Accepting request 819259 from home:jmoellers:branches:network

OBS-URL: https://build.opensuse.org/request/show/819259
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=289
This commit is contained in:
Reinhard Max 2020-07-21 07:32:24 +00:00 committed by Git OBS Bridge
parent 3e9509f4c7
commit 13336b5b52
4 changed files with 12 additions and 3 deletions

View File

@ -1,6 +1,6 @@
# See tmpfiles.d(5) for details # See tmpfiles.d(5) for details
#Type Path Mode UID GID Age Argument #Type Path Mode UID GID Age Argument
d /var/lib/named 755 named named - - d /var/lib/named 1775 root named - -
d /var/lib/named/dev 755 root root - - d /var/lib/named/dev 755 root root - -
c /var/lib/named/dev/null 666 root root - 1:3 c /var/lib/named/dev/null 666 root root - 1:3
c /var/lib/named/dev/random 666 root root - 1:8 c /var/lib/named/dev/random 666 root root - 1:8

View File

@ -1,3 +1,12 @@
-------------------------------------------------------------------
Tue Jun 30 08:32:21 UTC 2020 - Josef Möllers <josef.moellers@suse.com>
- Changed /var/lib/named to owner root:named and perms rwxrwxr-t
so that named, being a/the only member of the "named" group
has full r/w access yet cannot change directories owned by root
in the case of a compromized named.
[bsc#1173307, bind-chrootenv.conf]
------------------------------------------------------------------- -------------------------------------------------------------------
Thu Jun 18 06:35:35 UTC 2020 - Josef Möllers <josef.moellers@suse.com> Thu Jun 18 06:35:35 UTC 2020 - Josef Möllers <josef.moellers@suse.com>

View File

@ -1,6 +1,6 @@
# See tmpfiles.d(5) for details # See tmpfiles.d(5) for details
#Type Path Mode UID GID Age Argument #Type Path Mode UID GID Age Argument
d /var/lib/named 755 named named - - d /var/lib/named 1775 root named - -
d /var/lib/named/dyn 755 named named - - d /var/lib/named/dyn 755 named named - -
d /var/lib/named/master 755 named named - - d /var/lib/named/master 755 named named - -
d /var/lib/named/slave 755 named named - - d /var/lib/named/slave 755 named named - -

View File

@ -561,7 +561,7 @@ fi
%if %{with_systemd} %if %{with_systemd}
%{_prefix}/lib/tmpfiles.d/bind-chrootenv.conf %{_prefix}/lib/tmpfiles.d/bind-chrootenv.conf
%endif %endif
%attr(-,named,named) %dir %{_var}/lib/named %attr(1775,root,named) %dir %{_var}/lib/named
%dir %{_var}/lib/named%{_sysconfdir} %dir %{_var}/lib/named%{_sysconfdir}
%dir %{_var}/lib/named%{_sysconfdir}/named.d %dir %{_var}/lib/named%{_sysconfdir}/named.d
%dir %{_var}/lib/named/dev %dir %{_var}/lib/named/dev