pam_rundir: patching issue 2/3

This commit is contained in:
Issam Maghni 2018-06-25 23:34:21 -04:00 committed by maxice8
parent 207bbf2184
commit 7cce72a8e3
2 changed files with 22 additions and 1 deletions

View file

@ -0,0 +1,21 @@
--- pam_rundir.c
+++ pam_rundir.c
@@ -24,6 +24,8 @@
#include <sys/types.h>
#include <sys/stat.h>
#include <sys/file.h>
+#include <sys/prctl.h>
+#include <linux/securebits.h>
#include <string.h>
#include <pwd.h>
#include <fcntl.h>
@@ -396,6 +398,9 @@ pam_sm_open_session (pam_handle_t *pamh, int flags, int argc, const char **argv)
goto done;
}
+ /* to bypass permission checks for mkdir, in case it isn't group
+ * writable */
+ prctl (PR_SET_SECUREBITS, SECBIT_NO_SETUID_FIXUP);
/* set euid so if we do create the dir, it is own by the user */
if (seteuid (pw->pw_uid) < 0)
{

View file

@ -1,7 +1,7 @@
# Template file for 'pam_rundir-1.0.0'
pkgname=pam_rundir
version=1.0.0
revision=1
revision=2
build_style=configure
configure_args="--prefix=/usr --with-parentdir=/run/user"
makedepends="pam-devel"