From mboxrd@z Thu Jan 1 00:00:00 1970 From: Alex Griffin Subject: bug#27135: /root is world readable by default Date: Mon, 29 May 2017 14:04:34 -0500 Message-ID: <1496084674.772351.992061712.59A7C89F@webmail.messagingengine.com> Mime-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:35857) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1dFPyT-0003RE-AI for bug-guix@gnu.org; Mon, 29 May 2017 15:05:05 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1dFPyQ-0001l5-6n for bug-guix@gnu.org; Mon, 29 May 2017 15:05:05 -0400 Received: from debbugs.gnu.org ([208.118.235.43]:41071) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1dFPyQ-0001l1-30 for bug-guix@gnu.org; Mon, 29 May 2017 15:05:02 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1dFPyP-00036v-Se for bug-guix@gnu.org; Mon, 29 May 2017 15:05:01 -0400 Sender: "Debbugs-submit" Resent-Message-ID: Received: from eggs.gnu.org ([2001:4830:134:3::10]:35774) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1dFPy4-0003OJ-2b for bug-guix@gnu.org; Mon, 29 May 2017 15:04:40 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1dFPy1-0001fy-0u for bug-guix@gnu.org; Mon, 29 May 2017 15:04:40 -0400 Received: from out1-smtp.messagingengine.com ([66.111.4.25]:52269) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1dFPy0-0001fV-GY for bug-guix@gnu.org; Mon, 29 May 2017 15:04:36 -0400 Received: from compute6.internal (compute6.nyi.internal [10.202.2.46]) by mailout.nyi.internal (Postfix) with ESMTP id 5383D209CC for ; Mon, 29 May 2017 15:04:34 -0400 (EDT) List-Id: Bug reports for GNU Guix List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-guix-bounces+gcggb-bug-guix=m.gmane.org@gnu.org Sender: "bug-Guix" To: 27135@debbugs.gnu.org After a default install of GuixSD, anybody can read root's home directory. I think /root should have permissions 700 instead of 755.