support/scripts/mkusers: allow option for system uid/gid
Some software decides based on uid/gid whether a user is a system or normal (human) user, with different behaviour for those flavors (example journald [2]). So adding logic to create system-users is necessary, we take the now common ranges from [1]. This extends the mkusers script to allow -2 for uid/gid, this argument will take an identifier from the user range. All identifiers used up to now should have been from the system range, so -1 is now interpreted as a system user/group. Note that after this commit, all the UIDs and GIDs that are created automatically (with -1) will change. That means if there is peristent data on an existing system that was created by such an automatic user, it will suddenly belong to a different user. However, this could already happen before: if a USERS line is added to a package, then other UIDs may change as well. Add system/user ranges as variables, and the argument for user/system uid variable as well. Thus some magic constants could be removed, some further occurences of -1 were replaced with equivalent logic. For consistency, the existing MIN/MAX_UID/GID variables are renamed to FIRST/LAST_USER_UID/GID. Update the documentation with the new automatic ranges. [1] - https://systemd.io/UIDS-GIDS/ [2] - https://www.freedesktop.org/software/systemd/man/journald.conf.html Signed-off-by: Norbert Lange <nolange79@gmail.com> [Arnout: use -1 for system users; refactor the changes a bit] Signed-off-by: Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
This commit is contained in:
committed by
Arnout Vandecappelle (Essensium/Mind)
parent
f22bff4a79
commit
41ea61d59c
@@ -20,13 +20,16 @@ Where:
|
||||
It can not be +root+, and must be unique. If set to +-+, then just a
|
||||
group will be created.
|
||||
- +uid+ is the desired UID for the user. It must be unique, and not
|
||||
+0+. If set to +-1+, then a unique UID will be computed by Buildroot
|
||||
in the range [1000...1999]
|
||||
+0+. If set to +-1+ or +-2+, then a unique UID will be computed by
|
||||
Buildroot, with +-1+ denoting a system UID from [100...999] and +-2+
|
||||
denoting a user UID from [1000...1999].
|
||||
- +group+ is the desired name for the user's main group. It can not
|
||||
be +root+. If the group does not exist, it will be created.
|
||||
- +gid+ is the desired GID for the user's main group. It must be unique,
|
||||
and not +0+. If set to +-1+, and the group does not already exist, then
|
||||
a unique GID will be computed by Buildroot in the range [1000..1999]
|
||||
and not +0+. If set to +-1+ or +-2+, and the group does not already
|
||||
exist, then a unique GID will be computed by Buildroot, with +-1+
|
||||
denoting a system GID from [100...999] and +-2+ denoting a user GID
|
||||
from [1000...1999].
|
||||
- +password+ is the crypt(3)-encoded password. If prefixed with +!+,
|
||||
then login is disabled. If prefixed with +=+, then it is interpreted
|
||||
as clear-text, and will be crypt-encoded (using MD5). If prefixed with
|
||||
|
||||
Reference in New Issue
Block a user