[From nobody Fri Sep 18 11:59:11 2026
Received: (at submit) by bugs.debian.org; 13 Sep 2014 19:37:21 +0000
X-Spam-Checker-Version: SpamAssassin 3.3.2-bugs.debian.org_2005_01_02
 (2011-06-06) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-9.4 required=4.0 tests=BAYES_00,DIGITS_LETTERS,
 HAS_PACKAGE,RCVD_IN_BL_SPAMCOP_NET,RCVD_IN_DNSWL_MED,RCVD_IN_NIX1,SPF_PASS,
 T_RP_MATCHES_RCVD,X_DEBBUGS_CC autolearn=ham
 version=3.3.2-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 19; hammy, 128; neutral, 39; spammy,
 1. spammytokens:0.860-+--truth hammytokens:0.000-+--H*F:U*sanvila,
 0.000-+--H*rp:U*sanvila, 0.000-+--logcheck, 0.000-+--H*u:DEB, 0.000-+--H*M:DEB
Return-path: &lt;sanvila@unex.es&gt;
Received: from pizarro.unex.es ([158.49.8.2])
 by buxtehude.debian.org with esmtp (Exim 4.80)
 (envelope-from &lt;sanvila@unex.es&gt;) id 1XSt8K-0005dP-QX
 for submit@bugs.debian.org; Sat, 13 Sep 2014 19:37:21 +0000
Received: from zproxy02.servicios.unex.es (zproxy02.unex.es [158.49.17.43])
 by pizarro.unex.es (Postfix) with ESMTP id 6C4C811E2A1
 for &lt;submit@bugs.debian.org&gt;; Sat, 13 Sep 2014 20:53:10 +0200 (CEST)
Received: from localhost (localhost [127.0.0.1])
 by zproxy02.servicios.unex.es (Postfix) with ESMTP id E062C64170
 for &lt;submit@bugs.debian.org&gt;; Sat, 13 Sep 2014 20:14:49 +0200 (CEST)
Received: from zproxy02.servicios.unex.es ([127.0.0.1])
 by localhost (zproxy02.servicios.unex.es [127.0.0.1]) (amavisd-new, port 10032)
 with ESMTP id hZW3iiLqm-7u for &lt;submit@bugs.debian.org&gt;;
 Sat, 13 Sep 2014 20:14:49 +0200 (CEST)
Received: from localhost (localhost [127.0.0.1])
 by zproxy02.servicios.unex.es (Postfix) with ESMTP id 43A1964185
 for &lt;submit@bugs.debian.org&gt;; Sat, 13 Sep 2014 20:14:49 +0200 (CEST)
X-Virus-Scanned: amavisd-new at zproxy02.siue
Received: from zproxy02.servicios.unex.es ([127.0.0.1])
 by localhost (zproxy02.servicios.unex.es [127.0.0.1]) (amavisd-new, port 10026)
 with ESMTP id uIxtybt4bamE for &lt;submit@bugs.debian.org&gt;;
 Sat, 13 Sep 2014 20:14:49 +0200 (CEST)
Received: from cantor.unex.es (cantor.unex.es [158.49.50.20])
 by zproxy02.servicios.unex.es (Postfix) with ESMTPSA id 0A0E564170
 for &lt;submit@bugs.debian.org&gt;; Sat, 13 Sep 2014 20:14:48 +0200 (CEST)
Received: by cantor.unex.es (Postfix, from userid 1000)
 id 307A742EBD; Sat, 13 Sep 2014 20:15:24 +0200 (CEST)
Received: from localhost (localhost [127.0.0.1])
 by cantor.unex.es (Postfix) with ESMTP id 2477C3FDB3
 for &lt;submit@bugs.debian.org&gt;; Sat, 13 Sep 2014 20:15:24 +0200 (CEST)
Date: Sat, 13 Sep 2014 20:15:24 +0200 (CEST)
From: Santiago Vila &lt;sanvila@unex.es&gt;
To: submit@bugs.debian.org
Subject: puppet resource does not tell the truth for files that may not be
 accessed
Message-ID: &lt;alpine.DEB.2.11.1409131949130.25087@cantor.unex.es&gt;
User-Agent: Alpine 2.11 (DEB 23 2013-08-11)
X-Debbugs-Cc: sanvila@unex.es
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Delivered-To: submit@bugs.debian.org

Package: puppet-common
Version: 3.7.0-1

I have a bunch of logcheck rules in /etc/logcheck/ignore.d.paranoid/mylogcheck,
served by puppet.

If I query puppet about it as root, I get this:

# puppet resource file /etc/logcheck/ignore.d.paranoid/mylogcheck
file { '/etc/logcheck/ignore.d.paranoid/mylogcheck':
  ensure  =&gt; 'file',
  content =&gt; '{md5}88fc34cf0e49645dc5635ee44ec803a4',
  ctime   =&gt; '2014-09-13 13:12:13 +0200',
  group   =&gt; '116',
  mode    =&gt; '640',
  mtime   =&gt; '2014-09-13 13:12:13 +0200',
  owner   =&gt; '0',
  type    =&gt; 'file',
}

but if I query about it as a normal user, I get this:

$ puppet resource file /etc/logcheck/ignore.d.paranoid/mylogcheck
Warning: /File[/etc/logcheck/ignore.d.paranoid/mylogcheck]: Could not stat; permission denied
file { '/etc/logcheck/ignore.d.paranoid/mylogcheck':
  ensure =&gt; 'absent',
}

The ensure =&gt; 'absent' part is simply not true.

The &quot;ignore.d.paranoid&quot; directory above is root:logcheck and it has
&quot;rwxr-s---&quot; permissions, so the considered file may not even be
accessed.

It should be noted that puppet gives a proper error for files it can
access but not read. In fact, if I change &quot;ignore.d.paranoid&quot; to be
mode 755 and try again as a normal user, I get this instead:

$ puppet resource file /etc/logcheck/ignore.d.paranoid/mylogcheck 
Error: Could not run: Could not read file /etc/logcheck/ignore.d.paranoid/mylogcheck: Permission denied @ rb_sysopen - /etc/logcheck/ignore.d.paranoid/mylogcheck

So, maybe this could be fixed by considering this case as an Error and
not as a Warning.

Thanks.
]