Gentoo Archives: gentoo-user

From: "Canek Peláez Valdés" <caneko@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] USB automount
Date: Thu, 13 Sep 2012 14:52:01
Message-Id: CADPrc83Rri0K30sPV0QLRsmX5+rfss_uN1bfUHL3NUfsVvFcMA@mail.gmail.com
In Reply to: Re: [gentoo-user] USB automount by Neil Bothwick
1 On Thu, Sep 13, 2012 at 9:42 AM, Neil Bothwick <neil@××××××××××.uk> wrote:
2 > On Thu, 13 Sep 2012 09:19:19 -0500, Canek Peláez Valdés wrote:
3 >
4 >> > A normal user can pumount *WHAT THAT SAME USER* has pmounted. Now
5 >> > try for a general solution.
6 >>
7 >> The general solution is using something like udisks+polkit. That is a
8 >> true general solution; otherwise you end up like the author of
9 >> calibre, with a security mess on his hands:
10 >>
11 >> https://bugs.launchpad.net/calibre/+bug/885027
12 >>
13 >> If you dismiss the security implications of sudoing pmount, because
14 >> you care only about *your* use cases, on *your* machine, by definition
15 >> that is not a "general solution".
16 >
17 > You should never need to sudo pmount, it is supposed to run as a normal
18 > user. Walter is using sudo to run pumount, which is nothing like the
19 > situation described in that bug. Even pmount avoids the situations
20 > described in that bug because it is only capable of operating in /media.
21
22 OK, noted. It is still not "a general solution", which is my main point.
23
24 Regards.
25 --
26 Canek Peláez Valdés
27 Posgrado en Ciencia e Ingeniería de la Computación
28 Universidad Nacional Autónoma de México