Blame SOURCES/0040-SUDO-Run-the-sudo-responder-as-the-SSSD-user.patch

905b4d
From 88b6f5da86301ac3f76cacdc99d7ab5045a5a3a6 Mon Sep 17 00:00:00 2001
905b4d
From: Jakub Hrozek <jhrozek@redhat.com>
905b4d
Date: Fri, 17 Oct 2014 18:14:45 +0200
905b4d
Subject: [PATCH 40/46] SUDO: Run the sudo responder as the SSSD user
905b4d
905b4d
Reviewed-by: Pavel Reichl <preichl@redhat.com>
905b4d
Reviewed-by: Simo Sorce <simo@redhat.com>
905b4d
(cherry picked from commit 3f9e2c24dbc14b2eafbe4f5a5ee16fe9af3c3f75)
905b4d
---
905b4d
 src/monitor/monitor.c        | 3 ++-
905b4d
 src/responder/sudo/sudosrv.c | 2 +-
905b4d
 2 files changed, 3 insertions(+), 2 deletions(-)
905b4d
905b4d
diff --git a/src/monitor/monitor.c b/src/monitor/monitor.c
905b4d
index 61a9f0b849a460da88b393b4f08795fb7a571886..d09aeba9033ff1460f9d4a6c51f35edbf2e67fa6 100644
905b4d
--- a/src/monitor/monitor.c
905b4d
+++ b/src/monitor/monitor.c
905b4d
@@ -1065,7 +1065,8 @@ static bool svc_supported_as_nonroot(const char *svc_name)
905b4d
     if ((strcmp(svc_name, "nss") == 0)
905b4d
         || (strcmp(svc_name, "pam") == 0)
905b4d
         || (strcmp(svc_name, "autofs") == 0)
905b4d
-        || (strcmp(svc_name, "pac") == 0)) {
905b4d
+        || (strcmp(svc_name, "pac") == 0)
905b4d
+        || (strcmp(svc_name, "sudo") == 0)) {
905b4d
         return true;
905b4d
     }
905b4d
     return false;
905b4d
diff --git a/src/responder/sudo/sudosrv.c b/src/responder/sudo/sudosrv.c
905b4d
index 038e3fd7da0829ce554a31694725c3dddaf5c038..a25f98ecabaa952a7cd87c54cd302903cb563faf 100644
905b4d
--- a/src/responder/sudo/sudosrv.c
905b4d
+++ b/src/responder/sudo/sudosrv.c
905b4d
@@ -195,7 +195,7 @@ int main(int argc, const char *argv[])
905b4d
     /* set up things like debug, signals, daemonization, etc... */
905b4d
     debug_log_file = "sssd_sudo";
905b4d
 
905b4d
-    ret = server_setup("sssd[sudo]", 0, 0, 0, CONFDB_SUDO_CONF_ENTRY,
905b4d
+    ret = server_setup("sssd[sudo]", 0, uid, gid, CONFDB_SUDO_CONF_ENTRY,
905b4d
                        &main_ctx);
905b4d
     if (ret != EOK) {
905b4d
         return 2;
905b4d
-- 
905b4d
1.9.3
905b4d