From lianep@nihil.Eng.Sun.COM Sun Jul 25 21:17:04 2010
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o6Q4H3HA007520
	for <psarc-ext@sac.sfbay.sun.com>; Sun, 25 Jul 2010 21:17:04 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.4) with ESMTP id o6Q4H3Dh030480
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Sun, 25 Jul 2010 22:17:03 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0L6500401D8FER00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Sun, 25 Jul 2010 21:17:03 -0700 (PDT)
Received: from nihil.Eng.Sun.COM ([129.146.228.161])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0L650021UD8EWCC0@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Sun,
 25 Jul 2010 21:17:02 -0700 (PDT)
Received: from nihil.Eng.Sun.COM (localhost [127.0.0.1])
	by nihil.Eng.Sun.COM (8.14.4+Sun/8.14.4) with ESMTP id o6Q4H0sK110020; Sun,
 25 Jul 2010 21:17:00 -0700 (PDT)
Received: (from lianep@localhost)
	by nihil.Eng.Sun.COM (8.14.4+Sun/8.14.4/Submit) id o6Q4H0vG110018; Sun,
 25 Jul 2010 21:17:00 -0700 (PDT)
Date: Sun, 25 Jul 2010 21:17:00 -0700 (PDT)
From: Liane Praza <lianep@nihil.Eng.Sun.COM>
Subject: logadm.conf upgrade [PSARC/2010/290 FastTrack timeout 07/27/2010]
To: psarc-ext@sun.com
Cc: antonello.cruz@oracle.com, gavin.maltby@oracle.com
Message-id: <201007260417.o6Q4H0vG110018@nihil.Eng.Sun.COM>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 2456

This case seeks minor binding.  The timer is shorter than the
standard week to accomodate a tight integration schedule.  If
anyone needs additional time to review this, let us know.

Template Version: @(#)sac_nextcase 1.70 03/30/10 SMI
This information is Copyright (c) 2010, Oracle and/or its affiliates. All rights reserved.
1. Introduction
    1.1. Project/Component Working Name:
	 logadm.conf upgrade
    1.2. Name of Document Author/Supplier:
	 Author:  Antonello Cruz
    1.3  Date of This Document:
	25 July, 2010
4. Technical Description
    4.1. Details:
         IPS tags /etc/logadm.conf with preserve=true so that changes
         made by sysadmins are preserved on image-update. This creates a
         problem when a pkg needs to add an entry in /etc/logadm.conf.
         First, it is likely that the pkg does not own /etc/logadm.conf
         second the file may not be installed in the system if the
         original file has been edited.

         To workaround this problem this project will create a new
         directory in /etc/logadm.d and an SMF service
         svc:/system/logadm-upgrade. A pkg wanting to add entries
         in /etc/logadm.conf can drop a file with the entries in that
         directory. The start method of the service will look for
         logname for the entry, as defined in logadm.conf(4), in
         /etc/logadm.conf. If the logname is not found, the entry from
         the file will be appended to /etc/logadm.conf. The pkg dropping
	 a file in /etc/logadm.d have to set the actuator
	 refresh_fmri='svc:/system/logadm-upgrade:default' in order to
	 have the contents of the file processed on install on a live
	 BE.

         Only files with permissions 644, owned by root and group sys
         will be processed.

         This is supposed to be an interim solution as the right approach
         is to migrate /etc/logadm.conf to SMF.

         This project seeks minor binding.

    4.5. Interfaces:
         
         /etc/logadm.d          directory       Uncommitted
         svc:/system/logadm-upgrade             Uncommitted

    4.10. Packaging & Delivery:
         The svc:/system/logadm-upgrade service will be delivered
         by SUNWcs which is the same package delivering /etc/logadm.conf
    

6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		ON
    6.5. ARC review type: FastTrack
    6.6. ARC Exposure: open


From johnlev@barman.uk.sun.com Mon Jul 26 03:09:20 2010
Received: from sunmail6brm.central.sun.com (sunmail6brm.Central.Sun.COM [129.147.4.169])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o6QA9Kjj010085
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 26 Jul 2010 03:09:20 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail6brm.central.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id o6QA9JqZ022576
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Mon, 26 Jul 2010 05:09:20 -0500 (CDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0L6500003TJJ7Z00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Mon, 26 Jul 2010 03:09:19 -0700 (PDT)
Received: from dm-uk-01.uk.sun.com ([129.156.101.115])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0L6500AW6TJI4G90@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Mon,
 26 Jul 2010 03:09:19 -0700 (PDT)
Received: from barman.uk.sun.com (barman.UK.Sun.COM [129.156.132.12])
	by dm-uk-01.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id o6QA9Glh029000; Mon, 26 Jul 2010 11:09:17 +0100 (BST)
Received: from johnlev by barman.uk.sun.com with local (Exim 4.42)
	id 1OdKWD-0002CT-DH; Mon, 26 Jul 2010 11:02:45 +0100
X-URL: http://jurassic.eng/~johnlev/
Date: Mon, 26 Jul 2010 11:02:45 +0100
From: John Levon <john.levon@sun.com>
Subject: Re: logadm.conf upgrade [PSARC/2010/290 FastTrack timeout 07/27/2010]
In-reply-to: <201007260417.o6Q4H0vG110018@nihil.Eng.Sun.COM>
Sender: John Levon <johnlev@barman.uk.sun.com>
To: Liane Praza <lianep@nihil.Eng.Sun.COM>
Cc: psarc-ext@sun.com, antonello.cruz@oracle.com, gavin.maltby@oracle.com
Message-id: <20100726100245.GA3554@barman.uk.sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <201007260417.o6Q4H0vG110018@nihil.Eng.Sun.COM>
User-Agent: Mutt/1.5.6i
Status: RO
Content-Length: 951

On Sun, Jul 25, 2010 at 09:17:00PM -0700, Liane Praza wrote:

>          To workaround this problem this project will create a new
>          directory in /etc/logadm.d and an SMF service
>          svc:/system/logadm-upgrade. A pkg wanting to add entries
>          in /etc/logadm.conf can drop a file with the entries in that
>          directory. The start method of the service will look for
>          logname for the entry, as defined in logadm.conf(4), in
>          /etc/logadm.conf. If the logname is not found, the entry from
>          the file will be appended to /etc/logadm.conf. The pkg dropping
> 	 a file in /etc/logadm.d have to set the actuator
> 	 refresh_fmri='svc:/system/logadm-upgrade:default' in order to
> 	 have the contents of the file processed on install on a live
> 	 BE.

How does an uninstall remove the logadm entry? Why can't this just
process /etc/logadm.d in place (like /etc/logrotate.d on Linux) ?

regards
john

From gww@sac.sfbay.sun.com Mon Jul 26 08:10:53 2010
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o6QFAqC4014055
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 26 Jul 2010 08:10:53 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.4) with ESMTP id o6QFAq9F060073
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Mon, 26 Jul 2010 09:10:52 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0L66005057I4CL00@nwk-avmta-1.sfbay.Sun.COM> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Mon, 26 Jul 2010 08:10:52 -0700 (PDT)
Received: from dm-sfbay-01.sfbay.sun.com ([129.145.155.118])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0L6600DTP7I4SLE0@nwk-avmta-1.sfbay.Sun.COM> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Mon,
 26 Jul 2010 08:10:52 -0700 (PDT)
Received: from sac.sfbay.sun.com (sac.SFBay.Sun.COM [10.5.240.67])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id o6QFAp3i025785; Mon, 26 Jul 2010 08:10:51 -0700 (PDT)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o6QFApDt014052; Mon,
 26 Jul 2010 08:10:51 -0700 (PDT)
Received: (from gww@localhost)	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit)
 id o6QFApJ7014051; Mon, 26 Jul 2010 08:10:51 -0700 (PDT)
Date: Mon, 26 Jul 2010 08:10:51 -0700 (PDT)
From: Gary Winiger <gww@sac.sfbay.sun.com>
Subject: Re: logadm.conf upgrade [PSARC/2010/290 FastTrack timeout 07/27/2010]
To: lianep@nihil.Eng.Sun.COM, psarc-ext@sun.com
Cc: antonello.cruz@oracle.com, gavin.maltby@oracle.com
Message-id: <201007261510.o6QFApJ7014051@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 441

> This case seeks minor binding.  The timer is shorter than the
> standard week to accomodate a tight integration schedule.  If
> anyone needs additional time to review this, let us know.

	I'd like to see the aswer to John's question, other than
	that +1.

	And not this case; is there some place that the architecture
	of solving the "post-install script" problem in general is
	documented.  -- Seems like a nice Best Practice ;-)

Gary..

From danek.duvall@oracle.com Mon Jul 26 10:53:13 2010
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o6QHrDh9018698
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 26 Jul 2010 10:53:13 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id o6QHrDTj002746
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Mon, 26 Jul 2010 10:53:13 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0L6600C07F0PDA00@brm-avmta-1.central.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Mon, 26 Jul 2010 11:53:13 -0600 (MDT)
Received: from dm-sfbay-01.sfbay.sun.com ([129.145.155.118])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0L66004SAF0OXMB0@brm-avmta-1.central.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Mon,
 26 Jul 2010 11:53:12 -0600 (MDT)
Received: from smelly.SFBay.Sun.COM (smelly.SFBay.Sun.COM [129.146.228.142])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id o6QHrBWT027963; Mon, 26 Jul 2010 10:53:12 -0700 (PDT)
Received: from smelly.SFBay.Sun.COM (smelly [127.0.0.1])
	by smelly.SFBay.Sun.COM (8.14.4+Sun/8.14.4) with ESMTP id o6QHrB2h009739; Mon,
 26 Jul 2010 10:53:11 -0700 (PDT)
Received: (from dduvall@localhost)
	by smelly.SFBay.Sun.COM (8.14.4+Sun/8.14.4/Submit) id o6QHrBen009738; Mon,
 26 Jul 2010 10:53:11 -0700 (PDT)
Date: Mon, 26 Jul 2010 10:53:11 -0700
From: Danek Duvall <danek.duvall@oracle.com>
Subject: Re: logadm.conf upgrade [PSARC/2010/290 FastTrack timeout 07/27/2010]
In-reply-to: <201007260417.o6Q4H0vG110018@nihil.Eng.Sun.COM>
To: Liane Praza <lianep@nihil.Eng.Sun.COM>
Cc: psarc-ext@sun.com, antonello.cruz@oracle.com, gavin.maltby@oracle.com
Message-id: <20100726175311.GN2715@smelly.SFBay.Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <201007260417.o6Q4H0vG110018@nihil.Eng.Sun.COM>
User-Agent: Mutt/1.5.20 (2009-06-23)
Status: RO
Content-Length: 305

Liane Praza wrote:

>          Only files with permissions 644, owned by root and group sys
>          will be processed.

I suppose I can understand the other restrictions, but why only mode 644,
and not, say, 444, which would be a very natural mode for a file that's not
intended to be modified?

Danek

From antonello.cruz@oracle.com Mon Jul 26 11:37:12 2010
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o6QIbBgP019855
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 26 Jul 2010 11:37:11 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id o6QIbAda003411;
	Mon, 26 Jul 2010 11:37:10 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0L660011HH1YOJ00@nwk-avmta-1.sfbay.Sun.COM>; Mon,
 26 Jul 2010 11:37:10 -0700 (PDT)
Received: from brmea-mail-2.sun.com ([192.18.98.43])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0L6600HF4H1XF8A0@nwk-avmta-1.sfbay.Sun.COM>; Mon,
 26 Jul 2010 11:37:09 -0700 (PDT)
Received: from rcsinet15.oracle.com (rcsinet15.oracle.com [148.87.113.117])
	by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id o6QIb8BK005927; Mon,
 26 Jul 2010 18:37:08 +0000 (GMT)
Received: from acsmt354.oracle.com (acsmt354.oracle.com [141.146.40.154])
	by rcsinet15.oracle.com (Switch-3.4.2/Switch-3.4.1)
 with ESMTP id o6QIb77L021645; Mon, 26 Jul 2010 18:37:07 +0000 (GMT)
Received: from abhmt013.oracle.com by acsmt355.oracle.com	with ESMTP id
 437728911280169378; Mon, 26 Jul 2010 11:36:18 -0700
Received: from [10.7.251.3] (/10.7.251.3)
	by default (Oracle Beehive Gateway v4.0)	with ESMTP ; Mon,
 26 Jul 2010 11:36:17 -0700
Date: Mon, 26 Jul 2010 11:36:11 -0700
From: Antonello Cruz <antonello.cruz@oracle.com>
Subject: Re: logadm.conf upgrade [PSARC/2010/290 FastTrack timeout 07/27/2010]
In-reply-to: <20100726100245.GA3554@barman.uk.sun.com>
To: John Levon <john.levon@sun.com>
Cc: Liane Praza <lianep@nihil.Eng.Sun.COM>, psarc-ext@sun.com,
        gavin.maltby@oracle.com, Antonello Cruz <antonello.cruz@oracle.com>
Message-id: <4C4DD59B.2010108@oracle.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Source-IP: acsmt354.oracle.com [141.146.40.154]
X-Auth-Type: Internal IP
X-CT-RefId: str=0001.0A090205.4C4DD5D3.0210:SCFMA4539814,ss=1,fgs=0
References: <201007260417.o6Q4H0vG110018@nihil.Eng.Sun.COM>
 <20100726100245.GA3554@barman.uk.sun.com>
User-Agent: Mozilla/5.0 (X11; U; SunOS i86pc; en-US; rv:1.9.1.10)
 Gecko/20100621 Thunderbird/3.0.5
Status: RO
Content-Length: 1707

On 07/26/10 03:02 AM, John Levon wrote:
> On Sun, Jul 25, 2010 at 09:17:00PM -0700, Liane Praza wrote:
>
>>           To workaround this problem this project will create a new
>>           directory in /etc/logadm.d and an SMF service
>>           svc:/system/logadm-upgrade. A pkg wanting to add entries
>>           in /etc/logadm.conf can drop a file with the entries in that
>>           directory. The start method of the service will look for
>>           logname for the entry, as defined in logadm.conf(4), in
>>           /etc/logadm.conf. If the logname is not found, the entry from
>>           the file will be appended to /etc/logadm.conf. The pkg dropping
>> 	 a file in /etc/logadm.d have to set the actuator
>> 	 refresh_fmri='svc:/system/logadm-upgrade:default' in order to
>> 	 have the contents of the file processed on install on a live
>> 	 BE.
>
> How does an uninstall remove the logadm entry? Why can't this just
> process /etc/logadm.d in place (like /etc/logrotate.d on Linux) ?

That would be a very reasonable thing to consider when doing
general improvements to logadm.conf (e.g its current re-writing
behaviour which makes it hostile to read-only /etc deployments).
But, it seems like managing the directory in a way that allows
administrative customization like logadm.conf does today would take
more significant interface investment in the Committed parts of
logadm.conf than is an appropriate scope for this project.  This
project replaces the S10 i.logadmconf functionality, which did not
support removals either, and was also an ON-private Class Action Script.
We've attempted to set the interface stability at a level which
reflects that.

Antonello

>
> regards
> john


From antonello.cruz@oracle.com Mon Jul 26 11:39:28 2010
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o6QIdRfD019969
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 26 Jul 2010 11:39:27 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id o6QIdRFP018758
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Mon, 26 Jul 2010 11:39:27 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0L660020XH5R2G00@nwk-avmta-1.sfbay.Sun.COM> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Mon, 26 Jul 2010 11:39:27 -0700 (PDT)
Received: from sca-ea-mail-3.sun.com ([192.18.43.21])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0L6600HKMH5QF280@nwk-avmta-1.sfbay.Sun.COM> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Mon,
 26 Jul 2010 11:39:26 -0700 (PDT)
Received: from acsinet15.oracle.com (acsinet15.oracle.com [141.146.126.227])
	by sca-ea-mail-3.sun.com (8.13.6+Sun/8.12.9) with ESMTP id o6QIdPgD008065;
 Mon, 26 Jul 2010 18:39:26 +0000 (GMT)
Received: from acsmt354.oracle.com (acsmt354.oracle.com [141.146.40.154])
	by acsinet15.oracle.com (Switch-3.4.2/Switch-3.4.1)
 with ESMTP id o6QIdLqD030960; Mon, 26 Jul 2010 18:39:22 +0000 (GMT)
Received: from abhmt007.oracle.com by acsmt355.oracle.com	with ESMTP id
 458694141280169435; Mon, 26 Jul 2010 11:37:15 -0700
Received: from [10.7.251.3] (/10.7.251.3)
	by default (Oracle Beehive Gateway v4.0)	with ESMTP ; Mon,
 26 Jul 2010 11:37:15 -0700
Date: Mon, 26 Jul 2010 11:37:09 -0700
From: Antonello Cruz <antonello.cruz@oracle.com>
Subject: Re: logadm.conf upgrade [PSARC/2010/290 FastTrack timeout 07/27/2010]
In-reply-to: <20100726175311.GN2715@smelly.SFBay.Sun.COM>
To: Danek Duvall <danek.duvall@oracle.com>
Cc: Liane Praza <lianep@nihil.Eng.Sun.COM>, psarc-ext@sun.com,
        gavin.maltby@oracle.com
Message-id: <4C4DD5D5.1030708@oracle.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Source-IP: acsmt354.oracle.com [141.146.40.154]
X-Auth-Type: Internal IP
X-CT-RefId: str=0001.0A090201.4C4DD65C.0006:SCFMA4539814,ss=1,fgs=0
References: <201007260417.o6Q4H0vG110018@nihil.Eng.Sun.COM>
 <20100726175311.GN2715@smelly.SFBay.Sun.COM>
User-Agent: Mozilla/5.0 (X11; U; SunOS i86pc; en-US; rv:1.9.1.10)
 Gecko/20100621 Thunderbird/3.0.5
Status: RO
Content-Length: 434

On 07/26/10 10:53 AM, Danek Duvall wrote:
> Liane Praza wrote:
>
>>           Only files with permissions 644, owned by root and group sys
>>           will be processed.
>
> I suppose I can understand the other restrictions, but why only mode 644,
> and not, say, 444, which would be a very natural mode for a file that's not
> intended to be modified?
It makes sense. I'll change the restriction to mode 444.

Antonello

>
> Danek


From scott.rotondo@oracle.com Mon Jul 26 11:48:21 2010
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o6QImLWF020006
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 26 Jul 2010 11:48:21 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id o6QImL0q007428
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Mon, 26 Jul 2010 11:48:21 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0L6600401HKL0R00@nwk-avmta-1.sfbay.Sun.COM> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Mon, 26 Jul 2010 11:48:21 -0700 (PDT)
Received: from sca-ea-mail-2.sun.com ([192.18.43.25])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0L6600H9VHKKFC80@nwk-avmta-1.sfbay.Sun.COM> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Mon,
 26 Jul 2010 11:48:20 -0700 (PDT)
Received: from acsinet15.oracle.com (acsinet15.oracle.com [141.146.126.227])
	by sca-ea-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id o6QImFHf008275;
 Mon, 26 Jul 2010 18:48:15 +0000 (GMT)
Received: from acsmt354.oracle.com (acsmt354.oracle.com [141.146.40.154])
	by acsinet15.oracle.com (Switch-3.4.2/Switch-3.4.1)
 with ESMTP id o6QIXk8X011348; Mon, 26 Jul 2010 18:48:13 +0000 (GMT)
Received: from abhmt015.oracle.com by acsmt353.oracle.com	with ESMTP id
 458728841280170077; Mon, 26 Jul 2010 11:47:57 -0700
Received: from [129.146.108.62] (/129.146.108.62)
	by default (Oracle Beehive Gateway v4.0)	with ESMTP ; Mon,
 26 Jul 2010 11:47:56 -0700
Date: Mon, 26 Jul 2010 11:47:58 -0700
From: Scott Rotondo <scott.rotondo@oracle.com>
Subject: Re: logadm.conf upgrade [PSARC/2010/290 FastTrack timeout 07/27/2010]
In-reply-to: <4C4DD5D5.1030708@oracle.com>
To: Antonello Cruz <antonello.cruz@oracle.com>
Cc: Danek Duvall <danek.duvall@oracle.com>,
        Liane Praza <lianep@nihil.Eng.Sun.COM>, psarc-ext@sun.com,
        gavin.maltby@oracle.com
Message-id: <4C4DD85E.8050701@oracle.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Source-IP: acsmt354.oracle.com [141.146.40.154]
X-Auth-Type: Internal IP
X-CT-RefId: str=0001.0A090201.4C4DD86E.001B:SCFMA4539814,ss=1,fgs=0
References: <201007260417.o6Q4H0vG110018@nihil.Eng.Sun.COM>
 <20100726175311.GN2715@smelly.SFBay.Sun.COM> <4C4DD5D5.1030708@oracle.com>
User-Agent: Mozilla/5.0 (X11; U; SunOS i86pc; en-US; rv:1.9.1.10)
 Gecko/20100621 Lightning/1.0b1
 OracleBeehiveExtension/1.0.0.0pre11-OracleInternal Thunderbird/3.0.5
Status: RO
Content-Length: 784

On 07/26/10 11:37 AM, Antonello Cruz wrote:
> On 07/26/10 10:53 AM, Danek Duvall wrote:
>> Liane Praza wrote:
>>
>>> Only files with permissions 644, owned by root and group sys
>>> will be processed.
>>
>> I suppose I can understand the other restrictions, but why only mode 644,
>> and not, say, 444, which would be a very natural mode for a file
>> that's not
>> intended to be modified?
> It makes sense. I'll change the restriction to mode 444.
>
> Antonello

I think Danek was suggesting a larger set of acceptable permissions (or 
perhaps no restriction at all) rather than simply changing the 644 
requirement to 444.

	Scott

-- 
Scott Rotondo
Senior Principal Engineer, Solaris Core OS Engineering
President, Trusted Computing Group
Phone: +1 650 786 6309 (Internal x86309)

From scott.rotondo@oracle.com Mon Jul 26 11:59:41 2010
Received: from sunmail6brm.central.sun.com (sunmail6brm.Central.Sun.COM [129.147.4.169])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o6QIxfbX020328
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 26 Jul 2010 11:59:41 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail6brm.central.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id o6QIxemI017352
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Mon, 26 Jul 2010 13:59:40 -0500 (CDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0L6600I03I3GGF00@brm-avmta-1.central.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Mon, 26 Jul 2010 12:59:40 -0600 (MDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0L6600F2RI3GHY60@brm-avmta-1.central.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Mon,
 26 Jul 2010 12:59:40 -0600 (MDT)
Received: from rcsinet13.oracle.com (rcsinet13.oracle.com [148.87.113.125])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id o6QIxdaT008556; Mon,
 26 Jul 2010 18:59:39 +0000 (GMT)
Received: from acsmt355.oracle.com (acsmt355.oracle.com [141.146.40.155])
	by rcsinet13.oracle.com (Switch-3.4.2/Switch-3.4.1)
 with ESMTP id o6QIxbi7009364; Mon, 26 Jul 2010 18:59:38 +0000 (GMT)
Received: from abhmt002.oracle.com by acsmt354.oracle.com	with ESMTP id
 458755081280170757; Mon, 26 Jul 2010 11:59:17 -0700
Received: from [129.146.108.62] (/129.146.108.62)
	by default (Oracle Beehive Gateway v4.0)	with ESMTP ; Mon,
 26 Jul 2010 11:59:17 -0700
Date: Mon, 26 Jul 2010 11:59:19 -0700
From: Scott Rotondo <scott.rotondo@oracle.com>
Subject: Re: logadm.conf upgrade [PSARC/2010/290 FastTrack timeout 07/27/2010]
In-reply-to: <4C4DD85E.8050701@oracle.com>
To: Antonello Cruz <antonello.cruz@oracle.com>
Cc: Danek Duvall <danek.duvall@oracle.com>,
        Liane Praza <lianep@nihil.Eng.Sun.COM>, psarc-ext@sun.com,
        gavin.maltby@oracle.com
Message-id: <4C4DDB07.9010000@oracle.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Source-IP: acsmt355.oracle.com [141.146.40.155]
X-Auth-Type: Internal IP
X-CT-RefId: str=0001.0A090208.4C4DDB1A.0236:SCFMA4539814,ss=1,fgs=0
References: <201007260417.o6Q4H0vG110018@nihil.Eng.Sun.COM>
 <20100726175311.GN2715@smelly.SFBay.Sun.COM> <4C4DD5D5.1030708@oracle.com>
 <4C4DD85E.8050701@oracle.com>
User-Agent: Mozilla/5.0 (X11; U; SunOS i86pc; en-US; rv:1.9.1.10)
 Gecko/20100621 Lightning/1.0b1
 OracleBeehiveExtension/1.0.0.0pre11-OracleInternal Thunderbird/3.0.5
Status: RO
Content-Length: 531

On 07/26/10 11:47 AM, Scott Rotondo wrote:
> I think Danek was suggesting a larger set of acceptable permissions (or
> perhaps no restriction at all) rather than simply changing the 644
> requirement to 444.

On second thought, I think I misunderstood the context of this comment 
the first time around. It doesn't seem unreasonable to require these 
files to be mode 444.

	Scott

-- 
Scott Rotondo
Senior Principal Engineer, Solaris Core OS Engineering
President, Trusted Computing Group
Phone: +1 650 786 6309 (Internal x86309)

From antonello.cruz@oracle.com Mon Jul 26 12:11:31 2010
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o6QJBVBE020507
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 26 Jul 2010 12:11:31 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id o6QJBV5f000463
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Mon, 26 Jul 2010 12:11:31 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0L660040HIN7FB00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Mon, 26 Jul 2010 12:11:31 -0700 (PDT)
Received: from sca-ea-mail-2.sun.com ([192.18.43.25])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0L6600MGSIN74E60@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Mon,
 26 Jul 2010 12:11:31 -0700 (PDT)
Received: from rcsinet13.oracle.com (rcsinet13.oracle.com [148.87.113.125])
	by sca-ea-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id o6QJBP6q018389;
 Mon, 26 Jul 2010 19:11:25 +0000 (GMT)
Received: from acsmt354.oracle.com (acsmt354.oracle.com [141.146.40.154])
	by rcsinet13.oracle.com (Switch-3.4.2/Switch-3.4.1)
 with ESMTP id o6QJBMLY017353; Mon, 26 Jul 2010 19:11:23 +0000 (GMT)
Received: from abhmt009.oracle.com by acsmt355.oracle.com	with ESMTP id
 458791021280171416; Mon, 26 Jul 2010 12:10:16 -0700
Received: from [10.7.251.3] (/10.7.251.3)
	by default (Oracle Beehive Gateway v4.0)	with ESMTP ; Mon,
 26 Jul 2010 12:10:15 -0700
Date: Mon, 26 Jul 2010 12:10:10 -0700
From: Antonello Cruz <antonello.cruz@oracle.com>
Subject: Re: logadm.conf upgrade [PSARC/2010/290 FastTrack timeout 07/27/2010]
In-reply-to: <4C4DDB07.9010000@oracle.com>
To: Scott Rotondo <scott.rotondo@oracle.com>
Cc: Danek Duvall <danek.duvall@oracle.com>,
        Liane Praza <lianep@nihil.Eng.Sun.COM>, psarc-ext@sun.com,
        gavin.maltby@oracle.com, Antonello Cruz <antonello.cruz@oracle.com>
Message-id: <4C4DDD92.2040808@oracle.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Source-IP: acsmt354.oracle.com [141.146.40.154]
X-Auth-Type: Internal IP
X-CT-RefId: str=0001.0A090205.4C4DDDDC.0124:SCFMA4539814,ss=1,fgs=0
References: <201007260417.o6Q4H0vG110018@nihil.Eng.Sun.COM>
 <20100726175311.GN2715@smelly.SFBay.Sun.COM> <4C4DD5D5.1030708@oracle.com>
 <4C4DD85E.8050701@oracle.com> <4C4DDB07.9010000@oracle.com>
User-Agent: Mozilla/5.0 (X11; U; SunOS i86pc; en-US; rv:1.9.1.10)
 Gecko/20100621 Thunderbird/3.0.5
Status: RO
Content-Length: 851

On 07/26/10 11:59 AM, Scott Rotondo wrote:
> On 07/26/10 11:47 AM, Scott Rotondo wrote:
>> I think Danek was suggesting a larger set of acceptable permissions (or
>> perhaps no restriction at all) rather than simply changing the 644
>> requirement to 444.
>
> On second thought, I think I misunderstood the context of this comment
> the first time around. It doesn't seem unreasonable to require these
> files to be mode 444.
Well, your second email came just when I had finished my reply. Since it 
is not immediately clear why I am restricting access to the files in 
/etc/logadm.d I'll send my original reply here anyway.

logadm can run arbitrary scripts defined on the entries of logadm.conf 
If I just add a file that anyone can write to in /etc/logadm.d/ it would 
be a security vulnerability.

Thanks for the feedback,

Antonello
>
> Scott
>


From Andrew.Gabriel@oracle.com Mon Jul 26 12:34:38 2010
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o6QJYcHt020651
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 26 Jul 2010 12:34:38 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id o6QJYaeU021315;
	Mon, 26 Jul 2010 12:34:37 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0L660050BJPPKT00@nwk-avmta-2.sfbay.sun.com>; Mon,
 26 Jul 2010 12:34:37 -0700 (PDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0L6600MURJPN4E70@nwk-avmta-2.sfbay.sun.com>; Mon,
 26 Jul 2010 12:34:36 -0700 (PDT)
Received: from rcsinet13.oracle.com (rcsinet13.oracle.com [148.87.113.125])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id o6QJYYbZ028267; Mon,
 26 Jul 2010 19:34:35 +0000 (GMT)
Received: from acsmt355.oracle.com (acsmt355.oracle.com [141.146.40.155])
	by rcsinet13.oracle.com (Switch-3.4.2/Switch-3.4.1)
 with ESMTP id o6QJYR9e022916; Mon, 26 Jul 2010 19:34:28 +0000 (GMT)
Received: from abhmt014.oracle.com by acsmt353.oracle.com	with ESMTP id
 437902611280172860; Mon, 26 Jul 2010 12:34:20 -0700
Received: from [81.187.162.109] (/81.187.162.109)
	by default (Oracle Beehive Gateway v4.0)	with ESMTP ; Mon,
 26 Jul 2010 12:34:20 -0700
Date: Mon, 26 Jul 2010 20:35:19 +0100
From: Andrew Gabriel <Andrew.Gabriel@oracle.com>
Subject: Re: logadm.conf upgrade [PSARC/2010/290 FastTrack timeout 07/27/2010]
In-reply-to: <4C4DD59B.2010108@oracle.com>
To: Antonello Cruz <antonello.cruz@oracle.com>
Cc: John Levon <john.levon@sun.com>, Liane Praza <lianep@nihil.Eng.Sun.COM>,
        psarc-ext@sun.com, gavin.maltby@oracle.com
Message-id: <4C4DE377.6000802@oracle.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Source-IP: acsmt355.oracle.com [141.146.40.155]
X-Auth-Type: Internal IP
X-CT-RefId: str=0001.0A090207.4C4DE34A.00E5:SCFMA4539814,ss=1,fgs=0
References: <201007260417.o6Q4H0vG110018@nihil.Eng.Sun.COM>
 <20100726100245.GA3554@barman.uk.sun.com> <4C4DD59B.2010108@oracle.com>
User-Agent: Thunderbird 2.0.0.23 (X11/20090929)
Status: RO
Content-Length: 2060

Antonello Cruz wrote:
> On 07/26/10 03:02 AM, John Levon wrote:
>> On Sun, Jul 25, 2010 at 09:17:00PM -0700, Liane Praza wrote:
>>
>>>           To workaround this problem this project will create a new
>>>           directory in /etc/logadm.d and an SMF service
>>>           svc:/system/logadm-upgrade. A pkg wanting to add entries
>>>           in /etc/logadm.conf can drop a file with the entries in that
>>>           directory. The start method of the service will look for
>>>           logname for the entry, as defined in logadm.conf(4), in
>>>           /etc/logadm.conf. If the logname is not found, the entry from
>>>           the file will be appended to /etc/logadm.conf. The pkg 
>>> dropping
>>>      a file in /etc/logadm.d have to set the actuator
>>>      refresh_fmri='svc:/system/logadm-upgrade:default' in order to
>>>      have the contents of the file processed on install on a live
>>>      BE.
>>
>> How does an uninstall remove the logadm entry? Why can't this just
>> process /etc/logadm.d in place (like /etc/logrotate.d on Linux) ?
>
> That would be a very reasonable thing to consider when doing
> general improvements to logadm.conf (e.g its current re-writing
> behaviour which makes it hostile to read-only /etc deployments).
> But, it seems like managing the directory in a way that allows
> administrative customization like logadm.conf does today would take
> more significant interface investment in the Committed parts of
> logadm.conf than is an appropriate scope for this project.  This
> project replaces the S10 i.logadmconf functionality, which did not
> support removals either, and was also an ON-private Class Action Script.
> We've attempted to set the interface stability at a level which
> reflects that.

I'm struggling to understand why it would be difficult, for example, to 
treat the default configuration of logadm(1M) as simply the 
concatenation of all files in /etc/logadm.d, plus the existing 
/etc/logadm.conf for backwards compatibility. Seems like a real nice 
KISS solution.

-- 
Andrew Gabriel

From gary.winiger@oracle.com Mon Jul 26 15:29:28 2010
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o6QMTSqx024763
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 26 Jul 2010 15:29:28 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id o6QMTSFL006222
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Mon, 26 Jul 2010 15:29:28 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0L6600F01RT48V00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Mon, 26 Jul 2010 15:29:28 -0700 (PDT)
Received: from sca-ea-mail-3.sun.com ([192.18.43.21])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0L6600MIURT34GE0@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Mon,
 26 Jul 2010 15:29:27 -0700 (PDT)
Received: from acsinet15.oracle.com (acsinet15.oracle.com [141.146.126.227])
	by sca-ea-mail-3.sun.com (8.13.6+Sun/8.12.9) with ESMTP id o6QMTRUW006687;
 Mon, 26 Jul 2010 22:29:27 +0000 (GMT)
Received: from acsmt353.oracle.com (acsmt353.oracle.com [141.146.40.153])
	by acsinet15.oracle.com (Switch-3.4.2/Switch-3.4.1)
 with ESMTP id o6QLCDLi029343; Mon, 26 Jul 2010 22:29:25 +0000 (GMT)
Received: from abhmt014.oracle.com by acsmt355.oracle.com	with ESMTP id
 438335601280183310; Mon, 26 Jul 2010 15:28:30 -0700
Received: from gwws-macbook-pro.local (/10.7.251.252)
	by default (Oracle Beehive Gateway v4.0)	with ESMTP ; Mon,
 26 Jul 2010 15:28:29 -0700
Date: Mon, 26 Jul 2010 15:28:28 -0700
From: Gary Winiger <gary.winiger@oracle.com>
Subject: Re: logadm.conf upgrade [PSARC/2010/290 FastTrack timeout 07/27/2010]
In-reply-to: <4C4DDD92.2040808@oracle.com>
To: Antonello Cruz <antonello.cruz@oracle.com>
Cc: Scott Rotondo <scott.rotondo@oracle.com>,
        Danek Duvall <danek.duvall@oracle.com>,
        Liane Praza <lianep@nihil.Eng.Sun.COM>, psarc-ext@sun.com,
        gavin.maltby@oracle.com
Message-id: <4C4E0C0C.5010502@oracle.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Source-IP: acsmt353.oracle.com [141.146.40.153]
X-Auth-Type: Internal IP
X-CT-RefId: str=0001.0A0B0209.4C4E0C46.01D9:SCFMA4539814,ss=1,fgs=0
References: <201007260417.o6Q4H0vG110018@nihil.Eng.Sun.COM>
 <20100726175311.GN2715@smelly.SFBay.Sun.COM> <4C4DD5D5.1030708@oracle.com>
 <4C4DD85E.8050701@oracle.com> <4C4DDB07.9010000@oracle.com>
 <4C4DDD92.2040808@oracle.com>
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US; rv:1.9.1.11)
 Gecko/20100711 Thunderbird/3.0.6
Status: RO
Content-Length: 756

On 7/26/10 12:10 PM, Antonello Cruz wrote:

> Well, your second email came just when I had finished my reply. Since it
> is not immediately clear why I am restricting access to the files in
> /etc/logadm.d I'll send my original reply here anyway.
>
> logadm can run arbitrary scripts defined on the entries of logadm.conf
> If I just add a file that anyone can write to in /etc/logadm.d/ it would
> be a security vulnerability.

	Isn't the point that /etc/logadm.d must not be writable without
	privilege.  That is logadm.d must be 644 root:sys or any other
	group.  Aren't the currently existent foo.d directories 644
	root:sys.  The one's I'm familiar with are.  And similarly the
	files in them for consumption are no greater than 644 root:sys.

Gary..

From gavin.maltby@oracle.com Mon Jul 26 16:05:03 2010
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o6QN53Yh025696
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 26 Jul 2010 16:05:03 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.4) with ESMTP id o6QN51lJ019230;
	Mon, 26 Jul 2010 17:05:02 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0L6600H03TGDA200@nwk-avmta-2.sfbay.sun.com>; Mon,
 26 Jul 2010 16:05:01 -0700 (PDT)
Received: from brmea-mail-1.sun.com ([192.18.98.31])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0L6600GL7TGDRK20@nwk-avmta-2.sfbay.sun.com>; Mon,
 26 Jul 2010 16:05:01 -0700 (PDT)
Received: from acsinet15.oracle.com (acsinet15.oracle.com [141.146.126.227])
	by brmea-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id o6QN50SP000538; Mon,
 26 Jul 2010 23:05:00 +0000 (GMT)
Received: from acsmt353.oracle.com (acsmt353.oracle.com [141.146.40.153])
	by acsinet15.oracle.com (Switch-3.4.2/Switch-3.4.1)
 with ESMTP id o6QKSccP000360; Mon, 26 Jul 2010 23:04:53 +0000 (GMT)
Received: from abhmt020.oracle.com by acsmt354.oracle.com	with ESMTP id
 459383861280185492; Mon, 26 Jul 2010 16:04:52 -0700
Received: from [10.7.250.122] (/10.7.250.122)
	by default (Oracle Beehive Gateway v4.0)	with ESMTP ; Mon,
 26 Jul 2010 16:04:52 -0700
Date: Tue, 27 Jul 2010 09:04:37 +1000
From: Gavin Maltby <gavin.maltby@oracle.com>
Subject: Re: logadm.conf upgrade [PSARC/2010/290 FastTrack timeout 07/27/2010]
In-reply-to: <4C4DE377.6000802@oracle.com>
To: Andrew Gabriel <Andrew.Gabriel@oracle.com>
Cc: Antonello Cruz <antonello.cruz@oracle.com>,
        John Levon <john.levon@sun.com>,
        Liane Praza <lianep@nihil.Eng.Sun.COM>, psarc-ext@sun.com
Message-id: <4C4E1485.8000504@oracle.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Source-IP: acsmt353.oracle.com [141.146.40.153]
X-Auth-Type: Internal IP
X-CT-RefId: str=0001.0A090206.4C4E1497.034E:SCFMA4539814,ss=1,fgs=0
References: <201007260417.o6Q4H0vG110018@nihil.Eng.Sun.COM>
 <20100726100245.GA3554@barman.uk.sun.com> <4C4DD59B.2010108@oracle.com>
 <4C4DE377.6000802@oracle.com>
User-Agent: Mozilla/5.0 (X11; U; SunOS i86pc; en-US; rv:1.9.1.10)
 Gecko/20100621 Lightning/1.0b1 Thunderbird/3.0.5
Status: RO
Content-Length: 712

On 07/27/10 05:35, Andrew Gabriel wrote:

> I'm struggling to understand why it would be difficult, for example, to
> treat the default configuration of logadm(1M) as simply the
> concatenation of all files in /etc/logadm.d, plus the existing
> /etc/logadm.conf for backwards compatibility. Seems like a real nice
> KISS solution.

I can see the attraction of that, and that should be considered as
one possible approach or part of the solution in a project that
aims to address the current weaknesses of logadm.  For now
we simply need a means for the dependent project to deliver new
log file rotation entries, and embarking on any rewhacking of
logadm as a prerequisite is incompatible with schedules.

Gavin

From Nicolas.Williams@oracle.com Mon Jul 26 16:21:36 2010
Received: from sunmail6brm.central.sun.com (sunmail6brm.Central.Sun.COM [129.147.4.169])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o6QNLam4025869
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 26 Jul 2010 16:21:36 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail6brm.central.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id o6QNLYBx023570;
	Mon, 26 Jul 2010 18:21:34 -0500 (CDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0L6600I03U7Y7F00@nwk-avmta-2.sfbay.sun.com>; Mon,
 26 Jul 2010 16:21:34 -0700 (PDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0L6600G2FU7YRK70@nwk-avmta-2.sfbay.sun.com>; Mon,
 26 Jul 2010 16:21:34 -0700 (PDT)
Received: from rcsinet15.oracle.com (rcsinet15.oracle.com [148.87.113.117])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id o6QNLXMW019777; Mon,
 26 Jul 2010 23:21:33 +0000 (GMT)
Received: from acsmt353.oracle.com (acsmt353.oracle.com [141.146.40.153])
	by rcsinet15.oracle.com (Switch-3.4.2/Switch-3.4.1)
 with ESMTP id o6QIHaLX014278; Mon, 26 Jul 2010 23:21:32 +0000 (GMT)
Received: from abhmt002.oracle.com by acsmt355.oracle.com	with ESMTP id
 438455211280186447; Mon, 26 Jul 2010 16:20:47 -0700
Received: from oracle.com (/129.153.128.104)
	by default (Oracle Beehive Gateway v4.0)	with ESMTP ; Mon,
 26 Jul 2010 16:20:47 -0700
Date: Mon, 26 Jul 2010 18:20:35 -0500
From: Nicolas Williams <Nicolas.Williams@oracle.com>
Subject: Re: logadm.conf upgrade [PSARC/2010/290 FastTrack timeout 07/27/2010]
In-reply-to: <20100726100245.GA3554@barman.uk.sun.com>
To: John Levon <john.levon@sun.com>
Cc: Liane Praza <lianep@nihil.Eng.Sun.COM>, psarc-ext@sun.com,
        antonello.cruz@oracle.com, gavin.maltby@oracle.com
Message-id: <20100726232035.GE27130@oracle.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
X-Source-IP: acsmt353.oracle.com [141.146.40.153]
X-Auth-Type: Internal IP
X-CT-RefId: str=0001.0A090209.4C4E187C.0289:SCFMA4539814,ss=1,fgs=0
References: <201007260417.o6Q4H0vG110018@nihil.Eng.Sun.COM>
 <20100726100245.GA3554@barman.uk.sun.com>
User-Agent: Mutt/1.5.20 (2010-03-02)
Status: RO
Content-Length: 1548

On Mon, Jul 26, 2010 at 11:02:45AM +0100, John Levon wrote:
> On Sun, Jul 25, 2010 at 09:17:00PM -0700, Liane Praza wrote:
> 
> >          To workaround this problem this project will create a new
> >          directory in /etc/logadm.d and an SMF service
> >          svc:/system/logadm-upgrade. A pkg wanting to add entries
> >          in /etc/logadm.conf can drop a file with the entries in that
> >          directory. The start method of the service will look for
> >          logname for the entry, as defined in logadm.conf(4), in
> >          /etc/logadm.conf. If the logname is not found, the entry from
> >          the file will be appended to /etc/logadm.conf. The pkg dropping
> > 	 a file in /etc/logadm.d have to set the actuator
> > 	 refresh_fmri='svc:/system/logadm-upgrade:default' in order to
> > 	 have the contents of the file processed on install on a live
> > 	 BE.
> 
> How does an uninstall remove the logadm entry? Why can't this just
> process /etc/logadm.d in place (like /etc/logrotate.d on Linux) ?

I've a prototype start method for a service that essentially generalizes
what this project does.  Packages would deliver SVR4-style post* and CAS
scripts into .d-like directories.  The start method of this service
scans for new such items delivered by new pkgs and saves backup
copies... so it can also detect pkg removals, and then it runs the
scripts for additions and removals as expected.

Time to generalize this?  I mean, how many *upgrade* services will we
have littering the SMF service namespace?

Nico
-- 

From Nicolas.Williams@oracle.com Mon Jul 26 16:32:26 2010
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o6QNWQE2026286
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 26 Jul 2010 16:32:26 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id o6QNWM3R004286;
	Mon, 26 Jul 2010 16:32:25 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0L6600I03UPYTU00@nwk-avmta-2.sfbay.sun.com>; Mon,
 26 Jul 2010 16:32:22 -0700 (PDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0L6600GU7UPXRK90@nwk-avmta-2.sfbay.sun.com>; Mon,
 26 Jul 2010 16:32:21 -0700 (PDT)
Received: from acsinet15.oracle.com (acsinet15.oracle.com [141.146.126.227])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id o6QNWK01023844; Mon,
 26 Jul 2010 23:32:20 +0000 (GMT)
Received: from acsmt354.oracle.com (acsmt354.oracle.com [141.146.40.154])
	by acsinet15.oracle.com (Switch-3.4.2/Switch-3.4.1)
 with ESMTP id o6QNWJ3i023029; Mon, 26 Jul 2010 23:32:19 +0000 (GMT)
Received: from abhmt005.oracle.com by acsmt354.oracle.com	with ESMTP id
 459439581280187131; Mon, 26 Jul 2010 16:32:11 -0700
Received: from oracle.com (/129.153.128.104)
	by default (Oracle Beehive Gateway v4.0)	with ESMTP ; Mon,
 26 Jul 2010 16:32:11 -0700
Date: Mon, 26 Jul 2010 18:31:59 -0500
From: Nicolas Williams <Nicolas.Williams@oracle.com>
Subject: Re: logadm.conf upgrade [PSARC/2010/290 FastTrack timeout 07/27/2010]
In-reply-to: <20100726232035.GE27130@oracle.com>
To: John Levon <john.levon@sun.com>
Cc: Liane Praza <lianep@nihil.Eng.Sun.COM>, psarc-ext@sun.com,
        antonello.cruz@oracle.com, gavin.maltby@oracle.com
Message-id: <20100726233159.GF27130@oracle.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
X-Source-IP: acsmt354.oracle.com [141.146.40.154]
X-Auth-Type: Internal IP
X-CT-RefId: str=0001.0A090206.4C4E1B03.022E:SCFMA4539814,ss=1,fgs=0
References: <201007260417.o6Q4H0vG110018@nihil.Eng.Sun.COM>
 <20100726100245.GA3554@barman.uk.sun.com> <20100726232035.GE27130@oracle.com>
User-Agent: Mutt/1.5.20 (2010-03-02)
Status: RO
Content-Length: 684

On Mon, Jul 26, 2010 at 06:20:35PM -0500, Nicolas Williams wrote:
> I've a prototype start method for a service that essentially generalizes
> what this project does.  Packages would deliver SVR4-style post* and CAS
> scripts into .d-like directories.  The start method of this service
> scans for new such items delivered by new pkgs and saves backup
> copies... so it can also detect pkg removals, and then it runs the
> scripts for additions and removals as expected.
> 
> Time to generalize this?  I mean, how many *upgrade* services will we
> have littering the SMF service namespace?

Actually, never mind.  On third thought I think I'd rather litter the
SMF service namespace.

From liane.praza@oracle.com Wed Jul 28 07:05:11 2010
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o6SE5BCh022503
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 28 Jul 2010 07:05:11 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id o6SE5BCM018697
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Wed, 28 Jul 2010 07:05:11 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0L6900205TSNSQ00@brm-avmta-1.central.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Wed, 28 Jul 2010 08:05:11 -0600 (MDT)
Received: from sca-ea-mail-4.sun.com ([192.18.43.22])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0L6900JD1TSMTX40@brm-avmta-1.central.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Wed,
 28 Jul 2010 08:05:10 -0600 (MDT)
Received: from acsinet15.oracle.com (acsinet15.oracle.com [141.146.126.227])
	by sca-ea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id o6SE59tO016296;
 Wed, 28 Jul 2010 14:05:10 +0000 (GMT)
Received: from acsmt354.oracle.com (acsmt354.oracle.com [141.146.40.154])
	by acsinet15.oracle.com (Switch-3.4.2/Switch-3.4.1)
 with ESMTP id o6SAPxHl015522; Wed, 28 Jul 2010 14:05:07 +0000 (GMT)
Received: from abhmt009.oracle.com by acsmt353.oracle.com	with ESMTP id
 444570121280325905; Wed, 28 Jul 2010 07:05:05 -0700
Received: from [10.7.251.216] (/10.7.251.216)
	by default (Oracle Beehive Gateway v4.0)	with ESMTP ; Wed,
 28 Jul 2010 07:05:04 -0700
Date: Wed, 28 Jul 2010 07:05:02 -0700
From: Liane Praza <liane.praza@oracle.com>
Subject: Re: logadm.conf upgrade [PSARC/2010/290 FastTrack timeout 07/27/2010]
In-reply-to: <201007260417.o6Q4H0vG110018@nihil.Eng.Sun.COM>
To: Liane Praza <lianep@nihil.Eng.Sun.COM>
Cc: psarc-ext@sun.com, antonello.cruz@oracle.com, gavin.maltby@oracle.com
Message-id: <4C50390E.8090401@oracle.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Source-IP: acsmt354.oracle.com [141.146.40.154]
X-Auth-Type: Internal IP
X-CT-RefId: str=0001.0A090208.4C503915.0120:SCFMA4539814,ss=1,fgs=0
References: <201007260417.o6Q4H0vG110018@nihil.Eng.Sun.COM>
User-Agent: Mozilla/5.0 (X11; U; SunOS i86pc; en-US; rv:1.9.1.8) Gecko/20100412
 Lightning/1.0b1 Thunderbird/3.0.3
Status: RO
Content-Length: 220

Based on my current read of the case log, all outstanding questions on 
this case have been answered, it was given its +1 conditional on those 
answers, and it timed out yesterday.  Thus, I'm marking it approved.

liane

