|
|
ad9e5f |
From cb7b35ca10c82c9725c3527e3ec5fb8cb7c61bc0 Mon Sep 17 00:00:00 2001
|
|
|
ea00c4 |
From: Eduardo Otubo <otubo@redhat.com>
|
|
|
fc6e82 |
Date: Fri, 7 May 2021 13:36:08 +0200
|
|
|
c1c26e |
Subject: limit permissions on def_log_file
|
|
|
c1c26e |
|
|
|
c1c26e |
This sets a default mode of 0600 on def_log_file, and makes this
|
|
|
c1c26e |
configurable via the def_log_file_mode option in cloud.cfg.
|
|
|
c1c26e |
|
|
|
c1c26e |
LP: #1541196
|
|
|
c1c26e |
Resolves: rhbz#1424612
|
|
|
c1c26e |
X-approved-upstream: true
|
|
|
ea00c4 |
|
|
|
fc6e82 |
Conflicts 21.1:
|
|
|
fc6e82 |
cloudinit/stages.py: adjusting call of ensure_file() to use more
|
|
|
fc6e82 |
recent version
|
|
|
fc6e82 |
|
|
|
ea00c4 |
Signed-off-by: Eduardo Otubo <otubo@redhat.com>
|
|
|
c1c26e |
---
|
|
|
c1c26e |
cloudinit/settings.py | 1 +
|
|
|
fc6e82 |
cloudinit/stages.py | 1 +
|
|
|
c1c26e |
doc/examples/cloud-config.txt | 4 ++++
|
|
|
fc6e82 |
3 files changed, 6 insertions(+)
|
|
|
c1c26e |
|
|
|
c1c26e |
diff --git a/cloudinit/settings.py b/cloudinit/settings.py
|
|
|
ad9e5f |
index 39650a5b..3c2145e9 100644
|
|
|
c1c26e |
--- a/cloudinit/settings.py
|
|
|
c1c26e |
+++ b/cloudinit/settings.py
|
|
|
ad9e5f |
@@ -49,6 +49,7 @@ CFG_BUILTIN = {
|
|
|
ad9e5f |
"None",
|
|
|
c1c26e |
],
|
|
|
ad9e5f |
"def_log_file": "/var/log/cloud-init.log",
|
|
|
ad9e5f |
+ "def_log_file_mode": 0o600,
|
|
|
ad9e5f |
"log_cfgs": [],
|
|
|
ad9e5f |
"mount_default_fields": [None, None, "auto", "defaults,nofail", "0", "2"],
|
|
|
ad9e5f |
"ssh_deletekeys": False,
|
|
|
c1c26e |
diff --git a/cloudinit/stages.py b/cloudinit/stages.py
|
|
|
ad9e5f |
index 3f17294b..61db1dbd 100644
|
|
|
c1c26e |
--- a/cloudinit/stages.py
|
|
|
c1c26e |
+++ b/cloudinit/stages.py
|
|
|
ad9e5f |
@@ -205,6 +205,7 @@ class Init(object):
|
|
|
c1c26e |
def _initialize_filesystem(self):
|
|
|
c1c26e |
util.ensure_dirs(self._initial_subdirs())
|
|
|
ad9e5f |
log_file = util.get_cfg_option_str(self.cfg, "def_log_file")
|
|
|
ad9e5f |
+ log_file_mode = util.get_cfg_option_int(self.cfg, "def_log_file_mode")
|
|
|
c1c26e |
if log_file:
|
|
|
ad9e5f |
util.ensure_file(log_file, mode=0o640, preserve_mode=True)
|
|
|
ad9e5f |
perms = self.cfg.get("syslog_fix_perms")
|
|
|
c1c26e |
diff --git a/doc/examples/cloud-config.txt b/doc/examples/cloud-config.txt
|
|
|
ad9e5f |
index a2b4a3fa..0ccf3147 100644
|
|
|
c1c26e |
--- a/doc/examples/cloud-config.txt
|
|
|
c1c26e |
+++ b/doc/examples/cloud-config.txt
|
|
|
ea00c4 |
@@ -414,10 +414,14 @@ timezone: US/Eastern
|
|
|
c1c26e |
# if syslog_fix_perms is a list, it will iterate through and use the
|
|
|
c1c26e |
# first pair that does not raise error.
|
|
|
c1c26e |
#
|
|
|
c1c26e |
+# 'def_log_file' will be created with mode 'def_log_file_mode', which
|
|
|
c1c26e |
+# is specified as a numeric value and defaults to 0600.
|
|
|
c1c26e |
+#
|
|
|
c1c26e |
# the default values are '/var/log/cloud-init.log' and 'syslog:adm'
|
|
|
c1c26e |
# the value of 'def_log_file' should match what is configured in logging
|
|
|
c1c26e |
# if either is empty, then no change of ownership will be done
|
|
|
c1c26e |
def_log_file: /var/log/my-logging-file.log
|
|
|
c1c26e |
+def_log_file_mode: 0600
|
|
|
c1c26e |
syslog_fix_perms: syslog:root
|
|
|
c1c26e |
|
|
|
c1c26e |
# you can set passwords for a user or multiple users
|
|
|
c1c26e |
--
|
|
|
ad9e5f |
2.31.1
|
|
|
c1c26e |
|