public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
Search results ordered by [date|relevance]  view[summary|nested|Atom feed]
thread overview below | download: 
* Re: [gentoo-dev] user management mitigation
  @ 2011-12-04 17:12 99%     ` Mike Gilbert
  0 siblings, 0 replies; 1+ results
From: Mike Gilbert @ 2011-12-04 17:12 UTC (permalink / raw
  To: gentoo-dev

[-- Attachment #1: Type: text/plain, Size: 1175 bytes --]

On 12/04/2011 09:44 AM, Leho Kraav wrote:
> So after a reading through a bunch of stuff [1][2][3][4][5], what I'm going to do for the goal above is:
> 
>  * move to sys-apps/shadow trunk [6]
>  * fork my own user.eclass from v1.17, modify it to use --root $ROOT when calling shadow stuff

I think a possible problem here would be a build system that uses
user/group id's from the host root during the build process. If any
packages do this, it is possible that the users/groups would need to be
added in both /etc/passwd and ${ROOT}etc/passwd.

>  * stick my user.eclass into myoverlay/eclass/
>  * # echo "lkraav" > myoverlay/profiles/repo_name
>  * # echo "[DEFAULT]\neclass-overrides = lkraav" > /etc/portage/repos.conf
>  * # echo "PORTAGE_RSYNC_EXTRA_OPTS=\"--exclude=/metadata/cache\"" >> /etc/make.conf
>  * # rm -rf /usr/portage/metadata/cache
>  * # echo "emerge --regen" >> /etc/cron.weekly/09-my-portage-update-script

That sounds about right.

>  * subscribe to atom feed of portage user.eclass changes, merge stuff until sys-apps/shadow-4.1.4.5 surfaces and maybe main tree user.eclass gets patched to use --root

We have one of those!?


[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 230 bytes --]

^ permalink raw reply	[relevance 99%]

Results 1-1 of 1 | reverse | options above
-- pct% links below jump to the message on this page, permalinks otherwise --
     [not found]     <i46IO-6A-19@gated-at.bofh.it>
     [not found]     ` <i46IO-6A-17@gated-at.bofh.it>
2011-12-04 14:44       ` [gentoo-dev] user management mitigation Leho Kraav
2011-12-04 17:12 99%     ` Mike Gilbert

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox