From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp1 ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms11 with LMTPS id eORBEb6UsV+gdwAA0tVLHw (envelope-from ) for ; Sun, 15 Nov 2020 20:51:10 +0000 Received: from aspmx1.migadu.com ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp1 with LMTPS id lNIJDb6UsV+/QwAAbx9fmQ (envelope-from ) for ; Sun, 15 Nov 2020 20:51:10 +0000 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id B35189403A9 for ; Sun, 15 Nov 2020 20:51:09 +0000 (UTC) Received: from localhost ([::1]:52432 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1keOzM-00064f-NA for larch@yhetil.org; Sun, 15 Nov 2020 15:51:08 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]:38324) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1keOzG-00064L-Iu for guix-patches@gnu.org; Sun, 15 Nov 2020 15:51:02 -0500 Received: from debbugs.gnu.org ([209.51.188.43]:42737) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1keOzG-00087W-9q for guix-patches@gnu.org; Sun, 15 Nov 2020 15:51:02 -0500 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1keOzG-0005KU-7l for guix-patches@gnu.org; Sun, 15 Nov 2020 15:51:02 -0500 X-Loop: help-debbugs@gnu.org Subject: [bug#44623] [PATCH] archive: Warn about replacing an ACL symlink. Resent-From: Ludovic =?UTF-8?Q?Court=C3=A8s?= Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Sun, 15 Nov 2020 20:51:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 44623 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: Tobias Geerinckx-Rice Cc: 44623@debbugs.gnu.org Received: via spool by 44623-submit@debbugs.gnu.org id=B44623.160547344120457 (code B ref 44623); Sun, 15 Nov 2020 20:51:02 +0000 Received: (at 44623) by debbugs.gnu.org; 15 Nov 2020 20:50:41 +0000 Received: from localhost ([127.0.0.1]:54283 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1keOyv-0005Jt-KZ for submit@debbugs.gnu.org; Sun, 15 Nov 2020 15:50:41 -0500 Received: from eggs.gnu.org ([209.51.188.92]:38150) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1keOyu-0005Jf-DJ for 44623@debbugs.gnu.org; Sun, 15 Nov 2020 15:50:40 -0500 Received: from fencepost.gnu.org ([2001:470:142:3::e]:47949) by eggs.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1keOyp-0007wF-3I; Sun, 15 Nov 2020 15:50:35 -0500 Received: from [2a01:e0a:1d:7270:af76:b9b:ca24:c465] (port=45256 helo=ribbon) by fencepost.gnu.org with esmtpsa (TLS1.2:RSA_AES_256_CBC_SHA1:256) (Exim 4.82) (envelope-from ) id 1keOyo-00042l-IJ; Sun, 15 Nov 2020 15:50:34 -0500 From: Ludovic =?UTF-8?Q?Court=C3=A8s?= References: <20201113202041.2447-1-me@tobias.gr> Date: Sun, 15 Nov 2020 21:50:33 +0100 In-Reply-To: <20201113202041.2447-1-me@tobias.gr> (Tobias Geerinckx-Rice's message of "Fri, 13 Nov 2020 21:20:41 +0100") Message-ID: <871rgu73ae.fsf@gnu.org> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.1 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable X-Spam-Score: -2.3 (--) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-Spam-Score: -3.3 (---) X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+larch=yhetil.org@gnu.org Sender: "Guix-patches" X-Scanner: ns3122888.ip-94-23-21.eu Authentication-Results: aspmx1.migadu.com; dkim=none; dmarc=pass (policy=none) header.from=gnu.org; spf=pass (aspmx1.migadu.com: domain of guix-patches-bounces@gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=guix-patches-bounces@gnu.org X-Spam-Score: -1.51 X-TUID: 7v9mbX+AhgSb Tobias Geerinckx-Rice skribis: > * guix/scripts/archive.scm (authorize-key): Warn when %ACL-FILE is a > symbolic link and print an additional hint for Guix System users. Oh, I was convinced that =E2=80=98guix archive --authorize=E2=80=99 would n= ow fail on Guix System, but indeed it doesn=E2=80=99t, due to the canonical rename tri= ck. > + ;; Warn about potentially volatile ACLs, but continue: system reconfig= uration > + ;; might not be possible without (newly-authorized) substitutes. > + (when (and (access? %acl-file F_OK) > + (eq? 'symlink (stat:type (lstat %acl-file)))) You can do both at once (thus avoiding a TOCTTOU race) with: (let ((stat (false-if-exception (lstat %acl-file)))) (when (and stat =E2=80=A6) =E2=80=A6)) Otherwise LGTM (for =E2=80=98master=E2=80=99), thanks! Ludo=E2=80=99.