Bug 678621 - Running cumin apps as root user can cause permission problems if log files are created.
Summary: Running cumin apps as root user can cause permission problems if log files ar...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise MRG
Classification: Red Hat
Component: cumin
Version: 1.3
Hardware: Unspecified
OS: Unspecified
low
medium
Target Milestone: 2.0
: ---
Assignee: Trevor McKay
QA Contact: Jan Sarenik
URL:
Whiteboard:
Depends On:
Blocks: 693778
TreeView+ depends on / blocked
 
Reported: 2011-02-18 16:07 UTC by Trevor McKay
Modified: 2011-06-23 15:41 UTC (History)
2 users (show)

Fixed In Version: cumin-0_1_4552-1_el5
Doc Type: Bug Fix
Doc Text:
Cause If a cumin application such as cumin-admin or cumin-web is run as the "root" user and it creates a log file in $CUMIN_HOME/log, the log file will be owned by the "root" user and will not be writable by the "cumin" user. Consequence Cumin applications run as the "cumin" user that write to such log files will raise exceptions and exit. This applies to the cumin service when started with /sbin/service cumin start. Fix If a cumin application run as the "root" user creates a log file, the file's ownership will be changed to match the ownership of the containing directory. Result Since the ownership of $CUMIN_HOME/log is set to the "cumin" user at installation, any cumin applications that create log files in $CUMIN_HOME/log will set ownership of those log files to the "cumin" user.
Clone Of:
Environment:
Last Closed: 2011-06-23 15:41:56 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHEA-2011:0889 0 normal SHIPPED_LIVE Red Hat Enterprise MRG Grid 2.0 Release 2011-06-23 15:35:53 UTC

Description Trevor McKay 2011-02-18 16:07:00 UTC
Description of problem:

Creation of log files by the root user causes permission problems for the cumin service later on.  This occurs when an app running as root attempts to log and finds that the particular log file needs to be created.  In this case, the log file is owned by root and cannot be written by the cumin user later on.

Version-Release number of selected component (if applicable):

I believe the possibility for this appeared in cumin-0.1.4410-2.el5 when the rpm was changed to add the "cumin" user.

How reproducible:

100%

Steps to Reproduce:
1.  rm -rf /var/log/cumin/data.log
2.  run cumin-data manually as root user from command line
3.  ctrl-C 
4.  ls -ltr /var/log/cumin to see that data.log is owned by root.
5.  /sbin/service cumin start
  
Actual results:

The cumin-data process will get exceptions trying to access the log file.  ps -ef | grep -i cumin-data should show a defunct process.  /usr/bin/cumin will continue to try to start new instances, which will fail.

Expected results:

Cumin should run normally.

Additional info:

This could happen with cumin-web and the web.log file as well.  As long as the log files exist and are owned by "cumin" before root runs anything, the problem will not be seen.

Comment 2 Trevor McKay 2011-02-22 18:24:29 UTC
    Technical note added. If any revisions are required, please edit the "Technical Notes" field
    accordingly. All revisions will be proofread by the Engineering Content Services team.
    
    New Contents:
Cause
    If a cumin application such as cumin-admin or cumin-web is run as the "root" user and it creates a log file in $CUMIN_HOME/log, the log file will be owned by the "root" user and will not be writable by the "cumin" user.

Consequence
    Cumin applications run as the "cumin" user that write to such log files will raise exceptions and exit.  This applies to the cumin service when started with /sbin/service cumin start.

Fix
    If a cumin application run as the "root" user creates a log file, the file's ownership will be changed to match the ownership of the containing directory.

Result
    Since the ownership of $CUMIN_HOME/log is set to the "cumin" user at installation, any cumin applications that create log files in $CUMIN_HOME/log will set ownership of those log files to the "cumin" user.

Comment 3 Trevor McKay 2011-02-22 20:14:57 UTC
Also added logging for cumin-admin back in, which had been removed because of this problem.  cumin-admin now logs to admin.log, instead of data.log as previous.

Comment 4 Jan Sarenik 2011-04-07 07:18:18 UTC
Verified in all versions since cumin-0_1_4552-1_el5 up to
cumin-0.1.4683-1.el5

Comment 5 errata-xmlrpc 2011-06-23 15:41:56 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHEA-2011-0889.html


Note You need to log in before you can comment on or make changes to this bug.