4 ms·
Doas is doa on Linux at least. Last I checked maybe 6 months ago the password timeout feature was still broke. You get asked for the password every single time
by tekchip 3y ago
Doas is doa on Linux at least. Last I checked maybe 6 months ago the password timeout feature was still broke. You get asked for the password every single time you run doas even if it was just 2 seconds prior. Maddening. Apparently this has been the state for years now?
- JdeBP 3y agoAs mentioned elsewhere, this is because it relies upon a kernel mechanism that Linux simply does not have, and fixing this involves fixing Linux. To which I add that it is important not to conflate Jesse Smith's doas, the portable doas that has code for different operating systems including OpenBSD, with Duncan Overbruck's OpenDoas, the "open" doas that is tied to Linux has has had the code for other operating systems removed and mechanisms copied in from sudo for things like timeout flag files. * https://github.com/slicer69/doas https://github.com/slicer69/doas * https://github.com/Duncaen/OpenDoas https://github.com/Duncaen/OpenDoas
- somat 3y agoIt is because openbsd persists the auth via a cookie in the terminal. that is, to do it the openbsd way a change in the tty code is required. It is odd that the linux port does not track the process id or something. http://man.openbsd.org/tty.4#TIOCSETVERAUTH http://man.openbsd.org/tty.4#TIOCSETVERAUTH A post I found on the rational behind this mechanism. https://marc.info/?l=openbsd-misc&m=150032397404966&w=2 https://marc.info/?l=openbsd-misc&m=150032397404966&w=2 edit: I was looking at the opendoas project and it does something with the persist option, still reading the code but it looks like it sets some sort of timestamp on file descriptor 0. update: found it, here is the timestamp code. probably a user space version of what openbsd doas does in the kernel. https://github.com/Duncaen/OpenDoas/blob/master/timestamp.c https://github.com/Duncaen/OpenDoas/blob/master/timestamp.c So linux doas is trying to do something. Note that per that mail post I found doas auth persist has a different scope than sudo auth persist. this can have implications in a scripted environment.