[SGVLUG] Qmail oddity (?) [at least, hard to find the answer online...]

Emerson, Tom (*IC) Tom.Emerson at wbconsultant.com
Mon Nov 2 15:44:24 PST 2009


I got an odd question thrown at me today - seems messages were simply "not being delivered" to some users we recently set up for the SCGS library (using qmail)  Nothing special about these "users", in fact, they were basically set up via the "adduser" command with no further embellishment.  I checked the /var/log/qmail/current logfile and found this message:

    Uh-oh:_home_directory_is_writable.

So, being the well versed admin that I am, I put that into the search box and got:

========================
Re: delivery 2: deferral: Uh-oh:_home_directory_is_writable._(#4.7.0)

Greg White
Wed, 07 Mar 2001 21:21:37 -0800

On Wed, Mar 07, 2001 at 09:24:10PM -0800, Hatem wrote:
> Is there anyone familiar with the above error?

Search any search engine or qmail archive with the exact text of your
subject line. This is a FAQ.
>
> !!
> your help is appreciated!
>
> thanks.

HTH,
=========================

"with all due respect"... NIFD - several people asked the question, rarely was it answered (and in the few cases it was answered, it was a cryptic/snide response as above)

It actually is NOT in the (qmail) FAQ (or, at least, not in the "life with qmail" documentation)

I was only able to find a tangential reference to this in a book excerpt, and even then, it dismisses discussion with "on the theory that..."  (no examples or proof, just a theory...)

Some of the questioners even went so far as to point out that the home directory of the user(s) in question were, in fact, NOT "world writable" [or even group writable] (mode 755, in most cases), thus they were even more perplexed.

It seems to me to be an odd requirement, especially given that some "plain vanilla installations" of Linux would have a useradd/adduser commandset that would create "insecure" users.  [this is a gentoo system, as I recall]

So, can any "qmail" experts out there give me a better explanation than "mere theory" as to why this is a requirement?


More information about the SGVLUG mailing list