Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1612630

Summary: [RFE] Remove default ACL on files in insights-client pacakge​
Product: Red Hat Hybrid Cloud Console (console.redhat.com) Reporter: Jaylin Zhou <zzhou>
Component: ClientAssignee: jcrafts
Status: CLOSED DUPLICATE QA Contact: Jeff Needle <jneedle>
Severity: high Docs Contact:
Priority: unspecified    
Version: unspecifiedCC: jcrafts, jnewton, klape, lphiri
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-08-06 18:37:55 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Jaylin Zhou 2018-08-06 03:05:41 UTC
Description of problem:

For files provided by insights-client rpm, default ACL exists:

# getfacl /etc/insights-client/
getfacl: Removing leading '/' from absolute path names
# file: etc/insights-client/
# owner: root
# group: root
user::rwx
group::r-x
group:insights:rwx
mask::rwx
other::r-x
default:user::rwx
default:group::r-x        #effective:r--
default:group:insights:rwx    #effective:rw-
default:mask::rw-
default:other::r-x

For files from other rpm like httpd, ACL is off.

# getfacl /etc/httpd/
getfacl: Removing leading '/' from absolute path names
# file: etc/httpd/
# owner: root
# group: root
user::rwx
group::r-x
other::r-x 

Version-Release number of selected component (if applicable):

insights-client-3.0.3-9.el7_5.noarch

How reproducible:


Steps to Reproduce:
1. Install insights-client package
2. Check ACL of the dirs/files provided by insights-client package


Actual results:
# getfacl /etc/insights-client/
getfacl: Removing leading '/' from absolute path names
# file: etc/insights-client/
# owner: root
# group: root
user::rwx
group::r-x
group:insights:rwx
mask::rwx
other::r-x
default:user::rwx
default:group::r-x        #effective:r--
default:group:insights:rwx    #effective:rw-
default:mask::rw-
default:other::r-x

Expected results:
Remove default ACL. 

Additional info:

Comment 2 Kyle Lape 2018-08-06 18:37:55 UTC

*** This bug has been marked as a duplicate of bug 1570867 ***