[Pkg-cacti-maint] Bug#923309: cacti-spine_1.1.37-2~bpo9+1 fails to run under non-root user

Paul Allen paul at inetz.com
Wed May 8 22:14:37 BST 2019


Sorry for the late reply, work became insane after this.

I upgraded to the new cacti-spine again and ran the setcap command and
it is working for the non-root user now. Thanks for the assistance on
this. The bug can now be closed.

Paul Allen

Inetz Sr. Systems Administrator
801-415-2562

On 3/14/19 5:03 AM, Paul Gevers wrote:
> Control: tags -1 moreinfo
>
> Hi Paul
>
> On 27-02-2019 21:53, Sven Hartge wrote:
>> On 27.02.19 21:35, Paul Gevers wrote:
>>
>>> @Paul, Thanks for reporting this issue. Please check the existing
>>> comments in bug 904332
>>>
>>> https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=904332
>>>
>>> @Sven can you please help us and maybe explain how Paul should be using
>>> the cacti-spine binary with these Linux capabilities enabled that we
>>> added in that version by your patch. I guess he needs to install
>>> libcap2-bin and run $(chmod u-s /usr/sbin/spine)
>> Yes, but one additional step:
>>
>> You also need to set the capabilities:
>>
>>    setcap cap_net_raw+ep /usr/sbin/spine
>>
>> After that, everything should be back in working order.
>>
>> If not, then the bug is at a different place. Also the missing setuid
>> bit and the missing capabilities only prevent the use of the
>> ICMP-Checker for Host Liveliness Checking, but not the failure to run at
>> all.
>>
>> Without those two bits in place, SNMP gathering will still work.
> Did the reply from Sven help? I.e. do you think this bug can be closed?
>
> Paul
>



More information about the Pkg-cacti-maint mailing list