You are not logged in.
Lately I noticed that in my /etc/ and /usr/share/man/man1 there are a number of files with either 000 or 444 file permissions. I cannot think of a reason why root should not be able to write to these files. What could be the cause of this?
I use umask 0007. And if i look into the packages that own these files I don't see these 000 or 444 permissions. If I reinstall lvm2 for example the permissions in /etc/lvm/profile/ of the files mentioned below still don't have write access for root.
# cd /etc
# find . \! -perm /u+w
./lvm/profile/cache-mq.profile
./lvm/profile/thin-performance.profile
./lvm/profile/thin-generic.profile
./lvm/profile/command_profile_template.profile
./lvm/profile/metadata_profile_template.profile
./lvm/profile/lvmdbusd.profile
./lvm/profile/cache-smq.profile
./sudoers
./shadow
./gshadow-
./ssl/certs/java/cacerts
./mail.rc
./machine-id
./ca-certificates/extracted/edk2-cacerts.bin
./ca-certificates/extracted/ca-bundle.trust.crt
./ca-certificates/extracted/objsign-ca-bundle.pem
./ca-certificates/extracted/cadir
/etc/ca-certificates/extracted/cadir/Trustis_FPS_Root_CA.pem
/etc/ca-certificates/extracted/cadir/QuoVadis_Root_CA_2_G3.pem
(...snip...)
./ca-certificates/extracted/email-ca-bundle.pem
./ca-certificates/extracted/tls-ca-bundle.pem
./shadow-
./icalicense
./icalicense/clientlicense
./gshadow
./udev/hwdb.bi# cd /user/share/man/man1
# find . \! -perm /u+w
./cdda2wav.1.gz
./cdda2ogg.1.gz
./cdda2mp3.1.gz
./lua.1.gz
./dbilogstrip.1p.gz
./cdrecord.1.gz
./lwp-download.1p.gz
./scgskeleton.1.gz
./POST.1p.gz
./readcd.1.gz
./lwp-request.1p.gz
./lwp-dump.1p.gz
./config_data.1p.gz
./ldns-config.1.gz
./toast.1.gz
./mail.1.gz
./rscsi.1.gz
./HEAD.1p.gz
./scgcheck.1.gz
./btcflash.1.gz
./lwp-mirror.1p.gz
./dbiprof.1p.gz
./GET.1p.gz
./dbiproxy.1p.gzOffline
I believe useradd / userdel set the umask 0777 so files they create have permissions 000, root has CAP_DAC_OVERRIDE so the permissions are ignored.
Offline
Most of these permissions will be coming from upstream.
Look at the lua source archive for example, and you'll see that the two man pages have the same mis-matched permissions that they do when installed from the Arch package:
$ bsdtar tvf /var/cache/pacman/pkg/lua-5.3.5-2-x86_64.pkg.tar.xz usr/share/man/man1/{luac,lua}.1.gz
-r--r--r-- 0 root root 1075 Jan 10 2019 usr/share/man/man1/lua.1.gz
-rw-r--r-- 0 root root 1419 Jan 10 2019 usr/share/man/man1/luac.1.gz
$ cd /tmp
$ curl -O -L https://www.lua.org/ftp/lua-5.3.5.tar.gz
$ bsdtar tvf lua-5.3.5.tar.gz lua-5.3.5/doc/{luac.1,lua.1}
-rw-r--r-- 0 lhf tecgraf 3071 Nov 16 2011 lua-5.3.5/doc/luac.1
-r--r--r-- 0 lhf tecgraf 2192 Oct 17 2016 lua-5.3.5/doc/lua.1At the end of the day, so long as the file perms are secure (regular users can't write to them), but accessible (regular users can read them), there's no need for the package maintainer to alter them.
Sakura:-
Mobo: MSI MAG X570S TORPEDO MAX // Processor: AMD Ryzen 9 5950X @4.9GHz // GFX: AMD Radeon RX 5700 XT // RAM: 32GB (4x 8GB) Corsair DDR4 (@ 3000MHz) // Storage: 1x 3TB HDD, 6x 1TB SSD, 2x 120GB SSD, 1x 275GB M2 SSD
Making lemonade from lemons since 2015.
Offline
I noted the permission issue because my backup tool rdiff-backups seems to stumble over this. I user rdiff-backup to push backups to a server. It connects to a non privileged user on my server via ssh, and the files get saved with that user as owner, but with the same 000 or 444 permissions. But once the files are written rdiff-backup can't seem to overwrite them because of the no-write permissions.
I could issue a chmod after every upgrade but that seems a bit clunky. Isn't there a cleaner way to to force files installed by packages to be writable to user?
Last edited by rwd (2020-02-16 18:21:15)
Offline
444 makes the files globally readable which is not the default for some of those files.
Edit:
For example the /etc/shadow /etc/gshadow which are only readable by root split out the password information from /etc/passwd /etc/group to prevent offline password attacks.
Last edited by loqs (2020-02-16 22:00:30)
Offline