Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #206946 > unrolled thread
| Started by | David <bouncingcats@gmail.com> |
|---|---|
| First post | 2019-04-04 13:00 +0200 |
| Last post | 2019-04-04 15:00 +0200 |
| Articles | 20 on this page of 80 — 24 participants |
Back to article view | Back to linux.debian.user
'synaptic' removed from buster David <bouncingcats@gmail.com> - 2019-04-04 13:00 +0200
Re: 'synaptic' removed from buster "Alexander V. Makartsev" <avbetev@gmail.com> - 2019-04-04 13:00 +0200
Re: 'synaptic' removed from buster Brad Rogers <brad@fineby.me.uk> - 2019-04-04 13:40 +0200
Re: 'synaptic' removed from buster Francisco M Neto <fmneto@fmneto.com.br> - 2019-04-04 14:50 +0200
Re: 'synaptic' removed from buster Curt <curty@free.fr> - 2019-04-04 15:00 +0200
Re: 'synaptic' removed from buster Jonathan Dowland <jmtd@debian.org> - 2019-04-05 17:10 +0200
Re: 'synaptic' removed from buster Reco <recoverym4n@enotuniq.net> - 2019-04-05 17:50 +0200
Re: 'synaptic' removed from buster Lee <ler762@gmail.com> - 2019-04-05 23:10 +0200
Re: 'synaptic' removed from buster Nicholas Geovanis <nickgeovanis@gmail.com> - 2019-04-06 00:40 +0200
Re: 'synaptic' removed from buster Nicholas Geovanis <nickgeovanis@gmail.com> - 2019-04-06 01:00 +0200
Re: 'synaptic' removed from buster David <bouncingcats@gmail.com> - 2019-04-06 01:50 +0200
Re: 'synaptic' removed from buster David Wright <deblis@lionunicorn.co.uk> - 2019-04-06 04:40 +0200
Re: 'synaptic' removed from buster Jonathan Dowland <jmtd@debian.org> - 2019-04-06 09:50 +0200
Re: 'synaptic' removed from buster David Wright <deblis@lionunicorn.co.uk> - 2019-04-10 18:10 +0200
Re: 'synaptic' removed from buster Nazar Zhuk <nazar@zhuk.online> - 2019-04-11 00:40 +0200
Re: 'synaptic' removed from buster Lee <ler762@gmail.com> - 2019-04-11 01:50 +0200
Re: 'synaptic' removed from buster David Wright <deblis@lionunicorn.co.uk> - 2019-04-11 05:30 +0200
Re: 'synaptic' removed from buster David Wright <deblis@lionunicorn.co.uk> - 2019-04-11 05:20 +0200
Re: 'synaptic' removed from buster Nazar Zhuk <nazar@zhuk.online> - 2019-04-11 21:00 +0200
Re: 'synaptic' removed from buster David Wright <deblis@lionunicorn.co.uk> - 2019-04-11 22:30 +0200
Re: 'synaptic' removed from buster Gene Heskett <gheskett@shentel.net> - 2019-04-06 15:10 +0200
Re: 'synaptic' removed from buster David Wright <deblis@lionunicorn.co.uk> - 2019-04-09 22:10 +0200
Re: 'synaptic' removed from buster Curt <curty@free.fr> - 2019-04-06 10:10 +0200
Re: 'synaptic' removed from buster Joe <joe@jretrading.com> - 2019-04-06 10:50 +0200
Re: 'synaptic' removed from buster David <bouncingcats@gmail.com> - 2019-04-06 11:00 +0200
Re: 'synaptic' removed from buster Dominic Knight <dominicknight@gmx.com> - 2019-04-06 12:40 +0200
Re: 'synaptic' removed from buster David Wright <deblis@lionunicorn.co.uk> - 2019-04-09 22:10 +0200
Re: 'synaptic' removed from buster rhkramer@gmail.com - 2019-04-06 14:10 +0200
Re: 'synaptic' removed from buster Curt <curty@free.fr> - 2019-04-06 15:00 +0200
Re: 'synaptic' removed from buster Greg Wooledge <wooledg@eeg.ccf.org> - 2019-04-08 14:30 +0200
Re: 'synaptic' removed from buster Jan Claeys <lists@janc.be> - 2019-04-06 14:50 +0200
Re: 'synaptic' removed from buster Reco <recoverym4n@enotuniq.net> - 2019-04-04 15:10 +0200
Re: 'synaptic' removed from buster Gene Heskett <gheskett@shentel.net> - 2019-04-04 16:20 +0200
Re: 'synaptic' removed from buster Reco <recoverym4n@enotuniq.net> - 2019-04-04 18:00 +0200
Re: 'synaptic' removed from buster <tomas@tuxteam.de> - 2019-04-04 21:30 +0200
Re: 'synaptic' removed from buster Ric Moore <wayward4now@gmail.com> - 2019-04-06 20:30 +0200
Re: 'synaptic' removed from buster Joe <joe@jretrading.com> - 2019-04-04 19:40 +0200
Re: 'synaptic' removed from buster Reco <recoverym4n@enotuniq.net> - 2019-04-04 19:50 +0200
Re: 'synaptic' removed from buster Gene Heskett <gheskett@shentel.net> - 2019-04-04 21:50 +0200
Re: 'synaptic' removed from buster Greg Wooledge <wooledg@eeg.ccf.org> - 2019-04-04 22:00 +0200
Re: 'synaptic' removed from buster Gene Heskett <gheskett@shentel.net> - 2019-04-04 22:20 +0200
Re: 'synaptic' removed from buster Greg Wooledge <wooledg@eeg.ccf.org> - 2019-04-04 22:30 +0200
Re: 'synaptic' removed from buster Jonathan Dowland <jmtd@debian.org> - 2019-04-05 17:10 +0200
Re: 'synaptic' removed from buster Gene Heskett <gheskett@shentel.net> - 2019-04-05 20:30 +0200
Re: 'synaptic' removed from buster David Wright <deblis@lionunicorn.co.uk> - 2019-04-06 05:20 +0200
Re: 'synaptic' removed from buster Gene Heskett <gheskett@shentel.net> - 2019-04-06 15:30 +0200
Re: 'synaptic' removed from buster David Wright <deblis@lionunicorn.co.uk> - 2019-04-09 22:40 +0200
Re: 'synaptic' removed from buster Jan Claeys <lists@janc.be> - 2019-04-05 21:40 +0200
Re: 'synaptic' removed from buster Gene Heskett <gheskett@shentel.net> - 2019-04-05 22:40 +0200
Re: 'synaptic' removed from buster David Wright <deblis@lionunicorn.co.uk> - 2019-04-05 22:40 +0200
Re: 'synaptic' removed from buster Jan Claeys <lists@janc.be> - 2019-04-06 15:00 +0200
Re: 'synaptic' removed from buster Doug <dmcgarrett@optonline.net> - 2019-04-06 01:30 +0200
Re: 'synaptic' removed from buster Jonathan Dowland <jmtd@debian.org> - 2019-04-05 17:10 +0200
Re: 'synaptic' removed from buster mick crane <mick.crane@gmail.com> - 2019-04-05 08:40 +0200
Re: 'synaptic' removed from buster <tomas@tuxteam.de> - 2019-04-05 08:50 +0200
Re: 'synaptic' removed from buster mick crane <mick.crane@gmail.com> - 2019-04-05 09:50 +0200
Re: 'synaptic' removed from buster <tomas@tuxteam.de> - 2019-04-05 12:00 +0200
Re: 'synaptic' removed from buster mick crane <mick.crane@gmail.com> - 2019-04-05 12:20 +0200
Re: 'synaptic' removed from buster <tomas@tuxteam.de> - 2019-04-05 12:30 +0200
Re: 'synaptic' removed from buster <tomas@tuxteam.de> - 2019-04-05 13:40 +0200
Re: 'synaptic' removed from buster mick crane <mick.crane@gmail.com> - 2019-04-05 13:50 +0200
Re: 'synaptic' removed from buster <tomas@tuxteam.de> - 2019-04-05 14:10 +0200
Re: 'synaptic' removed from buster mick crane <mick.crane@gmail.com> - 2019-04-05 13:40 +0200
Re: 'synaptic' removed from buster David Wright <deblis@lionunicorn.co.uk> - 2019-04-05 22:20 +0200
Re: 'synaptic' removed from buster mick crane <mick.crane@gmail.com> - 2019-04-06 03:10 +0200
Re: 'synaptic' removed from buster Gene Heskett <gheskett@shentel.net> - 2019-04-05 11:10 +0200
Re: 'synaptic' removed from buster mick crane <mick.crane@gmail.com> - 2019-04-05 12:00 +0200
Re: 'synaptic' removed from buster Brad Rogers <brad@fineby.me.uk> - 2019-04-04 15:50 +0200
Re: 'synaptic' removed from buster Francisco M Neto <fmneto@fmneto.com.br> - 2019-04-05 15:30 +0200
Re: 'synaptic' removed from buster David <bouncingcats@gmail.com> - 2019-04-05 15:40 +0200
Re: 'synaptic' removed from buster Francisco M Neto <fmneto@fmneto.com.br> - 2019-04-05 17:30 +0200
Re: 'synaptic' removed from buster Gene Heskett <gheskett@shentel.net> - 2019-04-05 19:50 +0200
Re: 'synaptic' removed from buster Charlie <taoquester@gmail.com> - 2019-04-06 00:40 +0200
Re: 'synaptic' removed from buster Gene Heskett <gheskett@shentel.net> - 2019-04-04 15:00 +0200
Re: 'synaptic' removed from buster Curt <curty@free.fr> - 2019-04-04 14:30 +0200
Re: 'synaptic' removed from buster David <bouncingcats@gmail.com> - 2019-04-04 16:40 +0200
Re: 'synaptic' removed from buster Richard Owlett <rowlett@cloud85.net> - 2019-04-05 14:50 +0200
Re: 'synaptic' removed from buster Andy Smith <andy@strugglers.net> - 2019-04-05 20:40 +0200
Re: 'synaptic' removed from buster Richard Owlett <rowlett@cloud85.net> - 2019-04-05 21:30 +0200
Re: 'synaptic' removed from buster Gene Heskett <gheskett@shentel.net> - 2019-04-04 15:00 +0200
Page 3 of 4 — ← Prev page 1 2 [3] 4 Next page →
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2019-04-04 22:20 +0200 |
| Message-ID | <xJh05-5ST-3@gated-at.bofh.it> |
| In reply to | #206991 |
On Thursday 04 April 2019 15:57:17 Greg Wooledge wrote: > On Thu, Apr 04, 2019 at 03:46:52PM -0400, Gene Heskett wrote: > > The solution seems simple enough, fix wayland. This is after all a > > multiuser and multitasking OS, why go out of the way, way out of the > > way to make it work like win-3.0? > > The notion of running a client as user X to talk to a display server > running as user Y seems to directly contradict the Wayland security > model. As far as I can understand it, given the rather vague Wayland > documentation I've seen so far. > > I think the "correct" fix for synaptic would be to redesign it to run > the graphical interface as you, communicating with an auxiliary > process that runs as root which can install and remove packages. That > second process could be a child of synaptic, or an independent daemon > of some kind. Authentication methods to be determined by whomever does > the work. > > I would not describe this solution as "simple". Maybe you had a > different solution in mind. I didn't intend to say it was simple. Its also incorrect. Fix one or the other, but I don't expect it to be "simple". You fix wayland once, or you fix half the os's utilities. Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <wooledg@eeg.ccf.org> |
|---|---|
| Date | 2019-04-04 22:30 +0200 |
| Message-ID | <xJh9L-5We-1@gated-at.bofh.it> |
| In reply to | #206993 |
On Thu, Apr 04, 2019 at 04:15:32PM -0400, Gene Heskett wrote: > I didn't intend to say it was simple. Its also incorrect. Fix one or the > other, but I don't expect it to be "simple". You fix wayland once, or > you fix half the os's utilities. Wayland isn't in need of a "fix", as I understand it. It's working as designed. How many graphical programs does Debian actually have that are intended to be run as root on a desktop? It's certainly not "half the os's utilities". I'd be surprised if there are as many as ten.
[toc] | [prev] | [next] | [standalone]
| From | Jonathan Dowland <jmtd@debian.org> |
|---|---|
| Date | 2019-04-05 17:10 +0200 |
| Message-ID | <xJyDD-7Y-3@gated-at.bofh.it> |
| In reply to | #206994 |
On Thu, Apr 04, 2019 at 04:22:43PM -0400, Greg Wooledge wrote: >How many graphical programs does Debian actually have that are intended >to be run as root on a desktop? It's certainly not "half the os's >utilities". I'd be surprised if there are as many as ten. Indeed, and running the UI toolkit code as root was always considered a bad design pattern, even whilst it works under X. -- ⢀⣴⠾⠻⢶⣦⠀ ⣾⠁⢠⠒⠀⣿⡁ Jonathan Dowland ⢿⡄⠘⠷⠚⠋⠀ https://jmtd.net ⠈⠳⣄⠀⠀⠀⠀ Please do not CC me, I am subscribed to the list.
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2019-04-05 20:30 +0200 |
| Message-ID | <xJBLc-1YA-9@gated-at.bofh.it> |
| In reply to | #207029 |
On Friday 05 April 2019 11:05:00 Jonathan Dowland wrote: [...] > Indeed, and running the UI toolkit code as root was always considered > a bad design pattern, even whilst it works under X. But thats no longer possible with X, root cannot use the users display. And for me, the only user on this multiple machine network, that is a major PITA because of the extremely inconsistent workaround's. Give us a method to su or sudo root, and run the stuff needing root, at least a consistent procedure thats good for all releases. Changing it around makes applying the same user package update to every machine a different operation. LinuxCNC is updated in master at least 2x a week sometimes daily as a new feature gets added and needs debugged. So even if wheezy is dead, synaptic gets run quite frequently to keep that up to date. The jessie install on the pi for instance won't let me run synaptic from anyplace but its own keyboard. Anyplace else, and ssh'd in, I have to sudo apt etc. Consistency is the magic word, and we don't have it. Thanks. Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2019-04-06 05:20 +0200 |
| Message-ID | <xJK26-7h1-3@gated-at.bofh.it> |
| In reply to | #207044 |
On Fri 05 Apr 2019 at 14:21:21 (-0400), Gene Heskett wrote: > On Friday 05 April 2019 11:05:00 Jonathan Dowland wrote: > > [...] > > > Indeed, and running the UI toolkit code as root was always considered > > a bad design pattern, even whilst it works under X. > > But thats no longer possible with X, root cannot use the users display. > > And for me, the only user on this multiple machine network, that is a > major PITA because of the extremely inconsistent workaround's. > > Give us a method to su or sudo root, and run the stuff needing root, at > least a consistent procedure thats good for all releases. Changing it > around makes applying the same user package update to every machine a > different operation. LinuxCNC is updated in master at least 2x a week > sometimes daily as a new feature gets added and needs debugged. So even > if wheezy is dead, synaptic gets run quite frequently to keep that up to > date. The jessie install on the pi for instance won't let me run > synaptic from anyplace but its own keyboard. Anyplace else, and ssh'd > in, I have to sudo apt etc. > > Consistency is the magic word, and we don't have it. I don't understand how you can expect consistency in an OS that supports ~10 architectures and four releases, written over a period of, say, six years or more. Particularly considering that it's not possible to revise the earlier releases to take account of changes forced by the evolution of software external to the project and by increasing security exigencies. You can hide any differences in how you obtain root by just wrapping your command in a script, appropriate for each architecture/release. Just one script to maintain if you use case or if/else. (BTW It beats me why you need the functionality of synaptic to keep a wheezy system going. What do you do with it beyond the equivalent of running apt-get update/upgrade?) Cheers, David.
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2019-04-06 15:30 +0200 |
| Message-ID | <xJTyp-4HM-9@gated-at.bofh.it> |
| In reply to | #207065 |
On Friday 05 April 2019 23:06:13 David Wright wrote: > On Fri 05 Apr 2019 at 14:21:21 (-0400), Gene Heskett wrote: > > On Friday 05 April 2019 11:05:00 Jonathan Dowland wrote: > > > > [...] > > > > > Indeed, and running the UI toolkit code as root was always > > > considered a bad design pattern, even whilst it works under X. > > > > But thats no longer possible with X, root cannot use the users > > display. > > > > And for me, the only user on this multiple machine network, that is > > a major PITA because of the extremely inconsistent workaround's. > > > > Give us a method to su or sudo root, and run the stuff needing root, > > at least a consistent procedure thats good for all releases. > > Changing it around makes applying the same user package update to > > every machine a different operation. LinuxCNC is updated in master > > at least 2x a week sometimes daily as a new feature gets added and > > needs debugged. So even if wheezy is dead, synaptic gets run quite > > frequently to keep that up to date. The jessie install on the pi for > > instance won't let me run synaptic from anyplace but its own > > keyboard. Anyplace else, and ssh'd in, I have to sudo apt etc. > > > > Consistency is the magic word, and we don't have it. > > I don't understand how you can expect consistency in an OS that > supports ~10 architectures and four releases, written over a period > of, say, six years or more. Particularly considering that it's > not possible to revise the earlier releases to take account of > changes forced by the evolution of software external to the project > and by increasing security exigencies. > If I'm willing to forgo web browsing, wheezy can still be running 20 years from now, the only changes needed would be for ssh|l|tls stuff if you are using it for email. I am behind a dd-wrt flashed router with no local firewalls running anyplace on this local net. No one has come past that that I didn't invite in, and I'm not doing a thing to get that security that the rest of you can't do, probably even better. So I don't worry about security, I worry about interoperability on my local network, but the way thats headed, there will not be the possibility of my ssh'ing into one of my other machines and doing a simple ls or pwd to see where I am. That IMO is not real security, but PARANOIA and should rightly be called as such. This os was originally able to ignore whether the key/mouse stroke came from its own keyboard, or one in Lisbon, Portugal. Or from this machine, 100+ feet of cat5 away. This is NOT an M$ single user system, so quit trying to restrict it to what a winders box can do. > You can hide any differences in how you obtain root by just wrapping > your command in a script, appropriate for each architecture/release. > Just one script to maintain if you use case or if/else. Then Make it so... > (BTW It beats me why you need the functionality of synaptic to keep > a wheezy system going. What do you do with it beyond the equivalent > of running apt-get update/upgrade?) Since the deb repo's went away, not much. I have 2 active lines left in my sources.list now. > Cheers, > David. Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2019-04-09 22:40 +0200 |
| Message-ID | <xL5Hc-iU-3@gated-at.bofh.it> |
| In reply to | #207077 |
On Sat 06 Apr 2019 at 09:26:51 (-0400), Gene Heskett wrote: > On Friday 05 April 2019 23:06:13 David Wright wrote: > > On Fri 05 Apr 2019 at 14:21:21 (-0400), Gene Heskett wrote: > > > On Friday 05 April 2019 11:05:00 Jonathan Dowland wrote: > > > > > > [...] > > > > > > > Indeed, and running the UI toolkit code as root was always > > > > considered a bad design pattern, even whilst it works under X. > > > > > > But thats no longer possible with X, root cannot use the users > > > display. > > > > > > And for me, the only user on this multiple machine network, that is > > > a major PITA because of the extremely inconsistent workaround's. > > > > > > Give us a method to su or sudo root, and run the stuff needing root, > > > at least a consistent procedure thats good for all releases. > > > Changing it around makes applying the same user package update to > > > every machine a different operation. LinuxCNC is updated in master > > > at least 2x a week sometimes daily as a new feature gets added and > > > needs debugged. So even if wheezy is dead, synaptic gets run quite > > > frequently to keep that up to date. The jessie install on the pi for > > > instance won't let me run synaptic from anyplace but its own > > > keyboard. Anyplace else, and ssh'd in, I have to sudo apt etc. > > > > > > Consistency is the magic word, and we don't have it. > > > > I don't understand how you can expect consistency in an OS that > > supports ~10 architectures and four releases, written over a period > > of, say, six years or more. Particularly considering that it's > > not possible to revise the earlier releases to take account of > > changes forced by the evolution of software external to the project > > and by increasing security exigencies. > > > If I'm willing to forgo web browsing, wheezy can still be running 20 > years from now, the only changes needed would be for ssh|l|tls stuff if > you are using it for email. I am behind a dd-wrt flashed router with no > local firewalls running anyplace on this local net. > > No one has come past that that I didn't invite in, and I'm not doing a > thing to get that security that the rest of you can't do, probably even > better. > > So I don't worry about security, I worry about interoperability on my > local network, but the way thats headed, there will not be the > possibility of my ssh'ing into one of my other machines and doing a > simple ls or pwd to see where I am. That IMO is not real security, but > PARANOIA and should rightly be called as such. > > This os was originally able to ignore whether the key/mouse stroke came > from its own keyboard, or one in Lisbon, Portugal. Or from this machine, > 100+ feet of cat5 away. This is NOT an M$ single user system, so quit > trying to restrict it to what a winders box can do. I keep reading here that you have problems with ssh -X and -Y, but find it difficult to replicate them here. I've been running a mix of wheezy/jessie/stretch here with no problems (though I have retired the wheezy versions recently and removed all references in apt-cacher-ng now that the archives have moved). > > You can hide any differences in how you obtain root by just wrapping > > your command in a script, appropriate for each architecture/release. > > Just one script to maintain if you use case or if/else. > > Then Make it so... I meant for you to do that, in the same way that I write scripts for some user programs in order to cover up the differences between versions of Debian, or the hardware (like sound cards) on different hosts. It just means the differences are put into the scripts so you can type the same thing without having to remember all the time. $HOSTNAME is obvious, but I also have $Mycodename which is set from the first line of sources.list. This gives a more consistent answer the debian_version, os-release etc as it's under my control. Cheers, David.
[toc] | [prev] | [next] | [standalone]
| From | Jan Claeys <lists@janc.be> |
|---|---|
| Date | 2019-04-05 21:40 +0200 |
| Message-ID | <xJCQV-2BR-7@gated-at.bofh.it> |
| In reply to | #206994 |
On Thu, 2019-04-04 at 16:22 -0400, Greg Wooledge wrote: > How many graphical programs does Debian actually have that are > intended to be run as root on a desktop? It's certainly not "half > the os's utilities". I'd be surprised if there are as many as ten. Another well-known one is GParted, which doesn't really have an alternative for people to use instead... -- Jan Claeys
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2019-04-05 22:40 +0200 |
| Message-ID | <xJDMZ-3c7-5@gated-at.bofh.it> |
| In reply to | #207048 |
On Friday 05 April 2019 15:34:15 Jan Claeys wrote: > On Thu, 2019-04-04 at 16:22 -0400, Greg Wooledge wrote: > > How many graphical programs does Debian actually have that are > > intended to be run as root on a desktop? It's certainly not "half > > the os's utilities". I'd be surprised if there are as many as ten. > > Another well-known one is GParted, which doesn't really have an > alternative for people to use instead... Its the swiss army knife of these tools, best to keep it handy. Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2019-04-05 22:40 +0200 |
| Message-ID | <xJDMZ-3c7-7@gated-at.bofh.it> |
| In reply to | #207048 |
On Fri 05 Apr 2019 at 21:34:15 (+0200), Jan Claeys wrote: > On Thu, 2019-04-04 at 16:22 -0400, Greg Wooledge wrote: > > How many graphical programs does Debian actually have that are > > intended to be run as root on a desktop? It's certainly not "half > > the os's utilities". I'd be surprised if there are as many as ten. > > Another well-known one is GParted, which doesn't really have an > alternative for people to use instead... Does parted not do the same things? I must admit that in 24 years of linux, I've never run a GUI application as root. And I would have thought there's a case for using a TUI rather than a GUI if the need was pressing. Cheers, David.
[toc] | [prev] | [next] | [standalone]
| From | Jan Claeys <lists@janc.be> |
|---|---|
| Date | 2019-04-06 15:00 +0200 |
| Message-ID | <xJT5o-4in-9@gated-at.bofh.it> |
| In reply to | #207053 |
On Fri, 2019-04-05 at 15:30 -0500, David Wright wrote: > On Fri 05 Apr 2019 at 21:34:15 (+0200), Jan Claeys wrote: > > Another well-known one is GParted, which doesn't really have an > > alternative for people to use instead... > > Does parted not do the same things? No, it can do some things GParted does (in fact, GParted uses libparted for those), but GParted has additional features that parted doesn't, like moving partitions including the filesystems on them. > I must admit that in 24 years of linux, I've never run a GUI > application as root. And I would have thought there's a case for > using a TUI rather than a GUI if the need was pressing. Obviously it would be better if GParted didn't run as root, but used a model where a unprivileged process calls a privileged process to do the actual "hard work" that needs those privileges. Unfortunately none of the GParted developers have had the combination of time & skills to rewrite GParted for that yet (help welcome). -- Jan Claeys (please don't CC me when replying to the list)
[toc] | [prev] | [next] | [standalone]
| From | Doug <dmcgarrett@optonline.net> |
|---|---|
| Date | 2019-04-06 01:30 +0200 |
| Message-ID | <xJGrv-4Ya-1@gated-at.bofh.it> |
| In reply to | #207048 |
On 04/05/2019 03:34 PM, Jan Claeys wrote: > On Thu, 2019-04-04 at 16:22 -0400, Greg Wooledge wrote: >> How many graphical programs does Debian actually have that are >> intended to be run as root on a desktop? It's certainly not "half >> the os's utilities". I'd be surprised if there are as many as ten. > Another well-known one is GParted, which doesn't really have an > alternative for people to use instead... > > You can download a version of GParted that is bootable, and you don't need your operating system to use it. You can then change labels, or expand or compress partitions without regard to what's on them. You can even add or delete partitions, so be careful. --doug
[toc] | [prev] | [next] | [standalone]
| From | Jonathan Dowland <jmtd@debian.org> |
|---|---|
| Date | 2019-04-05 17:10 +0200 |
| Message-ID | <xJyDE-7Y-7@gated-at.bofh.it> |
| In reply to | #206993 |
On Thu, Apr 04, 2019 at 04:15:32PM -0400, Gene Heskett wrote: >I didn't intend to say it was simple. Its also incorrect. Fix one or the >other, but I don't expect it to be "simple". You fix wayland once, or >you fix half the os's utilities. The "fix" you describe for Wayland would be to remove the security distinction between users. You enjoy throwing around comparisons to Windows-3.0: what you advocate would be a move entirely in that direction. -- ⢀⣴⠾⠻⢶⣦⠀ ⣾⠁⢠⠒⠀⣿⡁ Jonathan Dowland ⢿⡄⠘⠷⠚⠋⠀ https://jmtd.net ⠈⠳⣄⠀⠀⠀⠀ Please do not CC me, I am subscribed to the list.
[toc] | [prev] | [next] | [standalone]
| From | mick crane <mick.crane@gmail.com> |
|---|---|
| Date | 2019-04-05 08:40 +0200 |
| Message-ID | <xJqG6-3uO-3@gated-at.bofh.it> |
| In reply to | #206991 |
On 2019-04-04 20:57, Greg Wooledge wrote: > On Thu, Apr 04, 2019 at 03:46:52PM -0400, Gene Heskett wrote: >> The solution seems simple enough, fix wayland. This is after all a >> multiuser and multitasking OS, why go out of the way, way out of the >> way >> to make it work like win-3.0? > > The notion of running a client as user X to talk to a display server > running as user Y seems to directly contradict the Wayland security > model. As far as I can understand it, given the rather vague Wayland > documentation I've seen so far. > > I think the "correct" fix for synaptic would be to redesign it to run > the > graphical interface as you, communicating with an auxiliary process > that > runs as root which can install and remove packages. That second > process > could be a child of synaptic, or an independent daemon of some kind. > Authentication methods to be determined by whomever does the work. > > I would not describe this solution as "simple". Maybe you had a > different > solution in mind. Making you be root to download stuff off the internet never seemed like a good idea. mick -- Key ID 4BFEBB31
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2019-04-05 08:50 +0200 |
| Message-ID | <xJqPL-3yr-3@gated-at.bofh.it> |
| In reply to | #206998 |
[Multipart message — attachments visible in raw view] — view raw
On Fri, Apr 05, 2019 at 07:37:05AM +0100, mick crane wrote: [...] > Making you be root to download stuff off the internet never seemed > like a good idea. And letting "you" (not root) install things in system directories (/usr/bin et al) seems to be as bad an idea. Remember that little javascript in your browser made by "Fakebook"? It's running as you. Do you want it to put its grubby fingers all over your system dirs? No, the installer doesn't want root to "download stuff". It wants root to put things on /usr/bin, /etc and similar places. Actually it /needs/ root for that, and this seems to be a Good Thing. If you want to try out alternatives, you could do (kids: don't try this at home!): I repeat: **DON'T DO THIS AT HOME!** sudo chmod -R ugo+rwX / DON'T DO THIS! Enjoy your alternative Unix. Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | mick crane <mick.crane@gmail.com> |
|---|---|
| Date | 2019-04-05 09:50 +0200 |
| Message-ID | <xJrLP-48y-1@gated-at.bofh.it> |
| In reply to | #206999 |
On 2019-04-05 07:46, tomas@tuxteam.de wrote: > On Fri, Apr 05, 2019 at 07:37:05AM +0100, mick crane wrote: > > [...] > >> Making you be root to download stuff off the internet never seemed >> like a good idea. > > And letting "you" (not root) install things in system directories > (/usr/bin et al) seems to be as bad an idea. Remember that little > javascript in your browser made by "Fakebook"? It's running as > you. Do you want it to put its grubby fingers all over your system > dirs? > > No, the installer doesn't want root to "download stuff". It wants > root to put things on /usr/bin, /etc and similar places. Actually > it /needs/ root for that, and this seems to be a Good Thing. > > If you want to try out alternatives, you could do (kids: don't try > this at home!): > > I repeat: **DON'T DO THIS AT HOME!** > > sudo chmod -R ugo+rwX / > > DON'T DO THIS! > > Enjoy your alternative Unix. > > Cheers > -- t what's the issue with seeing what's available as you, checking what you need as root, downloading as you, install as root. mick -- Key ID 4BFEBB31
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2019-04-05 12:00 +0200 |
| Message-ID | <xJtNE-5n9-3@gated-at.bofh.it> |
| In reply to | #207002 |
[Multipart message — attachments visible in raw view] — view raw
On Fri, Apr 05, 2019 at 08:43:32AM +0100, mick crane wrote: > On 2019-04-05 07:46, tomas@tuxteam.de wrote: > >On Fri, Apr 05, 2019 at 07:37:05AM +0100, mick crane wrote: > > > >[...] > > > >>Making you be root to download stuff off the internet never seemed > >>like a good idea. > > > >And letting "you" (not root) install things in system directories > >(/usr/bin et al) seems to be as bad an idea [...] [...] > what's the issue with > seeing what's available as you, > checking what you need as root, > downloading as you, > install as root. Imagine some random javascript (running as you, the "normal" user starts doing system things (browser sandboxing? nah!). At this point I'd hope I get asked for my password, to get a chance to stop the whole shenanigan. But that's just me... Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | mick crane <mick.crane@gmail.com> |
|---|---|
| Date | 2019-04-05 12:20 +0200 |
| Message-ID | <xJu6Z-5JK-3@gated-at.bofh.it> |
| In reply to | #207006 |
On 2019-04-05 10:51, tomas@tuxteam.de wrote: > On Fri, Apr 05, 2019 at 08:43:32AM +0100, mick crane wrote: >> On 2019-04-05 07:46, tomas@tuxteam.de wrote: >> >On Fri, Apr 05, 2019 at 07:37:05AM +0100, mick crane wrote: >> > >> >[...] >> > >> >>Making you be root to download stuff off the internet never seemed >> >>like a good idea. >> > >> >And letting "you" (not root) install things in system directories >> >(/usr/bin et al) seems to be as bad an idea [...] > > [...] > >> what's the issue with >> seeing what's available as you, >> checking what you need as root, >> downloading as you, >> install as root. > > Imagine some random javascript (running as you, the "normal" user > starts doing system things (browser sandboxing? nah!). At this point > I'd hope I get asked for my password, to get a chance to stop the > whole shenanigan. But that's just me... > > Cheers > -- t well normal user isn't supposed to do system things. Sudo makes me nervous. -- Key ID 4BFEBB31
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2019-04-05 12:30 +0200 |
| Message-ID | <xJugG-5N9-7@gated-at.bofh.it> |
| In reply to | #207010 |
[Multipart message — attachments visible in raw view] — view raw
On Fri, Apr 05, 2019 at 11:07:42AM +0100, mick crane wrote: [...] > well normal user isn't supposed to do system things. Sudo makes me > nervous. You don't seem to understand sudo. It lets you control finely under which conditions a normal user is able to change to root. One posibility (one edit of /etc/sudoers away) would be "never", if you like that. Another (imo more sensible) would be: when doing backup, always; when installing packages, only this or that user, giving her credentials; or giving root's credentials. You name it. Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2019-04-05 13:40 +0200 |
| Message-ID | <xJvmp-6pO-1@gated-at.bofh.it> |
| In reply to | #207011 |
[Multipart message — attachments visible in raw view] — view raw
On Fri, Apr 05, 2019 at 12:28:18PM +0100, mick crane wrote: [...] > probably I don't understand. What I'm mooting is who knows what > skillful cracker can get hold of your account credentials when > online. If user can't do root stuff on strength of their own > password then any malignant activity would be limited. It's not about user/root as different /persons/, but as different /roles/. I want to be able to "do" root on my box (and I want everyone to have that possibility on their box). But I want to be aware of /when/ I'm playing the root role. Cheers -- t
[toc] | [prev] | [next] | [standalone]
Page 3 of 4 — ← Prev page 1 2 [3] 4 Next page →
Back to top | Article view | linux.debian.user
csiph-web