Howdy, fellow Debianites!
Given some extra hard drive space, I decided to move my /tmp dir
(currently located under / ) to a partition of its own. I am looking
forward to any advice, particularly of the been-there-done-that type:
* how should I configure my fstab entry? How does Debian installer do
it?
* is there anything Debian-specific to watch for?
* is it true that setting /tmp permissions to non-executable, while
hardening your box, prevents apt from working properly?
--
TIA,
Klistvud
Certifiable Loonix User #481801
http://bufferoverflow.tiddlyspot.com
--
To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: 1274603838.6845.1@compax">http://lists.debian.org/1274603838.6845.1@compax
05-23-2010, 08:45 AM
Ron Johnson
Moving /tmp to a separate partition. Advice?
On 05/23/2010 03:37 AM, Klistvud wrote:
Howdy, fellow Debianites!
Given some extra hard drive space, I decided to move my /tmp dir
(currently located under / ) to a partition of its own. I am looking
Why?
--
Dissent is patriotic, remember?
--
To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Sun May 23 11:30:06 2010
Return-path: <bounce-debian-user=tom=linux-archive.org@lists.debian.org>
Envelope-to: tom@linux-archive.org
Delivery-date: Sun, 23 May 2010 11:14:54 +0300
Received: from liszt.debian.org ([82.195.75.100]:49264)
by s2.java-tips.org with esmtps (TLSv1:AES256-SHA:256)
(Exim 4.69)
(envelope-from <bounce-debian-user=tom=linux-archive.org@lists.debian.org>)
id 1OG6Ki-0004jE-DC
for tom@linux-archive.org; Sun, 23 May 2010 11:14:53 +0300
Received: from localhost (localhost [127.0.0.1])
by liszt.debian.org (Postfix) with QMQP
id 76C5713A5452; Sun, 23 May 2010 08:50:51 +0000 (UTC)
Old-Return-Path: <gpall@ccf.auth.gr>
X-Spam-Checker-Version: SpamAssassin 3.2.5 (2008-06-10) on liszt.debian.org
X-Spam-Level:
X-Spam-Status: No, score=-11.5 required=4.0 tests=LDOSUBSCRIBER,LDO_WHITELIST,
MONEY,RCVD_IN_DNSWL_LOW autolearn=failed version=3.2.5
X-Original-To: lists-debian-user@liszt.debian.org
Delivered-To: lists-debian-user@liszt.debian.org
Received: from localhost (localhost [127.0.0.1])
by liszt.debian.org (Postfix) with ESMTP id 7138A13A5447
for <lists-debian-user@liszt.debian.org>; Sun, 23 May 2010 08:50:45 +0000 (UTC)
X-Virus-Scanned: at lists.debian.org with policy bank en-ht
X-Amavis-Spam-Status: No, score=-6 tagged_above=-10000 required=5.3
tests=[BAYES_00=-2, BODY_8BITS=1.5, LDO_WHITELIST=-5, MONEY=0.5,
RCVD_IN_DNSWL_LOW=-1] autolearn=ham
Received: from liszt.debian.org ([127.0.0.1])
by localhost (lists.debian.org [127.0.0.1]) (amavisd-new, port 2525)
with ESMTP id eIatXfbBqQA3 for <lists-debian-user@liszt.debian.org>;
Sun, 23 May 2010 08:50:38 +0000 (UTC)
X-policyd-weight: using cached result; rate: -7
Received: from hermes3.ccf.auth.gr (hermes3.ccf.auth.gr [155.207.1.69])
(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
(Client CN "AUTH Mail Servers", Issuer "AUTH Network Operations Center Certification Authority R3" (not verified))
by liszt.debian.org (Postfix) with ESMTPS id EBE3C13A50F3
for <debian-user@lists.debian.org>; Sun, 23 May 2010 08:50:37 +0000 (UTC)
Received: from [192.168.1.200] (79.103.217.59.dsl.dyn.forthnet.gr [79.103.217.59])
(authenticated bits=0)
by hermes3.ccf.auth.gr (8.14.4/8.14.4) with ESMTP id o4N8oVNt014099
(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT);
Sun, 23 May 2010 11:50:32 +0300
Message-ID: <4BF8EC56.7040706@ccf.auth.gr>
Date: Sun, 23 May 2010 11:50:30 +0300
From: =?UTF-8?B?zpPOuc+Oz4HOs86/z4IgzqDOrM67zrvOsc+C?=
<gpall@ccf.auth.gr>
User-Agent: Mozilla-Thunderbird 2.0.0.22 (X11/20090707)
MIME-Version: 1.0
To: AG <computing.account@googlemail.com>
CC: debian-user@lists.debian.org
Subject: Re: nepomuk indexer in systray
References: <4BF6707A.1010600@ccf.auth.gr> <4BF7B062.8070201@gmail.com>
In-Reply-To: <4BF7B062.8070201@gmail.com>
X-Enigmail-Version: 0.95.0
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg=sha1; boundary="------------ms010501010305060706080405"
X-Virus-Scanned: clamav-milter 0.96 at hermes1
X-Virus-Status: Clean
X-Rc-Virus: 2007-09-13_01
X-Rc-Spam: 2008-11-04_01
Resent-Message-ID: <0rS964MF7CO.A.9fH.rxO-LB@liszt>
Resent-From: debian-user@lists.debian.org
X-Mailing-List: <debian-user@lists.debian.org> archive/latest/577423
X-Loop: debian-user@lists.debian.org
List-Id: <debian-user.lists.debian.org>
List-Post: <mailto:debian-user@lists.debian.org>
List-Help: <mailto:debian-user-request@lists.debian.org?subject=help>
List-Subscribe: <mailto:debian-user-request@lists.debian.org?subject=subscribe>
List-Unsubscribe: <mailto:debian-user-request@lists.debian.org?subject=unsubscribe>
Precedence: list
Resent-Sender: debian-user-request@lists.debian.org
Resent-Date: Sun, 23 May 2010 08:50:51 +0000 (UTC)
This is a cryptographically signed message in MIME format.
On 21/05/10 12:37, =CE=93=CE=B9=CF=8E=CF=81=CE=B3=CE=BF=CF=82 =CE=A0=CE=
=AC=CE=BB=CE=BB=CE=B1=CF=82 wrote:
Hello to all!
I just upgraded my debian testing, installing nepomuk search. My
problem is that the indexer every now and then appears in the systray
for a second or so, and then disappears, which is very distracting
(or am I very sensitive? :-) )... Anyone knows how to stop the icon
from getting on my nerves? :-)
Thanks!
G.
Aside from disabling the damn thing from working automatically in the
first place - no.
KDE4 is becoming increasingly bloated and does seem to be calling in
an increasing amount of dependencies and additional database-related
libraries which then seemingly take over. Not OK.
My $0.02 worth.
AG
Agree... I also did not understand why some days ago as I upgraded my
debian testing + KDE, a hundred packets related to nepomuk were
installed, along with mysql server 5.1, and today as I upraded again,
mysql server was removed. What was that???
Dne, 23. 05. 2010 10:45:36 je Ron Johnson napisal(a):
Why?
I frequently burn double-layer DVDs, requiring around 8GB of free space
for temporary files. Until now, I had to do that on another rig. Also,
I'm planning to do some video editing, which, I'm told, likewise
requires huge amounts of temporary space. On my / partition, I have
nowhere *near* that amount of free space.
--
Regards,
Klistvud
Certifiable Loonix User #481801
http://bufferoverflow.tiddlyspot.com
--
To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: 1274605819.6845.2@compax">http://lists.debian.org/1274605819.6845.2@compax
05-23-2010, 10:28 AM
Moving /tmp to a separate partition. Advice?
On Sun, May 23, 2010 at 11:10:19AM +0200, Klistvud wrote:
> Dne, 23. 05. 2010 10:45:36 je Ron Johnson napisal(a):
> > Why?
> I frequently burn double-layer DVDs, requiring around 8GB of free space
> for temporary files. Until now, I had to do that on another rig. Also,
> I'm planning to do some video editing, which, I'm told, likewise
> requires huge amounts of temporary space. On my / partition, I have
> nowhere *near* that amount of free space.
IMHO, it is a good idea to implement LVM when possible.
In case you go on, I recently went through an actual BTDT situation:
Having /tmp mounted noexec,nosuid for security reasons, aptitude
failed to execute postinstall scripts.
The solution was to remount exec /tmp partition and rerun aptitude.
After that I had to add this to /etc/apt/apt.conf or under
/etc/apt/apt.conf.d/ (depends on your config)
On Sun, May 23, 2010 at 11:10:19AM +0200, Klistvud wrote:
Dne, 23. 05. 2010 10:45:36 je Ron Johnson napisal(a):
Why?
I frequently burn double-layer DVDs, requiring around 8GB of free
space for temporary files. Until now, I had to do that on another
rig. Also, I'm planning to do some video editing, which, I'm told,
likewise requires huge amounts of temporary space. On my /
partition, I have nowhere *near* that amount of free space.
Maybe there is an option in the config file of the application which you
use to burn DVDs that allows you to set the tmp dir?
Exactly. Either via $TMP, $TMPDIR, a command-line option or
app-specific variable.
--
Dissent is patriotic, remember?
--
To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
On Sun, May 23, 2010 at 11:10:19AM +0200, Klistvud wrote:
> Dne, 23. 05. 2010 10:45:36 je Ron Johnson napisal(a):
> >
> >Why?
> >
>
> I frequently burn double-layer DVDs, requiring around 8GB of free
> space for temporary files. Until now, I had to do that on another
> rig. Also, I'm planning to do some video editing, which, I'm told,
> likewise requires huge amounts of temporary space. On my /
> partition, I have nowhere *near* that amount of free space.
Maybe there is an option in the config file of the application which you
use to burn DVDs that allows you to set the tmp dir?
--
"Religion is excellent stuff for keeping common people quiet."
-- Napoleon Bonaparte
--
To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: 20100523122239.GC18258@fischer">http://lists.debian.org/20100523122239.GC18258@fischer
05-23-2010, 02:38 PM
Andrew Reid
Moving /tmp to a separate partition. Advice?
On Sunday 23 May 2010 04:37:18 Klistvud wrote:
> Howdy, fellow Debianites!
> Given some extra hard drive space, I decided to move my /tmp dir
> (currently located under / ) to a partition of its own. I am looking
> forward to any advice, particularly of the been-there-done-that type:
> * how should I configure my fstab entry? How does Debian installer do
> it?
Watch out for permissions -- /tmp is "1777" (rwxrwxrwt), it has to
be world-writable and have the sticky bit set, which ensures that only
users who create files in there can write to them. Permissions come
from the mounted FS, not the mount point, so make sure you set these
permissions while it's mounted.
Because of the world-writability, security conscious admins mount
it nodev and nosuid. If you're more careful, you can mount it noexec,
too, but that will break some third-party software installers that
work by examining your system, writing a custom config script inside
/tmp somewhere, and then running it.
So your fstab entry might look like:
> /dev/with/temp/ /tmp ext3 nosuid,nodev 0 2
> * is there anything Debian-specific to watch for?
Not that I recall.
> * is it true that setting /tmp permissions to non-executable, while
> hardening your box, prevents apt from working properly?
Setting /tmp to non-executable by the noexec mount option does break
things, but as I said above, my recollection is that it mostly breaks
third-party stuff. I think the apt scripts are all in /var/lib/dkpg/info,
and are run from there.
Setting the *directory* noexec seems very bad, since the exec bit
on directories controls the ability to cd to it, and turning that
off would make it largely useless.
As to "why", on moderately-high-availability multi-user systems, I
often put /tmp on a separate partition precisely so I can use mount
options to globally control access. This is more important in a
truly multi-user system than a home system, of course.
Misbehaving apps rarely but sometimes blow the lid off of /tmp, and
having it be on its own partition means this doesn't compromise the
system as a whole, and you can easily figure out what's going on by
seeing the logged errors and looking at "df" output. Some folks keep
/var/log on a separate partition for similar reasons.
Again, all of this is more important in a multi-user production
environment. On my home systems, I mostly don't worry about this
sort of thing.
-- A.
--
Andrew Reid / reidac@bellatlantic.net
--
To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: 201005231038.48482.reidac@bellatlantic.net">http://lists.debian.org/201005231038.48482.reidac@bellatlantic.net
05-23-2010, 03:00 PM
Rob Owens
Moving /tmp to a separate partition. Advice?
On Sun, May 23, 2010 at 10:37:18AM +0200, Klistvud wrote:
> Howdy, fellow Debianites!
> Given some extra hard drive space, I decided to move my /tmp dir
> (currently located under / ) to a partition of its own. I am looking
> forward to any advice, particularly of the been-there-done-that type:
> * how should I configure my fstab entry? How does Debian installer do
> it?
> * is there anything Debian-specific to watch for?
> * is it true that setting /tmp permissions to non-executable, while
> hardening your box, prevents apt from working properly?
>
Don't forget that the permissions on /tmp are:
rwxrwxrwt
If /tmp is its own partition, you might consider using ext2 for speed.
You could also consider RAID 0, if you have mulitple drives.
-Rob
--
To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: 20100523150009.GC23289@aurora.owens.net">http://lists.debian.org/20100523150009.GC23289@aurora.owens.net
05-23-2010, 05:12 PM
Klistvud
Moving /tmp to a separate partition. Advice?
Thanx for your exhaustive answer, it's an enlightening read. The point
that appears particularly interesting to me personally is:
Permissions come
from the mounted FS, not the mount point, so make sure you set these
permissions while it's mounted.
It's always good to learn something new.
--
Regards,
Klistvud
Certifiable Loonix User #481801
http://bufferoverflow.tiddlyspot.com
--
To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: 1274634775.6845.3@compax">http://lists.debian.org/1274634775.6845.3@compax
05-23-2010, 05:14 PM
Klistvud
Moving /tmp to a separate partition. Advice?
Dne, 23. 05. 2010 17:00:09 je Rob Owens napisal(a):
If /tmp is its own partition, you might consider using ext2 for speed.
You could also consider RAID 0, if you have mulitple drives.
A good suggestion, thanx. What about ext4, is it slower or faster than
ext2?
--
Regards,
Klistvud
Certifiable Loonix User #481801
http://bufferoverflow.tiddlyspot.com
--
To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: 1274634861.6845.4@compax">http://lists.debian.org/1274634861.6845.4@compax