default perms on cached files include w:r

Bug #1031796 reported by Tom Hancock
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Glance
Fix Released
High
Tom Hancock

Bug Description

By default all files created by glance daemons are w:r. This includes cached images and images in a file-backed configuration.
Setting a default umask with w: access seems a fix. I'll propose this fix.

Revision history for this message
Tom Hancock (tom-hancock) wrote :

s/with w:/without w:/ of course

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to glance (master)

Fix proposed to branch: master
Review: https://review.openstack.org/10653

Changed in glance:
assignee: nobody → Tom Hancock (tom-hancock)
status: New → In Progress
Brian Waldon (bcwaldon)
Changed in glance:
milestone: none → folsom-3
importance: Undecided → High
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to glance (master)

Reviewed: https://review.openstack.org/10653
Committed: http://github.com/openstack/glance/commit/e7919a2642f6e6180f30732394e7b0dc97868c6a
Submitter: Jenkins
Branch: master

commit e7919a2642f6e6180f30732394e7b0dc97868c6a
Author: Tom Hancock <email address hidden>
Date: Wed Aug 1 14:15:01 2012 +0000

    Process umask shouldn't allow world-readable files

    This ensures that image cache files and file-backed
    images are not world-readable.

    Fix LP bug 1031796

    Change-Id: I85a26b4e645e7cb32e17164e47fad62f4c44976a

Changed in glance:
status: In Progress → Fix Committed
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to glance (stable/essex)

Fix proposed to branch: stable/essex
Review: https://review.openstack.org/10863

Brian Waldon (bcwaldon)
no longer affects: glance/essex
Thierry Carrez (ttx)
Changed in glance:
status: Fix Committed → Fix Released
Thierry Carrez (ttx)
Changed in glance:
milestone: folsom-3 → 2012.2
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.