public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-dev] Don't use UIDs and GIDs below 100 without QA approval
@ 2021-11-11 10:59 Ulrich Mueller
  2021-11-11 11:34 ` Florian Schmaus
                   ` (4 more replies)
  0 siblings, 5 replies; 31+ messages in thread
From: Ulrich Mueller @ 2021-11-11 10:59 UTC (permalink / raw
  To: gentoo-dev

[-- Attachment #1: Type: text/plain, Size: 974 bytes --]

May I remind everybody that by QA policy allocation of UIDs and GIDs
in the range 0..100 needs explicit approval by the QA lead:
https://projects.gentoo.org/qa/policy-guide/user-group.html#pg0901

I have fixed the used_free_uidgids.sh script such that it will no longer
recommend any IDs below 101.

In any case, we have run out of GIDs:

   Recommended GID only: none
   Recommended UID only: 272
   Recommended UID+GID pair: none
   Free UIDs: 15
   Free GIDs: 0
   Free UID+GID pairs: 0

The question is of course how we should move forward. Certainly, using
IDs below 100 cannot be the solution, as we would run out of these very
soon.

We could:

- Open some part of the range between 500 and 1000. For example,
  500..799, which would leave 200 IDs for dynamic allocation.

- Open part of the range 60001..65533. Not sure if all software will be
  happy with that.

- Admit that the concept of static allocation has failed, and return to
  dynamic allocation.

Ulrich

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 507 bytes --]

^ permalink raw reply	[flat|nested] 31+ messages in thread

end of thread, other threads:[~2021-11-29 14:17 UTC | newest]

Thread overview: 31+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2021-11-11 10:59 [gentoo-dev] Don't use UIDs and GIDs below 100 without QA approval Ulrich Mueller
2021-11-11 11:34 ` Florian Schmaus
2021-11-11 11:40   ` Joonas Niilola
2021-11-11 11:48   ` Ulrich Mueller
2021-11-11 12:10     ` Pacho Ramos
2021-11-11 12:32       ` Jaco Kroon
2021-11-11 12:45         ` Ulrich Mueller
2021-11-11 12:13     ` Ionen Wolkens
2021-11-11 14:52     ` Florian Schmaus
2021-11-11 11:49   ` Rich Freeman
2021-11-11 18:31 ` Mike Gilbert
2021-11-11 19:08   ` Ulrich Mueller
2021-11-11 19:18     ` Mike Gilbert
2021-11-11 22:07 ` James Cloos
2021-11-13 10:08   ` Ulrich Mueller
2021-11-14 20:14 ` Ulrich Mueller
2021-11-14 20:15 ` Thomas Deutschmann
2021-11-14 23:37   ` Ulrich Mueller
2021-11-15  6:36   ` Eray Aslan
2021-11-28  4:13     ` William Hubbs
2021-11-28 10:06       ` Ulrich Mueller
2021-11-28 19:06         ` William Hubbs
2021-11-28 19:15           ` Michał Górny
2021-11-28 20:46             ` William Hubbs
2021-11-28 20:56               ` William Hubbs
2021-11-28 19:57         ` Michael Orlitzky
2021-11-28 20:26           ` William Hubbs
2021-11-28 20:34             ` Mike Gilbert
2021-11-28 20:42             ` Gordon Pettey
2021-11-28 20:52               ` William Hubbs
2021-11-29 14:17         ` Eray Aslan

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox