Gentoo Archives: gentoo-dev

From: Kent Fredric <kentnl@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] RFC: GLEP81 home directory guidelines
Date: Sat, 17 Aug 2019 18:03:03
Message-Id: 20190818060210.171e8d1f@katipo2.lan
In Reply to: Re: [gentoo-dev] RFC: GLEP81 home directory guidelines by Ulrich Mueller
1 On Sat, 17 Aug 2019 10:35:29 +0200
2 Ulrich Mueller <ulm@g.o> wrote:
3
4 > For example, "nobody" lives in /var/empty but cannot write to it, and
5 > that dir is owned by root.
6
7 What ensures that the permissions on /var/empty are correct for this
8 scenario?
9
10 Possibly having acct-* create a /var/lib/nobody or a /var/lib/ssh (or
11 similar) _and_ ensure the no-write permissions are correct could be a
12 feature?
13
14 Maybe this needs to be a feature or something in the eclass?
15
16 > ACCT_HOME_NOWRITE=1
17
18 * eclass decides what HOME should be (maybe just /var/empty,
19 /var/lib/nobody or, say, /var/lib/no-write/nobody)
20
21 * eclass ensures -w for u,g,o