Your message dated Sun, 16 Jan 2005 12:17:02 -0500
with message-id <[EMAIL PROTECTED]>
and subject line Bug#287522: fixed in harden-doc 3.0.1.2
has caused the attached Bug report to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere. Please contact me immediately.)
Debian bug tracking system administrator
(administrator, Debian Bugs database)
--------------------------------------
Received: (at submit) by bugs.debian.org; 28 Dec 2004 15:40:54 +0000
>From [EMAIL PROTECTED] Tue Dec 28 07:40:54 2004
Return-path: <[EMAIL PROTECTED]>
Received: from gelfand.mdcc.cx (stegun.mdcc.cx) [80.126.189.155]
by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
id 1CjJSv-0005xc-00; Tue, 28 Dec 2004 07:40:53 -0800
Received: from nagy.mdcc.cx (nagy.mdcc.cx [192.168.26.30])
by stegun.mdcc.cx (Postfix) with ESMTP id E825A722F;
Tue, 28 Dec 2004 16:40:49 +0100 (CET)
Received: by nagy.mdcc.cx (Postfix, from userid 1000)
id 56FBB2B5F33; Tue, 28 Dec 2004 16:40:57 +0100 (CET)
Date: Tue, 28 Dec 2004 16:40:57 +0100
From: Joost van Baal <[EMAIL PROTECTED]>
To: Debian Bug Tracking System <[EMAIL PROTECTED]>
Subject: harden-doc: more notes on read-only /usr
Message-ID: <[EMAIL PROTECTED]>
Mime-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha1;
protocol="application/pgp-signature"; boundary="qDbXVdCdHGoSgWSk"
Content-Disposition: inline
X-Reportbug-Version: 3.5
X-PGP-Fingerprint: 8FC6 A40E 31B8 7E0E 2270 D7A9 0606 9CF2 9694 57F0
X-PGP-Key-ID: 0x969457F0
X-PGP-Key: http://mdcc.cx/~joostvb/joostvb_key.asc
X-Accept-Language: nl, en
User-Agent: Mutt/1.5.6+20040907i
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2004_03_25
(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-7.0 required=4.0 tests=BAYES_00,HAS_PACKAGE,
HTML_10_20 autolearn=no version=2.60-bugs.debian.org_2004_03_25
X-Spam-Level:
--qDbXVdCdHGoSgWSk
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
Package: harden-doc
Version: 3.0.1.1
Severity: wishlist
Tags: patch
Hi,
The comment on failure during remount of /usr "Annoying but not really a
big deal." might need some elaborarion.
This patch against
/cvs/debian-doc/ddp/manuals.sgml/securing-howto/en/after-install.sgml,v
revision 1.4, date: 2004/12/28 10:58:49; might be helpful:
-------
--- after-install.sgml.dist 2004-12-28 11:58:49.000000000 +0100
+++ after-install.sgml 2004-12-28 16:39:46.000000000 +0100
@@ -435,9 +435,18 @@
</example>
=20
<p>Note that the Post-Invoke may fail with a "/usr busy" error message.
-This happens mainly when you are using files during the update that
-got updated. Annoying but not really a big deal. Just make sure
-these are no longer used and run the Post-Invoke manually.
+This happens mainly when your programs are using files during the
update
+that got updated. You can find these programs by running
+<example>
+ lsof +L1
+</example>
+Stop or restart these programs and run the Post-Invoke manually.
+<em>Beware!</em> This means you'll likely need to restart your X
+session (if you're running one) every time you do a major upgrade of
+your system. You might want to reconsider wether a read-only
+<file>/usr</file> is suitable for your system. See also this <url
+id=3D"http://lists.debian.org/debian-devel/2001/11/threads.html#00212"
+name=3D"discussion on debian-devel about read-only /usr">.
=20
<sect>Providing secure user access
=20
-------------
Bye,
Joost
--qDbXVdCdHGoSgWSk
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)
iD8DBQFB0X6JBgac8paUV/ARAlbyAJ4yMgNtAbbeXYjTiqCLA0IwwiscfwCeLl+i
Vlcxz5ItrEQZOymBOB4KiqU=
=I3Pa
-----END PGP SIGNATURE-----
--qDbXVdCdHGoSgWSk--
---------------------------------------
Received: (at 287522-close) by bugs.debian.org; 16 Jan 2005 17:23:07 +0000
>From [EMAIL PROTECTED] Sun Jan 16 09:23:07 2005
Return-path: <[EMAIL PROTECTED]>
Received: from newraff.debian.org [208.185.25.31] (mail)
by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
id 1CqE7H-0001Yx-00; Sun, 16 Jan 2005 09:23:07 -0800
Received: from katie by newraff.debian.org with local (Exim 3.35 1 (Debian))
id 1CqE1O-0005qN-00; Sun, 16 Jan 2005 12:17:02 -0500
From: Javier Fernandez-Sanguino Pen~a <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
X-Katie: $Revision: 1.55 $
Subject: Bug#287522: fixed in harden-doc 3.0.1.2
Message-Id: <[EMAIL PROTECTED]>
Sender: Archive Administrator <[EMAIL PROTECTED]>
Date: Sun, 16 Jan 2005 12:17:02 -0500
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02
(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-6.0 required=4.0 tests=BAYES_00,HAS_BUG_NUMBER
autolearn=no version=2.60-bugs.debian.org_2005_01_02
X-Spam-Level:
X-CrossAssassin-Score: 3
Source: harden-doc
Source-Version: 3.0.1.2
We believe that the bug you reported is fixed in the latest version of
harden-doc, which is due to be installed in the Debian FTP archive:
harden-doc_3.0.1.2.dsc
to pool/main/h/harden-doc/harden-doc_3.0.1.2.dsc
harden-doc_3.0.1.2.tar.gz
to pool/main/h/harden-doc/harden-doc_3.0.1.2.tar.gz
harden-doc_3.0.1.2_all.deb
to pool/main/h/harden-doc/harden-doc_3.0.1.2_all.deb
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Javier Fernandez-Sanguino Pen~a <[EMAIL PROTECTED]> (supplier of updated
harden-doc package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])
-----BEGIN PGP SIGNED MESSAGE-----
Format: 1.7
Date: Sun, 16 Jan 2005 03:55:22 +0100
Source: harden-doc
Binary: harden-doc
Architecture: source all
Version: 3.0.1.2
Distribution: unstable
Urgency: low
Maintainer: Javier Fernandez-Sanguino Pen~a <[EMAIL PROTECTED]>
Changed-By: Javier Fernandez-Sanguino Pen~a <[EMAIL PROTECTED]>
Description:
harden-doc - Useful documentation to secure a Debian system
Closes: 256523 285664 287522
Changes:
harden-doc (3.0.1.2) unstable; urgency=low
.
* Updated from CVS, many changes including:
- Clarify comments on ro /usr (Closes: #287522)
- Clarification on RPC section (Closes: #256523)
* Fix doc-base script, removed postscript, text and PDF versions
since doc-base only handles HTML files at present. (Closes: #285664)
Files:
7a0e7c3da074c925a897ca5de96d9d16 704 doc extra harden-doc_3.0.1.2.dsc
413e3beb48927a94124a2fde265e1bea 1115705 doc extra harden-doc_3.0.1.2.tar.gz
323de85af50f720928d537cedf49e224 5599326 doc extra harden-doc_3.0.1.2_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)
iQCVAwUBQeqFGPtEPvakNq0lAQGJHAP+MJYdJNMSA62OJ/H9VqKbuLC+rR7KWjUT
G+0cfa6/CXWrgA0sXuQltBkHhjQjZ3RhGM2vflgCzOXE958T05L7YAsi/g+TU4Cm
oe+cnM7PAI+bmVfoVEuq2ZGy8y/X5WWCHKUDjfvJx2j759wS6V0rvgiBhlZHh0mJ
4tNNDRsiyVI=
=9zhR
-----END PGP SIGNATURE-----
--
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]