Devuan bug report logs - #653
start-stop-daemon: matching only on non-root pidfile /run/puppet/master.pid is insecure

Package: puppet-master; Reported by: Joril <jorilx@gmail.com>; Keywords: debian; Forwarded to https://bugs.debian.org/1003867; Maintainer for puppet-master is (unknown).
Set bug forwarded-to-address to 'https://bugs.debian.org/1003867'. Request was from Mark Hindley <mark@hindley.org.uk> to control@bugs.devuan.org. Full text available.
Added tag(s) debian. Request was from Mark Hindley <mark@hindley.org.uk> to 653-submit@bugs.devuan.org. Full text available.

Message received at 653@bugs.devuan.org:


Received: (at 653) by bugs.devuan.org; 15 Jan 2022 10:00:02 +0000
Return-Path: <mark@hindley.org.uk>
Delivered-To: devuanbugs@dyne.org
Received: from tupac3.dyne.org [195.169.149.119]
	by doc.devuan.org with IMAP (fetchmail-6.4.16)
	for <debbugs@localhost> (single-drop); Sat, 15 Jan 2022 10:00:02 +0000 (UTC)
Received: from mx.hindley.org.uk (193-36-131-86.cfwn.uk [193.36.131.86])
	(using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
	(No client certificate requested)
	by mail.dyne.org (Postfix) with ESMTPS id 07BAF66135B
	for <653@bugs.devuan.org>; Sat, 15 Jan 2022 10:59:15 +0100 (CET)
Received: from apollo.hindleynet ([192.168.1.3] helo=hindley.org.uk)
	by mx.hindley.org.uk with smtp (Exim 4.84_2)
	(envelope-from <mark@hindley.org.uk>)
	id 1n8fq4-0006fy-Hj; Sat, 15 Jan 2022 09:59:12 +0000
Received: (nullmailer pid 32156 invoked by uid 1000);
	Sat, 15 Jan 2022 09:59:11 -0000
Date: Sat, 15 Jan 2022 09:59:11 +0000
From: Mark Hindley <mark@hindley.org.uk>
To: Joril <jorilx@gmail.com>, 653@bugs.devuan.org
Subject: Re: bug#653: start-stop-daemon: matching only on non-root pidfile
 /run/puppet/master.pid is insecure
Message-ID: <YeKa77XpW6uRqbt/@hindley.org.uk>
References: <164223690854.6170.5422121946210487709.reportbug@atools.panizzolo.local>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <164223690854.6170.5422121946210487709.reportbug@atools.panizzolo.local>
X-Debbugs-No-Ack: No Thanks
X-Spam-Status: No, score=0.4 required=5.0 tests=RCVD_IN_DNSWL_BLOCKED,
	RDNS_DYNAMIC,SPF_PASS autolearn=disabled version=3.4.2
X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on mail.dyne.org

Control: tags -1 debian

Joril,

Thanks for this.

On Sat, Jan 15, 2022 at 09:55:08AM +0100, Joril wrote:
> Package: puppet-master
> Version: 5.5.10-4
> Severity: normal

Puppet-master is not a forked package in Devuan and we use Debian's packages
directly without recompilation. Please would you report this issue to Debian's
BTS.

Thanks.

Mark

Information forwarded to devuan-bugs@lists.dyne.org, devuan-dev@lists.dyne.org:
bug#653; Package puppet-master. Full text available.

Message received at submit@bugs.devuan.org:


Received: (at submit) by bugs.devuan.org; 15 Jan 2022 08:55:41 +0000
Return-Path: <jorilx@gmail.com>
Delivered-To: devuanbugs@dyne.org
Received: from tupac3.dyne.org [195.169.149.119]
	by doc.devuan.org with IMAP (fetchmail-6.4.16)
	for <debbugs@localhost> (single-drop); Sat, 15 Jan 2022 08:55:41 +0000 (UTC)
Received: from smtpauth.panizzolo.it (smtpauth.panizzolo.it [78.47.72.61])
	(using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
	(No client certificate requested)
	by mail.dyne.org (Postfix) with ESMTPS id D8D8D661360
	for <submit@bugs.devuan.org>; Sat, 15 Jan 2022 09:55:01 +0100 (CET)
Received: from atools.panizzolo.local (unknown [217.194.188.145])
	by smtpauth.panizzolo.it (Postfix) with ESMTP id F0C931203C2;
	Sat, 15 Jan 2022 09:55:00 +0100 (CET)
Received: by atools.panizzolo.local (Postfix, from userid 1000)
	id A055F555; Sat, 15 Jan 2022 09:55:08 +0100 (CET)
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Joril <jorilx@gmail.com>
To: Devuan Bug Tracking System <submit@bugs.devuan.org>
Subject: start-stop-daemon: matching only on non-root pidfile /run/puppet/master.pid is insecure
Message-ID: <164223690854.6170.5422121946210487709.reportbug@atools.panizzolo.local>
Date: Sat, 15 Jan 2022 09:55:08 +0100
X-Spam-Status: No, score=3.2 required=5.0 tests=DKIM_ADSP_CUSTOM_MED,
	FORGED_GMAIL_RCVD,FREEMAIL_FROM,NML_ADSP_CUSTOM_MED,
	RCVD_IN_DNSWL_BLOCKED,SPF_SOFTFAIL autolearn=disabled version=3.4.2
X-Spam-Level: ***
X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on mail.dyne.org

Package: puppet-master
Version: 5.5.10-4
Severity: normal

Dear Maintainer,

Trying to stop puppet-master on Beowulf results in this error:

# service puppet-master stop
[....] Stopping puppet masterstart-stop-daemon: matching only on non-root pidfile /run/puppet/master.pid is insecure
 failed!

Thanks for your time!

-- System Information:
Distributor ID:	Devuan
Description:	Devuan GNU/Linux 3 (beowulf)
Release:	3
Codename:	beowulf
Architecture: x86_64

Kernel: Linux 4.19.0-18-amd64 (SMP w/1 CPU core)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE=en_US:en (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: sysvinit (via /sbin/init)
LSM: AppArmor: enabled

Versions of packages puppet-master depends on:
ii  lsb-base  10.2019051400
ii  puppet    5.5.10-4
ii  ruby      1:2.5.1

puppet-master recommends no packages.

puppet-master suggests no packages.

-- no debconf information

Acknowledgement sent to Joril <jorilx@gmail.com>:
New bug report received and forwarded. Copy sent to devuan-dev@lists.dyne.org. Full text available.
Report forwarded to devuan-bugs@lists.dyne.org, devuan-dev@lists.dyne.org:
bug#653; Package puppet-master. Full text available.

Devuan BTS -- Powered by Debian bug tracking system
Copyright (C) 1999 Darren O. Benham,
1997 nCipher Corporation Ltd, 1994-97 Ian Jackson.

Devuan Bugs Owner <owner@bugs.devuan.org>.
Last modified: Sun, 22 May 2022 18:39:02 UTC