mbox series

[bug#34730,0/4] Add (gnu build accounts) and use it to create /etc/passwd & co.

Message ID 20190304111213.8436-1-ludo@gnu.org
Headers show
Series Add (gnu build accounts) and use it to create /etc/passwd & co. | expand

Message

Ludovic Courtès March 4, 2019, 11:12 a.m. UTC
Hello Guix!

This patch series adds a new module, (gnu build accounts), and
uses it to create /etc/{passwd,group,shadow} upon system activation.

This replaces functionality currently provided by the Shadow
command-line tools (‘useradd’, ‘usermod’, etc.) and libc (‘getspnam’,
‘putpwent’, and all these wonderful APIs.)

It’s more code on our side, but it’s overall much less code involved
to create those databases.  The code makes the UID/GID allocation
strategy and state handling (preserving passwords and UIDs/GIDs, not
reusing currently-used UIDs/GIDs, etc.) much clearer and auditable.
Previously all this was buried in imperative calls to ‘useradd’ & co.,
which in turn have an ID allocation strategy baked deep down into
the Shadow code.

As a side effect the system boots slightly faster and we get PIDs
starting at ~190 instead of ~300 on a bare-bones system.  :-)

Feedback welcome!

Ludo’.

Ludovic Courtès (4):
  system: Add (gnu system accounts).
  activation: Operate on <user-account> and <user-group> records.
  Add (gnu build accounts).
  activation: Build account databases with (gnu build accounts).

 Makefile.am              |   1 +
 gnu/build/accounts.scm   | 561 +++++++++++++++++++++++++++++++++++++++
 gnu/build/activation.scm | 245 +++--------------
 gnu/build/install.scm    |   3 +-
 gnu/local.mk             |   2 +
 gnu/system/accounts.scm  | 109 ++++++++
 gnu/system/shadow.scm    |  92 +++----
 tests/accounts.scm       | 309 +++++++++++++++++++++
 8 files changed, 1061 insertions(+), 261 deletions(-)
 create mode 100644 gnu/build/accounts.scm
 create mode 100644 gnu/system/accounts.scm
 create mode 100644 tests/accounts.scm

Comments

Ludovic Courtès March 7, 2019, 7:49 p.m. UTC | #1
Hello!

Pushed!  I’ve reconfigured and rebooted my system and I confirm I can
still log in.  :-)

  0ae735bcc8 activation: Build account databases with (gnu build accounts).
  ec600e4544 Add (gnu build accounts).
  6061d01512 activation: Operate on <user-account> and <user-group> records.
  f6f67b87c0 system: Add (gnu system accounts).

Ludo’.