diff --git a/.cvsignore b/.cvsignore deleted file mode 100644 index ba589d2..0000000 --- a/.cvsignore +++ /dev/null @@ -1 +0,0 @@ -usermode-1.103.tar.bz2 diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..0e2dc37 --- /dev/null +++ b/.gitignore @@ -0,0 +1,12 @@ +usermode-1.105.tar.xz +/usermode-1.106.tar.xz +/usermode-1.106.1.tar.xz +/usermode-1.107.tar.xz +/usermode-1.108.tar.xz +/usermode-1.109.tar.xz +/usermode-1.110.tar.xz +/usermode-1.111.tar.xz +/usermode-1.112.tar.xz +/usermode-1.112.autotoolized.tar.xz +/usermode-1.113.tar.xz +/usermode-1.114.tar.xz diff --git a/Makefile b/Makefile deleted file mode 100644 index 45bd02b..0000000 --- a/Makefile +++ /dev/null @@ -1,21 +0,0 @@ -# Makefile for source rpm: usermode -# $Id: Makefile,v 1.2 2007/10/15 19:29:38 notting Exp $ -NAME := usermode -SPECFILE = $(firstword $(wildcard *.spec)) - -define find-makefile-common -for d in common ../common ../../common ; do if [ -f $$d/Makefile.common ] ; then if [ -f $$d/CVS/Root -a -w $$d/Makefile.common ] ; then cd $$d ; cvs -Q update ; fi ; echo "$$d/Makefile.common" ; break ; fi ; done -endef - -MAKEFILE_COMMON := $(shell $(find-makefile-common)) - -ifeq ($(MAKEFILE_COMMON),) -# attempt a checkout -define checkout-makefile-common -test -f CVS/Root && { cvs -Q -d $$(cat CVS/Root) checkout common && echo "common/Makefile.common" ; } || { echo "ERROR: I can't figure out how to checkout the 'common' module." ; exit -1 ; } >&2 -endef - -MAKEFILE_COMMON := $(shell $(checkout-makefile-common)) -endif - -include $(MAKEFILE_COMMON) diff --git a/config-util b/config-util new file mode 100644 index 0000000..a6b9096 --- /dev/null +++ b/config-util @@ -0,0 +1,2 @@ +USER=root +UGROUPS=wheel diff --git a/fix-sast.patch b/fix-sast.patch new file mode 100644 index 0000000..755ff3e --- /dev/null +++ b/fix-sast.patch @@ -0,0 +1,36 @@ +diff --git a/gsmclient.c b/gsmclient.c +index fb93a5c..93e9a64 100644 +--- a/gsmclient.c ++++ b/gsmclient.c +@@ -182,6 +182,7 @@ gsm_client_init (GsmClient *client, gpointer data) + char pid_str[64]; + int empty_vector_len = 0; + char *empty_vector[] = { NULL }; ++ gchar *curdir; + + (void)data; + client->priv = g_new (GsmClientPrivate, 1); +@@ -197,8 +198,10 @@ gsm_client_init (GsmClient *client, gpointer data) + /* Default property values (this code assumes we start + * with an empty proplist) + */ ++ curdir = g_get_current_dir (); + push_prop (client, smprop_new_string (GSM_CLIENT_PROPERTY_CURRENT_DIRECTORY, +- g_get_current_dir (), -1)); ++ curdir, -1)); ++ g_free(curdir); + + g_snprintf (pid_str, sizeof (pid_str), "%d", (int) getpid ()); + push_prop (client, smprop_new_string (GSM_CLIENT_PROPERTY_PROCESS_ID, +diff --git a/shvar.c b/shvar.c +index 0e199c6..62723db 100644 +--- a/shvar.c ++++ b/shvar.c +@@ -348,6 +348,7 @@ svSetValue(shvarFile *s, const char *key, const char *value) + s->modified = 1; + goto bail; /* do not need keyValue */ + } ++ else goto bail; + goto end; + } + diff --git a/sources b/sources index 5d24209..5065b51 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -f3650586d3199b5ccefd6ab0b35c844c usermode-1.103.tar.bz2 +SHA512 (usermode-1.114.tar.xz) = 703eb218704c7a11cdce25a71f4fc91bf4f042a8b185f79f3954699081c0db8a6234ad6f11738d8b2fe6a492a03d029cbe01762a47869edc473e4fbaa6e0ee32 diff --git a/usermode.spec b/usermode.spec index 9bb0e37..048552f 100644 --- a/usermode.spec +++ b/usermode.spec @@ -1,65 +1,79 @@ +# Add `--without gtk' option (enable gtk by default): +# No GTK 2 in RHEL 10 +%if 0%{?rhel} > 9 +%bcond_with gtk +%else +%bcond_without gtk +%endif + Summary: Tools for certain user account management tasks Name: usermode -Version: 1.103 -Release: 1%{?dist} -License: GPLv2+ -Group: Applications/System -URL: https://fedorahosted.org/usermode/ -Source: https://fedorahosted.org/releases/u/s/usermode/usermode-%{version}.tar.bz2 +Version: 1.114 +Release: 17%{?dist} +License: GPL-2.0-or-later +URL: https://pagure.io/%{name}/ +Source: https://releases.pagure.org/%{name}/%{name}-%{version}.tar.xz +Source1: config-util +Patch1: fix-sast.patch Requires: pam, passwd, util-linux -BuildRequires: desktop-file-utils, gettext, glib2-devel, gtk2-devel, intltool -BuildRequires: libblkid-devel, libSM-devel, libselinux-devel, libuser-devel -BuildRequires: pam-devel, perl-XML-Parser, startup-notification-devel -BuildRequires: util-linux -BuildRoot: %(mktemp -ud %{_tmppath}/%{name}-%{version}-%{release}-XXXXXX) +# https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org/thread/IJFYI5Q2BYZKIGDFS2WLOBDUSEGWHIKV/ +BuildRequires: make +BuildRequires: gcc +BuildRequires: gettext, glib2-devel, intltool +%if %{with gtk} +BuildRequires: desktop-file-utils, gtk2-devel, startup-notification-devel, libSM-devel +%endif +BuildRequires: libblkid-devel, libselinux-devel, libuser-devel +BuildRequires: pam-devel, perl-XML-Parser +%if %{with gtk} %package gtk Summary: Graphical tools for certain user account management tasks -Group: Applications/System Requires: %{name} = %{version}-%{release} +%endif + +%global _hardened_build 1 %description The usermode package contains the userhelper program, which can be used to allow configured programs to be run with superuser privileges by ordinary users. +%if %{with gtk} %description gtk The usermode-gtk package contains several graphical tools for users: userinfo, usermount and userpasswd. Userinfo allows users to change their finger information. Usermount lets users mount, unmount, and -format filesystems. Userpasswd allows users to change their +format file systems. Userpasswd allows users to change their passwords. Install the usermode-gtk package if you would like to provide users with graphical tools for certain account management tasks. +%endif %prep %setup -q +%patch -P 1 -p 1 %build -%configure --with-selinux +%configure --with-selinux --without-fexecve %{!?with_gtk:--without-gtk} -make %{?_smp_mflags} +%make_build %install -rm -rf $RPM_BUILD_ROOT -make install DESTDIR=$RPM_BUILD_ROOT INSTALL='install -p' +%make_install +%if %{with gtk} # make userformat symlink to usermount ln -sf usermount $RPM_BUILD_ROOT%{_bindir}/userformat ln -s usermount.1 $RPM_BUILD_ROOT%{_mandir}/man1/userformat.1 +%endif -# We set up the shutdown programs to be wrapped in this package. Other -# packages are on their own.... -mkdir -p $RPM_BUILD_ROOT/etc/pam.d $RPM_BUILD_ROOT/etc/security/console.apps -for wrappedapp in halt reboot poweroff ; do - ln -s consolehelper $RPM_BUILD_ROOT%{_bindir}/${wrappedapp} - install -p -m644 $wrappedapp \ - $RPM_BUILD_ROOT/etc/security/console.apps/${wrappedapp} - install -p -m644 shutdown.pamd $RPM_BUILD_ROOT/etc/pam.d/${wrappedapp} -done -echo 'USER=root' > $RPM_BUILD_ROOT/etc/security/console.apps/config-util +mkdir -p $RPM_BUILD_ROOT/etc/security/console.apps +install -p -m 644 %{SOURCE1} \ + $RPM_BUILD_ROOT/etc/security/console.apps/config-util +%if %{with gtk} for i in redhat-userinfo.desktop redhat-userpasswd.desktop \ redhat-usermount.desktop; do echo 'NotShowIn=GNOME;KDE;' >>$RPM_BUILD_ROOT%{_datadir}/applications/$i @@ -67,34 +81,22 @@ for i in redhat-userinfo.desktop redhat-userpasswd.desktop \ --dir $RPM_BUILD_ROOT%{_datadir}/applications \ $RPM_BUILD_ROOT%{_datadir}/applications/$i done +%endif %find_lang %{name} -%clean -rm -rf $RPM_BUILD_ROOT - %files -f %{name}.lang -%defattr(-,root,root,-) -%doc COPYING ChangeLog NEWS README -%attr(4711,root,root) /usr/sbin/userhelper +%license COPYING +%doc ChangeLog NEWS README +%attr(4711,root,root) /%{_sbindir}/userhelper %{_bindir}/consolehelper %{_mandir}/man8/userhelper.8* %{_mandir}/man8/consolehelper.8* -# PAM console wrappers -%{_bindir}/halt -%{_bindir}/reboot -%{_bindir}/poweroff -%exclude %{_bindir}/shutdown -%config(noreplace) /etc/pam.d/halt -%config(noreplace) /etc/pam.d/reboot -%config(noreplace) /etc/pam.d/poweroff +%dir /etc/security/console.apps %config(noreplace) /etc/security/console.apps/config-util -%config(noreplace) /etc/security/console.apps/halt -%config(noreplace) /etc/security/console.apps/reboot -%config(noreplace) /etc/security/console.apps/poweroff +%if %{with gtk} %files gtk -%defattr(-,root,root,-) %{_bindir}/usermount %{_mandir}/man1/usermount.1* %{_bindir}/userformat @@ -110,8 +112,208 @@ rm -rf $RPM_BUILD_ROOT %{_datadir}/%{name} %{_datadir}/pixmaps/* %{_datadir}/applications/* +%endif %changelog +* Fri Jul 17 2026 Fedora Release Engineering - 1.114-17 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild + +* Sat Jan 17 2026 Fedora Release Engineering - 1.114-16 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild + +* Wed Aug 27 2025 Michal Hlavinka - 1.114-15 +- revert back and take ownership of console.apps as usermode still needs it + +* Wed Aug 27 2025 Michal Hlavinka - 1.114-14 +- drop console.apps files as pam no longer uses those and pam_console + was dropped https://fedoraproject.org/wiki/Changes/RemovePamConsole + +* Fri Jul 25 2025 Fedora Release Engineering - 1.114-13 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild + +* Thu Jan 30 2025 Michal Hlavinka - 1.114-12 +- fix static analysis issues and ftbfs + +* Sun Jan 19 2025 Fedora Release Engineering - 1.114-11 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + +* Sat Jul 20 2024 Fedora Release Engineering - 1.114-10 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + +* Sat Jan 27 2024 Fedora Release Engineering - 1.114-9 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Sat Jul 22 2023 Fedora Release Engineering - 1.114-8 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild + +* Sat Jan 21 2023 Fedora Release Engineering - 1.114-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild + +* Fri Jan 06 2023 Tomas Popela - 1.114-6 +- Don't build GTK 2 bits on RHEL 10 as GTK 2 won't be available there + +* Sat Jul 23 2022 Fedora Release Engineering - 1.114-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild + +* Sat Jan 22 2022 Fedora Release Engineering - 1.114-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild + +* Fri Jul 23 2021 Fedora Release Engineering - 1.114-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild + +* Wed Jun 16 2021 Jiri Kucera - 1.114-2 +- Do not use fexecve + Script executed via fexecve has a file descriptor number in + argv[0]. This results in unexpected output: when displaying + the script help, a user see "Usage: [options]" + instead of "Usage: [options]". + Resolves: #1969918 + +* Tue May 04 2021 Jiri Kucera - 1.114-1 +- Update to usermode-1.114 +- Allow to optionally disable GTK + +* Mon May 03 2021 Jiri Kucera - 1.113-1 +- Update to usermode-1.113 + +* Wed Jan 27 2021 Fedora Release Engineering - 1.112-10 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild + +* Wed Sep 09 2020 Jiri Kucera - 1.112-9 +- Do not use deprecated selinux headers + Resolves #1865598 + +* Sat Aug 01 2020 Fedora Release Engineering - 1.112-8 +- Second attempt - Rebuilt for + https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild + +* Wed Jul 29 2020 Fedora Release Engineering - 1.112-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild + +* Fri Jan 31 2020 Fedora Release Engineering - 1.112-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild + +* Sat Jul 27 2019 Fedora Release Engineering - 1.112-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild + +* Sun Feb 03 2019 Fedora Release Engineering - 1.112-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild + +* Tue Aug 07 2018 Jiri Kucera - 1.112-3 +- Dropped need to run autotools +- must be now included manually + Resolves #1606624 +- Fixed bad FSF address + +* Sat Jul 14 2018 Fedora Release Engineering - 1.112-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild + +* Thu Feb 22 2018 Jiri Kucera - 1.112-1 +- Update to usermode-1.112 + Resolves #1269643 + +* Wed Feb 21 2018 Jiri Kucera - 1.111-14 +- Added missing gcc dependency + +* Fri Feb 09 2018 Fedora Release Engineering - 1.111-13 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild + +* Thu Aug 03 2017 Fedora Release Engineering - 1.111-12 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild + +* Thu Jul 27 2017 Fedora Release Engineering - 1.111-11 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild + +* Mon Apr 24 2017 Miloslav Trmač - 1.111-10 +- Fix a FBFS with -Werror=format-security + Resolves #1444750 +- Fix inconsistent dates in %%changelog + +* Sat Feb 11 2017 Fedora Release Engineering - 1.111-9 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild + +* Fri Feb 05 2016 Fedora Release Engineering - 1.111-8 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild + +* Fri Jun 19 2015 Fedora Release Engineering - 1.111-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild + +* Mon Aug 18 2014 Fedora Release Engineering - 1.111-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild + +* Sun Jun 08 2014 Fedora Release Engineering - 1.111-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild + +* Sun Aug 04 2013 Fedora Release Engineering - 1.111-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild + +* Tue May 21 2013 Miloslav Trmač - 1.111-3 +- Enable hardened build + Resolves: #965471 + +* Fri Feb 15 2013 Fedora Release Engineering - 1.111-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild + +* Sat Sep 22 2012 Miloslav Trmač - 1.111-1 +- Update to usermode-1.111 + +* Tue Aug 21 2012 Miloslav Trmač - 1.110-2 +- Drop no longer necessary %%clean and %%defattr commands. + +* Mon Aug 20 2012 Miloslav Trmač - 1.110-1 +- Update to usermode-1.110. + Note that this drops halt/poweroff/reboot helpers, the respective + implementations in systemd now include PolicyKit support. Spec file change + based on a patch by Lennart Poettering . + Resolves: #804088, #849208 + +* Sun Jul 22 2012 Fedora Release Engineering - 1.109-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild + +* Sat Mar 3 2012 Miloslav Trmač - 1.109-1 +- Update to usermode-1.109 + +* Sat Jan 14 2012 Fedora Release Engineering - 1.108-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild + +* Mon Oct 3 2011 Miloslav Trmač - 1.108-1 +- Update to usermode-1.108 + Resolves: #622813, #716524 + +* Thu Mar 31 2011 Miloslav Trmač - 1.107-1 +- Update to usermode-1.107 + Resolves: #668731 +- Add UGROUPS=wheel to config-util + Resolves: #688690 + +* Mon Feb 07 2011 Fedora Release Engineering - 1.106.1-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild + +* Wed Sep 29 2010 jkeating - 1.106.1-2 +- Rebuilt for gcc bug 634757 + +* Tue Sep 14 2010 Miloslav Trmač - 1.106.1-1 +- Update to usermode-1.106.1 + +* Thu Aug 26 2010 Miloslav Trmač - 1.106-1 +- Update to usermode-1.106 + +* Thu Apr 8 2010 Miloslav Trmač - 1.105-1 +- Update to usermode-1.105 + Resolves: #578124 + Resolves: #580481 + +* Fri Mar 26 2010 Miloslav Trmač - 1.104.2-1 +- Update to usermode-1.104.2 + +* Thu Mar 4 2010 Miloslav Trmač - 1.104.1-1 +- Update to usermode-1.104.1 +- Drop no longer necessary references to BuildRoot: + +* Thu Feb 25 2010 Miloslav Trmač - 1.104-1 +- Update to usermode-1.104 + Resolves: #567117 + * Tue Feb 16 2010 Miloslav Trmač - 1.103-1 - Update to usermode-1.103 @@ -408,10 +610,10 @@ rm -rf $RPM_BUILD_ROOT - Add getenforce checks - Add root_passwd check -* Tue Jul 1 2004 Dan Walsh 1.70-6 +* Thu Jul 1 2004 Dan Walsh 1.70-6 - More fixes to make targeted policy work correctly -* Tue Jul 1 2004 Dan Walsh 1.70-5 +* Thu Jul 1 2004 Dan Walsh 1.70-5 - Fix to use root if user not defined * Tue May 25 2004 Dan Walsh 1.70-4 @@ -580,7 +782,7 @@ rm -rf $RPM_BUILD_ROOT - remove the pixmap we don't use any more (we use stock pixmaps now) - update translations -* Thu Apr 16 2002 Nalin Dahyabhai 1.54-1 +* Tue Apr 16 2002 Nalin Dahyabhai 1.54-1 - suppress even error messages from Xlib when consolehelper calls gtk_init_check() to see if the display is available @@ -657,7 +859,7 @@ rm -rf $RPM_BUILD_ROOT * Fri Nov 2 2001 Nalin Dahyabhai 1.45-1 - propagate environment variables from libpam to applications -* Fri Oct 3 2001 Nalin Dahyabhai 1.44-1 +* Wed Oct 3 2001 Nalin Dahyabhai 1.44-1 - only try to call gtk_main_quit() if we've got a loop to get out of (#54109) - obey RPM_OPT_FLAGS, obey @@ -797,7 +999,7 @@ rm -rf $RPM_BUILD_ROOT * Tue Mar 07 2000 Nalin Dahyabhai - queue notice messages until we get prompts in userhelper to fix bug #8745 -* Fri Feb 03 2000 Nalin Dahyabhai +* Thu Feb 03 2000 Nalin Dahyabhai - free trip through the build system * Tue Jan 11 2000 Nalin Dahyabhai