From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp1.migadu.com ([2001:41d0:1008:1e59::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms8.migadu.com with LMTPS id GEcaBHVDomUNLQEAkFu2QA (envelope-from ) for ; Sat, 13 Jan 2024 09:01:57 +0100 Received: from aspmx1.migadu.com ([2001:41d0:403:58f0::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp1.migadu.com with LMTPS id UFxBOnRDomVnPgAA62LTzQ (envelope-from ) for ; Sat, 13 Jan 2024 09:01:57 +0100 X-Envelope-To: larch@yhetil.org Authentication-Results: aspmx1.migadu.com; dkim=none; spf=pass (aspmx1.migadu.com: domain of "bug-guix-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="bug-guix-bounces+larch=yhetil.org@gnu.org"; dmarc=none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1705132916; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding:resent-cc: resent-from:resent-sender:resent-message-id:list-id:list-help: list-unsubscribe:list-subscribe:list-post; bh=BP+4Gg9QRa/xxjqCII6LdJOJOJ9sbZ5wgO5WGbyIppA=; b=FHvsWRDRcdf/svKEF8VNeA7i3uNdMwYwqL46KtJUNuqav2brvBQwQNFKY5N5uXiQiXlxVz /su0xEEEt0JqJWfaQKvtualTcEwpHpC56LCSyn3HodOgHv9xD25mBgmsLTL5CX/LfLBhQD uq8mYtm+bVTY+kkewrW+ZVkkDbugvde4pFjhZH+xhb6a8AgOTeNW+W51wJZYfxciGqPUdc bAxxX/y/+ME9O0cpmnsQDLHX7Mw8A+d/NyuajgexK3/4A5VEoIL4Jlzuz4PHiZif7XNryx to/6UPesoe7qtz9npPjDpDXruiZPtUwXQhXC731sstl5X2fwIS9URRPvCWvLLA== ARC-Authentication-Results: i=1; aspmx1.migadu.com; dkim=none; spf=pass (aspmx1.migadu.com: domain of "bug-guix-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="bug-guix-bounces+larch=yhetil.org@gnu.org"; dmarc=none ARC-Seal: i=1; s=key1; d=yhetil.org; t=1705132916; a=rsa-sha256; cv=none; b=KyjIgnqAAomAhzURx2iji/ZcbpyOoi8LUM3Ov5mnt+OQVhm9M7mrxxhn0wqDJnVhDRX36F BoZaVONwlcEHF0HMG4ew0MXPw7TwXrro3tU7ptOM1Ymi02eNtWmOYKMGzjT8t4X+0IKINP yOQX10cafG7SYnjojIEh67mIuFsht3HFsb5BbBbcftYOa+d2t/2TpZKlJ3JW1v9IIBTGn6 8tvjHUB7oz4SKEzdIqxiMJnz5F6SnR3keZMzF3bltWnL9+mufP+JAWG8qUshJsa7bM5wwI R9YUSUT6Ug8dMKDsrTaBMYMweVdP0Qh98gh4xYeWE/sAYJefFzXg9LHiWHnkKw== Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id 961455896D for ; Sat, 13 Jan 2024 09:01:56 +0100 (CET) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1rOYxf-0007uI-60; Sat, 13 Jan 2024 03:01:47 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1rNwg5-0001Mx-Sp for bug-guix@gnu.org; Thu, 11 Jan 2024 10:09:06 -0500 Received: from debbugs.gnu.org ([2001:470:142:5::43]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1rNwg4-0007Sq-V0 for bug-guix@gnu.org; Thu, 11 Jan 2024 10:09:05 -0500 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1rNwg2-0001z2-4B for bug-guix@gnu.org; Thu, 11 Jan 2024 10:09:02 -0500 X-Loop: help-debbugs@gnu.org Subject: bug#68387: guix shell --container --share=/etc overrides shadow files Resent-From: Christina O'Donnell Original-Sender: "Debbugs-submit" Resent-CC: bug-guix@gnu.org Resent-Date: Thu, 11 Jan 2024 15:09:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: report 68387 X-GNU-PR-Package: guix X-GNU-PR-Keywords: To: 68387@debbugs.gnu.org X-Debbugs-Original-To: bug-guix@gnu.org Received: via spool by submit@debbugs.gnu.org id=B.17049857347604 (code B ref -1); Thu, 11 Jan 2024 15:09:01 +0000 Received: (at submit) by debbugs.gnu.org; 11 Jan 2024 15:08:54 +0000 Received: from localhost ([127.0.0.1]:33591 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1rNwfs-0001ya-P1 for submit@debbugs.gnu.org; Thu, 11 Jan 2024 10:08:53 -0500 Received: from lists.gnu.org ([2001:470:142::17]:38272) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1rNvlb-0005zx-OL for submit@debbugs.gnu.org; Thu, 11 Jan 2024 09:10:47 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1rNvlY-0007hB-81 for bug-guix@gnu.org; Thu, 11 Jan 2024 09:10:40 -0500 Received: from vmi993448.contaboserver.net ([194.163.141.236] helo=mutix.org) by eggs.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1rNvlW-00031s-2V for bug-guix@gnu.org; Thu, 11 Jan 2024 09:10:40 -0500 Received: from [192.168.1.81] (host86-132-246-87.range86-132.btcentralplus.com [86.132.246.87]) (Authenticated sender: cdo) by mutix.org (Postfix) with ESMTPSA id 30CB1A6320E for ; Thu, 11 Jan 2024 15:10:34 +0100 (CET) Message-ID: Date: Thu, 11 Jan 2024 14:10:33 +0000 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.15.0 From: Christina O'Donnell Content-Language: en-US Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit Received-SPF: pass client-ip=194.163.141.236; envelope-from=cdo@mutix.org; helo=mutix.org X-Spam_score_int: -18 X-Spam_score: -1.9 X-Spam_bar: - X-Spam_report: (-1.9 / 5.0 requ) BAYES_00=-1.9, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-Mailman-Approved-At: Thu, 11 Jan 2024 10:08:51 -0500 X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-Mailman-Approved-At: Sat, 13 Jan 2024 03:01:44 -0500 X-BeenThere: bug-guix@gnu.org List-Id: Bug reports for GNU Guix List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-guix-bounces+larch=yhetil.org@gnu.org Sender: bug-guix-bounces+larch=yhetil.org@gnu.org X-Migadu-Flow: FLOW_IN X-Migadu-Country: US X-Migadu-Spam-Score: -5.61 X-Migadu-Queue-Id: 961455896D X-Spam-Score: -5.61 X-Migadu-Scanner: mx11.migadu.com X-TUID: YwRr4/0Dhcz0 Hi Guix, Running the below command as root overrides the running system's shadow files (/etc/shadow, /etc/passwd, and /etc/group). WARNING: Don't run the following outside of a VM!   guix shell --container --share=/etc This erases the current user from the passwd database, meaning `su` and `sudo` no longer work, and you can't log in. Discussion The context is that I was tracking down a libreoffice bug using guix time-machine and ran the very clever command trying to get the display working.   sudo guix time-machine ... -- environment -C --ad-hoc coreutils sway \     --preserve='DISPLAY' --preserve='XDG' --share=/etc -- sway Now of course if you write random commands with sudo, you should expect to brick your system from time to time. And setting `--share=/etc` wasn't particularly smart idea. However, it would have been nice to not have that wipe my shadow files. For example, being warned about sharing /etc with a container. To reproduce, run the Guix command in a basic VM image, connecting to Guix daemon on the host.[1] Please let me know if you have any questions! Kind regards,  - Christina O'Donnell https://mutix.org/ --- [1] See my blog for more details: https://mutix.org/pages/blog/20240109-how-to-run-guix-in-vm.html