Last modified: 2014-03-17 21:49:52 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T62937, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 60937 - Remove remnant /data/project/.system/sudoers and /etc/sudoers.d/tools-login
Remove remnant /data/project/.system/sudoers and /etc/sudoers.d/tools-login
Status: RESOLVED WONTFIX
Product: Wikimedia Labs
Classification: Unclassified
tools (Other open bugs)
unspecified
All All
: Unprioritized normal
: ---
Assigned To: Tim Landscheidt
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-02-06 02:22 UTC by Tim Landscheidt
Modified: 2014-03-17 21:49 UTC (History)
3 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Tim Landscheidt 2014-02-06 02:22:39 UTC
Those seem to have been created April 2013 and earlier; they should be removed as to not confuse the upcoming tool usernames change.
Comment 1 Tim Landscheidt 2014-02-10 21:46:33 UTC
Deleted /data/project/.system/sudoers; all entries also in LDAP.
Comment 2 Tim Landscheidt 2014-02-10 21:53:12 UTC
... and /etc/sudoers.d/tools-{dev,login} (configuration for the above to work on the respective hosts) as well.
Comment 3 Tim Landscheidt 2014-02-11 10:57:36 UTC
(In reply to comment #1)
> Deleted /data/project/.system/sudoers; all entries also in LDAP.

Yes, but only as rules for the new service group system; no old ones, and so broke "become" for the affected tools.

I'll diff [[wikitech:Special:NovaServiceGroup]] and [[wikitech:Special:NovaSudoer]] to create a list of affected tools, deploy a hot fix to /etc/sudoers.d and submit a change to Puppet.
Comment 4 Tim Landscheidt 2014-02-11 11:17:47 UTC
List of affected tools:

- afcbot
- anagrimes
- csbot
- daahbot
- ftl
- legobot
- matilda
- wiktioutils
Comment 5 Tim Landscheidt 2014-02-11 11:23:00 UTC
/etc/sudoers.d/tools-ldap-fix deployed to all Tools nodes.
Comment 6 Gerrit Notification Bot 2014-02-11 12:35:14 UTC
Change 112666 had a related patch set uploaded by Tim Landscheidt:
Tools: Work around missing LDAP sudo rules

https://gerrit.wikimedia.org/r/112666
Comment 7 Gerrit Notification Bot 2014-03-17 21:48:23 UTC
Change 112666 abandoned by Tim Landscheidt:
Tools: Work around missing LDAP sudo rules

Reason:
In eqiad no longer necessary.

https://gerrit.wikimedia.org/r/112666

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links