Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #174275 > unrolled thread
| Started by | Richard Owlett <rowlett@cloud85.net> |
|---|---|
| First post | 2016-11-07 13:20 +0100 |
| Last post | 2016-11-07 15:00 +0100 |
| Articles | 20 on this page of 77 — 18 participants |
Back to article view | Back to linux.debian.user
parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-07 13:20 +0100
Re: parted is ALMOST suitable Felipe Salvador <felipe.salvador@gmail.com> - 2016-11-07 13:30 +0100
Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-07 13:40 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 14:00 +0100
Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-07 14:20 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 15:00 +0100
Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-07 15:50 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 16:10 +0100
Re: parted is ALMOST suitable Lisi Reisz <lisi.reisz@gmail.com> - 2016-11-07 17:30 +0100
Re: parted is ALMOST suitable Felipe Salvador <felipe.salvador@gmail.com> - 2016-11-07 15:30 +0100
Re: parted is ALMOST suitable Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2016-11-07 16:20 +0100
Re: parted is ALMOST suitable Aldo Maggi <aldomaggi@katamail.com> - 2016-11-07 18:20 +0100
Re: parted is ALMOST suitable Felipe Salvador <felipe.salvador@gmail.com> - 2016-11-07 19:00 +0100
Re: parted is ALMOST suitable Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2016-11-08 19:10 +0100
Re: parted is ALMOST suitable Glenn English <ghe2001@gmail.com> - 2016-11-08 19:40 +0100
Re: parted is ALMOST suitable Stefan Monnier <monnier@iro.umontreal.ca> - 2016-11-08 21:10 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-08 21:50 +0100
Re: parted is ALMOST suitable Stefan Monnier <monnier@iro.umontreal.ca> - 2016-11-09 00:20 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-09 18:40 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-09 21:40 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-09 21:50 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-09 22:20 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-09 09:50 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-09 11:20 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-09 11:30 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-09 11:50 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-09 12:10 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-09 17:10 +0100
Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-09 15:20 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-09 20:50 +0100
Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-09 21:40 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-09 21:10 +0100
Re: parted is ALMOST suitable Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2016-11-10 01:20 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-10 10:10 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-09 19:30 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-09 21:40 +0100
Re: parted is ALMOST suitable Stefan Monnier <monnier@iro.umontreal.ca> - 2016-11-08 22:10 +0100
Re: parted is ALMOST suitable Lisi Reisz <lisi.reisz@gmail.com> - 2016-11-09 16:00 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-09 09:40 +0100
Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-07 16:30 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-07 17:10 +0100
Re: parted is ALMOST suitable Felipe Salvador <felipe.salvador@gmail.com> - 2016-11-07 18:50 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-07 20:20 +0100
Re: parted is ALMOST suitable Lisi Reisz <lisi.reisz@gmail.com> - 2016-11-08 00:50 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-08 01:40 +0100
Re: parted is ALMOST suitable Michael Lange <klappnase@freenet.de> - 2016-11-08 03:50 +0100
Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-08 12:00 +0100
Correction - Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-08 12:20 +0100
Re: Correction - Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-08 20:30 +0100
Re: parted is ALMOST suitable David Wright <deblis@lionunicorn.co.uk> - 2016-11-08 13:50 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-08 20:10 +0100
Re: parted is ALMOST suitable Frank <zuiderduin@gmx.com> - 2016-11-07 13:30 +0100
Re: parted is ALMOST suitable Darac Marjal <mailinglist@darac.org.uk> - 2016-11-07 13:40 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 13:50 +0100
Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-07 14:30 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 15:10 +0100
Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-07 15:20 +0100
Re: parted is ALMOST suitable Greg Wooledge <wooledg@eeg.ccf.org> - 2016-11-07 15:30 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 15:40 +0100
Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-07 17:00 +0100
Re: parted is ALMOST suitable Greg Wooledge <wooledg@eeg.ccf.org> - 2016-11-07 17:10 +0100
Re: parted is ALMOST suitable Nicolas George <george@nsup.org> - 2016-11-07 17:20 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 15:30 +0100
Re: parted is ALMOST suitable Greg Wooledge <wooledg@eeg.ccf.org> - 2016-11-07 15:40 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 16:10 +0100
Re: parted is ALMOST suitable Reco <recoverym4n@gmail.com> - 2016-11-07 18:00 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-08 10:20 +0100
Re: parted is ALMOST suitable Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-07 21:10 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-08 01:00 +0100
Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-08 12:20 +0100
Re: parted is ALMOST suitable Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-11 15:40 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-11 17:30 +0100
Re: parted is ALMOST suitable Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-11 18:10 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-11 18:40 +0100
Re: parted is ALMOST suitable David Wright <deblis@lionunicorn.co.uk> - 2016-11-07 15:10 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 15:10 +0100
Re: parted is ALMOST suitable rhkramer@gmail.com - 2016-11-07 15:00 +0100
Page 1 of 4 [1] 2 3 4 Next page →
| From | Richard Owlett <rowlett@cloud85.net> |
|---|---|
| Date | 2016-11-07 13:20 +0100 |
| Subject | parted is ALMOST suitable |
| Message-ID | <sAR46-30v-17@gated-at.bofh.it> |
I need to identify file system on all partitions of my hard drive
whether mounted or not.
parted /dev/sda print | grep ext | grep -v exte
reports the desired information [partitions formatted ext?] in a
convenient format.
*HOWEVER* parted requires root privileges. That is not acceptable.
Suggestions?
TIA
[toc] | [next] | [standalone]
| From | Felipe Salvador <felipe.salvador@gmail.com> |
|---|---|
| Date | 2016-11-07 13:30 +0100 |
| Message-ID | <sARdL-33z-25@gated-at.bofh.it> |
| In reply to | #174275 |
On Mon, Nov 07, 2016 at 06:11:50AM -0600, Richard Owlett wrote: > *HOWEVER* parted requires root privileges. That is not acceptable. > Suggestions? > TIA lsblk -fr ? -- Felipe Salvador
[toc] | [prev] | [next] | [standalone]
| From | Richard Owlett <rowlett@cloud85.net> |
|---|---|
| Date | 2016-11-07 13:40 +0100 |
| Message-ID | <sARns-376-37@gated-at.bofh.it> |
| In reply to | #174277 |
On 11/7/2016 6:20 AM, Felipe Salvador wrote:
> On Mon, Nov 07, 2016 at 06:11:50AM -0600, Richard Owlett wrote:
>> *HOWEVER* parted requires root privileges. That is not acceptable.
>> Suggestions?
>> TIA
>
> lsblk -fr ?
>
Debian is perverse ;{
man page suggested good things.
However when run as other than root, there is a column heading
"FSTYPE".
It is blank for all partitions.
They are present when run as root.
Thanks for trying.
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2016-11-07 14:00 +0100 |
| Message-ID | <sARGT-3e5-9@gated-at.bofh.it> |
| In reply to | #174280 |
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
On Mon, Nov 07, 2016 at 06:37:53AM -0600, Richard Owlett wrote:
> On 11/7/2016 6:20 AM, Felipe Salvador wrote:
> >On Mon, Nov 07, 2016 at 06:11:50AM -0600, Richard Owlett wrote:
> >>*HOWEVER* parted requires root privileges. That is not acceptable.
> >>Suggestions?
> >>TIA
> >
> >lsblk -fr ?
> >
>
> Debian is perverse ;{
Uh... aren't we all?
> man page suggested good things.
> However when run as other than root, there is a column heading
> "FSTYPE".
> It is blank for all partitions.
> They are present when run as root.
Perhaps it needs read access to the partition's content, which it
only gets as root? (Or as group disk, as the case may be).
Debian is trying to protect you from someone taking over your...
say Apache and exfiltrating your most carefully kept secrets on
your harddisk. Just imagine how embarrassing that will be when
Wikileaks publishes that all!
;-D
regards
- -- t
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
iEYEARECAAYFAlggeOgACgkQBcgs9XrR2kYfuACdHtFYRmuLtAPQ7ShPD8ZIJwB5
+hwAnj0J/pTjTpopjNck+DJ8Xb22K7m6
=qNZ4
-----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Richard Owlett <rowlett@cloud85.net> |
|---|---|
| Date | 2016-11-07 14:20 +0100 |
| Message-ID | <sAS0c-3Aq-91@gated-at.bofh.it> |
| In reply to | #174283 |
On 11/7/2016 6:51 AM, tomas@tuxteam.de wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> On Mon, Nov 07, 2016 at 06:37:53AM -0600, Richard Owlett wrote:
>> On 11/7/2016 6:20 AM, Felipe Salvador wrote:
>>> On Mon, Nov 07, 2016 at 06:11:50AM -0600, Richard Owlett wrote:
>>>> *HOWEVER* parted requires root privileges. That is not acceptable.
>>>> Suggestions?
>>>> TIA
>>>
>>> lsblk -fr ?
>>>
>>
>> Debian is perverse ;{
>
> Uh... aren't we all?
Who? Me? You should have met a supervisor I had ~40 years ago.
>
>> man page suggested good things.
>> However when run as other than root, there is a column heading
>> "FSTYPE".
>> It is blank for all partitions.
>> They are present when run as root.
>
> Perhaps it needs read access to the partition's content, which it
> only gets as root? (Or as group disk, as the case may be).
>
> Debian is trying to protect you from someone taking over your...
> say Apache and exfiltrating your most carefully kept secrets on
> your harddisk. Just imagine how embarrassing that will be when
> Wikileaks publishes that all!
>
> ;-D
>
My Debian machines do not physically have networking capability.
See my email hearder. Mr. Gates can handle some things ;/
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2016-11-07 15:00 +0100 |
| Message-ID | <sASCX-3R8-21@gated-at.bofh.it> |
| In reply to | #174288 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Mon, Nov 07, 2016 at 07:12:00AM -0600, Richard Owlett wrote: [...] > >Debian is trying to protect you from someone taking over your... > >say Apache [...] > > My Debian machines do not physically have networking capability. > See my email hearder. Mr. Gates can handle some things ;/ No physical networking capability is needed for surprising things to happen. Spiritual network access may be enough (say playing a video file which carries a stack smashing exploit for your video player). I seem to discern in you the old DOS attitude which brought about a Golden Era of Virus (which is returning via the "The Browser is The Machine", mind you ;-) (please, don't take the above really seriously: but yes, many decisions behind all that permissions circus in Unix and children can be traced back to an effort to separate different things. If you let that concept sink in, you won't be surprised as often). regards - -- tomás -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlggiFoACgkQBcgs9XrR2kZy7wCfRZaATrhbYIuH7TR0+LpFnPuO XYAAnivpYOSb36gdDW5LcArlKsW6p1vW =0lLZ -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Richard Owlett <rowlett@cloud85.net> |
|---|---|
| Date | 2016-11-07 15:50 +0100 |
| Message-ID | <sATpf-4qY-9@gated-at.bofh.it> |
| In reply to | #174293 |
On 11/7/2016 7:57 AM, tomas@tuxteam.de wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > On Mon, Nov 07, 2016 at 07:12:00AM -0600, Richard Owlett wrote: > > [...] > >>> Debian is trying to protect you from someone taking over your... >>> say Apache [...] >> >> My Debian machines do not physically have networking capability. >> See my email hearder. Mr. Gates can handle some things ;/ > > No physical networking capability is needed for surprising things > to happen. Spiritual network access may be enough (say playing a > video file which carries a stack smashing exploit for your video > player). > > I seem to discern in you the old DOS attitude which brought about > a Golden Era of Virus (which is returning via the "The Browser is > The Machine", mind you ;-) > > (please, don't take the above really seriously: but yes, many > decisions behind all that permissions circus in Unix and children > can be traced back to an effort to separate different things. > If you let that concept sink in, you won't be surprised as often). > I doubt that were are that far apart in goals. I'm so old fashioned that I remember when the "cores" of core memory were visible to the naked eye.
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2016-11-07 16:10 +0100 |
| Message-ID | <sATIB-4Mo-7@gated-at.bofh.it> |
| In reply to | #174305 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Mon, Nov 07, 2016 at 08:48:29AM -0600, Richard Owlett wrote: > On 11/7/2016 7:57 AM, tomas@tuxteam.de wrote: > >-----BEGIN PGP SIGNED MESSAGE----- > >Hash: SHA1 > > > >On Mon, Nov 07, 2016 at 07:12:00AM -0600, Richard Owlett wrote: [...] > I doubt that were are that far apart in goals. I'm so old fashioned > that I remember when the "cores" of core memory were visible to the > naked eye. I missed that by a couple of years; my first programs were holes in paper, though :-) regards - -- t -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlggmJgACgkQBcgs9XrR2kafwQCeKHrUn8oJeBRCbM5fOMDrrtZG J5cAn2XcQk6FwyFI3icrgMGDMT4oVI15 =Wn88 -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Lisi Reisz <lisi.reisz@gmail.com> |
|---|---|
| Date | 2016-11-07 17:30 +0100 |
| Message-ID | <sAUY3-5vP-47@gated-at.bofh.it> |
| In reply to | #174305 |
On Monday 07 November 2016 14:48:29 Richard Owlett wrote: > On 11/7/2016 7:57 AM, tomas@tuxteam.de wrote: > > -----BEGIN PGP SIGNED MESSAGE----- > > Hash: SHA1 > > > > On Mon, Nov 07, 2016 at 07:12:00AM -0600, Richard Owlett wrote: > > > > [...] > > > >>> Debian is trying to protect you from someone taking over your... > >>> say Apache [...] > >> > >> My Debian machines do not physically have networking capability. > >> See my email hearder. Mr. Gates can handle some things ;/ > > > > No physical networking capability is needed for surprising things > > to happen. Spiritual network access may be enough (say playing a > > video file which carries a stack smashing exploit for your video > > player). > > > > I seem to discern in you the old DOS attitude which brought about > > a Golden Era of Virus (which is returning via the "The Browser is > > The Machine", mind you ;-) > > > > (please, don't take the above really seriously: but yes, many > > decisions behind all that permissions circus in Unix and children > > can be traced back to an effort to separate different things. > > If you let that concept sink in, you won't be surprised as often). > > I doubt that were are that far apart in goals. I'm so old > fashioned that I remember when the "cores" of core memory were > visible to the naked eye. My husband is so old fashioned that he insists on using cheques. The problem is that workmen et al don't like cheques. So I have taken to suggesting that he should pay me by cheque and I will pay the workmen electronically. I want them to work for us again!! Sometimes Richard, you have to accept that they have invented the quartz watch and not insist on using a wind up, then complaining when the local watch cleaner has closed down because everyone else has switched to quartz. Lisi
[toc] | [prev] | [next] | [standalone]
| From | Felipe Salvador <felipe.salvador@gmail.com> |
|---|---|
| Date | 2016-11-07 15:30 +0100 |
| Message-ID | <sAT5T-4ky-13@gated-at.bofh.it> |
| In reply to | #174280 |
On Mon, Nov 07, 2016 at 06:37:53AM -0600, Richard Owlett wrote:
> On 11/7/2016 6:20 AM, Felipe Salvador wrote:
> > On Mon, Nov 07, 2016 at 06:11:50AM -0600, Richard Owlett wrote:
> > > *HOWEVER* parted requires root privileges. That is not acceptable.
> > > Suggestions?
> > > TIA
> >
> > lsblk -fr ?
> >
>
> Debian is perverse ;{
> man page suggested good things.
> However when run as other than root, there is a column heading "FSTYPE".
> It is blank for all partitions.
> They are present when run as root.
> Thanks for trying.
I don't see this behaviour
~$ lsblk -fr
NAME FSTYPE LABEL UUID MOUNTPOINT
sda
sda1 ext2 ... /boot
sda2 ext4 ... /
sda3 ext2 ... /tmp
etc etc etc
or
file -s /dev/sda{1..5} | awk '{print $5}'
--
Felipe Salvador
[toc] | [prev] | [next] | [standalone]
| From | Joe Pfeiffer <pfeiffer@cs.nmsu.edu> |
|---|---|
| Date | 2016-11-07 16:20 +0100 |
| Message-ID | <sATSh-4Pz-15@gated-at.bofh.it> |
| In reply to | #174301 |
Felipe Salvador <felipe.salvador@gmail.com> writes:
> On Mon, Nov 07, 2016 at 06:37:53AM -0600, Richard Owlett wrote:
>> On 11/7/2016 6:20 AM, Felipe Salvador wrote:
>> > On Mon, Nov 07, 2016 at 06:11:50AM -0600, Richard Owlett wrote:
>> > > *HOWEVER* parted requires root privileges. That is not acceptable.
>> > > Suggestions?
>> > > TIA
>> >
>> > lsblk -fr ?
>> >
>>
>> Debian is perverse ;{
>> man page suggested good things.
>> However when run as other than root, there is a column heading "FSTYPE".
>
>> It is blank for all partitions.
>> They are present when run as root.
>> Thanks for trying.
>
> I don't see this behaviour
>
> ~$ lsblk -fr
> NAME FSTYPE LABEL UUID MOUNTPOINT
> sda
> sda1 ext2 ... /boot
> sda2 ext4 ... /
> sda3 ext2 ... /tmp
> etc etc etc
>
> or
>
> file -s /dev/sda{1..5} | awk '{print $5}'
I was just about to post a very similar followup when I discovered a
gaping security hole (really, about as big as it gets) on my machine:
snowball:404$ ls -l /dev/sda2
brw-rw-rw- 1 root root 8, 2 Nov 7 07:54 /dev/sda2
You might want to check your permissions as well....
[toc] | [prev] | [next] | [standalone]
| From | Aldo Maggi <aldomaggi@katamail.com> |
|---|---|
| Date | 2016-11-07 18:20 +0100 |
| Message-ID | <sAVKq-6d8-11@gated-at.bofh.it> |
| In reply to | #174308 |
[snip]
>>
>> file -s /dev/sda{1..5} | awk '{print $5}'
>
> I was just about to post a very similar followup when I discovered a
> gaping security hole (really, about as big as it gets) on my machine:
>
> snowball:404$ ls -l /dev/sda2
> brw-rw-rw- 1 root root 8, 2 Nov 7 07:54 /dev/sda2
I use stretch, but I have:
$ ls -l /dev/sda2
brw-rw---- 1 root disk 8, 2 nov 7 07:37 /dev/sda2
> You might want to check your permissions as well....
>
>
[toc] | [prev] | [next] | [standalone]
| From | Felipe Salvador <felipe.salvador@gmail.com> |
|---|---|
| Date | 2016-11-07 19:00 +0100 |
| Message-ID | <sAWn8-6sr-9@gated-at.bofh.it> |
| In reply to | #174308 |
On Mon, Nov 07, 2016 at 07:59:56AM -0700, Joe Pfeiffer wrote:
> Felipe Salvador <felipe.salvador@gmail.com> writes:
>
> > On Mon, Nov 07, 2016 at 06:37:53AM -0600, Richard Owlett wrote:
> >> On 11/7/2016 6:20 AM, Felipe Salvador wrote:
> >> > On Mon, Nov 07, 2016 at 06:11:50AM -0600, Richard Owlett wrote:
> >> > > *HOWEVER* parted requires root privileges. That is not acceptable.
> >> > > Suggestions?
> >> > > TIA
> >> >
> >> > lsblk -fr ?
> >> >
> >>
> >> Debian is perverse ;{
> >> man page suggested good things.
> >> However when run as other than root, there is a column heading "FSTYPE".
> >
> >> It is blank for all partitions.
> >> They are present when run as root.
> >> Thanks for trying.
> >
> > I don't see this behaviour
> >
> > ~$ lsblk -fr
> > NAME FSTYPE LABEL UUID MOUNTPOINT
> > sda
> > sda1 ext2 ... /boot
> > sda2 ext4 ... /
> > sda3 ext2 ... /tmp
> > etc etc etc
> >
> > or
> >
> > file -s /dev/sda{1..5} | awk '{print $5}'
>
> I was just about to post a very similar followup when I discovered a
> gaping security hole (really, about as big as it gets) on my machine:
>
> snowball:404$ ls -l /dev/sda2
> brw-rw-rw- 1 root root 8, 2 Nov 7 07:54 /dev/sda2
>
> You might want to check your permissions as well....
brw-rw---- 1 root disk 8, 0 nov 7 11:00 /dev/sda
I'm in the disk group
--
Felipe Salvador
[toc] | [prev] | [next] | [standalone]
| From | Joe Pfeiffer <pfeiffer@cs.nmsu.edu> |
|---|---|
| Date | 2016-11-08 19:10 +0100 |
| Message-ID | <sBj0m-4ko-43@gated-at.bofh.it> |
| In reply to | #174308 |
Joe Pfeiffer <pfeiffer@cs.nmsu.edu> writes:
> Felipe Salvador <felipe.salvador@gmail.com> writes:
>
>> On Mon, Nov 07, 2016 at 06:37:53AM -0600, Richard Owlett wrote:
>>> On 11/7/2016 6:20 AM, Felipe Salvador wrote:
>>> > On Mon, Nov 07, 2016 at 06:11:50AM -0600, Richard Owlett wrote:
>>> > > *HOWEVER* parted requires root privileges. That is not acceptable.
>>> > > Suggestions?
>>> > > TIA
>>> >
>>> > lsblk -fr ?
>>> >
>>>
>>> Debian is perverse ;{
>>> man page suggested good things.
>>> However when run as other than root, there is a column heading "FSTYPE".
>>
>>> It is blank for all partitions.
>>> They are present when run as root.
>>> Thanks for trying.
>>
>> I don't see this behaviour
>>
>> ~$ lsblk -fr
>> NAME FSTYPE LABEL UUID MOUNTPOINT
>> sda
>> sda1 ext2 ... /boot
>> sda2 ext4 ... /
>> sda3 ext2 ... /tmp
>> etc etc etc
>>
>> or
>>
>> file -s /dev/sda{1..5} | awk '{print $5}'
>
> I was just about to post a very similar followup when I discovered a
> gaping security hole (really, about as big as it gets) on my machine:
>
> snowball:404$ ls -l /dev/sda2
> brw-rw-rw- 1 root root 8, 2 Nov 7 07:54 /dev/sda2
>
> You might want to check your permissions as well....
Following up my own post in hopes this gets archived somewhere: the
bitscope software (which controls a USB oscilloscope) I had on my system
had installed a udev rule that was screwing up the disk permissions.
Upgrading to the latest version (why oh why can't these people put their
software in the repositories, or at least run their own repositories?)
fixed it.
[toc] | [prev] | [next] | [standalone]
| From | Glenn English <ghe2001@gmail.com> |
|---|---|
| Date | 2016-11-08 19:40 +0100 |
| Message-ID | <sBjto-4Ab-41@gated-at.bofh.it> |
| In reply to | #174357 |
>>>>> On Mon, Nov 07, 2016 at 06:11:50AM -0600, Richard Owlett wrote: >>>>>> *HOWEVER* parted requires root privileges. That is not acceptable. >>>>>> Suggestions? >>>>>> TIA Futzing with partitions is the admin's job. fdisk also want's root (or sudo). You want some user poking around in the disk(s)? -- Glenn English
[toc] | [prev] | [next] | [standalone]
| From | Stefan Monnier <monnier@iro.umontreal.ca> |
|---|---|
| Date | 2016-11-08 21:10 +0100 |
| Message-ID | <sBkSt-5IO-17@gated-at.bofh.it> |
| In reply to | #174361 |
>>>>>>> *HOWEVER* parted requires root privileges. That is not acceptable.
>>>>>>> Suggestions?
>>>>>>> TIA
> Futzing with partitions is the admin's job.
Could be, but it's not (g)parted's job to enforce these kinds of rules:
that's what Unix permissions (and Linux's capabilities) are for.
It's OK to add a warning and prompt the user to make sure he really
means to do that, but there's no point *preventing* the user from
shooting his own foot with this tool if he can do it with other
tools anyway.
> fdisk also want's root (or
> sudo). You want some user poking around in the disk(s)?
BTW, I have a pending bug report around this very same issue:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=439409
Feel free to weight in ;-)
Stefan
[toc] | [prev] | [next] | [standalone]
| From | Brian <ad44@cityscape.co.uk> |
|---|---|
| Date | 2016-11-08 21:50 +0100 |
| Message-ID | <sBlvb-5XM-1@gated-at.bofh.it> |
| In reply to | #174377 |
On Tue 08 Nov 2016 at 14:41:45 -0500, Stefan Monnier wrote: > >>>>>>> *HOWEVER* parted requires root privileges. That is not acceptable. > >>>>>>> Suggestions? > >>>>>>> TIA > > Futzing with partitions is the admin's job. > > Could be, but it's not (g)parted's job to enforce these kinds of rules: > that's what Unix permissions (and Linux's capabilities) are for. > > It's OK to add a warning and prompt the user to make sure he really > means to do that, but there's no point *preventing* the user from > shooting his own foot with this tool if he can do it with other > tools anyway. Users here get no opportunity to shoot themselves or anyone else in the foot. Access to raw disks is over my dead body. So I do not understand your point. -- Brian.
[toc] | [prev] | [next] | [standalone]
| From | Stefan Monnier <monnier@iro.umontreal.ca> |
|---|---|
| Date | 2016-11-09 00:20 +0100 |
| Message-ID | <sBnQm-7DS-7@gated-at.bofh.it> |
| In reply to | #174383 |
>> > Futzing with partitions is the admin's job.
>> Could be, but it's not (g)parted's job to enforce these kinds of rules:
>> that's what Unix permissions (and Linux's capabilities) are for.
>> It's OK to add a warning and prompt the user to make sure he really
>> means to do that, but there's no point *preventing* the user from
>> shooting his own foot with this tool if he can do it with other
>> tools anyway.
> Users here get no opportunity to shoot themselves or anyone else in the
> foot. Access to raw disks is over my dead body.
So your users don't have access rights to the raw disks?
Great! then (g)parted doesn't need to check anything since the kernel
will do that already.
> So I do not understand your point.
The fact that it checks if the user is UID 0 is either useless (because
the user doesn't have write access to the device anyway, as should
usually be the case for the real physical devices connected to the
machine) or annoying (because it doesn't give any extra security since
the user can shoot himself in the foot with any number of other tools
anyway).
It costs extra code with at best no benefit.
Stefan
[toc] | [prev] | [next] | [standalone]
| From | Brian <ad44@cityscape.co.uk> |
|---|---|
| Date | 2016-11-09 18:40 +0100 |
| Message-ID | <sBF0R-1Ui-19@gated-at.bofh.it> |
| In reply to | #174398 |
On Tue 08 Nov 2016 at 17:54:41 -0500, Stefan Monnier wrote: > >> > Futzing with partitions is the admin's job. > >> Could be, but it's not (g)parted's job to enforce these kinds of rules: > >> that's what Unix permissions (and Linux's capabilities) are for. > >> It's OK to add a warning and prompt the user to make sure he really > >> means to do that, but there's no point *preventing* the user from > >> shooting his own foot with this tool if he can do it with other > >> tools anyway. > > > Users here get no opportunity to shoot themselves or anyone else in the > > foot. Access to raw disks is over my dead body. > > So your users don't have access rights to the raw disks? > Great! then (g)parted doesn't need to check anything since the kernel > will do that already. > > > So I do not understand your point. > > The fact that it checks if the user is UID 0 is either useless (because > the user doesn't have write access to the device anyway, as should > usually be the case for the real physical devices connected to the > machine) or annoying (because it doesn't give any extra security since > the user can shoot himself in the foot with any number of other tools > anyway). > > It costs extra code with at best no benefit. A well-made couple of points. But a user being able to shoot himself in his own foot with other tools as a way of bolstering the argument doesn't bear close scrutiny nowadays. Perhaps a reason for updating the bug record to clarify what the issue is? -- Brian.
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2016-11-09 21:40 +0100 |
| Message-ID | <sBHP4-3Kz-51@gated-at.bofh.it> |
| In reply to | #174432 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Wed, Nov 09, 2016 at 05:38:01PM +0000, Brian wrote: > On Tue 08 Nov 2016 at 17:54:41 -0500, Stefan Monnier wrote: > > > >> > Futzing with partitions is the admin's job. > > >> Could be, but it's not (g)parted's job to enforce these kinds of rules: [...] > > It costs extra code with at best no benefit. > > A well-made couple of points. But a user being able to shoot himself > in his own foot with other tools as a way of bolstering the argument > doesn't bear close scrutiny nowadays. But this should be taken care of by the device files having appropriate permissions. An /dev/sda having -rw-rw-rw- is asking for trouble, I think we all agree on this :-) > Perhaps a reason for updating > the bug record to clarify what the issue is? Hm. Layering error. regards - -- t -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlgjiIIACgkQBcgs9XrR2kbPQACeOgjjHNwDURiKeeI8id4iNn9i eMsAn1rAkCgZXl3bL8MkzYwp0L27MeHA =0fEr -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
Page 1 of 4 [1] 2 3 4 Next page →
Back to top | Article view | linux.debian.user
csiph-web