5 ms·
Because sometimes you are writing software that interacts with hardware at a root level. This is really annoying advice you're giving since its absolute and wit
by tbranyen 9y ago
Because sometimes you are writing software that interacts with hardware at a root level. This is really annoying advice you're giving since its absolute and without context. No, not everything is "super dangerous" with sudo. Get that FUD outta here!
- diggan 9y agonpm should never interact with hardware, it's job is to install and manage packages. I could understand that you have to run nodejs with root, since it actually can use the hardware. But using npm with root user? I can't think of a single usecase.
- tbranyen 9y agoWell think harder. Npm runs scripts from package.json. Most folks wouldn't think twice to run sudo npm start as a replacement for sudo node. I sure wouldn't think npm would start mucking with file permissions.
- diggan 9y agoI'm sorry but that people can't figure out where to put `sudo` is not a usecase for using sudo... Instead of running `sudo npm start`, have `scripts.start` have the value `sudo node index.js` if you want. But then again, I'm not "most folks", I try to think when I am the root user and don't run third-party code willy-nilly when I am.
- chopin 9y agoI am not a node guy but as far as I understand nodejs is a webserver, no? _Never_ run any webserver as root. This is just bad practice.
- manigandham 9y agoNo, Node is a runtime for javascript code, using the same V8 engine from the Chrome browser. It is similar to the JVM runtime for Java code and the CLR for C#, although of course there is no intermediate compilation step for javascript. A webserver is one of many things that can be run using Node+JS, the point being that it's an entire runtime and can do pretty much anything any other language can do.
- yorwba 9y agoThe reason raw hardware access is limited to root is usually because it's "super dangerous", i.e. the consequences of your actions can be more far-reaching than usual and mistakes might have you lose more than just time.
- breatheoften 9y agoRunning npm as root is _super dangerous_ - full stop. npm install can run a large amount of arbitrary code downloaded from the internet via postinstall script hooks. Its absolutely banana-pants crazy to run `npm install` as a root user in any circumstance.
- rad88 9y agoIt's banana-pants crazy to run npm at all. Even given all the wisdom about running as sudo, best practices etc., this team released an update where `sudo npm --help` breaks the operating system. The recklessness and confusion of ideas that indicates... postinstall hooks, I don't even want npm running. This isn't even the first such shenanigans.
- xorcist 9y agoIf it runs untrusted code from the Internet, surely it doesn't matter much if you do it as root for most practical purposes? It could still run that spam relay, botnet software, exfiltrate your secrets and install that keylogger.
- breatheoften 9y agoIs your argument that one is better off to run $(potentially dangerous command) with sudo privileges because it’s also risky to run it without?
- saurik 9y agoYeah, it would really suck if those files installed by my operating system--the ones that are trivially verified and easily replaced as they are literally the same on every single computer--were to be damaged. Things are much safer if I run them as the user which owns all of my data and which I spend all my time logged in as, right? I mean, at least I haven't stupidly added any part of my home directory to my path, so I can trust that the software I am running was installed by someone running as root... oh wait :/. The only reason root even exists on a computer that has two users (root and the user that owns all the data) is to make sure that no software is installed on the system except by root. If you have things set up to also let you install software as the user that isn't root, then you have somehow missed the entire point of peiviledge separation and should just log in as root and do everything as root, as that is at that point fully equivalent.
- mbrumlow 9y agoRight, but that means your service is running with elevated privileges, that does not mean your build tool needs too. Furthermore if you do have a application that requires root level access then the parts that do should be isolated from the parts that don't. You don't get to just get a blank check to run as root because you need to bind to a low port.