Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 19 May 2003 15:43:29 +0300
From:      Ruslan Ermilov <ru@freebsd.org>
To:        Andy Farkas <andyf@speednet.com.au>
Cc:        current@freebsd.org
Subject:   Re: man(1) oddity - was: HEADS UP: bzip2(1) compression for manpages...
Message-ID:  <20030519124329.GC28176@sunbay.com>
In-Reply-To: <20030519220657.A93323-100000@hewey.af.speednet.com.au>
References:  <20030519120212.GJ17366@sunbay.com> <20030519220657.A93323-100000@hewey.af.speednet.com.au>

next in thread | previous in thread | raw e-mail | index | archive | help

--xo44VMWPx7vlQ2+2
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Mon, May 19, 2003 at 10:21:58PM +1000, Andy Farkas wrote:
> On Mon, 19 May 2003, Ruslan Ermilov wrote:
> >
> > Then realize what I've been trying to tell you: this is not the
> > problem of root vs. non-root, rather the message is only displayed
> > if we create a catpage, and we know we'll only display it to the
> > user after the whole manpage is formatted.  My example with
> > renaming cat8 was ought to hint you about this.
>=20
> Please realise what I've been trying to tell you: there is a difference in
> the user experience when one types `man ppp` on a 4.8 box and when one
> types `man ppp` on a 5.1-B box.  On a 4.8 box the user types `man ppp`,
> gets a message, then waits around 10 seconds for the page to display. On a
> 5.1-B box the user types `man ppp` and DOES NOT GET A MESSAGE BUT HAS TO
> WAIT 10 SECONDS before the page is displayed.
>=20
You got an explanation.  This is not really different between 4.8 and
5.1, nor is it root-specific.  Rather, it's a matter of creating or
nor creating the catpages.  It's up to the administrator to either
enable or disable the creation of catpages.  For slow machines, I'd
suggest formatting the manpages at buildworld time, by setting the
MANBUILDCAT=3D in /etc/make.conf.

> You keep saying that the page will be displayed quickly because groff is
> piping it to the pager, but this does not happen - there is always a
> considerable delay perhaps because groff is formatting..
>=20
I keep saying that formatting and displaying a manpage simultaneously
will give a quicker output than formatting the whole page, compressing
it, saving it, uncompressing it, and start displaying.

> > What are you proposing?  Should we display every action that
> > we're making?
>=20
> I want the same behaviour as is in 4.8-RELEASE.
>=20
So you want that catpages be again created in 5.1?  Like I said,
I am slowly working on this.

> > In other words: THERE IS NOTHING TO WAIT FOR in the case when
> > a catpage is not created, man(1) already launches the command
> > that will display you the output; the fact that it's somewhat
> > slow is irrelevant here.  When, on the other hand, a catpage
> > is getting created, the command that displays the output is
> > NOT run immediately; rather, a "Please wait, formatting ..."
> > is displayed, the formatting is done (and the result is saved
> > to a .cat file), and only after that the command that shows
> > you the manpage (catpage) is run:
>=20
> So it IS a root vs. non-root thing, because non-root cannot create a
> catpage anymore.
>=20
So, you want setuid man(1) binary back only to be able to see that
message again?  Be careful in what you ask, you may get it:

%%%
Index: Makefile
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
RCS file: /home/ncvs/src/gnu/usr.bin/man/man/Makefile,v
retrieving revision 1.33
diff -u -r1.33 Makefile
--- Makefile	15 Jan 2002 14:11:05 -0000	1.33
+++ Makefile	19 May 2003 12:37:36 -0000
@@ -20,6 +20,13 @@
 CFLAGS+=3D -DDO_COMPRESS -DCATMODE=3D0644
 CLEANFILES+=3D	man.1
=20
+.if defined(ENABLE_SUID_MAN)
+CFLAGS+=3D -DSETUID
+BINOWN=3D	man
+BINMODE=3D 4555
+INSTALLFLAGS=3D -fschg
+.endif
+
 .PATH:	${.CURDIR}/../manpath
=20
 man.1: ${.CURDIR}/man.man
%%%

But beware of consequences of re-enabling this:

: revision 1.33
: date: 2002/01/15 14:11:05;  author: ru;  state: Exp;  lines: +1 -4
: Do not install man(1) setuid ``man''.
:=20
: The catpaging and setuidness features of man(1) combined make
: it vulnerable to a number of security attacks.  Specifically,
: it was possible to overwrite system catpages with arbitrarily
: contents by either setting up a symlink to a directory holding
: system catpages, or by writing custom -mdoc or -man groff(1)
: macro packages and setting up GROFF_TMAC_PATH in environment
: to point to them.  (See PR below for details).
:=20
: This means man(1) can no longer create system catpages on a
: regular user's behalf.  (It is still able to if the user has
: write permissions to the directory holding catpages, e.g.,
: user's own manpages, or if the running user is ``root''.)
:=20
: To create and install catpages during ``make world'', please
: set MANBUILDCAT=3DYES in /etc/make.conf.  To rebuild catpages
: on a weekly basis, please set weekly_catman_enable=3D"YES" in
: /etc/periodic.conf.
:=20
: PR:             bin/32791

> > Scenario 1:		Scenario 2:
> > Please wait...,		format | display (simultaneously)
> > then format,
> > then display.
>=20
>=20
> Scene 1 does not happen for a Normal user anymore. Please understand this.
> The message does not appear to the user.
>=20
But this doesn't mean that "scenario 2" should display it either.


Cheers,
--=20
Ruslan Ermilov		Sysadmin and DBA,
ru@sunbay.com		Sunbay Software AG,
ru@FreeBSD.org		FreeBSD committer,
+380.652.512.251	Simferopol, Ukraine

http://www.FreeBSD.org	The Power To Serve
http://www.oracle.com	Enabling The Information Age

--xo44VMWPx7vlQ2+2
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (FreeBSD)

iD8DBQE+yNFxUkv4P6juNwoRAogjAJ9XsYo/fMfq4XSDRK30yv8BmQ0y5ACcDa44
TFR64duwrd3LLhQSmzZMU04=
=6Ksz
-----END PGP SIGNATURE-----

--xo44VMWPx7vlQ2+2--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20030519124329.GC28176>