Fix regression in PAM groups handling

Commit 991770cc5d re-introduced
a problem which was earler fixed in
4183d8ddbf. This commit fixes the
regression so that pam_group.so on Linux now works again.

(cherry picked from commit c2b3cc6fc27c8c354ec39eac016cceb05430370d)
This commit is contained in:
matt335672
2025-08-25 13:16:31 +01:00
parent b1fffbc9ab
commit 4ae0cb75b9
+13 -13
View File
@@ -680,6 +680,19 @@ session_start_wrapped(struct login_info *login_info,
int window_manager_pid; int window_manager_pid;
enum scp_screate_status status = E_SCP_SCREATE_GENERAL_ERROR; enum scp_screate_status status = E_SCP_SCREATE_GENERAL_ERROR;
/* Set the secondary groups before starting the session to prevent
* problems on PAM-based systems (see Linux pam_setcred(3)).
* If we have *BSD setusercontext() this is not done here */
#ifndef HAVE_SETUSERCONTEXT
if (g_initgroups(login_info->username) != 0)
{
LOG(LOG_LEVEL_ERROR,
"Failed to initialise secondary groups for %s: %s",
login_info->username, g_get_strerror());
return E_SCP_SCREATE_GENERAL_ERROR;
}
#endif
if (auth_start_session(login_info->auth_info, s->display) != 0) if (auth_start_session(login_info->auth_info, s->display) != 0)
{ {
// Errors are logged by the auth module, as they are // Errors are logged by the auth module, as they are
@@ -706,19 +719,6 @@ session_start_wrapped(struct login_info *login_info,
} }
#endif #endif
/* Set the secondary groups before starting the session to prevent
* problems on PAM-based systems (see Linux pam_setcred(3)).
* If we have *BSD setusercontext() this is not done here */
#ifndef HAVE_SETUSERCONTEXT
if (g_initgroups(login_info->username) != 0)
{
LOG(LOG_LEVEL_ERROR,
"Failed to initialise secondary groups for %s: %s",
login_info->username, g_get_strerror());
return E_SCP_SCREATE_GENERAL_ERROR;
}
#endif
/* start the X server in a new process group. /* start the X server in a new process group.
* *
* We group the X server, window manager and chansrv in a single * We group the X server, window manager and chansrv in a single