:: [DNG] Fwd: [Bug 225361] Re: .gvfs c…
Góra strony
Delete this message
Reply to this message
Autor: J. Fahrner
Data:  
Dla: Liste, DNG
Temat: [DNG] Fwd: [Bug 225361] Re: .gvfs can't be stat'd by root causing backup tools to fail
This is why I hate Gnome!
I'm wondering how they made something that root cannot access. This is
not Unix!

-------- Originalnachricht --------
Betreff: [Bug 225361] Re: .gvfs can't be stat'd by root causing backup
tools to fail
Datum: 2018-11-07 20:31
Von: Bug Watch Updater <225361@???>
An: jf@???
Antwort an: Bug 225361 <225361@???>

** Changed in: gvfs (ALT Linux)
        Status: Confirmed => Expired


** Changed in: gvfs
        Status: Confirmed => Expired


--
You received this bug notification because you are subscribed to the bug
report.
https://bugs.launchpad.net/bugs/225361

Title:
.gvfs can't be stat'd by root causing backup tools to fail

Status in gvfs:
Expired
Status in gvfs package in Ubuntu:
Fix Released
Status in gvfs package in ALT Linux:
Expired

Bug description:
Problem
=======
For security reasons ( possible DoS ), other users (esp. root) cannot
access a fuse filesystem, and not even stat the mountpoint:

       $ sudo stat .gvfs
       stat: cannot stat `.gvfs': Permission denied
       $ sudo ls -la
       ls: cannot access .gvfs: Permission denied
       d?????????   ? ?     ?         ?            ? .gvfs


This means "rsync --one-file-system" (and similar options for find,
tar...) cannot know this is a different file system they actually want
to exclude, and fail on the permission denied error.

Please note that it is GOOD AND CORRECT that root cannot copy the
.gvfs directory. The real problem is that the stat fails.

Workarounds
===========
* bind-mount the file system you want to backup beforehand (see
comment #67)

See also
=======
* Excellent description of the problem in bug 227724
* fuse-devel mailing list saying this will all be solved someday using
"private namespaces"

http://thread.gmane.org/gmane.comp.file-systems.fuse.devel/3497/focus=3502

http://thread.gmane.org/gmane.comp.file-systems.fuse.devel/7169/focus=7236
http://thread.gmane.org/gmane.comp.file-systems.fuse.devel/6197 (no
answer at all)
* Kernel documentation explaing the DoS
http://www.kernel.org/doc/Documentation/filesystems/fuse.txt

To manage notifications about this bug go to:
https://bugs.launchpad.net/gvfs/+bug/225361/+subscriptions