Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #235872 > unrolled thread
| Started by | songbird <songbird@anthive.com> |
|---|---|
| First post | 2021-06-04 14:00 +0200 |
| Last post | 2021-06-04 15:20 +0200 |
| Articles | 6 — 4 participants |
Back to article view | Back to linux.debian.user
what program sets up /run/user/1000/ ? songbird <songbird@anthive.com> - 2021-06-04 14:00 +0200
Re: what program sets up /run/user/1000/ ? Greg Wooledge <greg@wooledge.org> - 2021-06-04 14:10 +0200
Re: what program sets up /run/user/1000/ ? Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-06-04 14:40 +0200
Re: what program sets up /run/user/1000/ ? "Thomas Schmitt" <scdbackup@gmx.net> - 2021-06-04 14:50 +0200
Re: what program sets up /run/user/1000/ ? "Thomas Schmitt" <scdbackup@gmx.net> - 2021-06-04 14:40 +0200
Re: what program sets up /run/user/1000/ ? songbird <songbird@anthive.com> - 2021-06-04 15:20 +0200
| From | songbird <songbird@anthive.com> |
|---|---|
| Date | 2021-06-04 14:00 +0200 |
| Subject | what program sets up /run/user/1000/ ? |
| Message-ID | <CmgEx-6aP-3@gated-at.bofh.it> |
some strange fs entry shows up:
# ls -l /run/user/1000
ls: cannot access '/run/user/1000/doc': Permission denied
total 4
srw-rw-rw- 1 frog frog 0 Jun 4 07:06 bus
drwx------ 3 frog frog 60 Jun 4 07:06 dbus-1
drwx------ 2 frog frog 60 Jun 4 07:06 dconf
d????????? ? ? ? ? ? doc
drwx------ 2 frog frog 140 Jun 4 07:06 gnupg
drwx------ 2 frog frog 40 Jun 4 07:06 gvfs
-rw------- 1 frog frog 306 Jun 4 07:06 ICEauthority
drwx------ 2 frog frog 100 Jun 4 07:06 keyring
srw-rw-rw- 1 frog frog 0 Jun 4 07:06 pipewire-0
-rw-r----- 1 frog frog 0 Jun 4 07:06 pipewire-0.lock
drwx------ 2 frog frog 80 Jun 4 07:06 pulse
drwxr-xr-x 5 frog frog 140 Jun 4 07:06 systemd
# checkrestart
lsof: WARNING: can't stat() fuse.portal file system /run/user/1000/doc
Output information may be incomplete.
Found 3 processes using old versions of upgraded files
(1 distinct program)
(1 distinct packages)
These processes (1) do not seem to have an associated init script to restart them:
...
thanks! :)
songbird
[toc] | [next] | [standalone]
| From | Greg Wooledge <greg@wooledge.org> |
|---|---|
| Date | 2021-06-04 14:10 +0200 |
| Message-ID | <CmgOd-6tb-1@gated-at.bofh.it> |
| In reply to | #235872 |
On Fri, Jun 04, 2021 at 07:38:46AM -0400, songbird wrote: > # ls -l /run/user/1000 > ls: cannot access '/run/user/1000/doc': Permission denied > total 4 > srw-rw-rw- 1 frog frog 0 Jun 4 07:06 bus > drwx------ 3 frog frog 60 Jun 4 07:06 dbus-1 > drwx------ 2 frog frog 60 Jun 4 07:06 dconf > d????????? ? ? ? ? ? doc Didn't we *just* have this exact same discussion? At least you showed the shell prompt and the command that you ran, which is a huge improvement over the previous iteration, where we were left guessing at *so* many things. Thank you for that. In your case, because you were competent enough to show the shell prompt along with your command, we know that you ran this ls as *root*, not as user 1000. That's why you can't see it. Only user 1000 can see it. Here's (the start of) the previous discussion thread: <https://lists.debian.org/debian-user/2021/06/msg00020.html>
[toc] | [prev] | [next] | [standalone]
| From | Polyna-Maude Racicot-Summerside <debian@polynamaude.com> |
|---|---|
| Date | 2021-06-04 14:40 +0200 |
| Message-ID | <Cmhhg-6Cc-1@gated-at.bofh.it> |
| In reply to | #235872 |
[Multipart message — attachments visible in raw view] — view raw
Hi, On 2021-06-04 8:35 a.m., Thomas Schmitt wrote: > Hi, > > songbird wrote: >> some strange fs entry shows up: >> # ls -l /run/user/1000 >> d????????? ? ? ? ? ? doc > > We had this topic a few day ago. > https://lists.debian.org/debian-user/2021/06/msg00020.html > > I had some further private conversation with the OP John Conover which > causes me to summarize the problem like this: > > xdg-document-portal from package xdg-desktop-portal creates a FUSE mount > point as "portal" for offering selected files to the user with the giveni > id number (here: 1000). > https://flatpak.github.io/xdg-desktop-portal/portal-docs.html#gdbus-org.freedesktop.portal.Documents > states > "The document portal allows to make files from the outside world > available to sandboxed applications in a controlled way. > Exported files will be made accessible to the application via a fuse > filesystem that gets mounted at /run/user/$UID/doc/." > > Control is obviously to be done via systemd means. Probably by > /usr/lib/systemd/user/xdg-document-portal.service > as mentioned in > https://packages.debian.org/buster/amd64/xdg-desktop-portal/filelist > > It is the normal behavior of a FUSE mount point to deny any access to any > other user including the superuser. See > https://github.com/libfuse/libfuse > "Security implications" > which says > "No other user (including root) can access the contents of the mounted > filesystem (though this can be relaxed by allowing the use of the > allow_other and allow_root mount options in /etc/fuse.conf)" > > Reason is probably that the kernel hands over its internal VFS calls to > the FUSE driver program in userspace, which is then able to answer > with arbitrary deception to the caller of the corresponding libc function. > An old superuser might not expect to be served by code that did not go > through kernel development scrutiny. > > Relaxing this security precaution (as mentioned in above quote) might be > a bad idea. > I would rather disable xdg-document-portal in order to redice the risk > rather than increasing it. > > > Have a nice day :) > > Thomas > Thanks for this nice message. That's a great proof that some people with knowledge (and smart) do run GNOME. -- Polyna-Maude R.-Summerside -Be smart, Be wise, Support opensource development
[toc] | [prev] | [next] | [standalone]
| From | "Thomas Schmitt" <scdbackup@gmx.net> |
|---|---|
| Date | 2021-06-04 14:50 +0200 |
| Message-ID | <CmhqV-6Fg-1@gated-at.bofh.it> |
| In reply to | #235874 |
Hi, Polyna-Maude Racicot-Summerside wrote: > That's a great proof that some people with knowledge (and smart) do run > GNOME. Actually i run fvwm2 and don't even know how to get an xterm from the GNOME ridden Ubuntu VM which i have to start once in a year. The presented knowledge stems from a scary ride through the googleverse and over the package mountains of Debian. Have a nice day :) Thomas
[toc] | [prev] | [next] | [standalone]
| From | "Thomas Schmitt" <scdbackup@gmx.net> |
|---|---|
| Date | 2021-06-04 14:40 +0200 |
| Message-ID | <Cmhhg-6Cc-3@gated-at.bofh.it> |
| In reply to | #235872 |
Hi, songbird wrote: > some strange fs entry shows up: > # ls -l /run/user/1000 > d????????? ? ? ? ? ? doc We had this topic a few day ago. https://lists.debian.org/debian-user/2021/06/msg00020.html I had some further private conversation with the OP John Conover which causes me to summarize the problem like this: xdg-document-portal from package xdg-desktop-portal creates a FUSE mount point as "portal" for offering selected files to the user with the giveni id number (here: 1000). https://flatpak.github.io/xdg-desktop-portal/portal-docs.html#gdbus-org.freedesktop.portal.Documents states "The document portal allows to make files from the outside world available to sandboxed applications in a controlled way. Exported files will be made accessible to the application via a fuse filesystem that gets mounted at /run/user/$UID/doc/." Control is obviously to be done via systemd means. Probably by /usr/lib/systemd/user/xdg-document-portal.service as mentioned in https://packages.debian.org/buster/amd64/xdg-desktop-portal/filelist It is the normal behavior of a FUSE mount point to deny any access to any other user including the superuser. See https://github.com/libfuse/libfuse "Security implications" which says "No other user (including root) can access the contents of the mounted filesystem (though this can be relaxed by allowing the use of the allow_other and allow_root mount options in /etc/fuse.conf)" Reason is probably that the kernel hands over its internal VFS calls to the FUSE driver program in userspace, which is then able to answer with arbitrary deception to the caller of the corresponding libc function. An old superuser might not expect to be served by code that did not go through kernel development scrutiny. Relaxing this security precaution (as mentioned in above quote) might be a bad idea. I would rather disable xdg-document-portal in order to redice the risk rather than increasing it. Have a nice day :) Thomas
[toc] | [prev] | [next] | [standalone]
| From | songbird <songbird@anthive.com> |
|---|---|
| Date | 2021-06-04 15:20 +0200 |
| Message-ID | <CmhTX-73G-1@gated-at.bofh.it> |
| In reply to | #235877 |
Thomas Schmitt wrote: ... > Have a nice day :) thanks! sorry all, did not see the topic already went by. songbird
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web