Blame SOURCES/0011-Don-t-setfacl-when-the-socket-or-dir-aren-t-there.patch

b8b9f4
From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
664c67
From: Peter Jones <pjones@redhat.com>
664c67
Date: Fri, 20 Nov 2015 19:19:49 -0500
b8b9f4
Subject: [PATCH] Don't setfacl when the socket or dir aren't there.
664c67
664c67
Signed-off-by: Peter Jones <pjones@redhat.com>
664c67
(cherry picked from commit 4c70ae807156099bf027b57a94b7eae0a810b947)
664c67
---
664c67
 src/pesign-authorize-groups | 10 ++++++----
664c67
 src/pesign-authorize-users  | 10 ++++++----
664c67
 2 files changed, 12 insertions(+), 8 deletions(-)
664c67
664c67
diff --git a/src/pesign-authorize-groups b/src/pesign-authorize-groups
664c67
index 2236bea..2222809 100644
664c67
--- a/src/pesign-authorize-groups
664c67
+++ b/src/pesign-authorize-groups
664c67
@@ -11,9 +11,11 @@
664c67
 
664c67
 if [[ -r /etc/pesign/groups ]]; then
664c67
     for group in $(cat /etc/pesign/groups); do
664c67
-        setfacl -m g:${group}:rx /var/run/pesign
664c67
-        setfacl -m g:${group}:rw /var/run/pesign/socket
664c67
-        setfacl -m g:${username}:rx /etc/pki/pesign
664c67
-        setfacl -m g:${username}:r /etc/pki/pesign/{cert8,key3,secmod}.db
664c67
+	if [ -d /var/run/pesign ]; then
664c67
+	    setfacl -m g:${group}:rx /var/run/pesign
664c67
+	    if [ -e /var/run/pesign/socket ]; then
664c67
+		setfacl -m g:${group}:rw /var/run/pesign/socket
664c67
+	    fi
664c67
+	fi
664c67
     done
664c67
 fi
664c67
diff --git a/src/pesign-authorize-users b/src/pesign-authorize-users
664c67
index 9c38a25..22bddec 100644
664c67
--- a/src/pesign-authorize-users
664c67
+++ b/src/pesign-authorize-users
664c67
@@ -11,9 +11,11 @@
664c67
 
664c67
 if [[ -r /etc/pesign/users ]]; then
664c67
     for username in $(cat /etc/pesign/users); do
664c67
-        setfacl -m u:${username}:rx /var/run/pesign
664c67
-        setfacl -m u:${username}:rw /var/run/pesign/socket
664c67
-        setfacl -m u:${username}:rx /etc/pki/pesign
664c67
-        setfacl -m u:${username}:r /etc/pki/pesign/{cert8,key3,secmod}.db
664c67
+	if [ -d /var/run/pesign ]; then
664c67
+	    setfacl -m g:${username}:rx /var/run/pesign
664c67
+	    if [ -e /var/run/pesign/socket ]; then
664c67
+		setfacl -m g:${username}:rw /var/run/pesign/socket
664c67
+	    fi
664c67
+	fi
664c67
     done
664c67
 fi