| Summary: | systemd rootfs-postprocess command should check staticids | ||
|---|---|---|---|
| Product: | [Build System, Metadata & Runtime] OE-Core | Reporter: | Stephano Cetola <stephano> |
| Component: | core | Assignee: | Himani Barde <HimaniRamesh.Barde> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | normal | ||
| Priority: | Medium | CC: | chuckwolber, joshuagloe, meta.mr.watcher, meta.watcher, patrick.ohly, randy.macleod, richard.purdie |
| Version: | 2.1 | ||
| Target Milestone: | 6.99 | ||
| Hardware: | x86 | ||
| OS: | Multiple | ||
| Whiteboard: | RETEST | ||
| OS type for building Yocto: | --- | Type of Regression: | --- |
| Verified: | Documentation change: | No (bug/feature does not impact docs) | |
|
Description
Stephano Cetola
2016-06-16 15:43:48 UTC
Here's how Ostro OS solved this: https://github.com/ostroproject/ostro-os/commits/master/meta-ostro/classes/systemd-sysusers.bbclass Refkit still has the same class. I'm running into this in another distro. Is this still on the table for fixing in 2.4? I believe the window for 2.4M4 has closed though I will discuss this with the team today. If it is possible to include this in 2.4 I'll get it submitted today. Moving this to 2.5M1. I will backport to Rocko (2.4.1) if needed. Bulk move from 4.99 or 0.00 to 5.99 Himani - please take a look and see if you can retest. Retested on openembedded-core master branch.
The original issue has been fixed by commit 0c7e76df68 ("rootfs-postcommands: change sysusers.d command", 2023-06-15) by Louis Rannou.
The old systemd_create_users function, which created users/groups at rootfs time without checking static IDs, has been completely replaced by systemd_sysusers_check. The new function does NOT create users/groups — it only validates that users/groups defined in sysusers.d/*.conf already exist in /etc/passwd and /etc/group with consistent properties.
Static IDs are now enforced by useradd-staticids.bbclass at recipe parse time, before any user creation occurs. The rootfs postprocess step just verifies consistency afterward.
A follow-up commit 2a700c3102 (2023-12-27) further relaxed the check to ignore comment mismatches.
This bug can be marked as RESOLVED/FIXED.
As per Himani's comment. Stephano, re-open if you disagree. |