Re: Odd situation - SETUID fail
Posted in 2009
Jonathan Leffler wrote:
>
> | root@note-cim:/# grep informix /etc/passwd
> | informix:x:1001:1000:DBSA Informix:/home/informix:/bin/bash
>
>
> This is good. But I'm still very puzzled about why the error message
> suggests changing group to 'root'; I have a feeling this will be a key
> to the issue.
>
> Questions:
> (1) Are you just using local file for /etc/passwd and /etc/group?
> (2) Do you get any entries other than the informix entry when you run
> 'grep :1000: /etc/group'?
1 - Yes , just /etc/passwd and /etc/group. The default configuration on
OpenSuse 11.1
2 - No
| root@note-cim:~# grep ":1000" /etc/group
| informix:!:1000:
>
>
> | root@note-cim:/# rm -rf /INFORMIXTMP
> | removed `/INFORMIXTMP/.infxdirs'
> | removed `/INFORMIXTMP/.idsmoon.alarm'
> | removed directory: `/INFORMIXTMP'
>
>
> 100% tangential question: what version of 'rm' tells you what it is
> removing?
The linux "rm" , I just keep a alias with "-v" option:
| root@note-cim:~# which rm
| /bin/rm
| root@note-cim:~# type rm
| rm is aliased to `rm -v'
| root@note-cim:~# rpm -qf /bin/rm
| coreutils-6.12-32.10
| root@note-cim:~# alias rm
| alias rm='rm -v'
>
> | root@note-cim:/# echo $INFORMIXSERVER
> | idsmoon
> |
> | root@note-cim:/# chown :root /ifmxdados/*
>
>
> An unusual way of writing 'chgrp root', I assume? ... Hmmm, not
> quite; when I used it on Solaris (as root) it also changed the owner
> to root.
This is acceptable on linux, I don't remember if works on Solaris .
Copied from "man chown':
| Owner is unchanged if missing. Group is unchanged if missing,
but changed to login group if implied by a `:' fol-
| lowing a symbolic OWNER. OWNER and GROUP may be numeric as well
as symbolic.
>
>
> |
> | root@note-cim:/# ls -la /INFORMIXTMP/
> | total 12
> | drwxrwxr-t 2 informix informix 4096 2009-04-05 12:37 .
> | drwxr-xr-x 24 root root 4096 2009-04-05 12:37 ..
> | -rw-rw-r-- 1 root informix 22 2009-04-05 12:37 .infxdirs
> | srwxrwx--- 1 root informix 0 2009-04-05 12:37
> VP.idsmoon.010100s
>
>
>
> This is what I'd expect...but why the heck is it not working?
Good question!
>
> You're using a UC3DE version; it shouldn't be a question of 32-bit
> values being mishandled in a 64-bit environment, and it would be hard
> to explain even so.
My note is a Netbook , ASUS Eee PC 1000 , Intel Atom N270 . Before
install Linux and windows I do a research to know if is 32 or 64 bits,
and is 32 bits. this is the /proc/cpuinfo :
| root@note-cim:~# cat /proc/cpuinfo
| processor : 0
| vendor_id : GenuineIntel
| cpu family : 6
| model : 28
| model name : Intel(R) Atom(TM) CPU N270 @ 1.60GHz
| stepping : 2
| cpu MHz : 800.000
| cache size : 512 KB
| physical id : 0
| siblings : 2
| core id : 0
| cpu cores : 1
| apicid : 0
| initial apicid : 0
| fdiv_bug : no
| hlt_bug : no
| f00f_bug : no
| coma_bug : no
| fpu : yes
| fpu_exception : yes
| cpuid level : 10
| wp : yes
| flags : fpu vme de pse tsc msr pae mce cx8 apic sep mtrr
pge mca cmov pat clflush dts acpi mmx fxsr sse sse2 ss ht tm pbe nx
constant_tsc arch_perfmon pebs bts pni monitor ds_cpl est tm2 ssse3 xtpr
lahf_lm
| bogomips : 3199.96
| clflush size : 64
| power management:
>
>
> .
> | 13:24:28 IBM Informix Dynamic Server Version 11.50.UC3DE
> Software Serial Number AAA#B000000
> | 13:24:28 The chunk '/ifmxdados/L_rootdbs.ch1' must have
> owner-ID "informix" and group-ID "root".
>
>
>
> This message has me puzzled. Why is it saying 'root'? That's
> "warning" message +1663 from olutil.iem.
>
> The evidence I can find in the source code indicates that getegid() is
> being used to determine the group, so the oninit program is running
> 'setgid root' on your machine, for some weird reason.
>
>
I will execute one more test : download a OpenSuse 11.1 Live CD, boot on
my note and install the IDS , and watch if the same problem occur. If
yes , I will try this on a desktop machine ... if the problem persists ,
I tell you and this way, if you want, can simulate the problem.
My guess is some kind of incompatible call on GLIBC library. The gap
between 2.9 and 2.4 is to big...
| # rpm -q glibc
| glibc-2.9-2.11.1
| # grep -i glibc ids_machine_notes_11.50.txt
| (Nahant Update 3, Kernel: 2.6.9, Glibc: 2.3.4) for i686 compatible
| processors. The i686 version of glibc is required. The following
| - Red Hat Enterprise Linux ES release 5 (Kernel: 2.6.18, Glibc:
2.5)
>| - SUSE SLES 10 (Kernel: 2.6.16, Glibc: 2.4) for i686 and x86_64
| - Asianux 2.0 (Kernel: 2.6.9, Glibc: 2.3.4) for i686 and x86_64
| - Ubuntu Server Edition 6.06.1 LTS (Kernel: 2.6.15, Glibc:
2.3.6) for
| - Debian 4.0 (Kernel: 2.6.18, Glibc: 2.3.6) for i686 and x86_64