This is why I hate Gnome!
I'm wondering how they made something that root cannot access. This is
not Unix!
-------- Originalnachricht --------
Betreff: [Bug 225361] Re: .gvfs can't be stat'd by root causing backup
tools to fail
Datum: 2018-11-07 20:31
Von: Bug Watch Updater <225361@???>
An: jf@???
Antwort an: Bug 225361 <225361@???>
** Changed in: gvfs (ALT Linux)
Status: Confirmed => Expired
** Changed in: gvfs
Status: Confirmed => Expired
--
You received this bug notification because you are subscribed to the bug
report.
https://bugs.launchpad.net/bugs/225361
Title:
.gvfs can't be stat'd by root causing backup tools to fail
Status in gvfs:
Expired
Status in gvfs package in Ubuntu:
Fix Released
Status in gvfs package in ALT Linux:
Expired
Bug description:
Problem
=======
For security reasons ( possible DoS ), other users (esp. root) cannot
access a fuse filesystem, and not even stat the mountpoint:
$ sudo stat .gvfs
stat: cannot stat `.gvfs': Permission denied
$ sudo ls -la
ls: cannot access .gvfs: Permission denied
d????????? ? ? ? ? ? .gvfs
This means "rsync --one-file-system" (and similar options for find,
tar...) cannot know this is a different file system they actually want
to exclude, and fail on the permission denied error.
Please note that it is GOOD AND CORRECT that root cannot copy the
.gvfs directory. The real problem is that the stat fails.
Workarounds
===========
* bind-mount the file system you want to backup beforehand (see
comment #67)
See also
=======
* Excellent description of the problem in bug 227724
* fuse-devel mailing list saying this will all be solved someday using
"private namespaces"
http://thread.gmane.org/gmane.comp.file-systems.fuse.devel/3497/focus=3502
http://thread.gmane.org/gmane.comp.file-systems.fuse.devel/7169/focus=7236
http://thread.gmane.org/gmane.comp.file-systems.fuse.devel/6197 (no
answer at all)
* Kernel documentation explaing the DoS
http://www.kernel.org/doc/Documentation/filesystems/fuse.txt
To manage notifications about this bug go to:
https://bugs.launchpad.net/gvfs/+bug/225361/+subscriptions