control: severity -1 wishlist
# or minor, not sure..
thanks

Hi Thorsten,

thank you for flying debian-security-support and filing bugs!

On Tue, Aug 03, 2021 at 05:47:24PM +0200, Thorsten Glaser wrote:
> Colour my surprise when I did an “ls -l /var/lib” and saw:
> […]
> drwxr-xr-x  3 root                    root                     4096 Oct  1  
> 2019 ucf/
> drwxr-xr-x  2 root                    root                     4096 Jul  6  
> 2012 update-rc.d/
> drwxr-xr-x  2 root                    root                     4096 Sep  7  
> 2012 urandom/
> drwxr-xr-x  3 root                    root                     4096 Feb  7  
> 2007 vim/
> drwxr-xr-x  2 root                    root                     4096 Feb 17  
> 2020 xfonts/
> drwxr-xr-x  2 root                    root                     4096 Dec 17  
> 2015 xml-core/

I share your surprise... (and I joined maintenance of the package long after
this has been implemented the way it is.)
 
> That’s *massively* too wide. Scrolling up revealed the culprit:

too wide for what? and maybe rather: if that's a problem, why not use ls -ln 
/var/lib?
'ls -l' is not ment to be parsable...

also:

$ tput cols
295
$ tput cols
81
$ tput cols
128

(all on different terminals I have currently running here...)

> drwxr-xr-x  2 debian-security-support debian-security-support  4096 Feb 17  
> 2020 debian-security-support/
> 
> Unix usernames are supposed to be up to 8 characters

says who? (besides you obviously :) and then GNU's not unix ;) 

> (in fact, some
> environments fail if they are longer, silently truncate them, or
> otherwise explode). This is… untenable.

"untenable" (which means indefensible AIUI) is plain wrong, because...
 
> Please change this. Thanks!

change has a cost, you know :)

So why and how exactly should this be changed, what would be your migration
proposal and could you maybe be so kind and provide patches?

I'm not totally opposed to the idea, but I don't see how we can sensibly
fix installed systems as removing users is a no-go and I believe renaming
them is also a bad idea. Which leaves adding another user (for existing
installs) and then probably changing ownership for the existing files -
all actions where I see potential problems for little benefit.

Maybe/probably you could convince me by providing an migration plan and patches 
*and* the offer to help fixing potenial fallout...(!)

I definitly don't have a hard stance on this, I just don't share the
pain/problem and I see problems on the road for little benefit to me.


-- 
cheers,
        Holger

 ⢀⣴⠾⠻⢶⣦⠀
 ⣾⠁⢠⠒⠀⣿⡁  holger@(debian|reproducible-builds|layer-acht).org
 ⢿⡄⠘⠷⠚⠋⠀  OpenPGP: B8BF54137B09D35CF026FE9D 091AB856069AAA1C
 ⠈⠳⣄

There are only two kinds of nazis: stupid ones and those without an excuse.
(Volker Strübing)

Attachment: signature.asc
Description: PGP signature

Reply via email to