Gentoo Archives: gentoo-dev

From: Lars Wendler <polynomial-c@g.o>
To: Michael Orlitzky <mjo@g.o>
Cc: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] RFC: UID/GID assignment for apache (81)
Date: Tue, 13 Aug 2019 18:30:50
Message-Id: 20190813203035.6ab9e9b7@abudhabi.paradoxon.rec
In Reply to: Re: [gentoo-dev] RFC: UID/GID assignment for apache (81) by Michael Orlitzky
1 On Tue, 13 Aug 2019 14:21:29 -0400 Michael Orlitzky wrote:
2
3 >On 8/13/19 1:53 PM, Lars Wendler wrote:
4 >>
5 >> thanks for the review. I've force-pushed the acct-user/apache commit
6 >> with ACCT_USER_HOME_OWNER being set to root:root.
7 >>
8 >
9 >Is there any benefit to
10 >
11 > ACCT_USER_HOME=/var/www
12 > ACCT_USER_HOME_OWNER=root:root
13 >
14 >versus
15 >
16 > keepdir /var/www
17 >
18 >in the eclass?
19
20 If we leave ACCT_USER_HOME empty HOME will be set to
21 /dev/null for apache user. I don't know if this is what we want.
22
23 >I think root:root is correct for /var/www, but setting it explicitly
24 >will clobber any existing permissions that the administrator or other
25 >packages have set. For example, if my web developers have write access
26 >to /var/www via group membership, then when I install acct-user/apache,
27 >/var/www will get set back to root:root with mode 755 and they'll be
28 >locked out temporarily.
29 >
30
31 Lars
32
33 --
34 Lars Wendler
35 Gentoo package maintainer
36 GPG: 21CC CF02 4586 0A07 ED93 9F68 498F E765 960E 9B39

Replies

Subject Author
Re: [gentoo-dev] RFC: UID/GID assignment for apache (81) Michael Orlitzky <mjo@g.o>