teknoraver / rpms / systemd

Forked from rpms/systemd 2 months ago
Clone

Blame SOURCES/0857-pam-add-a-call-to-pam_namespace.patch

6f381c
From b1b7aaf83414c5b0bed6e61d38aefe29a21fdbcf Mon Sep 17 00:00:00 2001
6f381c
From: =?UTF-8?q?Zbigniew=20J=C4=99drzejewski-Szmek?= <zbyszek@in.waw.pl>
6f381c
Date: Wed, 23 Nov 2022 16:09:56 +0100
6f381c
Subject: [PATCH] pam: add a call to pam_namespace
6f381c
6f381c
A call to pam_namespace is required so that children of user@.service end up in
6f381c
a namespace as expected. pam_namespace gets called as part of the stack that
6f381c
creates a session (login, sshd, gdm, etc.) and those processes end up in a
6f381c
namespace, but it also needs to be called from our stack which is parallel and
6f381c
descends from pid1 itself.
6f381c
6f381c
The call to pam_namespace is similar to the call to pam_keyinit that was added
6f381c
in ab79099d1684457d040ee7c28b2012e8c1ea9a4f. The pam stack for user@.service
6f381c
creates a new session which is disconnected from the parent environment. Both
6f381c
calls are not suitable for inclusion in the shared part of the stack (e.g.
6f381c
@system-auth on Fedora/RHEL systems), because for example su/sudo/runuser
6f381c
should not include them.
6f381c
6f381c
(cherry picked from commit 0ef48896d9f23b9fd547a532a4e6e6b8f8b12901)
6f381c
6f381c
Resolves: #1861836
6f381c
---
6f381c
 src/login/systemd-user.m4 | 1 +
6f381c
 1 file changed, 1 insertion(+)
6f381c
6f381c
diff --git a/src/login/systemd-user.m4 b/src/login/systemd-user.m4
6f381c
index 20c8999331..eb291beaed 100644
6f381c
--- a/src/login/systemd-user.m4
6f381c
+++ b/src/login/systemd-user.m4
6f381c
@@ -9,4 +9,5 @@ session required pam_selinux.so nottys open
6f381c
 )m4_dnl
6f381c
 session required pam_loginuid.so
6f381c
 session optional pam_keyinit.so force revoke
6f381c
+session required pam_namespace.so
6f381c
 session optional pam_systemd.so