Package: netdata
Version: 1.5.0+dfsg-4
Severity: normal

Hi!

The exim4 plugin/monitor needs CAP_SETUID to function, otherwise you
only get the following log messages upon netdata start:

,----
| Mar  1 01:29:01 ds9 exim[564661]: exim: setuid for log-file creation failed, 
aborting
| Mar  1 01:29:01 ds9 exim[564662]: exim: setuid for log-file creation failed, 
aborting
| Mar  1 01:29:01 ds9 exim[564660]: 2017-03-01 01:29:01 unable to set gid=112 
or uid=112 (euid=0): calling tls_validate_require_cipher
| Mar  1 01:29:01 ds9 exim[564660]: 2017-03-01 01:29:01 Cannot open main log 
file "/var/log/exim4/mainlog": Permission denied: euid=0 egid=112
| Mar  1 01:29:01 ds9 exim[564660]: exim: could not open panic log - aborting: 
see message(s) above
| Mar  1 01:29:01 ds9 exim[564665]: exim: setuid for log-file creation failed, 
aborting
| Mar  1 01:29:01 ds9 exim[564666]: exim: setuid for log-file creation failed, 
aborting
| Mar  1 01:29:01 ds9 exim[564664]: 2017-03-01 01:29:01 unable to set gid=112 
or uid=112 (euid=0): calling tls_validate_require_cipher
| Mar  1 01:29:01 ds9 exim[564664]: 2017-03-01 01:29:01 Cannot open main log 
file "/var/log/exim4/mainlog": Permission denied: euid=0 egid=112
| Mar  1 01:29:01 ds9 exim[564664]: exim: could not open panic log - aborting: 
see message(s) above
`----

/usr/sbin/exim4 is setuid-root and will change to
Debian-exim:Debian-Exim (uid/gid 112/112 on my system) after start. 
If th CAP_SETUID capability is absent, this will not work and the
execution of "/usr/sbin/exim4 -bpc" from the exim4-plugin will not work.

Grüße,
Sven.

-- System Information:
Debian Release: 9.0
  APT prefers unstable-debug
  APT policy: (500, 'unstable-debug'), (500, 'testing-debug'), (500, 
'unstable'), (500, 'testing'), (200, 'experimental'), (1, 'experimental-debug')
Architecture: i386 (x86_64)
Foreign Architectures: amd64

Kernel: Linux 4.8.0-2-amd64 (SMP w/4 CPU cores)
Locale: LANG=de_DE.utf8, LC_CTYPE=de_DE.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages netdata depends on:
ii  adduser              3.115
ii  init-system-helpers  1.47
ii  libc6                2.24-9
ii  libcap2-bin          1:2.25-1
ii  libuuid1             2.29.1-1
ii  lsb-base             9.20161125
ii  netdata-data         1.5.0+dfsg-4
ii  python               2.7.13-2
ii  python-yaml          3.12-1
ii  zlib1g               1:1.2.8.dfsg-5

Versions of packages netdata recommends:
pn  nodejs  <none>

netdata suggests no packages.

-- Configuration Files:
/etc/netdata/health.d/disks.conf changed [not included]
/etc/netdata/health_alarm_notify.conf changed [not included]
/etc/netdata/netdata.conf changed [not included]
/etc/netdata/python.d/apache.conf changed [not included]

-- debconf-show failed

-- debsums errors found:
debsums: changed file /lib/systemd/system/netdata.service (from netdata package)

Reply via email to