redhat.com>  2008-08-08 14:47:52 EDT ---
>$ rpmlint pads-1.2-1.fc9.src.rpm
>pads.src: W: strange-permission pads.init 0755
>pads.src: W: strange-permission pads.sysconfig 0640
>
>- pads.init and pads.sysconfig might be 0644

These are just the src files. I can change them, but I generally make them what
they would be when installed. I do set the permission explicitly on install so
I can make these 644 if needed.


>$ rpmlint /usr/src/redhat/RPMS/i386/pads-1.2-1.fc9.i386.rpm
>pads.i386: E: non-readable /etc/sysconfig/pads 0640
>
>- is there a reason why not 0644 for /etc/sysconfig/pads and /etc/pads.conf

It can give out details that non-root users shouldn't see. You can specify what
networks to listen too, what uid to run as, what config file to use. I
generally believe this info is not required for someone that is not the admin.

-- 
Configure bugmail: https://bugzilla.redhat.com/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.




More information about the package-review mailing list