On Tuesday 29 Jan 2013 10:19:16 Alan McKinnon wrote:
> On Tue, 29 Jan 2013 06:37:47 +0000
> 
> Mick <[email protected]> wrote:
> > Hi All,
> > 
> > I got this message when net-mail/mailbase-1.1 was emerged:
> > 
> > * Messages for package net-mail/mailbase-1.1:
> >  * Your //var/spool/mail/ directory permissions differ from
> >  *   those which mailbase wants to set it to (03775).
> >  *   If you did not change them on purpose, consider running:
> >  *
> >  *     chown root:mail //var/spool/mail/
> >  *     chmod 03775 //var/spool/mail/
> > 
> > Running this chmod changed access rights from:
> >   drwxrwxr-x  2 root mail 4096 Jan 28 19:57 mail
> > 
> > to a sticky-fied:
> >   drwxrwsr-t  2 root mail 4096 Jan 28 19:57 mail
> > 
> > Any idea why are the sticky bits for group and others required?
> 
> sticky for group so that all sub-dirs and files in them are owned by
> the mail group. Without it, they would be owned by the user running
> "mailx" and the mail system can no longer manager them.
> 
> sticky for others is so that you can't delete my mail but you can still
> create your own mail spool files. Identical logic to /tmp (assuming
> that you are in the mail group)

Thanks Alan, it makes sense now.  No one other than mail are in the mail group 
in this box (my laptop):

$ less /etc/group | grep mail
mail:x:12:mail

I have rkhunter and some cron jobs using ssmtp to email me log info, but they 
have been running as root.  That's why I hadn't experienced a problem with the 
previous access rights.  I wonder why this was picked up in the 1.1 version 
and not previously - perhaps a test was added on purpose in the ebuild.
-- 
Regards,
Mick

Attachment: signature.asc
Description: This is a digitally signed message part.

Reply via email to