From mboxrd@z Thu Jan 1 00:00:00 1970 From: Ricardo Wurmus Subject: bug#37162: =?UTF-8?Q?=E2=80=98guix?= pack -f =?UTF-8?Q?docker=E2=80=99?= creates an image without /etc/passwd Date: Sun, 25 Aug 2019 18:28:09 +0200 Message-ID: <871rx9jjl2.fsf@elephly.net> References: <87r25c3p0e.fsf@inria.fr> <87a7bxexs6.fsf@gmail.com> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Return-path: Received: from eggs.gnu.org ([2001:470:142:3::10]:34443) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1i1vO4-000280-4S for bug-guix@gnu.org; Sun, 25 Aug 2019 12:29:05 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1i1vO3-0005e0-4q for bug-guix@gnu.org; Sun, 25 Aug 2019 12:29:04 -0400 Received: from debbugs.gnu.org ([209.51.188.43]:36200) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1i1vO2-0005dR-TZ for bug-guix@gnu.org; Sun, 25 Aug 2019 12:29:03 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1i1vO1-0003P1-Lb for bug-guix@gnu.org; Sun, 25 Aug 2019 12:29:01 -0400 Sender: "Debbugs-submit" Resent-Message-ID: In-reply-to: <87a7bxexs6.fsf@gmail.com> List-Id: Bug reports for GNU Guix List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-guix-bounces+gcggb-bug-guix=m.gmane.org@gnu.org Sender: "bug-Guix" To: Maxim Cournoyer Cc: 37162@debbugs.gnu.org, Ludovic =?UTF-8?Q?Court=C3=A8s?= Hi Maxim, > Ludovic Court=C3=A8s writes: > >> =E2=80=98guix pack -f docker=E2=80=99 currently creates an image without >> /etc/{passwd,group,shadow}. >> >> It=E2=80=99s OK most of the time, but again it looks like a gratuitous a= nnoyance >> for those cases where having them around matters (that=E2=80=99s also th= e reason >> why guix-daemon creates them.) > > Would that include the files required for PAM authentication to work > correctly? I remember struggling with this use case: using the Docker > image with CQFD wrapper, which must be able to create a user and > sudo'ing (or 'su') to it in the docker container. I wonder if at this point it wouldn=E2=80=99t be better to build a whole sy= stem container. Isn=E2=80=99t that outside the scope of =E2=80=9Cguix pack=E2= =80=9D and rather a task for =E2=80=9Cguix system=E2=80=9D? --=20 Ricardo