Bug 11043

Summary: inconsistent shadow backup files
Product: [Build System, Metadata & Runtime] OE-Core Reporter: Patrick Ohly <patrick.ohly>
Component: devtools / tool chainAssignee: Changqing Li <changqing.li>
Status: RESOLVED WORKSFORME QA Contact:
Severity: normal    
Priority: Medium CC: meta.mr.watcher, meta.watcher, randy.macleod, ross.burton
Version: unspecified   
Target Milestone: 2.7   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: No (bug/feature does not impact docs)

Description Patrick Ohly 2017-02-10 11:28:02 UTC
In bug #11007 it was found that removing a user during the rootfs construction leads to a /etc/shadow- file with a "games" entry that does not exit in the corresponding /etc/passwd-.

This looks like a bug in the "shadow" scripts which create these backup files.
It is not relevant for rootfs construction (the solution for #11007 will be to remove the backup files), but might hint towards something that could have bigger impact elsewhere (runtime?) and thus should be investigated.
Comment 1 Maxin B. John 2017-02-13 09:18:21 UTC
password related backup files created (from shadow-utils) during image build time, should not be present in the final image. Ideally, we should delete those files and run "pwck" and "grpck" during image creation time to verify the integrity of password and group files.
Comment 2 Patrick Ohly 2017-02-13 10:02:13 UTC
(In reply to comment #1)
> password related backup files created (from shadow-utils) during image build
> time, should not be present in the final image. Ideally, we should delete
> those files

I'm doing that now as solution for bug #11007 (patch pending). However, this bug here is about the code which led to the inconsistent backup files in the first place - IMHO that shouldn't have happened.

> and run "pwck" and "grpck" during image creation time to verify
> the integrity of password and group files.

Sounds like a useful QA check.
Comment 3 Ross Burton 2017-04-19 15:51:31 UTC
The patch to remove backup files was merged in OE-Core e5628c80a52f3caeea9d9dc7f67d1b8a61222aef.
Comment 4 Ross Burton 2017-10-13 15:56:33 UTC
Reassigning to 2.5M2.  Removing the files at rootfs time means they're not inconsistant but something was writing the bad files in the first place...
Comment 5 Randy MacLeod 2018-10-18 15:15:25 UTC
@changqing, First step is to check if there are oeqa stress tests for adding/removing users/groups. We were going to just delete this defect since people think that everything works well now but I'd like to be 100% sure that things are solid. I'm sure Ross will have some ideas about how to test as well.
Comment 6 Changqing Li 2018-11-12 09:43:01 UTC
@Randy, I checked current test cases, there is no testcase that designed to test
adding/removing users/groups. only have 2 testcase under selftest,  which designed to test ssh with/without passwd, during test, use useradd and usermod. (see imagefeatures.py)

And I retest Bug11007 today, even I revert commit e5628c80a52f3caeea9d9dc7f67d1b8a61222aef, I can build success, and after boot,
I checked passwd- and shadow- both don't have account games.


I think maybe we can close this defect and open a new enhancement defect for 
add testcases to test adding/removing users/groups. Maybe Ross  can comments
his idea about the testcases in the new enhacement defect.
Comment 7 Changqing Li 2018-12-04 08:12:04 UTC
cannot reproduce bug 11007 event revert commit e5628c80a52f3caeea9d9dc7f67d1b8a61222aef