#1038861 login updates login.defs, adds options that old groupmod doesn't understand

Package:
login
Source:
login
Description:
system login tools
Submitter:
Marc Haber
Date:
2026-01-10 11:02:37 UTC
Severity:
normal
#1038861#5
Date:
2023-06-22 06:13:24 UTC
From:
To:
Hi,

upgrading from bullseye to bookworm, during the "apt upgrade" step, it
may happen that login updates login.defs and adds the NONEXISTENT and
PREVENT_NO_AUTH options to login.defs. However, it is not guaranteed
that passwd gets upgraded quickly afterwards. Old groupmod, from old
passwd, doesn't understand the new configuration options and logs

Jun 22 07:38:41 emptybullseye99 groupmod[6828]: unknown configuration item `NONEXISTENT'
Jun 22 07:38:41 emptybullseye99 groupmod[6828]: unknown configuration item `PREVENT_NO_AUTH'

Those messages also end up on the console, unfortunately without a
prefix indicating which program caused the message. It just says
"configuration error - unknown item NONEXISTENT". If groupmod didn't log to
syslog as well, I would still be searching.

This shows, for example, when openssh-client tries to rename its ssh
group to _ssh in postinst between the updates of login and passwd. I
have also seen this when upgrading udev from bullseye to bookworm as it
tries to create the new sgx group.

Functionality is not affected, the operation succeeds, but there is a
confusing error message on the console.

Maybe it would be a good idea to have a versioned dependency between
login and passwd, preventing the case of an old binary not fully
understanding a new configuration file.

Greetings
Marc

#1038861#10
Date:
2023-06-22 13:05:42 UTC
From:
To:
That does seem annoying, I don't really see any reason for those error
messages.

I filed https://github.com/shadow-maint/shadow/issues/746 about this.

#1038861#15
Date:
2023-10-01 18:22:14 UTC
From:
To:
Hello,

I am upgrading my debian 11 to debian 12 and all my systems are affected
by this bug. The systems are fully upgraded and the bug is persistent.

$ apt info login
[...]
Version: 1:4.13+dfsg-1+b1
[...]

$ apt info passwd
[...]
Version: 1:4.13+dfsg1-1+b1
[...]

No only the upgrade process is affected, but most commands that read
/etc/login.defs : useradd, userdell, groupmems, ... etc.

As I am an user of QubesOS, I reported the bug first on :
https://github.com/QubesOS/qubes-issues/issues/8559

It should not matter as the relevant programs come from debian bookworm
stable.

Cdlt

#1038861#20
Date:
2023-10-02 07:48:01 UTC
From:
To:
Hello,

My bad, it seems that the systems were not fully upgraded.

Cdlt.

#1038861#29
Date:
2026-01-10 10:10:20 UTC
From:
To:
Es gibt eine Familienspende in Höhe von 1.850.000,00 USD von Cheng Charlie
Saephan. Bitte antworten Sie für weitere Informationen. Denken Sie daran,
Ihrer Familie und den Bedürftigen in Ihrer Umgebung Gutes zu tun.

Dies ist bereits der zweite Versuch, Sie zu erreichen. Bitte antworten Sie
für weitere Details.