All this Archlinux User Groups needed?

Which groups can be safely deleted?

I went a bit crazy with groups when I had printer and bluetooth installation problems so, I finished up with all these:

sys log scanner power cups rfkill users video storage optical lp audio wheel adm michael lpadmin

Which can I safely delete?

1 Like

https://wiki.archlinux.org/title/Users_and_groups#Group_management

the mighty link top the archwiki :wink:
we do already set a minimal modern combination of groups for the common Desktop user per default on EndeavourOS:

And as you can see here:

1 Like

I’m not being snarky here, this is just a question.
What benefits would there be to removing the extra groups? From a different direction, what would be gained by removing the extra groups?

Pudge

@pudge I won’t, if it does not pose any security issues. I was always taught to delete anything you are never going to use, so I gues I am applying it to groups.

2 Likes

I wasn’t proposing a solution, I was literally asking a question.

Pudge

[build@buildsystem ~]$ groups
sys vboxusers libvirt rfkill users wheel build

removing groups is not needed only removing user from groups could be something “needed”
Removal of groups should be only a thing if you created the groups before manually :wink:

The thing to remove can be only packages… and services/timers/sockets

2 Likes

Security.

It is best for your user account to only have the groups it needs.

7 Likes

I get it, and and it’s something I hadn’t thought about until you asked. I just prefer to have only the groups EnOS uses and delete the rest, such as lpadmin.

and they are?

There is no universal answer. It depends on your personal needs and preferences.

If you don’t know, you can always remove everything except wheel and michael and then add back what you need when something doesn’t work. Personally, I only have sys, wheel and my user group.

@dalto

users

group is also listed as unused on archwiki page… should we investigate this?

1 Like

users shouldn’t be added by default in my opinion.

1 Like

Thank you @dalto I will do just that. I read that you need

audio

in some cases related to accessing the frame buffer, but I’m not sure that applies to me, since I don’t even know what it is :rofl:

Here is what I was concerned about

uid=1000(michael) gid=1000(michael) groups=1000(michael),3(sys),19(log),96(scanner),98(power),999(adm),998(wheel),996(audio),991(lp),990(optical),987(storage),985(video),984(users),982(rfkill),209(cups),1001(lpadmin)

AFAIK it’s used by Debian based or other distros as the default/main user group. It is about how the local admin wants to handle a multi-user system for data sharing. Arch uses the group named as the user name. :person_shrugging:

1 Like

calamares default sets users group in addition to that… but we can change that indeed…

1 Like

2022-04-25_11-52

less is more …

4 Likes

Perfect. It makes the journey so much more meaningful when founders are paying attention :1st_place_medal:

all medals go to the community… coming up with questions and solutions to make EndeavourOS better day by day :rocketa_purple:

1 Like

I agree. It’s why I :heart: this community :rocketa_purple: