[cups.general] Possibly insecure default LogFilePerm value 0644

Johannes Meixner jsmeix at suse.de
Tue Jul 12 04:38:51 PDT 2011


Hello,

On Jul 12 03:42 Helge Blischke wrote:
> Making the error_log at least world readable makes sense in cases where
> utilities outside of CUPS are used to schow diagnostic or status information
> for aborted jobs to the user. For instance I myself often use WARNING and
> NOTICE messages in my filters to log the occurance of arguable conditions to
> the error_log.

Could you provide more details because I do not understand why you need
a world readable error_log file for this because tools like "lpstat"
are run by normal users and can display queue state information
(in particular the printer-state-message attribute in CUPS)
via appropriate CUPS library calls (e.g. via a cupsDoRequest call)
without the need to read the /var/log/cups/error_log file directly
and e.g. WARNING/NOTICE messages in filters set the printer-state-message
attribute according to "man 7 filter" (at least in CUPS 1.4.6 which I run).


Kind Regards
Johannes Meixner
-- 
SUSE LINUX Products GmbH -- Maxfeldstrasse 5 -- 90409 Nuernberg -- Germany
HRB 16746 (AG Nuernberg) GF: Jeff Hawn, Jennifer Guild, Felix Imendoerffer





More information about the cups mailing list