diff --git a/.gitignore b/.gitignore index cf05f91..0e2dc37 100644 --- a/.gitignore +++ b/.gitignore @@ -2,3 +2,11 @@ usermode-1.105.tar.xz /usermode-1.106.tar.xz /usermode-1.106.1.tar.xz /usermode-1.107.tar.xz +/usermode-1.108.tar.xz +/usermode-1.109.tar.xz +/usermode-1.110.tar.xz +/usermode-1.111.tar.xz +/usermode-1.112.tar.xz +/usermode-1.112.autotoolized.tar.xz +/usermode-1.113.tar.xz +/usermode-1.114.tar.xz diff --git a/fix-sast.patch b/fix-sast.patch new file mode 100644 index 0000000..755ff3e --- /dev/null +++ b/fix-sast.patch @@ -0,0 +1,36 @@ +diff --git a/gsmclient.c b/gsmclient.c +index fb93a5c..93e9a64 100644 +--- a/gsmclient.c ++++ b/gsmclient.c +@@ -182,6 +182,7 @@ gsm_client_init (GsmClient *client, gpointer data) + char pid_str[64]; + int empty_vector_len = 0; + char *empty_vector[] = { NULL }; ++ gchar *curdir; + + (void)data; + client->priv = g_new (GsmClientPrivate, 1); +@@ -197,8 +198,10 @@ gsm_client_init (GsmClient *client, gpointer data) + /* Default property values (this code assumes we start + * with an empty proplist) + */ ++ curdir = g_get_current_dir (); + push_prop (client, smprop_new_string (GSM_CLIENT_PROPERTY_CURRENT_DIRECTORY, +- g_get_current_dir (), -1)); ++ curdir, -1)); ++ g_free(curdir); + + g_snprintf (pid_str, sizeof (pid_str), "%d", (int) getpid ()); + push_prop (client, smprop_new_string (GSM_CLIENT_PROPERTY_PROCESS_ID, +diff --git a/shvar.c b/shvar.c +index 0e199c6..62723db 100644 +--- a/shvar.c ++++ b/shvar.c +@@ -348,6 +348,7 @@ svSetValue(shvarFile *s, const char *key, const char *value) + s->modified = 1; + goto bail; /* do not need keyValue */ + } ++ else goto bail; + goto end; + } + diff --git a/sources b/sources index 6ef84ec..5065b51 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -00a53086a5716106585fe0234f1030d3 usermode-1.107.tar.xz +SHA512 (usermode-1.114.tar.xz) = 703eb218704c7a11cdce25a71f4fc91bf4f042a8b185f79f3954699081c0db8a6234ad6f11738d8b2fe6a492a03d029cbe01762a47869edc473e4fbaa6e0ee32 diff --git a/usermode.spec b/usermode.spec index 415ae3b..048552f 100644 --- a/usermode.spec +++ b/usermode.spec @@ -1,28 +1,45 @@ +# Add `--without gtk' option (enable gtk by default): +# No GTK 2 in RHEL 10 +%if 0%{?rhel} > 9 +%bcond_with gtk +%else +%bcond_without gtk +%endif + Summary: Tools for certain user account management tasks Name: usermode -Version: 1.107 -Release: 1%{?dist} -License: GPLv2+ -Group: Applications/System -URL: https://fedorahosted.org/usermode/ -Source: https://fedorahosted.org/releases/u/s/usermode/usermode-%{version}.tar.xz +Version: 1.114 +Release: 17%{?dist} +License: GPL-2.0-or-later +URL: https://pagure.io/%{name}/ +Source: https://releases.pagure.org/%{name}/%{name}-%{version}.tar.xz Source1: config-util +Patch1: fix-sast.patch Requires: pam, passwd, util-linux -BuildRequires: desktop-file-utils, gettext, glib2-devel, gtk2-devel, intltool -BuildRequires: libblkid-devel, libSM-devel, libselinux-devel, libuser-devel -BuildRequires: pam-devel, perl-XML-Parser, startup-notification-devel -BuildRequires: util-linux +# https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org/thread/IJFYI5Q2BYZKIGDFS2WLOBDUSEGWHIKV/ +BuildRequires: make +BuildRequires: gcc +BuildRequires: gettext, glib2-devel, intltool +%if %{with gtk} +BuildRequires: desktop-file-utils, gtk2-devel, startup-notification-devel, libSM-devel +%endif +BuildRequires: libblkid-devel, libselinux-devel, libuser-devel +BuildRequires: pam-devel, perl-XML-Parser +%if %{with gtk} %package gtk Summary: Graphical tools for certain user account management tasks -Group: Applications/System Requires: %{name} = %{version}-%{release} +%endif + +%global _hardened_build 1 %description The usermode package contains the userhelper program, which can be used to allow configured programs to be run with superuser privileges by ordinary users. +%if %{with gtk} %description gtk The usermode-gtk package contains several graphical tools for users: userinfo, usermount and userpasswd. Userinfo allows users to change @@ -32,34 +49,31 @@ passwords. Install the usermode-gtk package if you would like to provide users with graphical tools for certain account management tasks. +%endif %prep %setup -q +%patch -P 1 -p 1 %build -%configure --with-selinux +%configure --with-selinux --without-fexecve %{!?with_gtk:--without-gtk} -make %{?_smp_mflags} +%make_build %install -make install DESTDIR=$RPM_BUILD_ROOT INSTALL='install -p' +%make_install +%if %{with gtk} # make userformat symlink to usermount ln -sf usermount $RPM_BUILD_ROOT%{_bindir}/userformat ln -s usermount.1 $RPM_BUILD_ROOT%{_mandir}/man1/userformat.1 +%endif -# We set up the shutdown programs to be wrapped in this package. Other -# packages are on their own.... -mkdir -p $RPM_BUILD_ROOT/etc/pam.d $RPM_BUILD_ROOT/etc/security/console.apps -for wrappedapp in halt reboot poweroff ; do - ln -s consolehelper $RPM_BUILD_ROOT%{_bindir}/${wrappedapp} - install -p -m644 $wrappedapp \ - $RPM_BUILD_ROOT/etc/security/console.apps/${wrappedapp} - install -p -m644 shutdown.pamd $RPM_BUILD_ROOT/etc/pam.d/${wrappedapp} -done +mkdir -p $RPM_BUILD_ROOT/etc/security/console.apps install -p -m 644 %{SOURCE1} \ $RPM_BUILD_ROOT/etc/security/console.apps/config-util +%if %{with gtk} for i in redhat-userinfo.desktop redhat-userpasswd.desktop \ redhat-usermount.desktop; do echo 'NotShowIn=GNOME;KDE;' >>$RPM_BUILD_ROOT%{_datadir}/applications/$i @@ -67,34 +81,22 @@ for i in redhat-userinfo.desktop redhat-userpasswd.desktop \ --dir $RPM_BUILD_ROOT%{_datadir}/applications \ $RPM_BUILD_ROOT%{_datadir}/applications/$i done +%endif %find_lang %{name} -%clean -rm -rf $RPM_BUILD_ROOT - %files -f %{name}.lang -%defattr(-,root,root,-) -%doc COPYING ChangeLog NEWS README -%attr(4711,root,root) /usr/sbin/userhelper +%license COPYING +%doc ChangeLog NEWS README +%attr(4711,root,root) /%{_sbindir}/userhelper %{_bindir}/consolehelper %{_mandir}/man8/userhelper.8* %{_mandir}/man8/consolehelper.8* -# PAM console wrappers -%{_bindir}/halt -%{_bindir}/reboot -%{_bindir}/poweroff -%exclude %{_bindir}/shutdown -%config(noreplace) /etc/pam.d/halt -%config(noreplace) /etc/pam.d/reboot -%config(noreplace) /etc/pam.d/poweroff +%dir /etc/security/console.apps %config(noreplace) /etc/security/console.apps/config-util -%config(noreplace) /etc/security/console.apps/halt -%config(noreplace) /etc/security/console.apps/reboot -%config(noreplace) /etc/security/console.apps/poweroff +%if %{with gtk} %files gtk -%defattr(-,root,root,-) %{_bindir}/usermount %{_mandir}/man1/usermount.1* %{_bindir}/userformat @@ -110,8 +112,174 @@ rm -rf $RPM_BUILD_ROOT %{_datadir}/%{name} %{_datadir}/pixmaps/* %{_datadir}/applications/* +%endif %changelog +* Fri Jul 17 2026 Fedora Release Engineering - 1.114-17 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild + +* Sat Jan 17 2026 Fedora Release Engineering - 1.114-16 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild + +* Wed Aug 27 2025 Michal Hlavinka - 1.114-15 +- revert back and take ownership of console.apps as usermode still needs it + +* Wed Aug 27 2025 Michal Hlavinka - 1.114-14 +- drop console.apps files as pam no longer uses those and pam_console + was dropped https://fedoraproject.org/wiki/Changes/RemovePamConsole + +* Fri Jul 25 2025 Fedora Release Engineering - 1.114-13 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild + +* Thu Jan 30 2025 Michal Hlavinka - 1.114-12 +- fix static analysis issues and ftbfs + +* Sun Jan 19 2025 Fedora Release Engineering - 1.114-11 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + +* Sat Jul 20 2024 Fedora Release Engineering - 1.114-10 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + +* Sat Jan 27 2024 Fedora Release Engineering - 1.114-9 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Sat Jul 22 2023 Fedora Release Engineering - 1.114-8 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild + +* Sat Jan 21 2023 Fedora Release Engineering - 1.114-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild + +* Fri Jan 06 2023 Tomas Popela - 1.114-6 +- Don't build GTK 2 bits on RHEL 10 as GTK 2 won't be available there + +* Sat Jul 23 2022 Fedora Release Engineering - 1.114-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild + +* Sat Jan 22 2022 Fedora Release Engineering - 1.114-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild + +* Fri Jul 23 2021 Fedora Release Engineering - 1.114-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild + +* Wed Jun 16 2021 Jiri Kucera - 1.114-2 +- Do not use fexecve + Script executed via fexecve has a file descriptor number in + argv[0]. This results in unexpected output: when displaying + the script help, a user see "Usage: [options]" + instead of "Usage: [options]". + Resolves: #1969918 + +* Tue May 04 2021 Jiri Kucera - 1.114-1 +- Update to usermode-1.114 +- Allow to optionally disable GTK + +* Mon May 03 2021 Jiri Kucera - 1.113-1 +- Update to usermode-1.113 + +* Wed Jan 27 2021 Fedora Release Engineering - 1.112-10 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild + +* Wed Sep 09 2020 Jiri Kucera - 1.112-9 +- Do not use deprecated selinux headers + Resolves #1865598 + +* Sat Aug 01 2020 Fedora Release Engineering - 1.112-8 +- Second attempt - Rebuilt for + https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild + +* Wed Jul 29 2020 Fedora Release Engineering - 1.112-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild + +* Fri Jan 31 2020 Fedora Release Engineering - 1.112-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild + +* Sat Jul 27 2019 Fedora Release Engineering - 1.112-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild + +* Sun Feb 03 2019 Fedora Release Engineering - 1.112-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild + +* Tue Aug 07 2018 Jiri Kucera - 1.112-3 +- Dropped need to run autotools +- must be now included manually + Resolves #1606624 +- Fixed bad FSF address + +* Sat Jul 14 2018 Fedora Release Engineering - 1.112-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild + +* Thu Feb 22 2018 Jiri Kucera - 1.112-1 +- Update to usermode-1.112 + Resolves #1269643 + +* Wed Feb 21 2018 Jiri Kucera - 1.111-14 +- Added missing gcc dependency + +* Fri Feb 09 2018 Fedora Release Engineering - 1.111-13 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild + +* Thu Aug 03 2017 Fedora Release Engineering - 1.111-12 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild + +* Thu Jul 27 2017 Fedora Release Engineering - 1.111-11 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild + +* Mon Apr 24 2017 Miloslav Trmač - 1.111-10 +- Fix a FBFS with -Werror=format-security + Resolves #1444750 +- Fix inconsistent dates in %%changelog + +* Sat Feb 11 2017 Fedora Release Engineering - 1.111-9 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild + +* Fri Feb 05 2016 Fedora Release Engineering - 1.111-8 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild + +* Fri Jun 19 2015 Fedora Release Engineering - 1.111-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild + +* Mon Aug 18 2014 Fedora Release Engineering - 1.111-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild + +* Sun Jun 08 2014 Fedora Release Engineering - 1.111-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild + +* Sun Aug 04 2013 Fedora Release Engineering - 1.111-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild + +* Tue May 21 2013 Miloslav Trmač - 1.111-3 +- Enable hardened build + Resolves: #965471 + +* Fri Feb 15 2013 Fedora Release Engineering - 1.111-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild + +* Sat Sep 22 2012 Miloslav Trmač - 1.111-1 +- Update to usermode-1.111 + +* Tue Aug 21 2012 Miloslav Trmač - 1.110-2 +- Drop no longer necessary %%clean and %%defattr commands. + +* Mon Aug 20 2012 Miloslav Trmač - 1.110-1 +- Update to usermode-1.110. + Note that this drops halt/poweroff/reboot helpers, the respective + implementations in systemd now include PolicyKit support. Spec file change + based on a patch by Lennart Poettering . + Resolves: #804088, #849208 + +* Sun Jul 22 2012 Fedora Release Engineering - 1.109-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild + +* Sat Mar 3 2012 Miloslav Trmač - 1.109-1 +- Update to usermode-1.109 + +* Sat Jan 14 2012 Fedora Release Engineering - 1.108-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild + +* Mon Oct 3 2011 Miloslav Trmač - 1.108-1 +- Update to usermode-1.108 + Resolves: #622813, #716524 + * Thu Mar 31 2011 Miloslav Trmač - 1.107-1 - Update to usermode-1.107 Resolves: #668731 @@ -442,10 +610,10 @@ rm -rf $RPM_BUILD_ROOT - Add getenforce checks - Add root_passwd check -* Tue Jul 1 2004 Dan Walsh 1.70-6 +* Thu Jul 1 2004 Dan Walsh 1.70-6 - More fixes to make targeted policy work correctly -* Tue Jul 1 2004 Dan Walsh 1.70-5 +* Thu Jul 1 2004 Dan Walsh 1.70-5 - Fix to use root if user not defined * Tue May 25 2004 Dan Walsh 1.70-4 @@ -614,7 +782,7 @@ rm -rf $RPM_BUILD_ROOT - remove the pixmap we don't use any more (we use stock pixmaps now) - update translations -* Thu Apr 16 2002 Nalin Dahyabhai 1.54-1 +* Tue Apr 16 2002 Nalin Dahyabhai 1.54-1 - suppress even error messages from Xlib when consolehelper calls gtk_init_check() to see if the display is available @@ -691,7 +859,7 @@ rm -rf $RPM_BUILD_ROOT * Fri Nov 2 2001 Nalin Dahyabhai 1.45-1 - propagate environment variables from libpam to applications -* Fri Oct 3 2001 Nalin Dahyabhai 1.44-1 +* Wed Oct 3 2001 Nalin Dahyabhai 1.44-1 - only try to call gtk_main_quit() if we've got a loop to get out of (#54109) - obey RPM_OPT_FLAGS, obey @@ -831,7 +999,7 @@ rm -rf $RPM_BUILD_ROOT * Tue Mar 07 2000 Nalin Dahyabhai - queue notice messages until we get prompts in userhelper to fix bug #8745 -* Fri Feb 03 2000 Nalin Dahyabhai +* Thu Feb 03 2000 Nalin Dahyabhai - free trip through the build system * Tue Jan 11 2000 Nalin Dahyabhai