In bug #11007 it was found that removing a user during the rootfs construction leads to a /etc/shadow- file with a "games" entry that does not exit in the corresponding /etc/passwd-. This looks like a bug in the "shadow" scripts which create these backup files. It is not relevant for rootfs construction (the solution for #11007 will be to remove the backup files), but might hint towards something that could have bigger impact elsewhere (runtime?) and thus should be investigated.
password related backup files created (from shadow-utils) during image build time, should not be present in the final image. Ideally, we should delete those files and run "pwck" and "grpck" during image creation time to verify the integrity of password and group files.
(In reply to comment #1) > password related backup files created (from shadow-utils) during image build > time, should not be present in the final image. Ideally, we should delete > those files I'm doing that now as solution for bug #11007 (patch pending). However, this bug here is about the code which led to the inconsistent backup files in the first place - IMHO that shouldn't have happened. > and run "pwck" and "grpck" during image creation time to verify > the integrity of password and group files. Sounds like a useful QA check.
The patch to remove backup files was merged in OE-Core e5628c80a52f3caeea9d9dc7f67d1b8a61222aef.
Reassigning to 2.5M2. Removing the files at rootfs time means they're not inconsistant but something was writing the bad files in the first place...
@changqing, First step is to check if there are oeqa stress tests for adding/removing users/groups. We were going to just delete this defect since people think that everything works well now but I'd like to be 100% sure that things are solid. I'm sure Ross will have some ideas about how to test as well.
@Randy, I checked current test cases, there is no testcase that designed to test adding/removing users/groups. only have 2 testcase under selftest, which designed to test ssh with/without passwd, during test, use useradd and usermod. (see imagefeatures.py) And I retest Bug11007 today, even I revert commit e5628c80a52f3caeea9d9dc7f67d1b8a61222aef, I can build success, and after boot, I checked passwd- and shadow- both don't have account games. I think maybe we can close this defect and open a new enhancement defect for add testcases to test adding/removing users/groups. Maybe Ross can comments his idea about the testcases in the new enhacement defect.
cannot reproduce bug 11007 event revert commit e5628c80a52f3caeea9d9dc7f67d1b8a61222aef