]> git-server-git.apps.pok.os.sepia.ceph.com Git - ceph.git/commitdiff
debian/ceph-common.postinst: fix /var/log/ceph permissions
authorSage Weil <sage@redhat.com>
Tue, 18 Aug 2015 17:46:34 +0000 (13:46 -0400)
committerSage Weil <sage@redhat.com>
Thu, 27 Aug 2015 00:35:15 +0000 (20:35 -0400)
Signed-off-by: Sage Weil <sage@redhat.com>
debian/ceph-common.postinst

index f6e0d7a04c225bf50e399d2d5bab16d546ffcfc0..6a14f1ec1aeb3b8f2e7e2744465418008b5e2a30 100644 (file)
@@ -80,7 +80,9 @@ case "$1" in
        if ! dpkg-statoverride --list /var/log/ceph >/dev/null
        then
            chown -R $SERVER_USER:$SERVER_GROUP /var/log/ceph
-           chmod u=rwx,g=rxs,o= /var/log/ceph
+          # members of group ceph can log here, but cannot remove
+          # others' files.  non-members cannot read any logs.
+           chmod u=rwx,g=rwxs,o=t /var/log/ceph
        fi
 
     ;;