Package: netdata
Version: 1.19.0-2~bpo10+1
Severity: important

Dear Maintainer,

I did my own backport of netdata 1.19.0-2 to buster without any change
from unstable sources and noticed that mail alarms do not work.

I see some "Failed to create spool file
/var/spool/exim4//input//1j5uL8-0001du-VH-D: Read-only file system"
errors from exim logs and "failed to send email notification" from netdata logs

I believe that the change introduced by
https://salsa.debian.org/debian/netdata/-/commit/421a6b0b905cd3cbb51a2cdf193f75a4166a6e5b
fallbacks the fix for this issue already reported in #851852 and fixed
in 
https://salsa.debian.org/debian/netdata/-/commit/ddac3bd0ae77f5a722df7ae2ae1938055c20012a

I believe that the systemd service file should be reconsidered as far as
filesystem permissions are concerned.

I would recommend the following as a compromise between security and
functionality, with the additional benefit of simplifying the service
file maintenance:

ProtectSystem=strict
ReadWriteDirectories=/var

What do you think ?
Cheers !

-- System Information:
Debian Release: 10.3
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 4.19.0-8-amd64 (SMP w/4 CPU cores)
Locale: LANG=fr_FR.UTF-8, LC_CTYPE=fr_FR.UTF-8 (charmap=UTF-8), 
LANGUAGE=fr_FR.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages netdata depends on:
ii  netdata-core          1.19.0-2~bpo10+1
ii  netdata-plugins-bash  1.19.0-2~bpo10+1
ii  netdata-web           1.19.0-2~bpo10+1

Versions of packages netdata recommends:
pn  netdata-plugins-nodejs  <none>
ii  netdata-plugins-python  1.19.0-2~bpo10+1

netdata suggests no packages.

-- no debconf information

Reply via email to