RPM Support For Systemd Sysusers.d
Summary
RPM supports creating users and groups according to configuration provided in sysusers.d snippets shipped in package payload.
The goal of the proposal is to fully integrate this RPM functionality in Fedora.
Owner
- Name: Michal Sekletar, Zbigniew Jędrzejewski-Szmek, Panu Matilainen
- Email: msekleta@redhat.com, zbyszek@in.waw.pl, pmatilai@redhat.com
Current status
- Targeted release: Fedora Linux 42
- Last updated: 2024-12-20
- [Announced]
- [<will be assigned by the Wrangler> Discussion thread]
- FESCo issue: <will be assigned by the Wrangler>
- Tracker bug: <will be assigned by the Wrangler>
- Release notes tracker: <will be assigned by the Wrangler>
Detailed Description
The aim of this proposal is twofold. First is to make sure that RPM functionality is fully integrated in Fedora. Second is to raise awareness about the current state and change packaging guidelines accordingly in order to simplify and cleanup user/group management done by RPM packages. Hope is to have fully declarative system user and group management in all RPMs because over time we should be able to drop manual useradd/groupadd invocations or use of %sysusers_create_compat from rpm scriptlets.
Feedback
Discussion about idea to submit the proposal on fedora-devel list.
Benefit to Fedora
- Declarative system user and group management by packages
- Potential for spec file simplification, concretely, removal of relevant part of %pre scripts in some packages.
- Ability to query what user and groups are provided by given package as well as ability to have dependencies on users/groups from different packages.
- Make use of native rpm functionality in favor of current %sysusers_compat_create.
Scope
- Proposal owners:
- Change rpm so that it generates hard dependency between packages A and B in case A depends on user or group provided by package B. Rpm currently has downstream patch so that only weak dependencies are generated.
- Make sure that previous change in rpm doesn't cause package dependency issues during system installation.
- Work on fix for shadow-utils so that useradd and groupadd work correctly in chroot on SELinux enabled systems (shadow-utils issue.)
- Other developers:
- We would welcome any help with shadow-utils issue.
- Release engineering: N/A (not needed for this Change)
- Policies and guidelines: N/A (not needed for this Change)
- Trademark approval: N/A (not needed for this Change)
- Alignment with the Fedora Strategy:
Upgrade/compatibility impact
There is no upgrade/compatibility impact.
How To Test
- Select rpm package that creates system user/group account in %pre
- Remove part of %pre scriptlet that handles user/group creation
- Create equivalent sysusers.d configuration file and ship it as part of rpm payload under /usr/lib/sysusers.d/.
- Rebuild the package
- Verify that package has been built correctly and it has rpm provides for installed user account and group (e.g. user(foo), group(bar)).
- Verify that you can install the package and installed files have correct ownership.
User Experience
There shouldn't be any user observable change to previous state. Potential packaging related benefits are mostly of interest to package maintainers.
Dependencies
None
Contingency Plan
- Contingency mechanism: If we are not confident by mass-rebuild that we can deliver the feature we will postpone its delivery to later Fedora release. There are no explicit rollback/cleanup actions that need to taken.
- Contingency deadline: Mass Rebuild of RPMs on Wed 2025-01-15.
- Blocks release? No
Documentation
Release Notes
N/A