Comment 25 for bug 401056

Revision history for this message
StefanPotyra (sistpoty) wrote :

Hi,

that's really a tough case, hence I subscribed both mvo (since it affects the uprade path) and slangasek (to have the release-manager on board).

The tricky part is that it's not 100% guaranteed that the deleted syslog user (which will then get readded later on) will have the same uid. These would lead us with a number of "orphaned" files in /var/log, which could be made readable to another (unwanted) user that happens to obtain the new uid.

Given that, I believe that the right thing to do is to just not delete the syslog user and to not assume that it's not present for the udpated package.

However I'd really like to hear a second opinion on this.

Cheers,
     Stefan.