add pam_open_session() support to su, fixing bug #8831.
authorMartin Schlemmer <azarah@gentoo.org>
Sat, 19 Oct 2002 09:31:05 +0000 (09:31 +0000)
committerMartin Schlemmer <azarah@gentoo.org>
Sat, 19 Oct 2002 09:31:05 +0000 (09:31 +0000)
sys-apps/shadow/ChangeLog
sys-apps/shadow/files/digest-shadow-4.0.3-r1 [new file with mode: 0644]
sys-apps/shadow/files/shadow-4.0.3-su-pam_open_session.patch [new file with mode: 0644]
sys-apps/shadow/shadow-4.0.3-r1.ebuild [new file with mode: 0644]

index ef913e4c4d0560527ac957372dde049ed5ab3857..696df31252fd8da6f15f56001e30bdd5fd2071c2 100644 (file)
@@ -1,6 +1,15 @@
 # ChangeLog for sys-apps/shadow
 # Copyright 2002 Gentoo Technologies, Inc.; Distributed under the GPL
-# $Header: /var/cvsroot/gentoo-x86/sys-apps/shadow/ChangeLog,v 1.15 2002/10/12 19:43:29 azarah Exp $
+# $Header: /var/cvsroot/gentoo-x86/sys-apps/shadow/ChangeLog,v 1.16 2002/10/19 09:31:05 azarah Exp $
+
+*shadow-4.0.3-r1 (19 Oct 2002)
+
+  19 Oct 2002; Martin Schlemmer <azarah@gentoo.org> shadow-4.0.3-r1.ebuild :
+
+  Get su to call pam_open_session(), and also set DISPLAY and XAUTHORITY,
+  else the session entries in /etc/pam.d/su never get executed, and
+  pam_xauth for one, is then never used.  This should close bug #8831.
+
 
   12 Oct 2002; Martin Schlemmer <azarah@gentoo.org> shadow-4.0.3.ebuild :
 
diff --git a/sys-apps/shadow/files/digest-shadow-4.0.3-r1 b/sys-apps/shadow/files/digest-shadow-4.0.3-r1
new file mode 100644 (file)
index 0000000..aee0733
--- /dev/null
@@ -0,0 +1 @@
+MD5 873e49fcde0d665e916414722ecb0d72 shadow-4.0.3.tar.gz 1055089
diff --git a/sys-apps/shadow/files/shadow-4.0.3-su-pam_open_session.patch b/sys-apps/shadow/files/shadow-4.0.3-su-pam_open_session.patch
new file mode 100644 (file)
index 0000000..48d4700
--- /dev/null
@@ -0,0 +1,51 @@
+--- shadow-4.0.3/src/su.c.orig 2002-10-19 09:54:05.000000000 +0200
++++ shadow-4.0.3/src/su.c      2002-10-19 11:28:43.000000000 +0200
+@@ -252,6 +252,14 @@
+                */
+               if ((cp = getenv ("TERM")))
+                       addenv ("TERM", cp);
++              /*
++               * Also leave DISPLAY and XAUTHORITY if present, else
++               * pam_xauth will not work.
++               */
++              if ((cp = getenv ("DISPLAY")))
++                      addenv ("DISPLAY", cp);
++              if ((cp = getenv ("XAUTHORITY")))
++                      addenv ("XAUTHORITY", cp);
+       } else {
+               while (*envp)
+                       addenv (*envp++, NULL);
+@@ -507,7 +515,10 @@
+       }
+ #endif
+ 
++/* setup the environment for pam later on, else we run into auth problems */
++#ifndef USE_PAM
+       environ = newenvp;      /* make new environment active */
++#endif
+ 
+       if (getenv ("IFS"))     /* don't export user IFS ... */
+               addenv ("IFS= \t\n", NULL);     /* ... instead, set a safe IFS */
+@@ -555,6 +566,22 @@
+               exit (1);
+       }
+ 
++      ret = pam_open_session (pamh, 0);
++      if (ret != PAM_SUCCESS) {
++              SYSLOG ((LOG_ERR, "pam_open_session: %s",
++                      pam_strerror (pamh, ret)));
++              fprintf (stderr, "%s: %s\n", Prog,
++                      pam_strerror (pamh, ret));
++              pam_end (pamh, ret);
++              exit (1);
++      }
++
++      /* we need to setup the environment *after* pam_open_session(),
++       * else the UID is changed before stuff like pam_xauth could
++       * run, and we cannot access /etc/shadow and co
++       */
++      environ = newenvp;      /* make new environment active */
++
+       /* become the new user */
+       if (change_uid (&pwent)) {
+               pam_setcred (pamh, PAM_DELETE_CRED);
diff --git a/sys-apps/shadow/shadow-4.0.3-r1.ebuild b/sys-apps/shadow/shadow-4.0.3-r1.ebuild
new file mode 100644 (file)
index 0000000..84a59d0
--- /dev/null
@@ -0,0 +1,158 @@
+# Copyright 1999-2002 Gentoo Technologies, Inc.
+# Distributed under the terms of the GNU General Public License v2
+# $Header: /var/cvsroot/gentoo-x86/sys-apps/shadow/shadow-4.0.3-r1.ebuild,v 1.1 2002/10/19 09:31:05 azarah Exp $
+
+inherit libtool
+
+S="${WORKDIR}/${P}"
+HOMEPAGE="http://shadow.pld.org.pl/"
+DESCRIPTION="Utilities to deal with user accounts"
+SRC_URI="ftp://ftp.pld.org.pl/software/shadow/${P}.tar.gz"
+
+LICENSE="BSD"
+SLOT="0"
+KEYWORDS="~x86 ~ppc ~sparc ~sparc64 ~alpha"
+
+DEPEND=">=sys-libs/pam-0.75-r4
+       >=sys-libs/cracklib-2.7-r3
+       sys-devel/gettext"
+       
+RDEPEND=">=sys-libs/pam-0.75-r4
+       >=sys-libs/cracklib-2.7-r3"
+
+
+pkg_preinst() { 
+       rm -f ${ROOT}/etc/pam.d/system-auth.new
+}
+
+src_unpack() {
+       unpack ${A}
+
+       # Get su to call pam_open_session(), and also set DISPLAY and XAUTHORITY,
+       # else the session entries in /etc/pam.d/su never get executed, and
+       # pam_xauth for one, is then never used.  This should close bug #8831.
+       #
+       # <azarah@gentoo.org> (19 Oct 2002)
+       cd ${S}; patch -p1 < ${FILESDIR}/${P}-su-pam_open_session.patch || die
+}
+
+src_compile() {
+       elibtoolize
+
+       local myconf=""
+       use nls || myconf="${myconf} --disable-nls"
+
+       ./configure --disable-desrpc \
+               --with-libcrypt \
+               --with-libcrack \
+               --with-libpam \
+               --enable-shared=no \
+               --enable-static=yes \
+               --host=${CHOST} \
+               ${myconf} || die "bad configure"
+               
+       # Parallel make fails sometimes
+       make || die "compile problem"
+}
+
+src_install() {
+       dodir /etc/default /etc/skel
+
+       make prefix=${D}/usr \
+               exec_prefix=${D} \
+               mandir=${D}/usr/share/man \
+               install || die "install problem"
+
+       #do not install this login, but rather the one from
+       #util-linux, as this one have a serious root exploit
+       #with pam_limits in use.
+       rm ${D}/bin/login
+
+       mv ${D}/lib ${D}/usr
+       dosed "s:/lib':/usr/lib':g" /usr/lib/libshadow.la
+       dosed "s:/lib/:/usr/lib/:g" /usr/lib/libshadow.la
+       dosed "s:/lib':/usr/lib':g" /usr/lib/libmisc.la
+       dosed "s:/lib/:/usr/lib/:g" /usr/lib/libmisc.la
+       dosym /usr/bin/newgrp /usr/bin/sg
+       dosym /usr/sbin/useradd /usr/sbin/adduser
+       dosym /usr/sbin/vipw /usr/sbin/vigr
+       # remove dead links
+       rm -f ${D}/bin/{sg,vipw}
+
+       insinto /etc
+       # Using a securetty with devfs device names added
+       # (compat names kept for non-devfs compatibility)
+       insopts -m0600 ; doins ${FILESDIR}/securetty
+       insopts -m0600 ; doins ${S}/etc/login.access
+       insopts -m0644 ; doins ${S}/etc/limits
+
+       # needed for 'adduser -D'
+       keepdir /etc/default
+
+# From sys-apps/pam-login now
+#      insopts -m0644 ; doins ${FILESDIR}/login.defs
+       insinto /etc/pam.d ; insopts -m0644
+       cd ${FILESDIR}/pam.d
+       doins *
+       newins system-auth system-auth.new
+       newins shadow chage
+       newins shadow chsh
+       newins shadow chfn
+       newins shadow useradd
+       newins shadow groupadd
+       cd ${S}
+
+       # the manpage install is beyond my comprehension, and also broken.
+       # just do it over.
+       rm -rf ${D}/usr/share/man/*
+       for q in man/*.[0-9]
+       do
+               local dir="${D}/usr/share/man/man${q##*.}"
+               mkdir -p $dir
+               cp $q $dir
+       done
+       
+       #dont install the manpage, since we dont use
+       #login with shadow
+       rm ${D}/usr/share/man/man1/login.*
+       
+       cd ${S}/doc
+       dodoc ANNOUNCE INSTALL LICENSE README WISHLIST
+       docinto txt
+       dodoc HOWTO LSM README.* *.txt
+
+       # Fix sparc serial console
+       if [ "${ARCH}" == "sparc" -o "${ARCH}" == "sparc64" ]; then
+               cd ${D}/etc
+               cp securetty securetty.orig
+               # ttyS0 and its devfsd counterpart (Sparc serial port "A")
+               sed -e 's:\(vc/1\)$:tts/0\n\1:' \
+                       -e 's:\(tty1\)$:ttyS0\n\1:' \
+                       securetty.orig > securetty || die
+               rm securetty.orig
+       fi
+}
+
+pkg_postinst() {
+       echo
+       echo "****************************************************"
+       echo "   Due to a security issue, ${ROOT}etc/pam.d/system-auth "
+       echo "   is being updated automatically. Your old "
+       echo "   system-auth will be backed up as:"
+       echo "   ${ROOT}etc/pam.d/system-auth.bak"
+       echo "****************************************************"
+       echo
+       local CHECK1=`md5sum ${ROOT}/etc/pam.d/system-auth | cut -d ' ' -f 1`
+       local CHECK2=`md5sum ${ROOT}/etc/pam.d/system-auth.new | cut -d ' ' -f 1`
+
+       if [ "$CHECK1" != "$CHECK2" ];
+       then
+               cp -a ${ROOT}/etc/pam.d/system-auth \
+                     ${ROOT}/etc/pam.d/system-auth.bak;
+               mv -f ${ROOT}/etc/pam.d/system-auth.new \
+                     ${ROOT}/etc/pam.d/system-auth
+       else
+               rm -f ${ROOT}/etc/pam.d/system-auth.new
+       fi
+}
+