Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #235872 > unrolled thread

what program sets up /run/user/1000/ ?

Started bysongbird <songbird@anthive.com>
First post2021-06-04 14:00 +0200
Last post2021-06-04 15:20 +0200
Articles 6 — 4 participants

Back to article view | Back to linux.debian.user


Contents

  what program sets up /run/user/1000/ ? songbird <songbird@anthive.com> - 2021-06-04 14:00 +0200
    Re: what program sets up /run/user/1000/ ? Greg Wooledge <greg@wooledge.org> - 2021-06-04 14:10 +0200
    Re: what program sets up /run/user/1000/ ? Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-06-04 14:40 +0200
      Re: what program sets up /run/user/1000/ ? "Thomas Schmitt" <scdbackup@gmx.net> - 2021-06-04 14:50 +0200
    Re: what program sets up /run/user/1000/ ? "Thomas Schmitt" <scdbackup@gmx.net> - 2021-06-04 14:40 +0200
      Re: what program sets up /run/user/1000/ ? songbird <songbird@anthive.com> - 2021-06-04 15:20 +0200

#235872 — what program sets up /run/user/1000/ ?

Fromsongbird <songbird@anthive.com>
Date2021-06-04 14:00 +0200
Subjectwhat program sets up /run/user/1000/ ?
Message-ID<CmgEx-6aP-3@gated-at.bofh.it>
  some strange fs entry shows up:

# ls -l /run/user/1000
ls: cannot access '/run/user/1000/doc': Permission denied
total 4
srw-rw-rw- 1 frog frog   0 Jun  4 07:06 bus
drwx------ 3 frog frog  60 Jun  4 07:06 dbus-1
drwx------ 2 frog frog  60 Jun  4 07:06 dconf
d????????? ? ?  ?    ?            ? doc
drwx------ 2 frog frog 140 Jun  4 07:06 gnupg
drwx------ 2 frog frog  40 Jun  4 07:06 gvfs
-rw------- 1 frog frog 306 Jun  4 07:06 ICEauthority
drwx------ 2 frog frog 100 Jun  4 07:06 keyring
srw-rw-rw- 1 frog frog   0 Jun  4 07:06 pipewire-0
-rw-r----- 1 frog frog   0 Jun  4 07:06 pipewire-0.lock
drwx------ 2 frog frog  80 Jun  4 07:06 pulse
drwxr-xr-x 5 frog frog 140 Jun  4 07:06 systemd


# checkrestart
lsof: WARNING: can't stat() fuse.portal file system /run/user/1000/doc
      Output information may be incomplete.
Found 3 processes using old versions of upgraded files
(1 distinct program)
(1 distinct packages)
These processes (1) do not seem to have an associated init script to restart them:
...

  thanks!  :)


  songbird

[toc] | [next] | [standalone]


#235873

FromGreg Wooledge <greg@wooledge.org>
Date2021-06-04 14:10 +0200
Message-ID<CmgOd-6tb-1@gated-at.bofh.it>
In reply to#235872
On Fri, Jun 04, 2021 at 07:38:46AM -0400, songbird wrote:
> # ls -l /run/user/1000
> ls: cannot access '/run/user/1000/doc': Permission denied
> total 4
> srw-rw-rw- 1 frog frog   0 Jun  4 07:06 bus
> drwx------ 3 frog frog  60 Jun  4 07:06 dbus-1
> drwx------ 2 frog frog  60 Jun  4 07:06 dconf
> d????????? ? ?  ?    ?            ? doc

Didn't we *just* have this exact same discussion?

At least you showed the shell prompt and the command that you ran,
which is a huge improvement over the previous iteration, where we
were left guessing at *so* many things.  Thank you for that.

In your case, because you were competent enough to show the shell prompt
along with your command, we know that you ran this ls as *root*, not
as user 1000.  That's why you can't see it.  Only user 1000 can see it.

Here's (the start of) the previous discussion thread:
<https://lists.debian.org/debian-user/2021/06/msg00020.html>

[toc] | [prev] | [next] | [standalone]


#235874

FromPolyna-Maude Racicot-Summerside <debian@polynamaude.com>
Date2021-06-04 14:40 +0200
Message-ID<Cmhhg-6Cc-1@gated-at.bofh.it>
In reply to#235872

[Multipart message — attachments visible in raw view] — view raw

Hi,

On 2021-06-04 8:35 a.m., Thomas Schmitt wrote:
> Hi,
> 
> songbird wrote:
>>  some strange fs entry shows up:
>> # ls -l /run/user/1000
>> d????????? ? ?  ?    ?            ? doc
> 
> We had this topic a few day ago.
>   https://lists.debian.org/debian-user/2021/06/msg00020.html
> 
> I had some further private conversation with the OP John Conover which
> causes me to summarize the problem like this:
> 
> xdg-document-portal from package xdg-desktop-portal creates a FUSE mount
> point as "portal" for offering selected files to the user with the giveni
> id number (here: 1000).
>   https://flatpak.github.io/xdg-desktop-portal/portal-docs.html#gdbus-org.freedesktop.portal.Documents
> states
>  "The document portal allows to make files from the outside world
>   available to sandboxed applications in a controlled way.
>   Exported files will be made accessible to the application via a fuse
>   filesystem that gets mounted at /run/user/$UID/doc/."
> 
> Control is obviously to be done via systemd means. Probably by
>   /usr/lib/systemd/user/xdg-document-portal.service
> as mentioned in
>   https://packages.debian.org/buster/amd64/xdg-desktop-portal/filelist
> 
> It is the normal behavior of a FUSE mount point to deny any access to any
> other user including the superuser. See
>   https://github.com/libfuse/libfuse
>   "Security implications"
> which says
>   "No other user (including root) can access the contents of the mounted
>    filesystem (though this can be relaxed by allowing the use of the
>    allow_other and allow_root mount options in /etc/fuse.conf)"
> 
> Reason is probably that the kernel hands over its internal VFS calls to
> the FUSE driver program in userspace, which is then able to answer
> with arbitrary deception to the caller of the corresponding libc function.
> An old superuser might not expect to be served by code that did not go
> through kernel development scrutiny.
> 
> Relaxing this security precaution (as mentioned in above quote) might be
> a bad idea.
> I would rather disable xdg-document-portal in order to redice the risk
> rather than increasing it.
> 
> 
> Have a nice day :)
> 
> Thomas
> 
Thanks for this nice message.
That's a great proof that some people with knowledge (and smart) do run
GNOME.

-- 
Polyna-Maude R.-Summerside
-Be smart, Be wise, Support opensource development

[toc] | [prev] | [next] | [standalone]


#235878

From"Thomas Schmitt" <scdbackup@gmx.net>
Date2021-06-04 14:50 +0200
Message-ID<CmhqV-6Fg-1@gated-at.bofh.it>
In reply to#235874
Hi,

Polyna-Maude Racicot-Summerside wrote:
> That's a great proof that some people with knowledge (and smart) do run
> GNOME.

Actually i run fvwm2 and don't even know how to get an xterm from the
GNOME ridden Ubuntu VM which i have to start once in a year.

The presented knowledge stems from a scary ride through the googleverse
and over the package mountains of Debian.


Have a nice day :)

Thomas

[toc] | [prev] | [next] | [standalone]


#235877

From"Thomas Schmitt" <scdbackup@gmx.net>
Date2021-06-04 14:40 +0200
Message-ID<Cmhhg-6Cc-3@gated-at.bofh.it>
In reply to#235872
Hi,

songbird wrote:
>  some strange fs entry shows up:
> # ls -l /run/user/1000
> d????????? ? ?  ?    ?            ? doc

We had this topic a few day ago.
  https://lists.debian.org/debian-user/2021/06/msg00020.html

I had some further private conversation with the OP John Conover which
causes me to summarize the problem like this:

xdg-document-portal from package xdg-desktop-portal creates a FUSE mount
point as "portal" for offering selected files to the user with the giveni
id number (here: 1000).
  https://flatpak.github.io/xdg-desktop-portal/portal-docs.html#gdbus-org.freedesktop.portal.Documents
states
 "The document portal allows to make files from the outside world
  available to sandboxed applications in a controlled way.
  Exported files will be made accessible to the application via a fuse
  filesystem that gets mounted at /run/user/$UID/doc/."

Control is obviously to be done via systemd means. Probably by
  /usr/lib/systemd/user/xdg-document-portal.service
as mentioned in
  https://packages.debian.org/buster/amd64/xdg-desktop-portal/filelist

It is the normal behavior of a FUSE mount point to deny any access to any
other user including the superuser. See
  https://github.com/libfuse/libfuse
  "Security implications"
which says
  "No other user (including root) can access the contents of the mounted
   filesystem (though this can be relaxed by allowing the use of the
   allow_other and allow_root mount options in /etc/fuse.conf)"

Reason is probably that the kernel hands over its internal VFS calls to
the FUSE driver program in userspace, which is then able to answer
with arbitrary deception to the caller of the corresponding libc function.
An old superuser might not expect to be served by code that did not go
through kernel development scrutiny.

Relaxing this security precaution (as mentioned in above quote) might be
a bad idea.
I would rather disable xdg-document-portal in order to redice the risk
rather than increasing it.


Have a nice day :)

Thomas

[toc] | [prev] | [next] | [standalone]


#235881

Fromsongbird <songbird@anthive.com>
Date2021-06-04 15:20 +0200
Message-ID<CmhTX-73G-1@gated-at.bofh.it>
In reply to#235877
Thomas Schmitt wrote:
...
> Have a nice day :)

  thanks!  sorry all, did not see the topic already went by.


  songbird

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web