Amanda-Users

Re: New setup: problem with permissions

2004-12-28 23:47:57
Subject: Re: New setup: problem with permissions
From: "Dwight Tovey" <dwight AT dtovey DOT net>
To: amanda-users AT amanda DOT org
Date: Tue, 28 Dec 2004 21:32:20 -0700 (MST)
Jon LaBadie said:
> On Tue, Dec 28, 2004 at 05:15:30PM -0700, Dwight Tovey wrote:
>> I'm looking at using Amanda for my backup solution, and I've run into a
>> bit of a problem that I'm hoping to get some help with.
>>
> ...
>>
>> If I try to use the device instead of the mountpoint, amcheck (and
>> eventually amdump) fails with "Can't open disk 'hda6'" for each
>> 'include'.
>>  Looking at the source I found that every time it encounters an
>> 'include',
>> Amanda trys to do an 'opendir()' to verify the included name.  Since the
>> device is not a directory, the opendir() fails resulting in the
>> displayed
>> error.
>>
>> So, is there any way around this short of running Amanda as 'root'?  Is
>> there really any problem with running as root?
>
> If the amanda installation was done as root, then all the necessary
> set-user-id-root permissions should have been done at that time.
> Amanda tries to run with the minimum necessary permissions, but
> at times, the minimum is root.  Thus several amanda programs are
> setuid'ed during installation.  These include the "runtar" program
> that invokes gnutar.
>

OK.  I've verified that the "runtar" program is setuid root, so ultimatly
the 'tar' program will be run as root and it should have access to the
protected directories.  So why am I seeing the failure?

In checking the log from the last run, I found:
FAIL dumper medea home_all 20041228 0 [ [access as bkoper not allowed from
bkoper AT medea.dtovey DOT net] amandahostsauth failed]

The 'medea.dtovey.net' name resolves to the external interface, but I only
had an entry in .amandahosts for the internal interface.  I've now
modified .amandahosts so that there are entries for both interfaces, so
maybe it will work tonight.  However it leaves me wondering why this one
disklist entry tried to come in on the external interface while everything
else was using the internal.

Thanks for the response.
    /dwight
-- 
Dwight N. Tovey
email: dwight AT dtovey DOT net
web: http://www.dtovey.net/~dwight
-----------
What do you call a male ladybug?


<Prev in Thread] Current Thread [Next in Thread>