Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #244606 > unrolled thread

Security

Started byPolyna-Maude Racicot-Summerside <debian@polynamaude.com>
First post2022-01-25 21:10 +0100
Last post2022-01-28 17:30 +0100
Articles 20 on this page of 23 — 10 participants

Back to article view | Back to linux.debian.user


Contents

  Security Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2022-01-25 21:10 +0100
    Re: Security Andy Smith <andy@strugglers.net> - 2022-01-25 21:50 +0100
      Re: Security Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2022-01-25 22:00 +0100
        Re: Security Nicholas Geovanis <nickgeovanis@gmail.com> - 2022-01-26 16:40 +0100
    Re: Security Nate Bargmann <n0nb@n0nb.us> - 2022-01-25 23:20 +0100
      Re: Security Andrei POPESCU <andreimpopescu@gmail.com> - 2022-01-26 19:40 +0100
        Re: Security Nicholas Geovanis <nickgeovanis@gmail.com> - 2022-01-28 04:50 +0100
          Re: Security Dan Ritter <dsr@randomstring.org> - 2022-01-28 14:20 +0100
            Re: Security Nicholas Geovanis <nickgeovanis@gmail.com> - 2022-01-28 17:20 +0100
              Re: Security Dan Ritter <dsr@randomstring.org> - 2022-01-28 19:00 +0100
          Re: Security Vincent Lefevre <vincent@vinc17.net> - 2022-01-28 16:20 +0100
            Re: Security Nicholas Geovanis <nickgeovanis@gmail.com> - 2022-01-28 17:30 +0100
            Re: Security Richard Hector <richard@walnut.gen.nz> - 2022-01-30 13:40 +0100
              Re: Security Reco <recoverym4n@enotuniq.net> - 2022-01-30 14:20 +0100
                Re: Security Andrei POPESCU <andreimpopescu@gmail.com> - 2022-01-30 14:40 +0100
                  Re: Security Reco <recoverym4n@enotuniq.net> - 2022-01-30 17:50 +0100
                    Re: Security Andrei POPESCU <andreimpopescu@gmail.com> - 2022-02-04 09:50 +0100
                      Re: Security Reco <recoverym4n@enotuniq.net> - 2022-02-04 10:20 +0100
                      Re: Security <tomas@tuxteam.de> - 2022-02-04 10:20 +0100
              Re: Security Vincent Lefevre <vincent@vinc17.net> - 2022-02-01 12:30 +0100
                Re: Security Richard Hector <richard@walnut.gen.nz> - 2022-02-02 02:00 +0100
                  Re: Security Vincent Lefevre <vincent@vinc17.net> - 2022-02-02 15:10 +0100
          Re: Security Andrei POPESCU <andreimpopescu@gmail.com> - 2022-01-28 17:30 +0100

Page 1 of 2  [1] 2  Next page →


#244606 — Security

FromPolyna-Maude Racicot-Summerside <debian@polynamaude.com>
Date2022-01-25 21:10 +0100
SubjectSecurity
Message-ID<DJAiB-7jg-3@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

Hi Guys / Girls,
I'm also on the security advisory mailing list.

Kind of strange that some people complains we lag behind when I get
information everyday that fixes are available for packages in the stable
/ old stable release.

And I go against the suggestion by mirroring security-updates repository.

And again, everyday, every two days at most, I get new packages fixing
some bugs.

So people who say that there's no update or that they lag shall install
a Debian machine and tell me how often they receive new updates.

This is not a opinion, this is a fact with logs to show.
-- 
Polyna-Maude R.-Summerside
-Be smart, Be wise, Support opensource development

[toc] | [next] | [standalone]


#244607

FromAndy Smith <andy@strugglers.net>
Date2022-01-25 21:50 +0100
Message-ID<DJAVl-7zN-21@gated-at.bofh.it>
In reply to#244606
Hello,

On Tue, Jan 25, 2022 at 03:05:51PM -0500, Polyna-Maude Racicot-Summerside wrote:
> Kind of strange that some people complains we lag behind when I get
> information everyday that fixes are available for packages in the stable
> / old stable release.

I think you are getting worked up over the actions of a troll.

You will never get them to change their mind no matter how much
factual evidence you come up with, because they aren't posting in
good faith. If they were then they would have either accepted the
answers they got five times over the first time they brought it up
here, or else not accepted them and given up. Instead they went on
to write a "press release" and threaten more to come regarding
"excommunicated" developers. Their goal is to cause drama, not find
a solution for any real world problem.

I recommend just moving on with your life and accepting that this
person is going to keep posting the same claims over and over
without feeling the need to refute them every time.

Cheers,
Andy

-- 
https://bitfolk.com/ -- No-nonsense VPS hosting

[toc] | [prev] | [next] | [standalone]


#244608

FromPolyna-Maude Racicot-Summerside <debian@polynamaude.com>
Date2022-01-25 22:00 +0100
Message-ID<DJB4Z-7EA-1@gated-at.bofh.it>
In reply to#244607

[Multipart message — attachments visible in raw view] — view raw

On 2022-01-25 15:47, Andy Smith wrote:
> Hello,
> 
> On Tue, Jan 25, 2022 at 03:05:51PM -0500, Polyna-Maude Racicot-Summerside wrote:
>> Kind of strange that some people complains we lag behind when I get
>> information everyday that fixes are available for packages in the stable
>> / old stable release.
> 
> I think you are getting worked up over the actions of a troll.
> 
> You will never get them to change their mind no matter how much
> factual evidence you come up with, because they aren't posting in
> good faith. If they were then they would have either accepted the
> answers they got five times over the first time they brought it up
> here, or else not accepted them and given up. Instead they went on
> to write a "press release" and threaten more to come regarding
> "excommunicated" developers. Their goal is to cause drama, not find
> a solution for any real world problem.
> 
> I recommend just moving on with your life and accepting that this
> person is going to keep posting the same claims over and over
> without feeling the need to refute them every time.
> 
This message was more regarding some new users or ones who could have
doubt on the safety / security of the Debian ecosystem.

Sadly some of these people may cause some harm.

> Cheers,
> Andy
> 

-- 
Polyna-Maude R.-Summerside
-Be smart, Be wise, Support opensource development

[toc] | [prev] | [next] | [standalone]


#244624

FromNicholas Geovanis <nickgeovanis@gmail.com>
Date2022-01-26 16:40 +0100
Message-ID<DJSyR-36Q-3@gated-at.bofh.it>
In reply to#244608

[Multipart message — attachments visible in raw view] — view raw

The proper way IMO is to subscribe to the CERT for your nation. Be the
interface to it for your organization within your local responsibilities.
You will then receive the high-risk advisories before they are publically
released. That paid off, for example, during the ghost/meltdown Intel
vulnerabilities.

On Tue, Jan 25, 2022, 2:52 PM Polyna-Maude Racicot-Summerside <
debian@polynamaude.com> wrote:

>
>
> On 2022-01-25 15:47, Andy Smith wrote:
> > Hello,
> >
> > On Tue, Jan 25, 2022 at 03:05:51PM -0500, Polyna-Maude
> Racicot-Summerside wrote:
> >> Kind of strange that some people complains we lag behind when I get
> >> information everyday that fixes are available for packages in the stable
> >> / old stable release.
> >
> > I think you are getting worked up over the actions of a troll.
> >
> > You will never get them to change their mind no matter how much
> > factual evidence you come up with, because they aren't posting in
> > good faith. If they were then they would have either accepted the
> > answers they got five times over the first time they brought it up
> > here, or else not accepted them and given up. Instead they went on
> > to write a "press release" and threaten more to come regarding
> > "excommunicated" developers. Their goal is to cause drama, not find
> > a solution for any real world problem.
> >
> > I recommend just moving on with your life and accepting that this
> > person is going to keep posting the same claims over and over
> > without feeling the need to refute them every time.
> >
> This message was more regarding some new users or ones who could have
> doubt on the safety / security of the Debian ecosystem.
>
> Sadly some of these people may cause some harm.
>
> > Cheers,
> > Andy
> >
>
> --
> Polyna-Maude R.-Summerside
> -Be smart, Be wise, Support opensource development
>

[toc] | [prev] | [next] | [standalone]


#244610

FromNate Bargmann <n0nb@n0nb.us>
Date2022-01-25 23:20 +0100
Message-ID<DJCkq-hG-9@gated-at.bofh.it>
In reply to#244606

[Multipart message — attachments visible in raw view] — view raw

I am subscribed to that list and get them too.

I just see that three more messages popped in since this morning from
the security list.

The complaints seem to be only about browsers.  The inference seems to
be that the latest release always fixes security bugs.  While this is
true to an extent, what is seldom acknowledged is that new releases also
bring new and as yet undisclosed bugs that will be fixed next time or
the time after or the time after that or...  I figure it's a gamble
either way and stick with the Debian packages.

- Nate

-- 
"The optimist proclaims that we live in the best of all
possible worlds.  The pessimist fears this is true."
Web: https://www.n0nb.us
Projects: https://github.com/N0NB
GPG fingerprint: 82D6 4F6B 0E67 CD41 F689 BBA6 FB2C 5130 D55A 8819

[toc] | [prev] | [next] | [standalone]


#244636

FromAndrei POPESCU <andreimpopescu@gmail.com>
Date2022-01-26 19:40 +0100
Message-ID<DJVn4-4Zi-3@gated-at.bofh.it>
In reply to#244610

[Multipart message — attachments visible in raw view] — view raw

On Ma, 25 ian 22, 16:13:23, Nate Bargmann wrote:
> I am subscribed to that list and get them too.
> 
> I just see that three more messages popped in since this morning from
> the security list.
> 
> The complaints seem to be only about browsers.  The inference seems to
> be that the latest release always fixes security bugs.  While this is
> true to an extent, what is seldom acknowledged is that new releases also
> bring new and as yet undisclosed bugs that will be fixed next time or
> the time after or the time after that or...  I figure it's a gamble
> either way and stick with the Debian packages.

I'll use the opportunity to draw attention to DSA-5059-1, see e.g. this 
article for details:

https://arstechnica.com/information-technology/2022/01/a-bug-lurking-for-12-years-gives-attackers-root-on-every-major-linux-distro/

And please don't bother to reply with "there are no other users on this 
system I should worry about", the bad guys could still find ways to get 
in, e.g. via a compromised browser, regardless if you are behind a 
firewall or not[1].

Any system connecting to the internet should be kept up-to-date.

Even if you don't care about your data, privacy, etc., your system will 
probably become part of some botnet and be used to spread malware and 
spam to others.


[1] Of course, the risk level is significantly lower for the typical 
home user, but still not negligible in my opinion - we just can't know 
what unknown browser vulnerabilities there might be lurking, which the 
bad guys could actively exploit via malicious websites (vs. targeted 
attacks for high value targets).

In today's world once your browser is compromised https://xkcd.com/1200/ 
applies.


Kind regards,
Andrei
-- 
http://wiki.debian.org/FAQsFromDebianUser

[toc] | [prev] | [next] | [standalone]


#244705

FromNicholas Geovanis <nickgeovanis@gmail.com>
Date2022-01-28 04:50 +0100
Message-ID<DKqqR-84C-1@gated-at.bofh.it>
In reply to#244636

[Multipart message — attachments visible in raw view] — view raw

On Wed, Jan 26, 2022, 12:39 PM Andrei POPESCU <andreimpopescu@gmail.com>
wrote:

> On Ma, 25 ian 22, 16:13:23, Nate Bargmann wrote:
> > I am subscribed to that list and get them too.
> >
> > I just see that three more messages popped in since this morning from
> > the security list.
> >
> > The complaints seem to be only about browsers.  The inference seems to
> > be that the latest release always fixes security bugs.  While this is
> > true to an extent, what is seldom acknowledged is that new releases also
> > bring new and as yet undisclosed bugs that will be fixed next time or
> > the time after or the time after that or...  I figure it's a gamble
> > either way and stick with the Debian packages.
>
> I'll use the opportunity to draw attention to DSA-5059-1, see e.g. this
> article for details:
>
>
> https://arstechnica.com/information-technology/2022/01/a-bug-lurking-for-12-years-gives-attackers-root-on-every-major-linux-distro/
>
> And please don't bother to reply with "there are no other users on this
> system I should worry about", the bad guys could still find ways to get
> in, e.g. via a compromised browser, regardless if you are behind a
> firewall or not[1].
>

Servers don't have browsers installed on them, for exactly this reason.

I think your argument above that is a red herring. Because file attribute
modification detection should be running regularly. On home machines as
well as servers. Without that, "keeping the system up-to-date" will not
prevent intrusion.

IOW you closed the barn door before the cow escaped. Good. But she went out
the other door that was still open.

Any system connecting to the internet should be kept up-to-date.
>
> Even if you don't care about your data, privacy, etc., your system will
> probably become part of some botnet and be used to spread malware and
> spam to others.
>
>
> [1] Of course, the risk level is significantly lower for the typical
> home user, but still not negligible in my opinion - we just can't know
> what unknown browser vulnerabilities there might be lurking, which the
> bad guys could actively exploit via malicious websites (vs. targeted
> attacks for high value targets).
>
> In today's world once your browser is compromised https://xkcd.com/1200/
> applies.
>
>
> Kind regards,
> Andrei
> --
> http://wiki.debian.org/FAQsFromDebianUser
>

[toc] | [prev] | [next] | [standalone]


#244713

FromDan Ritter <dsr@randomstring.org>
Date2022-01-28 14:20 +0100
Message-ID<DKzku-5wz-7@gated-at.bofh.it>
In reply to#244705
Nicholas Geovanis wrote: 
> On Wed, Jan 26, 2022, 12:39 PM Andrei POPESCU <andreimpopescu@gmail.com>
> wrote:
> 
> > On Ma, 25 ian 22, 16:13:23, Nate Bargmann wrote:
> > And please don't bother to reply with "there are no other users on this
> > system I should worry about", the bad guys could still find ways to get
> > in, e.g. via a compromised browser, regardless if you are behind a
> > firewall or not[1].
> >
> 
> Servers don't have browsers installed on them, for exactly this reason.

Note that browsers can sneak in where you aren't expecting them;
"headless chromium" is a part of many automated QA systems and
HTML to PDF generators.

-dsr-

[toc] | [prev] | [next] | [standalone]


#244728

FromNicholas Geovanis <nickgeovanis@gmail.com>
Date2022-01-28 17:20 +0100
Message-ID<DKC8G-7cQ-3@gated-at.bofh.it>
In reply to#244713

[Multipart message — attachments visible in raw view] — view raw

On Fri, Jan 28, 2022, 6:57 AM Dan Ritter <dsr@randomstring.org> wrote:

> Nicholas Geovanis wrote:
> > On Wed, Jan 26, 2022, 12:39 PM Andrei POPESCU <andreimpopescu@gmail.com>
> > wrote:
> >
> > > On Ma, 25 ian 22, 16:13:23, Nate Bargmann wrote:
> > > And please don't bother to reply with "there are no other users on this
> > > system I should worry about", the bad guys could still find ways to get
> > > in, e.g. via a compromised browser, regardless if you are behind a
> > > firewall or not[1].
> > >
> >
> > Servers don't have browsers installed on them, for exactly this reason.
>
> Note that browsers can sneak in where you aren't expecting them;
> "headless chromium" is a part of many automated QA systems and
> HTML to PDF generators.
>

Absolutely, and also unnecessary on servers. Especially in presence of
cloud where we can make a clean custom spin easily.

-dsr-
>

[toc] | [prev] | [next] | [standalone]


#244743

FromDan Ritter <dsr@randomstring.org>
Date2022-01-28 19:00 +0100
Message-ID<DKDHs-7Zb-5@gated-at.bofh.it>
In reply to#244728
Nicholas Geovanis wrote: 
> On Fri, Jan 28, 2022, 6:57 AM Dan Ritter <dsr@randomstring.org> wrote:
> 
> > Nicholas Geovanis wrote:
> > > On Wed, Jan 26, 2022, 12:39 PM Andrei POPESCU <andreimpopescu@gmail.com>
> > > wrote:
> > >
> > > > On Ma, 25 ian 22, 16:13:23, Nate Bargmann wrote:
> > > > And please don't bother to reply with "there are no other users on this
> > > > system I should worry about", the bad guys could still find ways to get
> > > > in, e.g. via a compromised browser, regardless if you are behind a
> > > > firewall or not[1].
> > > >
> > >
> > > Servers don't have browsers installed on them, for exactly this reason.
> >
> > Note that browsers can sneak in where you aren't expecting them;
> > "headless chromium" is a part of many automated QA systems and
> > HTML to PDF generators.
> >
> 
> Absolutely, and also unnecessary on servers. Especially in presence of
> cloud where we can make a clean custom spin easily.

It turns out that not all software has the same requirements
and affordances that you consider universal.

-dsr-

[toc] | [prev] | [next] | [standalone]


#244722

FromVincent Lefevre <vincent@vinc17.net>
Date2022-01-28 16:20 +0100
Message-ID<DKBcC-6Eh-15@gated-at.bofh.it>
In reply to#244705
On 2022-01-27 21:44:07 -0600, Nicholas Geovanis wrote:
> On Wed, Jan 26, 2022, 12:39 PM Andrei POPESCU <andreimpopescu@gmail.com>
> wrote:
> 
> > I'll use the opportunity to draw attention to DSA-5059-1, see e.g. this
> > article for details:
> >
> >
> > https://arstechnica.com/information-technology/2022/01/a-bug-lurking-for-12-years-gives-attackers-root-on-every-major-linux-distro/
> >
> > And please don't bother to reply with "there are no other users on this
> > system I should worry about", the bad guys could still find ways to get
> > in, e.g. via a compromised browser, regardless if you are behind a
> > firewall or not[1].

Running the browser in firejail should be sufficient as the profile
should disable pkexec, e.g.

$ firejail --profile=firefox ls   
Reading profile /etc/firejail/firefox.profile
[...]
Error: execute permission denied for /usr/bin/pkexec
Error: no suitable pkexec executable found

> Servers don't have browsers installed on them, for exactly this reason.

Servers shouldn't have pkexec installed in the first place, anyway.

-- 
Vincent Lefèvre <vincent@vinc17.net> - Web: <https://www.vinc17.net/>
100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/>
Work: CR INRIA - computer arithmetic / AriC project (LIP, ENS-Lyon)

[toc] | [prev] | [next] | [standalone]


#244731

FromNicholas Geovanis <nickgeovanis@gmail.com>
Date2022-01-28 17:30 +0100
Message-ID<DKCil-7fX-11@gated-at.bofh.it>
In reply to#244722

[Multipart message — attachments visible in raw view] — view raw

On Fri, Jan 28, 2022, 9:17 AM Vincent Lefevre <vincent@vinc17.net> wrote:

> On 2022-01-27 21:44:07 -0600, Nicholas Geovanis wrote:
> > On Wed, Jan 26, 2022, 12:39 PM Andrei POPESCU <andreimpopescu@gmail.com>
> > wrote:
> >
> > > I'll use the opportunity to draw attention to DSA-5059-1, see e.g. this
> > > article for details:
> > >
> > >
> > >
> https://arstechnica.com/information-technology/2022/01/a-bug-lurking-for-12-years-gives-attackers-root-on-every-major-linux-distro/
> > >
> > > And please don't bother to reply with "there are no other users on this
> > > system I should worry about", the bad guys could still find ways to get
> > > in, e.g. via a compromised browser, regardless if you are behind a
> > > firewall or not[1].
>
> Running the browser in firejail should be sufficient as the profile
> should disable pkexec, e.g.
>

Vincent's point is the right one I think. We need to deploy security "in
depth". Every single setuid executable should be SHIPPED protected, just
pick your style of protection.

SElinux should be shipped enabled like Redhat does. Think it's too hard to
administer? Then ship it with multiple models implemented in multiple rule
sets like Redhat does. Then you can choose your style of mandatory access
control with a mouse click at installation.

$ firejail --profile=firefox ls
> Reading profile /etc/firejail/firefox.profile
> [...]
> Error: execute permission denied for /usr/bin/pkexec
> Error: no suitable pkexec executable found
>
> > Servers don't have browsers installed on them, for exactly this reason.
>
> Servers shouldn't have pkexec installed in the first place, anyway.
>
> --
> Vincent Lefèvre <vincent@vinc17.net> - Web: <https://www.vinc17.net/>
> 100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/>
> Work: CR INRIA - computer arithmetic / AriC project (LIP, ENS-Lyon)
>
>

[toc] | [prev] | [next] | [standalone]


#244815

FromRichard Hector <richard@walnut.gen.nz>
Date2022-01-30 13:40 +0100
Message-ID<DLhER-6Uh-5@gated-at.bofh.it>
In reply to#244722
On 29/01/22 04:17, Vincent Lefevre wrote:

> Servers shouldn't have pkexec installed in the first place, anyway.
> 

libvirt-daemon-system depends on policykit-1.

Should that not be on my (kvm) server either?

Cheers,
Richard

[toc] | [prev] | [next] | [standalone]


#244816

FromReco <recoverym4n@enotuniq.net>
Date2022-01-30 14:20 +0100
Message-ID<DLihz-7my-1@gated-at.bofh.it>
In reply to#244815
	Hi.

On Mon, Jan 31, 2022 at 01:36:06AM +1300, Richard Hector wrote:
> On 29/01/22 04:17, Vincent Lefevre wrote:
> 
> > Servers shouldn't have pkexec installed in the first place, anyway.
> > 
> 
> libvirt-daemon-system depends on policykit-1.
> 
> Should that not be on my (kvm) server either?

Many years ago exactly this was disputed in #768376.
Long story short - the only reason libvirt-daemon-system depends on
policykit-1 is because GNOME users could be confused if it does not.

Reco

[toc] | [prev] | [next] | [standalone]


#244817

FromAndrei POPESCU <andreimpopescu@gmail.com>
Date2022-01-30 14:40 +0100
Message-ID<DLiAV-7tr-1@gated-at.bofh.it>
In reply to#244816

[Multipart message — attachments visible in raw view] — view raw

On Du, 30 ian 22, 15:54:17, Reco wrote:
> 	Hi.
> 
> On Mon, Jan 31, 2022 at 01:36:06AM +1300, Richard Hector wrote:
> > On 29/01/22 04:17, Vincent Lefevre wrote:
> > 
> > > Servers shouldn't have pkexec installed in the first place, anyway.
> > > 
> > 
> > libvirt-daemon-system depends on policykit-1.
> > 
> > Should that not be on my (kvm) server either?
> 
> Many years ago exactly this was disputed in #768376.
> Long story short - the only reason libvirt-daemon-system depends on
> policykit-1 is because GNOME users could be confused if it does not.

As far as I can tell the Maintainer's stance (in 2014) was:

    Having polkit installed and doing nothing (for people switching to
    socke based permission checks) is IMHO a better service to our users
    than having all the bugs for people installing without recommends (and
    there are many of those)
 

How does "people installing without recommends" translate to "GNOME 
users" is beyond me, considering that GNOME users would have policykit-1 
installed anyway (as a dependency of GNOME) and they are much less 
likely to disable installation of Recommends in the first place.

As written in message #80 circumstances have changed, maybe the 
Maintainer will reconsider.

Kind regards,
Andrei
-- 
http://wiki.debian.org/FAQsFromDebianUser

[toc] | [prev] | [next] | [standalone]


#244818

FromReco <recoverym4n@enotuniq.net>
Date2022-01-30 17:50 +0100
Message-ID<DLlyN-K9-1@gated-at.bofh.it>
In reply to#244817
	Hi.

On Sun, Jan 30, 2022 at 02:39:14PM +0100, Andrei POPESCU wrote:
> On Du, 30 ian 22, 15:54:17, Reco wrote:
> > On Mon, Jan 31, 2022 at 01:36:06AM +1300, Richard Hector wrote:
> > > On 29/01/22 04:17, Vincent Lefevre wrote:
> > > 
> > > > Servers shouldn't have pkexec installed in the first place, anyway.
> > > > 
> > > 
> > > libvirt-daemon-system depends on policykit-1.
> > > 
> > > Should that not be on my (kvm) server either?
> > 
> > Many years ago exactly this was disputed in #768376.
> > Long story short - the only reason libvirt-daemon-system depends on
> > policykit-1 is because GNOME users could be confused if it does not.
> 
> As far as I can tell the Maintainer's stance (in 2014) was:
> 
>     Having polkit installed and doing nothing (for people switching to
>     socke based permission checks) is IMHO a better service to our users
>     than having all the bugs for people installing without recommends (and
>     there are many of those)
>  
> 
> How does "people installing without recommends" translate to "GNOME 
> users" is beyond me,

Easy. Look closely at two graphical frontends to libvirt they provide in
main archive.
Now ask yourself - would I need these on a server? Who would need to use
these?


> considering that GNOME users would have policykit-1 
> installed anyway (as a dependency of GNOME) and they are much less 
> likely to disable installation of Recommends in the first place.

Back in '14 that was not universal axiom. Things have changed since then
somewhat though.


> As written in message #80 circumstances have changed, maybe the 
> Maintainer will reconsider.

Possibly, although unlikely. I mean, it was a wishlist priority bug,
after all.

My point in all this - PolicyKit was redundant on a typical server back
then, and by large it still is. Even if your server has libvirt,
although in this case some assembly is required.

Reco

[toc] | [prev] | [next] | [standalone]


#245001

FromAndrei POPESCU <andreimpopescu@gmail.com>
Date2022-02-04 09:50 +0100
Message-ID<DN2s1-5E8-1@gated-at.bofh.it>
In reply to#244818

[Multipart message — attachments visible in raw view] — view raw

On Du, 30 ian 22, 19:27:56, Reco wrote:
> 
> > 
> > How does "people installing without recommends" translate to "GNOME 
> > users" is beyond me,
> 
> Easy. Look closely at two graphical frontends to libvirt they provide in
> main archive.
> Now ask yourself - would I need these on a server? Who would need to use
> these?
 
Those who want a graphical tool to manage their VMs? Installing some 
-gnome packages still doesn't make me a GNOME user ;)

(e.g. I'm using network-manager-gnome with LXDE)
 
Kind regards,
Andrei
-- 
http://wiki.debian.org/FAQsFromDebianUser

[toc] | [prev] | [next] | [standalone]


#245002

FromReco <recoverym4n@enotuniq.net>
Date2022-02-04 10:20 +0100
Message-ID<DN2V3-634-3@gated-at.bofh.it>
In reply to#245001
	Hi.

On Fri, Feb 04, 2022 at 09:43:18AM +0100, Andrei POPESCU wrote:
> On Du, 30 ian 22, 19:27:56, Reco wrote:
> > 
> > > 
> > > How does "people installing without recommends" translate to "GNOME 
> > > users" is beyond me,
> > 
> > Easy. Look closely at two graphical frontends to libvirt they provide in
> > main archive.
> > Now ask yourself - would I need these on a server? Who would need to use
> > these?
>  
> Those who want a graphical tool to manage their VMs?

I.e. those who have a dozen VM at most, a single "server" to host them,
and said "server" is most probably translates to a localhost. I don't
see all that as a bad thing, but each GUI has its share of limitations
once it comes to managing something in big quantities, and both GNOME
boxes and Virt Manager follow that principle.


> Installing some -gnome packages still doesn't make me a GNOME user ;)

But installing them gives you a pile of GNOME core packages by
dependency.
Thus the software in question behaves the way GNOME developers want it
to behave, and the dependent software does it too. #768376 is a fine
example of that.
Thus I have bad news for you - installing either GNOME boxes or Virt
Manager (or other GNOME stuff) made you GNOME user, but if you insist
you're not - I won't press it ;)

For the record, for me both "GNOME" and "GNOME user" does not have a
negative connotation. About the only flaw of GNOME project for me is
their abuse of Scrum software development methodology, and that's a
topic for another discussion.

Reco

[toc] | [prev] | [next] | [standalone]


#245003

From<tomas@tuxteam.de>
Date2022-02-04 10:20 +0100
Message-ID<DN2V4-634-11@gated-at.bofh.it>
In reply to#245001

[Multipart message — attachments visible in raw view] — view raw

On Fri, Feb 04, 2022 at 09:43:18AM +0100, Andrei POPESCU wrote:

[...]

> Those who want a graphical tool to manage their VMs? Installing some 
> -gnome packages still doesn't make me a GNOME user ;)
> 
> (e.g. I'm using network-manager-gnome with LXDE)

It creeps slowly on you ;-P

(Just kidding. Everyone be happy with the tools (s)he prefers: provided
they're free, of course :-)

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#244904

FromVincent Lefevre <vincent@vinc17.net>
Date2022-02-01 12:30 +0100
Message-ID<DLZwe-4X-9@gated-at.bofh.it>
In reply to#244815
On 2022-01-31 01:36:06 +1300, Richard Hector wrote:
> On 29/01/22 04:17, Vincent Lefevre wrote:
> > Servers shouldn't have pkexec installed in the first place, anyway.
> 
> libvirt-daemon-system depends on policykit-1.
> 
> Should that not be on my (kvm) server either?

I don't need libvirt-daemon-system on my server. And I don't see
why it would be needed in general. If I understand correctly,
libvirt is used to manage VMs, but what is mostly exposed on the
Internet (e.g. as a web server) is the VM itself, which doesn't
need libvirt.

-- 
Vincent Lefèvre <vincent@vinc17.net> - Web: <https://www.vinc17.net/>
100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/>
Work: CR INRIA - computer arithmetic / AriC project (LIP, ENS-Lyon)

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | linux.debian.user


csiph-web