1 |
On Sat, 17 Aug 2019 10:35:29 +0200 |
2 |
Ulrich Mueller <ulm@g.o> wrote: |
3 |
|
4 |
> For example, "nobody" lives in /var/empty but cannot write to it, and |
5 |
> that dir is owned by root. |
6 |
|
7 |
What ensures that the permissions on /var/empty are correct for this |
8 |
scenario? |
9 |
|
10 |
Possibly having acct-* create a /var/lib/nobody or a /var/lib/ssh (or |
11 |
similar) _and_ ensure the no-write permissions are correct could be a |
12 |
feature? |
13 |
|
14 |
Maybe this needs to be a feature or something in the eclass? |
15 |
|
16 |
> ACCT_HOME_NOWRITE=1 |
17 |
|
18 |
* eclass decides what HOME should be (maybe just /var/empty, |
19 |
/var/lib/nobody or, say, /var/lib/no-write/nobody) |
20 |
|
21 |
* eclass ensures -w for u,g,o |