6 ms·
Running "n stable" removed bin, lib, share, include directories from /usr/local
- cmwelsh 14y agoI used to use n before I found out about nvm[1]. I used to have issues installing Node.js packages with n, but so far nvm just works. The best advantage of nvm is that I can easily install global packages without being the root user, because it installs your Node.js files in a per-user ~/nvm/ folder (this is customizable to whatever folder you choose). [1] https://github.com/creationix/nvm https://github.com/creationix/nvm
- dfc 14y ago"The best advantage of nvm is that I can easily install global packages without being the root user" One of us is very confused (it easily could be me). I do not understand this statement at all. How is something global if its in a user directory?
- cmwelsh 14y agoWhen you install a package using npm with the flag -g, it means that the package is global, i.e. available from any current working directory. The default is to only search the current directory hierarchy for a folder called "node_modules". That way every project that you work on can have its own versions of every library, instead of sharing them for the entire system. You can learn more about "global" vs "local" packages by reading the npm manual.
- deleted 14y ago[deleted]
- almost 14y agoLooks like the mods changed the title I gave. Just for those that don't know, "n" is a version manager for Node.JS that some use to handle multiple copies of Node.JS on their system.
- nym 14y agoYour original title was slightly linkbaity. I approve of the mod's change for clarity.
- almost 14y agoThey were probably right to do it. But it would have been useful to keep the reference to Node.JS in there as not everyone knows what "n" is.
- ars 14y agoI read it as: "Running and stable with no bin, lib, share, include directories in /usr/local". Which didn't seem all that exciting to me, so I clicked just to see what all the excitement was with not having a /usr/local. PS. "n" is a terrible name for a program - it's impossible to google.
- lukeschlather 14y agoI was hopelessly confused by the title. It may have made the title not linkbait, but it definitely muddled things.
- benatkin 14y agoHe merged a pull request from someone he probably didn't know (new to node.js, different country). Without looking at the rest of the file it looks OK to me. That's probably what happened - he didn't get all of the program's relevant structure in his mind when he read the code. https://github.com/visionmedia/n/pull/85/files#r1781158 https://github.com/visionmedia/n/pull/85/files#r1781158
- zobzu 14y agoWhich is slightly scary security wise. Over the large number of libs, programs, etc people often pull half-blind if the code looks "mostly ok and does what it says" Except it can do also a lot of other bad things, and its too much to review. So in the end you trust the tree owner, and he blindly trust a zillion people. I actually have zero good solution to this, but it'll be interesting when it is used for a large attack.
- rhizome 14y agoAs far as the headline goes, not running any of this as root is a good start.
- benatkin 14y agoThat by itself is rarely a solution, especially these days. People store very important stuff in their home directories. It would need to be something like an isolated user account, a virtual machine, or a browser window.
- deleted 14y ago[deleted]
- adgar2 14y ago> Except it can do also a lot of other bad things, and its too much to review. So in the end you trust the tree owner, and he blindly trust a zillion people. > I actually have zero good solution to this, but it'll be interesting when it is used for a large attack. The only solution is intelligence and prudence on the part of the tree owners. Large software systems need to ultimately be in the hands of smart and wise people. Unfortunately, that wasn't the case here.
- paulrademacher 14y agohttps://github.com/visionmedia/n/pull/85/files#r1781158 https://github.com/visionmedia/n/pull/85/files#r1781158 | for d in bin lib share include; do | rm -rf $N_PREFIX/$d LGTM!
- rat87 14y agoReminds me of https://github.com/MrMEEE/bumblebee-Old-and-abbandoned/issues/123 https://github.com/MrMEEE/bumblebee-Old-and-abbandoned/issue... (install script does rm -rf /usr for ubuntu) although I guess deleting /usr/local isn't nearly as bad.
- 1SaltwaterC 14y agoDepends on platform. It is under FreeBSD. It wipes the entire userland that isn't part of the base system. That means every piece of software installed from the ports collection.
- lmm 14y agoYeah, but honestly that's FreeBSD's fault for installing system-managed software in a poor location for such. (speaking as a FreeBSD user myself)
- SCdF 14y agoSomewhat off-topic, but allowing people to post inline images-- especially animated ones, is such an awful idea.
- protomyth 14y agoMakes me wish we had a transactional file system and the ability to force certain deletes to verify even if run as root with the -rf flags so we could roll back this type of thing.
- cokernel_hacker 14y agoTransactional filesystems have been implemented at considerable expense. To be clear, I mention transactions at a high enough level to encompass deleting a subdirectory (most reasonably implemented filesystems have support for tiny transaction that ensure that metadata is available on disk in a consistent fashion). When I say considerable expense, I mean _very_ considerable expense. I know of no efficient implementation and only one practical implementation: TxF. TxF is not very fast either, it requires double the writes and, on top of that, is not easy to use. Microsoft is considering deprecating TxF due to the cost of continuing it's maintenance at the expense of other features [1] I think a more reasonable model for what you want is filesystem snapshots. This is a feature that can be implemented with relatively high performance and without causing terribly large amounts of complication (needing to transact file descriptors, etc.) [1] http://msdn.microsoft.com/en-us/library/windows/desktop/hh802690(v=vs.85).aspx http://msdn.microsoft.com/en-us/library/windows/desktop/hh80...
- lmm 14y agoMy setup is pretty simple and could recover from this with few problems: I use ZFS and have zfSnap configured to take a snapshot every hour, saved for five days. So I'd lose potentially the last hour's worth of changes to /usr/local, but that's unlikely to be big.
- mcosta 14y agobsd? linux? solaris?
- lmm 14y agoFreeBSD; I didn't trust any of the ZFS implementations for linux (I'm not sure there is one that works for your root filesystem yet?) and Solaris didn't find all of my hard drives. If you're thinking of switching there really isn't much difference between FreeBSD and Linux (at least if you're talking about a traditional Linux like Slackware); most of the admin commands work like Linux did up until 5 years ago, and obviously the UI is just KDE or whatever you like.
- tjholowaychuk 14y agomy bad, sorry about the limbo-merge guys, I'll read PRs closer and/or ignore them since I don't have time
- Evbn 14y agoWow, just today I commented on the Anvil post about how to delete your system using this exact bug.
- ben0x539 14y agoAs a non-Node.js user, I'm more bewildered by how easily github issues turn into reddit threads.
- TazeTSchnitzel 14y agoWorse than reddit threads. No moderation and unstructured.
- Xion 14y agoThis looks more like 4chan to me.
- 1SaltwaterC 14y agoIt isn't a node.js related problem, but more of a GitHub related problem when a specific issue is deemed to be "legendary". Example: https://github.com/MrMEEE/bumblebee-Old-and-abbandoned/issues/123 https://github.com/MrMEEE/bumblebee-Old-and-abbandoned/issue...
- almost 14y agoIt only happens occasionally on bugs issues that get a lot of attention (by being posted to HN for example, sorry about that). Usually GitHub issues threads are sensible and helpful places.
- ben0x539 14y agoThat's what so scary to me. There's all that productive discussion that is only a step over some noteworthiness threshold away from being completely ruined. I wouldn't think of blaming HN or even reddit submitters for that, though.
- HNSucksAss 14y agoWTF is "n"?