Red Hat Bugzilla – Bug 782493
Propose that you turn on PrivateTmp=true in service file for ctdb
Last modified: 2012-02-07 09:35:43 EST
I would like to propose using PrivateTmp for ctdb, to make it more secure
and avoid users from being able to potentially effect it.
Any change on this bug. We are coming up to Feature Freeze, and would like some comment on this bug.
If you do not believe this application uses /tmp than please comment on this and close the bug.
If you believe this application needs to use /tmp to communicate with other applications or users then you can close this bug with that comment.
If your app does not use systemd, then close this bug with that comment.
If you have no idea, then please add a comment, and change the bug to assigned.
I need to update the status on this feature.
Thanks for your help.
Sorry for the late response. ctdb uses a socket in /tmp/ to communicate with other applications (samba) and the users via the ctdb client program.
I will reach out to upstream to see if it would be possible to move to socket to a more suitable place like /var/run or /var/lib/ctdb.
Great, I would go with /var/run (/run)