From mboxrd@z Thu Jan 1 00:00:00 1970 X-Msuck: nntp://news.gmane.io/gmane.comp.sysutils.supervision.general/2177 Path: news.gmane.org!not-for-mail From: Vallo Kallaste Newsgroups: gmane.comp.sysutils.supervision.general Subject: Re: s6-log does not obey umask Date: Thu, 13 Dec 2012 17:24:04 +0200 Message-ID: <20121213152404.GC16171@hape.internal> References: <20121113204647.GA22147@hape.internal> <20121114022902.GA25513@skarnet.org> <20121114085747.GA26489@hape.internal> <20121114092721.GA4609@skarnet.org> Reply-To: kalts@estpak.ee NNTP-Posting-Host: plane.gmane.org Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-Trace: ger.gmane.org 1355412250 26519 80.91.229.3 (13 Dec 2012 15:24:10 GMT) X-Complaints-To: usenet@ger.gmane.org NNTP-Posting-Date: Thu, 13 Dec 2012 15:24:10 +0000 (UTC) To: supervision@list.skarnet.org Original-X-From: supervision-return-2411-gcsg-supervision=m.gmane.org@list.skarnet.org Thu Dec 13 16:24:24 2012 Return-path: Envelope-to: gcsg-supervision@plane.gmane.org Original-Received: from antah.skarnet.org ([212.85.147.14]) by plane.gmane.org with smtp (Exim 4.69) (envelope-from ) id 1TjAe2-0007Jp-FW for gcsg-supervision@plane.gmane.org; Thu, 13 Dec 2012 16:24:18 +0100 Original-Received: (qmail 4851 invoked by uid 76); 13 Dec 2012 14:21:05 -0000 Mailing-List: contact supervision-help@list.skarnet.org; run by ezmlm List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Archive: Original-Received: (qmail 4842 invoked from network); 13 Dec 2012 14:21:05 -0000 Content-Disposition: inline In-Reply-To: <20121114092721.GA4609@skarnet.org> User-Agent: Mutt/1.5.20 (2009-06-14) Xref: news.gmane.org gmane.comp.sysutils.supervision.general:2177 Archived-At: On Wed, Nov 14, 2012 at 10:27:21AM +0100, Laurent Bercot wrote: > > I will move other logdirs out of /some/dir, it's easier and cleaner > > than resorting to ACL kludgery. > > In your example, /some/dir is a unique logdir. What are you trying to > accomplish ? I had other logdirs under /some/dir, some services have additional logging and do not send all logs to stdout. /some/dir/current has world-readable bit always on. By allowing some UID's to step through the /some/dir to some other dir under it the UID can read /some/dir/current. The file name is always "current" so there is nothing left to guess even if the UID could not list the directory content. It is simple case and I moved the other logdirs out of /some/dir. BR, -- Vallo