Fix regression in PAM groups handling
Commit991770cc5dre-introduced a problem which was earler fixed in4183d8ddbf. This commit fixes the regression so that pam_group.so on Linux now works again. (cherry picked from commit c2b3cc6fc27c8c354ec39eac016cceb05430370d)
This commit is contained in:
+13
-13
@@ -680,6 +680,19 @@ session_start_wrapped(struct login_info *login_info,
|
||||
int window_manager_pid;
|
||||
enum scp_screate_status status = E_SCP_SCREATE_GENERAL_ERROR;
|
||||
|
||||
/* Set the secondary groups before starting the session to prevent
|
||||
* problems on PAM-based systems (see Linux pam_setcred(3)).
|
||||
* If we have *BSD setusercontext() this is not done here */
|
||||
#ifndef HAVE_SETUSERCONTEXT
|
||||
if (g_initgroups(login_info->username) != 0)
|
||||
{
|
||||
LOG(LOG_LEVEL_ERROR,
|
||||
"Failed to initialise secondary groups for %s: %s",
|
||||
login_info->username, g_get_strerror());
|
||||
return E_SCP_SCREATE_GENERAL_ERROR;
|
||||
}
|
||||
#endif
|
||||
|
||||
if (auth_start_session(login_info->auth_info, s->display) != 0)
|
||||
{
|
||||
// Errors are logged by the auth module, as they are
|
||||
@@ -706,19 +719,6 @@ session_start_wrapped(struct login_info *login_info,
|
||||
}
|
||||
#endif
|
||||
|
||||
/* Set the secondary groups before starting the session to prevent
|
||||
* problems on PAM-based systems (see Linux pam_setcred(3)).
|
||||
* If we have *BSD setusercontext() this is not done here */
|
||||
#ifndef HAVE_SETUSERCONTEXT
|
||||
if (g_initgroups(login_info->username) != 0)
|
||||
{
|
||||
LOG(LOG_LEVEL_ERROR,
|
||||
"Failed to initialise secondary groups for %s: %s",
|
||||
login_info->username, g_get_strerror());
|
||||
return E_SCP_SCREATE_GENERAL_ERROR;
|
||||
}
|
||||
#endif
|
||||
|
||||
/* start the X server in a new process group.
|
||||
*
|
||||
* We group the X server, window manager and chansrv in a single
|
||||
|
||||
Reference in New Issue
Block a user