Bug 241226
Summary: | Pam Namespace Enhancements. | ||||||
---|---|---|---|---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Daniel Walsh <dwalsh> | ||||
Component: | pam | Assignee: | Tomas Mraz <tmraz> | ||||
Status: | CLOSED RAWHIDE | QA Contact: | |||||
Severity: | medium | Docs Contact: | |||||
Priority: | medium | ||||||
Version: | rawhide | ||||||
Target Milestone: | --- | ||||||
Target Release: | --- | ||||||
Hardware: | All | ||||||
OS: | Linux | ||||||
Whiteboard: | |||||||
Fixed In Version: | pam-0.99.7.1-6.fc8 | Doc Type: | Bug Fix | ||||
Doc Text: | Story Points: | --- | |||||
Clone Of: | Environment: | ||||||
Last Closed: | 2007-06-05 07:03:41 UTC | Type: | --- | ||||
Regression: | --- | Mount Type: | --- | ||||
Documentation: | --- | CRM: | |||||
Verified Versions: | Category: | --- | |||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
Cloudforms Team: | --- | Target Upstream Version: | |||||
Embargoed: | |||||||
Attachments: |
|
Description
Daniel Walsh
2007-05-24 14:27:11 UTC
So I have patch implementing this against RHEL-5 pam. I changed the specification a little bit: 1) polyinstatiation for users xguest,xfriend only: <dir> <inst-prefix> <method> ~xguest,xfriend The '~' should be just the first character of the override user list. 2) tmpfs polyinstatiation <dir> tmpfs tmpfs <override user list> tmpfs is mounted on <dir>. Instance initialization script is called after the mount, otherwise it wouldn't be possible to initialize the directory. 3) tmpdir polyinstatiation <dir> <inst-prefix> tmpdir <override user list> Temporary directory <inst-prefix>XXXXXX is created using mkdtemp() and bind-mounted as in normal polyinstatiation. When the session is closed 'rm -rf' is called on the temporary directory. Created attachment 155825 [details]
And here is the patch
This is great, although I think you should bring your changes up for discussion on the SELInux/LSPP list. Since these guys developed them. You might get more feedback. I also want the changes in Rawhide so we can do some experimenting with it there. Built in rawhide (pam-0.99.7.1-6.fc8) There were no reactions on Fedora-selinux and LSPP lists to an e-mail I sent about this topic. Please test it in rawhide - if the functionality is OK as it is I'll add it to the pam_namespace documentation and probably release update with it in Fedora 7 as well. |