Blame SOURCES/0013-Improve-our-setfacl-scripts-for-database-and-socket-.patch

fe5aa1
From 9cd3272fc54f7941f347c4ec9e15176c2ed7da36 Mon Sep 17 00:00:00 2001
fe5aa1
From: Peter Jones <pjones@redhat.com>
fe5aa1
Date: Wed, 20 Apr 2016 11:44:08 -0400
fe5aa1
Subject: [PATCH 13/15] Improve our setfacl scripts for database and socket
fe5aa1
 ownership.
fe5aa1
fe5aa1
Signed-off-by: Peter Jones <pjones@redhat.com>
fe5aa1
(cherry picked from commit a90c967205733c35a97c0c3e67131fa9b5b935fc)
fe5aa1
---
fe5aa1
 src/pesign-authorize-groups | 15 ++++++++++-----
fe5aa1
 src/pesign-authorize-users  | 19 ++++++++++++-------
fe5aa1
 2 files changed, 22 insertions(+), 12 deletions(-)
fe5aa1
fe5aa1
diff --git a/src/pesign-authorize-groups b/src/pesign-authorize-groups
fe5aa1
index 13aefa6..a4f895e 100644
fe5aa1
--- a/src/pesign-authorize-groups
fe5aa1
+++ b/src/pesign-authorize-groups
fe5aa1
@@ -1,4 +1,5 @@
fe5aa1
 #!/bin/bash
fe5aa1
+set -e
fe5aa1
 
fe5aa1
 #
fe5aa1
 # With /run/pesign/socket on tmpfs, a simple way of restoring the
fe5aa1
@@ -9,7 +10,7 @@
fe5aa1
 
fe5aa1
 # License: GPLv2
fe5aa1
 
fe5aa1
-if [[ -r /etc/pesign/groups ]]; then
fe5aa1
+if [ -r /etc/pesign/groups ]; then
fe5aa1
     for group in $(cat /etc/pesign/groups); do
fe5aa1
 	if [ -d /var/run/pesign ]; then
fe5aa1
 	    setfacl -m g:${group}:rx /var/run/pesign
fe5aa1
@@ -17,9 +18,13 @@ if [[ -r /etc/pesign/groups ]]; then
fe5aa1
 		setfacl -m g:${group}:rw /var/run/pesign/socket
fe5aa1
 	    fi
fe5aa1
 	fi
fe5aa1
-	if [ -d /etc/pki/pesign ]; then
fe5aa1
-	    setfacl -m g:${group}:rx /etc/pki/pesign
fe5aa1
-	    setfacl -m g:${group}:r /etc/pki/pesign/{cert8,key3,secmod}.db
fe5aa1
-	fi
fe5aa1
+	for x in /etc/pki/pesign* ; do
fe5aa1
+	    if [ -d ${x} ]; then
fe5aa1
+		setfacl -m g:${group}:rx /etc/pki/pesign
fe5aa1
+		for y in ${x}/{cert8,key3,secmod}.db ; do
fe5aa1
+		    setfacl -m g:${group}:rw ${y}
fe5aa1
+		done
fe5aa1
+	    fi
fe5aa1
+	done
fe5aa1
     done
fe5aa1
 fi
fe5aa1
diff --git a/src/pesign-authorize-users b/src/pesign-authorize-users
fe5aa1
index a43ce44..8b9a885 100644
fe5aa1
--- a/src/pesign-authorize-users
fe5aa1
+++ b/src/pesign-authorize-users
fe5aa1
@@ -1,4 +1,5 @@
fe5aa1
 #!/bin/bash
fe5aa1
+set -e
fe5aa1
 
fe5aa1
 #
fe5aa1
 # With /run/pesign/socket on tmpfs, a simple way of restoring the
fe5aa1
@@ -9,17 +10,21 @@
fe5aa1
 
fe5aa1
 # License: GPLv2
fe5aa1
 
fe5aa1
-if [[ -r /etc/pesign/users ]]; then
fe5aa1
+if [ -r /etc/pesign/users ]; then
fe5aa1
     for username in $(cat /etc/pesign/users); do
fe5aa1
 	if [ -d /var/run/pesign ]; then
fe5aa1
-	    setfacl -m u:${username}:rx /var/run/pesign
fe5aa1
+	    setfacl -m g:${username}:rx /var/run/pesign
fe5aa1
 	    if [ -e /var/run/pesign/socket ]; then
fe5aa1
-		setfacl -m u:${username}:rw /var/run/pesign/socket
fe5aa1
+		setfacl -m g:${username}:rw /var/run/pesign/socket
fe5aa1
 	    fi
fe5aa1
 	fi
fe5aa1
-	if [ -d /etc/pki/pesign ]; then
fe5aa1
-	    setfacl -m u:${username}:rx /etc/pki/pesign
fe5aa1
-	    setfacl -m u:${username}:r /etc/pki/pesign/{cert8,key3,secmod}.db
fe5aa1
-	fi
fe5aa1
+	for x in /etc/pki/pesign* ; do
fe5aa1
+	    if [ -d ${x} ]; then
fe5aa1
+		setfacl -m g:${username}:rx /etc/pki/pesign
fe5aa1
+		for y in ${x}/{cert8,key3,secmod}.db ; do
fe5aa1
+		    setfacl -m g:${username}:rw ${y}
fe5aa1
+		done
fe5aa1
+	    fi
fe5aa1
+	done
fe5aa1
     done
fe5aa1
 fi
fe5aa1
-- 
fe5aa1
2.5.5
fe5aa1