We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Description
/boot/boot/grub/menu.lst permissions are 0755, and setting it to 0644 or 0600 is gone on reboot.
/boot/boot/grub/menu.lst
0755
0644
0600
This could also be fixed by enforcing the permission by whatever is resetting it on boot
Impact
Low impact, just that the file is world readable, and doesn't need to be executable
Environment and steps to reproduce
chmod 0600 /boot/boot/grub/menu.lst
systemctl reboot
stat /boot/boot/grub/menu.lst
The text was updated successfully, but these errors were encountered:
It's a FAT filesystem and won't store permissions, or?
Sorry, something went wrong.
/boot is a FAT filesystem, it doesn't support permissions. It has to be FAT because that's the EFI boot partition. So we can't fix this.
/boot
Reopening: we should mount with the umask=0077 option. The unit is here: https://github.com/flatcar-linux/init/blob/flatcar-master/systemd/system/boot.mount.
umask=0077
Restrict Permissions of grub/menu.lst
f18612f
This is described in the following issue: flatcar/Flatcar#296 Setting the `Options=umask` parameter as that behaviour is well documented by systemd: https://www.freedesktop.org/software/systemd/man/latest/systemd.mount.html#Options.
No branches or pull requests
Description
/boot/boot/grub/menu.lst
permissions are0755
, and setting it to0644
or0600
is gone on reboot.This could also be fixed by enforcing the permission by whatever is resetting it on boot
Impact
Low impact, just that the file is world readable, and doesn't need to be executable
Environment and steps to reproduce
a.
chmod 0600 /boot/boot/grub/menu.lst
b.
systemctl reboot
c.
stat /boot/boot/grub/menu.lst
The text was updated successfully, but these errors were encountered: