Blame SOURCES/1008-ifcfg-rh-handle-802-1x-ca-path-cve-2020-10754.patch

e8bede
From 0da5e2e48c617f13e4583d72c2c5a72e4b6e299c Mon Sep 17 00:00:00 2001
e8bede
From: Thomas Haller <thaller@redhat.com>
e8bede
Date: Tue, 26 May 2020 15:26:04 +0200
e8bede
Subject: [PATCH 1/1] ifcfg-rh: fix handling "802-1x.{phase2-,}ca-path" in
e8bede
 ifcfg-rh settings plugin
e8bede
e8bede
https://bugzilla.redhat.com/show_bug.cgi?id=1840210
e8bede
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/issues/448
e8bede
(cherry picked from commit b6b6639c7c8fa667b8fcbc310b65d88124fdc260)
e8bede
(cherry picked from commit 67f1da27fe95fbe09999a953558a0b3e4dcfdd69)
e8bede
(cherry picked from commit 7a20dd4dbbd51081b598f4d42254190a03271471)
e8bede
---
e8bede
 src/settings/plugins/ifcfg-rh/nms-ifcfg-rh-reader.c | 8 ++++++++
e8bede
 src/settings/plugins/ifcfg-rh/nms-ifcfg-rh-writer.c | 5 +++++
e8bede
 2 files changed, 13 insertions(+)
e8bede
e8bede
diff --git a/src/settings/plugins/ifcfg-rh/nms-ifcfg-rh-reader.c b/src/settings/plugins/ifcfg-rh/nms-ifcfg-rh-reader.c
e8bede
index e01f7344cdfe..9cb21f92ac5b 100644
e8bede
--- a/src/settings/plugins/ifcfg-rh/nms-ifcfg-rh-reader.c
e8bede
+++ b/src/settings/plugins/ifcfg-rh/nms-ifcfg-rh-reader.c
e8bede
@@ -3626,6 +3626,14 @@ next:
e8bede
 	timeout = svGetValueInt64 (ifcfg, "IEEE_8021X_AUTH_TIMEOUT", 10, 0, G_MAXINT32, 0);
e8bede
 	g_object_set (s_8021x, NM_SETTING_802_1X_AUTH_TIMEOUT, (int) timeout, NULL);
e8bede
 
e8bede
+	nm_clear_g_free (&value);
e8bede
+	v = svGetValueStr (ifcfg, "IEEE_8021X_CA_PATH", &value);
e8bede
+	g_object_set (s_8021x, NM_SETTING_802_1X_CA_PATH, v, NULL);
e8bede
+
e8bede
+	nm_clear_g_free (&value);
e8bede
+	v = svGetValueStr (ifcfg, "IEEE_8021X_PHASE2_CA_PATH", &value);
e8bede
+	g_object_set (s_8021x, NM_SETTING_802_1X_PHASE2_CA_PATH, v, NULL);
e8bede
+
e8bede
 	g_object_set (s_8021x,
e8bede
 	              NM_SETTING_802_1X_OPTIONAL,
e8bede
 	              svGetValueBoolean (ifcfg, "IEEE_8021X_OPTIONAL", FALSE),
e8bede
diff --git a/src/settings/plugins/ifcfg-rh/nms-ifcfg-rh-writer.c b/src/settings/plugins/ifcfg-rh/nms-ifcfg-rh-writer.c
e8bede
index 90a1a2b8f6f9..3afdb2acd14d 100644
e8bede
--- a/src/settings/plugins/ifcfg-rh/nms-ifcfg-rh-writer.c
e8bede
+++ b/src/settings/plugins/ifcfg-rh/nms-ifcfg-rh-writer.c
e8bede
@@ -530,6 +530,11 @@ write_8021x_setting (NMConnection *connection,
e8bede
 	                             "IEEE_8021X_OPTIONAL",
e8bede
 	                             nm_setting_802_1x_get_optional (s_8021x));
e8bede
 
e8bede
+	svSetValue (ifcfg, "IEEE_8021X_CA_PATH",
e8bede
+	            nm_setting_802_1x_get_ca_path (s_8021x));
e8bede
+	svSetValue (ifcfg, "IEEE_8021X_PHASE2_CA_PATH",
e8bede
+	            nm_setting_802_1x_get_phase2_ca_path (s_8021x));
e8bede
+
e8bede
 	if (!write_8021x_certs (s_8021x, secrets, blobs, FALSE, ifcfg, error))
e8bede
 		return FALSE;
e8bede
 
e8bede
-- 
e8bede
2.26.2
e8bede