Bug 580572
| Summary: | getfacl/setfacl remove SUID/SGID/Sticky-Bits | ||||||
|---|---|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 5 | Reporter: | Bruno Cornec <bruno.cornec> | ||||
| Component: | acl | Assignee: | Kamil Dudka <kdudka> | ||||
| Status: | CLOSED ERRATA | QA Contact: | Ondrej Moriš <omoris> | ||||
| Severity: | high | Docs Contact: | |||||
| Priority: | high | ||||||
| Version: | 5.5 | CC: | bgollahe, brandon, bruno.cornec, bzeranski, gnugv_maintainer, jmoskovc, josh, martinez, omoris, ovasik, ralph, sct, steved | ||||
| Target Milestone: | rc | Keywords: | Patch, Triaged | ||||
| Target Release: | 5.7 | ||||||
| Hardware: | All | ||||||
| OS: | Linux | ||||||
| Whiteboard: | |||||||
| Fixed In Version: | acl-2.2.39-7.el5 | Doc Type: | Bug Fix | ||||
| Doc Text: | Story Points: | --- | |||||
| Clone Of: | 467936 | Environment: | |||||
| Last Closed: | 2012-02-21 06:15:47 UTC | Type: | --- | ||||
| Regression: | --- | Mount Type: | --- | ||||
| Documentation: | --- | CRM: | |||||
| Verified Versions: | Category: | --- | |||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||
| Embargoed: | |||||||
| Bug Depends On: | 467936 | ||||||
| Bug Blocks: | 571751, 700848, 758797 | ||||||
| Attachments: |
|
||||||
|
Description
Bruno Cornec
2010-04-08 14:37:30 UTC
This request was evaluated by Red Hat Product Management for inclusion in the current release of Red Hat Enterprise Linux. Because the affected component is not scheduled to be updated in the current release, Red Hat is unfortunately unable to address this request at this time. Red Hat invites you to ask your support representative to propose this request, if appropriate and relevant, in the next release of Red Hat Enterprise Linux. Do you mean that it will never been fixed in RHEL 5.x ? Do you mean I also need to clone it for RHEL 6 ? No, it was just automated message informing you that the fix is not planned for upcoming RHEL-5.6 minor update. It still could be solved later in RHEL-5.7+ if the acl update will get approved by PM. If you want to increase chances of the acl package update, contact Red Hat product support - as Bugzilla is just bug tracking system for RHEL. You don't have to clone it for RHEL-6... Created attachment 473538 [details] backport of related upstream patches http://git.savannah.gnu.org/cgit/acl.git/commit/?id=45833cc http://git.savannah.gnu.org/cgit/acl.git/commit/?id=8c635f8 http://git.savannah.gnu.org/cgit/acl.git/commit/?id=1623002 This request was evaluated by Red Hat Product Management for inclusion in the current release of Red Hat Enterprise Linux. Because the affected component is not scheduled to be updated in the current release, Red Hat is unfortunately unable to address this request at this time. Red Hat invites you to ask your support representative to propose this request, if appropriate and relevant, in the next release of Red Hat Enterprise Linux. This request was evaluated by Red Hat Product Management for inclusion in the current release of Red Hat Enterprise Linux. Because the affected component is not scheduled to be updated in the current release, Red Hat is unfortunately unable to address this request at this time. Red Hat invites you to ask your support representative to propose this request, if appropriate and relevant, in the next release of Red Hat Enterprise Linux. This bug still exists in RHEL 6.2 - specifically, if I do 'getfacl file1 | setfacl --set-file=- file2', the setuid, setgid and sticky bits are ignored. This bug has been NOT included in RHEL 5/6 fixes for over a year - please fix it for the next release. (In reply to comment #18) > This bug still exists in RHEL 6.2 - specifically, if I do 'getfacl file1 | > setfacl --set-file=- file2', the setuid, setgid and sticky bits are ignored. This bug was about setfacl --restore. Are you referring to a particular upstream fix? No, I was pointing out that this is an open security-related bug that has been pushed back 3 RHEL5 releases, and that it also affects RHEL6. Also, while I suppose it's possible that the internal mechanisms are actually different, setfacl --restore and setfacl --set-file are effectively the same thing when a single file is involved, and neither one properly restores the setXid and sticky bits. Also, since upstream patches were posted to this bug over a year ago, I don't understand why this has still not been addressed. I have tried your example. I get the same results on RHEL-6.2 as I get for the upstream acl. If the behavior is wrong, then it is an upstream bug and it needs to be fixed upstream. josh: If you are trying to report the new issue, please open new bugzilla. In addition, if you have security concerns about this, feel free to ask secalert about it... this bugzilla is not marked security and was not reported by customer support. Priority of the RHEL updates is driven by customer requests, as the update capacity is of course limited. If you want to increase the priority of some fix, please escalate it via product support. Bugzilla (in the case of RHEL) is just tracking tool, not support tool. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHBA-2012-0242.html |