Re: [gentoo-dev] RFC: acct-{user,group} for milter (438)

2019-12-16 Thread Ralph Seichter
* Michael Orlitzky: > I'm sure someone will object to the name acct-user/_milter-regex, but > that would be the easiest option, being the upstream default. Admittedly, _milter-regex makes me wince. It displeases my sense of aesthetics and affects sorting order in acct-*. I'd like to lose the unde

Re: [gentoo-dev] RFC: acct-{user,group} for milter (438)

2019-12-15 Thread Michael Orlitzky
On 12/15/19 9:46 AM, Ralph Seichter wrote: > > Milter-regex only needs a user to isolate the process and it's single > configuration file (/etc/milter-regex.conf). My PR adds acct-user/milter > without a home directory, because milter-regex does not need one, nor > does it write anything to disk.

Re: [gentoo-dev] RFC: acct-{user,group} for milter (438)

2019-12-15 Thread Ralph Seichter
> Milter-regex only needs a user to isolate the process and it's single > configuration file (/etc/milter-regex.conf). I forgot to mention: $ ls -l /etc/milter-regex.conf -rw-r--r-- 1 root root 2.3K Dec 14 22:13 /etc/milter-regex.conf Owned by root, world-readable because nothing sensitive i

Re: [gentoo-dev] RFC: acct-{user,group} for milter (438)

2019-12-15 Thread Ralph Seichter
* Michael Orlitzky: > (a) we still have a dumb security vulnerability, in that these daemons > can modify each others' files That vulnerability has existed as long as the second package came around and re-used the "milter" user, and to my knowledge nothing bad has come of it so far. I have an op

Re: [gentoo-dev] RFC: acct-{user,group} for milter (438)

2019-12-14 Thread Michael Orlitzky
On 12/14/19 11:53 PM, Ralph Seichter wrote: Of the three packages you mentioned, milter-regex (not regex-milter) is the only one with a name that actually contains "milter". OpenDMARC should never have user a user named milter in the first place, and in the future it should use "opendmarc". Bes

Re: [gentoo-dev] RFC: acct-{user,group} for milter (438)

2019-12-14 Thread Ralph Seichter
* Michael Orlitzky: > I guess we could keep "milter" for only regex-milter, but that has the > disadvantage that it messes with the opendmarc package in the meantime. Of the three packages you mentioned, milter-regex (not regex-milter) is the only one with a name that actually contains "milter"

Re: [gentoo-dev] RFC: acct-{user,group} for milter (438)

2019-12-14 Thread Michael Orlitzky
On 12/13/19 4:17 PM, Ralph Seichter wrote: The mail-filter/milter-regex ebuild already uses user/group 'milter', and for the currently open bump to version 2.7 I'd like to claim GID/UID 438. I recently cited the "milter" user on this list as a bad example from the user.eclass days... it was us

[gentoo-dev] RFC: acct-{user,group} for milter (438)

2019-12-13 Thread Ralph Seichter
The mail-filter/milter-regex ebuild already uses user/group 'milter', and for the currently open bump to version 2.7 I'd like to claim GID/UID 438. I have checked the assignment list[1] and used Notmuch for a full text search of previous mentions of GID/UID 438. From what I can tell, 438 has not b