Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #243433
| From | David Robert Newman <david@davidrobertnewman.com> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: doas 101 question |
| Date | 2021-12-25 06:00 +0100 |
| Message-ID | <Dy7jX-7Fn-1@gated-at.bofh.it> (permalink) |
| References | <Dvsbf-6Z6-11@gated-at.bofh.it> <Dvzmp-3Em-1@gated-at.bofh.it> <DvAs9-4kI-1@gated-at.bofh.it> <DvJvr-1SQ-3@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On 12/18/21 7:08 AM, Greg Wooledge wrote:
> On Fri, Dec 17, 2021 at 09:20:59PM -0800, David Newman wrote:
>> Thanks for this. I get similar results where doas shows root's PATH -- but I
>> cannot execute a file called '/usr/local/sbin/s', which is owned by
>> root:root and has 0750 permissions, unless I specify the full path:
>>
>> dnewman@coppi:~$ echo $PATH
>> /usr/local/bin:/usr/bin:/bin:/usr/local/games:/usr/games
>> dnewman@coppi:~$ cat /etc/doas.conf
>> permit nopass setenv {
>> PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin } dnewman
>> dnewman@coppi:~$ doas env | grep PATH
>> PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
>> dnewman@coppi:~$ doas s mailman3
>> doas: s: command not found
>> dnewman@coppi:~$ doas /usr/local/sbin/s mailman3
>> ● mailman3.service - GNU Mailing List Manager
>> ..
> Same here, and it's not the permissions that are the issue.
>
> unicorn:~$ PATH=/usr/local/bin:/usr/bin:/bin
> unicorn:~$ type fdisk
> bash: type: fdisk: not found
> unicorn:~$ doas fdisk -l | head -n2
> doas (greg@unicorn) password:
> doas: fdisk: command not found
> unicorn:~$ doas /sbin/fdisk -l | head -n2
> doas (greg@unicorn) password:
> Disk /dev/sda: 931.51 GiB, 1000204886016 bytes, 1953525168 sectors
> Disk model: TOSHIBA DT01ACA1
>
> Looks like doas performs the search for the command *before* it sets
> the environment. You'd need to petition the developers to make a change
> to the program's behavior in order to get what you want. Most likely
> this would need to be argued upstream, as I cannot imagine Debian writing
> a local patch for that. Not in a setuid program like this, and not after
> the bullshit they pulled with su in buster.
I asked doas author Ted Unangst about this. His reply:
> Sorry, only very limited env replacement can be done in setenv. root's environment isn't available before the switch.
Ergo, it is just as you suspected. This isn't an issue with OpenBSD
because regular users's PATHs already include sbin directories. It is an
issue with Debian because (a) a regular user's PATH doesn't include sbin
directories and (b) the change in su behavior awhile back restricted
access to some root privileges. It's not an issue with sudo, but for
various reasons I'm more comfortable using doas.
My workaround was to add aliases for a few commands to my .bashrc file,
e.g. (but not a real example):
alias ua='doas /usr/sbin/useradd'
Thanks for the sanity check.
dn
>
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
doas 101 question David Newman <dnewman@networktest.com> - 2021-12-17 21:40 +0100
Re: doas 101 question Greg Wooledge <greg@wooledge.org> - 2021-12-18 05:20 +0100
Re: doas 101 question David Newman <dnewman@networktest.com> - 2021-12-18 06:30 +0100
Re: doas 101 question Tim Woodall <debianuser@woodall.me.uk> - 2021-12-18 08:00 +0100
Re: doas 101 question Greg Wooledge <greg@wooledge.org> - 2021-12-18 16:10 +0100
Re: doas 101 question David Robert Newman <david@davidrobertnewman.com> - 2021-12-25 06:00 +0100
Re: doas 101 question Greg Wooledge <greg@wooledge.org> - 2021-12-25 15:00 +0100
csiph-web