accountsservice ver. bump

This commit is contained in:
Rmys
2025-02-24 19:18:58 +03:00
parent 9ebef31ba6
commit 2ff6e5b071
9 changed files with 525 additions and 1 deletions
@@ -0,0 +1,54 @@
From da65bee12d9118fe1a49c8718d428fe61d232339 Mon Sep 17 00:00:00 2001
From: Ray Strode <rstrode@redhat.com>
Date: Tue, 11 Apr 2023 10:09:07 -0400
Subject: [PATCH 1/2] mocklibc: Fix compiler warning
print_indent is defined in one file and used in another without a
forward declaration. That leads to a compiler warning/error.
This commit fixes that.
---
subprojects/mocklibc.wrap | 2 ++
subprojects/packagefiles/mocklibc-print-indent.diff | 13 +++++++++++++
2 files changed, 15 insertions(+)
create mode 100644 subprojects/packagefiles/mocklibc-print-indent.diff
diff --git a/subprojects/mocklibc.wrap b/subprojects/mocklibc.wrap
index af82298..539ee83 100644
--- a/subprojects/mocklibc.wrap
+++ b/subprojects/mocklibc.wrap
@@ -1,10 +1,12 @@
[wrap-file]
directory = mocklibc-1.0
source_url = https://storage.googleapis.com/google-code-archive-downloads/v2/code.google.com/mocklibc/mocklibc-1.0.tar.gz
source_filename = mocklibc-1.0.tar.gz
source_hash = b2236a6af1028414783e9734a46ea051916ec226479d6a55a3bb823bff68f120
patch_url = https://wrapdb.mesonbuild.com/v1/projects/mocklibc/1.0/2/get_zip
patch_filename = mocklibc-1.0-2-wrap.zip
patch_hash = 0280f96a2eeb3c023e5acf4e00cef03d362868218d4a85347ea45137c0ef6c56
+
+diff_files = mocklibc-print-indent.diff
diff --git a/subprojects/packagefiles/mocklibc-print-indent.diff b/subprojects/packagefiles/mocklibc-print-indent.diff
new file mode 100644
index 0000000..4aaed40
--- /dev/null
+++ b/subprojects/packagefiles/mocklibc-print-indent.diff
@@ -0,0 +1,13 @@
+diff -up mocklibc-1.0/src/netgroup-debug.c.print-indent mocklibc-1.0/src/netgroup-debug.c
+--- mocklibc-1.0/src/netgroup-debug.c.print-indent 2023-04-11 10:20:53.717381559 -0400
++++ mocklibc-1.0/src/netgroup-debug.c 2023-04-11 10:21:02.296270333 -0400
+@@ -21,6 +21,9 @@
+ #include <stdio.h>
+ #include <stdlib.h>
+
++void print_indent (FILE *stream,
++ unsigned int indent);
++
+ void netgroup_debug_print_entry(struct entry *entry, FILE *stream, unsigned int indent) {
+ print_indent(stream, indent);
+
--
2.39.2
@@ -0,0 +1,145 @@
From 99aa57bfa59e2578c4ef47e84338f7de85c6f61b Mon Sep 17 00:00:00 2001
From: Ray Strode <rstrode@redhat.com>
Date: Tue, 11 Apr 2023 10:11:05 -0400
Subject: [PATCH 2/2] user-manager: Fix another compiler warning
-Wswitch-enum apparently complains about missing entries even if there
is a default:.
This commit ensures ACT_USER_MANAGER_SEAT_STATE_UNLOADED is added to the
default case to fix that warning.
---
src/libaccountsservice/act-user-manager.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/src/libaccountsservice/act-user-manager.c b/src/libaccountsservice/act-user-manager.c
index 61b4da5..3bbd480 100644
--- a/src/libaccountsservice/act-user-manager.c
+++ b/src/libaccountsservice/act-user-manager.c
@@ -1727,60 +1727,61 @@ unload_seat (ActUserManager *manager)
{
ActUserManagerPrivate *priv = act_user_manager_get_instance_private (manager);
priv->seat.state = ACT_USER_MANAGER_SEAT_STATE_UNLOADED;
g_free (priv->seat.id);
priv->seat.id = NULL;
g_free (priv->seat.session_id);
priv->seat.session_id = NULL;
g_debug ("ActUserManager: seat unloaded, so trying to set loaded property");
maybe_set_is_loaded (manager);
}
static void
load_new_session_incrementally (ActUserManagerNewSession *new_session)
{
switch (new_session->state) {
case ACT_USER_MANAGER_NEW_SESSION_STATE_GET_UID:
get_uid_for_new_session (new_session);
break;
case ACT_USER_MANAGER_NEW_SESSION_STATE_GET_X11_DISPLAY:
get_x11_display_for_new_session (new_session);
break;
case ACT_USER_MANAGER_NEW_SESSION_STATE_MAYBE_ADD:
maybe_add_new_session (new_session);
break;
case ACT_USER_MANAGER_NEW_SESSION_STATE_LOADED:
break;
+ case ACT_USER_MANAGER_NEW_SESSION_STATE_UNLOADED:
default:
g_assert_not_reached ();
}
}
static void
free_fetch_user_request (ActUserManagerFetchUserRequest *request)
{
ActUserManager *manager = request->manager;
ActUserManagerPrivate *priv = act_user_manager_get_instance_private (manager);
if (request->user != NULL) {
g_object_set_data (G_OBJECT (request->user), "fetch-user-request", NULL);
g_object_weak_unref (G_OBJECT (request->user), (GWeakNotify) on_user_destroyed, manager);
}
priv->fetch_user_requests = g_slist_remove (priv->fetch_user_requests, request);
if (request->type == ACT_USER_MANAGER_FETCH_USER_FROM_USERNAME_REQUEST) {
g_free (request->username);
}
g_free (request->object_path);
g_free (request->description);
g_cancellable_cancel (request->cancellable);
g_object_unref (request->cancellable);
g_debug ("ActUserManager: unrefing manager owned by fetch user request");
g_object_unref (manager);
@@ -2243,60 +2244,61 @@ load_users (ActUserManager *manager)
return;
}
load_user_paths (manager, (const char * const *) user_paths);
load_included_usernames (manager);
priv->list_cached_users_done = TRUE;
}
static gboolean
load_seat_incrementally (ActUserManager *manager)
{
ActUserManagerPrivate *priv = act_user_manager_get_instance_private (manager);
priv->seat.load_idle_id = 0;
switch (priv->seat.state) {
case ACT_USER_MANAGER_SEAT_STATE_GET_SESSION_ID:
get_current_session_id (manager);
break;
case ACT_USER_MANAGER_SEAT_STATE_GET_ID:
get_seat_id_for_current_session (manager);
break;
case ACT_USER_MANAGER_SEAT_STATE_GET_SEAT_PROXY:
get_seat_proxy (manager);
break;
case ACT_USER_MANAGER_SEAT_STATE_LOADED:
g_debug ("ActUserManager: Seat loading sequence complete");
break;
+ case ACT_USER_MANAGER_NEW_SESSION_STATE_UNLOADED:
default:
g_assert_not_reached ();
}
if (priv->seat.state == ACT_USER_MANAGER_SEAT_STATE_LOADED) {
load_sessions (manager);
}
maybe_set_is_loaded (manager);
return FALSE;
}
static gboolean
load_idle (ActUserManager *manager)
{
ActUserManagerPrivate *priv = act_user_manager_get_instance_private (manager);
priv->seat.state = ACT_USER_MANAGER_SEAT_STATE_UNLOADED + 1;
load_seat_incrementally (manager);
priv->load_id = 0;
return FALSE;
}
static void
queue_load_seat (ActUserManager *manager)
{
ActUserManagerPrivate *priv = act_user_manager_get_instance_private (manager);
--
2.39.2
@@ -0,0 +1,111 @@
From e050e4aa99818f7559ab48568ea6662dc4104317 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Bj=C3=B6rn=20Esser?= <besser82@fedoraproject.org>
Date: Thu, 30 Jan 2025 12:36:21 +0100
Subject: [PATCH 3/3] act-user: Use the reentrant interfaces of
crypt{,_gensalt}(3)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
The crypt(3) function is known to clobber its static allocated internal
buffer when called multiple times consecutively or (especially) when
called in parallel (e.g. from independently operation threads), and
should generally not be used if a reentrant implementation exists.
The reentrant interface, named crypt_rn(3), operates in the same way as
the well known crypt(3) function, but takes an extra parameter of
'struct crypt_data' which includes space for its result (among other
things), so applications can utilize the reentrant interface, in a way
each invocation of the crypt_rn(3) function will freely operate on their
own dedicated memory areas when hashing passphrases.
The same applies for the crypt_gensalt(3) function, to which libxcrypt
offers a variety of reentrant interfaces as well.
Also ensure the buffers in use are properly zeroized.
Signed-off-by: Björn Esser <besser82@fedoraproject.org>
---
src/libaccountsservice/act-user.c | 53 ++++++++-----------------------
1 file changed, 13 insertions(+), 40 deletions(-)
diff --git a/src/libaccountsservice/act-user.c b/src/libaccountsservice/act-user.c
index 77b7b2f..4fd2c62 100644
--- a/src/libaccountsservice/act-user.c
+++ b/src/libaccountsservice/act-user.c
@@ -1748,51 +1748,22 @@ act_user_set_account_type (ActUser *user,
}
}
-#ifdef HAVE_CRYPT_GENSALT
static gchar *
-generate_salt_for_crypt_hash (void)
-{
- return g_strdup (crypt_gensalt (NULL, 0, NULL, 0));
-}
-#else
-static const gchar
-salt_char (GRand *rand)
+make_crypted (const gchar *plain)
{
- const gchar salt[] = "ABCDEFGHIJKLMNOPQRSTUVXYZ"
- "abcdefghijklmnopqrstuvxyz"
- "./0123456789";
-
- return salt[g_rand_int_range (rand, 0, G_N_ELEMENTS (salt))];
-}
+ gchar *crypted = NULL;
+ g_autofree struct crypt_data *cd = NULL;
-static gchar *
-generate_salt_for_crypt_hash (void)
-{
- g_autoptr (GString) salt = NULL;
- g_autoptr (GRand) rand = NULL;
- gint i;
+ cd = g_malloc0 (sizeof (struct crypt_data));
- rand = g_rand_new ();
- salt = g_string_sized_new (21);
+ crypt_gensalt_rn (NULL, 0, NULL, 0,
+ cd->input, sizeof (cd->input));
+ crypted = g_strdup (crypt_rn (plain, cd->input,
+ cd, sizeof (struct crypt_data)));
- /* sha512crypt */
- g_string_append (salt, "$6$");
- for (i = 0; i < 16; i++) {
- g_string_append_c (salt, salt_char (rand));
- }
- g_string_append_c (salt, '$');
+ explicit_bzero (cd, sizeof (struct crypt_data));
- return g_strdup (salt->str);
-}
-#endif
-
-static gchar *
-make_crypted (const gchar *plain)
-{
- g_autofree char *salt = NULL;
-
- salt = generate_salt_for_crypt_hash ();
- return g_strdup (crypt (plain, salt));
+ return crypted;
}
/**
@@ -1828,7 +1799,9 @@ act_user_set_password (ActUser *user,
&error)) {
g_warning ("SetPassword call failed: %s", error->message);
}
- memset (crypted, 0, strlen (crypted));
+ if (crypted) {
+ explicit_bzero (crypted, strlen (crypted));
+ }
}
/**
--
2.48.1