This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
Home Products Support Community News


Re: [Xen-devel] [PATCH] Scrub vnc password for vfb

To: Keir Fraser <Keir.Fraser@xxxxxxxxxxxx>
Subject: Re: [Xen-devel] [PATCH] Scrub vnc password for vfb
From: "Daniel P. Berrange" <berrange@xxxxxxxxxx>
Date: Tue, 5 Feb 2008 14:06:02 +0000
Cc: xen-devel@xxxxxxxxxxxxxxxxxxx, Masaki Kanno <kanno.masaki@xxxxxxxxxxxxxx>
Delivery-date: Tue, 05 Feb 2008 06:06:32 -0800
Envelope-to: www-data@xxxxxxxxxxxxxxxxxx
In-reply-to: <C3CDD296.134A8%Keir.Fraser@xxxxxxxxxxxx>
List-help: <mailto:xen-devel-request@lists.xensource.com?subject=help>
List-id: Xen developer discussion <xen-devel.lists.xensource.com>
List-post: <mailto:xen-devel@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=unsubscribe>
References: <48C867CB54FB42kanno.masaki@xxxxxxxxxxxxxx> <C3CDD296.134A8%Keir.Fraser@xxxxxxxxxxxx>
Reply-to: "Daniel P. Berrange" <berrange@xxxxxxxxxx>
Sender: xen-devel-bounces@xxxxxxxxxxxxxxxxxxx
User-agent: Mutt/1.4.1i
On Tue, Feb 05, 2008 at 08:45:10AM +0000, Keir Fraser wrote:
> This leads to a question -- should xend.log (and our other log files) be
> world readable in the first place?

In Fedora & RHEL  /etc/xen and /var/log/xen are both mode 0700

> If we want to change it we may have to hack the logging package a bit, as it
> seems that Python's open() function calls fopen() which does not allow you
> to manually specify access permissions. Although we could have xend set its
> umask to 0770. Maybe that would break other stuff though?

The permissions of the logfile don't really matter once you set the directory
permissions - and this gives the admin flexibility to chmod/chgrp the dir
to allow selected users acccess to the logs

The main reason for scrubbing the logs is to protect users' passwords when
they post logfiles to mailing lists / bug trackers :-)

|=- Red Hat, Engineering, Emerging Technologies, Boston.  +1 978 392 2496 -=|
|=-           Perl modules: http://search.cpan.org/~danberr/              -=|
|=-               Projects: http://freshmeat.net/~danielpb/               -=|
|=-  GnuPG: 7D3B9505   F3C9 553F A1DA 4AC2 5648 23C1 B3DF F742 7D3B 9505  -=| 

Xen-devel mailing list

<Prev in Thread] Current Thread [Next in Thread>