This commit is contained in:
Neil Hanlon 2022-10-18 13:08:27 -04:00
parent 16a9ba7f14
commit 6b0762045e
Signed by: neil
GPG Key ID: 705BC21EC3C70F34
4 changed files with 49 additions and 33 deletions

View File

@ -16,35 +16,29 @@ sudo:x:16:
dialout:x:18: dialout:x:18:
floppy:x:19: floppy:x:19:
games:x:20: games:x:20:
tape:x:30: tape:x:33:
video:x:39: video:x:39:
ftp:x:50: ftp:x:50:
lock:x:54: lock:x:54:
audio:x:63: audio:x:63:
nobody:x:99: nobody:x:99:
users:x:100: users:x:100:
utmp:x:22:
utempter:x:35:
ssh_keys:x:999: ssh_keys:x:999:
systemd-journal:x:190: systemd-journal:x:190:
dbus:x:81:
polkitd:x:998: polkitd:x:998:
etcd:x:997: etcd:x:997:
dip:x:40: dip:x:40:
cgred:x:996: cgred:x:996:
tss:x:59:
avahi-autoipd:x:170: avahi-autoipd:x:170:
rpc:x:32:
sssd:x:993: sssd:x:993:
dockerroot:x:986: dockerroot:x:986:
rpcuser:x:29: rpcuser:x:29:
nfsnobody:x:65534: nfsnobody:x:65534:
kube:x:994: kube:x:994:
sshd:x:74:
chrony:x:992: chrony:x:992:
tcpdump:x:72: tcpdump:x:72:
ceph:x:167: ceph:x:167:
input:x:995: input:x:104:
systemd-timesync:x:991: systemd-timesync:x:991:
systemd-network:x:990: systemd-network:x:990:
systemd-resolve:x:989: systemd-resolve:x:989:

View File

@ -0,0 +1,9 @@
remove-from-packages:
# The grub bits are mainly designed for desktops, and IMO haven't seen
# enough testing in concert with ostree. At some point we'll flesh out
# the full plan in https://github.com/coreos/fedora-coreos-tracker/issues/47
- [grub2-tools, /etc/grub.d/08_fallback_counting,
/etc/grub.d/10_reset_boot_success,
/etc/grub.d/12_menu_auto_hide,
/usr/lib/systemd/.*]

View File

@ -6,28 +6,35 @@ lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin
sync:x:5:0:sync:/sbin:/bin/sync sync:x:5:0:sync:/sbin:/bin/sync
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
halt:x:7:0:halt:/sbin:/sbin/halt halt:x:7:0:halt:/sbin:/sbin/halt
mail:x:8:12:mail:/var/spool/mail:/sbin/nologin adm:x:3:4:adm:/var/adm:/usr/sbin/nologin
operator:x:11:0:operator:/root:/sbin/nologin avahi-autoipd:x:170:170:Avahi IPv4LL Stack:/var/lib/avahi-autoipd:/usr/sbin/nologin
games:x:12:100:games:/usr/games:/sbin/nologin bin:x:1:1:bin:/bin:/usr/sbin/nologin
ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin ceph:x:167:167:Ceph daemons:/var/lib/ceph:/usr/sbin/nologin
nobody:x:99:99:Nobody:/:/sbin/nologin chrony:x:994:992::/var/lib/chrony:/usr/sbin/nologin
dbus:x:81:81:System message bus:/:/sbin/nologin cockpit-ws:x:988:987:User for cockpit-ws:/:/usr/sbin/nologin
polkitd:x:999:998:User for polkitd:/:/sbin/nologin daemon:x:2:2:daemon:/sbin:/usr/sbin/nologin
etcd:x:998:997:etcd user:/var/lib/etcd:/sbin/nologin dbus:x:81:81:System Message Bus:/:/usr/sbin/nologin
tss:x:59:59:Account used by the trousers package to sandbox the tcsd daemon:/dev/null:/sbin/nologin dockerroot:x:997:986:Docker User:/var/lib/docker:/usr/sbin/nologin
avahi-autoipd:x:170:170:Avahi IPv4LL Stack:/var/lib/avahi-autoipd:/sbin/nologin etcd:x:998:997:etcd user:/var/lib/etcd:/usr/sbin/nologin
rpc:x:32:32:Rpcbind Daemon:/var/lib/rpcbind:/sbin/nologin ftp:x:14:50:FTP User:/var/ftp:/usr/sbin/nologin
sssd:x:995:993:User for sssd:/:/sbin/nologin games:x:12:100:games:/usr/games:/usr/sbin/nologin
dockerroot:x:997:986:Docker User:/var/lib/docker:/sbin/nologin halt:x:7:0:halt:/sbin:/sbin/halt
rpcuser:x:29:29:RPC Service User:/var/lib/nfs:/sbin/nologin kube:x:996:994:Kubernetes user:/:/usr/sbin/nologin
nfsnobody:x:65534:65534:Anonymous NFS User:/var/lib/nfs:/sbin/nologin lp:x:4:7:lp:/var/spool/lpd:/usr/sbin/nologin
kube:x:996:994:Kubernetes user:/:/sbin/nologin mail:x:8:12:mail:/var/spool/mail:/usr/sbin/nologin
sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin nfsnobody:x:65534:65534:Anonymous NFS User:/var/lib/nfs:/usr/sbin/nologin
chrony:x:994:992::/var/lib/chrony:/sbin/nologin nobody:x:99:99:Kernel Overflow User:/:/usr/sbin/nologin
tcpdump:x:72:72::/:/sbin/nologin operator:x:11:0:operator:/root:/usr/sbin/nologin
ceph:x:167:167:Ceph daemons:/var/lib/ceph:/sbin/nologin polkitd:x:999:998:User for polkitd:/:/usr/sbin/nologin
systemd-timesync:x:993:991:systemd Time Synchronization:/:/sbin/nologin root:x:0:0:Super User:/root:/bin/bash
systemd-network:x:991:990:systemd Network Management:/:/sbin/nologin rpc:x:32:32:Rpcbind Daemon:/var/lib/rpcbind:/usr/sbin/nologin
systemd-resolve:x:990:989:systemd Resolver:/:/sbin/nologin rpcuser:x:29:29:RPC Service User:/var/lib/nfs:/usr/sbin/nologin
systemd-bus-proxy:x:989:988:systemd Bus Proxy:/:/sbin/nologin shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
cockpit-ws:x:988:987:User for cockpit-ws:/:/sbin/nologin sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/usr/sbin/nologin
sssd:x:995:993:User for sssd:/:/usr/sbin/nologin
sync:x:5:0:sync:/sbin:/bin/sync
systemd-bus-proxy:x:989:988:systemd Bus Proxy:/:/usr/sbin/nologin
systemd-network:x:991:990:systemd Network Management:/:/usr/sbin/nologin
systemd-resolve:x:990:989:systemd Resolver:/:/usr/sbin/nologin
systemd-timesync:x:993:991:systemd Time Synchronization:/:/usr/sbin/nologin
tcpdump:x:72:72::/:/usr/sbin/nologin

View File

@ -8,11 +8,15 @@ ostree-layers:
- overlay/08nouveau - overlay/08nouveau
- overlay/09misc - overlay/09misc
- overlay/20platform-chrony - overlay/20platform-chrony
- overlay/15fcos
conditional-include: conditional-include:
- if: releasever <= 8 - if: releasever <= 8
include: fallback-hostname.yaml include: fallback-hostname.yaml
- if: basearch != "s390x"
# And remove some cruft from grub2
include: grub2-removals.yaml
packages: packages:
- rpm - rpm
@ -29,6 +33,7 @@ packages:
- polkit - polkit
- coreos-installer - coreos-installer
ignore-removed-users: ignore-removed-users:
- root - root
ignore-removed-groups: ignore-removed-groups:
@ -38,6 +43,7 @@ etc-group-members:
- sudo - sudo
- systemd-journal - systemd-journal
- adm - adm
- docker
check-passwd: check-passwd: