From 4ae0cb75b93c5378b6fa31d4024463098a9a3289 Mon Sep 17 00:00:00 2001 From: matt335672 <30179339+matt335672@users.noreply.github.com> Date: Mon, 25 Aug 2025 13:16:31 +0100 Subject: [PATCH] Fix regression in PAM groups handling Commit 991770cc5df33ddaa7b24238ded84b63c809dc8b re-introduced a problem which was earler fixed in 4183d8ddbfd1399a1c7255f6de31298bea18655b. This commit fixes the regression so that pam_group.so on Linux now works again. (cherry picked from commit c2b3cc6fc27c8c354ec39eac016cceb05430370d) --- sesman/sesexec/session.c | 26 +++++++++++++------------- 1 file changed, 13 insertions(+), 13 deletions(-) diff --git a/sesman/sesexec/session.c b/sesman/sesexec/session.c index 93b9579d..c4249b7a 100644 --- a/sesman/sesexec/session.c +++ b/sesman/sesexec/session.c @@ -680,6 +680,19 @@ session_start_wrapped(struct login_info *login_info, int window_manager_pid; enum scp_screate_status status = E_SCP_SCREATE_GENERAL_ERROR; + /* Set the secondary groups before starting the session to prevent + * problems on PAM-based systems (see Linux pam_setcred(3)). + * If we have *BSD setusercontext() this is not done here */ +#ifndef HAVE_SETUSERCONTEXT + if (g_initgroups(login_info->username) != 0) + { + LOG(LOG_LEVEL_ERROR, + "Failed to initialise secondary groups for %s: %s", + login_info->username, g_get_strerror()); + return E_SCP_SCREATE_GENERAL_ERROR; + } +#endif + if (auth_start_session(login_info->auth_info, s->display) != 0) { // Errors are logged by the auth module, as they are @@ -706,19 +719,6 @@ session_start_wrapped(struct login_info *login_info, } #endif - /* Set the secondary groups before starting the session to prevent - * problems on PAM-based systems (see Linux pam_setcred(3)). - * If we have *BSD setusercontext() this is not done here */ -#ifndef HAVE_SETUSERCONTEXT - if (g_initgroups(login_info->username) != 0) - { - LOG(LOG_LEVEL_ERROR, - "Failed to initialise secondary groups for %s: %s", - login_info->username, g_get_strerror()); - return E_SCP_SCREATE_GENERAL_ERROR; - } -#endif - /* start the X server in a new process group. * * We group the X server, window manager and chansrv in a single