@cryptotaxi247 / netdata-1 / commits / 55c10760e

fix permissions in spec file

Costa Tsaousis (ktsaou) committed Jan 12, 2018 at 01:31 UTC 55c10760e24d4d6cd7553e253237f7279aa4ea59
3 files changed +31 -19
netdata-installer.sh
+1 -1
@@ -813,7 +813,7 @@ if [ ${UID} -eq 0 ]
813 if [ -f "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/cgroup-network-helper.sh" ]
814 then
815 run chown root "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/cgroup-network-helper.sh"
816 - run chmod 0500 "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/cgroup-network-helper.sh"
816 + run chmod 0550 "${NETDATA_PREFIX}/usr/libexec/netdata/plugins.d/cgroup-network-helper.sh"
817 fi
818
819 else
netdata.spec.in
+9 -7
@@ -194,27 +194,29 @@ rm -rf "${RPM_BUILD_ROOT}"
194 %{_libexecdir}/%{name}
195 %{_sbindir}/%{name}
196
197 -%caps(cap_dac_read_search,cap_sys_ptrace=ep) %attr(0555,root,root) %{_libexecdir}/%{name}/plugins.d/apps.plugin
197 +%caps(cap_dac_read_search,cap_sys_ptrace=ep) %attr(0550,root,netdata) %{_libexecdir}/%{name}/plugins.d/apps.plugin
198
199 %if %{with netns}
200 # cgroup-network detects the network interfaces of CGROUPs
201 # it must be able to use setns() and run cgroup-network-helper.sh as root
202 # the helper script reads /proc/PID/fdinfo/* files, runs virsh, etc.
203 -%caps(cap_setuid=ep) %attr(4555,root,root) %{_libexecdir}/%{name}/plugins.d/cgroup-network
204 -%attr(0555,root,root) %{_libexecdir}/%{name}/plugins.d/cgroup-network-helper.sh
203 +%caps(cap_setuid=ep) %attr(4550,root,netdata) %{_libexecdir}/%{name}/plugins.d/cgroup-network
204 +%attr(0550,root,root) %{_libexecdir}/%{name}/plugins.d/cgroup-network-helper.sh
205 %endif
206
207 %if %{with freeipmi}
208 -%caps(cap_setuid=ep) %attr(4555,root,root) %{_libexecdir}/%{name}/plugins.d/freeipmi.plugin
208 +%caps(cap_setuid=ep) %attr(4550,root,netdata) %{_libexecdir}/%{name}/plugins.d/freeipmi.plugin
209 %endif
210
211 -%attr(0700,netdata,netdata) %dir %{_localstatedir}/cache/%{name}
212 -%attr(0700,netdata,netdata) %dir %{_localstatedir}/log/%{name}
213 -%attr(0700,netdata,netdata) %dir %{_localstatedir}/lib/%{name}
211 +%attr(0770,netdata,netdata) %dir %{_localstatedir}/cache/%{name}
212 +%attr(0770,netdata,netdata) %dir %{_localstatedir}/log/%{name}
213 +%attr(0770,netdata,netdata) %dir %{_localstatedir}/lib/%{name}
214
215 %dir %{_datadir}/%{name}
216 %dir %{_sysconfdir}/%{name}/health.d
217 %dir %{_sysconfdir}/%{name}/python.d
218 +%dir %{_sysconfdir}/%{name}/charts.d
219 +%dir %{_sysconfdir}/%{name}/node.d
220
221 %if %{with systemd}
222 %{_unitdir}/netdata.service
system/netdata.conf
+21 -11
@@ -1,14 +1,24 @@
1 -# NetData Configuration
1 +# netdata configuration
2 +#
3 +# You can download the latest version of this file, using:
4 +#
5 +# wget -O /etc/netdata/netdata.conf http://localhost:19999/netdata.conf
6 +# or
7 +# curl -o /etc/netdata/netdata.conf http://localhost:19999/netdata.conf
8 +#
9 +# You can uncomment and change any of the options below.
10 +# The value shown in the commented settings, is the default value.
11 #
3 -# To see defaults, grab one from your instance:
4 -# http://localhost:19999/netdata.conf
5 -
6 -# global netdata configuration
12
13 [global]
9 - run as user = netdata
10 - web files owner = root
11 - web files group = netdata
12 - # Netdata is not designed to be exposed to potentially hostile networks
13 - # See https://github.com/firehol/netdata/issues/164
14 - bind to = localhost
14 + run as user = netdata
15 +
16 + # the default database size - 1 hour
17 + history = 3600
18 +
19 + # by default do not expose the netdata port
20 + bind to = localhost
21 +
22 +[web]
23 + web files owner = root
24 + web files group = netdata