Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #209864 > unrolled thread
| Started by | Gene Heskett <gheskett@shentel.net> |
|---|---|
| First post | 2019-06-13 21:40 +0200 |
| Last post | 2019-06-15 12:00 +0200 |
| Articles | 14 — 7 participants |
Back to article view | Back to linux.debian.user
web page problem Gene Heskett <gheskett@shentel.net> - 2019-06-13 21:40 +0200
Re: web page problem Felix Miata <mrmazda@earthlink.net> - 2019-06-13 22:10 +0200
Re: web page problem Gene Heskett <gheskett@shentel.net> - 2019-06-13 22:50 +0200
Re: web page problem Felix Miata <mrmazda@earthlink.net> - 2019-06-13 23:10 +0200
Re: web page problem Gene Heskett <gheskett@shentel.net> - 2019-06-14 00:20 +0200
Re: web page problem Greg Wooledge <wooledg@eeg.ccf.org> - 2019-06-14 14:50 +0200
Re: web page problem <tomas@tuxteam.de> - 2019-06-14 15:00 +0200
Re: web page problem Greg Wooledge <wooledg@eeg.ccf.org> - 2019-06-14 15:10 +0200
Re: web page problem Gene Heskett <gheskett@shentel.net> - 2019-06-15 03:20 +0200
Re: web page problem Joe <joe@jretrading.com> - 2019-06-14 15:10 +0200
Re: web page problem Kevin DAGNEAUX <kevin.dagneaux@fiitelcom.fr> - 2019-06-14 16:10 +0200
Re: web page problem Gene Heskett <gheskett@shentel.net> - 2019-06-15 03:30 +0200
Re: web page problem Gene Heskett <gheskett@shentel.net> - 2019-06-14 17:30 +0200
Re: web page problem mick crane <mick.crane@gmail.com> - 2019-06-15 12:00 +0200
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2019-06-13 21:40 +0200 |
| Subject | web page problem |
| Message-ID | <y8DJL-7XQ-7@gated-at.bofh.it> |
Greetings all; And it's my web page. My local network has several machines, most of which are managing some sort of metal/wood carving CNC machines. I just today managed to build, install and run, the latest master of LinuxCNC on a raspberry pi 3b. Now I'd like to make it available for download as debs to other pi 3b users by putting a link to that machine and the directory on it, which is sitting on an sshfs share permissioned as me. Sure, I can copy them to another dir on this machine, but I'd much rather just share the link so the user can click on what he needs (there are several language files for the docs etc there also), but I can't make the /sshnet/machine/path/to/files work for apache2 to serve up. And I am far from a web expert. So how is that done? Its another machine but its not running a server, hasn't the resources to do it, just the /sshnet access which is done as me, gene but on the pi, which is stuck by the raspian installer with pi as the first user, so its the same user number. But apache2 is running in its own sandbox and with dd-wrt standing guard at the gateway, I've no handy way around the NAT I use to let folks get to the apache2 server. So it has to come thru that pinhole. Or do I have to copy them across to a local dir I can share and chown them to match the apache2 sandboxes names? I can do that, but that also means I'd have to do it all over again when there's an update. And thats often 4 or 5 times a week! And that boggles what little short term memory I have left so I would much rather commit it to an inotifywait triggered script I can coble up in 2 or 3 hours. Suggestions gleefully tried. Thanks all; Cheers, gene. -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) If we desire respect for the law, we must first make the law respectable. - Louis D. Brandeis Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [next] | [standalone]
| From | Felix Miata <mrmazda@earthlink.net> |
|---|---|
| Date | 2019-06-13 22:10 +0200 |
| Message-ID | <y8EcN-8nb-5@gated-at.bofh.it> |
| In reply to | #209864 |
Gene Heskett composed on 2019-06-13 15:33 (UTC-0400): > I just today managed to build, install and run, the latest master of > LinuxCNC on a raspberry pi 3b. Now I'd like to make it available for > download as debs to other pi 3b users by putting a link to that machine > and the directory on it, which is sitting on an sshfs share permissioned > as me. I'm no Apache expert, but this is what I'd try: On the PC running Apache, in /etc/apache2/default.server.conf, add: Alias /urlDebSub/ "/LocalPathHostingTheDebs/" I'd expect clients wishing to download the debs to find them at: http://geneslinuxbox.net/urlDebSub/ It might suffice to instead of adding the line to default.server.conf to put them in a .conf file in /etc/apache2/conf.d/. This latter suggestion is not one I'd ever thought to try until now. -- Evolution as taught in public schools is religion, not science. Team OS/2 ** Reg. Linux User #211409 ** a11y rocks! Felix Miata *** http://fm.no-ip.com/
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2019-06-13 22:50 +0200 |
| Message-ID | <y8EPv-8r-7@gated-at.bofh.it> |
| In reply to | #209865 |
On Thursday 13 June 2019 04:03:04 pm Felix Miata wrote: Alias /urlDebSub/ "/LocalPathHostingTheDebs/" I've done that to /etc apache2/apache2.conf, and restarted it. Then because the web servers root page is at /var/www/html, and gene is the head of the data, I touched urlDebSub in /var/www/html/gene, made it owned by www-data:www-data, and modified gene/index.html accordingly. No errors, but blank page. Suspect a perms breakage someplace. I get perfect results, but www-data:www-data can't. And I can't make the whole chain a 0777. Or shouldn't. 0755 should do it, but doesn't seem to. Damn, another 1 second power failure. not long enough to kill everything, but crash it sure as hell. And its not that noisy out. Getting old, sure as tuncket its a substation regulator with burned up contacts. It will take me a few to sort things again. -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) If we desire respect for the law, we must first make the law respectable. - Louis D. Brandeis Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | Felix Miata <mrmazda@earthlink.net> |
|---|---|
| Date | 2019-06-13 23:10 +0200 |
| Message-ID | <y8F8R-u7-1@gated-at.bofh.it> |
| In reply to | #209867 |
Gene Heskett composed on 2019-06-13 16:44 (UTC-0400):
> Felix Miata wrote:
> Alias /urlDebSub/ "/LocalPathHostingTheDebs/"
> I've done that to /etc apache2/apache2.conf, and restarted it.
> Then because the web servers root page is at /var/www/html, and gene is
> the head of the data, I touched urlDebSub in /var/www/html/gene, made it
Can touch create a new directory, or only a file?
urlDebSub is an alias seen in URLs on the web, not a real directory on the Apache
server.
e.g. My screenshots are in a directory named screenshots. The alias name in
default-server.conf is /SS/, so the URL to reach the screenshots I host reads
www.mywebsite.com/SS/.
> owned by www-data:www-data, and modified gene/index.html accordingly. No
> errors, but blank page. Suspect a perms breakage someplace. I get
> perfect results, but www-data:www-data can't. And I can't make the
> whole chain a 0777. Or shouldn't. 0755 should do it, but doesn't seem
> to.
Probably need something like this:
<Directory "/LocalPathHostingTheDebs">
Options Indexes MultiViews FollowSymLinks
AllowOverride None
<IfModule !mod_access_compat.c>
Require all granted
</IfModule>
<IfModule mod_access_compat.c>
Order allow,deny
Allow from all
</IfModule>
</Directory>
--
Evolution as taught in public schools is religion, not science.
Team OS/2 ** Reg. Linux User #211409 ** a11y rocks!
Felix Miata *** http://fm.no-ip.com/
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2019-06-14 00:20 +0200 |
| Message-ID | <y8GeC-17P-3@gated-at.bofh.it> |
| In reply to | #209868 |
On Thursday 13 June 2019 05:09:35 pm Felix Miata wrote: > Gene Heskett composed on 2019-06-13 16:44 (UTC-0400): > > Felix Miata wrote: > > > > Alias /urlDebSub/ "/LocalPathHostingTheDebs/" > > > > I've done that to /etc apache2/apache2.conf, and restarted it. > > > > Then because the web servers root page is at /var/www/html, and gene > > is the head of the data, I touched urlDebSub in /var/www/html/gene, > > made it > > Can touch create a new directory, or only a file? > > urlDebSub is an alias seen in URLs on the web, not a real directory on > the Apache server. > > e.g. My screenshots are in a directory named screenshots. The alias > name in default-server.conf is /SS/, so the URL to reach the > screenshots I host reads www.mywebsite.com/SS/. > > > owned by www-data:www-data, and modified gene/index.html > > accordingly. No errors, but blank page. Suspect a perms breakage > > someplace. I get perfect results, but www-data:www-data can't. And > > I can't make the whole chain a 0777. Or shouldn't. 0755 should do > > it, but doesn't seem to. > > Probably need something like this: > > <Directory "/LocalPathHostingTheDebs"> > Options Indexes MultiViews FollowSymLinks > AllowOverride None > <IfModule !mod_access_compat.c> > Require all granted > </IfModule> > <IfModule mod_access_compat.c> > Order allow,deny > Allow from all > </IfModule> > </Directory> looks good, but the problem is, only gene=user 1000 has any rights to follow that path, so this access must be done as gene, not the default www-data:www-data, or even as the parent session of apache2.. Is there an "as user=gene" command that can be used only for this stanza that I can put in this stanza? root cannot go up this path to see anything, neither can www-data. Is this a place where making gene a member of group www-data would help? No, I just looked and I am already a member of that group. Help, I've built a sandbox not even root can get into!!! And since apache2 doesn't believe in man pages, what do they use instead of? -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) If we desire respect for the law, we must first make the law respectable. - Louis D. Brandeis Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <wooledg@eeg.ccf.org> |
|---|---|
| Date | 2019-06-14 14:50 +0200 |
| Message-ID | <y8TOx-Mv-3@gated-at.bofh.it> |
| In reply to | #209870 |
On Thu, Jun 13, 2019 at 06:11:03PM -0400, Gene Heskett wrote: > looks good, but the problem is, only gene=user 1000 has any rights to > follow that path, so this access must be done as gene, not the default > www-data:www-data, or even as the parent session of apache2.. So change the ownership/permissions on the content. To serve it up from a web server, you need to make it world-readable. This means that directories require the x bit, and files require the r bit, for the "other" (right-most characters in ls -l output, least significant bits in the octal mode). In other words, 711 or 755 on the directories, and 644 on the files. > Is there > an "as user=gene" command that can be used only for this stanza that I > can put in this stanza? root cannot go up this path to see anything, > neither can www-data. If root can't see the files, that means you're dealing with some kind of remote file system, like NFS? If so, you really need to state the full relevant details up front. If you need to change permissions on an NFS-mounted file system that you're serving up through a web server on the NFS client system, then you'll need to make the changes *on* the NFS server, or as the owner of the files on the NFS client. By the way, I recommend running the web server from the same box where the files reside if at all possible, just for efficiency and sanity. > Is this a place where making gene a member of group www-data would help? No. Longer answer: each process has its own UID, GID and list of supplementary groups. If the apache worker process that tries to read your content is running as UID www-data and GID www-data with no supplementary groups, then the *only* permissions that matter are the "other" permissions on the file (those always matter), or the "group" permissions if the *FILE* belongs to group www-data (sounds like this is not the case), or the "user" permissions if the *FILE* belongs to user www-data (definitely not the case). When you "add user gene to group www-data", this has absolutely zero effect on a process that is running as user www-data/group www-data. (Daemons are launched by lower-level system processes that do not give half a flip about what groups users are "in" in /etc/group.) The only effect that your group addition has is on *logins* made by the user named gene. Future login sessions for gene will have one more group added to their list of supplementary groups. Adding a user to a group has no effect on files that you own. Each file has one user-owner, one group-owner, one octal mode number declaring yes/no permissions for user/group/owner, and some ACL crap that I *really* am not going to get into here. Suffice to say, "adding a user to a group" is not a thing that file systems or the files in them care about. Adding a user to a group has no effect on the privileges of daemons that are started by your init system. It *does* appear to affect the group membership of your at jobs, though. I didn't test cron, and of course neither cron(8) nor crontab(1) tells me whether it affects cron jobs, because why would they mention something important like the privileges of your running jobs....
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2019-06-14 15:00 +0200 |
| Message-ID | <y8TYd-PH-5@gated-at.bofh.it> |
| In reply to | #209896 |
[Multipart message — attachments visible in raw view] — view raw
On Fri, Jun 14, 2019 at 08:46:51AM -0400, Greg Wooledge wrote: > On Thu, Jun 13, 2019 at 06:11:03PM -0400, Gene Heskett wrote: > > looks good, but the problem is, only gene=user 1000 has any rights to > > follow that path, so this access must be done as gene, not the default > > www-data:www-data, or even as the parent session of apache2.. > > So change the ownership/permissions on the content. To serve it up > from a web server, you need to make it world-readable. This means that > directories require the x bit, and files require the r bit, for the > "other" (right-most characters in ls -l output, least significant bits > in the octal mode). Perhaps group readable (074x, x being usually 0) and setting the file's group would suffice? That's my standard setup: the files belong to a "www admin" (can be a regular user, can be root) and have the group www-data. So the web server hasn't (usually) write access to normal htmls and cgi-bins (oh, for the last, execute access for the group is necessary, so 075x. Better safe than... Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <wooledg@eeg.ccf.org> |
|---|---|
| Date | 2019-06-14 15:10 +0200 |
| Message-ID | <y8U7T-18o-3@gated-at.bofh.it> |
| In reply to | #209898 |
On Fri, Jun 14, 2019 at 02:58:05PM +0200, tomas@tuxteam.de wrote: > That's my standard setup: the files belong to a "www admin" (can be a > regular user, can be root) and have the group www-data. So the web > server hasn't (usually) write access to normal htmls and cgi-bins > (oh, for the last, execute access for the group is necessary, so 075x. Changing the group-owner of the files is one possible approach, yes. However, I prefer to remind myself that if I put something on the web, the entire world can see it. So any attempt to restrict who can read the files on my local system would be entirely pointless, if they can simply read them on the world wide web instead. Thus, making the files world-readable is completely rational. And saves you the headaches and hassles of managing group permissions and umasks and so on. (However, those headaches may return if you are trying to allow multiple people administrative access to the content. That's a separate issue.)
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2019-06-15 03:20 +0200 |
| Message-ID | <y95wl-7Y2-1@gated-at.bofh.it> |
| In reply to | #209899 |
On Friday 14 June 2019 09:04:22 am Greg Wooledge wrote: > On Fri, Jun 14, 2019 at 02:58:05PM +0200, tomas@tuxteam.de wrote: > > That's my standard setup: the files belong to a "www admin" (can be > > a regular user, can be root) and have the group www-data. So the web > > server hasn't (usually) write access to normal htmls and cgi-bins > > (oh, for the last, execute access for the group is necessary, so > > 075x. > > Changing the group-owner of the files is one possible approach, yes. > > However, I prefer to remind myself that if I put something on the web, > the entire world can see it. So any attempt to restrict who can read > the files on my local system would be entirely pointless, if they can > simply read them on the world wide web instead. That is the intended scenario. The problem was in getting the files to a place where I could manipulate the rights, then move them to where they could be seen on my web page. They can now be accessed by the world, although its not something most would try to do with a pi. Realtime kernels for armhf, aren't that great, often giving IRQ delays of several milliseconds. But at the speeds of a bigger lathe, its actually "good enough for the girls I go with". Although its customary to run a threading tap at whats a good cutting speed, when rigid tapping on a lathe, one must consider the weight of the spinning chuck, which at 40 lbs, can cause quite a delay between issuing the reverse command at the bottom of the hole, the overshoot can run the tap into the bottom of the hole, lock it and break it. Its possible to measure this over shoot while cutting air, which I am going, and offset the reversal point, which I am doing by hand, but its also possible to make it automatic, something I've yet to attempt to do, but on paper looks easy enough. But realistically, 300 revs and a 40 lb chuck is making the drive belts yelp at reverse time now, with just a 1 hp motor. Overshoot is about 3.5 turns, so thats a good indicator to slow it some more. But the fact that I have done it, can do it with a 70 year old formerly manual machine does drop jaws. I'll readily admit I like to impress any visiting frogs there may be. :) > Thus, making the files world-readable is completely rational. And > saves you the headaches and hassles of managing group permissions and > umasks and so on. (However, those headaches may return if you are > trying to allow multiple people administrative access to the content. > That's a separate issue.) And as long as I am still sucking air, I am the lone admin. Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) If we desire respect for the law, we must first make the law respectable. - Louis D. Brandeis Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | Joe <joe@jretrading.com> |
|---|---|
| Date | 2019-06-14 15:10 +0200 |
| Message-ID | <y8U7T-18o-5@gated-at.bofh.it> |
| In reply to | #209898 |
On Fri, 14 Jun 2019 14:58:05 +0200 <tomas@tuxteam.de> wrote: > On Fri, Jun 14, 2019 at 08:46:51AM -0400, Greg Wooledge wrote: > > On Thu, Jun 13, 2019 at 06:11:03PM -0400, Gene Heskett wrote: > > > looks good, but the problem is, only gene=user 1000 has any > > > rights to follow that path, so this access must be done as gene, > > > not the default www-data:www-data, or even as the parent session > > > of apache2.. > > > > So change the ownership/permissions on the content. To serve it up > > from a web server, you need to make it world-readable. This means > > that directories require the x bit, and files require the r bit, > > for the "other" (right-most characters in ls -l output, least > > significant bits in the octal mode). > > Perhaps group readable (074x, x being usually 0) and setting the > file's group would suffice? > > That's my standard setup: the files belong to a "www admin" (can be a > regular user, can be root) and have the group www-data. So the web > server hasn't (usually) write access to normal htmls and cgi-bins > (oh, for the last, execute access for the group is necessary, so 075x. > > Better safe than... > Even safer, post/run it on someone else's web server. Web space is no longer given away free by (most) ISPs, but a small amount can be had for 'hobby' money now. -- Joe
[toc] | [prev] | [next] | [standalone]
| From | Kevin DAGNEAUX <kevin.dagneaux@fiitelcom.fr> |
|---|---|
| Date | 2019-06-14 16:10 +0200 |
| Message-ID | <y8V3Y-1H0-5@gated-at.bofh.it> |
| In reply to | #209900 |
[Multipart message — attachments visible in raw view] — view raw
Le 14/06/2019 à 15:04, Joe a écrit : > On Fri, 14 Jun 2019 14:58:05 +0200 > <tomas@tuxteam.de> wrote: > >> On Fri, Jun 14, 2019 at 08:46:51AM -0400, Greg Wooledge wrote: >>> On Thu, Jun 13, 2019 at 06:11:03PM -0400, Gene Heskett wrote: >>>> looks good, but the problem is, only gene=user 1000 has any >>>> rights to follow that path, so this access must be done as gene, >>>> not the default www-data:www-data, or even as the parent session >>>> of apache2.. >>> So change the ownership/permissions on the content. To serve it up >>> from a web server, you need to make it world-readable. This means >>> that directories require the x bit, and files require the r bit, >>> for the "other" (right-most characters in ls -l output, least >>> significant bits in the octal mode). >> Perhaps group readable (074x, x being usually 0) and setting the >> file's group would suffice? >> >> That's my standard setup: the files belong to a "www admin" (can be a >> regular user, can be root) and have the group www-data. So the web >> server hasn't (usually) write access to normal htmls and cgi-bins >> (oh, for the last, execute access for the group is necessary, so 075x. >> >> Better safe than... >> > Even safer, post/run it on someone else's web server. Web space is no > longer given away free by (most) ISPs, but a small amount can be had for > 'hobby' money now. Another approch is to use apache mpm itk
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2019-06-15 03:30 +0200 |
| Message-ID | <y95G1-81b-1@gated-at.bofh.it> |
| In reply to | #209900 |
On Friday 14 June 2019 09:04:50 am Joe wrote: > On Fri, 14 Jun 2019 14:58:05 +0200 > > <tomas@tuxteam.de> wrote: > > On Fri, Jun 14, 2019 at 08:46:51AM -0400, Greg Wooledge wrote: > > > On Thu, Jun 13, 2019 at 06:11:03PM -0400, Gene Heskett wrote: > > > > looks good, but the problem is, only gene=user 1000 has any > > > > rights to follow that path, so this access must be done as gene, > > > > not the default www-data:www-data, or even as the parent session > > > > of apache2.. > > > > > > So change the ownership/permissions on the content. To serve it > > > up from a web server, you need to make it world-readable. This > > > means that directories require the x bit, and files require the r > > > bit, for the "other" (right-most characters in ls -l output, least > > > significant bits in the octal mode). > > > > Perhaps group readable (074x, x being usually 0) and setting the > > file's group would suffice? > > > > That's my standard setup: the files belong to a "www admin" (can be > > a regular user, can be root) and have the group www-data. So the web > > server hasn't (usually) write access to normal htmls and cgi-bins > > (oh, for the last, execute access for the group is necessary, so > > 075x. > > > > Better safe than... > > Even safer, post/run it on someone else's web server. Web space is no > longer given away free by (most) ISPs, but a small amount can be had > for 'hobby' money now. The pro and cons are in favor of doing it myself just for the total control. The only sufferer is the one that wants to download my work as the uplink speed is noticeably slower. But he still gets it for only his bandwidth/time cost. But because most ISP's think we are dumber than rocks, they block incoming port 80. But I am also a fan of the Hitachi 6309, a cmos and smarter clone of the moto 6809, but with fringies thrown in, hence the tongue-in-cheek use of port 6309 to run my web server on. Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) If we desire respect for the law, we must first make the law respectable. - Louis D. Brandeis Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2019-06-14 17:30 +0200 |
| Message-ID | <y8Wjn-2mW-5@gated-at.bofh.it> |
| In reply to | #209896 |
On Friday 14 June 2019 08:46:51 am Greg Wooledge wrote: > On Thu, Jun 13, 2019 at 06:11:03PM -0400, Gene Heskett wrote: > > looks good, but the problem is, only gene=user 1000 has any rights > > to follow that path, so this access must be done as gene, not the > > default www-data:www-data, or even as the parent session of > > apache2.. > So in the end I copied the debs to a /home/gene/subdir made to catch them, and changed the ownership of the subdir and contents to www-data, then moved the whole thing to /var/www/html/gene/subdir, and added that to the <a href "####",statement> and they can now be downloaded by interested parties. > So change the ownership/permissions on the content. To serve it up > from a web server, you need to make it world-readable. This means > that directories require the x bit, and files require the r bit, for > the "other" (right-most characters in ls -l output, least significant > bits in the octal mode). > > In other words, 711 or 755 on the directories, and 644 on the files. > > > Is there > > an "as user=gene" command that can be used only for this stanza that > > I can put in this stanza? root cannot go up this path to see > > anything, neither can www-data. > > If root can't see the files, that means you're dealing with some kind > of remote file system, like NFS? If so, you really need to state the > full relevant details up front. Not NFS, its too wibbly, works only with the right phase of the moon and your astrological period or some such. But an sshfs mount as me Just Works. Because one of those isn't yet set for passwordless key file access, I get asked for my password once, so this file has to be run by hand: #!/bin/bash sshfs gene@shop:/ /sshnet/shop sshfs gene@lathe:/ /sshnet/lathe sshfs gene@GO704:/ /sshnet/GO704 sshfs pi@picnc:/ /sshnet/picnc sshfs gene@rock64:/ /sshnet/rock64 I keep a bunch of that sort of stuff in ~/gene/bin, which is first in my $PATH. And I just got a lunch order from my missus. later. > > If you need to change permissions on an NFS-mounted file system that > you're serving up through a web server on the NFS client system, then > you'll need to make the changes *on* the NFS server, or as the owner > of the files on the NFS client. > > By the way, I recommend running the web server from the same box where > the files reside if at all possible, just for efficiency and sanity. > > > Is this a place where making gene a member of group www-data would > > help? > > No. > > Longer answer: each process has its own UID, GID and list of > supplementary groups. If the apache worker process that tries to read > your content is running as UID www-data and GID www-data with no > supplementary groups, then the *only* permissions that matter are the > "other" permissions on the file (those always matter), or the "group" > permissions if the *FILE* belongs to group www-data (sounds like this > is not the case), or the "user" permissions if the *FILE* belongs to > user www-data (definitely not the case). > > When you "add user gene to group www-data", this has absolutely zero > effect on a process that is running as user www-data/group www-data. > (Daemons are launched by lower-level system processes that do not give > half a flip about what groups users are "in" in /etc/group.) The only > effect that your group addition has is on *logins* made by the user > named gene. Future login sessions for gene will have one more group > added to their list of supplementary groups. > > Adding a user to a group has no effect on files that you own. Each > file has one user-owner, one group-owner, one octal mode number > declaring yes/no permissions for user/group/owner, and some ACL crap > that I *really* am not going to get into here. Suffice to say, > "adding a user to a group" is not a thing that file systems or the > files in them care about. > > Adding a user to a group has no effect on the privileges of daemons > that are started by your init system. So it would appear now. With wheezy it was useally the fix. > It *does* appear to affect the group membership of your at jobs, > though. I didn't test cron, and of course neither cron(8) nor > crontab(1) tells me whether it affects cron jobs, because why would > they mention something important like the privileges of your running > jobs.... Good question, because I have another perms problem that is preventing awfull from generating any data from looking at the apache2 logs, and again it worked flawlessly on wheezy. Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) If we desire respect for the law, we must first make the law respectable. - Louis D. Brandeis Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | mick crane <mick.crane@gmail.com> |
|---|---|
| Date | 2019-06-15 12:00 +0200 |
| Message-ID | <y9dDz-4h7-1@gated-at.bofh.it> |
| In reply to | #209864 |
On 2019-06-13 20:33, Gene Heskett wrote: > Greetings all; > > And it's my web page. > > Or do I have to copy them across to a local dir I can share and chown > them to match the apache2 sandboxes names? Don't know if supposed to but can put a soft link in /var/www/html pointing to directory anywhere readable by group www-data. -- Key ID 4BFEBB31
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web