Skip to main content

Module logging

Module logging 

Source
Expand description

§Log directory setup

Log files can contain session ids and request metadata, so the directory must be private to the current user. On Unix it is created with mode 0o700, and an existing directory is accepted only if it is not a symlink and we can restrict it to 0o700 (which fails unless we own it). This defeats a pre-created or symlinked directory planted by another local user.

Functions§

prepare_log_dir
Creates dir if needed and makes sure only the current user can access it.