Community Packages

Please read this before reporting a bug:

Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.

REPEAT: Do NOT report bugs for outdated packages!

FS#71925 - [shadowsocks-libev] Employ DynamicUser=yes instead of User=nobody

Attached to Project: Community Packages
Opened by Tommy Zhang (T-J-M) - Thursday, 26 August 2021, 07:09 GMT
Last edited by Morten Linderud (Foxboron) - Saturday, 28 August 2021, 11:51 GMT
Task Type Bug Report
Category Packages
Status Assigned
Assigned To Felix Yan (felixonmars)
Architecture All
Severity Low
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 0%
Votes 1
Private No



I've got a warning reported by systemd reads '[🡕] /usr/lib/systemd/system/shadowsocks-libev@.service:8: Special user nobody configured, this is not safe!', which might be the result of 'User=nobody' in all four systemd service files related to this package. Comparing to the current solution, a better choice might employ 'DynamicUser=yes' to replace 'User=nobody', which is considered a better security-related practice.
This task depends upon

Comment by Tommy Zhang (T-J-M) - Thursday, 26 August 2021, 07:12 GMT
P.S. I'm not an expert on how Arch's bug tracking system works. If this task is unfortunately lost from the corresponding package name, I would suggest it shadowsocks-libev with version 3.3.5-3, currently maintained by felixonmars(Felix Yan).
Comment by Tommy Zhang (T-J-M) - Thursday, 26 August 2021, 07:15 GMT Comment by Tommy Zhang (T-J-M) - Tuesday, 31 August 2021, 10:29 GMT
A patch to fix this issue has been generated and attached to this comment.