Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #175882 > unrolled thread
| Started by | Xen <list@xenhideout.nl> |
|---|---|
| First post | 2016-12-22 18:40 +0100 |
| Last post | 2016-12-23 15:20 +0100 |
| Articles | 20 — 7 participants |
Back to article view | Back to linux.debian.user
chgrp with user Xen <list@xenhideout.nl> - 2016-12-22 18:40 +0100
Re: chgrp with user Dan Ritter <dsr@randomstring.org> - 2016-12-22 20:10 +0100
Re: chgrp with user Xen <list@xenhideout.nl> - 2016-12-23 01:20 +0100
Re: chgrp with user Greg Wooledge <wooledg@eeg.ccf.org> - 2016-12-23 14:10 +0100
Re: chgrp with user Xen <list@xenhideout.nl> - 2016-12-27 12:30 +0100
Re: chgrp with user deloptes <deloptes@gmail.com> - 2016-12-23 00:50 +0100
Re: chgrp with user Xen <list@xenhideout.nl> - 2016-12-23 01:20 +0100
Re: chgrp with user Nicolas George <george@nsup.org> - 2016-12-23 09:40 +0100
Re: chgrp with user Xen <list@xenhideout.nl> - 2016-12-27 13:30 +0100
Re: chgrp with user Gene Heskett <gheskett@shentel.net> - 2016-12-27 16:00 +0100
Re: chgrp with user Xen <list@xenhideout.nl> - 2016-12-27 16:40 +0100
Re: chgrp with user deloptes <deloptes@gmail.com> - 2016-12-27 21:10 +0100
Re: chgrp with user Greg Wooledge <wooledg@eeg.ccf.org> - 2016-12-27 22:50 +0100
Re: chgrp with user Xen <list@xenhideout.nl> - 2016-12-27 23:00 +0100
Re: chgrp with user Xen <list@xenhideout.nl> - 2016-12-27 23:20 +0100
Re: chgrp with user Xen <list@xenhideout.nl> - 2016-12-28 13:40 +0100
Re: chgrp with user deloptes <deloptes@gmail.com> - 2016-12-28 20:20 +0100
Re: chgrp with user Xen <list@xenhideout.nl> - 2016-12-29 09:10 +0100
Re: chgrp with user Xen <list@xenhideout.nl> - 2016-12-27 22:50 +0100
Re: chgrp with user Andy Smith <andy@strugglers.net> - 2016-12-23 15:20 +0100
| From | Xen <list@xenhideout.nl> |
|---|---|
| Date | 2016-12-22 18:40 +0100 |
| Subject | chgrp with user |
| Message-ID | <sRfvs-3YW-37@gated-at.bofh.it> |
I am trying to get a webserver to run under my regular user, or at least to have the website's files under control of my regular user, but the webserver runs as www-data. But it seems I cannot do chgrp as a user. Is there any way to achieve this? I mean I could add my user's group to the www-data user and I guess then I'd have access but I don't really see how changing a file's group could be a security risk. Maybe I should add myself to www-data instead?
[toc] | [next] | [standalone]
| From | Dan Ritter <dsr@randomstring.org> |
|---|---|
| Date | 2016-12-22 20:10 +0100 |
| Message-ID | <sRgUz-4Xr-57@gated-at.bofh.it> |
| In reply to | #175882 |
On Thu, Dec 22, 2016 at 06:24:59PM +0100, Xen wrote: > I am trying to get a webserver to run under my regular user, or at least to > have the website's files under control of my regular user, but the webserver > runs as www-data. > > But it seems I cannot do chgrp as a user. > > Is there any way to achieve this? > > I mean I could add my user's group to the www-data user and I guess then I'd > have access but I don't really see how changing a file's group could be a > security risk. Maybe I should add myself to www-data instead? Yes, add your regular user to the www-data group, then log out and come back in. The web-server is a door in to your system. Limiting what it can see is preferable. -dsr-
[toc] | [prev] | [next] | [standalone]
| From | Xen <list@xenhideout.nl> |
|---|---|
| Date | 2016-12-23 01:20 +0100 |
| Message-ID | <sRlKy-82e-9@gated-at.bofh.it> |
| In reply to | #175884 |
Dan Ritter schreef op 22-12-2016 20:04: > On Thu, Dec 22, 2016 at 06:24:59PM +0100, Xen wrote: >> I am trying to get a webserver to run under my regular user, or at >> least to >> have the website's files under control of my regular user, but the >> webserver >> runs as www-data. >> >> But it seems I cannot do chgrp as a user. >> >> Is there any way to achieve this? >> >> I mean I could add my user's group to the www-data user and I guess >> then I'd >> have access but I don't really see how changing a file's group could >> be a >> security risk. Maybe I should add myself to www-data instead? > > Yes, add your regular user to the www-data group, then log out > and come back in. > > The web-server is a door in to your system. Limiting what it can > see is preferable. Aye, thanks. It just took me a while to figure out I could add myself to that group instead, so I was concerned I would have to become root all the time in order to do that sort of stuff. Life becomes a whole lot easier if you can do stuff with your regular user, which is why I am putting stuff in my user home directory in the first place, instead of some central location.
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <wooledg@eeg.ccf.org> |
|---|---|
| Date | 2016-12-23 14:10 +0100 |
| Message-ID | <sRxLH-7js-23@gated-at.bofh.it> |
| In reply to | #175886 |
On Fri, Dec 23, 2016 at 01:17:23AM +0100, Xen wrote: > Life becomes a whole lot easier if you can do stuff with your regular > user, which is why I am putting stuff in my user home directory in the > first place, instead of some central location. Making your life easier should NOT be your #1 priority when talking about a public web server, especially if PHP is involved in any way. Security should be at least somewhere near the top of the list. You want to minimize the damage that an attacker can do when (not if) your Apache+PHP stack gets compromised by yet another PHP vulnerability.
[toc] | [prev] | [next] | [standalone]
| From | Xen <list@xenhideout.nl> |
|---|---|
| Date | 2016-12-27 12:30 +0100 |
| Message-ID | <sSY78-1nC-19@gated-at.bofh.it> |
| In reply to | #175890 |
Greg Wooledge schreef op 23-12-2016 14:07: > On Fri, Dec 23, 2016 at 01:17:23AM +0100, Xen wrote: >> Life becomes a whole lot easier if you can do stuff with your regular >> user, which is why I am putting stuff in my user home directory in the >> first place, instead of some central location. > > Making your life easier should NOT be your #1 priority when talking > about a public web server, especially if PHP is involved in any way. > Security should be at least somewhere near the top of the list. > > You want to minimize the damage that an attacker can do when (not if) > your Apache+PHP stack gets compromised by yet another PHP > vulnerability. Trust me, any sane webhost that has websites running under user accounts would put those websites in user directories. There is no point in putting it in any other location at all because the safety of the webserver (instance) is a separate concern from the location and access rights of some user files. Typically for a webserver (and I am running this in an LXC instance with pretty much nothing else) the only files that could ever be at risk are the user's files. Especially after I get this container to run unpriviledged, I don't think that there is a reason to think that web-files owned by www-data are less at risk or less risky than web-files owned by your average user account. So yes, I think that have an enclosed space in which you can feel at home, not have to worry about anything, and no files exist in that space other than those of your unpriviledged user, IS the number one priority. And well, as Nicholas says. Most web-applications will also warn you about write access. They tell you to get them write access for a single file, and then to remove it when they are done. Yes that means not running the server as your regular user I guess, but that is the model of this system: the webserver doesn't run as your regular user because normally it would serve many such users. I don't know how you would solve that if you really ran a web-host but adding users to www-data so they can chgrp and chmod would solve that problem just like now right. Thank you, the other user, for the hint on forwarding port 80 to something else. But if I have my unpriviledged container that is also almost the same thing right. So I guess actually running the webserver as my regular user would be a bad idea (it is kinda hard in a certain sense to remove write access from your own files to your own user) but this comes close, so yeah, I guess the problem is already solved. So thank you for your answers, please.
[toc] | [prev] | [next] | [standalone]
| From | deloptes <deloptes@gmail.com> |
|---|---|
| Date | 2016-12-23 00:50 +0100 |
| Message-ID | <sRlhv-7zC-3@gated-at.bofh.it> |
| In reply to | #175882 |
Xen wrote: > Is there any way to achieve this? there is no need to run a web server as your user. perhaps you want to chown your-user.www-data /path or something like php5 -S <addr>:<port> Run with built-in web server. Give up the bad ideas, seriously! trhstfd
[toc] | [prev] | [next] | [standalone]
| From | Xen <list@xenhideout.nl> |
|---|---|
| Date | 2016-12-23 01:20 +0100 |
| Message-ID | <sRlKy-82e-11@gated-at.bofh.it> |
| In reply to | #175885 |
deloptes schreef op 23-12-2016 0:40: > perhaps you want to chown your-user.www-data /path > > or something like > > php5 -S <addr>:<port> Run with built-in web server. > > Give up the bad ideas, seriously! I think my point was more that I didn't know how to chgrp, but I found I needed to add myself to www-data first before I could chgrp to it. Which seems reasonable, I just don't get why it would be required :p. In general you can only use it to give permissions to something, not take it away. Maybe if you got really inventive you could trigger some process running under a certain user to do something with a file owned by you if it otherwise wouldn't have been able to..., but... ;-). You could also achieve that by giving everything o+rwx permissions... But ehm.. I guess it is just a personal bafflement ;-). In that I fail to see how giving permissions to something you already own to another would be a security implication. But maybe it is more an identity issue.
[toc] | [prev] | [next] | [standalone]
| From | Nicolas George <george@nsup.org> |
|---|---|
| Date | 2016-12-23 09:40 +0100 |
| Message-ID | <sRtyp-4vW-9@gated-at.bofh.it> |
| In reply to | #175887 |
[Multipart message — attachments visible in raw view] — view raw
Le tridi 3 nivôse, an CCXXV, Xen a écrit : > I think my point was more that I didn't know how to chgrp, but I found I > needed to add myself to www-data first before I could chgrp to it. Just a basic sanity check: If your web server is running as www-data, then it is better if the files do NOT belong to that user and/or group. For the group, it does not matter much, but for the user it is very important. Most importantly, the web server must not have write access to the files it serves. Some web applications need write access, of course, but they should get write access ONLY to the files and directories they need, NEVER the program files. And the web server must be configured to never execute anything from these directories, if they are served. For example, if your application is making photo albums, it needs write access to the directory where it stores the photos, but only that, and all ScriptAlias or equivalent must be disabled for that directory. Regards, -- Nicolas George
[toc] | [prev] | [next] | [standalone]
| From | Xen <list@xenhideout.nl> |
|---|---|
| Date | 2016-12-27 13:30 +0100 |
| Message-ID | <sSZ3c-1Zj-5@gated-at.bofh.it> |
| In reply to | #175889 |
Nicolas George schreef op 23-12-2016 9:32: > Le tridi 3 nivôse, an CCXXV, Xen a écrit : >> I think my point was more that I didn't know how to chgrp, but I found >> I >> needed to add myself to www-data first before I could chgrp to it. > > Just a basic sanity check: > > If your web server is running as www-data, then it is better if the > files do NOT belong to that user and/or group. For the group, it does > not matter much, but for the user it is very important. That's the problem I've had with dokuwiki (and other such programs). Since they create lost of files those programs typically create those files as the user the webserver is running as, which would typically be www-data. Sometimes you want to be able those files directly as a user outside of the application (which is typically the case for me) so how do you give access to those files as your user? That's rather hard? But any program running under any (limited) user does not have rights to chown to another user. What remains is either something filessytem specific (inheritance through setfacl, if that works) or some service that keeps chowning files in the background. Which may even be the nicest solution in the end because you are in full control of something like that and do not depend on the proper functioning of the server. Call it a quick solution that works. So what you then would get -- but I know no other solution as of now -- is that you service/daemon is just going to chown stuff to your regular user with www-data as the group, and if the webserver needs write access to the files it just created (which it probably does) you give g+w to it. Those are not program files, just data, but not all server (applications) exclusively use a database. The same applies to OwnCloud and I'm the kind of person that likes to do stuff outside of control of the application because the application may be severely limited in moving data around or importing data. So the solution each time seems to be to ensure that the files are owned by your regular user and given g+w to the group which is then www-data, in this case. It can also be the reverse: don't touch the ownership but give all files g+w to your own user who is part of www-data. I guess it depends on how "personal" you want to make those files but you need to do this anyway. For these packages the program files are just sitting in /usr/share, that is not an issue. But /var/lib/xxx is not a very "user servicable" directory. That is not a place you easily go to (as a shell user, and not at all as a GUI user either) so in order to keep your data manageable to your own person and separate from the rest of the system you have to give it a better location anyway, whether it be /data, or /srv, or even some home directory of some kind (not recommended in this case I guess). So supposing you end up with /srv/owncloud you really want all those files to become owned by your regular user and the group that it already had + g+w. Or just do g+w while you are in www-data. I haven't checked those applications but in general since they cannot chown anyway I assume that this works: chmod g+s will retain group ownership from the containing directory setfacl -d -m g::rwx will make everything group writable. Also on the containing directory. I don't consider these acl permissions to be so great, but that's just me you know. They stand so apart from the regular permissions we have, almost superseding it completely. The only alternative is a service that will retain these permissions after the fact (triggered by some event or some watch daemon) but I think changing these web applications is really "onbegonnen werk" as we say in Dutch (work that seems so endless that there is no use even beginning it). I think it is also safer to retain ownership and control of that yourself (so you can pick and choose). Besides this is in this case only about group permissions and the webserver already has write access in this case. It's just about your user also being able to manipulate it. And only applies to filesystem data and files created by the web application on disk. It would be nice to have a better sense of "who owns what" in any case. I feel the gap between the administrator and the regular user is too big, but that's just me. I think it would be helpful if it was easier to place user data (such as wiki data) more under control of the regular user. Something like.... ordinarily, something like Dokuwiki is a very personal thing, not something big or site-wide. But we require usually (as per the package at least) site-wide servers to run it. Not a very good combination in my idea. Maybe running it AS your personal user would be a better idea but that is more work and is perhaps, as said here, also not ideal. Personally I am probably going to implement one of the above. I think SystemD makes it very easy to watch a directory right? But maybe I will just do it on my own :p. Having services for the automatic correction of user and file permissions wouldn't be so bad. Anyway, those are just my thoughts alright.
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2016-12-27 16:00 +0100 |
| Message-ID | <sT1ol-3k0-3@gated-at.bofh.it> |
| In reply to | #175969 |
On Tuesday 27 December 2016 07:28:58 Xen wrote: > Nicolas George schreef op 23-12-2016 9:32: > > Le tridi 3 nivôse, an CCXXV, Xen a écrit : > >> I think my point was more that I didn't know how to chgrp, but I > >> found I > >> needed to add myself to www-data first before I could chgrp to it. > > > > Just a basic sanity check: > > > > If your web server is running as www-data, then it is better if the > > files do NOT belong to that user and/or group. For the group, it > > does not matter much, but for the user it is very important. > > That's the problem I've had with dokuwiki (and other such programs). > > Since they create lost of files those programs typically create those > files as the user the webserver is running as, which would typically > be www-data. Sometimes you want to be able those files directly as a > user outside of the application (which is typically the case for me) > so how do you give access to those files as your user? > > That's rather hard? Uhh, no. Add yourself to the www-data group. > > But any program running under any (limited) user does not have rights > to chown to another user. What remains is either something filessytem > specific (inheritance through setfacl, if that works) or some service > that keeps chowning files in the background. > > Which may even be the nicest solution in the end because you are in > full control of something like that and do not depend on the proper > functioning of the server. Call it a quick solution that works. > > So what you then would get -- but I know no other solution as of now > -- is that you service/daemon is just going to chown stuff to your > regular user with www-data as the group, and if the webserver needs > write access to the files it just created (which it probably does) you > give g+w to it. > > Those are not program files, just data, but not all server > (applications) exclusively use a database. > > The same applies to OwnCloud and I'm the kind of person that likes to > do stuff outside of control of the application because the application > may be severely limited in moving data around or importing data. > > So the solution each time seems to be to ensure that the files are > owned by your regular user and given g+w to the group which is then > www-data, in this case. It can also be the reverse: don't touch the > ownership but give all files g+w to your own user who is part of > www-data. > > I guess it depends on how "personal" you want to make those files but > you need to do this anyway. For these packages the program files are > just sitting in /usr/share, that is not an issue. > > But /var/lib/xxx is not a very "user servicable" directory. That is > not a place you easily go to (as a shell user, and not at all as a GUI > user either) so in order to keep your data manageable to your own > person and separate from the rest of the system you have to give it a > better location anyway, whether it be /data, or /srv, or even some > home directory of some kind (not recommended in this case I guess). So > supposing you end up with /srv/owncloud you really want all those > files to become owned by your regular user and the group that it > already had + g+w. Or just do g+w while you are in www-data. > > I haven't checked those applications but in general since they cannot > chown anyway I assume that this works: > > chmod g+s will retain group ownership from the containing directory > setfacl -d -m g::rwx will make everything group writable. > > Also on the containing directory. I don't consider these acl > permissions to be so great, but that's just me you know. They stand so > apart from the regular permissions we have, almost superseding it > completely. > > The only alternative is a service that will retain these permissions > after the fact (triggered by some event or some watch daemon) but I > think changing these web applications is really "onbegonnen werk" as > we say in Dutch (work that seems so endless that there is no use even > beginning it). I think it is also safer to retain ownership and > control of that yourself (so you can pick and choose). > > Besides this is in this case only about group permissions and the > webserver already has write access in this case. It's just about your > user also being able to manipulate it. > > And only applies to filesystem data and files created by the web > application on disk. > > It would be nice to have a better sense of "who owns what" in any > case. I feel the gap between the administrator and the regular user is > too big, but that's just me. I think it would be helpful if it was > easier to place user data (such as wiki data) more under control of > the regular user. Something like.... ordinarily, something like > Dokuwiki is a very personal thing, not something big or site-wide. > > But we require usually (as per the package at least) site-wide servers > to run it. Not a very good combination in my idea. Maybe running it AS > your personal user would be a better idea but that is more work and is > perhaps, as said here, also not ideal. Personally I am probably going > to implement one of the above. I think SystemD makes it very easy to > watch a directory right? > > But maybe I will just do it on my own :p. Having services for the > automatic correction of user and file permissions wouldn't be so bad. > > Anyway, those are just my thoughts alright. Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | Xen <list@xenhideout.nl> |
|---|---|
| Date | 2016-12-27 16:40 +0100 |
| Message-ID | <sT213-3O3-7@gated-at.bofh.it> |
| In reply to | #175979 |
Gene Heskett schreef op 27-12-2016 15:51: >> Since they create lost of files those programs typically create those >> files as the user the webserver is running as, which would typically >> be www-data. Sometimes you want to be able those files directly as a >> user outside of the application (which is typically the case for me) >> so how do you give access to those files as your user? >> >> That's rather hard? > > Uhh, no. Add yourself to the www-data group. Wrong. These programs typically create stuff without g+w so your user has no write access to it. So you need at least one of the solutions mentioned. Thanks.
[toc] | [prev] | [next] | [standalone]
| From | deloptes <deloptes@gmail.com> |
|---|---|
| Date | 2016-12-27 21:10 +0100 |
| Message-ID | <sT6em-6EK-23@gated-at.bofh.it> |
| In reply to | #175980 |
Xen wrote: > Wrong. These programs typically create stuff without g+w so your user > has no write access to it. > > So you need at least one of the solutions mentioned. You keep insisting doing wrong things. If you use mediawiki, you do not need write access as a user. Leave this to the system and use the interface and/or tools provided. > The same applies to OwnCloud and I'm the kind of person that likes to do > stuff outside of control of the application because the application may > be severely limited in moving data around or importing data. You are an i**ot I would immediately fire. Start reading the interfaces and using the programs as designed. If you want to do things your own way I do not want to know about it. regards
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <wooledg@eeg.ccf.org> |
|---|---|
| Date | 2016-12-27 22:50 +0100 |
| Message-ID | <sT7N7-7x6-3@gated-at.bofh.it> |
| In reply to | #175984 |
On Tue, Dec 27, 2016 at 10:43:19PM +0100, Xen wrote: > Wrong does not exist. Irony.
[toc] | [prev] | [next] | [standalone]
| From | Xen <list@xenhideout.nl> |
|---|---|
| Date | 2016-12-27 23:00 +0100 |
| Message-ID | <sT7WO-7AB-21@gated-at.bofh.it> |
| In reply to | #175987 |
Greg Wooledge schreef op 27-12-2016 22:44: > On Tue, Dec 27, 2016 at 10:43:19PM +0100, Xen wrote: >> Wrong does not exist. > > Irony. It is perfectly acceptable to do things a different way. It is also perfectly clear that many tools such as Dokuwiki do not provide the tools that perhaps Mediawiki provides, or the tools that have been written for it. It is also very clear that OwnCloud provides very limited data import utilities. Do you wait around until it has been written, or do you do your own thing? I'm the idiot that does his own thing yes and it works very well, if I may add. Owncloud had no problem with importing "new files" and neither does Dokuwiki. So why should I listen to others who think they have a better idea, but won't solve my problems? All those very smart people only have opinions but don't solve anything for you. You are the only one that will care about you. You need to solve your own problems and not listen to others who are in different life situations or are running different companies or have different life goals or needs that they attribute to you because they cannot live or see outside the bubble of their own little world, and cannot understand why you are doing it or what you need. A solution to one person does not apply to another if that other person is living in a different world, has different needs, or different requirments. I needed to move gigabytes of Data into Owncloud and it did not provide tools for it. So I moved it there myself. What's the problem with that? If I may add, what's the problem with that? Can you answer it? It updated its database just fine and all was fine? What was the problem with that? Seriously, what is the problem with that? You're making me really angry now. Always this messing about with other people's choices but you are not providing solutions for me, only complaints. Talking about the other person that I won't even mention anymore. Complaining about people doing the wrong thing but you are not providing solutions for me or doing any work. So I will do it my way thank you very much. It is just empty talk, what you do. What I do works and provides a solution. What you do is complain and you do not provide anything, save for yourself, but I am not helped with that, nor is anyone else if you complain like that. Now enough.
[toc] | [prev] | [next] | [standalone]
| From | Xen <list@xenhideout.nl> |
|---|---|
| Date | 2016-12-27 23:20 +0100 |
| Message-ID | <sT8g9-7WJ-7@gated-at.bofh.it> |
| In reply to | #175989 |
Xen schreef op 27-12-2016 22:54: > What I do works and provides a solution. What you do is complain and > you do not provide anything, save for yourself, but I am not helped > with that, nor is anyone else if you complain like that. > > Now enough. Lost my temper there, Winston would say. Yes, I play video games too. What's the problem with that? You have a problem with that too? :).
[toc] | [prev] | [next] | [standalone]
| From | Xen <list@xenhideout.nl> |
|---|---|
| Date | 2016-12-28 13:40 +0100 |
| Message-ID | <sTlGp-8ds-3@gated-at.bofh.it> |
| In reply to | #175991 |
Xen schreef op 27-12-2016 23:13: > Lost my temper there, Winston would say. Yes, I play video games too. > What's the problem with that? You have a problem with that too? :). Also still want to add, If I may. That even Mediawiki probably doesn't provide all the tools you'd need to completely circumvent the filesystem. For example, no one in his right mind would probably use Media-wiki specific tools to back up the database. Also Media-wiki probably stores all content in the database, so it is not even equivalent here. Those people who say you are doing the wrong thing would also resort to the wrong thing if shit hit the fan. And that's all I can say about it. If they really ended up in a problem situation they would *also* do that "wrong thing" to solve the problem and get or keep their company running, for instance. When in a practical situation all those petty concerns about what is right and what is wrong do not matter anymore. What matters then is results and nothing else. That, I wanted to say here. You will use the appropriate tools to solve the problem at hand NOW, yes, you too will do that. And if the "right tools" won't do that, you will use the "wrong tools" because they then actually yield results whereas the "right tools" don't for example because they do not even exist. I really wonder if anyone here backs up a Media-wiki database for example by using some Media-wiki "export" function or if in fact you back up the (MySQL) database yourself. I really think I can predict all of us are going to use filesystem tools indeed. And not Media-wiki tools. Drupal for instance has "drush sql-dump" to export the (MySQL) database but are you seriously going to use that every time you export or back-up the database? Why should you? I don't like snapshots but they are certainly the easiest way to back-up any filesystem without interruption. And even if you didn't mysqldump might still be the more appropriate tool (http://dev.mysql.com/doc/refman/5.7/en/mysqldump.html) and will cover other databases as well (tables) (and besides) drush sql-dump uses mysqldump too. Everyone in the right position would use the "wrong" tool because it would work whereas the "right" tool would not or would not even be available. When it comes down to it, practical matters supersede theoretical concerns, but you can't see this from the comfort of your seat into another person's computer or site or server. So please, some leniency with the "inadequacies" of other people because they might be doing the right thing whereas you can't see that they do because you do not have the information for it. Not all situations are identical and everyone chooses the appropriate path for him or herself. I hope that is enough now. Regards.
[toc] | [prev] | [next] | [standalone]
| From | deloptes <deloptes@gmail.com> |
|---|---|
| Date | 2016-12-28 20:20 +0100 |
| Message-ID | <sTrVw-49v-5@gated-at.bofh.it> |
| In reply to | #176003 |
Xen wrote: > Xen schreef op 27-12-2016 23:13: > >> Lost my temper there, Winston would say. Yes, I play video games too. >> What's the problem with that? You have a problem with that too? :). > > Also still want to add, If I may. > No need to be so sensitive to what I say. We also do "wrong" things, but do not discuss them :) It was repeated couple of times what your options are regarding your problem. I don't think much more can be said and done. > That even Mediawiki probably doesn't provide all the tools you'd need to > completely circumvent the filesystem. > > For example, no one in his right mind would probably use Media-wiki > specific tools to back up the database. Also Media-wiki probably stores > all content in the database, so it is not even equivalent here. > The scope defines the right and wrong. The scope in your case is simply wrong - accept it! > Those people who say you are doing the wrong thing would also resort to > the wrong thing if shit hit the fan. And that's all I can say about it. > If they really ended up in a problem situation they would *also* do that > "wrong thing" to solve the problem and get or keep their company > running, for instance. After 15+y of experience with big size companies I could say a lot of people get payed so that such thing never happens and even if happens a backup plan has been signed off and tested already ... so probably not true. If true ... some one was an i**ot and will get fired > > When in a practical situation all those petty concerns about what is > right and what is wrong do not matter anymore. What matters then is > results and nothing else. That, I wanted to say here. > There is always right and wrong - the scope defines it and we are always bound to a specific scope/context. > You will use the appropriate tools to solve the problem at hand NOW, > yes, you too will do that. And if the "right tools" won't do that, you > will use the "wrong tools" because they then actually yield results > whereas the "right tools" don't for example because they do not even > exist. > Many people told you it is inappropriate to run web server with your credentials (write access to your data etc) I prefer using php build in server, where possible. Where not possible I work on a test system ( like virtual server configured to run on localhost only etc) There are so many options. My insult was because you refuse to use your imagination and insist to do it the wrong way. Talking about complaining, I think you complain the most. > I really wonder if anyone here backs up a Media-wiki database for > example by using some Media-wiki "export" function or if in fact you > back up the (MySQL) database yourself. I really think I can predict all > of us are going to use filesystem tools indeed. And not Media-wiki > tools. > Only a db dump will not be sufficient > Drupal for instance has "drush sql-dump" to export the (MySQL) database > but are you seriously going to use that every time you export or back-up > the database? Why should you? > yes. why? because it is intended to the work that I need to be done. > I don't like snapshots but they are certainly the easiest way to back-up > any filesystem without interruption. And even if you didn't mysqldump > might still be the more appropriate tool > (http://dev.mysql.com/doc/refman/5.7/en/mysqldump.html) and will cover > other databases as well (tables) (and besides) drush sql-dump uses > mysqldump too. > no need to comment this, I hope you understand why > Everyone in the right position would use the "wrong" tool because it > would work whereas the "right" tool would not or would not even be > available. When it comes down to it, practical matters supersede > theoretical concerns, but you can't see this from the comfort of your > seat into another person's computer or site or server. > I don't remember when it was the last time I had a situation when I did or used the wrong tool. You have to spent a bit more time on planning and you don't have situations, where you have to do something wrong to solve a problem. Usually I would say 3/4 is planning and 1/4 is working - it's because being a human means you have a brain and if you use it more, you use your hands less. A pure principle of economy in nature :) > So please, some leniency with the "inadequacies" of other people because > they might be doing the right thing whereas you can't see that they do > because you do not have the information for it. Not all situations are > identical and everyone chooses the appropriate path for him or herself. > > I hope that is enough now. > No need to advocate for yourself. I simply don't understand the frustration, but hopefully you will forgive if I have insulted you in some way. I think your question has been answered and you can find your way. You have received many ideas in how your problem may be solved easily. Please also keep in mind this is a public list - a lot of people read it and we write things that could benefit the rest as well. regards
[toc] | [prev] | [next] | [standalone]
| From | Xen <list@xenhideout.nl> |
|---|---|
| Date | 2016-12-29 09:10 +0100 |
| Message-ID | <sTDWF-42Z-3@gated-at.bofh.it> |
| In reply to | #176047 |
deloptes schreef op 28-12-2016 20:17: > Xen wrote: > >> Xen schreef op 27-12-2016 23:13: >> >>> Lost my temper there, Winston would say. Yes, I play video games too. >>> What's the problem with that? You have a problem with that too? :). >> >> Also still want to add, If I may. >> > > No need to be so sensitive to what I say. We also do "wrong" things, > but do > not discuss them :) > It was repeated couple of times what your options are regarding your > problem. I don't think much more can be said and done. Well, thank you I guess :). >> For example, no one in his right mind would probably use Media-wiki >> specific tools to back up the database. Also Media-wiki probably >> stores >> all content in the database, so it is not even equivalent here. >> > > The scope defines the right and wrong. The scope in your case is simply > wrong - accept it! I don't understand what you mean by scope here. If the scope defines right and wrong (I take it you mean the choices you subsequently make here) then the scope itself cannot be right or wrong, as it just provides the context or framework (frame) in which those choices become "right or wrong" as you put it. So last time I checked my case there was no scope in it, but I'm not sure what you mean :p. However I will say again that if you want to keep the discussion to technical issues and not moral issues, better words would perhaps be correct and incorrect. >> Those people who say you are doing the wrong thing would also resort >> to >> the wrong thing if shit hit the fan. And that's all I can say about >> it. >> If they really ended up in a problem situation they would *also* do >> that >> "wrong thing" to solve the problem and get or keep their company >> running, for instance. > > After 15+y of experience with big size companies I could say a lot of > people > get payed so that such thing never happens and even if happens a backup > plan has been signed off and tested already ... so probably not true. > If > true ... some one was an i**ot and will get fired That's rather being in denial about real life I think. "Real people never get into trouble." Yeah, sure. Fantasy world this right. Everything is perfect as long as you are not stupid. I think getting in trouble is more the norm than the other thing you mention ;-). Having contingency plans for everything and everything is well thought-out. And besides, I am not a big-sized company. Also, such companies would be molochs that would never be capable of responding flexibly to new circumstances. No James Bond there ;-). >> When in a practical situation all those petty concerns about what is >> right and what is wrong do not matter anymore. What matters then is >> results and nothing else. That, I wanted to say here. >> > > There is always right and wrong - the scope defines it and we are > always > bound to a specific scope/context. So now I understand what you mean by scope, and I agree with that notion. But I also think you misconstrue the scope of another person. I would rather say the conditions someone has to deal with (the current status of the (delimited) system (in its entirety, in that sense) a person has to deal with) define the conditions. Within those conditions a request or goal arises. Now it becomes an engineering problem: how to reach the goal or meet the requirements given the current status, or current conditions. Regardless, conditions such as "do you have 20 hours to read documentation first, or would that mean you succumb to apathy in the meantime" also form part of that "scope" you mean. It's not just pure technical, the human comes also into play. Now you can say "That human is an idiot if that would happen" but this is precisely what you can't see behind your computer screen. "That human should first have received 30+ hours of formal education into the problem he/she tries to solve" is also a statement that belies the current "scope" because it is a wish for something else to deal with. This wish is not reality, the reality may be that this person (or anyone in a larger system) would not have received this formal education (for instance). Any judgement or wish or berating the /past/ as that in the /past/ people have been idiots and this resulted in this situation, does nothing to change the scope and situation NOW. > Many people told you it is inappropriate to run web server with your > credentials (write access to your data etc) That wast just my first suggestion that I immediately followed up by saying that giving the web-server write access or something like that would be a good alternative. The thing that prompted my question was simply that Drupal needed write access to some file. Since I was not yet part of www-data I could only do so by assuming root, which I do not like to do. So I was looking for the (for me at that point not yet entirely obvious) solution to add myself to www-data or to add www-data to "me". I ended my first message with the suggestion that maybe the former (myself to www-data) was the solution and now you act as if only other people repeated that to me ;-). I had already implemented it before anyone had answered. Cause I suggested it myself you know. I was just looking for feedback as to whether this was the right path. But basically my question was also about in general... Let's say I am offended ;-) by the amount of times I myself have to attain root to do anything in my system. I am always looking for ways to do less with root and more with my user. It was also a theoretical question (or perhaps practical, but still) as to what is the security risk of a user that gives group ownership to his/her files of a group he/she doesn't belong to. I can understand why it would be odd, off, or wrong, in that sense, that it would feel really weird if you could make your file member of a group, say "teachers" when you are in fact not part of that group because you are a "student". Then people might get the wrong idea if this was a real system people used (which is rarely the case today, I think, since such systems would typically use their own account databases, I think). But still, in the fantasy world where Linux/Unix permissions still matter ;-). I mean groups and group ownership for the most part when it is not security (system) related but rather people related... Graphical environments do not show file ownership anyway. Even our KDE and Mint systems and the like do not show file ownership, let alone group ownership. They might show access data (rights) -- Mint does that. Limited, using an icon. But group ownership is not really a "people" thing these days. There are not really "people" groups all that much. Certainly not any that are not system related (such as staff, or "wheel") (had to abuse Google for that). So on the filesystem groups hardly matter. Anyway. I guess principially it would be "off" for people to give group "ownership" to something they weren't part of (for their own files) but at the same time anyone who has the rights to do that, already has access to the file. This person is now granting access to someone else, but could also just as easily set the file to 777 and accomplish basically the same albeit in a limited or different form. So how can assigning a group one is not part of be a /security/ violation? That was really my question I guess... after a while ;-). > I prefer using php build in server, where possible. Where not possible > I > work on a test system ( like virtual server configured to run on > localhost > only etc) > > There are so many options. My insult was because you refuse to use your > imagination and insist to do it the wrong way. > Talking about complaining, I think you complain the most. That's something I find interesting. I do complain a lot. But I think I have reason to :p. But I don't complain about stuff people do that doesn't affect me. I fail to see how what I do affects you. Example. (Did I say before?). I was in ##Kernel and person does not want to answer my question until I say what I want the information for. How does it affect him? Well, suppose I did something and then became popular with it and my work would find itself back into the kernel at some point but according to their important people it would be the wrong thing to do, then it could embarrass them or create problems for them in the end seeing as they now had to deal with some (to them) anomaly that they now have to deal with after the fact, while they would have wanted to prevent it. But this goes pretty far. So am I complaining? Yes I am, I am complaining about people interfering with choice to such an extent. Person answered "Just trying to ensure you're not doing something unwise" or something of the kind. I mean, that means the interference starts the moment you start moving. The interference starts the moment you even open your mouth or write a thought down that someone else can read. That goes pretty far. In general it goes that far... I also sometimes complain about choices people have made in the past but predominantly about how it takes choice away from me. I don't mind when people do stuff for their own. I mind when their choices are informed by a wish to steer users in a certain direction whether those users want it or not. So effectively that is complaining about the same thing: the limitation of choice. I basically complain about nothing else, for the most part. I mean some example here that people might easily agree with.. is the "The One Apple Way" mindset that Apple has. Whereas the phrase belongs to Microsoft with their "One Microsoft Way" address. I find it a bit difficult to come up with a Microsoft example. Oh yes, the forced updates. Updates were fine in ... well whatever. Now Microsoft not only forces you to run updates, they also force you to run updates while your computer is left unusable in the meantime, sometimes taking as much as 30 minutes to shut down or boot up your computer. They also decided that you want many other new features that most people do not actually want. No one actually wanted the tile interfaces and Windows Phone is a disaster. Oh, if you don't use a Windows Phone you won't know this. Windows Phone has a prediction engine for words you type. That is always wrong. So if you were to write a sentence like "I want to eat the cookie" it would change it into "I want to eat a cookie" without your knowing or influence, and you can't turn it off, and each time it happens you have to take note and go back to change "a" back into "the". And it just keeps doing that forever. And it always is wrong about what it does. Always. That's Microsoft Phone. There you have it. That's the Windows Phone. Anyway enough about this. I feel bad about taking StackExchange's answer through Google Search results for the term "wheel" I couldn't easily find from this Windows 10 machine :p (Oops! :P). Too lazy to log onto a Debian Machine I guess :p. So yes I do complain a lot but mostly about people or companies or systems forcing stuff onto me that I don't want, which happens a lot these days, and much less in the past, so my complaining has gone up immensely ;-). And when you force YOUR way onto me, that's the same to me. >> I really wonder if anyone here backs up a Media-wiki database for >> example by using some Media-wiki "export" function or if in fact you >> back up the (MySQL) database yourself. I really think I can predict >> all >> of us are going to use filesystem tools indeed. And not Media-wiki >> tools. >> > > Only a db dump will not be sufficient So you ensure that this other (filesystem) data is on its dedicated volume and you probably use the cheat way of using a free and cheap snapshot to back up this file data too. You organize your locations in such a way that a logical essential snapshot -- or alternatively you shut down your machine, which is like the "real" way to do it instead of creating a snapshot, but who does that right -- will cover all those parts and you won't need to use any program specific tools. Maybe that makes it harder to migrate it into a different server. Fine. That is a separate concern and can come into play, but if this is not part of YOUR (or my) scope, then that issue does not arise, and so the answer becomes different, and it is no longer (that which you mention) the appropriate tool to use!!! Changing scope, changing answers. I do not need (and I don't use Mediawiki of course) any import ability at this point. I want to be able to back up the data with minimal effort and knowledge, and hence, maximum results for the effort I put in, in that sense. Maximum "RoI" as they call it. You can also call that not wasting your time. >> Drupal for instance has "drush sql-dump" to export the (MySQL) >> database >> but are you seriously going to use that every time you export or >> back-up >> the database? Why should you? >> > > yes. why? because it is intended to the work that I need to be done. And you don't question that? Because it is intended for it you think it is perfect and that it is your best choice? It might not be perfect. It might be flawed. Who knows. And for me personally -- I would first have to learn this tool, because the help does not explicitly state what parts of the database it saves -- only data, or also configuration? How do I export data only? Not possible. Anyway. This time investment in learning the tool is also part of the scope. Do I have the time for learning that? I can spend my three hours learning to use this tool and not have a backup. Or I spend my three hours creating a snaphot and having a backup ready within seconds, so to speak. That is also part of scope you know. I don't have endless time to learn every single tool that presents itself. Maybe If I spent another 30 years on it, yes. Sure. But I like my toolset to be limited because the less tools I need the better I will be capable of using them and the less time I need to spend in learning superfluous ones. Like, In a Kitchen you can have a .. whatever. There are general purpose applicances and then there are specific purpose things. There are knives specifically for cutting grapefruits. Yes you can get a tool for every specific thing. Then your kitchen will pile over and you need to stay minimalist to have a manageable set and not collect endless amounts (and mounds) of junk. Same with a computer. Minimalist toolsets are better. Why? Because it's Debian-like :p. Nuf said? :P. > no need to comment this, I hope you understand why Well I hope you understand the value of minimalism and using essential building blocks as tools rather than specific tools for every specific purpose. Imagine one grep for text files and one grep for source code files and another grep for log files and one grep for... That's senseless. That's bigotry. You need a limited set of tools or you can't work with it, ever. Or you'll keep learning forever for no purpose. You might say "We need to use the specific grep because it was intended to be used for that". But that's bigotry, is what I had wanted to say here. Just because it was intended for it doesn't mean you have to use it. Because it was intended by someone else, who might not be as smart as you are ;-). And certainly can't make your choices. Or might work for TupperWare and needs more stuff to sell. To you. Toolmakers for computer systems are no different. Even if they are open source, they want to have more tools to sell to you. So they'll be important and find a use for their products. So "Because it was made for it" is a stupid reason. That's no reason at all. That's just someone else's opinion. >> Everyone in the right position would use the "wrong" tool because it >> would work whereas the "right" tool would not or would not even be >> available. When it comes down to it, practical matters supersede >> theoretical concerns, but you can't see this from the comfort of your >> seat into another person's computer or site or server. >> > > I don't remember when it was the last time I had a situation when I did > or > used the wrong tool. You have to spent a bit more time on planning and > you > don't have situations, where you have to do something wrong to solve a > problem. Usually I would say 3/4 is planning and 1/4 is working - it's > because being a human means you have a brain and if you use it more, > you > use your hands less. A pure principle of economy in nature :) Perhaps you are already settled in your tools and your mechanics. Perhaps you are not "building" a life, you are just "sustaining" it. I don't know how old you are or how long you've worked, but I do not really have much experience in working for a boss and I have to do my own thing and I am actually completely auto-didact in Linux. There is seriously not a single thing I have learned or acquired from formal education or even a colleague telling me or explaining to me. I also haven't met anyone that used Linux in... like... I don't know, some 6 years I guess other than a girl that just used it for fun, in a little way I guess. But anyway, I was just using your jargon right. What to you is a wrong tool is not a wrong tool to me. I might not even agree with the way it works. I might not even agree with its interface. Just because someone else has called it appropriate for me, doesn't mean it is appropriate for me. Just because someone else intended it for something, doesn't mean I consider it a good intent. I am my own authority in these matters. And the minimalist principle applies. I do not have endless seas of time to learn endless amounts of tools. Maybe later, yes. Not now. Now I need work to get done, ASAP, in that sense, and not have to wait while I have to read books about it first, so to speak, while not even getting hands on experience, in that sense. Linux is an endless learning experience to begin with. It never stops. If you don't limit that, it will consume you, and it already does, because I don't limit myself enough already. And other people then invite you to limit yourself even LESS than that. Doesn't work, sorry. I can't learn all your tools. There are too many. I can't learn all your files, all your help pages, there is an endless sea of them. Doesn't work. I have to limit myself, and restrict myself, or I won't get anything done ever. They say restricting is the beginning of manifestation and I think it is true. I wrote the remainder first: >> So please, some leniency with the "inadequacies" of other people >> because >> they might be doing the right thing whereas you can't see that they do >> because you do not have the information for it. Not all situations are >> identical and everyone chooses the appropriate path for him or >> herself. >> >> I hope that is enough now. >> > > No need to advocate for yourself. I simply don't understand the > frustration, > but hopefully you will forgive if I have insulted you in some way. > I think your question has been answered and you can find your way. You > have > received many ideas in how your problem may be solved easily. > > Please also keep in mind this is a public list - a lot of people read > it and > we write things that could benefit the rest as well. Sometimes that results in insincerity because your answer is then more directed at the other people you don't want to do the same thing as this person is doing, than it is about helping this person help achieve his goal. And if our answer is about educating everyone rather than a single person, by its very nature your education can only be about one way to do things. Then suddenly the topic becomes: what is this One and Only way to do something? And that precludes diversity, because the answer has to fit all, because since the Everything is your audience, you now have to write a single answer to everyone. No more specific answers to specific people, no, there is just one answer that has to apply to everyone. And if this is the case here, then no small wonder that your answer does not apply to me (or to anyone) -- you're not even really talking to me, but to the people who are silently listening in the back. In that case there can never really be an answer that really fits me because you were not even trying to achieve that. And if I then object to the answer, because it does not fit me and what I am trying to do, that is only natural, and that the natural outcome of your actual intent: to provide a "one size fits all" answer to me.
[toc] | [prev] | [next] | [standalone]
| From | Xen <list@xenhideout.nl> |
|---|---|
| Date | 2016-12-27 22:50 +0100 |
| Message-ID | <sT7N7-7x6-5@gated-at.bofh.it> |
| In reply to | #175984 |
deloptes schreef op 27-12-2016 21:05: > You are an i**ot I would immediately fire. Start reading the interfaces > and > using the programs as designed. If you want to do things your own way I > do > not want to know about it. Nobody asked you about it. You should stop feeling addressed as if you were the sole person on this thread or this mailing list. I did not explicitly address you and so you should not act as if I did. You are the idiot that thinks you are special or something. Now be gone. > You keep insisting doing wrong things. If you use mediawiki, you do not > need > write access as a user. Leave this to the system and use the interface > and/or tools provided. Same here. Wrong does not exist. You are an idiot that does not know the distinction between wrong as in "the wrong thing to do" and wrong as in "the wrong solution to a problem".
[toc] | [prev] | [next] | [standalone]
| From | Andy Smith <andy@strugglers.net> |
|---|---|
| Date | 2016-12-23 15:20 +0100 |
| Message-ID | <sRyRr-7Wo-1@gated-at.bofh.it> |
| In reply to | #175882 |
Hi Xen, On Thu, Dec 22, 2016 at 06:24:59PM +0100, Xen wrote: > I am trying to get a webserver to run under my regular user, or at > least to have the website's files under control of my regular user, > but the webserver runs as www-data. You've been shown how to put yourself in the www-data group so that you can make the files group-writable and still edit them with your normal user. Other solutions include: - Run a separate web server on a high port, so that it can listen on this port without needing special privileges. Proxy to this server from your main web server that listens on port 80. In this way the main web server does not need PHP and touches no files, it just listens on port 80 and proxies connections. The other web server runs as an unprivileged user and reads the files. - If using apache, you can make each vhost run as a different unprivileged user with a different MPM such as apache2-mpm-itk. Other web servers may have similar features. - You could run PHP under FastCGI which would let you potentially run each site's FastCGI server as a different user. Although this would mean that every page would have to come through FastCGI with no opportunity for simple static file serving. Here's an example of php-fpm under nginx on jessie: https://www.howtoforge.com/tutorial/installing-nginx-with-php-fpm-and-mariadb-lemp-on-debian-jessie/ That example doesn't show how to have different users. This one does; it is for Ubuntu but you can pretty easily get the idea: https://www.digitalocean.com/community/tutorials/how-to-host-multiple-websites-securely-with-nginx-and-php-fpm-on-ubuntu-14-04 Cheers, Andy -- https://bitfolk.com/ -- No-nonsense VPS hosting
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web