Tech Support > Operating Systems > Linux / Variants > RHN updates and protected /bin files -- what happens?
RHN updates and protected /bin files -- what happens?
Posted by Dan DeLion on September 13th, 2003


I protected my various /bin directories against cockroaches with chattr -iu
on the files, but now I'm wondering what kind of side effects this may cause
with the RHN (Redhat Network) automatic updates/patches. Will some of these
updates fail, or cause a partial-install mess, or will RHN deal with it
gracefully?



Posted by John Reiser on September 13th, 2003


Yes.

Yes.

No.

It happened to me "by accident", and rpm refuses to deal with chattr.
See http://bugzilla.redhat.com/bugzilla/...g.cgi?id=66511


Posted by Michael W. Cocke on September 13th, 2003


On Fri, 12 Sep 2003 21:39:59 -0700, John Reiser <jreiser@BitWagon.com>
wrote:


I suggest tripwire - it's a major pain to set up, but works fine for
letting you know what, if any, files have changed.

Mike-

Mornings: Evolution in action. Only the grumpy will survive.
-----------------------------------------------------

Please note - Due to the intense volume of spam, we have
installed site-wide spam filters at catherders.com. If
email from you bounces, try non-HTML, non-encoded,
non-attachments.


----== Posted via Newsfeed.Com - Unlimited-Uncensored-Secure Usenet News==----
http://www.newsfeed.com The #1 Newsgroup Service in the World! >100,000 Newsgroups
---= 19 East/West-Coast Specialized Servers - Total Privacy via Encryption =---

Posted by Dan DeLion on September 13th, 2003


Using chattr -i helps prevent some attacks while tripwire only warns after
something happens.




"Michael W. Cocke" <cocke@catherders.com> wrote in message
newsf16mvkapp01n4fl5tdvq1in2plm5nmf4n@4ax.com...



Posted by Dan DeLion on September 13th, 2003


That's a serious bug in RHN.

I wonder what would the best way to perform the updates in this case?

Perhaps set up a cron script to chattr -iu and then run up2date -u, then put
the chattr back?



"John Reiser" <jreiser@BitWagon.com> wrote in message
news:3F629F9F.1090806@BitWagon.com...


Posted by Rich Piotrowski on September 13th, 2003


On Sat, 13 Sep 2003 19:42:01 GMT, "Dan DeLion"
<noemail@northpole.nowhere> wrote:

******** top posting corrected **********

Why is that a bug? You make the files immutable then complain when
they can't be overwritten?


Rich Piotrowski

To reply via E-Mail use rpiotro(at)wi(dot)rr(dot)com


Similar Posts