From: Alexandre Rostovtsev Date: Sat, 31 Dec 2011 08:34:36 +0000 (+0000) Subject: Add upstream patches to fix login problems with slow pam modules. Add default-enabled... X-Git-Url: http://git.tremily.us/gitweb.cgi?a=commitdiff_plain;h=67a2a323c85330e8882839800a234d4369ceeea0;p=gentoo.git Add upstream patches to fix login problems with slow pam modules. Add default-enabled fallback USE flag to pull in metacity (bug #395295, thanks to Octavio Ruiz (Ta^3) for reporting). Use a better systemd service file (bug #396317, thanks to Michał Górny). Ship systemd service file and pam.d files in FILESDIR instead of a separate tarball; these are small files and unlikely to change (bug #396317, comment 8). Punt unused elibc_glibc from IUSE. Move gnome2_src_prepare after eautoreconf. Forced to drop arm keyword due to gnome-session dependency (bug #390345). Package-Manager: portage-2.2.0_alpha84/cvs/Linux x86_64 --- diff --git a/gnome-base/gdm/ChangeLog b/gnome-base/gdm/ChangeLog index ce3bc8d6abc4..3730e9d07ae2 100644 --- a/gnome-base/gdm/ChangeLog +++ b/gnome-base/gdm/ChangeLog @@ -1,6 +1,23 @@ # ChangeLog for gnome-base/gdm # Copyright 1999-2011 Gentoo Foundation; Distributed under the GPL v2 -# $Header: /var/cvsroot/gentoo-x86/gnome-base/gdm/ChangeLog,v 1.348 2011/11/05 08:19:52 tetromino Exp $ +# $Header: /var/cvsroot/gentoo-x86/gnome-base/gdm/ChangeLog,v 1.349 2011/12/31 08:34:36 tetromino Exp $ + +*gdm-3.2.1.1-r2 (31 Dec 2011) + + 31 Dec 2011; Alexandre Rostovtsev + +files/gdm-3.2.1.1-pam-fix-1.patch, +files/3.2.1.1/gdm-fingerprint, + +files/gdm-3.2.1.1-pam-fix-2.patch, +files/3.2.1.1/gdm, + +files/3.2.1.1/gdm.service, +files/3.2.1.1/gdm-autologin, + +files/3.2.1.1/gdm-welcome, gdm-3.2.1.1-r1.ebuild, +gdm-3.2.1.1-r2.ebuild, + +files/3.2.1.1/gdm-password, +files/3.2.1.1/gdm-smartcard, metadata.xml: + Add upstream patches to fix login problems with slow pam modules. Add + default-enabled fallback USE flag to pull in metacity (bug #395295, thanks to + Octavio Ruiz (Ta^3) for reporting). Use a better systemd service file (bug + #396317, thanks to Michał Górny). Ship systemd service file and pam.d files + in FILESDIR instead of a separate tarball; these are small files and unlikely + to change (bug #396317, comment 8). Punt unused elibc_glibc from IUSE. Move + gnome2_src_prepare after eautoreconf. + Forced to drop arm keyword due to gnome-session dependency (bug #390345). *gdm-3.2.1.1-r1 (05 Nov 2011) diff --git a/gnome-base/gdm/Manifest b/gnome-base/gdm/Manifest index 5c463a1335d0..aee5e20d4e60 100644 --- a/gnome-base/gdm/Manifest +++ b/gnome-base/gdm/Manifest @@ -1,6 +1,13 @@ -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 +AUX 3.2.1.1/gdm 274 RMD160 88c235b0e1907829a38a1be9c8f0fdc262b042d7 SHA1 3b08e4022e421417cb1fd9a03fd01c1ddedb27d5 SHA256 4c26f02021ffa41500fa98aeda61dde6d059243f027cf93f8fb00fde39a9edd3 +AUX 3.2.1.1/gdm-autologin 369 RMD160 2adb17241b378ad4ca10e6241cb21b5a679c0973 SHA1 8372a199f5e00fb0d9d2630d0ced060f190d2af2 SHA256 e964a100e72a8eccea4ed8e1558ae70cbe5b7cbea67415651d0c0bdcea2d06c8 +AUX 3.2.1.1/gdm-fingerprint 466 RMD160 3f63354ccce1de0dacc3c4b304673fa56fb35e4e SHA1 6e2d0d67e4c9cbff1efe3de5f57b1ace137c3314 SHA256 3af315d6abe928dd769f2cc9896d536e187ab373b29667c185e452ac6063d9cc +AUX 3.2.1.1/gdm-password 274 RMD160 88c235b0e1907829a38a1be9c8f0fdc262b042d7 SHA1 3b08e4022e421417cb1fd9a03fd01c1ddedb27d5 SHA256 4c26f02021ffa41500fa98aeda61dde6d059243f027cf93f8fb00fde39a9edd3 +AUX 3.2.1.1/gdm-smartcard 573 RMD160 6e1655b9b6d6cb1710cf052bcf45e0f305ecd244 SHA1 19d459d5970e53ac9a40abdedd183873309b37bf SHA256 9c548668770aa68e730e5d5159d77067dbd0795dae2b7ba6d6ee347f88e90062 +AUX 3.2.1.1/gdm-welcome 326 RMD160 c69bf97510ca352e0da904e9b922c9eadebe7bde SHA1 f626c04e40c838a795f6be599bf01481e16eb854 SHA256 9325241dfd722e58e93dd1dc81714bef4b3b211f4fb8551f39a698415722934a +AUX 3.2.1.1/gdm.service 202 RMD160 0192b184238f97e2060f4462bd6a9dcb0e2ec2f3 SHA1 f457a6f0c9e6e842eb1a8193ca4e27412e4b484b SHA256 21b105f56bc90178e05806583e3be5e74857c02ec6443318669f9ab6f947bb79 AUX 49-keychain 181 RMD160 32ce131e93fc2d8640edee72ad42124537860156 SHA1 b4518f9d8ba65d0cf4d64ded844e59be343088d3 SHA256 d73e07847bfa6ac69938aa309f5c137d4c36248cedf9834db1315ba1b2b87140 AUX 50-ssh-agent 243 RMD160 14327252dc1da75bdb49380960434a613b28cfa6 SHA1 e808be7a34324b269d493585990f134e82cc722a SHA256 f0790148b975ef1e7a37ffe8f5d90f943746f0a3bcf9d7fad8500219e2114042 AUX gdm-2.13.0.1-selinux-remove-attr.patch 908 RMD160 5d766a45d7c5db2453f9bdfaa7cdf02232bc66e5 SHA1 b8c6bda65c8f3f28a601167d8e8b50d4aa1db221 SHA256 40074297200e3424a1baeb483d7fc50d9846a0c74ce46d72845090647d28d14b @@ -19,6 +26,8 @@ AUX gdm-2.32.0-selinux-remove-attr.patch 851 RMD160 10dc29802fb29047188bff7aafe9 AUX gdm-2.32.0-xinitrc-ssh-agent.patch 863 RMD160 6ea58bdc1fa24d41f3c51fc7cdbabc05417053f0 SHA1 ad98258168b84c80d581085804b61649ac67e4d5 SHA256 71231d08baf41ee7b91c33c3d8a731c078d1d29328e09223efb1f579bacdaffe AUX gdm-3.2.1.1-custom-session.patch 1317 RMD160 20a1dd5608f4154fe53fae4def03f509769da878 SHA1 4acf8ed9b11eb531505c0c58805f1b37948fcb77 SHA256 75bd1bdc0d396fee71ff41c2657f922a4c8e290c891cc72f47647ab832d0c285 AUX gdm-3.2.1.1-disable-accessibility.patch 1637 RMD160 12f69b9b67fc6dbb0a57ed25f0d0ea68167f53f2 SHA1 0e6580f88768d2f8c20d2cfdf5d9c8ecb7f84e66 SHA256 60ef48cf07dab78c3f09e5e57cd9138398cfe1d5de4b17408d3c08da58239932 +AUX gdm-3.2.1.1-pam-fix-1.patch 5032 RMD160 91fc5366a10d8fee936f0ba90aba97c60c284f94 SHA1 140f5b76f8253cce85f564beb2073c996dce1458 SHA256 3109179ed53fac5b6cd0465b5d940421d95cb303942a641e7d388f621a15ce81 +AUX gdm-3.2.1.1-pam-fix-2.patch 1127 RMD160 c6976c00dfdc6499064a4267fc3e2aabc1ff1d93 SHA1 d7cb0cf459e627dc8e6575e753191a2b15d5dc37 SHA256 6a8857ec7a748ca17a2e3ae99df79f1bd59d501b23d60a44761b92fda490ae02 DIST gdm-2.20.11.tar.bz2 4013059 RMD160 e400bb8a0b78a2e8b0da98edd2e0f3a7a0267f04 SHA1 be23bdf32b7a4254ac80983f4edf25cafa847ff3 SHA256 2e21c9a44941cd0033aaa6b381b563488bbdd0ad1a28ef05f7e0178891f1eaa2 DIST gdm-2.20.9-gentoo-files-r1.tar.bz2 3494 RMD160 9d8f9954bd0d8b657a2faf2516b4548b9f1556d3 SHA1 28ceedb42440fdb50dffa7e69b18f213b00e3935 SHA256 666c0bf1ba28ccc257bf1235b5286e1eb9e15230c0036413ab428e09c54238f9 DIST gdm-2.32.1.tar.bz2 2441685 RMD160 70526a3ddec3ff8a1313243641bf807a2218f3ae SHA1 75017d6acfc8e158e0df848629431021b25998a5 SHA256 7ba9cb2a8efb9856994467b14e4837a281fcf6d9dc9a267ea38a9aae1ec55abc @@ -29,13 +38,14 @@ EBUILD gdm-2.20.11-r1.ebuild 7220 RMD160 4e8e841fca070f7ca8d0c4c1011f24e39de62de EBUILD gdm-2.20.11.ebuild 6981 RMD160 d89e163666b53c173578abce9846fed4dde4d5f9 SHA1 5dff7be8ab624c3b15b5dfe6bfb14ae1afc6f0d7 SHA256 174e8685993d432e3cad052626a318f6b622a07954d873ac79c27db0d8ebe3f5 EBUILD gdm-2.32.1-r1.ebuild 5596 RMD160 69277cc8730fe8c9b5157db0fb8175ee5828e427 SHA1 c71e7cddf7f3fb6701901415170ef73c9e3460d0 SHA256 98ba7249fea7956e4978528c65c183499aa29bac33a317ea8a2325ff6f3b1e6c EBUILD gdm-2.32.1.ebuild 5602 RMD160 921d0774cb460a577868e5c68d4b57e6d73c1368 SHA1 b62cedc7eb647f0dd7f493c059a54691d124f349 SHA256 c75ebeeaa77288325da04258e6d12ae4bd7ed4d3c3b8ebc87d4399802e0ce262 -EBUILD gdm-3.2.1.1-r1.ebuild 8538 RMD160 cc334c8e325335028cca8825033ff82231dec4e2 SHA1 e1a211e8411c5bcb5c624aa933d7728faff08c13 SHA256 9fd444e1e9cbae769c5a07e73a6d94ba90bef3e8edc55ff206836853bdd1359a -MISC ChangeLog 49150 RMD160 b94dbd4a5bb59ff9b9cee613bd69565e31e70227 SHA1 73a1417671ae01d924db35c727f1278ed35e4199 SHA256 322d4c4adbe818d4c0d055dfbf1ec13c12dcc8792a856d0dc41f8dbb0809013d -MISC metadata.xml 914 RMD160 0b4fafbdb6fe9d54da1e3f9773fd158d0a81d5d4 SHA1 e175fe2fea96347e191465d9a63320ce3ced44f2 SHA256 efbc3886382ee7ea1ca1dbef1e49bdfb1086c0a5e352525a7cff58ac54fc1ec7 +EBUILD gdm-3.2.1.1-r1.ebuild 8498 RMD160 355a361418ce8d7124cdd98fb18577a960924d61 SHA1 3807abf826722cd938a10c12e64b745289ee5771 SHA256 3c78044a835c5a9a9d923226aa6b2363161f27b2f63531ad98fae2d9addf4b3a +EBUILD gdm-3.2.1.1-r2.ebuild 8467 RMD160 4810e3883f160ce7e01a07d98e5b589708cecf7d SHA1 a2cb56840d07a4e995de4b0b189eb29f0d7b5548 SHA256 31994d7049e783fc173e15a9170bfcd643bacb4574a6715185747ea1257ff143 +MISC ChangeLog 50164 RMD160 77fd95fd4e9b2fa719ff4413d8f2e39579a075bb SHA1 d8866567416204aa252d5a6c4b9eac251608d583 SHA256 a4f440a3d0a9afdf19d09e6a1c1d2aae8090d0d32821abed1e385606eb42840c +MISC metadata.xml 1036 RMD160 27b54cac75516ed19069fdb0048631b26e063708 SHA1 15a745e1b7b5cdc03393182a5a7cf79d04810a2c SHA256 2ddbd14d7829a3b67e9acb46d90f7385e48e67c309258b1716c682523f26fb07 -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.18 (GNU/Linux) -iF4EAREIAAYFAk608a0ACgkQdjK8w9WeBnBkmQEAsLRrCU7iliUM5IwFSBP8C/u4 -8xBwOIRITbKbSVcgPogA/j41ad8+WqNl+nL9IQeYczNeyErOEl2MINVd/feoKAxD -=XHvo +iF4EAREIAAYFAk7+ySEACgkQdjK8w9WeBnAEbQD+MJ/vkgGcgj8L0t3g8Wsz5/Th +kWCsRpbe/vOwxuIhewIBAJiYcNvueJeeoVN3U+rP1CrA30Q6mv4VR0D46tGlWrm/ +=GBFN -----END PGP SIGNATURE----- diff --git a/gnome-base/gdm/files/3.2.1.1/gdm b/gnome-base/gdm/files/3.2.1.1/gdm new file mode 100644 index 000000000000..d965ecac53bc --- /dev/null +++ b/gnome-base/gdm/files/3.2.1.1/gdm @@ -0,0 +1,11 @@ +#%PAM-1.0 +auth optional pam_env.so +auth include system-login +auth required pam_nologin.so + +account include system-login + +password include system-login + +session include system-auth +#Keyring=session optional pam_gnome_keyring.so auto_start diff --git a/gnome-base/gdm/files/3.2.1.1/gdm-autologin b/gnome-base/gdm/files/3.2.1.1/gdm-autologin new file mode 100644 index 000000000000..9d165d6d9cc5 --- /dev/null +++ b/gnome-base/gdm/files/3.2.1.1/gdm-autologin @@ -0,0 +1,10 @@ +#%PAM-1.0 +auth optional pam_env.so +auth required pam_nologin.so +auth required pam_permit.so +account include system-login +password include system-login +session include system-auth +# For the keyring to unlock with autologin, you need to set an empty +# password on the keyring. +#Keyring=session optional pam_gnome_keyring.so auto_start diff --git a/gnome-base/gdm/files/3.2.1.1/gdm-fingerprint b/gnome-base/gdm/files/3.2.1.1/gdm-fingerprint new file mode 100644 index 000000000000..7d38de945fd3 --- /dev/null +++ b/gnome-base/gdm/files/3.2.1.1/gdm-fingerprint @@ -0,0 +1,14 @@ +#%PAM-1.0 +# Note: no pam_gnome_keyring.so support since the login password is not used +auth optional pam_env.so +auth required pam_tally2.so onerr=succeed +auth required pam_shells.so +auth required pam_nologin.so +auth required pam_fprintd.so +auth optional pam_permit.so + +account include system-login + +password required pam_deny.so + +session include system-auth diff --git a/gnome-base/gdm/files/3.2.1.1/gdm-password b/gnome-base/gdm/files/3.2.1.1/gdm-password new file mode 100644 index 000000000000..d965ecac53bc --- /dev/null +++ b/gnome-base/gdm/files/3.2.1.1/gdm-password @@ -0,0 +1,11 @@ +#%PAM-1.0 +auth optional pam_env.so +auth include system-login +auth required pam_nologin.so + +account include system-login + +password include system-login + +session include system-auth +#Keyring=session optional pam_gnome_keyring.so auto_start diff --git a/gnome-base/gdm/files/3.2.1.1/gdm-smartcard b/gnome-base/gdm/files/3.2.1.1/gdm-smartcard new file mode 100644 index 000000000000..5cf884da8713 --- /dev/null +++ b/gnome-base/gdm/files/3.2.1.1/gdm-smartcard @@ -0,0 +1,15 @@ +#%PAM-1.0 +auth optional pam_env.so +auth required pam_tally2.so onerr=succeed +auth required pam_shells.so +auth required pam_nologin.so +auth [success=done ignore=ignore default=die] pam_pkcs11.so wait_for_card card_only +auth optional pam_permit.so + +account include system-login + +password optional pam_pkcs11.so +password required pam_cracklib.so difok=2 minlen=8 dcredit=2 ocredit=2 retry=3 +password optional pam_permit.so + +session include system-auth diff --git a/gnome-base/gdm/files/3.2.1.1/gdm-welcome b/gnome-base/gdm/files/3.2.1.1/gdm-welcome new file mode 100644 index 000000000000..932eefee357f --- /dev/null +++ b/gnome-base/gdm/files/3.2.1.1/gdm-welcome @@ -0,0 +1,9 @@ +#%PAM-1.0 +auth required pam_env.so +auth required pam_permit.so +account required pam_nologin.so +account include system-services +password include system-services +session required pam_loginuid.so +session optional pam_keyinit.so force revoke +session include system-services diff --git a/gnome-base/gdm/files/3.2.1.1/gdm.service b/gnome-base/gdm/files/3.2.1.1/gdm.service new file mode 100644 index 000000000000..63bb08e90219 --- /dev/null +++ b/gnome-base/gdm/files/3.2.1.1/gdm.service @@ -0,0 +1,11 @@ +[Unit] +Description=GNOME Display Manager +After=systemd-user-sessions.service + +[Service] +ExecStart=/usr/bin/gdm --nodaemon +Type=dbus +BusName=org.gnome.DisplayManager + +[Install] +WantedBy=graphical.target diff --git a/gnome-base/gdm/files/gdm-3.2.1.1-pam-fix-1.patch b/gnome-base/gdm/files/gdm-3.2.1.1-pam-fix-1.patch new file mode 100644 index 000000000000..0fe399ee0376 --- /dev/null +++ b/gnome-base/gdm/files/gdm-3.2.1.1-pam-fix-1.patch @@ -0,0 +1,126 @@ +From 9c354795892b8c5fd661a35653991a88fabc76bf Mon Sep 17 00:00:00 2001 +From: Ray Strode +Date: Mon, 24 Oct 2011 16:39:45 -0400 +Subject: [PATCH] daemon: Don't emit session-exited when non-authenticated + worker fails + +Sometimes PAM modules are finicky and don't die when you tell them to. +Instead they fail some seconds later. + +If a user successfully logs in with one stack and another stack is +being troublesome, then we'll get notified about it finishing up +after the user is already logged in. + +When that happens, we erroneously assume the stack finishing is the +stack the user's session is running on and then proceed to log the +user out. + +This commit makes us be a little more careful about our bookkeeping +so we can ignore failures from slow PAM modules. +--- + daemon/gdm-session-direct.c | 23 ++++++++++++++--------- + 1 files changed, 14 insertions(+), 9 deletions(-) + +diff --git a/daemon/gdm-session-direct.c b/daemon/gdm-session-direct.c +index e178985..bb2bff8 100644 +--- a/daemon/gdm-session-direct.c ++++ b/daemon/gdm-session-direct.c +@@ -91,10 +91,11 @@ struct _GdmSessionDirectPrivate + + GHashTable *conversations; + ++ GdmSessionConversation *session_conversation; ++ + GList *pending_connections; + + GPid session_pid; +- guint32 is_running : 1; + + /* object lifetime scope */ + char *id; +@@ -1073,7 +1074,7 @@ gdm_session_direct_handle_session_started (GdmSessionDirect *session, + pid); + + session->priv->session_pid = pid; +- session->priv->is_running = TRUE; ++ session->priv->session_conversation = conversation; + + _gdm_session_session_started (GDM_SESSION (session), conversation->service_name, pid); + +@@ -1129,7 +1130,7 @@ gdm_session_direct_handle_session_exited (GdmSessionDirect *session, + g_debug ("GdmSessionDirect: Emitting 'session-exited' signal with exit code '%d'", + code); + +- session->priv->is_running = FALSE; ++ session->priv->session_conversation = NULL; + _gdm_session_session_exited (GDM_SESSION (session), code); + + return DBUS_HANDLER_RESULT_HANDLED; +@@ -1158,7 +1159,7 @@ gdm_session_direct_handle_session_died (GdmSessionDirect *session, + g_debug ("GdmSessionDirect: Emitting 'session-died' signal with signal number '%d'", + code); + +- session->priv->is_running = FALSE; ++ session->priv->session_conversation = NULL; + _gdm_session_session_died (GDM_SESSION (session), code); + + return DBUS_HANDLER_RESULT_HANDLED; +@@ -1790,7 +1791,7 @@ worker_exited (GdmSessionWorkerJob *job, + g_debug ("GdmSessionDirect: Worker job exited: %d", code); + + g_object_ref (conversation->job); +- if (conversation->session->priv->is_running) { ++ if (conversation->session->priv->session_conversation == conversation) { + _gdm_session_session_exited (GDM_SESSION (conversation->session), code); + } + +@@ -1819,7 +1820,7 @@ worker_died (GdmSessionWorkerJob *job, + g_debug ("GdmSessionDirect: Worker job died: %d", signum); + + g_object_ref (conversation->job); +- if (conversation->session->priv->is_running) { ++ if (conversation->session->priv->session_conversation == conversation) { + _gdm_session_session_died (GDM_SESSION (conversation->session), signum); + } + +@@ -2442,6 +2443,10 @@ stop_all_other_conversations (GdmSessionDirect *session, + g_strdup (conversation_to_keep->service_name), + conversation_to_keep); + } ++ ++ if (session->priv->session_conversation != conversation_to_keep) { ++ session->priv->session_conversation = NULL; ++ } + } + + } +@@ -2456,7 +2461,7 @@ gdm_session_direct_start_session (GdmSession *session, + char *program; + + g_return_if_fail (session != NULL); +- g_return_if_fail (impl->priv->is_running == FALSE); ++ g_return_if_fail (impl->priv->session_conversation == NULL); + + conversation = find_conversation_by_name (impl, service_name); + +@@ -2504,7 +2509,7 @@ gdm_session_direct_close (GdmSession *session) + + g_debug ("GdmSessionDirect: Closing session"); + +- if (impl->priv->is_running) { ++ if (impl->priv->session_conversation != NULL) { + gdm_session_record_logout (impl->priv->session_pid, + impl->priv->selected_user, + impl->priv->display_hostname, +@@ -2540,7 +2545,7 @@ gdm_session_direct_close (GdmSession *session) + g_hash_table_remove_all (impl->priv->environment); + + impl->priv->session_pid = -1; +- impl->priv->is_running = FALSE; ++ impl->priv->session_conversation = NULL; + } + + static void +-- +1.7.8.1 + diff --git a/gnome-base/gdm/files/gdm-3.2.1.1-pam-fix-2.patch b/gnome-base/gdm/files/gdm-3.2.1.1-pam-fix-2.patch new file mode 100644 index 000000000000..20e85399c9e9 --- /dev/null +++ b/gnome-base/gdm/files/gdm-3.2.1.1-pam-fix-2.patch @@ -0,0 +1,27 @@ +From 9c874ee6f595906faf59f891f20492530888804b Mon Sep 17 00:00:00 2001 +From: Ray Strode +Date: Mon, 24 Oct 2011 16:45:46 -0400 +Subject: [PATCH] worker: don't block SIGTERM + +If the slave tells us to go away, we should go away, +not wait a PAM module decides to let us get back to the +main loop. +--- + daemon/session-worker-main.c | 1 - + 1 files changed, 0 insertions(+), 1 deletions(-) + +diff --git a/daemon/session-worker-main.c b/daemon/session-worker-main.c +index 9d40b8d..42fcd52 100644 +--- a/daemon/session-worker-main.c ++++ b/daemon/session-worker-main.c +@@ -188,7 +188,6 @@ main (int argc, + gdm_signal_handler_set_fatal_func (signal_handler, + (GDestroyNotify)g_main_loop_quit, + main_loop); +- gdm_signal_handler_add (signal_handler, SIGTERM, signal_cb, NULL); + gdm_signal_handler_add (signal_handler, SIGINT, signal_cb, NULL); + gdm_signal_handler_add (signal_handler, SIGILL, signal_cb, NULL); + gdm_signal_handler_add (signal_handler, SIGBUS, signal_cb, NULL); +-- +1.7.8.1 + diff --git a/gnome-base/gdm/gdm-3.2.1.1-r1.ebuild b/gnome-base/gdm/gdm-3.2.1.1-r1.ebuild index b5a6f8e3c8be..e8b7040c1f53 100644 --- a/gnome-base/gdm/gdm-3.2.1.1-r1.ebuild +++ b/gnome-base/gdm/gdm-3.2.1.1-r1.ebuild @@ -1,6 +1,6 @@ # Copyright 1999-2011 Gentoo Foundation # Distributed under the terms of the GNU General Public License v2 -# $Header: /var/cvsroot/gentoo-x86/gnome-base/gdm/gdm-3.2.1.1-r1.ebuild,v 1.1 2011/11/05 08:19:52 tetromino Exp $ +# $Header: /var/cvsroot/gentoo-x86/gnome-base/gdm/gdm-3.2.1.1-r1.ebuild,v 1.2 2011/12/31 08:34:36 tetromino Exp $ EAPI="4" GNOME2_LA_PUNT="yes" @@ -13,10 +13,9 @@ HOMEPAGE="http://www.gnome.org/projects/gdm/" LICENSE="GPL-2" SLOT="0" -KEYWORDS="~amd64 ~arm ~sh ~x86" +KEYWORDS="~amd64 ~sh ~x86" -IUSE_LIBC="elibc_glibc" -IUSE="accessibility +consolekit fprint +gnome-shell ipv6 gnome-keyring +introspection selinux smartcard tcpd test xinerama +xklavier $IUSE_LIBC" +IUSE="accessibility +consolekit fprint +gnome-shell ipv6 gnome-keyring +introspection selinux smartcard tcpd test xinerama +xklavier" # Name of the tarball with gentoo specific files GDM_EXTRA="${PN}-3.2.1.1-gentoo-files" diff --git a/gnome-base/gdm/gdm-3.2.1.1-r2.ebuild b/gnome-base/gdm/gdm-3.2.1.1-r2.ebuild new file mode 100644 index 000000000000..f1d5004852b3 --- /dev/null +++ b/gnome-base/gdm/gdm-3.2.1.1-r2.ebuild @@ -0,0 +1,267 @@ +# Copyright 1999-2011 Gentoo Foundation +# Distributed under the terms of the GNU General Public License v2 +# $Header: /var/cvsroot/gentoo-x86/gnome-base/gdm/gdm-3.2.1.1-r2.ebuild,v 1.1 2011/12/31 08:34:36 tetromino Exp $ + +EAPI="4" +GNOME2_LA_PUNT="yes" +GCONF_DEBUG="yes" + +inherit autotools eutils gnome2 pam systemd + +DESCRIPTION="GNOME Display Manager" +HOMEPAGE="http://www.gnome.org/projects/gdm/" + +LICENSE="GPL-2" +SLOT="0" +KEYWORDS="~amd64 ~sh ~x86" + +IUSE="accessibility +consolekit +fallback fprint +gnome-shell ipv6 gnome-keyring +introspection selinux smartcard tcpd test xinerama +xklavier" + +# NOTE: x11-base/xorg-server dep is for X_SERVER_PATH etc, bug #295686 +# nspr used by smartcard extension +# dconf, dbus and g-s-d are needed at install time for dconf update +COMMON_DEPEND=" + >=dev-libs/dbus-glib-0.74 + >=dev-libs/glib-2.29.3:2 + >=x11-libs/gtk+-2.91.1:3 + >=x11-libs/pango-1.3 + dev-libs/nspr + >=dev-libs/nss-3.11.1 + >=media-libs/fontconfig-2.5.0 + >=media-libs/libcanberra-0.4[gtk3] + >=gnome-base/gconf-2.31.3 + >=x11-misc/xdg-utils-1.0.2-r3 + >=sys-power/upower-0.9 + >=sys-apps/accountsservice-0.6.12 + + gnome-base/dconf + >=gnome-base/gnome-settings-daemon-3.1.4 + gnome-base/gsettings-desktop-schemas + sys-apps/dbus + + app-text/iso-codes + + x11-base/xorg-server + x11-libs/libXi + x11-libs/libXau + x11-libs/libX11 + x11-libs/libXdmcp + x11-libs/libXext + x11-libs/libXft + x11-libs/libXrandr + x11-apps/sessreg + + virtual/pam + consolekit? ( sys-auth/consolekit ) + + accessibility? ( x11-libs/libXevie ) + gnome-keyring? ( >=gnome-base/gnome-keyring-2.22[pam] ) + introspection? ( >=dev-libs/gobject-introspection-0.9.12 ) + selinux? ( sys-libs/libselinux ) + tcpd? ( >=sys-apps/tcp-wrappers-7.6 ) + xinerama? ( x11-libs/libXinerama ) + xklavier? ( >=x11-libs/libxklavier-4 )" +DEPEND="${COMMON_DEPEND} + test? ( >=dev-libs/check-0.9.4 ) + xinerama? ( x11-proto/xineramaproto ) + app-text/docbook-xml-dtd:4.1.2 + sys-devel/gettext + x11-proto/inputproto + x11-proto/randrproto + >=dev-util/intltool-0.40.0 + >=dev-util/pkgconfig-0.19 + >=app-text/scrollkeeper-0.1.4 + >=app-text/gnome-doc-utils-0.3.2" +# XXX: These deps are from session and desktop files in data/ directory +# at-spi:1 is needed for at-spi-registryd (spawned by simple-chooser) +# fprintd is used via dbus by gdm-fingerprint-extension +RDEPEND="${COMMON_DEPEND} + >=gnome-base/gnome-session-2.91.92 + x11-apps/xhost + + accessibility? ( + app-accessibility/gnome-mag + app-accessibility/gok + app-accessibility/orca + gnome-extra/at-spi:1 ) + consolekit? ( gnome-extra/polkit-gnome ) + fallback? ( x11-wm/metacity ) + fprint? ( + sys-auth/fprintd + sys-auth/pam_fprint ) + gnome-shell? ( >=gnome-base/gnome-shell-3.1.90 ) + !gnome-shell? ( x11-wm/metacity ) + smartcard? ( + app-crypt/coolkey + sys-auth/pam_pkcs11 ) + + !gnome-extra/fast-user-switch-applet" + +pkg_setup() { + DOCS="AUTHORS ChangeLog NEWS README TODO" + + # PAM is the only auth scheme supported + # even though configure lists shadow and crypt + # they don't have any corresponding code. + # --with-at-spi-registryd-directory= needs to be passed explicitly because + # of https://bugzilla.gnome.org/show_bug.cgi?id=607643#c4 + G2CONF="${G2CONF} + --disable-schemas-install + --disable-static + --localstatedir=${EPREFIX}/var + --with-xdmcp=yes + --enable-authentication-scheme=pam + --with-pam-prefix=${EPREFIX}/etc + --with-at-spi-registryd-directory=${EPREFIX}/usr/libexec + $(use_with accessibility xevie) + $(use_enable ipv6) + $(use_enable xklavier libxklavier) + $(use_with consolekit console-kit) + $(use_with selinux) + $(use_with tcpd tcp-wrappers) + $(use_with xinerama)" + + enewgroup gdm + enewgroup video # Just in case it hasn't been created yet + enewuser gdm -1 -1 /var/lib/gdm gdm,video + + # For compatibility with certain versions of nvidia-drivers, etc., need to + # ensure that gdm user is in the video group + if ! egetent group video | grep -q gdm; then + # FIXME XXX: is this at all portable, ldap-safe, etc.? + # XXX: egetent does not have a 1-argument form, so we can't use it to + # get the list of gdm's groups + local g=$(groups gdm) + elog "Adding user gdm to video group" + usermod -G video,${g// /,} gdm || die "Adding user gdm to video group failed" + fi +} + +src_prepare() { + # remove unneeded linker directive for selinux, bug #41022 + epatch "${FILESDIR}/${PN}-2.32.0-selinux-remove-attr.patch" + + # daemonize so that the boot process can continue, bug #236701 + epatch "${FILESDIR}/${PN}-2.32.0-fix-daemonize-regression.patch" + + # GDM grabs VT2 instead of VT7, bug 261339, bug 284053, bug 288852 + epatch "${FILESDIR}/${PN}-2.32.0-fix-vt-problems.patch" + + # make custom session work, bug #216984 + epatch "${FILESDIR}/${PN}-3.2.1.1-custom-session.patch" + + # ssh-agent handling must be done at xinitrc.d, bug #220603 + epatch "${FILESDIR}/${PN}-2.32.0-xinitrc-ssh-agent.patch" + + # fix libxklavier automagic support + epatch "${FILESDIR}/${PN}-2.32.0-automagic-libxklavier-support.patch" + + # fixes for logging in with slow pam modules from git master branch + epatch "${FILESDIR}/${PN}-3.2.1.1-pam-fix-"{1,2}.patch + + # don't load accessibility support at runtime when USE=-accessibility + use accessibility || epatch "${FILESDIR}/${PN}-3.2.1.1-disable-accessibility.patch" + + # make gdm-fallback session the default if USE=-gnome-shell + if ! use gnome-shell; then + sed -e "s:'gdm-shell':'gdm-fallback':" \ + -i data/00-upstream-settings || die "sed failed" + fi + + mkdir -p "${S}"/m4 + intltoolize --force --copy --automake || die "intltoolize failed" + eautoreconf + + gnome2_src_prepare +} + +src_install() { + gnome2_src_install + + # Install the systemd unit file + systemd_dounit "${FILESDIR}/3.2.1.1/gdm.service" + + # gdm-binary should be gdm to work with our init (#5598) + rm -f "${ED}/usr/sbin/gdm" + ln -sfn /usr/sbin/gdm-binary "${ED}/usr/sbin/gdm" + # our x11's scripts point to /usr/bin/gdm + ln -sfn /usr/sbin/gdm-binary "${ED}/usr/bin/gdm" + + # log, etc. + keepdir /var/log/gdm + + # add xinitrc.d scripts + exeinto /etc/X11/xinit/xinitrc.d + doexe "${FILESDIR}/49-keychain" + doexe "${FILESDIR}/50-ssh-agent" + + # install XDG_DATA_DIRS gdm changes + echo 'XDG_DATA_DIRS="/usr/share/gdm"' > 99xdg-gdm + doenvd 99xdg-gdm + + # install PAM files + mkdir "${T}/pam.d" || die "mkdir failed" + cp "${FILESDIR}/3.2.1.1"/gdm{,-autologin,-password,-fingerprint,-smartcard,-welcome} \ + "${T}/pam.d" || die "cp failed" + use gnome-keyring && sed -i "s:#Keyring=::g" "${T}/pam.d"/* + dopamd "${T}/pam.d"/* +} + +pkg_postinst() { + gnome2_pkg_postinst + + dbus-launch dconf update || die "'dconf update' failed" + + ewarn + ewarn "This is an EXPERIMENTAL release, please bear with its bugs and" + ewarn "visit us on #gentoo-desktop if you have problems." + ewarn + + elog "To make GDM start at boot, edit /etc/conf.d/xdm" + elog "and then execute 'rc-update add xdm default'." + elog "If you already have GDM running, you will need to restart it." + + elog + elog "GDM ignores most non-localization environment variables. If you" + elog "need GDM to launch gnome-session with a particular environment," + elog "you need to use pam_env.so in /etc/pam.d/gdm-welcome; see" + elog "the pam_env man page for more information." + elog + + if use gnome-keyring; then + elog "For autologin to unlock your keyring, you need to set an empty" + elog "password on your keyring. Use app-crypt/seahorse for that." + fi + + if [ -f "/etc/X11/gdm/gdm.conf" ]; then + elog "You had /etc/X11/gdm/gdm.conf which is the old configuration" + elog "file. It has been moved to /etc/X11/gdm/gdm-pre-gnome-2.16" + mv /etc/X11/gdm/gdm.conf /etc/X11/gdm/gdm-pre-gnome-2.16 + fi + + # https://bugzilla.redhat.com/show_bug.cgi?id=513579 + # Lennart says this problem is fixed, but users are still reporting problems + # XXX: Do we want this elog? +# if has_version "media-libs/libcanberra[pulseaudio]" ; then +# elog +# elog "You have media-libs/libcanberra with the pulseaudio USE flag" +# elog "enabled. GDM will start a pulseaudio process to play sounds. This" +# elog "process should automatically terminate when a user logs into a" +# elog "desktop session. If GDM's pulseaudio fails to terminate and" +# elog "causes problems for users' audio, you can prevent GDM from" +# elog "starting pulseaudio by editing /var/lib/gdm/.pulse/client.conf" +# elog "so it contains the following two lines:" +# elog +# elog "autospawn = no" +# elog "daemon-binary = /bin/true" +# fi +} + +pkg_postrm() { + gnome2_pkg_postrm + + if rc-config list default | grep -q xdm; then + elog "To remove GDM from startup please execute" + elog "'rc-update del xdm default'" + fi +} diff --git a/gnome-base/gdm/metadata.xml b/gnome-base/gdm/metadata.xml index 126b49076e55..06edf49ad140 100644 --- a/gnome-base/gdm/metadata.xml +++ b/gnome-base/gdm/metadata.xml @@ -6,6 +6,8 @@ Allow proper handling of removable media according to who is actually present on the machine. Enables Distributed Multihead X (DMX) support + Install x11-wm/metacity as fallback in + case gnome-shell greeter fails to start Enables experimental fingerprint authentication using sys-auth/fprintd Enables a greeter based on GNOME Shell (uses