<?xml version="1.0" encoding="UTF-8" ?>

<bugzilla version="5.2"
          urlbase="https://bugzilla.altlinux.org/"
          
          maintainer="jenya@basealt.ru"
>

    <bug>
          <bug_id>32541</bug_id>
          
          <creation_ts>2016-09-28 11:38:26 +0300</creation_ts>
          <short_desc>why not make /etc/default/ readble by all?</short_desc>
          <delta_ts>2017-03-07 20:23:37 +0300</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>4</classification_id>
          <classification>Development</classification>
          <product>Sisyphus</product>
          <component>shadow-utils</component>
          <version>unstable</version>
          <rep_platform>all</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>CLOSED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P3</priority>
          <bug_severity>enhancement</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Ivan Zakharyaschev">imz</reporter>
          <assigned_to name="Mikhail Efremov">sem</assigned_to>
          <cc>ldv</cc>
    
    <cc>sem</cc>
          
          <qa_contact>qa-sisyphus</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>158822</commentid>
    <comment_count>0</comment_count>
    <who name="Ivan Zakharyaschev">imz</who>
    <bug_when>2016-09-28 11:38:26 +0300</bug_when>
    <thetext>shadow-utils-4.1.4.2-alt8


$ rpm -qf /etc/default -lv | fgrep /etc/default
drwxr-x--x    2 root    root                0 июн 21  2012 /etc/default
-rw-------    1 root    root              118 июн 21  2012 /etc/default/useradd
$ 

Why should the list of things that are in the directory be secret?


$ egrep &apos;^/etc/default&apos; /ALT/Sisyphus/{noarch,x86_64}/base/contents_index
/ALT/Sisyphus/noarch/base/contents_index:/etc/default/eeepc-acpi-scripts	eeepc-acpi-scripts
/ALT/Sisyphus/noarch/base/contents_index:/etc/default/google-chrome	google-chrome-preinstall
/ALT/Sisyphus/noarch/base/contents_index:/etc/default/jetty	jetty
/ALT/Sisyphus/noarch/base/contents_index:/etc/default/vivaldi	vivaldi-preinstall
/ALT/Sisyphus/noarch/base/contents_index:/etc/default/yandex-browser	yandex-browser-preinstall
/ALT/Sisyphus/noarch/base/contents_index:/etc/default/yandex-browser-beta	yandex-browser-preinstall
/ALT/Sisyphus/x86_64/base/contents_index:/etc/default	shadow-utils
/ALT/Sisyphus/x86_64/base/contents_index:/etc/default/aufs	aufs2-util
/ALT/Sisyphus/x86_64/base/contents_index:/etc/default/aufs	aufs2-util-ng
/ALT/Sisyphus/x86_64/base/contents_index:/etc/default/aufs	aufs3-util
/ALT/Sisyphus/x86_64/base/contents_index:/etc/default/cryptmount	cryptmount
/ALT/Sisyphus/x86_64/base/contents_index:/etc/default/grub	grub2-common
/ALT/Sisyphus/x86_64/base/contents_index:/etc/default/ld10k1	/etc/default/ld10k1
/ALT/Sisyphus/x86_64/base/contents_index:/etc/default/ltsp-client-setup	ltsp-client
/ALT/Sisyphus/x86_64/base/contents_index:/etc/default/useradd	shadow-utils
/ALT/Sisyphus/x86_64/base/contents_index:/etc/default/vservers-default	util-vserver
$ 

Are there plans for /etc/default/ to hold some files with secret names?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>158823</commentid>
    <comment_count>1</comment_count>
    <who name="Ivan Zakharyaschev">imz</who>
    <bug_when>2016-09-28 11:58:13 +0300</bug_when>
    <thetext>In Ubuntu Trusty, it&apos;s readable by all.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>162333</commentid>
    <comment_count>2</comment_count>
    <who name="Repository Robot">repository-robot</who>
    <bug_when>2017-03-07 20:23:37 +0300</bug_when>
    <thetext>shadow-1:4.4-alt1 -&gt; sisyphus:

* Fri Mar 03 2017 Mikhail Efremov &lt;sem@altlinux&gt; 1:4.4-alt1
- Don&apos;t own %_sysconfdir/default/ (closes: #32541).
- Fix possible crash if gmtime() returns NULL.
- chsh: Fix duplicate warning.
- Enable audit support.
- Don&apos;t package ChangeLog/NEWS files.
- Spec cleanup.
- submap: Add control scripts for newuidmap/newgidmap.
- Fix build: ignore write() return value.
- configure.ac: Drop man/po/Makefile.
- Drop FORCE_SHADOW.
- Don&apos;t create missing files.
- Fixes from usptream git:
  + Keep the permissions of the original file when creating a backup.
  + useradd: Read defaults after changing root directories.
  + Don&apos;t crash on bogus keys in login.defs if PAM is enabled.
  + Last bits of enabling subuids.
  + Make login.def files valid ASCII instead of UTF-8.
  + include getdef.h for getdef_bool prototype.
  + Print error message if SELinux file context manipulation fails.
  + Fix regression in useradd not loading defaults properly.
  + */Makefile.am: Replace INCLUDES with AM_CPPFLAGS.
- Updated to 4.4 (fixes CVE-2016-6252).</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>