Call g_set_allusercontext() on appropriate systems

This commit is contained in:
matt335672
2022-12-15 15:08:11 +00:00
parent 48e46d183a
commit a35082e6c5
2 changed files with 18 additions and 6 deletions
+14 -5
View File
@@ -117,9 +117,15 @@ env_set_user(int uid, char **passwd_file, int display,
if (error == 0)
{
g_rm_temp_dir();
/*
* Set the primary group. Note that secondary groups should already
* have been set */
g_clearenv();
#ifdef HAVE_SETUSERCONTEXT
error = g_set_allusercontext(uid);
#else
/* Set some of the things setusercontext() handles on other
* systems */
/* Primary group. Note that secondary groups should already
* have been set, if we're not using setusercontext() */
error = g_setgid(pw_gid);
if (error == 0)
@@ -127,13 +133,16 @@ env_set_user(int uid, char **passwd_file, int display,
error = g_setuid(uid);
}
if (error == 0)
{
g_setenv("PATH", "/sbin:/bin:/usr/bin:/usr/local/bin", 1);
}
#endif
g_mk_socket_path(0);
if (error == 0)
{
g_clearenv();
g_setenv("SHELL", pw_shell, 1);
g_setenv("PATH", "/sbin:/bin:/usr/bin:/usr/local/bin", 1);
g_setenv("USER", pw_username, 1);
g_setenv("LOGNAME", pw_username, 1);
g_sprintf(text, "%d", uid);
+4 -1
View File
@@ -582,7 +582,9 @@ session_start(struct auth_info *auth_info,
g_delete_wait_obj(g_term_event);
/* Set the secondary groups before starting the session to prevent
* problems on PAM-based systems (see pam_setcred(3)) */
* problems on PAM-based systems (see Linux pam_setcred(3)).
* If we have *BSD setusercontext() this is not done here */
#ifndef HAVE_SETUSERCONTEXT
if (g_initgroups(username) != 0)
{
LOG(LOG_LEVEL_ERROR,
@@ -590,6 +592,7 @@ session_start(struct auth_info *auth_info,
username, g_get_strerror());
g_exit(1);
}
#endif
sesman_close_all(0);
auth_start_session(auth_info, display);