Change: Authselect: Hardcode nss-altfiles in profiles #3663
Labels
No labels
document it
fast track
meeting
next release
nonresponsive maintainer
packager revocation
pending announcement
provenpackager
python 2 exception
self contained change
stalled
Status
Accepted
Status
Duplicate
Status
Insufficient data
Status
Invalid
Status
Rejected
system wide change
updates policy exception
vote-in-progress
No milestone
No project
No assignees
7 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
fesco/tickets#3663
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Currently, authselect users can enable nss-altfiles in nsswitch.conf using "with-altfiles" feature. This proposal is to remove the feature and hardcode nss-altfiles support in nsswitch.conf in all shipped profiles, making it required.
Owners, do not implement this work until the FESCo vote has explicitly ended.
When a FESCo member has marked this ticket as APPROVED, you may proceed with the implementation. See the FESCo ticket policy and the Changes policy for more information.
If no decision has been rendered after 7 days from the filing of this ticket and no indication (such as a -1 vote) that this will be taken up at a FESCo meeting, please feel free to ping for a status update.
REMINDER: This ticket is for FESCo members to vote on the proposal. Further discussion should happen in the Discourse discussion linked above. Additional discussion may happen on the Fedora Devel mailing list.
cc @pbrezina
The links here are pointing to another change.
Summary is also incorrect
Updated
I'm -1. There are no benefits listed for non-Atomic installations in the change request and we know that we have a lot of problems related to nss-altfiles in Atomic ones:
We haven't moved away from using nss-altfiles yet because it requires work to migrate existing systems and things "mostly" work for now and the problems are known (UID/GID drifts, etc.).
But this is really high on my TODO list.
High level summary of the issues with nss-altfiles:
Issues specific to building bootable container images:
Thanks, that is very helpful context. I wonder if, given the list of known affected tooling whether this should be classified as "system-wide" instead ...
Either way, the -1 vote puts this on the agenda for next week's meeting, so we'll have some chance to discuss this.
Hi, I'm commenting as the author of the change. I am fine to wait until nss-altfiles requirement is removed from atomic images - that would be the ideal and preferred solution. However, I would like to see a concrete timeline, not promises or wishful thinking since this is on the table for at least since Fedora 27 ~9 years. If I see that this becomes a priority, I am happy to revoke the change.
This topic is on the agenda for today's meeting:
https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org/thread/PWMQRM2RQXWIGSQQPX643JE3ADM5Y3AC/
I'm -1 on this as well.
This was discussed during today's meeting. The Change proposal is REJECTED (+6, 0, -0) (meeting log starting at 17:06:48).
!info FESCo would like to see a resolution to this longstanding problem area and encourages the relevant parties (CoreOS, Atomic, bootc initiative, authselect maintainers) to collaborate.
Maybe @nimbinatus can help get things unstuck here as Bootc Initiative lead?
👋 Let me get the discussion going in the initiative channel on Matrix, see if I can get a firm timeline for you in the next couple weeks.
Change rejection now processed.
Thanks Aoife!