From unknown Fri Jun 20 07:14:56 2025 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-Mailer: MIME-tools 5.509 (Entity 5.509) Content-Type: text/plain; charset=utf-8 From: bug#55361 <55361@debbugs.gnu.org> To: bug#55361 <55361@debbugs.gnu.org> Subject: Status: [Installer] Extra unprivileged =?UTF-8?Q?=E2=80=9Croot=E2=80=9D?= account added Reply-To: bug#55361 <55361@debbugs.gnu.org> Date: Fri, 20 Jun 2025 14:14:56 +0000 retitle 55361 [Installer] Extra unprivileged =E2=80=9Croot=E2=80=9D account= added reassign 55361 guix submitter 55361 Ludovic Court=C3=A8s severity 55361 important thanks From debbugs-submit-bounces@debbugs.gnu.org Wed May 11 05:36:55 2022 Received: (at submit) by debbugs.gnu.org; 11 May 2022 09:36:55 +0000 Received: from localhost ([127.0.0.1]:36101 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1noim3-0003Hf-FR for submit@debbugs.gnu.org; Wed, 11 May 2022 05:36:55 -0400 Received: from lists.gnu.org ([209.51.188.17]:48458) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1noim2-0003HY-EZ for submit@debbugs.gnu.org; Wed, 11 May 2022 05:36:50 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:44832) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1noim2-0005TV-6I for bug-guix@gnu.org; Wed, 11 May 2022 05:36:50 -0400 Received: from fencepost.gnu.org ([2001:470:142:3::e]:35896) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1noim0-0001hj-Rg for bug-guix@gnu.org; Wed, 11 May 2022 05:36:49 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=gnu.org; s=fencepost-gnu-org; h=MIME-Version:Date:Subject:To:From:in-reply-to: references; bh=xa6ZS30GTPifgbPoTvi9BT5+lIbzUTL4Xt27mgKcdWg=; b=Y0sWdUwLB7B2D3 c84n6RgnTHbQ8rzMcGgSTi8nxZ/L5+DSlq9M+zBvlVDPtG32poryWyqXlumfhBI3nf6y8S8pn45eS hF1nlGnoilp4NCuZhbHRBXBKYyOSS6Va6wc4ftM54hDXsHycYXnM5/Fz4vOWaAQdJOhQqAPiHjSmb P8AQ9yx+Yomgy4dAZTJ7STQ+Dk+8WSG5mxx5JFEom0jTFw9A44aG1lBmkPP5wYBZ4Mb8i66eKIsvO 9mbxkPH7utF+0LATt6TVSyr/c9rlSNEj+hAdjYSsuP1GAPacZ7qF5ua6+N7+HvWZzHw8iLI3WC4jt r01z6KncduGoeDqhZGGA==; Received: from 91-160-117-201.subs.proxad.net ([91.160.117.201]:59966 helo=ribbon) by fencepost.gnu.org with esmtpsa (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1noim0-0008Md-3n for bug-guix@gnu.org; Wed, 11 May 2022 05:36:48 -0400 From: =?utf-8?Q?Ludovic_Court=C3=A8s?= To: bug-guix@gnu.org Subject: [Installer] Extra unprivileged =?utf-8?B?4oCccm9vdOKAnQ==?= account added X-Debbugs-Cc: Mathieu Othacehe X-URL: http://www.fdn.fr/~lcourtes/ X-Revolutionary-Date: 22 =?utf-8?Q?Flor=C3=A9al?= an 230 de la =?utf-8?Q?R?= =?utf-8?Q?=C3=A9volution?= X-PGP-Key-ID: 0x090B11993D9AEBB5 X-PGP-Key: http://www.fdn.fr/~lcourtes/ludovic.asc X-PGP-Fingerprint: 3CE4 6455 8A84 FDC6 9DB4 0CFB 090B 1199 3D9A EBB5 X-OS: x86_64-pc-linux-gnu Date: Wed, 11 May 2022 11:36:46 +0200 Message-ID: <87ee10o1g1.fsf@inria.fr> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.2 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable X-Spam-Score: -2.3 (--) X-Debbugs-Envelope-To: submit X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -3.3 (---) The installer built from: --8<---------------cut here---------------start------------->8--- Generation 214 May 02 2022 21:44:14 (current) guix 6b588da repository URL: https://git.savannah.gnu.org/git/guix.git branch: master commit: 6b588da368c77cde82ea2f22ca315116228777ad --8<---------------cut here---------------end--------------->8--- =E2=80=A6 adds an unprivileged =E2=80=9Croot=E2=80=9D account to the =E2=80= =98users=E2=80=99 section of the OS config. Ludo=E2=80=99. From debbugs-submit-bounces@debbugs.gnu.org Wed May 11 09:42:50 2022 Received: (at control) by debbugs.gnu.org; 11 May 2022 13:42:50 +0000 Received: from localhost ([127.0.0.1]:36584 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nomc6-0006tR-Jp for submit@debbugs.gnu.org; Wed, 11 May 2022 09:42:50 -0400 Received: from eggs.gnu.org ([209.51.188.92]:39236) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nomc4-0006tF-UN for control@debbugs.gnu.org; Wed, 11 May 2022 09:42:49 -0400 Received: from fencepost.gnu.org ([2001:470:142:3::e]:40570) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nombz-0007EB-MC for control@debbugs.gnu.org; Wed, 11 May 2022 09:42:43 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=gnu.org; s=fencepost-gnu-org; h=MIME-version:Subject:From:To:Date:in-reply-to: references; bh=XfDlwF9hUCE+EIlRXY72/Lk35ezz9BT0Q37wrDoNE4Q=; b=XAhiOhDv0HUt82 vozo7aQxefQWI8BVqQyZPrly5d015zJj7VmJF1NaC70AptRXIojHGEVW/60YRaDdCNmWwmOLRKQHP CF2Btem4av2OUkg44pqOnrKqj+DaY1lWyP7kZOh4UC2hXtBwWK9mPRREt/3s5eYNcWJN74Rssj8qe vS2dtvdc6BwoRTws4iCRkAFS3nRlqlMauzsGOk35Ux4dvMXssU1FQbbBi1XeBsA7dCW6zgjlyS+4w Lyo46f1vdKvvSzGJv27OQcExZTuYnPm3MInkOvrBOSlz1JKduW1d4sfdIAwVeas0mIL8+ggIUbY5u EEaNi+0ZTnRUZwS/a+Qw==; Received: from 91-160-117-201.subs.proxad.net ([91.160.117.201]:55473 helo=ribbon) by fencepost.gnu.org with esmtpsa (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nombz-0005rU-9p for control@debbugs.gnu.org; Wed, 11 May 2022 09:42:43 -0400 Date: Wed, 11 May 2022 15:42:41 +0200 Message-Id: <87czgknq26.fsf@gnu.org> To: control@debbugs.gnu.org From: =?utf-8?Q?Ludovic_Court=C3=A8s?= Subject: control message for bug #55361 MIME-version: 1.0 Content-type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Spam-Score: -2.3 (--) X-Debbugs-Envelope-To: control X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -3.3 (---) severity 55361 important quit From debbugs-submit-bounces@debbugs.gnu.org Wed May 11 09:43:03 2022 Received: (at control) by debbugs.gnu.org; 11 May 2022 13:43:03 +0000 Received: from localhost ([127.0.0.1]:36589 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nomcI-0006uR-RQ for submit@debbugs.gnu.org; Wed, 11 May 2022 09:43:03 -0400 Received: from eggs.gnu.org ([209.51.188.92]:39276) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nomcG-0006tf-Aw for control@debbugs.gnu.org; Wed, 11 May 2022 09:43:00 -0400 Received: from fencepost.gnu.org ([2001:470:142:3::e]:40592) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nomcB-0007G7-1f for control@debbugs.gnu.org; Wed, 11 May 2022 09:42:55 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=gnu.org; s=fencepost-gnu-org; h=MIME-version:Subject:From:To:Date:in-reply-to: references; bh=YaCMAPydx6pZMKPWf34oEpA1AbIV/gsAb9b7fU5dGLg=; b=QnIkB0qR9DJJ2q 0WpU3gnS481/6eHUNxNXTP412cA8BlxlhWEcZ7DJVqufHXRUJ05FQlK+uwXt6YwrEHrfKtTz3cgGW 3BT2r80iQiwlSpSzpQt6HvpRWUVur5lBzsAGwu8qku+R/dL9g2GhmEyauLtxCB2LqN3yB2716cAj8 uvFZPuufSdJtQ/J4wJXn57XfWvCXIo/+dFkHxoQ90ph1GBZG+DmBFtXQaP7QAKylV3jVdwDYjlbUm LSs/FfvHXPhZUDmzLYyyrSBnENVk5SVzANuPSOTPJQU+yuUiQ78S1HG2cfDbYDt9T4aX6n1z7G6I8 ltpZbII3nILVuyBiybnA==; Received: from 91-160-117-201.subs.proxad.net ([91.160.117.201]:54687 helo=ribbon) by fencepost.gnu.org with esmtpsa (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nomcA-0005sd-LR for control@debbugs.gnu.org; Wed, 11 May 2022 09:42:54 -0400 Date: Wed, 11 May 2022 15:42:52 +0200 Message-Id: <87bkw4nq1v.fsf@gnu.org> To: control@debbugs.gnu.org From: =?utf-8?Q?Ludovic_Court=C3=A8s?= Subject: control message for bug #53214 MIME-version: 1.0 Content-type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Spam-Score: -2.3 (--) X-Debbugs-Envelope-To: control X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -3.3 (---) block 53214 by 55361 quit From debbugs-submit-bounces@debbugs.gnu.org Fri May 20 18:19:17 2022 Received: (at 55361-done) by debbugs.gnu.org; 20 May 2022 22:19:17 +0000 Received: from localhost ([127.0.0.1]:40322 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nsAxp-0006bt-MG for submit@debbugs.gnu.org; Fri, 20 May 2022 18:19:17 -0400 Received: from eggs.gnu.org ([209.51.188.92]:54592) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nsAxm-0006bc-Ih for 55361-done@debbugs.gnu.org; Fri, 20 May 2022 18:19:16 -0400 Received: from fencepost.gnu.org ([2001:470:142:3::e]:38650) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nsAxh-0006ni-8H for 55361-done@debbugs.gnu.org; Fri, 20 May 2022 18:19:09 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=gnu.org; s=fencepost-gnu-org; h=MIME-Version:In-Reply-To:Date:References:Subject:To: From; bh=jLlistd9pG3CNFnQOYnUil1AvlkVc4vbKFKCuvQR1zs=; b=lYlb3zo5nVmHzzHReE+n 7jVBapo6S+q3+N5t0+QeGq7sQ6Vx4qH0iYBqPQsLQuxicv9n0Xr8qrd1sdrl6bYvud5zEEVFIfT3B f8Q5BaR6iiQXQvBW5wRAV2kjrAWIHiQ1DqV16rp7HkWwevU7HTrosQh/k4Wq5p3ANA7/Qn5zs0cLQ 1jlv0/OzM/fLXFMz8dCdIuAFybLcFCgSSz8VdAjsEdFJaW/I3kgwGhYlsSPv5yK3pZS//w7QqwF3B BNKp9hFJSkz2YJPoZd5Dj5CRLvcYSInM6vSLpXfMLB+FhkSHYGBk7+AoeH1ATYIc+4ye7SA9qDI/Z 8fYELbqreYjFTQ==; Received: from 91-160-117-201.subs.proxad.net ([91.160.117.201]:59445 helo=ribbon) by fencepost.gnu.org with esmtpsa (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nsAxf-0003Ju-Tm; Fri, 20 May 2022 18:19:08 -0400 From: =?utf-8?Q?Ludovic_Court=C3=A8s?= To: 55361-done@debbugs.gnu.org Subject: Re: bug#55361: [Installer] Extra unprivileged =?utf-8?B?4oCccm9v?= =?utf-8?B?dOKAnQ==?= account added References: <87ee10o1g1.fsf@inria.fr> Date: Sat, 21 May 2022 00:19:06 +0200 In-Reply-To: <87ee10o1g1.fsf@inria.fr> ("Ludovic =?utf-8?Q?Court=C3=A8s=22?= =?utf-8?Q?'s?= message of "Wed, 11 May 2022 11:36:46 +0200") Message-ID: <87h75jvodh.fsf@gnu.org> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.2 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable X-Spam-Score: -2.3 (--) X-Debbugs-Envelope-To: 55361-done Cc: Mathieu Othacehe X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -3.3 (---) Ludovic Court=C3=A8s skribis: > The installer built from: > > Generation 214 May 02 2022 21:44:14 (current) > guix 6b588da > repository URL: https://git.savannah.gnu.org/git/guix.git > branch: master > commit: 6b588da368c77cde82ea2f22ca315116228777ad > > =E2=80=A6 adds an unprivileged =E2=80=9Croot=E2=80=9D account to the =E2= =80=98users=E2=80=99 section of the OS > config. Fixed in 48c748226e2a94d2dec9bfdf84601455f00d6f5e, which reverts c2125e59d0774cda3e559adeb056459a5f23586b. Ludo=E2=80=99. From debbugs-submit-bounces@debbugs.gnu.org Sat May 21 08:54:58 2022 Received: (at 55361) by debbugs.gnu.org; 21 May 2022 12:54:58 +0000 Received: from localhost ([127.0.0.1]:40918 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nsOdG-0002li-Iy for submit@debbugs.gnu.org; Sat, 21 May 2022 08:54:58 -0400 Received: from mailout.easymail.ca ([64.68.200.34]:56414) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nsOdE-0002lU-Cl for 55361@debbugs.gnu.org; Sat, 21 May 2022 08:54:57 -0400 Received: from localhost (localhost [127.0.0.1]) by mailout.easymail.ca (Postfix) with ESMTP id E8730A4E67; Sat, 21 May 2022 12:54:50 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=bokr.com; s=easymail; t=1653137690; bh=sWZ8tCDV+gz4svMPvD2ThJ2wKGBdR0wBWA/+v9Ah5LA=; h=From:Date:To:Subject:Reply-To:References:In-Reply-To:From; b=Z+b+a4QZNh9dc93uxhelkEzs1DHOP+nkG0Zfaq7CIn0mRP2fS4d8lCWVGY55LT6xf p1mkeGeJfYEaXtJjmNU+YcVvlQk7RbGlglkoHpWE2Dms03RPjOS/0Mm7EZ+NictCQT Pf6VB8J6Utok2BirpAvcK+9aeifg5FRh9JkI3qDbxM3xdt/Yo4i/kiWdA4IB2/t4Kr 10MkcDnOyiQPO+AX5YizIkaA3Lq8NfS4IJe/Lr/7mKMcRvJ4ACmGjyi+DrdI864zD9 1znnG7zGdz3Yn8H99wLUz9ik+Ws3ZC3En4xTKJ6U5rdULM0s1i7ax4wdiGTOIFM23k cb5k2JIgrZuFg== X-Virus-Scanned: Debian amavisd-new at emo03-pco.easydns.vpn Received: from mailout.easymail.ca ([127.0.0.1]) by localhost (emo03-pco.easydns.vpn [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kvWsd3QNFxAA; Sat, 21 May 2022 12:54:50 +0000 (UTC) Received: from localhost (m83-185-41-1.cust.tele2.se [83.185.41.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mailout.easymail.ca (Postfix) with ESMTPSA id 0416CA4E57; Sat, 21 May 2022 12:54:49 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=bokr.com; s=easymail; t=1653137690; bh=sWZ8tCDV+gz4svMPvD2ThJ2wKGBdR0wBWA/+v9Ah5LA=; h=From:Date:To:Subject:Reply-To:References:In-Reply-To:From; b=Z+b+a4QZNh9dc93uxhelkEzs1DHOP+nkG0Zfaq7CIn0mRP2fS4d8lCWVGY55LT6xf p1mkeGeJfYEaXtJjmNU+YcVvlQk7RbGlglkoHpWE2Dms03RPjOS/0Mm7EZ+NictCQT Pf6VB8J6Utok2BirpAvcK+9aeifg5FRh9JkI3qDbxM3xdt/Yo4i/kiWdA4IB2/t4Kr 10MkcDnOyiQPO+AX5YizIkaA3Lq8NfS4IJe/Lr/7mKMcRvJ4ACmGjyi+DrdI864zD9 1znnG7zGdz3Yn8H99wLUz9ik+Ws3ZC3En4xTKJ6U5rdULM0s1i7ax4wdiGTOIFM23k cb5k2JIgrZuFg== From: bokr@bokr.com Date: Sat, 21 May 2022 14:54:34 +0200 To: 55361@debbugs.gnu.org, ludo@gnu.org Subject: Re: bug#55361: [Installer] =?utf-8?Q?Extra?= =?utf-8?B?IHVucHJpdmlsZWdlZCDigJxyb2904oCd?= account added Message-ID: <20220521125434.GA2334@LionPure> References: <87ee10o1g1.fsf@inria.fr> <87h75jvodh.fsf@gnu.org> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <87h75jvodh.fsf@gnu.org> User-Agent: Mutt/1.10.1 (2018-07-13) X-Spam-Score: -2.3 (--) X-Debbugs-Envelope-To: 55361 X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: bokr@bokr.com Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -3.3 (---) Hello, On +2022-05-21 00:19:06 +0200, Ludovic Courtès wrote: > Ludovic Courtès skribis: > > > The installer built from: > > > > Generation 214 May 02 2022 21:44:14 (current) > > guix 6b588da > > repository URL: https://git.savannah.gnu.org/git/guix.git > > branch: master > > commit: 6b588da368c77cde82ea2f22ca315116228777ad > > > > … adds an unprivileged “root” account to the ‘users’ section of the OS > > config. > > Fixed in 48c748226e2a94d2dec9bfdf84601455f00d6f5e, which reverts > c2125e59d0774cda3e559adeb056459a5f23586b. > > Ludo’. > > > --8<---------------cut here---------------start------------->8--- commit c2125e59d0774cda3e559adeb056459a5f23586b Author: Mathieu Othacehe Date: Mon Apr 4 16:38:09 2022 +0200 installer: user: Remove useless filtering. --8<---------------cut here---------------end--------------->8--- --8<---------------cut here---------------start------------->8--- commit 48c748226e2a94d2dec9bfdf84601455f00d6f5e Author: Ludovic Courtès Date: Fri May 20 20:41:02 2022 +0200 Revert "installer: user: Remove useless filtering." This reverts commit c2125e59d0774cda3e559adeb056459a5f23586b. Fixes . --8<---------------cut here---------------end--------------->8--- Assuming my date-diff hack worked: --8<---------------cut here---------------start------------->8--- ~/wb/guix]$ date-diff '2022-04-04 16:38:09' '2022-05-20 20:41:02' 46days 4hrs 2min 53sec --8<---------------cut here---------------end--------------->8--- Is this like coming home from 46day vacation and noticing that, oops, someone left the kitchen door open, and hoping no ++ungoodniks noticed? Or meh? Is. or should there be, a required signoff on an exploitability assessment in the commit, when it has that scent? (e.g. anything possibly opening a door to root privilges). Personally, I am happy to see "fixed," but I would be happier seeing a signed exploitability assessment, esp if by someone concentrating on that aspect of things. Thoughts? -- Regards, Bengt Richter From debbugs-submit-bounces@debbugs.gnu.org Sat May 21 09:34:10 2022 Received: (at 55361) by debbugs.gnu.org; 21 May 2022 13:34:10 +0000 Received: from localhost ([127.0.0.1]:41001 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nsPFC-00062l-1b for submit@debbugs.gnu.org; Sat, 21 May 2022 09:34:10 -0400 Received: from tobias.gr ([80.241.217.52]:36698) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nsPF7-00062Z-QV for 55361@debbugs.gnu.org; Sat, 21 May 2022 09:34:08 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; s=2018; bh=rcv+m6R1GE6Th vOTnyDgOLuz+7TiN8HM7b5LgSr/85M=; h=references:in-reply-to:subject:cc: to:from:date; d=tobias.gr; b=aYKjP7BiNeDnzCXVJAldtDvfhDAfYRCWIHQl9sGjS KcnK1IQWcnpcGXgGiI4aFqpBVx2WjWxhJH478hOs7u0DgfWr0/kpkUm84nSP02TK88dRbA RnmgYr/grl5u9oHJvGTfW/6R+n8L/VWDYLVP5bW3w7OTQky5G19a2PpNQapyOioIDS8kFQ 9WMTHK3+zqXaUiKAxmDBI6wrqudQ0M3gpwguMUAHltgoBipJd+x5VmAIiLUSYhAHQtLHrZ /C9yMzmsRXnFT3W9bsGBgG7gwcd+8rXh5q/fPqPBDeNv/b4GTEsQVd9tgzLD5+lR+UaOyZ QDShsp9krOB0RbqQogdPg== Received: by submission.tobias.gr (OpenSMTPD) with ESMTP id 1e226371; Sat, 21 May 2022 13:34:04 +0000 (UTC) MIME-Version: 1.0 Date: Sat, 21 May 2022 15:34:02 +0200 From: Tobias Geerinckx-Rice To: bokr@bokr.com Subject: =?UTF-8?Q?Re=3A_bug=2355361=3A_=5BInstaller=5D_Extra_unprivilege?= =?UTF-8?Q?d_=E2=80=9Croot=E2=80=9D_account_added?= In-Reply-To: <20220521125434.GA2334@LionPure> References: <87ee10o1g1.fsf@inria.fr> <87h75jvodh.fsf@gnu.org> <20220521125434.GA2334@LionPure> Message-ID: <7245779f538e8f9ac6a19f5cc3efbe03@tobias.gr> Content-Type: text/plain; charset=US-ASCII; format=flowed Content-Transfer-Encoding: 7bit X-Spam-Score: -0.0 (/) X-Debbugs-Envelope-To: 55361 Cc: ludo@gnu.org, 55361@debbugs.gnu.org X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.0 (-) Hi bokr, What makes this commit special? If there's a security aspect here, what is it? > Personally, I am happy to see "fixed," but I would be happier > seeing a signed exploitability assessment, esp if by someone > concentrating on that aspect of things. I don't think anyone is going to volunteer for that honour, unless you are :-) Kind regards, T G-R Sent from a Web browser. Excuse or enjoy my brevity. From debbugs-submit-bounces@debbugs.gnu.org Sat May 21 12:51:35 2022 Received: (at 55361) by debbugs.gnu.org; 21 May 2022 16:51:35 +0000 Received: from localhost ([127.0.0.1]:42879 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nsSKF-0007cZ-4a for submit@debbugs.gnu.org; Sat, 21 May 2022 12:51:35 -0400 Received: from eggs.gnu.org ([209.51.188.92]:35248) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nsSKA-0007cH-Pu for 55361@debbugs.gnu.org; Sat, 21 May 2022 12:51:33 -0400 Received: from fencepost.gnu.org ([2001:470:142:3::e]:54270) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nsSK5-0000xm-AF; Sat, 21 May 2022 12:51:25 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=gnu.org; s=fencepost-gnu-org; h=MIME-Version:In-Reply-To:Date:References:Subject:To: From; bh=ljR7/OItnWFdEg2gD0GxnbM38yOrk1zC21/bkNBf9Vw=; b=Faul4PVQ39GOvvCImKRx +qEOyNFB2vdE4eUijsZPL4Nn4scAERgE3ckjDLzsxaWN0obmCcD3P4CUKYI645M0oR8ty++9oBTwn RTPDJD5kJBxcl7oNpR8vQQLA8/skjoBd37CK2orFMLvSzGPMc2pziRwF+/tYgaBUY5R8aKbk4n2mt EMBioirVRFKUWJaQJ6NtT9e9yH8P/DqnbYMXoL4rLnv2gYOUeKOfo5qZkEaPCezvrIrNTFk11n/1Y nk919HNZEKGttEbGmbOpz96ya3+WpebNTVizWo02uKggG+pW2+s4xBFJJ3lhRXrVWQGFbZOXlB4ds i5zatMZ8Fl8ZPQ==; Received: from 91-160-117-201.subs.proxad.net ([91.160.117.201]:52848 helo=ribbon) by fencepost.gnu.org with esmtpsa (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nsSK3-0006az-91; Sat, 21 May 2022 12:51:24 -0400 From: =?utf-8?Q?Ludovic_Court=C3=A8s?= To: bokr@bokr.com Subject: Re: bug#55361: [Installer] Extra unprivileged =?utf-8?B?4oCccm9v?= =?utf-8?B?dOKAnQ==?= account added References: <87ee10o1g1.fsf@inria.fr> <87h75jvodh.fsf@gnu.org> <20220521125434.GA2334@LionPure> X-URL: http://www.fdn.fr/~lcourtes/ X-Revolutionary-Date: 2 Prairial an 230 de la =?utf-8?Q?R=C3=A9volution?= X-PGP-Key-ID: 0x090B11993D9AEBB5 X-PGP-Key: http://www.fdn.fr/~lcourtes/ludovic.asc X-PGP-Fingerprint: 3CE4 6455 8A84 FDC6 9DB4 0CFB 090B 1199 3D9A EBB5 X-OS: x86_64-pc-linux-gnu Date: Sat, 21 May 2022 18:51:21 +0200 In-Reply-To: <20220521125434.GA2334@LionPure> (bokr@bokr.com's message of "Sat, 21 May 2022 14:54:34 +0200") Message-ID: <875ylyu8vq.fsf@gnu.org> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.2 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable X-Spam-Score: -2.3 (--) X-Debbugs-Envelope-To: 55361 Cc: 55361@debbugs.gnu.org X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -3.3 (---) Hi, bokr@bokr.com skribis: > Assuming my date-diff hack worked: > > ~/wb/guix]$ date-diff '2022-04-04 16:38:09' '2022-05-20 20:41:02' > 46days 4hrs 2min 53sec > > Is this like coming home from 46day vacation and noticing > that, oops, someone left the kitchen door open, > and hoping no ++ungoodniks noticed? Or meh? Heh. It was a minor annoyance: the generated OS config would have an unnecessary =E2=80=9Croot=E2=80=9D user account (unnecessary because it=E2= =80=99s included by default), which =E2=80=98guix system init=E2=80=99 would warn about and ign= ore, and the end result is unchanged. IWBN to augment the installation tests with a check for that, but that=E2= =80=99s tricky. But like Tobias wrote, contributions are welcome. :-) Thanks, Ludo=E2=80=99. From unknown Fri Jun 20 07:14:56 2025 Received: (at fakecontrol) by fakecontrolmessage; To: internal_control@debbugs.gnu.org From: Debbugs Internal Request Subject: Internal Control Message-Id: bug archived. Date: Sun, 19 Jun 2022 11:24:08 +0000 User-Agent: Fakemail v42.6.9 # This is a fake control message. # # The action: # bug archived. thanks # This fakemail brought to you by your local debbugs # administrator