Hi Michael, thanks for your answer.
On Fri, Aug 09, 2019 at 04:16:06PM +0200, Michael Biebl wrote: > I have never seen this behaviour myself on the multitude of systems I > run (laptop, servers, VM, containers) so I don't really have any idea. How closely are you watching the ACLs on the journal files? > What are the permissions /ACLs on > > /run/log/journal/8f018d505adf4ecaad2720811a888b04/ [4/1633]mh@oversway:~ $ ls -lad /run/log/journal/8f018d505adf4ecaad2720811a888b04 drwxr-s---+ 2 root systemd-journal 200 Aug 10 08:09 /run/log/journal/8f018d505adf4ecaad2720811a888b04/ [5/1634]mh@oversway:~ $ sudo getfacl /run/log/journal/8f018d505adf4ecaad2720811a888b04 getfacl: Removing leading '/' from absolute path names # file: run/log/journal/8f018d505adf4ecaad2720811a888b04 # owner: root # group: systemd-journal # flags: -s- user::rwx group::r-x group:adm:r-x mask::r-x other::--- default:user::rwx default:group::r-x default:group:adm:r-x default:mask::r-x default:other::--- [6/1635]mh@oversway:~ $ > Do you have any tmpfiles which references files in /run/log ? How would I find that out? > Can you exclude that non-systemd components change the permissions? Of course not, but no components that I have installed willingly. I'll roll out a monitoring job that runs more often than once daily so that the change gets timed more exactly. Unless I report back, don't bother with more research, it might be a real stupid thing. Greetings Marc -- ----------------------------------------------------------------------------- Marc Haber | "I don't trust Computers. They | Mailadresse im Header Leimen, Germany | lose things." Winona Ryder | Fon: *49 6224 1600402 Nordisch by Nature | How to make an American Quilt | Fax: *49 6224 1600421 _______________________________________________ Pkg-systemd-maintainers mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-systemd-maintainers
