New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Stemcell 3262.12] Permissions for /tmp are 700 instead of 770 #97
Comments
After some more investigation:
|
Nice investigation! I agree with what you've discovered. So, to recap, the issue happens to be fixed on bosh-agent's develop, but we should consider backporting those fixes onto 3262.x because, while most environments won't hit this initially, if the agent crashes or is intentionally restarted we will start seeing this strange and incorrect behavior during standard BOSH lifecycles. Sounds like something @cppforlife will care about. |
I believe this could be closed at this point? @voelzmo @dpb587-pivotal |
yeah, this is fixed in most recent stemcells. |
We've seen permissions for
/tmp
being wrong for many VMs that have been updated to use stemcell 3262.12. Instead of770
, it has700
.Here an example from the agent logs of a Director provisioned with bosh-init on a 3262.12 stemcell:
It seems like first the monit jobs are started
Then the agent is re-started
Then some chmodding happens on
/tmp
and the directory which is later bind-mounted to/tmp
At that point in time, the directory
/var/vcap/data/root_tmp
is not mounted to/tmp
yetI can't really find in the agent logs now when that happened. On the VM itself it seems, however, that the bind-mount happened some time
And in
/tmp
we have some postgres .lock file which breaks Director updatesNote that the files were created before the above things in the agent log happened?
For comparison, here is some output for a stemcell where it actually works
Creation of
/tmp
and some chmoddingsome chmodding and bind-mounting
Then some more chmodding and actual bind-mounting
Monit start seems to happen only after that:
any ideas what happened there?
The text was updated successfully, but these errors were encountered: