GNU bug report logs - #34494
proot-based non-root setup: refusing to run with elevated privileges (UID 0)

Previous Next

Package: guix;

Reported by: Florian Thevissen <mail <at> florian-thevissen.de>

Date: Fri, 15 Feb 2019 21:10:02 UTC

Severity: normal

Tags: notabug

Done: Ludovic Courtès <ludo <at> gnu.org>

Bug is archived. No further changes may be made.

Full log


Message #5 received at submit <at> debbugs.gnu.org (full text, mbox):

From: Florian Thevissen <mail <at> florian-thevissen.de>
To: bug-Guix <at> gnu.org
Subject: proot-based non-root setup: refusing to run with elevated privileges
 (UID 0)
Date: Fri, 15 Feb 2019 21:39:21 +0100
[Message part 1 (text/plain, inline)]
Hi,

I am trying to get guix to run on a system where I do not have root 
access, following a guide by pjotrp involving proot, here: 
https://github.com/pjotrp/guix-notes/blob/master/GUIX-NO-ROOT.org .

All guix operations that involve the script perform-download fail with 
the error:

   guix perform-download: error: refusing to run with elevated
   privileges (UID 0)

I am not sure if this hints at a bug in guix itself, but a comment in 
the guix sources lets me assume so. It says in package-management.scm:355

   “Note that scripts like ‘guix perform-download’ do not run as root (…)”

In my setup, following this guide, however, it apparently is run as 
root, and (assert-low-privileges) in the script perform-download.scm:89 
acts accordingly by signalling the error and exiting.

(By the way - running guix-daemon with proot root privileges fails (-0), 
and running it without (no -0) fails also.)

Now my question: why is perform-download run as root following pjotrs 
guide, and is there anything that can be done about it?

I am a bit at a loss here, being unfamiliar with the guix sources and 
overall system setup.

Looking forward to help, thanks,

Florian

​
[Message part 2 (text/html, inline)]

This bug report was last modified 6 years and 76 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.