Call g_set_allusercontext() on appropriate systems
This commit is contained in:
+14
-5
@@ -117,9 +117,15 @@ env_set_user(int uid, char **passwd_file, int display,
|
||||
if (error == 0)
|
||||
{
|
||||
g_rm_temp_dir();
|
||||
/*
|
||||
* Set the primary group. Note that secondary groups should already
|
||||
* have been set */
|
||||
g_clearenv();
|
||||
#ifdef HAVE_SETUSERCONTEXT
|
||||
error = g_set_allusercontext(uid);
|
||||
#else
|
||||
/* Set some of the things setusercontext() handles on other
|
||||
* systems */
|
||||
|
||||
/* Primary group. Note that secondary groups should already
|
||||
* have been set, if we're not using setusercontext() */
|
||||
error = g_setgid(pw_gid);
|
||||
|
||||
if (error == 0)
|
||||
@@ -127,13 +133,16 @@ env_set_user(int uid, char **passwd_file, int display,
|
||||
error = g_setuid(uid);
|
||||
}
|
||||
|
||||
if (error == 0)
|
||||
{
|
||||
g_setenv("PATH", "/sbin:/bin:/usr/bin:/usr/local/bin", 1);
|
||||
}
|
||||
#endif
|
||||
g_mk_socket_path(0);
|
||||
|
||||
if (error == 0)
|
||||
{
|
||||
g_clearenv();
|
||||
g_setenv("SHELL", pw_shell, 1);
|
||||
g_setenv("PATH", "/sbin:/bin:/usr/bin:/usr/local/bin", 1);
|
||||
g_setenv("USER", pw_username, 1);
|
||||
g_setenv("LOGNAME", pw_username, 1);
|
||||
g_sprintf(text, "%d", uid);
|
||||
|
||||
+4
-1
@@ -582,7 +582,9 @@ session_start(struct auth_info *auth_info,
|
||||
g_delete_wait_obj(g_term_event);
|
||||
|
||||
/* Set the secondary groups before starting the session to prevent
|
||||
* problems on PAM-based systems (see pam_setcred(3)) */
|
||||
* problems on PAM-based systems (see Linux pam_setcred(3)).
|
||||
* If we have *BSD setusercontext() this is not done here */
|
||||
#ifndef HAVE_SETUSERCONTEXT
|
||||
if (g_initgroups(username) != 0)
|
||||
{
|
||||
LOG(LOG_LEVEL_ERROR,
|
||||
@@ -590,6 +592,7 @@ session_start(struct auth_info *auth_info,
|
||||
username, g_get_strerror());
|
||||
g_exit(1);
|
||||
}
|
||||
#endif
|
||||
|
||||
sesman_close_all(0);
|
||||
auth_start_session(auth_info, display);
|
||||
|
||||
Reference in New Issue
Block a user