Hi Chris and Guillem,

On Sun, May 10, 2026 at 08:28:25PM +0200, Guillem Jover wrote:
> On Wed, 2026-05-06 at 17:14:19 +0200, Chris Boot wrote:
> > 2. In the pppd tarball, I will let /etc/ppp/peers/ be mode 0755, just
> >    like it is in pppoe/wvdial/xtel. I believe that this should resolve
> >    the dpkg file metadata conflict.
> 
> Hmm, I think I'd rather see the actual intended perms be part of the
> tar metadata. More so given that I think this is a security sensitive
> directory?

I was telling Chris much the same and as he preferred the statoverride
mechanism, I asked him to invite you for review.

> > 2. The files in question are conffiles so we'd need to do the
> >    rm_conffile dance anyway if we were to move the files to
> >    /usr/share/doc.
> 
> Hmm, I'm not sure I understand this concern, why would these files need
> to be moved to /usr/share/doc if the permissions get changed? Isn't
> the main problem only the directory?

I can probably shed some light here has much of the context happened
between me and Chris offline. We recognized that all of those conffiles
do not actually contain any configuration. Effectively, they're
documentation. Having the hermetic-/usr use case in mind, we considered
that moving them out of /etc below /usr would be a sensible path
forward.

I am aware that the hermetic-/usr view is not consensus. At present, it
is mainly Luca Boccassi pushing for it, but it vaguely makes sense to
me.

> If something would really require removing these conffiles, to me that
> means that option would be less desirable as missing the conffiles by
> default would be less user friendly.

I hear you. We do have opposing views on this in Debian. Please let me
skip that discussion as I am fine either way and understand the
arguments of either side.

Helmut

Reply via email to