Bug 254961

Summary: SERVER INTERPRETED ACCESS TYPES - FUBAR
Product: [Fedora] Fedora Reporter: Sami Farin <hvtaifwkbgefbaei>
Component: xorg-x11-serverAssignee: Adam Jackson <ajax>
Status: CLOSED WONTFIX QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: high Docs Contact:
Priority: medium    
Version: 9CC: triage, xgl-maint
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: All   
Whiteboard: bzcl34nup
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2009-07-14 16:48:42 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
an evil hack to make si:localgroup/localuser work none

Description Sami Farin 2007-08-26 12:38:20 UTC
Description of problem:
In an attempt to make this work:

# cat /etc/X0.hosts
si:localgroup:xuser

as documented, I noticed that can NOT work because os/access.c is missing
call to strchr, so several strcmp calls end up comparing
"localgroup" to "localgroup:xuser" or whatever...

And as an extra bonus, if I do not specify -auth parameter to Xorg,
access from localhost is granted for everyone, totally ignoring
my ONLY line in /etc/X0.hosts.

I now run Xorg, started with command:
xinit /home/safari/.xinitrc -- -tst -novtswitch -nolisten tcp -audit 4
-logverbose 666 -verbose 666

Now lusers with group != xuser get denied:
AUDIT: Sun Aug 26 15:20:37 2007: 4617 X: client 26 rejected from local host (uid
527, gid 528)
AUDIT: Sun Aug 26 15:20:37 2007: 4617 X: client 26 disconnected

(I just have to do 'newgrp xuser' before starting X programs... no need for
pam_xauth.so, iptables rules for port 6000 accesss, xauth, ...)

Now I only have to find a way to disallow adding/removing hosts with xhost.
But that's next week's project.

I attached a patch which fixes the situation for me...
1) take care of ':'
2) bail out of EnableLocalHost if at least one FamilyServerInterpreted
   -type host is specified. (called from auth.c:CheckAuthorization() )

real fix would be adding some saner parsing for ':' and maybe
command line flag for Xorg which disables call to EnableLocalHost
if no -auth was specified.  or what?? 

Version-Release number of selected component (if applicable):
1.3.0.0-22

How reproducible:
always

Steps to Reproduce:
1. echo "si:localgroup:xuser" > /etc/X0.hosts
2. xinit ~/.xinitrc
3. as user not having gid xuser, start some X program
  
Actual results:
X program can be started

Expected results:
not ignoring /etc/X0.hosts

Additional info:

Comment 1 Sami Farin 2007-08-26 12:38:20 UTC
Created attachment 172941 [details]
an evil hack to make si:localgroup/localuser work

Comment 2 Bug Zapper 2008-04-04 13:40:46 UTC
Based on the date this bug was created, it appears to have been reported
during the development of Fedora 8. In order to refocus our efforts as
a project we are changing the version of this bug to '8'.

If this bug still exists in rawhide, please change the version back to
rawhide.
(If you're unable to change the bug's version, add a comment to the bug
and someone will change it for you.)

Thanks for your help and we apologize for the interruption.

The process we're following is outlined here:
http://fedoraproject.org/wiki/BugZappers/F9CleanUp

We will be following the process here:
http://fedoraproject.org/wiki/BugZappers/HouseKeeping to ensure this
doesn't happen again.

Comment 3 Bug Zapper 2008-05-14 03:09:02 UTC
Changing version to '9' as part of upcoming Fedora 9 GA.
More information and reason for this action is here:
http://fedoraproject.org/wiki/BugZappers/HouseKeeping

Comment 4 Bug Zapper 2009-06-09 22:47:15 UTC
This message is a reminder that Fedora 9 is nearing its end of life.
Approximately 30 (thirty) days from now Fedora will stop maintaining
and issuing updates for Fedora 9.  It is Fedora's policy to close all
bug reports from releases that are no longer maintained.  At that time
this bug will be closed as WONTFIX if it remains open with a Fedora 
'version' of '9'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, simply change the 'version' 
to a later Fedora version prior to Fedora 9's end of life.

Bug Reporter: Thank you for reporting this issue and we are sorry that 
we may not be able to fix it before Fedora 9 is end of life.  If you 
would still like to see this bug fixed and are able to reproduce it 
against a later version of Fedora please change the 'version' of this 
bug to the applicable version.  If you are unable to change the version, 
please add a comment here and someone will do it for you.

Although we aim to fix as many bugs as possible during every release's 
lifetime, sometimes those efforts are overtaken by events.  Often a 
more recent Fedora release includes newer upstream software that fixes 
bugs or makes them obsolete.

The process we are following is described here: 
http://fedoraproject.org/wiki/BugZappers/HouseKeeping

Comment 5 Bug Zapper 2009-07-14 16:48:42 UTC
Fedora 9 changed to end-of-life (EOL) status on 2009-07-10. Fedora 9 is 
no longer maintained, which means that it will not receive any further 
security or bug fix updates. As a result we are closing this bug.

If you can reproduce this bug against a currently maintained version of 
Fedora please feel free to reopen this bug against that version.

Thank you for reporting this bug and we are sorry it could not be fixed.