From: Martin Schlemmer Date: Sat, 19 Oct 2002 09:31:05 +0000 (+0000) Subject: add pam_open_session() support to su, fixing bug #8831. X-Git-Url: http://git.tremily.us/gitweb.cgi?a=commitdiff_plain;h=b681c083dd88cbc4b2b059c723b69d6798ba4440;p=gentoo.git add pam_open_session() support to su, fixing bug #8831. --- diff --git a/sys-apps/shadow/ChangeLog b/sys-apps/shadow/ChangeLog index ef913e4c4d05..696df31252fd 100644 --- a/sys-apps/shadow/ChangeLog +++ b/sys-apps/shadow/ChangeLog @@ -1,6 +1,15 @@ # ChangeLog for sys-apps/shadow # Copyright 2002 Gentoo Technologies, Inc.; Distributed under the GPL -# $Header: /var/cvsroot/gentoo-x86/sys-apps/shadow/ChangeLog,v 1.15 2002/10/12 19:43:29 azarah Exp $ +# $Header: /var/cvsroot/gentoo-x86/sys-apps/shadow/ChangeLog,v 1.16 2002/10/19 09:31:05 azarah Exp $ + +*shadow-4.0.3-r1 (19 Oct 2002) + + 19 Oct 2002; Martin Schlemmer shadow-4.0.3-r1.ebuild : + + Get su to call pam_open_session(), and also set DISPLAY and XAUTHORITY, + else the session entries in /etc/pam.d/su never get executed, and + pam_xauth for one, is then never used. This should close bug #8831. + 12 Oct 2002; Martin Schlemmer shadow-4.0.3.ebuild : diff --git a/sys-apps/shadow/files/digest-shadow-4.0.3-r1 b/sys-apps/shadow/files/digest-shadow-4.0.3-r1 new file mode 100644 index 000000000000..aee0733f80f7 --- /dev/null +++ b/sys-apps/shadow/files/digest-shadow-4.0.3-r1 @@ -0,0 +1 @@ +MD5 873e49fcde0d665e916414722ecb0d72 shadow-4.0.3.tar.gz 1055089 diff --git a/sys-apps/shadow/files/shadow-4.0.3-su-pam_open_session.patch b/sys-apps/shadow/files/shadow-4.0.3-su-pam_open_session.patch new file mode 100644 index 000000000000..48d470006ac4 --- /dev/null +++ b/sys-apps/shadow/files/shadow-4.0.3-su-pam_open_session.patch @@ -0,0 +1,51 @@ +--- shadow-4.0.3/src/su.c.orig 2002-10-19 09:54:05.000000000 +0200 ++++ shadow-4.0.3/src/su.c 2002-10-19 11:28:43.000000000 +0200 +@@ -252,6 +252,14 @@ + */ + if ((cp = getenv ("TERM"))) + addenv ("TERM", cp); ++ /* ++ * Also leave DISPLAY and XAUTHORITY if present, else ++ * pam_xauth will not work. ++ */ ++ if ((cp = getenv ("DISPLAY"))) ++ addenv ("DISPLAY", cp); ++ if ((cp = getenv ("XAUTHORITY"))) ++ addenv ("XAUTHORITY", cp); + } else { + while (*envp) + addenv (*envp++, NULL); +@@ -507,7 +515,10 @@ + } + #endif + ++/* setup the environment for pam later on, else we run into auth problems */ ++#ifndef USE_PAM + environ = newenvp; /* make new environment active */ ++#endif + + if (getenv ("IFS")) /* don't export user IFS ... */ + addenv ("IFS= \t\n", NULL); /* ... instead, set a safe IFS */ +@@ -555,6 +566,22 @@ + exit (1); + } + ++ ret = pam_open_session (pamh, 0); ++ if (ret != PAM_SUCCESS) { ++ SYSLOG ((LOG_ERR, "pam_open_session: %s", ++ pam_strerror (pamh, ret))); ++ fprintf (stderr, "%s: %s\n", Prog, ++ pam_strerror (pamh, ret)); ++ pam_end (pamh, ret); ++ exit (1); ++ } ++ ++ /* we need to setup the environment *after* pam_open_session(), ++ * else the UID is changed before stuff like pam_xauth could ++ * run, and we cannot access /etc/shadow and co ++ */ ++ environ = newenvp; /* make new environment active */ ++ + /* become the new user */ + if (change_uid (&pwent)) { + pam_setcred (pamh, PAM_DELETE_CRED); diff --git a/sys-apps/shadow/shadow-4.0.3-r1.ebuild b/sys-apps/shadow/shadow-4.0.3-r1.ebuild new file mode 100644 index 000000000000..84a59d0b9d17 --- /dev/null +++ b/sys-apps/shadow/shadow-4.0.3-r1.ebuild @@ -0,0 +1,158 @@ +# Copyright 1999-2002 Gentoo Technologies, Inc. +# Distributed under the terms of the GNU General Public License v2 +# $Header: /var/cvsroot/gentoo-x86/sys-apps/shadow/shadow-4.0.3-r1.ebuild,v 1.1 2002/10/19 09:31:05 azarah Exp $ + +inherit libtool + +S="${WORKDIR}/${P}" +HOMEPAGE="http://shadow.pld.org.pl/" +DESCRIPTION="Utilities to deal with user accounts" +SRC_URI="ftp://ftp.pld.org.pl/software/shadow/${P}.tar.gz" + +LICENSE="BSD" +SLOT="0" +KEYWORDS="~x86 ~ppc ~sparc ~sparc64 ~alpha" + +DEPEND=">=sys-libs/pam-0.75-r4 + >=sys-libs/cracklib-2.7-r3 + sys-devel/gettext" + +RDEPEND=">=sys-libs/pam-0.75-r4 + >=sys-libs/cracklib-2.7-r3" + + +pkg_preinst() { + rm -f ${ROOT}/etc/pam.d/system-auth.new +} + +src_unpack() { + unpack ${A} + + # Get su to call pam_open_session(), and also set DISPLAY and XAUTHORITY, + # else the session entries in /etc/pam.d/su never get executed, and + # pam_xauth for one, is then never used. This should close bug #8831. + # + # (19 Oct 2002) + cd ${S}; patch -p1 < ${FILESDIR}/${P}-su-pam_open_session.patch || die +} + +src_compile() { + elibtoolize + + local myconf="" + use nls || myconf="${myconf} --disable-nls" + + ./configure --disable-desrpc \ + --with-libcrypt \ + --with-libcrack \ + --with-libpam \ + --enable-shared=no \ + --enable-static=yes \ + --host=${CHOST} \ + ${myconf} || die "bad configure" + + # Parallel make fails sometimes + make || die "compile problem" +} + +src_install() { + dodir /etc/default /etc/skel + + make prefix=${D}/usr \ + exec_prefix=${D} \ + mandir=${D}/usr/share/man \ + install || die "install problem" + + #do not install this login, but rather the one from + #util-linux, as this one have a serious root exploit + #with pam_limits in use. + rm ${D}/bin/login + + mv ${D}/lib ${D}/usr + dosed "s:/lib':/usr/lib':g" /usr/lib/libshadow.la + dosed "s:/lib/:/usr/lib/:g" /usr/lib/libshadow.la + dosed "s:/lib':/usr/lib':g" /usr/lib/libmisc.la + dosed "s:/lib/:/usr/lib/:g" /usr/lib/libmisc.la + dosym /usr/bin/newgrp /usr/bin/sg + dosym /usr/sbin/useradd /usr/sbin/adduser + dosym /usr/sbin/vipw /usr/sbin/vigr + # remove dead links + rm -f ${D}/bin/{sg,vipw} + + insinto /etc + # Using a securetty with devfs device names added + # (compat names kept for non-devfs compatibility) + insopts -m0600 ; doins ${FILESDIR}/securetty + insopts -m0600 ; doins ${S}/etc/login.access + insopts -m0644 ; doins ${S}/etc/limits + + # needed for 'adduser -D' + keepdir /etc/default + +# From sys-apps/pam-login now +# insopts -m0644 ; doins ${FILESDIR}/login.defs + insinto /etc/pam.d ; insopts -m0644 + cd ${FILESDIR}/pam.d + doins * + newins system-auth system-auth.new + newins shadow chage + newins shadow chsh + newins shadow chfn + newins shadow useradd + newins shadow groupadd + cd ${S} + + # the manpage install is beyond my comprehension, and also broken. + # just do it over. + rm -rf ${D}/usr/share/man/* + for q in man/*.[0-9] + do + local dir="${D}/usr/share/man/man${q##*.}" + mkdir -p $dir + cp $q $dir + done + + #dont install the manpage, since we dont use + #login with shadow + rm ${D}/usr/share/man/man1/login.* + + cd ${S}/doc + dodoc ANNOUNCE INSTALL LICENSE README WISHLIST + docinto txt + dodoc HOWTO LSM README.* *.txt + + # Fix sparc serial console + if [ "${ARCH}" == "sparc" -o "${ARCH}" == "sparc64" ]; then + cd ${D}/etc + cp securetty securetty.orig + # ttyS0 and its devfsd counterpart (Sparc serial port "A") + sed -e 's:\(vc/1\)$:tts/0\n\1:' \ + -e 's:\(tty1\)$:ttyS0\n\1:' \ + securetty.orig > securetty || die + rm securetty.orig + fi +} + +pkg_postinst() { + echo + echo "****************************************************" + echo " Due to a security issue, ${ROOT}etc/pam.d/system-auth " + echo " is being updated automatically. Your old " + echo " system-auth will be backed up as:" + echo " ${ROOT}etc/pam.d/system-auth.bak" + echo "****************************************************" + echo + local CHECK1=`md5sum ${ROOT}/etc/pam.d/system-auth | cut -d ' ' -f 1` + local CHECK2=`md5sum ${ROOT}/etc/pam.d/system-auth.new | cut -d ' ' -f 1` + + if [ "$CHECK1" != "$CHECK2" ]; + then + cp -a ${ROOT}/etc/pam.d/system-auth \ + ${ROOT}/etc/pam.d/system-auth.bak; + mv -f ${ROOT}/etc/pam.d/system-auth.new \ + ${ROOT}/etc/pam.d/system-auth + else + rm -f ${ROOT}/etc/pam.d/system-auth.new + fi +} +