Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 544164 - net-fs/nfs-utils: rpc.statd should be run as non-root
Summary: net-fs/nfs-utils: rpc.statd should be run as non-root
Status: UNCONFIRMED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] Server (show other bugs)
Hardware: All Linux
: Normal enhancement
Assignee: Gentoo's Team for Core System packages
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-03-22 22:10 UTC by Markus Lischka
Modified: 2017-09-08 10:33 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
nfs-utils-statd-user-ebuild.diff (nfs-utils-statd-user-ebuild.diff,771 bytes, patch)
2017-06-22 18:20 UTC, Alan Swanson
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Markus Lischka 2015-03-22 22:10:59 UTC
rpc.statd is running as root after installing net-fs/nfs-utils: It does not drop root privileges and outputs a warning message to syslog:

rpc.statd: Running as root.  chown /var/lib/nfs to choose different user

My expected result after installation would be that /var/lib/nfs and corresponding files are chowned by a specific, non-privileged user. This is the default behavior on Debian (cf. <https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=574510>) and Fedora (cf. <https://bugzilla.redhat.com/show_bug.cgi?id=495066>).

Manually changing ownerships after installation works around this problem:

> useradd -r -c "added for nfs-utils" -d /var/lib/nfs -s /sbin/nologin statd
> chown statd:statd /var/lib/nfs /var/lib/nfs/sm /var/lib/nfs/sm.bak /var/lib/nfs/state


emerge --info:

Portage 2.2.14 (python 3.3.5-final-0, default/linux/amd64/13.0/desktop/kde, gcc-4.8.3, glibc-2.19-r1, 3.18.7-gentoo x86_64)
=================================================================
System uname: Linux-3.18.7-gentoo-x86_64-Intel-R-_Core-TM-2_Duo_CPU_E8400_@_3.00GHz-with-gentoo-2.2
KiB Mem:     8141604 total,    253420 free
KiB Swap:   16777212 total,  16777044 free
Timestamp of tree: Fri, 20 Mar 2015 18:15:01 +0000
ld GNU ld (Gentoo 2.24 p1.4) 2.24
app-shells/bash:          4.2_p53
dev-java/java-config:     2.2.0
dev-lang/perl:            5.20.1-r4
dev-lang/python:          2.7.9-r1, 3.3.5-r1, 3.4.1
dev-util/cmake:           2.8.12.2-r1
dev-util/pkgconfig:       0.28-r1
sys-apps/baselayout:      2.2
sys-apps/openrc:          0.13.11
sys-apps/sandbox:         2.6-r1
sys-devel/autoconf:       2.13, 2.69
sys-devel/automake:       1.11.6-r1, 1.13.4
sys-devel/binutils:       2.24-r3
sys-devel/gcc:            4.8.3
sys-devel/gcc-config:     1.7.3
sys-devel/libtool:        2.4.4
sys-devel/make:           4.1-r1
sys-kernel/linux-headers: 3.18 (virtual/os-headers)
sys-libs/glibc:           2.19-r1
Repositories: gentoo local
ACCEPT_KEYWORDS="amd64"
ACCEPT_LICENSE="* -@EULA"
CBUILD="x86_64-pc-linux-gnu"
CFLAGS="-march=native -O2 -pipe"
CHOST="x86_64-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/lib64/libreoffice/program/sofficerc /usr/share/cdlabelgen /usr/share/config /usr/share/gnupg/qualified.txt /usr/share/themes/oxygen-gtk/gtk-2.0 /usr/share/themes/oxygen-gtk/gtk-3.0"
CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/dconf /etc/env.d /etc/fonts/fonts.conf /etc/gconf /etc/gentoo-release /etc/php/apache2-php5.5/ext-active/ /etc/php/cgi-php5.5/ext-active/ /etc/php/cli-php5.5/ext-active/ /etc/revdep-rebuild /etc/sandbox.d /etc/terminfo"
CXXFLAGS="-march=native -O2 -pipe"
DISTDIR="/usr/portage/distfiles"
EMERGE_DEFAULT_OPTS="--with-bdeps=y --keep-going"
FCFLAGS="-O2 -pipe"
FEATURES="assume-digests binpkg-logs collision-protect config-protect-if-modified distlocks ebuild-locks fixlafiles merge-sync news parallel-fetch preserve-libs protect-owned sandbox sfperms strict test test-fail-continue unknown-features-warn unmerge-logs unmerge-orphans userfetch userpriv usersandbox usersync xattr"
FFLAGS="-O2 -pipe"
GENTOO_MIRRORS="http://ftp.uni-erlangen.de/pub/mirrors/gentoo http://ftp.halifax.rwth-aachen.de/gentoo http://distfiles.gentoo.org"
LDFLAGS="-Wl,-O1 -Wl,--as-needed"
MAKEOPTS="-j3 -l3"
PKGDIR="/usr/portage/packages"
PORTAGE_CONFIGROOT="/"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --omit-dir-times --compress --force --whole-file --delete --stats --human-readable --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
PORTDIR_OVERLAY="/usr/local/portage"
SYNC="rsync://rsync.europe.gentoo.org/gentoo-portage"
USE="X a52 aac acl acpi alsa amd64 bash-completion berkdb branding bzip2 cairo caps cdda cdr cli consolekit cracklib crypt cups cxx dbus declarative dri dts dvd dvdr emacs emboss encode exif fam ffmpeg firefox flac fortran gdbm gif glamor gphoto2 gpm gtk iconv ipv6 java java6 jpeg kde kipi lame lcms libnotify lm_sensors mad mmx mmxext mng modules mp3 mp4 mpeg multilib ncurses nls nptl nsplugin ogg opengl openmp pam pango pcre pdf phonon plasma png policykit ppds pulseaudio qt3support qt4 readline samba scanner sdl semantic-desktop session smp spell sqlite sse sse2 sse3 sse4_1 ssl ssse3 startup-notification svg syslog tcpd theora tiff truetype udev udisks unicode upower usb vaapi vorbis wmf wxwidgets x264 xattr xcb xcomposite xft xinerama xml xscreensaver xv xvid zlib" ABI_X86="64" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci" APACHE2_MODULES="alias auth_basic authn_default authn_file authz_default authz_groupfile authz_host authz_user autoindex dav dav_fs deflate dir env filter headers include log_config mime negotiation rewrite setenvif status" APACHE2_MPMS="prefork" CALLIGRA_FEATURES="kexi words flow plan sheets stage tables krita karbon braindump author" CAMERAS="ptp2" COLLECTD_PLUGINS="df interface irq load memory rrdtool swap syslog" CPU_FLAGS_X86="mmx mmxext sse sse2 sse3 sse4_1 ssse3" ELIBC="glibc" GPSD_PROTOCOLS="ashtech aivdm earthmate evermore fv18 garmin garmintxt gpsclock itrax mtk3301 nmea ntrip navcom oceanserver oldstyle oncore rtcm104v2 rtcm104v3 sirf superstar2 timing tsip tripmate tnt ublox ubx" INPUT_DEVICES="evdev keyboard mouse" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" LIBREOFFICE_EXTENSIONS="nlpsolver presenter-minimizer" LINGUAS="de_DE de en_US en" OFFICE_IMPLEMENTATION="libreoffice" PHP_TARGETS="php5-5" PYTHON_SINGLE_TARGET="python2_7" PYTHON_TARGETS="python2_7 python3_3" RUBY_TARGETS="ruby19 ruby20" SANE_BACKENDS="test" USERLAND="GNU" VIDEO_CARDS="intel vesa" XTABLES_ADDONS="quota2 psd pknock lscan length2 ipv4options ipset ipp2p iface geoip fuzzy condition tee tarpit sysrq steal rawnat logmark ipmark dhcpmac delude chaos account"
Unset:  CPPFLAGS, CTARGET, INSTALL_MASK, LANG, LC_ALL, PORTAGE_BUNZIP2_COMMAND, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS, USE_PYTHON
Comment 1 SpanKY gentoo-dev 2015-03-27 22:49:37 UTC
nfs-utils has never dropped perms afaik on Gentoo
Comment 2 Alan Swanson 2017-06-22 18:20:06 UTC
Created attachment 477634 [details, diff]
nfs-utils-statd-user-ebuild.diff

This security issue still needs to fixed to run rpc.statd unprivileged. Attached is diff to nfs-utils ebuild to resolve. Permissions for sm and sm.bak are also set to 700 as recommended by Linux NFS FAQ.

Beyond the diff there are a couple of possible further options;
- Could use the configure option "--with-statduser". However it's only used by the chown in Makefile.am install doing the same as ebuild chown but it doesn't chown /var/lib/nfs which is the default statdpath that rpc.statd uses to set its euid, so not worth it.
- Optionally, like Redhat you could change statdpath to /var/lib/nfs/statd with configure option "--withstatdpath" to avoid chowning /var/lib/nfs itself. Not worth changing now though.
Comment 3 Alan Swanson 2017-06-23 15:27:10 UTC
The ebuild should also inherit user for enewuser and enwegroup but was missing in the diff.
Comment 4 Ivan Iraci 2017-09-08 10:33:38 UTC
Same problem here.

Alan Swanson's fix works for me.