Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #209864 > unrolled thread

web page problem

Started byGene Heskett <gheskett@shentel.net>
First post2019-06-13 21:40 +0200
Last post2019-06-15 12:00 +0200
Articles 14 — 7 participants

Back to article view | Back to linux.debian.user


Contents

  web page problem Gene Heskett <gheskett@shentel.net> - 2019-06-13 21:40 +0200
    Re: web page problem Felix Miata <mrmazda@earthlink.net> - 2019-06-13 22:10 +0200
      Re: web page problem Gene Heskett <gheskett@shentel.net> - 2019-06-13 22:50 +0200
        Re: web page problem Felix Miata <mrmazda@earthlink.net> - 2019-06-13 23:10 +0200
          Re: web page problem Gene Heskett <gheskett@shentel.net> - 2019-06-14 00:20 +0200
            Re: web page problem Greg Wooledge <wooledg@eeg.ccf.org> - 2019-06-14 14:50 +0200
              Re: web page problem <tomas@tuxteam.de> - 2019-06-14 15:00 +0200
                Re: web page problem Greg Wooledge <wooledg@eeg.ccf.org> - 2019-06-14 15:10 +0200
                  Re: web page problem Gene Heskett <gheskett@shentel.net> - 2019-06-15 03:20 +0200
                Re: web page problem Joe <joe@jretrading.com> - 2019-06-14 15:10 +0200
                  Re: web page problem Kevin DAGNEAUX <kevin.dagneaux@fiitelcom.fr> - 2019-06-14 16:10 +0200
                  Re: web page problem Gene Heskett <gheskett@shentel.net> - 2019-06-15 03:30 +0200
              Re: web page problem Gene Heskett <gheskett@shentel.net> - 2019-06-14 17:30 +0200
    Re: web page problem mick crane <mick.crane@gmail.com> - 2019-06-15 12:00 +0200

#209864 — web page problem

FromGene Heskett <gheskett@shentel.net>
Date2019-06-13 21:40 +0200
Subjectweb page problem
Message-ID<y8DJL-7XQ-7@gated-at.bofh.it>
Greetings all;

And it's my web page.

My local network has several machines, most of which are managing some 
sort of metal/wood carving CNC machines.

I just today managed to build, install and run, the latest master of 
LinuxCNC on a raspberry pi 3b. Now I'd like to make it available for 
download as debs to other pi 3b users by putting a link to that machine 
and the directory on it, which is sitting on an sshfs share permissioned 
as me.

Sure, I can copy them to another dir on this machine, but I'd much rather 
just share the link so the user can click on what he needs (there are 
several language files for the docs etc there also), but I can't make 
the /sshnet/machine/path/to/files work for apache2 to serve up.  And I 
am far from a web expert.

So how is that done? Its another machine but its not running a server, 
hasn't the resources to do it, just the /sshnet access which is done as 
me, gene but on the pi, which is stuck by the raspian installer with pi 
as the first user, so its the same user number.  But apache2 is running 
in its own sandbox and with dd-wrt standing guard at the gateway, I've 
no handy way around the NAT I use to let folks get to the apache2 
server.  So it has to come thru that pinhole.

Or do I have to copy them across to a local dir I can share and chown 
them to match the apache2 sandboxes names? I can do that, but that also 
means I'd have to do it all over again when there's an update.  And 
thats often 4 or 5 times a week! And that boggles what little short term 
memory I have left so I would much rather commit it to an inotifywait 
triggered script I can coble up in 2 or 3 hours.

Suggestions gleefully tried.

Thanks all;

Cheers, gene.

-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
If we desire respect for the law, we must first make the law respectable.
 - Louis D. Brandeis
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [next] | [standalone]


#209865

FromFelix Miata <mrmazda@earthlink.net>
Date2019-06-13 22:10 +0200
Message-ID<y8EcN-8nb-5@gated-at.bofh.it>
In reply to#209864
Gene Heskett composed on 2019-06-13 15:33 (UTC-0400):

> I just today managed to build, install and run, the latest master of 
> LinuxCNC on a raspberry pi 3b. Now I'd like to make it available for 
> download as debs to other pi 3b users by putting a link to that machine 
> and the directory on it, which is sitting on an sshfs share permissioned 
> as me.
I'm no Apache expert, but this is what I'd try:

On the PC running Apache, in /etc/apache2/default.server.conf, add:

	Alias	/urlDebSub/ "/LocalPathHostingTheDebs/"

I'd expect clients wishing to download the debs to find them at:

	http://geneslinuxbox.net/urlDebSub/

It might suffice to instead of adding the line to default.server.conf to put them
in a .conf file in /etc/apache2/conf.d/. This latter suggestion is not one I'd
ever thought to try until now.
-- 
Evolution as taught in public schools is religion, not science.

 Team OS/2 ** Reg. Linux User #211409 ** a11y rocks!

Felix Miata  ***  http://fm.no-ip.com/

[toc] | [prev] | [next] | [standalone]


#209867

FromGene Heskett <gheskett@shentel.net>
Date2019-06-13 22:50 +0200
Message-ID<y8EPv-8r-7@gated-at.bofh.it>
In reply to#209865
On Thursday 13 June 2019 04:03:04 pm Felix Miata wrote:

Alias   /urlDebSub/ "/LocalPathHostingTheDebs/"

I've done that to /etc apache2/apache2.conf, and restarted it.

Then because the web servers root page is at /var/www/html, and gene is 
the head of the data, I touched urlDebSub in /var/www/html/gene, made it 
owned by www-data:www-data, and modified gene/index.html accordingly. No 
errors, but blank page. Suspect a perms breakage someplace. I get 
perfect results, but www-data:www-data can't.  And I can't make the 
whole chain a 0777. Or shouldn't. 0755 should do it, but doesn't seem 
to.

Damn, another 1 second power failure. not long enough to kill everything, 
but crash it sure as hell.  And its not that noisy out. Getting old, 
sure as tuncket its a substation regulator with burned up contacts. It 
will take me a few to sort things again.


-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
If we desire respect for the law, we must first make the law respectable.
 - Louis D. Brandeis
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#209868

FromFelix Miata <mrmazda@earthlink.net>
Date2019-06-13 23:10 +0200
Message-ID<y8F8R-u7-1@gated-at.bofh.it>
In reply to#209867
Gene Heskett composed on 2019-06-13 16:44 (UTC-0400):

> Felix Miata wrote:

> Alias   /urlDebSub/ "/LocalPathHostingTheDebs/"

> I've done that to /etc apache2/apache2.conf, and restarted it.

> Then because the web servers root page is at /var/www/html, and gene is 
> the head of the data, I touched urlDebSub in /var/www/html/gene, made it 

Can touch create a new directory, or only a file?

urlDebSub is an alias seen in URLs on the web, not a real directory on the Apache
server.

e.g. My screenshots are in a directory named screenshots. The alias name in
default-server.conf is /SS/, so the URL to reach the screenshots I host reads
www.mywebsite.com/SS/.

> owned by www-data:www-data, and modified gene/index.html accordingly. No 
> errors, but blank page. Suspect a perms breakage someplace. I get 
> perfect results, but www-data:www-data can't.  And I can't make the 
> whole chain a 0777. Or shouldn't. 0755 should do it, but doesn't seem 
> to.
Probably need something like this:

<Directory "/LocalPathHostingTheDebs">
 Options Indexes MultiViews FollowSymLinks
 AllowOverride None
        <IfModule !mod_access_compat.c>
                Require all granted
        </IfModule>
        <IfModule mod_access_compat.c>
                Order allow,deny
                Allow from all
        </IfModule>
</Directory>
-- 
Evolution as taught in public schools is religion, not science.

 Team OS/2 ** Reg. Linux User #211409 ** a11y rocks!

Felix Miata  ***  http://fm.no-ip.com/

[toc] | [prev] | [next] | [standalone]


#209870

FromGene Heskett <gheskett@shentel.net>
Date2019-06-14 00:20 +0200
Message-ID<y8GeC-17P-3@gated-at.bofh.it>
In reply to#209868
On Thursday 13 June 2019 05:09:35 pm Felix Miata wrote:

> Gene Heskett composed on 2019-06-13 16:44 (UTC-0400):
> > Felix Miata wrote:
> >
> > Alias   /urlDebSub/ "/LocalPathHostingTheDebs/"
> >
> > I've done that to /etc apache2/apache2.conf, and restarted it.
> >
> > Then because the web servers root page is at /var/www/html, and gene
> > is the head of the data, I touched urlDebSub in /var/www/html/gene,
> > made it
>
> Can touch create a new directory, or only a file?
>
> urlDebSub is an alias seen in URLs on the web, not a real directory on
> the Apache server.
>
> e.g. My screenshots are in a directory named screenshots. The alias
> name in default-server.conf is /SS/, so the URL to reach the
> screenshots I host reads www.mywebsite.com/SS/.
>
> > owned by www-data:www-data, and modified gene/index.html
> > accordingly. No errors, but blank page. Suspect a perms breakage
> > someplace. I get perfect results, but www-data:www-data can't.  And
> > I can't make the whole chain a 0777. Or shouldn't. 0755 should do
> > it, but doesn't seem to.
>
> Probably need something like this:
>
> <Directory "/LocalPathHostingTheDebs">
>  Options Indexes MultiViews FollowSymLinks
>  AllowOverride None
>         <IfModule !mod_access_compat.c>
>                 Require all granted
>         </IfModule>
>         <IfModule mod_access_compat.c>
>                 Order allow,deny
>                 Allow from all
>         </IfModule>
> </Directory>
looks good, but the problem is, only gene=user 1000 has any rights to 
follow that path, so this access must be done as gene, not the default 
www-data:www-data, or even as the parent session of apache2.. Is there 
an "as user=gene" command that can be used only for this stanza that I 
can put in this stanza?  root cannot go up this path to see anything,  
neither can www-data.

Is this a place where making gene a member of group www-data would help? 
No, I just looked and I am already a member of that group. 

Help, I've built a sandbox not even root can get into!!!

And since apache2 doesn't believe in man pages, what do they use instead 
of?


-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
If we desire respect for the law, we must first make the law respectable.
 - Louis D. Brandeis
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#209896

FromGreg Wooledge <wooledg@eeg.ccf.org>
Date2019-06-14 14:50 +0200
Message-ID<y8TOx-Mv-3@gated-at.bofh.it>
In reply to#209870
On Thu, Jun 13, 2019 at 06:11:03PM -0400, Gene Heskett wrote:
> looks good, but the problem is, only gene=user 1000 has any rights to 
> follow that path, so this access must be done as gene, not the default 
> www-data:www-data, or even as the parent session of apache2..

So change the ownership/permissions on the content.  To serve it up
from a web server, you need to make it world-readable.  This means that
directories require the x bit, and files require the r bit, for the
"other" (right-most characters in ls -l output, least significant bits
in the octal mode).

In other words, 711 or 755 on the directories, and 644 on the files.

> Is there 
> an "as user=gene" command that can be used only for this stanza that I 
> can put in this stanza?  root cannot go up this path to see anything,  
> neither can www-data.

If root can't see the files, that means you're dealing with some kind
of remote file system, like NFS?  If so, you really need to state the
full relevant details up front.

If you need to change permissions on an NFS-mounted file system that
you're serving up through a web server on the NFS client system, then
you'll need to make the changes *on* the NFS server, or as the owner
of the files on the NFS client.

By the way, I recommend running the web server from the same box where
the files reside if at all possible, just for efficiency and sanity.

> Is this a place where making gene a member of group www-data would help? 

No.

Longer answer: each process has its own UID, GID and list of supplementary
groups.  If the apache worker process that tries to read your content is
running as UID www-data and GID www-data with no supplementary groups,
then the *only* permissions that matter are the "other" permissions on
the file (those always matter), or the "group" permissions if the *FILE*
belongs to group www-data (sounds like this is not the case), or the
"user" permissions if the *FILE* belongs to user www-data (definitely
not the case).

When you "add user gene to group www-data", this has absolutely zero
effect on a process that is running as user www-data/group www-data.
(Daemons are launched by lower-level system processes that do not give
half a flip about what groups users are "in" in /etc/group.)  The only
effect that your group addition has is on *logins* made by the user
named gene.  Future login sessions for gene will have one more group
added to their list of supplementary groups.

Adding a user to a group has no effect on files that you own.  Each file
has one user-owner, one group-owner, one octal mode number declaring
yes/no permissions for user/group/owner, and some ACL crap that I *really*
am not going to get into here.  Suffice to say, "adding a user to a group"
is not a thing that file systems or the files in them care about.

Adding a user to a group has no effect on the privileges of daemons
that are started by your init system.

It *does* appear to affect the group membership of your at jobs, though.
I didn't test cron, and of course neither cron(8) nor crontab(1) tells me
whether it affects cron jobs, because why would they mention something
important like the privileges of your running jobs....

[toc] | [prev] | [next] | [standalone]


#209898

From<tomas@tuxteam.de>
Date2019-06-14 15:00 +0200
Message-ID<y8TYd-PH-5@gated-at.bofh.it>
In reply to#209896

[Multipart message — attachments visible in raw view] — view raw

On Fri, Jun 14, 2019 at 08:46:51AM -0400, Greg Wooledge wrote:
> On Thu, Jun 13, 2019 at 06:11:03PM -0400, Gene Heskett wrote:
> > looks good, but the problem is, only gene=user 1000 has any rights to 
> > follow that path, so this access must be done as gene, not the default 
> > www-data:www-data, or even as the parent session of apache2..
> 
> So change the ownership/permissions on the content.  To serve it up
> from a web server, you need to make it world-readable.  This means that
> directories require the x bit, and files require the r bit, for the
> "other" (right-most characters in ls -l output, least significant bits
> in the octal mode).

Perhaps group readable (074x, x being usually 0) and setting the file's
group would suffice?

That's my standard setup: the files belong to a "www admin" (can be a
regular user, can be root) and have the group www-data. So the web
server hasn't (usually) write access to normal htmls and cgi-bins
(oh, for the last, execute access for the group is necessary, so 075x.

Better safe than...

Cheers
-- t

[toc] | [prev] | [next] | [standalone]


#209899

FromGreg Wooledge <wooledg@eeg.ccf.org>
Date2019-06-14 15:10 +0200
Message-ID<y8U7T-18o-3@gated-at.bofh.it>
In reply to#209898
On Fri, Jun 14, 2019 at 02:58:05PM +0200, tomas@tuxteam.de wrote:
> That's my standard setup: the files belong to a "www admin" (can be a
> regular user, can be root) and have the group www-data. So the web
> server hasn't (usually) write access to normal htmls and cgi-bins
> (oh, for the last, execute access for the group is necessary, so 075x.

Changing the group-owner of the files is one possible approach, yes.

However, I prefer to remind myself that if I put something on the web,
the entire world can see it.  So any attempt to restrict who can read
the files on my local system would be entirely pointless, if they can
simply read them on the world wide web instead.

Thus, making the files world-readable is completely rational.  And saves
you the headaches and hassles of managing group permissions and umasks
and so on.  (However, those headaches may return if you are trying to
allow multiple people administrative access to the content.  That's a
separate issue.)

[toc] | [prev] | [next] | [standalone]


#209915

FromGene Heskett <gheskett@shentel.net>
Date2019-06-15 03:20 +0200
Message-ID<y95wl-7Y2-1@gated-at.bofh.it>
In reply to#209899
On Friday 14 June 2019 09:04:22 am Greg Wooledge wrote:

> On Fri, Jun 14, 2019 at 02:58:05PM +0200, tomas@tuxteam.de wrote:
> > That's my standard setup: the files belong to a "www admin" (can be
> > a regular user, can be root) and have the group www-data. So the web
> > server hasn't (usually) write access to normal htmls and cgi-bins
> > (oh, for the last, execute access for the group is necessary, so
> > 075x.
>
> Changing the group-owner of the files is one possible approach, yes.
>
> However, I prefer to remind myself that if I put something on the web,
> the entire world can see it.  So any attempt to restrict who can read
> the files on my local system would be entirely pointless, if they can
> simply read them on the world wide web instead.

That is the intended scenario. The problem was in getting the files to a 
place where I could manipulate the rights, then move them to where they 
could be seen on my web page. They can now be accessed by the world, 
although its not something most would try to do with a pi. Realtime 
kernels for armhf, aren't that great, often giving IRQ delays of several 
milliseconds. But at the speeds of a bigger lathe, its actually "good 
enough for the girls I go with".

Although its customary to run a threading tap at whats a good cutting 
speed, when rigid tapping on a lathe, one must consider the weight of 
the spinning chuck, which at 40 lbs, can cause quite a delay between 
issuing the reverse command at the bottom of the hole, the overshoot can 
run the tap into the bottom of the hole, lock it and break it. Its 
possible to measure this over shoot while cutting air, which I am going, 
and offset the reversal point, which I am doing by hand, but its also 
possible to make it automatic, something I've yet to attempt to do, but 
on paper looks easy enough. But realistically, 300 revs and a 40 lb 
chuck is making the drive belts yelp at reverse time now, with just a 1 
hp motor. Overshoot is about 3.5 turns, so thats a good indicator to 
slow it some more.  But the fact that I have done it, can do it with a 
70 year old formerly manual machine does drop jaws.  I'll readily admit 
I like to impress any visiting frogs there may be. :)

> Thus, making the files world-readable is completely rational.  And
> saves you the headaches and hassles of managing group permissions and
> umasks and so on.  (However, those headaches may return if you are
> trying to allow multiple people administrative access to the content. 
> That's a separate issue.)

And as long as I am still sucking air, I am the lone admin.

Cheers, Gene Heskett
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
If we desire respect for the law, we must first make the law respectable.
 - Louis D. Brandeis
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#209900

FromJoe <joe@jretrading.com>
Date2019-06-14 15:10 +0200
Message-ID<y8U7T-18o-5@gated-at.bofh.it>
In reply to#209898
On Fri, 14 Jun 2019 14:58:05 +0200
<tomas@tuxteam.de> wrote:

> On Fri, Jun 14, 2019 at 08:46:51AM -0400, Greg Wooledge wrote:
> > On Thu, Jun 13, 2019 at 06:11:03PM -0400, Gene Heskett wrote:  
> > > looks good, but the problem is, only gene=user 1000 has any
> > > rights to follow that path, so this access must be done as gene,
> > > not the default www-data:www-data, or even as the parent session
> > > of apache2..  
> > 
> > So change the ownership/permissions on the content.  To serve it up
> > from a web server, you need to make it world-readable.  This means
> > that directories require the x bit, and files require the r bit,
> > for the "other" (right-most characters in ls -l output, least
> > significant bits in the octal mode).  
> 
> Perhaps group readable (074x, x being usually 0) and setting the
> file's group would suffice?
> 
> That's my standard setup: the files belong to a "www admin" (can be a
> regular user, can be root) and have the group www-data. So the web
> server hasn't (usually) write access to normal htmls and cgi-bins
> (oh, for the last, execute access for the group is necessary, so 075x.
> 
> Better safe than...
> 

Even safer, post/run it on someone else's web server. Web space is no
longer given away free by (most) ISPs, but a small amount can be had for
'hobby' money now.

-- 
Joe

[toc] | [prev] | [next] | [standalone]


#209902

FromKevin DAGNEAUX <kevin.dagneaux@fiitelcom.fr>
Date2019-06-14 16:10 +0200
Message-ID<y8V3Y-1H0-5@gated-at.bofh.it>
In reply to#209900

[Multipart message — attachments visible in raw view] — view raw

Le 14/06/2019 à 15:04, Joe a écrit :
> On Fri, 14 Jun 2019 14:58:05 +0200
> <tomas@tuxteam.de> wrote:
>
>> On Fri, Jun 14, 2019 at 08:46:51AM -0400, Greg Wooledge wrote:
>>> On Thu, Jun 13, 2019 at 06:11:03PM -0400, Gene Heskett wrote:
>>>> looks good, but the problem is, only gene=user 1000 has any
>>>> rights to follow that path, so this access must be done as gene,
>>>> not the default www-data:www-data, or even as the parent session
>>>> of apache2..
>>> So change the ownership/permissions on the content.  To serve it up
>>> from a web server, you need to make it world-readable.  This means
>>> that directories require the x bit, and files require the r bit,
>>> for the "other" (right-most characters in ls -l output, least
>>> significant bits in the octal mode).
>> Perhaps group readable (074x, x being usually 0) and setting the
>> file's group would suffice?
>>
>> That's my standard setup: the files belong to a "www admin" (can be a
>> regular user, can be root) and have the group www-data. So the web
>> server hasn't (usually) write access to normal htmls and cgi-bins
>> (oh, for the last, execute access for the group is necessary, so 075x.
>>
>> Better safe than...
>>
> Even safer, post/run it on someone else's web server. Web space is no
> longer given away free by (most) ISPs, but a small amount can be had for
> 'hobby' money now.

Another approch is to use apache mpm itk


[toc] | [prev] | [next] | [standalone]


#209916

FromGene Heskett <gheskett@shentel.net>
Date2019-06-15 03:30 +0200
Message-ID<y95G1-81b-1@gated-at.bofh.it>
In reply to#209900
On Friday 14 June 2019 09:04:50 am Joe wrote:

> On Fri, 14 Jun 2019 14:58:05 +0200
>
> <tomas@tuxteam.de> wrote:
> > On Fri, Jun 14, 2019 at 08:46:51AM -0400, Greg Wooledge wrote:
> > > On Thu, Jun 13, 2019 at 06:11:03PM -0400, Gene Heskett wrote:
> > > > looks good, but the problem is, only gene=user 1000 has any
> > > > rights to follow that path, so this access must be done as gene,
> > > > not the default www-data:www-data, or even as the parent session
> > > > of apache2..
> > >
> > > So change the ownership/permissions on the content.  To serve it
> > > up from a web server, you need to make it world-readable.  This
> > > means that directories require the x bit, and files require the r
> > > bit, for the "other" (right-most characters in ls -l output, least
> > > significant bits in the octal mode).
> >
> > Perhaps group readable (074x, x being usually 0) and setting the
> > file's group would suffice?
> >
> > That's my standard setup: the files belong to a "www admin" (can be
> > a regular user, can be root) and have the group www-data. So the web
> > server hasn't (usually) write access to normal htmls and cgi-bins
> > (oh, for the last, execute access for the group is necessary, so
> > 075x.
> >
> > Better safe than...
>
> Even safer, post/run it on someone else's web server. Web space is no
> longer given away free by (most) ISPs, but a small amount can be had
> for 'hobby' money now.

The pro and cons are in favor of doing it myself just for the total 
control. The only sufferer is the one that wants to download my work as 
the uplink speed is noticeably slower. But he still gets it for only his 
bandwidth/time cost.  But because most ISP's think we are dumber than 
rocks, they block incoming port 80.  But I am also a fan of the Hitachi 
6309, a cmos and smarter clone of the moto 6809, but with fringies 
thrown in, hence the tongue-in-cheek use of port 6309 to run my web 
server on.

Cheers, Gene Heskett
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
If we desire respect for the law, we must first make the law respectable.
 - Louis D. Brandeis
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#209905

FromGene Heskett <gheskett@shentel.net>
Date2019-06-14 17:30 +0200
Message-ID<y8Wjn-2mW-5@gated-at.bofh.it>
In reply to#209896
On Friday 14 June 2019 08:46:51 am Greg Wooledge wrote:

> On Thu, Jun 13, 2019 at 06:11:03PM -0400, Gene Heskett wrote:
> > looks good, but the problem is, only gene=user 1000 has any rights
> > to follow that path, so this access must be done as gene, not the
> > default www-data:www-data, or even as the parent session of
> > apache2..
>
So in the end I copied the debs to a /home/gene/subdir made to catch 
them, and changed the ownership of the subdir and contents to www-data, 
then moved the whole thing to /var/www/html/gene/subdir, and added that 
to the <a href "####",statement> and they can now be downloaded by 
interested parties.

> So change the ownership/permissions on the content.  To serve it up
> from a web server, you need to make it world-readable.  This means
> that directories require the x bit, and files require the r bit, for
> the "other" (right-most characters in ls -l output, least significant
> bits in the octal mode).
>
> In other words, 711 or 755 on the directories, and 644 on the files.
>
> > Is there
> > an "as user=gene" command that can be used only for this stanza that
> > I can put in this stanza?  root cannot go up this path to see
> > anything, neither can www-data.
>
> If root can't see the files, that means you're dealing with some kind
> of remote file system, like NFS?  If so, you really need to state the
> full relevant details up front.

Not NFS, its too wibbly, works only with the right phase of the moon and 
your astrological period or some such.  But an sshfs mount as me Just 
Works. Because one of those isn't yet set for passwordless key file 
access, I get asked for my password once, so this file has to be run by 
hand:

#!/bin/bash
sshfs gene@shop:/ /sshnet/shop
sshfs gene@lathe:/ /sshnet/lathe
sshfs gene@GO704:/ /sshnet/GO704
sshfs pi@picnc:/ /sshnet/picnc
sshfs gene@rock64:/ /sshnet/rock64

I keep  a bunch of that sort of stuff in ~/gene/bin, which is first in my 
$PATH.
And I just got a lunch order from my missus. later.
>
> If you need to change permissions on an NFS-mounted file system that
> you're serving up through a web server on the NFS client system, then
> you'll need to make the changes *on* the NFS server, or as the owner
> of the files on the NFS client.
>
> By the way, I recommend running the web server from the same box where
> the files reside if at all possible, just for efficiency and sanity.
>
> > Is this a place where making gene a member of group www-data would
> > help?
>
> No.
>
> Longer answer: each process has its own UID, GID and list of
> supplementary groups.  If the apache worker process that tries to read
> your content is running as UID www-data and GID www-data with no
> supplementary groups, then the *only* permissions that matter are the
> "other" permissions on the file (those always matter), or the "group"
> permissions if the *FILE* belongs to group www-data (sounds like this
> is not the case), or the "user" permissions if the *FILE* belongs to
> user www-data (definitely not the case).
>
> When you "add user gene to group www-data", this has absolutely zero
> effect on a process that is running as user www-data/group www-data.
> (Daemons are launched by lower-level system processes that do not give
> half a flip about what groups users are "in" in /etc/group.)  The only
> effect that your group addition has is on *logins* made by the user
> named gene.  Future login sessions for gene will have one more group
> added to their list of supplementary groups.
>
> Adding a user to a group has no effect on files that you own.  Each
> file has one user-owner, one group-owner, one octal mode number
> declaring yes/no permissions for user/group/owner, and some ACL crap
> that I *really* am not going to get into here.  Suffice to say,
> "adding a user to a group" is not a thing that file systems or the
> files in them care about.
>
> Adding a user to a group has no effect on the privileges of daemons
> that are started by your init system.

So it would appear now. With wheezy it was useally the fix.

> It *does* appear to affect the group membership of your at jobs,
> though. I didn't test cron, and of course neither cron(8) nor
> crontab(1) tells me whether it affects cron jobs, because why would
> they mention something important like the privileges of your running
> jobs....

Good question, because I have another perms problem that is preventing 
awfull from generating any data from looking at the apache2 logs, and 
again it worked flawlessly on wheezy.

Cheers, Gene Heskett
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
If we desire respect for the law, we must first make the law respectable.
 - Louis D. Brandeis
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#209928

Frommick crane <mick.crane@gmail.com>
Date2019-06-15 12:00 +0200
Message-ID<y9dDz-4h7-1@gated-at.bofh.it>
In reply to#209864
On 2019-06-13 20:33, Gene Heskett wrote:
> Greetings all;
> 
> And it's my web page.

> 
> Or do I have to copy them across to a local dir I can share and chown
> them to match the apache2 sandboxes names?

Don't know if supposed to but can put a soft link in /var/www/html 
pointing to directory anywhere readable by group www-data.



-- 
Key ID    4BFEBB31

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web