Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #174275 > unrolled thread

parted is ALMOST suitable

Started byRichard Owlett <rowlett@cloud85.net>
First post2016-11-07 13:20 +0100
Last post2016-11-07 15:00 +0100
Articles 20 on this page of 77 — 18 participants

Back to article view | Back to linux.debian.user


Contents

  parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-07 13:20 +0100
    Re: parted is ALMOST suitable Felipe Salvador <felipe.salvador@gmail.com> - 2016-11-07 13:30 +0100
      Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-07 13:40 +0100
        Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 14:00 +0100
          Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-07 14:20 +0100
            Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 15:00 +0100
              Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-07 15:50 +0100
                Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 16:10 +0100
                Re: parted is ALMOST suitable Lisi Reisz <lisi.reisz@gmail.com> - 2016-11-07 17:30 +0100
        Re: parted is ALMOST suitable Felipe Salvador <felipe.salvador@gmail.com> - 2016-11-07 15:30 +0100
          Re: parted is ALMOST suitable Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2016-11-07 16:20 +0100
            Re: parted is ALMOST suitable Aldo Maggi <aldomaggi@katamail.com> - 2016-11-07 18:20 +0100
            Re: parted is ALMOST suitable Felipe Salvador <felipe.salvador@gmail.com> - 2016-11-07 19:00 +0100
            Re: parted is ALMOST suitable Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2016-11-08 19:10 +0100
              Re: parted is ALMOST suitable Glenn English <ghe2001@gmail.com> - 2016-11-08 19:40 +0100
                Re: parted is ALMOST suitable Stefan Monnier <monnier@iro.umontreal.ca> - 2016-11-08 21:10 +0100
                  Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-08 21:50 +0100
                    Re: parted is ALMOST suitable Stefan Monnier <monnier@iro.umontreal.ca> - 2016-11-09 00:20 +0100
                      Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-09 18:40 +0100
                        Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-09 21:40 +0100
                          Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-09 21:50 +0100
                            Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-09 22:20 +0100
                    Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-09 09:50 +0100
                      Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-09 11:20 +0100
                        Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-09 11:30 +0100
                          Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-09 11:50 +0100
                            Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-09 12:10 +0100
                              Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-09 17:10 +0100
                          Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-09 15:20 +0100
                            Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-09 20:50 +0100
                              Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-09 21:40 +0100
                          Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-09 21:10 +0100
                            Re: parted is ALMOST suitable Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2016-11-10 01:20 +0100
                              Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-10 10:10 +0100
                      Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-09 19:30 +0100
                        Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-09 21:40 +0100
                  Re: parted is ALMOST suitable Stefan Monnier <monnier@iro.umontreal.ca> - 2016-11-08 22:10 +0100
                    Re: parted is ALMOST suitable Lisi Reisz <lisi.reisz@gmail.com> - 2016-11-09 16:00 +0100
                  Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-09 09:40 +0100
          Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-07 16:30 +0100
            Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-07 17:10 +0100
              Re: parted is ALMOST suitable Felipe Salvador <felipe.salvador@gmail.com> - 2016-11-07 18:50 +0100
                Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-07 20:20 +0100
                  Re: parted is ALMOST suitable Lisi Reisz <lisi.reisz@gmail.com> - 2016-11-08 00:50 +0100
                    Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-08 01:40 +0100
                    Re: parted is ALMOST suitable Michael Lange <klappnase@freenet.de> - 2016-11-08 03:50 +0100
                      Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-08 12:00 +0100
                        Correction - Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-08 12:20 +0100
                          Re: Correction - Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-08 20:30 +0100
                        Re: parted is ALMOST suitable David Wright <deblis@lionunicorn.co.uk> - 2016-11-08 13:50 +0100
                          Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-08 20:10 +0100
    Re: parted is ALMOST suitable Frank <zuiderduin@gmx.com> - 2016-11-07 13:30 +0100
    Re: parted is ALMOST suitable Darac Marjal <mailinglist@darac.org.uk> - 2016-11-07 13:40 +0100
    Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 13:50 +0100
      Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-07 14:30 +0100
        Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 15:10 +0100
        Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-07 15:20 +0100
          Re: parted is ALMOST suitable Greg Wooledge <wooledg@eeg.ccf.org> - 2016-11-07 15:30 +0100
            Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 15:40 +0100
            Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-07 17:00 +0100
              Re: parted is ALMOST suitable Greg Wooledge <wooledg@eeg.ccf.org> - 2016-11-07 17:10 +0100
                Re: parted is ALMOST suitable Nicolas George <george@nsup.org> - 2016-11-07 17:20 +0100
          Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 15:30 +0100
            Re: parted is ALMOST suitable Greg Wooledge <wooledg@eeg.ccf.org> - 2016-11-07 15:40 +0100
              Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 16:10 +0100
                Re: parted is ALMOST suitable Reco <recoverym4n@gmail.com> - 2016-11-07 18:00 +0100
                  Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-08 10:20 +0100
          Re: parted is ALMOST suitable Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-07 21:10 +0100
            Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-08 01:00 +0100
              Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-08 12:20 +0100
              Re: parted is ALMOST suitable Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-11 15:40 +0100
                Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-11 17:30 +0100
                  Re: parted is ALMOST suitable Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-11 18:10 +0100
                    Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-11 18:40 +0100
      Re: parted is ALMOST suitable David Wright <deblis@lionunicorn.co.uk> - 2016-11-07 15:10 +0100
        Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 15:10 +0100
    Re: parted is ALMOST suitable rhkramer@gmail.com - 2016-11-07 15:00 +0100

Page 1 of 4  [1] 2 3 4  Next page →


#174275 — parted is ALMOST suitable

FromRichard Owlett <rowlett@cloud85.net>
Date2016-11-07 13:20 +0100
Subjectparted is ALMOST suitable
Message-ID<sAR46-30v-17@gated-at.bofh.it>
I need to identify file system on all partitions of my hard drive 
whether mounted or not.
     parted /dev/sda print | grep ext | grep -v exte
reports the desired information [partitions formatted ext?] in a 
convenient format.
*HOWEVER* parted requires root privileges. That is not acceptable.
Suggestions?
TIA

[toc] | [next] | [standalone]


#174277

FromFelipe Salvador <felipe.salvador@gmail.com>
Date2016-11-07 13:30 +0100
Message-ID<sARdL-33z-25@gated-at.bofh.it>
In reply to#174275
On Mon, Nov 07, 2016 at 06:11:50AM -0600, Richard Owlett wrote:
> *HOWEVER* parted requires root privileges. That is not acceptable.
> Suggestions?
> TIA

lsblk -fr ?

-- 
Felipe Salvador

[toc] | [prev] | [next] | [standalone]


#174280

FromRichard Owlett <rowlett@cloud85.net>
Date2016-11-07 13:40 +0100
Message-ID<sARns-376-37@gated-at.bofh.it>
In reply to#174277
On 11/7/2016 6:20 AM, Felipe Salvador wrote:
> On Mon, Nov 07, 2016 at 06:11:50AM -0600, Richard Owlett wrote:
>> *HOWEVER* parted requires root privileges. That is not acceptable.
>> Suggestions?
>> TIA
>
> lsblk -fr ?
>

Debian is perverse ;{
man page suggested good things.
However when run as other than root, there is a column heading 
"FSTYPE".
It is blank for all partitions.
They are present when run as root.
Thanks for trying.

[toc] | [prev] | [next] | [standalone]


#174283

From<tomas@tuxteam.de>
Date2016-11-07 14:00 +0100
Message-ID<sARGT-3e5-9@gated-at.bofh.it>
In reply to#174280
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Mon, Nov 07, 2016 at 06:37:53AM -0600, Richard Owlett wrote:
> On 11/7/2016 6:20 AM, Felipe Salvador wrote:
> >On Mon, Nov 07, 2016 at 06:11:50AM -0600, Richard Owlett wrote:
> >>*HOWEVER* parted requires root privileges. That is not acceptable.
> >>Suggestions?
> >>TIA
> >
> >lsblk -fr ?
> >
> 
> Debian is perverse ;{

Uh... aren't we all?

> man page suggested good things.
> However when run as other than root, there is a column heading
> "FSTYPE".
> It is blank for all partitions.
> They are present when run as root.

Perhaps it needs read access to the partition's content, which it
only gets as root? (Or as group disk, as the case may be).

Debian is trying to protect you from someone taking over your...
say Apache and exfiltrating your most carefully kept secrets on
your harddisk. Just imagine how embarrassing that will be when
Wikileaks publishes that all!

;-D

regards
- -- t
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlggeOgACgkQBcgs9XrR2kYfuACdHtFYRmuLtAPQ7ShPD8ZIJwB5
+hwAnj0J/pTjTpopjNck+DJ8Xb22K7m6
=qNZ4
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#174288

FromRichard Owlett <rowlett@cloud85.net>
Date2016-11-07 14:20 +0100
Message-ID<sAS0c-3Aq-91@gated-at.bofh.it>
In reply to#174283
On 11/7/2016 6:51 AM, tomas@tuxteam.de wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> On Mon, Nov 07, 2016 at 06:37:53AM -0600, Richard Owlett wrote:
>> On 11/7/2016 6:20 AM, Felipe Salvador wrote:
>>> On Mon, Nov 07, 2016 at 06:11:50AM -0600, Richard Owlett wrote:
>>>> *HOWEVER* parted requires root privileges. That is not acceptable.
>>>> Suggestions?
>>>> TIA
>>>
>>> lsblk -fr ?
>>>
>>
>> Debian is perverse ;{
>
> Uh... aren't we all?

Who? Me? You should have met a supervisor I had ~40 years ago.

>
>> man page suggested good things.
>> However when run as other than root, there is a column heading
>> "FSTYPE".
>> It is blank for all partitions.
>> They are present when run as root.
>
> Perhaps it needs read access to the partition's content, which it
> only gets as root? (Or as group disk, as the case may be).
>
> Debian is trying to protect you from someone taking over your...
> say Apache and exfiltrating your most carefully kept secrets on
> your harddisk. Just imagine how embarrassing that will be when
> Wikileaks publishes that all!
>
> ;-D
>

My Debian machines do not physically have networking capability.
See my email hearder. Mr. Gates can handle some things ;/

[toc] | [prev] | [next] | [standalone]


#174293

From<tomas@tuxteam.de>
Date2016-11-07 15:00 +0100
Message-ID<sASCX-3R8-21@gated-at.bofh.it>
In reply to#174288
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Mon, Nov 07, 2016 at 07:12:00AM -0600, Richard Owlett wrote:

[...]

> >Debian is trying to protect you from someone taking over your...
> >say Apache [...]
> 
> My Debian machines do not physically have networking capability.
> See my email hearder. Mr. Gates can handle some things ;/

No physical networking capability is needed for surprising things
to happen. Spiritual network access may be enough (say playing a
video file which carries a stack smashing exploit for your video
player).

I seem to discern in you the old DOS attitude which brought about
a Golden Era of Virus (which is returning via the "The Browser is
The Machine", mind you ;-)

(please, don't take the above really seriously: but yes, many
decisions behind all that permissions circus in Unix and children
can be traced back to an effort to separate different things.
If you let that concept sink in, you won't be surprised as often).

regards
- -- tomás
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlggiFoACgkQBcgs9XrR2kZy7wCfRZaATrhbYIuH7TR0+LpFnPuO
XYAAnivpYOSb36gdDW5LcArlKsW6p1vW
=0lLZ
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#174305

FromRichard Owlett <rowlett@cloud85.net>
Date2016-11-07 15:50 +0100
Message-ID<sATpf-4qY-9@gated-at.bofh.it>
In reply to#174293
On 11/7/2016 7:57 AM, tomas@tuxteam.de wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> On Mon, Nov 07, 2016 at 07:12:00AM -0600, Richard Owlett wrote:
>
> [...]
>
>>> Debian is trying to protect you from someone taking over your...
>>> say Apache [...]
>>
>> My Debian machines do not physically have networking capability.
>> See my email hearder. Mr. Gates can handle some things ;/
>
> No physical networking capability is needed for surprising things
> to happen. Spiritual network access may be enough (say playing a
> video file which carries a stack smashing exploit for your video
> player).
>
> I seem to discern in you the old DOS attitude which brought about
> a Golden Era of Virus (which is returning via the "The Browser is
> The Machine", mind you ;-)
>
> (please, don't take the above really seriously: but yes, many
> decisions behind all that permissions circus in Unix and children
> can be traced back to an effort to separate different things.
> If you let that concept sink in, you won't be surprised as often).
>

I doubt that were are that far apart in goals. I'm so old 
fashioned that I remember when the "cores" of core memory were 
visible to the naked eye.

[toc] | [prev] | [next] | [standalone]


#174307

From<tomas@tuxteam.de>
Date2016-11-07 16:10 +0100
Message-ID<sATIB-4Mo-7@gated-at.bofh.it>
In reply to#174305
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Mon, Nov 07, 2016 at 08:48:29AM -0600, Richard Owlett wrote:
> On 11/7/2016 7:57 AM, tomas@tuxteam.de wrote:
> >-----BEGIN PGP SIGNED MESSAGE-----
> >Hash: SHA1
> >
> >On Mon, Nov 07, 2016 at 07:12:00AM -0600, Richard Owlett wrote:

[...]

> I doubt that were are that far apart in goals. I'm so old fashioned
> that I remember when the "cores" of core memory were visible to the
> naked eye.

I missed that by a couple of years; my first programs were holes
in paper, though :-)

regards
- -- t
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlggmJgACgkQBcgs9XrR2kafwQCeKHrUn8oJeBRCbM5fOMDrrtZG
J5cAn2XcQk6FwyFI3icrgMGDMT4oVI15
=Wn88
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#174316

FromLisi Reisz <lisi.reisz@gmail.com>
Date2016-11-07 17:30 +0100
Message-ID<sAUY3-5vP-47@gated-at.bofh.it>
In reply to#174305
On Monday 07 November 2016 14:48:29 Richard Owlett wrote:
> On 11/7/2016 7:57 AM, tomas@tuxteam.de wrote:
> > -----BEGIN PGP SIGNED MESSAGE-----
> > Hash: SHA1
> >
> > On Mon, Nov 07, 2016 at 07:12:00AM -0600, Richard Owlett wrote:
> >
> > [...]
> >
> >>> Debian is trying to protect you from someone taking over your...
> >>> say Apache [...]
> >>
> >> My Debian machines do not physically have networking capability.
> >> See my email hearder. Mr. Gates can handle some things ;/
> >
> > No physical networking capability is needed for surprising things
> > to happen. Spiritual network access may be enough (say playing a
> > video file which carries a stack smashing exploit for your video
> > player).
> >
> > I seem to discern in you the old DOS attitude which brought about
> > a Golden Era of Virus (which is returning via the "The Browser is
> > The Machine", mind you ;-)
> >
> > (please, don't take the above really seriously: but yes, many
> > decisions behind all that permissions circus in Unix and children
> > can be traced back to an effort to separate different things.
> > If you let that concept sink in, you won't be surprised as often).
>
> I doubt that were are that far apart in goals. I'm so old
> fashioned that I remember when the "cores" of core memory were
> visible to the naked eye.

My husband is so old fashioned that he insists on using cheques.  The problem 
is that workmen et al don't like cheques.  So I have taken to suggesting that 
he should pay me by cheque and I will pay the workmen electronically.  I want 
them to work for us again!!

Sometimes Richard, you have to accept that they have invented the quartz watch 
and not insist on using a wind up, then complaining when the local watch 
cleaner has closed down because everyone else has switched to quartz.

Lisi

[toc] | [prev] | [next] | [standalone]


#174301

FromFelipe Salvador <felipe.salvador@gmail.com>
Date2016-11-07 15:30 +0100
Message-ID<sAT5T-4ky-13@gated-at.bofh.it>
In reply to#174280
On Mon, Nov 07, 2016 at 06:37:53AM -0600, Richard Owlett wrote:
> On 11/7/2016 6:20 AM, Felipe Salvador wrote:
> > On Mon, Nov 07, 2016 at 06:11:50AM -0600, Richard Owlett wrote:
> > > *HOWEVER* parted requires root privileges. That is not acceptable.
> > > Suggestions?
> > > TIA
> > 
> > lsblk -fr ?
> > 
> 
> Debian is perverse ;{
> man page suggested good things.
> However when run as other than root, there is a column heading "FSTYPE".

> It is blank for all partitions.
> They are present when run as root.
> Thanks for trying.

I don't see this behaviour

~$ lsblk -fr
NAME FSTYPE LABEL UUID MOUNTPOINT
sda
sda1 ext2  ... /boot
sda2 ext4  ... /
sda3 ext2  ... /tmp
etc etc etc

or

file -s /dev/sda{1..5} | awk '{print $5}'



-- 
Felipe Salvador

[toc] | [prev] | [next] | [standalone]


#174308

FromJoe Pfeiffer <pfeiffer@cs.nmsu.edu>
Date2016-11-07 16:20 +0100
Message-ID<sATSh-4Pz-15@gated-at.bofh.it>
In reply to#174301
Felipe Salvador <felipe.salvador@gmail.com> writes:

> On Mon, Nov 07, 2016 at 06:37:53AM -0600, Richard Owlett wrote:
>> On 11/7/2016 6:20 AM, Felipe Salvador wrote:
>> > On Mon, Nov 07, 2016 at 06:11:50AM -0600, Richard Owlett wrote:
>> > > *HOWEVER* parted requires root privileges. That is not acceptable.
>> > > Suggestions?
>> > > TIA
>> > 
>> > lsblk -fr ?
>> > 
>> 
>> Debian is perverse ;{
>> man page suggested good things.
>> However when run as other than root, there is a column heading "FSTYPE".
>
>> It is blank for all partitions.
>> They are present when run as root.
>> Thanks for trying.
>
> I don't see this behaviour
>
> ~$ lsblk -fr
> NAME FSTYPE LABEL UUID MOUNTPOINT
> sda
> sda1 ext2  ... /boot
> sda2 ext4  ... /
> sda3 ext2  ... /tmp
> etc etc etc
>
> or
>
> file -s /dev/sda{1..5} | awk '{print $5}'

I was just about to post a very similar followup when I discovered a
gaping security hole (really, about as big as it gets) on my machine:

snowball:404$ ls -l /dev/sda2
brw-rw-rw- 1 root root 8, 2 Nov  7 07:54 /dev/sda2

You might want to check your permissions as well....

[toc] | [prev] | [next] | [standalone]


#174318

FromAldo Maggi <aldomaggi@katamail.com>
Date2016-11-07 18:20 +0100
Message-ID<sAVKq-6d8-11@gated-at.bofh.it>
In reply to#174308

[snip]
>>
>> file -s /dev/sda{1..5} | awk '{print $5}'
>
> I was just about to post a very similar followup when I discovered a
> gaping security hole (really, about as big as it gets) on my machine:
>
> snowball:404$ ls -l /dev/sda2
> brw-rw-rw- 1 root root 8, 2 Nov  7 07:54 /dev/sda2

I use stretch, but I have:

$ ls -l /dev/sda2
brw-rw---- 1 root disk 8, 2 nov  7 07:37 /dev/sda2

> You might want to check your permissions as well....
>
>

[toc] | [prev] | [next] | [standalone]


#174322

FromFelipe Salvador <felipe.salvador@gmail.com>
Date2016-11-07 19:00 +0100
Message-ID<sAWn8-6sr-9@gated-at.bofh.it>
In reply to#174308
On Mon, Nov 07, 2016 at 07:59:56AM -0700, Joe Pfeiffer wrote:
> Felipe Salvador <felipe.salvador@gmail.com> writes:
> 
> > On Mon, Nov 07, 2016 at 06:37:53AM -0600, Richard Owlett wrote:
> >> On 11/7/2016 6:20 AM, Felipe Salvador wrote:
> >> > On Mon, Nov 07, 2016 at 06:11:50AM -0600, Richard Owlett wrote:
> >> > > *HOWEVER* parted requires root privileges. That is not acceptable.
> >> > > Suggestions?
> >> > > TIA
> >> > 
> >> > lsblk -fr ?
> >> > 
> >> 
> >> Debian is perverse ;{
> >> man page suggested good things.
> >> However when run as other than root, there is a column heading "FSTYPE".
> >
> >> It is blank for all partitions.
> >> They are present when run as root.
> >> Thanks for trying.
> >
> > I don't see this behaviour
> >
> > ~$ lsblk -fr
> > NAME FSTYPE LABEL UUID MOUNTPOINT
> > sda
> > sda1 ext2  ... /boot
> > sda2 ext4  ... /
> > sda3 ext2  ... /tmp
> > etc etc etc
> >
> > or
> >
> > file -s /dev/sda{1..5} | awk '{print $5}'
> 
> I was just about to post a very similar followup when I discovered a
> gaping security hole (really, about as big as it gets) on my machine:
> 
> snowball:404$ ls -l /dev/sda2
> brw-rw-rw- 1 root root 8, 2 Nov  7 07:54 /dev/sda2
> 
> You might want to check your permissions as well....

brw-rw---- 1 root disk 8, 0 nov  7 11:00 /dev/sda

I'm in the disk group

-- 
Felipe Salvador

[toc] | [prev] | [next] | [standalone]


#174357

FromJoe Pfeiffer <pfeiffer@cs.nmsu.edu>
Date2016-11-08 19:10 +0100
Message-ID<sBj0m-4ko-43@gated-at.bofh.it>
In reply to#174308
Joe Pfeiffer <pfeiffer@cs.nmsu.edu> writes:

> Felipe Salvador <felipe.salvador@gmail.com> writes:
>
>> On Mon, Nov 07, 2016 at 06:37:53AM -0600, Richard Owlett wrote:
>>> On 11/7/2016 6:20 AM, Felipe Salvador wrote:
>>> > On Mon, Nov 07, 2016 at 06:11:50AM -0600, Richard Owlett wrote:
>>> > > *HOWEVER* parted requires root privileges. That is not acceptable.
>>> > > Suggestions?
>>> > > TIA
>>> > 
>>> > lsblk -fr ?
>>> > 
>>> 
>>> Debian is perverse ;{
>>> man page suggested good things.
>>> However when run as other than root, there is a column heading "FSTYPE".
>>
>>> It is blank for all partitions.
>>> They are present when run as root.
>>> Thanks for trying.
>>
>> I don't see this behaviour
>>
>> ~$ lsblk -fr
>> NAME FSTYPE LABEL UUID MOUNTPOINT
>> sda
>> sda1 ext2  ... /boot
>> sda2 ext4  ... /
>> sda3 ext2  ... /tmp
>> etc etc etc
>>
>> or
>>
>> file -s /dev/sda{1..5} | awk '{print $5}'
>
> I was just about to post a very similar followup when I discovered a
> gaping security hole (really, about as big as it gets) on my machine:
>
> snowball:404$ ls -l /dev/sda2
> brw-rw-rw- 1 root root 8, 2 Nov  7 07:54 /dev/sda2
>
> You might want to check your permissions as well....

Following up my own post in hopes this gets archived somewhere:  the
bitscope software (which controls a USB oscilloscope) I had on my system
had installed a udev rule that was screwing up the disk permissions.
Upgrading to the latest version (why oh why can't these people put their
software in the repositories, or at least run their own repositories?)
fixed it.

[toc] | [prev] | [next] | [standalone]


#174361

FromGlenn English <ghe2001@gmail.com>
Date2016-11-08 19:40 +0100
Message-ID<sBjto-4Ab-41@gated-at.bofh.it>
In reply to#174357
>>>>> On Mon, Nov 07, 2016 at 06:11:50AM -0600, Richard Owlett wrote:
>>>>>> *HOWEVER* parted requires root privileges. That is not acceptable.
>>>>>> Suggestions?
>>>>>> TIA

Futzing with partitions is the admin's job. fdisk also want's root (or sudo). You want some user poking around in the disk(s)?

-- 
Glenn English

[toc] | [prev] | [next] | [standalone]


#174377

FromStefan Monnier <monnier@iro.umontreal.ca>
Date2016-11-08 21:10 +0100
Message-ID<sBkSt-5IO-17@gated-at.bofh.it>
In reply to#174361
>>>>>>> *HOWEVER* parted requires root privileges. That is not acceptable.
>>>>>>> Suggestions?
>>>>>>> TIA
> Futzing with partitions is the admin's job.

Could be, but it's not (g)parted's job to enforce these kinds of rules:
that's what Unix permissions (and Linux's capabilities) are for.

It's OK to add a warning and prompt the user to make sure he really
means to do that, but there's no point *preventing* the user from
shooting his own foot with this tool if he can do it with other
tools anyway.

> fdisk also want's root (or
> sudo). You want some user poking around in the disk(s)?

BTW, I have a pending bug report around this very same issue:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=439409

Feel free to weight in ;-)


        Stefan

[toc] | [prev] | [next] | [standalone]


#174383

FromBrian <ad44@cityscape.co.uk>
Date2016-11-08 21:50 +0100
Message-ID<sBlvb-5XM-1@gated-at.bofh.it>
In reply to#174377
On Tue 08 Nov 2016 at 14:41:45 -0500, Stefan Monnier wrote:

> >>>>>>> *HOWEVER* parted requires root privileges. That is not acceptable.
> >>>>>>> Suggestions?
> >>>>>>> TIA
> > Futzing with partitions is the admin's job.
> 
> Could be, but it's not (g)parted's job to enforce these kinds of rules:
> that's what Unix permissions (and Linux's capabilities) are for.
> 
> It's OK to add a warning and prompt the user to make sure he really
> means to do that, but there's no point *preventing* the user from
> shooting his own foot with this tool if he can do it with other
> tools anyway.

Users here get no opportunity to shoot themselves or anyone else in the
foot. Access to raw disks is over my dead body. So I do not understand
your point.

-- 
Brian.

[toc] | [prev] | [next] | [standalone]


#174398

FromStefan Monnier <monnier@iro.umontreal.ca>
Date2016-11-09 00:20 +0100
Message-ID<sBnQm-7DS-7@gated-at.bofh.it>
In reply to#174383
>> > Futzing with partitions is the admin's job.
>> Could be, but it's not (g)parted's job to enforce these kinds of rules:
>> that's what Unix permissions (and Linux's capabilities) are for.
>> It's OK to add a warning and prompt the user to make sure he really
>> means to do that, but there's no point *preventing* the user from
>> shooting his own foot with this tool if he can do it with other
>> tools anyway.

> Users here get no opportunity to shoot themselves or anyone else in the
> foot.  Access to raw disks is over my dead body.

So your users don't have access rights to the raw disks?
Great! then (g)parted doesn't need to check anything since the kernel
will do that already.

> So I do not understand your point.

The fact that it checks if the user is UID 0 is either useless (because
the user doesn't have write access to the device anyway, as should
usually be the case for the real physical devices connected to the
machine) or annoying (because it doesn't give any extra security since
the user can shoot himself in the foot with any number of other tools
anyway).

It costs extra code with at best no benefit.


        Stefan

[toc] | [prev] | [next] | [standalone]


#174432

FromBrian <ad44@cityscape.co.uk>
Date2016-11-09 18:40 +0100
Message-ID<sBF0R-1Ui-19@gated-at.bofh.it>
In reply to#174398
On Tue 08 Nov 2016 at 17:54:41 -0500, Stefan Monnier wrote:

> >> > Futzing with partitions is the admin's job.
> >> Could be, but it's not (g)parted's job to enforce these kinds of rules:
> >> that's what Unix permissions (and Linux's capabilities) are for.
> >> It's OK to add a warning and prompt the user to make sure he really
> >> means to do that, but there's no point *preventing* the user from
> >> shooting his own foot with this tool if he can do it with other
> >> tools anyway.
> 
> > Users here get no opportunity to shoot themselves or anyone else in the
> > foot.  Access to raw disks is over my dead body.
> 
> So your users don't have access rights to the raw disks?
> Great! then (g)parted doesn't need to check anything since the kernel
> will do that already.
> 
> > So I do not understand your point.
> 
> The fact that it checks if the user is UID 0 is either useless (because
> the user doesn't have write access to the device anyway, as should
> usually be the case for the real physical devices connected to the
> machine) or annoying (because it doesn't give any extra security since
> the user can shoot himself in the foot with any number of other tools
> anyway).
> 
> It costs extra code with at best no benefit.

A well-made couple of points. But a user being able to shoot himself
in his own foot with other tools as a way of bolstering the argument
doesn't bear close scrutiny nowadays. Perhaps a reason for updating
the bug record to clarify what the issue is?

-- 
Brian.

[toc] | [prev] | [next] | [standalone]


#174441

From<tomas@tuxteam.de>
Date2016-11-09 21:40 +0100
Message-ID<sBHP4-3Kz-51@gated-at.bofh.it>
In reply to#174432
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Wed, Nov 09, 2016 at 05:38:01PM +0000, Brian wrote:
> On Tue 08 Nov 2016 at 17:54:41 -0500, Stefan Monnier wrote:
> 
> > >> > Futzing with partitions is the admin's job.
> > >> Could be, but it's not (g)parted's job to enforce these kinds of rules:

[...]

> > It costs extra code with at best no benefit.
> 
> A well-made couple of points. But a user being able to shoot himself
> in his own foot with other tools as a way of bolstering the argument
> doesn't bear close scrutiny nowadays.

But this should be taken care of by the device files having appropriate
permissions. An /dev/sda having -rw-rw-rw- is asking for trouble, I
think we all agree on this :-)

>                                       Perhaps a reason for updating
> the bug record to clarify what the issue is?

Hm. Layering error.

regards
- -- t
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlgjiIIACgkQBcgs9XrR2kbPQACeOgjjHNwDURiKeeI8id4iNn9i
eMsAn1rAkCgZXl3bL8MkzYwp0L27MeHA
=0fEr
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


Page 1 of 4  [1] 2 3 4  Next page →

Back to top | Article view | linux.debian.user


csiph-web