Bug 10442 - avahi: deluser and delgroup in postrm script
Summary: avahi: deluser and delgroup in postrm script
Status: RESOLVED FIXED
Alias: None
Product: OE-Core
Classification: Build System, Metadata & Runtime
Component: connectivity (show other bugs)
Version: 2.2
Hardware: All Multiple
: Medium+ normal
Target Milestone: 2.3 M2
Assignee: Jussi Kukkonen
QA Contact: Juan Ramos
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2016-10-17 08:13 UTC by Markus Lehtonen
Modified: 2016-11-21 23:02 UTC (History)
4 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Markus Lehtonen 2016-10-17 08:13:14 UTC
This bug stemmed from the discussion in bug 10299.

I think that packages shouldn't remove users or groups in postrm scriptlets. Otherwise the system may be left with files with non-existent owner. It may even cause security issues if somebody, at a later time, adds a new user or group with the used-to-be-avahi UID or GID. In this case the new user has full access to the leftover files, e.g. configuration or log files.
Comment 1 Jussi Kukkonen 2016-10-17 08:34:43 UTC
This seems reasonable: if we wanted to remove users it should be part of USERADD machinery anyway, not up to individual postrm functions.

distcc has the same issue.
Comment 2 Maxin B. John 2016-10-17 12:23:52 UTC
In #9262, we had a similar discussion and "unofficially" agreed that we won't delete the existing users/groups from the rootfs.

https://bugzilla.yoctoproject.org/show_bug.cgi?id=9262#c2
Comment 3 Jussi Kukkonen 2016-11-07 08:41:23 UTC
Fixed in poky:

commit 5354a4a315550f71686af17b42818cb1976a7f19
Author: Jussi Kukkonen <jussi.kukkonen@intel.com>
Date:   Mon Oct 31 15:40:18 2016 +0200

    distcc: Don't remove users/groups in postrm
    
    There's no way to ensure that files owned by the users aren't left
    on the system at postrm time: Removing the user would mean those
    files are now owned by a non-existing user, and later may be owned
    by a completely unrelated new user.
    
    (From OE-Core rev: 776370efb9fa48b82ac991e3d001accd122d611b)
    
    Signed-off-by: Jussi Kukkonen <jussi.kukkonen@intel.com>
    Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>

commit b1e1c12a3f4d6a06aaf2ed18b1f2a9a7de5f0198
Author: Jussi Kukkonen <jussi.kukkonen@intel.com>
Date:   Mon Oct 31 15:40:17 2016 +0200

    avahi: Don't remove users/groups in postrm
    
    There's no way to ensure that files owned by the users aren't left
    on the system at postrm time: Removing the user would mean those
    files are now owned by a non-existing user, and later may be owned
    by a completely unrelated new user.
    
    [YOCTO #10442]
    
    (From OE-Core rev: c1be2196e7ffb23b7b243ecd8aca1827cbdfa443)
    
    Signed-off-by: Jussi Kukkonen <jussi.kukkonen@intel.com>
    Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>