From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from lists.gentoo.org (pigeon.gentoo.org [208.92.234.80]) by finch.gentoo.org (Postfix) with ESMTP id A823B1384B4 for ; Mon, 14 Dec 2015 06:06:13 +0000 (UTC) Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id 16F7121C064; Mon, 14 Dec 2015 06:06:06 +0000 (UTC) Received: from smtp.gentoo.org (smtp.gentoo.org [140.211.166.183]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by pigeon.gentoo.org (Postfix) with ESMTPS id 2C7C821C00B for ; Mon, 14 Dec 2015 06:06:05 +0000 (UTC) Received: from grubbs.orbis-terrarum.net (localhost [127.0.0.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by smtp.gentoo.org (Postfix) with ESMTPS id DB584340942 for ; Mon, 14 Dec 2015 06:06:02 +0000 (UTC) Received: (qmail 24209 invoked by uid 10000); 14 Dec 2015 06:06:02 -0000 Date: Mon, 14 Dec 2015 06:06:02 +0000 From: "Robin H. Johnson" To: gentoo-dev@lists.gentoo.org Subject: Re: [gentoo-dev] Use GLEP27! Message-ID: References: <22c8fc780e34e11cc460dcadda4202b4@omrb.pnpi.spb.ru> Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-dev@lists.gentoo.org Reply-to: gentoo-dev@lists.gentoo.org MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: User-Agent: Mutt/1.5.24 (2015-08-30) X-Archives-Salt: c9c38b81-aa50-42ca-a319-ceae415c860d X-Archives-Hash: cfbe3b15f26e68a24b99f6d18299b184 On Mon, Dec 14, 2015 at 07:49:42AM +0300, Alexey Shvetsov wrote: > Hi! > > Ok. Since there is GLEP27 we should make it reality. To do so i think we > should > 1. Have some list of system uid/gid (on wiki for example). Also we need > to agree on uid/gid numbers for services This database was already started, prior to GLEP27. In CVS, you want gentoo-src/eid_database/ > 2. Add uid/gid from list to existing ebuilds > 3. Make a repoman (or may be eclass) check, that will no allow to commit > ebuilds with enewuser enewgroup calls with undefined uids I think in the original discussion, there were concerns that there were cases where this was going to be valid. I think this check needs to come later, after we rule those out. It should however start to warn about them ASAP. > 4. Make some script or howto to migrate to determenistic uids/gids from Much of the work was implemented for GSOC2006, "Creandus" by developer pioto. Cardoe did more work on it later on. -- Robin Hugh Johnson Gentoo Linux: Developer, Infrastructure Lead, Foundation Trustee E-Mail : robbat2@gentoo.org GnuPG FP : 11ACBA4F 4778E3F6 E4EDF38E B27B944E 34884E85