5 ms·
Hmm, is there a straightforward way to be a bit more careful without detracting from the usefulness? What about a default blacklist of commands with the ability
by nickspacek 8y ago
Hmm, is there a straightforward way to be a bit more careful without detracting from the usefulness? What about a default blacklist of commands with the ability to override it through a config file?
- rcthompson 8y agoI don't think a blacklist could possibly be comprehensive enough. I think you'd have to use some OS permission-limiting system to prevent it and any subprocesses it spawns from have any write access to the filesystem.
- esotericn 8y agoPretty much. Is rm blacklisted? OK. How about bash -c "rm"? cp? mv? vim? ...? :D
- y4mi 8y agoYah, a whitelist of commands which includes bash would probably be best. You'd be fine using it and can simply switch to chainsaw mode by adding bash to the command
- malkarouri 8y agoI think the tool would be much more useful with a whitelist. Do this only for grep, awk, sed and other similar tools. Of course, much more thought is needed to try something like this. Somebody could as well use awk with its system command to do whatever..
- deleted 8y ago[deleted]
- conquistadog 8y agoEven an incomplete blacklist might be helpful, just in the interest of keeping perfect from being the enemy of good.
- amelius 8y agoOr perhaps use filesystem snapshots as an undo option ... if your fs supports them, of course.
- akavel 8y agoAuthor here: I hope something like that (syscall/capabilities limits) could work. If it is possible, it would just mostly solve the problem, I believe. I'm kinda starting to realize, that probably any command modifying some external state is potentially somewhat risky already, by potentially spinning some exponential feedback loop. (One person on lobste.rs mentioned that foo.bak.bak.bak.bak files could easily get created.) Regardless, I'm generally considering adding a shortcut/option to pause/unpause, and only execute on Ctrl-Enter when paused.
- rcthompson 8y agoAnother possibly reasonable option would be to create a (configurable) whitelist of commands that are considered safe, and keep running the pipeline automatically as long as it only contains whitelisted commands. Any time a non-whitelisted command is introduced, stop auto-running and require Ctrl+Enter or something, until the command once again consists of only whitelisted commands. This would save you, for example, if you had a custom command called "gr" which was short for "get rid of current directory" (obviously chosen as a pathological example since it's a prefix of grep). As you type the word "grep", auto-running is paused because "g", "gr", and "gre" are not whitelisted, and then once "grep" is fully typed, it recognizes that "grep" is on the whitelist and resumes auto-running. And it never ran the dangerous "gr" command.
- michaelmior 8y agoI hate to jump straight to Docker, but that seems to be a quick way to restrict access to the local file system. This of course limits utility, but would be much safer. Plus I think the usefulness of a tool like up is primarily in munging the input text anyway.
- traverseda 8y agoDocker is an obviously bad solution to this. If you can run a docker file you defacto have root on that computer ^1. Firejail could do exactly the same thing, but without requiring the user running it download an entire second operating system, or requiring them to have root. Also, the sandboxing mechanisms that docker uses are just generally available and aren't hard to use, so if they went that way they may as well just use the actual syscalls that do what they want instead of importing and entire other operating system to run your commands. This is where my rant about docker, and the habits it encourages, would go. If I could figure out a way to phrase it politely. 1: https://github.com/moby/moby/issues/9976 https://github.com/moby/moby/issues/9976
- akavel 8y agoWow, firejail seems super interesting, thanks a lot for the idea and mention! I'm not sure if I'll manage to use it, but certainly a good direction for some further research! https://firejail.wordpress.com/ https://firejail.wordpress.com/
- fwip 8y agoDocker containers don't need to be (and often aren't) "entire operating systems." Good point about it requiring root, though.
- michaelmior 8y agoThe problem I was suggesting could be solved Docker wasn't with the privileges of up itself, but the problem of commands you write within up being potentially destructive. I didn't say I thought Docker was a good solution.
- Nullabillity 8y ago
- LyndsySimon 8y agoIf it could be activated only by hotkey, that would be helpful.
- mordechai9000 8y agoYes, maybe similar to the way tab completion works.
- jimbokun 8y agoThink a whitelist would be much more appropriate for avoiding potentially harmful commands.