1 |
Hi! |
2 |
|
3 |
Ok. Since there is GLEP27 we should make it reality. To do so i think we |
4 |
should |
5 |
1. Have some list of system uid/gid (on wiki for example). Also we need |
6 |
to agree on uid/gid numbers for services |
7 |
2. Add uid/gid from list to existing ebuilds |
8 |
3. Make a repoman (or may be eclass) check, that will no allow to commit |
9 |
ebuilds with enewuser enewgroup calls with undefined uids |
10 |
4. Make some script or howto to migrate to determenistic uids/gids from |
11 |
1 |
12 |
|
13 |
|
14 |
|
15 |
Robin H. Johnson писал 13-12-2015 23:41: |
16 |
> On Sun, Dec 13, 2015 at 09:03:51PM +0300, Alexey Shvetsov wrote: |
17 |
>> Hi all! |
18 |
>> |
19 |
>> We trying to use ldap for users @work, many of our workstations |
20 |
>> running |
21 |
>> binary gentoo based distro called Calculate linux. However if we wanna |
22 |
>> have wide use of ldap there is a need for determenistic system group |
23 |
>> gids names and user uids. |
24 |
>> |
25 |
>> Many ebuilds in tree uses enewgroup and enewuser with -1 (aka next |
26 |
>> available parameter)[1]. However it will be much better to set distro |
27 |
>> wide deterministic uid and gid for system service name. So for example |
28 |
>> ldap users may have determenistic groups like video, audio, plugdev, |
29 |
>> etc.. |
30 |
> GLEP27 was approved for this, however it is barely used. |
31 |
> |
32 |
> Convert the rest of the tree to use it, and then you'll be done, aside |
33 |
> from the existing mess on user systems. |
34 |
|
35 |
-- |
36 |
Best Regards, |
37 |
Alexey 'Alexxy' Shvetsov |
38 |
Best Regards, |
39 |
Alexey 'Alexxy' Shvetsov, PhD |
40 |
Department of Molecular and Radiation Biophysics |
41 |
FSBI Petersburg Nuclear Physics Institute, NRC Kurchatov Institute, |
42 |
Leningrad region, Gatchina, Russia |
43 |
Gentoo Team Ru |
44 |
Gentoo Linux Dev |
45 |
mailto:alexxyum@×××××.com |
46 |
mailto:alexxy@g.o |
47 |
mailto:alexxy@×××××××××××××.ru |