Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #241596 > unrolled thread
| Started by | Charles Curley <charlescurley@charlescurley.com> |
|---|---|
| First post | 2021-10-22 16:30 +0200 |
| Last post | 2021-10-22 17:00 +0200 |
| Articles | 6 — 5 participants |
Back to article view | Back to linux.debian.user
This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by
below is the oldest one visible, not the original post.
Re: xhost-command in Debian11 Charles Curley <charlescurley@charlescurley.com> - 2021-10-22 16:30 +0200
Re: xhost-command in Debian11 David Wright <deblis@lionunicorn.co.uk> - 2021-10-22 16:50 +0200
Re: xhost-command in Debian1 Charles Curley <charlescurley@charlescurley.com> - 2021-10-23 20:40 +0200
Re: xhost-command in Debian1 Keith Bainbridge <keithrbaugroups@gmail.com> - 2021-10-24 08:00 +0200
Re: xhost-command in Debian1 Greg Wooledge <greg@wooledge.org> - 2021-10-24 15:20 +0200
Re: xhost-command in Debian11 Reco <recoverym4n@enotuniq.net> - 2021-10-22 17:00 +0200
| From | Charles Curley <charlescurley@charlescurley.com> |
|---|---|
| Date | 2021-10-22 16:30 +0200 |
| Subject | Re: xhost-command in Debian11 |
| Message-ID | <Db3Iu-8ry-13@gated-at.bofh.it> |
[Multipart message — attachments visible in raw view] — view raw
On Tue, 15 Jun 2021 21:51:28 +0200 <tomas@tuxteam.de> wrote: > Try adding > the option `--whitelist-environment=DISPLAY to your su command (hint: > you can add more variables to that whitelist, comma separated). I just tried this. No joy. charles@jhegaala:~$ echo $DISPLAY :0.0 charles@jhegaala:~$ su - Password: Today is Setting Orange, the 3rd of The Aftermath, 3187. P'tang! root@jhegaala:~# exit logout charles@jhegaala:~$ su --whitelist-environment=DISPLAY - Password: Today is Setting Orange, the 3rd of The Aftermath, 3187. This statement is false. root@jhegaala:~# echo $DISPLAY :0.0 root@jhegaala:~# xclock & [1] 311078 root@jhegaala:~# No protocol specified Error: Can't open display: :0.0 [1]+ Exit 1 xclock root@jhegaala:~# emacs & [1] 311095 root@jhegaala:~# No protocol specified Display :0.0 unavailable, simulating -nw fg emacs root@jhegaala:~# -- Does anybody read signatures any more? https://charlescurley.com https://charlescurley.com/blog/
[toc] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2021-10-22 16:50 +0200 |
| Message-ID | <Db41Q-6s-7@gated-at.bofh.it> |
| In reply to | #241596 |
On Fri 22 Oct 2021 at 08:25:36 (-0600), Charles Curley wrote: > On Tue, 15 Jun 2021 21:51:28 +0200 > <tomas@tuxteam.de> wrote: > > > Try adding > > the option `--whitelist-environment=DISPLAY to your su command (hint: > > you can add more variables to that whitelist, comma separated). > > I just tried this. No joy. > > charles@jhegaala:~$ echo $DISPLAY > :0.0 > charles@jhegaala:~$ su - > Password: > > Today is Setting Orange, the 3rd of The Aftermath, 3187. P'tang! > root@jhegaala:~# exit > logout > charles@jhegaala:~$ su --whitelist-environment=DISPLAY - > Password: > > Today is Setting Orange, the 3rd of The Aftermath, 3187. This statement is false. > root@jhegaala:~# echo $DISPLAY > :0.0 > root@jhegaala:~# xclock & > [1] 311078 > root@jhegaala:~# No protocol specified > Error: Can't open display: :0.0 > > [1]+ Exit 1 xclock > root@jhegaala:~# emacs & > [1] 311095 > root@jhegaala:~# No protocol specified > Display :0.0 unavailable, simulating -nw > fg > emacs > root@jhegaala:~# I think you need su --whitelist-environment=DISPLAY,XAUTHORITY - Cheers, David.
[toc] | [prev] | [next] | [standalone]
| From | Charles Curley <charlescurley@charlescurley.com> |
|---|---|
| Date | 2021-10-23 20:40 +0200 |
| Subject | Re: xhost-command in Debian1 |
| Message-ID | <Dbu5X-7Dt-9@gated-at.bofh.it> |
| In reply to | #241597 |
On Fri, 22 Oct 2021 09:44:25 -0500
David Wright <deblis@lionunicorn.co.uk> wrote:
> > root@jhegaala:~#
>
> I think you need su --whitelist-environment=DISPLAY,XAUTHORITY -
Thank you, also to Reco.
I did:
$ alias su="su --whitelist-environment=DISPLAY,XAUTHORITY"
That works. So I will add that to my other aliases in ~/.bashrc and in
/etc/skel/.bashrc.
I tried editing /etc/security/pam_env.conf, as tomas@tuxteam.de
suggested earlier, but that caused problems.
DISPLAY DEFAULT=${REMOTEHOST}:0.0 OVERRIDE=${DISPLAY}
XAUTHORITY DEFAULT="/home/charles/.Xauthority" OVERRIDE=${XAUTHORITY}
The DISPLAY line appears to work; that XUTHORITY line does not. It
caused /home/charles/.Xauthority to be owned by root, which in turn
caused problems when SSHing in as charles.
--
Does anybody read signatures any more?
https://charlescurley.com
https://charlescurley.com/blog/
[toc] | [prev] | [next] | [standalone]
| From | Keith Bainbridge <keithrbaugroups@gmail.com> |
|---|---|
| Date | 2021-10-24 08:00 +0200 |
| Subject | Re: xhost-command in Debian1 |
| Message-ID | <DbEI2-5VO-3@gated-at.bofh.it> |
| In reply to | #241621 |
On 24/10/21 05:31, Charles Curley wrote: > alias su="su --whitelist-environment=DISPLAY,XAUTHORITY" Doesn't that mean that when you type 'su' at a command prompt, the response will be running the command --whitelist-environment=DISPLAY,XAUTHORITY as root. You won't be able to switch to root using su in future? -- All the best Keith Bainbridge keithrbaugroups@gmail.com
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <greg@wooledge.org> |
|---|---|
| Date | 2021-10-24 15:20 +0200 |
| Subject | Re: xhost-command in Debian1 |
| Message-ID | <DbLzQ-1OA-19@gated-at.bofh.it> |
| In reply to | #241626 |
On Sun, Oct 24, 2021 at 04:59:06PM +1100, Keith Bainbridge wrote: > > On 24/10/21 05:31, Charles Curley wrote: > > alias su="su --whitelist-environment=DISPLAY,XAUTHORITY" > > > Doesn't that mean that when you type 'su' at a command prompt, the response > will be running the command > --whitelist-environment=DISPLAY,XAUTHORITY > as root. No. It will run the command su --whitelist-environment=DISPLAY,XAUTHORITY which has setuid privileges, and therefore will run with effective UID 0. It's a lot like doing alias ls='ls --color=auto' The second ls inside the alias expansion becomes the new command that gets executed. Aliases don't recurse into themselves, which is by design so that people can do things exactly like this.
[toc] | [prev] | [next] | [standalone]
| From | Reco <recoverym4n@enotuniq.net> |
|---|---|
| Date | 2021-10-22 17:00 +0200 |
| Message-ID | <Db4bx-aJ-7@gated-at.bofh.it> |
| In reply to | #241596 |
Hi. On Fri, Oct 22, 2021 at 08:25:36AM -0600, Charles Curley wrote: > charles@jhegaala:~$ su --whitelist-environment=DISPLAY - It won't be enough. You need this: su --whitelist-environment=DISPLAY,XAUTHORITY - Reco
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web