Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #174275 > unrolled thread
| Started by | Richard Owlett <rowlett@cloud85.net> |
|---|---|
| First post | 2016-11-07 13:20 +0100 |
| Last post | 2016-11-07 15:00 +0100 |
| Articles | 20 on this page of 77 — 18 participants |
Back to article view | Back to linux.debian.user
parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-07 13:20 +0100
Re: parted is ALMOST suitable Felipe Salvador <felipe.salvador@gmail.com> - 2016-11-07 13:30 +0100
Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-07 13:40 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 14:00 +0100
Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-07 14:20 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 15:00 +0100
Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-07 15:50 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 16:10 +0100
Re: parted is ALMOST suitable Lisi Reisz <lisi.reisz@gmail.com> - 2016-11-07 17:30 +0100
Re: parted is ALMOST suitable Felipe Salvador <felipe.salvador@gmail.com> - 2016-11-07 15:30 +0100
Re: parted is ALMOST suitable Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2016-11-07 16:20 +0100
Re: parted is ALMOST suitable Aldo Maggi <aldomaggi@katamail.com> - 2016-11-07 18:20 +0100
Re: parted is ALMOST suitable Felipe Salvador <felipe.salvador@gmail.com> - 2016-11-07 19:00 +0100
Re: parted is ALMOST suitable Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2016-11-08 19:10 +0100
Re: parted is ALMOST suitable Glenn English <ghe2001@gmail.com> - 2016-11-08 19:40 +0100
Re: parted is ALMOST suitable Stefan Monnier <monnier@iro.umontreal.ca> - 2016-11-08 21:10 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-08 21:50 +0100
Re: parted is ALMOST suitable Stefan Monnier <monnier@iro.umontreal.ca> - 2016-11-09 00:20 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-09 18:40 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-09 21:40 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-09 21:50 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-09 22:20 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-09 09:50 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-09 11:20 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-09 11:30 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-09 11:50 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-09 12:10 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-09 17:10 +0100
Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-09 15:20 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-09 20:50 +0100
Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-09 21:40 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-09 21:10 +0100
Re: parted is ALMOST suitable Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2016-11-10 01:20 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-10 10:10 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-09 19:30 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-09 21:40 +0100
Re: parted is ALMOST suitable Stefan Monnier <monnier@iro.umontreal.ca> - 2016-11-08 22:10 +0100
Re: parted is ALMOST suitable Lisi Reisz <lisi.reisz@gmail.com> - 2016-11-09 16:00 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-09 09:40 +0100
Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-07 16:30 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-07 17:10 +0100
Re: parted is ALMOST suitable Felipe Salvador <felipe.salvador@gmail.com> - 2016-11-07 18:50 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-07 20:20 +0100
Re: parted is ALMOST suitable Lisi Reisz <lisi.reisz@gmail.com> - 2016-11-08 00:50 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-08 01:40 +0100
Re: parted is ALMOST suitable Michael Lange <klappnase@freenet.de> - 2016-11-08 03:50 +0100
Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-08 12:00 +0100
Correction - Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-08 12:20 +0100
Re: Correction - Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-08 20:30 +0100
Re: parted is ALMOST suitable David Wright <deblis@lionunicorn.co.uk> - 2016-11-08 13:50 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-08 20:10 +0100
Re: parted is ALMOST suitable Frank <zuiderduin@gmx.com> - 2016-11-07 13:30 +0100
Re: parted is ALMOST suitable Darac Marjal <mailinglist@darac.org.uk> - 2016-11-07 13:40 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 13:50 +0100
Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-07 14:30 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 15:10 +0100
Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-07 15:20 +0100
Re: parted is ALMOST suitable Greg Wooledge <wooledg@eeg.ccf.org> - 2016-11-07 15:30 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 15:40 +0100
Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-07 17:00 +0100
Re: parted is ALMOST suitable Greg Wooledge <wooledg@eeg.ccf.org> - 2016-11-07 17:10 +0100
Re: parted is ALMOST suitable Nicolas George <george@nsup.org> - 2016-11-07 17:20 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 15:30 +0100
Re: parted is ALMOST suitable Greg Wooledge <wooledg@eeg.ccf.org> - 2016-11-07 15:40 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 16:10 +0100
Re: parted is ALMOST suitable Reco <recoverym4n@gmail.com> - 2016-11-07 18:00 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-08 10:20 +0100
Re: parted is ALMOST suitable Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-07 21:10 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-08 01:00 +0100
Re: parted is ALMOST suitable Richard Owlett <rowlett@cloud85.net> - 2016-11-08 12:20 +0100
Re: parted is ALMOST suitable Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-11 15:40 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-11 17:30 +0100
Re: parted is ALMOST suitable Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-11 18:10 +0100
Re: parted is ALMOST suitable Brian <ad44@cityscape.co.uk> - 2016-11-11 18:40 +0100
Re: parted is ALMOST suitable David Wright <deblis@lionunicorn.co.uk> - 2016-11-07 15:10 +0100
Re: parted is ALMOST suitable <tomas@tuxteam.de> - 2016-11-07 15:10 +0100
Re: parted is ALMOST suitable rhkramer@gmail.com - 2016-11-07 15:00 +0100
Page 2 of 4 — ← Prev page 1 [2] 3 4 Next page →
| From | Brian <ad44@cityscape.co.uk> |
|---|---|
| Date | 2016-11-09 21:50 +0100 |
| Message-ID | <sBHYJ-3NU-5@gated-at.bofh.it> |
| In reply to | #174441 |
On Wed 09 Nov 2016 at 21:35:14 +0100, tomas@tuxteam.de wrote:
> On Wed, Nov 09, 2016 at 05:38:01PM +0000, Brian wrote:
> > On Tue 08 Nov 2016 at 17:54:41 -0500, Stefan Monnier wrote:
> >
> > > >> > Futzing with partitions is the admin's job.
> > > >> Could be, but it's not (g)parted's job to enforce these kinds of rules:
>
> [...]
>
> > > It costs extra code with at best no benefit.
> >
> > A well-made couple of points. But a user being able to shoot himself
> > in his own foot with other tools as a way of bolstering the argument
> > doesn't bear close scrutiny nowadays.
>
> But this should be taken care of by the device files having appropriate
> permissions. An /dev/sda having -rw-rw-rw- is asking for trouble, I
> think we all agree on this :-)
I hope so.
> > Perhaps a reason for updating
> > the bug record to clarify what the issue is?
>
> Hm. Layering error.
Sorry. I'm unfamiliar with this term ("layering errors") and was just
trying to point out that the basis on which the report was submitted is
no longer valid and an additional report could make the point without
relying on outdated ideas.
--
Brian.
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2016-11-09 22:20 +0100 |
| Message-ID | <sBIrM-4d2-43@gated-at.bofh.it> |
| In reply to | #174442 |
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
On Wed, Nov 09, 2016 at 08:48:04PM +0000, Brian wrote:
> On Wed 09 Nov 2016 at 21:35:14 +0100, tomas@tuxteam.de wrote:
[...]
> > Hm. Layering error.
>
> Sorry. I'm unfamiliar with this term ("layering errors")
Sorry. Was meaning to say "layering violation": you design complex systems
in layers and try to take care of each aspect in the relevant layer. In
our case, the OS ("lower layer" of sorts) takes care of access control,
the application takes care of the user. This does away with subtle
irritations (in our case: "but the user *has* access permissions to
the block device, why...?) brought about by conflicting decisions
in different layers ("has explicitly to be UID 0" vs. "has to have
read or read/write access to the block device).
> and was just trying to point out that the basis on which the report was
> submitted is no longer valid and an additional report could make the
> point without relying on outdated ideas.
regards
- -- t
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
iEYEARECAAYFAlgjkWgACgkQBcgs9XrR2kazcQCdFWjUKAkxdBKKnj8ONpNlJi1h
aRkAnievFzGn6TeACL0LcEC3Rlioc6LR
=Z5Jw
-----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2016-11-09 09:50 +0100 |
| Message-ID | <sBwJX-4WR-1@gated-at.bofh.it> |
| In reply to | #174383 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Tue, Nov 08, 2016 at 08:39:51PM +0000, Brian wrote: > On Tue 08 Nov 2016 at 14:41:45 -0500, Stefan Monnier wrote: > > > >>>>>>> *HOWEVER* parted requires root privileges. That is not acceptable. > > >>>>>>> Suggestions? > > >>>>>>> TIA > > > Futzing with partitions is the admin's job. > > > > Could be, but it's not (g)parted's job to enforce these kinds of rules: > > that's what Unix permissions (and Linux's capabilities) are for. > > > > It's OK to add a warning and prompt the user to make sure he really > > means to do that, but there's no point *preventing* the user from > > shooting his own foot with this tool if he can do it with other > > tools anyway. > > Users here get no opportunity to shoot themselves or anyone else in the > foot. Access to raw disks is over my dead body. So I do not understand > your point. C'mon. Cut the drama. Dead bodies and that. As if "raw disk" were some kind of sacred stuff. In my case they are simple files on disk (disk images). Shall I have to become root every time I have to write a partition table to that? No. I just use fdisk. It's the job of file (device) permissions to ensure that. Or are you going to patch around bash's redirection operator too, to keep "users" from shooting themselves in the foot by issuing echo "mumble" > /dev/sda2 Not really. regards - -- tomás -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlgi4sEACgkQBcgs9XrR2kZqqACfdO/MbOeWhqyJHco4uOlI9l35 2FkAn2FsqBIT+AYMWlqrS52IydW5dgU1 =fTKB -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Brian <ad44@cityscape.co.uk> |
|---|---|
| Date | 2016-11-09 11:20 +0100 |
| Message-ID | <sBy94-5YV-9@gated-at.bofh.it> |
| In reply to | #174408 |
On Wed 09 Nov 2016 at 09:48:01 +0100, tomas@tuxteam.de wrote: > On Tue, Nov 08, 2016 at 08:39:51PM +0000, Brian wrote: > > On Tue 08 Nov 2016 at 14:41:45 -0500, Stefan Monnier wrote: > > > > > >>>>>>> *HOWEVER* parted requires root privileges. That is not acceptable. > > > >>>>>>> Suggestions? > > > >>>>>>> TIA > > > > Futzing with partitions is the admin's job. > > > > > > Could be, but it's not (g)parted's job to enforce these kinds of rules: > > > that's what Unix permissions (and Linux's capabilities) are for. > > > > > > It's OK to add a warning and prompt the user to make sure he really > > > means to do that, but there's no point *preventing* the user from > > > shooting his own foot with this tool if he can do it with other > > > tools anyway. > > > > Users here get no opportunity to shoot themselves or anyone else in the > > foot. Access to raw disks is over my dead body. So I do not understand > > your point. > > C'mon. Cut the drama. Dead bodies and that. It's a turn of phrase. Sometimes used with a touch of humour. > As if "raw disk" were some kind of sacred stuff. In my case they are > simple files on disk (disk images). Shall I have to become root every > time I have to write a partition table to that? No. I just use fdisk. > > It's the job of file (device) permissions to ensure that. Or are you > going to patch around bash's redirection operator too, to keep "users" > from shooting themselves in the foot by issuing > > echo "mumble" > /dev/sda2 > > Not really. That gives "-bash: /dev/sda2: Permission denied" for me with a fixed disk. It's the same for a removable disk. The system came like that. -- Brian.
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2016-11-09 11:30 +0100 |
| Message-ID | <sByiK-62n-29@gated-at.bofh.it> |
| In reply to | #174412 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Wed, Nov 09, 2016 at 10:12:13AM +0000, Brian wrote: > On Wed 09 Nov 2016 at 09:48:01 +0100, tomas@tuxteam.de wrote: > > > On Tue, Nov 08, 2016 at 08:39:51PM +0000, Brian wrote: > > > On Tue 08 Nov 2016 at 14:41:45 -0500, Stefan Monnier wrote: > > > > > > > >>>>>>> *HOWEVER* parted requires root privileges. That is not acceptable. > > > > >>>>>>> Suggestions? > > > > >>>>>>> TIA > > > > > Futzing with partitions is the admin's job. > > > > > > > > Could be, but it's not (g)parted's job to enforce these kinds of rules: > > > > that's what Unix permissions (and Linux's capabilities) are for. > > > > > > > > It's OK to add a warning and prompt the user to make sure he really > > > > means to do that, but there's no point *preventing* the user from > > > > shooting his own foot with this tool if he can do it with other > > > > tools anyway. > > > > > > Users here get no opportunity to shoot themselves or anyone else in the > > > foot. Access to raw disks is over my dead body. So I do not understand > > > your point. > > > > C'mon. Cut the drama. Dead bodies and that. > > It's a turn of phrase. Sometimes used with a touch of humour. > > > As if "raw disk" were some kind of sacred stuff. In my case they are > > simple files on disk (disk images). Shall I have to become root every > > time I have to write a partition table to that? No. I just use fdisk. > > > > It's the job of file (device) permissions to ensure that. Or are you > > going to patch around bash's redirection operator too, to keep "users" > > from shooting themselves in the foot by issuing > > > > echo "mumble" > /dev/sda2 > > > > Not really. > > That gives "-bash: /dev/sda2: Permission denied" for me with a fixed > disk. It's the same for a removable disk. The system came like that. Hopefully. But that's not because bash checks that (as parted is). It's because the permissions on the device file are set right! IOW, it's not the application's job (bash or parted), it's the OS's job (with the sysadmin's help) to check access permissions. BTW it's very easy to fool the application itself (and this migh be a perverse "solution" to Richard's problem). Just run gparted under fakeroot. It won't convey you read/write permissions you don't have, but it will fool gparted to think it's running as root: tomas@rasputin:~$ whoami tomas tomas@rasputin:~$ fakeroot whoami root tomas@rasputin:~$ So try running "fakeroot gparted" -- that might help. No need for elevated permissions :-) Fakeroot is in the like-named package. Regards - -- tomás -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlgi+f8ACgkQBcgs9XrR2kbsNgCggZ+IxtEt3EomY0RhA+erYApz f2UAn3Big3UUWWJ7ZWhAG184NCu7EPvm =YNug -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Brian <ad44@cityscape.co.uk> |
|---|---|
| Date | 2016-11-09 11:50 +0100 |
| Message-ID | <sByC6-69v-35@gated-at.bofh.it> |
| In reply to | #174413 |
On Wed 09 Nov 2016 at 11:27:11 +0100, tomas@tuxteam.de wrote: > On Wed, Nov 09, 2016 at 10:12:13AM +0000, Brian wrote: > > On Wed 09 Nov 2016 at 09:48:01 +0100, tomas@tuxteam.de wrote: > > > > > On Tue, Nov 08, 2016 at 08:39:51PM +0000, Brian wrote: > > > > On Tue 08 Nov 2016 at 14:41:45 -0500, Stefan Monnier wrote: > > > > > > > > > >>>>>>> *HOWEVER* parted requires root privileges. That is not acceptable. > > > > > >>>>>>> Suggestions? > > > > > >>>>>>> TIA > > > > > > Futzing with partitions is the admin's job. > > > > > > > > > > Could be, but it's not (g)parted's job to enforce these kinds of rules: > > > > > that's what Unix permissions (and Linux's capabilities) are for. > > > > > > > > > > It's OK to add a warning and prompt the user to make sure he really > > > > > means to do that, but there's no point *preventing* the user from > > > > > shooting his own foot with this tool if he can do it with other > > > > > tools anyway. > > > > > > > > Users here get no opportunity to shoot themselves or anyone else in the > > > > foot. Access to raw disks is over my dead body. So I do not understand > > > > your point. > > > > > > C'mon. Cut the drama. Dead bodies and that. > > > > It's a turn of phrase. Sometimes used with a touch of humour. > > > > > As if "raw disk" were some kind of sacred stuff. In my case they are > > > simple files on disk (disk images). Shall I have to become root every > > > time I have to write a partition table to that? No. I just use fdisk. > > > > > > It's the job of file (device) permissions to ensure that. Or are you > > > going to patch around bash's redirection operator too, to keep "users" > > > from shooting themselves in the foot by issuing > > > > > > echo "mumble" > /dev/sda2 > > > > > > Not really. > > > > That gives "-bash: /dev/sda2: Permission denied" for me with a fixed > > disk. It's the same for a removable disk. The system came like that. > > Hopefully. But that's not because bash checks that (as parted is). > It's because the permissions on the device file are set right! > > IOW, it's not the application's job (bash or parted), it's the OS's > job (with the sysadmin's help) to check access permissions. > > BTW it's very easy to fool the application itself (and this migh be > a perverse "solution" to Richard's problem). Just run gparted under > fakeroot. It won't convey you read/write permissions you don't have, > but it will fool gparted to think it's running as root: 'fakeroot lsblk -f' gives the same output on Jessie as 'lsblk -f". > tomas@rasputin:~$ whoami > tomas > tomas@rasputin:~$ fakeroot whoami > root > tomas@rasputin:~$ > > So try running "fakeroot gparted" -- that might help. No need for > elevated permissions :-) > > Fakeroot is in the like-named package. I hope cfdisk is an acceptable alternative to gparted, which is not on my system. 'fakeroot /sbin/cfdisk' gives "cfdisk: cannot open /dev/sda: Permission denied". -- Brian.
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2016-11-09 12:10 +0100 |
| Message-ID | <sByVr-6vX-9@gated-at.bofh.it> |
| In reply to | #174414 |
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
On Wed, Nov 09, 2016 at 10:45:52AM +0000, Brian wrote:
[...]
> I hope cfdisk is an acceptable alternative to gparted, which is not on
> my system. 'fakeroot /sbin/cfdisk' gives "cfdisk: cannot open /dev/sda:
> Permission denied".
We are talking past each other, I think.
The above result is to be expected. I'm perfectly OK with that.
You'd get that wih or without fakeroot (it doesn't convey powers
to you you don't have. That feat would imply a gaping security
hole in Linux. There are some, but the most obvious have been
covered -- hopefully! long ago.
The point Stefan (and me) are trying to make is that *the application
has no business in checking user permissions*, and parted is doing
exactly that ("am I root?"). It's something to be left to the OS
(try to open the device and catch an EACCESS error; translate that
for the user. That's what cfdisk above *is* doing, and I'm fine
with that!
*If* you happen to have read/write access to a device/file [1], then
cfdisk would let you just go ahead (right behaviour), while gparted
would stop you ("nyah nyah you aren' root" -- *wrong*).
[1] Stefan and me have given examples where that would make sense.
- -- t
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
iEYEARECAAYFAlgjAfYACgkQBcgs9XrR2kaPIwCeNf0Fb9cP5e4efUT3KoPrnK+V
87kAn0pivYKxpFwnQb0wa7i1rrpZdtsF
=FBNW
-----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Brian <ad44@cityscape.co.uk> |
|---|---|
| Date | 2016-11-09 17:10 +0100 |
| Message-ID | <sBDBM-18k-33@gated-at.bofh.it> |
| In reply to | #174415 |
On Wed 09 Nov 2016 at 12:01:10 +0100, tomas@tuxteam.de wrote:
> On Wed, Nov 09, 2016 at 10:45:52AM +0000, Brian wrote:
>
> [...]
>
> > I hope cfdisk is an acceptable alternative to gparted, which is not on
> > my system. 'fakeroot /sbin/cfdisk' gives "cfdisk: cannot open /dev/sda:
> > Permission denied".
>
> We are talking past each other, I think.
>
> The above result is to be expected. I'm perfectly OK with that.
> You'd get that wih or without fakeroot (it doesn't convey powers
> to you you don't have. That feat would imply a gaping security
> hole in Linux. There are some, but the most obvious have been
> covered -- hopefully! long ago.
>
> The point Stefan (and me) are trying to make is that *the application
> has no business in checking user permissions*, and parted is doing
> exactly that ("am I root?"). It's something to be left to the OS
> (try to open the device and catch an EACCESS error; translate that
> for the user. That's what cfdisk above *is* doing, and I'm fine
> with that!
>
> *If* you happen to have read/write access to a device/file [1], then
> cfdisk would let you just go ahead (right behaviour), while gparted
> would stop you ("nyah nyah you aren' root" -- *wrong*).
>
> [1] Stefan and me have given examples where that would make sense.
#439409 was filed in 2007 and in the context of repartiting an external
device. In 2011 the question was asked:
> Are you sure that you can simply "cat </dev/random >/dev/sdg" on
> your GNU/Linux distribution?
To which the answer was:
> Huh? Of course, I"m sure.
If the question had been asked after April 2014 and the release of udev
204-9 the answer would (or should) have been "no". The command can be
tried on Jessie. "Permission denied" is the result. This makes it
impossible for a user to cat a Debian ISO to a USB stick. That's also
the subject of a bug report. But nothing to do with gparted.
Granted that gparted should not be checking user permissions and there
is a case for having it stop doing so. However, ceasing to check if the
user is UID 0 doesn't get him anywhere (with an external device) unless
he or gparted can sneak past udev. A disk image as a file is a different
matter.
--
Brian.
[toc] | [prev] | [next] | [standalone]
| From | Richard Owlett <rowlett@cloud85.net> |
|---|---|
| Date | 2016-11-09 15:20 +0100 |
| Message-ID | <sBBTj-8ph-13@gated-at.bofh.it> |
| In reply to | #174413 |
On 11/9/2016 4:27 AM, tomas@tuxteam.de wrote: > [*SNIP*] > > BTW it's very easy to fool the application itself (and this might be > a perverse "solution" to Richard's problem). Just run gparted under > fakeroot. It won't convey you read/write permissions you don't have, > but it will fool gparted to think it's running as root: That may do the trick. Especially as what I wanted was descriptive information concerning the physical partition and wanted it displayed in a convenient format. I was explicitly avoiding operations requiring root privileges to avoid "shooting self in foot".
[toc] | [prev] | [next] | [standalone]
| From | Brian <ad44@cityscape.co.uk> |
|---|---|
| Date | 2016-11-09 20:50 +0100 |
| Message-ID | <sBH2F-3by-7@gated-at.bofh.it> |
| In reply to | #174421 |
On Wed 09 Nov 2016 at 08:10:37 -0600, Richard Owlett wrote: > On 11/9/2016 4:27 AM, tomas@tuxteam.de wrote: > >[*SNIP*] > > > >BTW it's very easy to fool the application itself (and this might be > >a perverse "solution" to Richard's problem). Just run gparted under > >fakeroot. It won't convey you read/write permissions you don't have, > >but it will fool gparted to think it's running as root: > > That may do the trick. Especially as what I wanted was descriptive > information concerning the physical partition and wanted it displayed in a > convenient format. I was explicitly avoiding operations requiring root > privileges to avoid "shooting self in foot". 'fakeroot gparted' will not do the trick for you. It is a dead end solution for what you want. -- Brian.
[toc] | [prev] | [next] | [standalone]
| From | Richard Owlett <rowlett@cloud85.net> |
|---|---|
| Date | 2016-11-09 21:40 +0100 |
| Message-ID | <sBHP3-3Kz-11@gated-at.bofh.it> |
| In reply to | #174437 |
On 11/9/2016 1:46 PM, Brian wrote: > On Wed 09 Nov 2016 at 08:10:37 -0600, Richard Owlett wrote: > >> On 11/9/2016 4:27 AM, tomas@tuxteam.de wrote: >>> [*SNIP*] >>> >>> BTW it's very easy to fool the application itself (and this might be >>> a perverse "solution" to Richard's problem). Just run gparted under >>> fakeroot. It won't convey you read/write permissions you don't have, >>> but it will fool gparted to think it's running as root: >> >> That may do the trick. Especially as what I wanted was descriptive >> information concerning the physical partition and wanted it displayed in a >> convenient format. I was explicitly avoiding operations requiring root >> privileges to avoid "shooting self in foot". > > 'fakeroot gparted' will not do the trick for you. It is a dead end > solution for what you want. > True. *BUT* testing it just now cleared up some moderately unrelated confusions ;/
[toc] | [prev] | [next] | [standalone]
| From | Brian <ad44@cityscape.co.uk> |
|---|---|
| Date | 2016-11-09 21:10 +0100 |
| Message-ID | <sBHm1-3y6-13@gated-at.bofh.it> |
| In reply to | #174413 |
On Wed 09 Nov 2016 at 11:27:11 +0100, tomas@tuxteam.de wrote: > On Wed, Nov 09, 2016 at 10:12:13AM +0000, Brian wrote: > > On Wed 09 Nov 2016 at 09:48:01 +0100, tomas@tuxteam.de wrote: > > > > > On Tue, Nov 08, 2016 at 08:39:51PM +0000, Brian wrote: > > > > On Tue 08 Nov 2016 at 14:41:45 -0500, Stefan Monnier wrote: > > > > > > > > > >>>>>>> *HOWEVER* parted requires root privileges. That is not acceptable. > > > > > >>>>>>> Suggestions? > > > > > >>>>>>> TIA > > > > > > Futzing with partitions is the admin's job. > > > > > > > > > > Could be, but it's not (g)parted's job to enforce these kinds of rules: > > > > > that's what Unix permissions (and Linux's capabilities) are for. > > > > > > > > > > It's OK to add a warning and prompt the user to make sure he really > > > > > means to do that, but there's no point *preventing* the user from > > > > > shooting his own foot with this tool if he can do it with other > > > > > tools anyway. > > > > > > > > Users here get no opportunity to shoot themselves or anyone else in the > > > > foot. Access to raw disks is over my dead body. So I do not understand > > > > your point. > > > > > > C'mon. Cut the drama. Dead bodies and that. > > > > It's a turn of phrase. Sometimes used with a touch of humour. > > > > > As if "raw disk" were some kind of sacred stuff. In my case they are > > > simple files on disk (disk images). Shall I have to become root every > > > time I have to write a partition table to that? No. I just use fdisk. > > > > > > It's the job of file (device) permissions to ensure that. Or are you > > > going to patch around bash's redirection operator too, to keep "users" > > > from shooting themselves in the foot by issuing > > > > > > echo "mumble" > /dev/sda2 > > > > > > Not really. > > > > That gives "-bash: /dev/sda2: Permission denied" for me with a fixed > > disk. It's the same for a removable disk. The system came like that. > > Hopefully. But that's not because bash checks that (as parted is). > It's because the permissions on the device file are set right! udev doesn't come into the picture for removable disks? It did on pre-Jessie. > IOW, it's not the application's job (bash or parted), it's the OS's > job (with the sysadmin's help) to check access permissions. > > BTW it's very easy to fool the application itself (and this migh be > a perverse "solution" to Richard's problem). Just run gparted under > fakeroot. It won't convey you read/write permissions you don't have, > but it will fool gparted to think it's running as root: Would you please give an example of when it is possible to fool the application and obtain somthing you otherwise wouldn't obtain as a user.
[toc] | [prev] | [next] | [standalone]
| From | Joe Pfeiffer <pfeiffer@cs.nmsu.edu> |
|---|---|
| Date | 2016-11-10 01:20 +0100 |
| Message-ID | <sBLfY-6pf-9@gated-at.bofh.it> |
| In reply to | #174438 |
Brian <ad44@cityscape.co.uk> writes: > On Wed 09 Nov 2016 at 11:27:11 +0100, tomas@tuxteam.de wrote: > >> On Wed, Nov 09, 2016 at 10:12:13AM +0000, Brian wrote: >> > >> > That gives "-bash: /dev/sda2: Permission denied" for me with a fixed >> > disk. It's the same for a removable disk. The system came like that. >> >> Hopefully. But that's not because bash checks that (as parted is). >> It's because the permissions on the device file are set right! > > udev doesn't come into the picture for removable disks? It did on > pre-Jessie. What is the relevance of udev here? Yes, udev sets the permissions, but the issue is whether they're right not who sets them.
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2016-11-10 10:10 +0100 |
| Message-ID | <sBTwR-3Ar-19@gated-at.bofh.it> |
| In reply to | #174449 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Wed, Nov 09, 2016 at 04:56:36PM -0700, Joe Pfeiffer wrote: > Brian <ad44@cityscape.co.uk> writes: [...] > >> Hopefully. But that's not because bash checks that (as parted is). > >> It's because the permissions on the device file are set right! > > > > udev doesn't come into the picture for removable disks? It did on > > pre-Jessie. > > What is the relevance of udev here? Yes, udev sets the permissions, but > the issue is whether they're right not who sets them. Exactly. That was my take, too. It's udev's job to react to events generated by the kernel and to set up things in user space (perms, symlinks, whatnot) according to whatever policy the distro and the sysadmin have set up. That's why the rules in /lib/udev (distribution) and /etc/udev (sysad, override the distro's) exist. The kernel is no place to have those rules, it's just the one enforcing them. Layering, again :-) - -- t -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlgkN10ACgkQBcgs9XrR2kbR+gCdEXRyxAM6+Wx/mcZ4FSxf4LMl T1sAn0yMoDTouLMigQyXHLvUFpP+RCbe =ijKP -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Brian <ad44@cityscape.co.uk> |
|---|---|
| Date | 2016-11-09 19:30 +0100 |
| Message-ID | <sBFNh-2u3-75@gated-at.bofh.it> |
| In reply to | #174408 |
On Wed 09 Nov 2016 at 09:48:01 +0100, tomas@tuxteam.de wrote: > On Tue, Nov 08, 2016 at 08:39:51PM +0000, Brian wrote: > > On Tue 08 Nov 2016 at 14:41:45 -0500, Stefan Monnier wrote: > > > > > >>>>>>> *HOWEVER* parted requires root privileges. That is not acceptable. > > > >>>>>>> Suggestions? > > > >>>>>>> TIA > > > > Futzing with partitions is the admin's job. > > > > > > Could be, but it's not (g)parted's job to enforce these kinds of rules: > > > that's what Unix permissions (and Linux's capabilities) are for. > > > > > > It's OK to add a warning and prompt the user to make sure he really > > > means to do that, but there's no point *preventing* the user from > > > shooting his own foot with this tool if he can do it with other > > > tools anyway. > > > > Users here get no opportunity to shoot themselves or anyone else in the > > foot. Access to raw disks is over my dead body. So I do not understand > > your point. > > C'mon. Cut the drama. Dead bodies and that. When I wrote that I had in mind the advice to put a user in the disk group to get 'lsblk -f' to give a wanted output. It will work. It also gives the user the opportunity to completely destroy the system with dd. > As if "raw disk" were some kind of sacred stuff. In my case they are > simple files on disk (disk images). Shall I have to become root every > time I have to write a partition table to that? No. I just use fdisk. > > It's the job of file (device) permissions to ensure that. Or are you > going to patch around bash's redirection operator too, to keep "users" > from shooting themselves in the foot by issuing > > echo "mumble" > /dev/sda2 > > Not really. Raw disk access to a device the user does not own *is* sacred. Access to a device the user does own is up to the user. Applications should not prevent that legitimate access taking place. Thank you for raising the disk image situation. -- Brian.
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2016-11-09 21:40 +0100 |
| Message-ID | <sBHP3-3Kz-21@gated-at.bofh.it> |
| In reply to | #174435 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Wed, Nov 09, 2016 at 06:29:32PM +0000, Brian wrote: [...] > Raw disk access to a device the user does not own *is* sacred. YES! And the OS takes care of that part! > Access to a device the user does own is up to the user. Again: wholeheartedly, yes. > Applications should not prevent that legitimate access taking > place. Thank you for raising the disk image situation. Seems we are in violent agreement :-) regards - -- tomás -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlgjh70ACgkQBcgs9XrR2kYDbACfQXr6xzcSxZDyrEHuyB3hh5mv kGAAnRFzgDDZkfTQowy+XN4hNhHNsiQF =O5aX -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Stefan Monnier <monnier@iro.umontreal.ca> |
|---|---|
| Date | 2016-11-08 22:10 +0100 |
| Message-ID | <sBlOy-6l2-31@gated-at.bofh.it> |
| In reply to | #174377 |
> Feel free to weight in ;-)
^^^
No idea where this `t` came from,
Stefan
[toc] | [prev] | [next] | [standalone]
| From | Lisi Reisz <lisi.reisz@gmail.com> |
|---|---|
| Date | 2016-11-09 16:00 +0100 |
| Message-ID | <sBCw2-el-31@gated-at.bofh.it> |
| In reply to | #174390 |
On Tuesday 08 November 2016 20:49:08 Stefan Monnier wrote: > > Feel free to weight in ;-) > > ^^^ > No idea where this `t` came from, > > > Stefan There's a gremlin in your keyboard too, is there? ;-) Lisi
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2016-11-09 09:40 +0100 |
| Message-ID | <sBwAi-4Tx-13@gated-at.bofh.it> |
| In reply to | #174377 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Tue, Nov 08, 2016 at 02:41:45PM -0500, Stefan Monnier wrote: > >>>>>>> *HOWEVER* parted requires root privileges. That is not acceptable. > >>>>>>> Suggestions? > >>>>>>> TIA > > Futzing with partitions is the admin's job. > > Could be, but it's not (g)parted's job to enforce these kinds of rules: > that's what Unix permissions (and Linux's capabilities) are for. > > It's OK to add a warning and prompt the user to make sure he really > means to do that, but there's no point *preventing* the user from > shooting his own foot with this tool if he can do it with other > tools anyway. > > > fdisk also want's root (or > > sudo). You want some user poking around in the disk(s)? > > BTW, I have a pending bug report around this very same issue: > https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=439409 > > Feel free to weight in ;-) Done. For me "this is the way gparted is designed" sounds so wrong on many levels that it took me a while to articulate myself :-) regards - -- t -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlgi4EUACgkQBcgs9XrR2kZQIgCcDwa+lVLv8fFUrJhMq8URV4Xq kzcAnRX6iNYN/fSKCe84iC/xWHkpJ5ZY =xRqQ -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Richard Owlett <rowlett@cloud85.net> |
|---|---|
| Date | 2016-11-07 16:30 +0100 |
| Message-ID | <sAU1Z-4T4-65@gated-at.bofh.it> |
| In reply to | #174301 |
On 11/7/2016 8:19 AM, Felipe Salvador wrote:
> On Mon, Nov 07, 2016 at 06:37:53AM -0600, Richard Owlett wrote:
>> On 11/7/2016 6:20 AM, Felipe Salvador wrote:
>>> On Mon, Nov 07, 2016 at 06:11:50AM -0600, Richard Owlett wrote:
>>>> *HOWEVER* parted requires root privileges. That is not acceptable.
>>>> Suggestions?
>>>> TIA
>>>
>>> lsblk -fr ?
>>>
>>
>> Debian is perverse ;{
>> man page suggested good things.
>> However when run as other than root, there is a column heading "FSTYPE".
>
>> It is blank for all partitions.
>> They are present when run as root.
>> Thanks for trying.
>
> I don't see this behaviour
>
> ~$ lsblk -fr
> NAME FSTYPE LABEL UUID MOUNTPOINT
> sda
> sda1 ext2 ... /boot
> sda2 ext4 ... /
> sda3 ext2 ... /tmp
> etc etc etc
>
> or
>
> file -s /dev/sda{1..5} | awk '{print $5}'
richard@full-jessier:~$ lsblk -fr
NAME FSTYPE LABEL UUID MOUNTPOINT
sda
sda1
sda2
sda5
sda6
sda7
sda8 [SWAP]
sda9 /
sda10
sda11
sda12
sdb
sdb1
sr0
richard@full-jessier:~$ su
Password:
root@full-jessier:/home/richard# lsblk -fr
NAME FSTYPE LABEL UUID MOUNTPOINT
sda
sda1 ntfs Main ...
sda2
sda5 ntfs Projects ...
sda6 ntfs F_drive ...
sda7 ntfs OldMachine ...
sda8 swap ...
sda9 ext4 full-jessie ...
sda10 ext2 jessie-dvds ...
sda11 ext2 myrepo ...
sda12 ext2 poolbak ...
I am using Debian 8.6.0 with MATE DE installed from purchased set
of DVD's.
For another project I had reason to verify the MD5SUMS of DVD1
and DVD2.
[toc] | [prev] | [next] | [standalone]
Page 2 of 4 — ← Prev page 1 [2] 3 4 Next page →
Back to top | Article view | linux.debian.user
csiph-web