C165: Fix ownership of suricata classification.config file.

Message ID 20220315182403.6359-1-stefan.schantl@ipfire.org
State Accepted
Commit 5f3dc2ca06d31bc73006d93abc969b42876fb0e0
Headers
Series C165: Fix ownership of suricata classification.config file. |

Commit Message

Stefan Schantl March 15, 2022, 6:24 p.m. UTC
  The file has to be write-able for the WUI and update script, which both
are executed as nobody.

Fixes #12803.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
---
 config/rootfiles/core/165/update.sh | 3 +++
 1 file changed, 3 insertions(+)
  

Comments

Adolf Belka March 19, 2022, 10 p.m. UTC | #1
Reviewed-by: Adolf Belka <adolf.belka@ipfire.org>

On 15/03/2022 19:24, Stefan Schantl wrote:
> The file has to be write-able for the WUI and update script, which both
> are executed as nobody.
>
> Fixes #12803.
>
> Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
> ---
>   config/rootfiles/core/165/update.sh | 3 +++
>   1 file changed, 3 insertions(+)
>
> diff --git a/config/rootfiles/core/165/update.sh b/config/rootfiles/core/165/update.sh
> index 00974de73..ffb552c80 100644
> --- a/config/rootfiles/core/165/update.sh
> +++ b/config/rootfiles/core/165/update.sh
> @@ -129,6 +129,9 @@ ldconfig
>   telinit u
>   /etc/rc.d/init.d/firewall restart
>   
> +# Fix ownership of classification file.
> +chown nobody:nobody /usr/share/suricata/classification.config
> +
>   # Rebuild IPS rules
>   rm -vf /tmp/ids_page_locked
>   perl -e "require '/var/ipfire/ids-functions.pl'; &IDS::oinkmaster();"
  

Patch

diff --git a/config/rootfiles/core/165/update.sh b/config/rootfiles/core/165/update.sh
index 00974de73..ffb552c80 100644
--- a/config/rootfiles/core/165/update.sh
+++ b/config/rootfiles/core/165/update.sh
@@ -129,6 +129,9 @@  ldconfig
 telinit u
 /etc/rc.d/init.d/firewall restart
 
+# Fix ownership of classification file.
+chown nobody:nobody /usr/share/suricata/classification.config
+
 # Rebuild IPS rules
 rm -vf /tmp/ids_page_locked
 perl -e "require '/var/ipfire/ids-functions.pl'; &IDS::oinkmaster();"