Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 168912 - net-analyzer/munin-1.3.3 /etc/munin/munin-node.conf config file inconsistency
Summary: net-analyzer/munin-1.3.3 /etc/munin/munin-node.conf config file inconsistency
Status: RESOLVED UPSTREAM
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Robin Johnson
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2007-03-01 17:24 UTC by pille
Modified: 2007-03-02 05:14 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description pille 2007-03-01 17:24:54 UTC
the config-file /etc/munin/munin-node.conf that's installed from upstream
has one line 'host *' and the following commented out part again (at end of file):

# uncomment this to only listen on the loopback/localhost interface
#
# host 127.0.0.1

if you just uncomment this last line in order to bind to loopback-interface,
it's ignored when starting the daemon, because of the first line.

a user may overlook this and end up in a more insecure configuration than intended.

Reproducible: Always

Steps to Reproduce:
1. emerge munin
2. comment out the 'host 127.0.0.1'-line (last one) in /etc/munin/munin-node.conf and forget about the 'host *'
3. /etc/init.d/munin-node start

Actual Results:  
munin-node binds on all interfaces

Expected Results:  
munin-node binds to loopback interface

in my opinion it's not a real bug,
but what the comment says is not correct or sufficient.
perhaps it's better to move that last part up to the first 'host *'
Comment 1 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2007-03-02 05:14:44 UTC
that file is provided by upstream. please take the matter to them.