# Collabora wants access to /etc/passwd?

**URL:** <https://forum.collaboraonline.com/t/collabora-wants-access-to-etc-passwd/3969>\
**Category:** Installation & Configuration\
**Created:** [August 21, 2025, 9:26pm UTC](https://forum.collaboraonline.com/t/collabora-wants-access-to-etc-passwd/3969 "2025-08-21T21:26:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Slogan4682](https://avatars.discourse-cdn.com/v4/letter/s/d07c76/32.png) [@Slogan4682](https://forum.collaboraonline.com/u/Slogan4682)\
**Post date:** [August 21, 2025, 9:26pm UTC](https://forum.collaboraonline.com/t/collabora-wants-access-to-etc-passwd/3969/1 "2025-08-21T21:26:03Z")

</div>

Hello all,

I set up a small Nextcloud server (latest versions, etc etc) and i noticed that the user www-data, under which everything runs, executes the following command:

cp --dereference --preserve=all /etc/passwd /tmp/coolwsd.dZO3nCn3iA/systemplate/etc/passwd

From what i gather, /tmp/coolwsd.dZO2nCn5iU/ is a temporary jail that collabora runs in, but the fact that it copies /etc/passwd worries me a bit.

Does anyone know why this is happening?

---

<div class="post-metadata">

**Author:** ![darshan](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.collaboraonline.com/darshan/32/2230_2.png) [@darshan](https://forum.collaboraonline.com/u/darshan)\
**Post date:** [August 22, 2025, 6:39am UTC](https://forum.collaboraonline.com/t/collabora-wants-access-to-etc-passwd/3969/2 "2025-08-22T06:39:25Z")

</div>

Hello @Slogan4682

Don;t worry about passwords 😉

That `cp` command is part of how **systemplate chroots** (the isolated jail environments for document processes) are prepared. Here’s what’s going on:

- **Collabora runs each document in a jailed environment** (a chroot-like container under `/tmp/coolwsd.*`), so that even if a document process is compromised, it doesn’t have access to the real host filesystem.
- To make that jail usable, Collabora needs to provide some _basic system files_ inside it — for example, `/etc/passwd`, `/etc/group`, locale files, fonts, etc. Without `/etc/passwd`, processes inside the jail may fail when calling library functions that look up user or group information.
- The `cp --dereference --preserve=all /etc/passwd …` step copies the **host’s `/etc/passwd` file into the jail** so that those lookups work. Importantly, this does not expose `/etc/passwd` to other users — it just makes it available to the sandboxed process that Collabora spawns.
- The **reason it copies rather than mounts** is to keep the jail isolated: the jailed process only sees a snapshot of `/etc/passwd`, not the real one.

Since `/etc/passwd` on modern Linux systems **does not contain password hashes** (those are stored in `/etc/shadow`, which is not copied), this is not a security risk. It only contains usernames, UIDs, GIDs, and shell/home directory info — essentially public information needed for system operation.

Thanks  
Darshan

---

<div class="post-metadata">

**Author:** ![Slogan4682](https://avatars.discourse-cdn.com/v4/letter/s/d07c76/32.png) [@Slogan4682](https://forum.collaboraonline.com/u/Slogan4682)\
**Post date:** [August 22, 2025, 6:47am UTC](https://forum.collaboraonline.com/t/collabora-wants-access-to-etc-passwd/3969/3 "2025-08-22T06:47:37Z")

</div>

Thank you Darshan, what you said is also in the documentation, but you explained it much better!! Now i understand, thank you 🙂

---

<div class="post-metadata">

**Author:** ![darshan](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.collaboraonline.com/darshan/32/2230_2.png) [@darshan](https://forum.collaboraonline.com/u/darshan)\
**Post date:** [August 22, 2025, 6:59am UTC](https://forum.collaboraonline.com/t/collabora-wants-access-to-etc-passwd/3969/4 "2025-08-22T06:59:45Z")

</div>


