Gentoo Archives: gentoo-dev

From: Mike Gilbert <floppym@g.o>
To: Gentoo Dev <gentoo-dev@l.g.o>
Subject: Re: [gentoo-dev] [PATCH] acct-user.eclass: don't modify existing user by default
Date: Mon, 04 Jan 2021 16:11:07
Message-Id: CAJ0EP43J-nuBopP9w9Q86vMpNq_7uCMkJ9cXjsKmfBDdY97UkQ@mail.gmail.com
In Reply to: Re: [gentoo-dev] [PATCH] acct-user.eclass: don't modify existing user by default by "Michał Górny"
1 On Mon, Jan 4, 2021 at 4:23 AM Michał Górny <mgorny@g.o> wrote:
2 >
3 > On Mon, 2021-01-04 at 02:35 +0100, Thomas Deutschmann wrote:
4 > > Modifying an existing user is a bad default and makes Gentoo
5 > > special because it is common for system administrators to make
6 > > modifications to user (i.e. putting an user into another service's
7 > > group to allow that user to access service in question) and it
8 > > would be unexpected to see these changes reverted during normal
9 > > world upgrade (which could break services).
10 >
11 > Not modifying an existing user is a horrible default that has already
12 > bricked one system (by removing /dev/null). So, over my dead commit
13 > access.
14
15 As the eclass maintainer, would you be willing to merge a similar
16 patch that enables user modifications by default, but provides
17 sysadmins a way to disable it?
18
19 I have a feeling that there will not be a consensus on the default
20 behavior, and I could see that getting escalated to council. However,
21 it might be nice to provide people with the option in the meantime.

Replies