1 |
On Thu, Sep 13, 2012 at 1:50 AM, Walter Dnes <waltdnes@××××××××.org> wrote: |
2 |
> On Wed, Sep 12, 2012 at 09:03:50AM +0100, Neil Bothwick wrote |
3 |
> |
4 |
>> I don't understand, why are you using sudo to run pmount when its core |
5 |
>> purpose is to be run by normal users? |
6 |
>> |
7 |
>> % whatis pmount |
8 |
>> pmount (1) - mount arbitrary hotpluggable devices as normal user |
9 |
> |
10 |
> A normal user can pumount *WHAT THAT SAME USER* has pmounted. Now try |
11 |
> for a general solution. |
12 |
|
13 |
The general solution is using something like udisks+polkit. That is a |
14 |
true general solution; otherwise you end up like the author of |
15 |
calibre, with a security mess on his hands: |
16 |
|
17 |
https://bugs.launchpad.net/calibre/+bug/885027 |
18 |
|
19 |
If you dismiss the security implications of sudoing pmount, because |
20 |
you care only about *your* use cases, on *your* machine, by definition |
21 |
that is not a "general solution". |
22 |
|
23 |
Of course, udisks/polkit/etc. goes hand in hand with udev, so you are |
24 |
probably not interested in using them. That is completely fine. |
25 |
|
26 |
Just don't call it a "general solution". |
27 |
|
28 |
Regards. |
29 |
-- |
30 |
Canek Peláez Valdés |
31 |
Posgrado en Ciencia e Ingeniería de la Computación |
32 |
Universidad Nacional Autónoma de México |