|
|
b51b82 |
diff -up Linux-PAM-1.3.1/modules/pam_keyinit/pam_keyinit.c.pam_keyinit-thread-safe Linux-PAM-1.3.1/modules/pam_keyinit/pam_keyinit.c
|
|
|
b51b82 |
--- Linux-PAM-1.3.1/modules/pam_keyinit/pam_keyinit.c.pam_keyinit-thread-safe 2017-02-10 11:10:15.000000000 +0100
|
|
|
b51b82 |
+++ Linux-PAM-1.3.1/modules/pam_keyinit/pam_keyinit.c 2022-04-25 12:10:28.071240439 +0200
|
|
|
b51b82 |
@@ -20,6 +20,7 @@
|
|
|
b51b82 |
#include <security/pam_modutil.h>
|
|
|
b51b82 |
#include <security/pam_ext.h>
|
|
|
b51b82 |
#include <sys/syscall.h>
|
|
|
b51b82 |
+#include <stdatomic.h>
|
|
|
b51b82 |
|
|
|
b51b82 |
#define KEY_SPEC_SESSION_KEYRING -3 /* ID for session keyring */
|
|
|
b51b82 |
#define KEY_SPEC_USER_KEYRING -4 /* ID for UID-specific keyring */
|
|
|
b51b82 |
@@ -30,12 +31,12 @@
|
|
|
b51b82 |
#define KEYCTL_REVOKE 3 /* revoke a key */
|
|
|
b51b82 |
#define KEYCTL_LINK 8 /* link a key into a keyring */
|
|
|
b51b82 |
|
|
|
b51b82 |
-static int my_session_keyring;
|
|
|
b51b82 |
-static int session_counter;
|
|
|
b51b82 |
-static int do_revoke;
|
|
|
b51b82 |
-static int revoke_as_uid;
|
|
|
b51b82 |
-static int revoke_as_gid;
|
|
|
b51b82 |
-static int xdebug = 0;
|
|
|
b51b82 |
+static _Thread_local int my_session_keyring = 0;
|
|
|
b51b82 |
+static _Atomic int session_counter = 0;
|
|
|
b51b82 |
+static _Thread_local int do_revoke = 0;
|
|
|
b51b82 |
+static _Thread_local uid_t revoke_as_uid;
|
|
|
b51b82 |
+static _Thread_local gid_t revoke_as_gid;
|
|
|
b51b82 |
+static _Thread_local int xdebug = 0;
|
|
|
b51b82 |
|
|
|
b51b82 |
static void debug(pam_handle_t *pamh, const char *fmt, ...)
|
|
|
b51b82 |
__attribute__((format(printf, 2, 3)));
|
|
|
b51b82 |
@@ -65,6 +66,33 @@ static int error(pam_handle_t *pamh, con
|
|
|
b51b82 |
return PAM_SESSION_ERR;
|
|
|
b51b82 |
}
|
|
|
b51b82 |
|
|
|
b51b82 |
+static int pam_setreuid(uid_t ruid, uid_t euid)
|
|
|
b51b82 |
+{
|
|
|
b51b82 |
+#if defined(SYS_setreuid32)
|
|
|
b51b82 |
+ return syscall(SYS_setreuid32, ruid, euid);
|
|
|
b51b82 |
+#else
|
|
|
b51b82 |
+ return syscall(SYS_setreuid, ruid, euid);
|
|
|
b51b82 |
+#endif
|
|
|
b51b82 |
+}
|
|
|
b51b82 |
+
|
|
|
b51b82 |
+static int pam_setregid(gid_t rgid, gid_t egid)
|
|
|
b51b82 |
+{
|
|
|
b51b82 |
+#if defined(SYS_setregid32)
|
|
|
b51b82 |
+ return syscall(SYS_setregid32, rgid, egid);
|
|
|
b51b82 |
+#else
|
|
|
b51b82 |
+ return syscall(SYS_setregid, rgid, egid);
|
|
|
b51b82 |
+#endif
|
|
|
b51b82 |
+}
|
|
|
b51b82 |
+
|
|
|
b51b82 |
+static int pam_setresuid(uid_t ruid, uid_t euid, uid_t suid)
|
|
|
b51b82 |
+{
|
|
|
b51b82 |
+#if defined(SYS_setresuid32)
|
|
|
b51b82 |
+ return syscall(SYS_setresuid32, ruid, euid, suid);
|
|
|
b51b82 |
+#else
|
|
|
b51b82 |
+ return syscall(SYS_setresuid, ruid, euid, suid);
|
|
|
b51b82 |
+#endif
|
|
|
b51b82 |
+}
|
|
|
b51b82 |
+
|
|
|
b51b82 |
/*
|
|
|
b51b82 |
* initialise the session keyring for this process
|
|
|
b51b82 |
*/
|
|
|
b51b82 |
@@ -139,23 +167,25 @@ static void kill_keyrings(pam_handle_t *
|
|
|
b51b82 |
|
|
|
b51b82 |
/* switch to the real UID and GID so that we have permission to
|
|
|
b51b82 |
* revoke the key */
|
|
|
b51b82 |
- if (revoke_as_gid != old_gid && setregid(-1, revoke_as_gid) < 0)
|
|
|
b51b82 |
+ if (revoke_as_gid != old_gid && pam_setregid(-1, revoke_as_gid) < 0)
|
|
|
b51b82 |
error(pamh, "Unable to change GID to %d temporarily\n",
|
|
|
b51b82 |
revoke_as_gid);
|
|
|
b51b82 |
|
|
|
b51b82 |
- if (revoke_as_uid != old_uid && setresuid(-1, revoke_as_uid, old_uid) < 0)
|
|
|
b51b82 |
+ if (revoke_as_uid != old_uid && pam_setresuid(-1, revoke_as_uid, old_uid) < 0)
|
|
|
b51b82 |
error(pamh, "Unable to change UID to %d temporarily\n",
|
|
|
b51b82 |
revoke_as_uid);
|
|
|
b51b82 |
+ if (getegid() != old_gid && pam_setregid(-1, old_gid) < 0)
|
|
|
b51b82 |
+ error(pamh, "Unable to change GID back to %d\n", old_gid);
|
|
|
b51b82 |
|
|
|
b51b82 |
syscall(__NR_keyctl,
|
|
|
b51b82 |
KEYCTL_REVOKE,
|
|
|
b51b82 |
my_session_keyring);
|
|
|
b51b82 |
|
|
|
b51b82 |
/* return to the orignal UID and GID (probably root) */
|
|
|
b51b82 |
- if (revoke_as_uid != old_uid && setreuid(-1, old_uid) < 0)
|
|
|
b51b82 |
+ if (revoke_as_uid != old_uid && pam_setreuid(-1, old_uid) < 0)
|
|
|
b51b82 |
error(pamh, "Unable to change UID back to %d\n", old_uid);
|
|
|
b51b82 |
|
|
|
b51b82 |
- if (revoke_as_gid != old_gid && setregid(-1, old_gid) < 0)
|
|
|
b51b82 |
+ if (revoke_as_gid != old_gid && pam_setregid(-1, old_gid) < 0)
|
|
|
b51b82 |
error(pamh, "Unable to change GID back to %d\n", old_gid);
|
|
|
b51b82 |
|
|
|
b51b82 |
my_session_keyring = 0;
|
|
|
b51b82 |
@@ -210,14 +240,14 @@ int pam_sm_open_session(pam_handle_t *pa
|
|
|
b51b82 |
|
|
|
b51b82 |
/* switch to the real UID and GID so that the keyring ends up owned by
|
|
|
b51b82 |
* the right user */
|
|
|
b51b82 |
- if (gid != old_gid && setregid(gid, -1) < 0) {
|
|
|
b51b82 |
+ if (gid != old_gid && pam_setregid(gid, -1) < 0) {
|
|
|
b51b82 |
error(pamh, "Unable to change GID to %d temporarily\n", gid);
|
|
|
b51b82 |
return PAM_SESSION_ERR;
|
|
|
b51b82 |
}
|
|
|
b51b82 |
|
|
|
b51b82 |
- if (uid != old_uid && setreuid(uid, -1) < 0) {
|
|
|
b51b82 |
+ if (uid != old_uid && pam_setreuid(uid, -1) < 0) {
|
|
|
b51b82 |
error(pamh, "Unable to change UID to %d temporarily\n", uid);
|
|
|
b51b82 |
- if (setregid(old_gid, -1) < 0)
|
|
|
b51b82 |
+ if (pam_setregid(old_gid, -1) < 0)
|
|
|
b51b82 |
error(pamh, "Unable to change GID back to %d\n", old_gid);
|
|
|
b51b82 |
return PAM_SESSION_ERR;
|
|
|
b51b82 |
}
|
|
|
b51b82 |
@@ -225,10 +255,10 @@ int pam_sm_open_session(pam_handle_t *pa
|
|
|
b51b82 |
ret = init_keyrings(pamh, force);
|
|
|
b51b82 |
|
|
|
b51b82 |
/* return to the orignal UID and GID (probably root) */
|
|
|
b51b82 |
- if (uid != old_uid && setreuid(old_uid, -1) < 0)
|
|
|
b51b82 |
+ if (uid != old_uid && pam_setreuid(old_uid, -1) < 0)
|
|
|
b51b82 |
ret = error(pamh, "Unable to change UID back to %d\n", old_uid);
|
|
|
b51b82 |
|
|
|
b51b82 |
- if (gid != old_gid && setregid(old_gid, -1) < 0)
|
|
|
b51b82 |
+ if (gid != old_gid && pam_setregid(old_gid, -1) < 0)
|
|
|
b51b82 |
ret = error(pamh, "Unable to change GID back to %d\n", old_gid);
|
|
|
b51b82 |
|
|
|
b51b82 |
return ret;
|