From mboxrd@z Thu Jan 1 00:00:00 1970 From: Vincent Legoll Subject: bug#23971: Nobody has a shell Date: Wed, 13 Jul 2016 12:10:18 +0200 Message-ID: Mime-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:47005) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bNJsX-0002BV-GT for bug-guix@gnu.org; Wed, 13 Jul 2016 09:07:06 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1bNJsV-00075F-GV for bug-guix@gnu.org; Wed, 13 Jul 2016 09:07:04 -0400 Received: from debbugs.gnu.org ([208.118.235.43]:36853) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bNJsV-00075A-DI for bug-guix@gnu.org; Wed, 13 Jul 2016 09:07:03 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1bNJsV-0000vt-8a for bug-guix@gnu.org; Wed, 13 Jul 2016 09:07:03 -0400 Sender: "Debbugs-submit" Resent-Message-ID: Received: from eggs.gnu.org ([2001:4830:134:3::10]:40522) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bNH7V-0005Up-7w for bug-guix@gnu.org; Wed, 13 Jul 2016 06:10:22 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1bNH7U-0006XA-6L for bug-guix@gnu.org; Wed, 13 Jul 2016 06:10:20 -0400 Received: from mail-qk0-x22f.google.com ([2607:f8b0:400d:c09::22f]:32844) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bNH7U-0006X4-1w for bug-guix@gnu.org; Wed, 13 Jul 2016 06:10:20 -0400 Received: by mail-qk0-x22f.google.com with SMTP id p74so38852871qka.0 for ; Wed, 13 Jul 2016 03:10:20 -0700 (PDT) List-Id: Bug reports for GNU Guix List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-guix-bounces+gcggb-bug-guix=m.gmane.org@gnu.org Sender: "bug-Guix" To: 23971@debbugs.gnu.org vince@guixsd ~/guix-packages$ grep nobody /etc/passwd nobody:x:65534:997::/var/empty:/gnu/store/7cdd8s466qyjh64m0byq0rz9gk1jid40-bash-4.3.42/bin/bash On my debian, this user is left out the door: $ grep nobody /etc/passwd nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin Even its HOME directory is non existent, purposedly... Is this not a security risk (greater attack surface) or something like that ? -- Vincent Legoll