Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #243433

Re: doas 101 question

From David Robert Newman <david@davidrobertnewman.com>
Newsgroups linux.debian.user
Subject Re: doas 101 question
Date 2021-12-25 06:00 +0100
Message-ID <Dy7jX-7Fn-1@gated-at.bofh.it> (permalink)
References <Dvsbf-6Z6-11@gated-at.bofh.it> <Dvzmp-3Em-1@gated-at.bofh.it> <DvAs9-4kI-1@gated-at.bofh.it> <DvJvr-1SQ-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On 12/18/21 7:08 AM, Greg Wooledge wrote:

> On Fri, Dec 17, 2021 at 09:20:59PM -0800, David Newman wrote:
>> Thanks for this. I get similar results where doas shows root's PATH -- but I
>> cannot execute a file called '/usr/local/sbin/s', which is owned by
>> root:root and has 0750 permissions, unless I specify the full path:
>>
>> dnewman@coppi:~$ echo $PATH
>> /usr/local/bin:/usr/bin:/bin:/usr/local/games:/usr/games
>> dnewman@coppi:~$ cat /etc/doas.conf
>> permit nopass setenv {
>> PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin } dnewman
>> dnewman@coppi:~$ doas env | grep PATH
>> PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
>> dnewman@coppi:~$ doas s mailman3
>> doas: s: command not found
>> dnewman@coppi:~$ doas /usr/local/sbin/s mailman3
>> ● mailman3.service - GNU Mailing List Manager
>> ..
> Same here, and it's not the permissions that are the issue.
>
> unicorn:~$ PATH=/usr/local/bin:/usr/bin:/bin
> unicorn:~$ type fdisk
> bash: type: fdisk: not found
> unicorn:~$ doas fdisk -l | head -n2
> doas (greg@unicorn) password:
> doas: fdisk: command not found
> unicorn:~$ doas /sbin/fdisk -l | head -n2
> doas (greg@unicorn) password:
> Disk /dev/sda: 931.51 GiB, 1000204886016 bytes, 1953525168 sectors
> Disk model: TOSHIBA DT01ACA1
>
> Looks like doas performs the search for the command *before* it sets
> the environment.  You'd need to petition the developers to make a change
> to the program's behavior in order to get what you want.  Most likely
> this would need to be argued upstream, as I cannot imagine Debian writing
> a local patch for that.  Not in a setuid program like this, and not after
> the bullshit they pulled with su in buster.

I asked doas author Ted Unangst about this. His reply:

> Sorry, only very limited env replacement can be done in setenv. root's environment isn't available before the switch.

Ergo, it is just as you suspected. This isn't an issue with OpenBSD 
because regular users's PATHs already include sbin directories. It is an 
issue with Debian because (a) a regular user's PATH doesn't include sbin 
directories and (b) the change in su behavior awhile back restricted 
access to some root privileges. It's not an issue with sudo, but for 
various reasons I'm more comfortable using doas.

My workaround was to add aliases for a few commands to my .bashrc file, 
e.g. (but not a real example):

alias ua='doas /usr/sbin/useradd'

Thanks for the sanity check.

dn





>

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

doas 101 question David Newman <dnewman@networktest.com> - 2021-12-17 21:40 +0100
  Re: doas 101 question Greg Wooledge <greg@wooledge.org> - 2021-12-18 05:20 +0100
    Re: doas 101 question David Newman <dnewman@networktest.com> - 2021-12-18 06:30 +0100
      Re: doas 101 question Tim Woodall <debianuser@woodall.me.uk> - 2021-12-18 08:00 +0100
      Re: doas 101 question Greg Wooledge <greg@wooledge.org> - 2021-12-18 16:10 +0100
        Re: doas 101 question David Robert Newman <david@davidrobertnewman.com> - 2021-12-25 06:00 +0100
          Re: doas 101 question Greg Wooledge <greg@wooledge.org> - 2021-12-25 15:00 +0100

csiph-web