Patch Detail
get:
Show a patch.
patch:
Update a patch.
put:
Update a patch.
GET /api/patches/686670/?format=api
{ "id": 686670, "url": "http://patchwork.ozlabs.org/api/patches/686670/?format=api", "web_url": "http://patchwork.ozlabs.org/project/buildroot/patch/1477423570-15694-3-git-send-email-bryce.ferguson@rockwellcollins.com/", "project": { "id": 27, "url": "http://patchwork.ozlabs.org/api/projects/27/?format=api", "name": "Buildroot development", "link_name": "buildroot", "list_id": "buildroot.buildroot.org", "list_email": "buildroot@buildroot.org", "web_url": "", "scm_url": "", "webscm_url": "", "list_archive_url": "", "list_archive_url_format": "", "commit_url_format": "" }, "msgid": "<1477423570-15694-3-git-send-email-bryce.ferguson@rockwellcollins.com>", "list_archive_url": null, "date": "2016-10-25T19:26:05", "name": "[v13,3/8] linux-pam: add system auth file and host variant", "commit_ref": null, "pull_url": null, "state": "superseded", "archived": false, "hash": "55b24a11ba942af52698119c1d41a01b1ac9b278", "submitter": { "id": 70083, "url": "http://patchwork.ozlabs.org/api/people/70083/?format=api", "name": "Bryce Ferguson", "email": "bryce.ferguson@rockwellcollins.com" }, "delegate": null, "mbox": "http://patchwork.ozlabs.org/project/buildroot/patch/1477423570-15694-3-git-send-email-bryce.ferguson@rockwellcollins.com/mbox/", "series": [], "comments": "http://patchwork.ozlabs.org/api/patches/686670/comments/", "check": "pending", "checks": "http://patchwork.ozlabs.org/api/patches/686670/checks/", "tags": {}, "related": [], "headers": { "Return-Path": "<buildroot-bounces@busybox.net>", "X-Original-To": [ "incoming@patchwork.ozlabs.org", "buildroot@lists.busybox.net" ], "Delivered-To": [ "patchwork-incoming@bilbo.ozlabs.org", "buildroot@osuosl.org" ], "Received": [ "from whitealder.osuosl.org (smtp1.osuosl.org [140.211.166.138])\n\t(using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits))\n\t(No client certificate requested)\n\tby ozlabs.org (Postfix) with ESMTPS id 3t3NSW6x4wz9snm\n\tfor <incoming@patchwork.ozlabs.org>;\n\tWed, 26 Oct 2016 06:26:51 +1100 (AEDT)", "from localhost (localhost [127.0.0.1])\n\tby whitealder.osuosl.org (Postfix) with ESMTP id 7550E9203D;\n\tTue, 25 Oct 2016 19:26:50 +0000 (UTC)", "from whitealder.osuosl.org ([127.0.0.1])\n\tby localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024)\n\twith ESMTP id PNdLAqTpZ2VU; Tue, 25 Oct 2016 19:26:42 +0000 (UTC)", "from ash.osuosl.org (ash.osuosl.org [140.211.166.34])\n\tby whitealder.osuosl.org (Postfix) with ESMTP id EC22791FE5;\n\tTue, 25 Oct 2016 19:26:35 +0000 (UTC)", "from hemlock.osuosl.org (smtp2.osuosl.org [140.211.166.133])\n\tby ash.osuosl.org (Postfix) with ESMTP id 7E4051C1E97\n\tfor <buildroot@lists.busybox.net>;\n\tTue, 25 Oct 2016 19:26:34 +0000 (UTC)", "from localhost (localhost [127.0.0.1])\n\tby hemlock.osuosl.org (Postfix) with ESMTP id 6FA7894CF7\n\tfor <buildroot@lists.busybox.net>;\n\tTue, 25 Oct 2016 19:26:34 +0000 (UTC)", "from hemlock.osuosl.org ([127.0.0.1])\n\tby localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024)\n\twith ESMTP id XEP74cQyIAMQ for <buildroot@lists.busybox.net>;\n\tTue, 25 Oct 2016 19:26:33 +0000 (UTC)", "from ch3vs02.rockwellcollins.com (ch3vs02.rockwellcollins.com\n\t[205.175.226.29])\n\tby hemlock.osuosl.org (Postfix) with ESMTPS id 909E08AD5F\n\tfor <buildroot@buildroot.org>; Tue, 25 Oct 2016 19:26:33 +0000 (UTC)", "from ofwch3n02.rockwellcollins.com (HELO\n\tdtulimr01.rockwellcollins.com) ([205.175.226.14])\n\tby ch3vs02.rockwellcollins.com with ESMTP; 25 Oct 2016 14:26:34 -0500" ], "X-Virus-Scanned": [ "amavisd-new at osuosl.org", "amavisd-new at osuosl.org" ], "X-Greylist": "domain auto-whitelisted by SQLgrey-1.7.6", "X-Received": "from largo.rockwellcollins.com (unknown [192.168.140.76])\n\tby dtulimr01.rockwellcollins.com (Postfix) with ESMTP id 84148601D8; \n\tTue, 25 Oct 2016 14:26:32 -0500 (CDT)", "From": "Bryce Ferguson <bryce.ferguson@rockwellcollins.com>", "To": "buildroot@buildroot.org", "Date": "Tue, 25 Oct 2016 14:26:05 -0500", "Message-Id": "<1477423570-15694-3-git-send-email-bryce.ferguson@rockwellcollins.com>", "X-Mailer": "git-send-email 1.9.1", "In-Reply-To": "<1477423570-15694-1-git-send-email-bryce.ferguson@rockwellcollins.com>", "References": "<1477423570-15694-1-git-send-email-bryce.ferguson@rockwellcollins.com>", "Cc": "Niranjan <niranjan.reddy@rockwellcollins.com>", "Subject": "[Buildroot] [PATCH v13 3/8] linux-pam: add system auth file and\n\thost variant", "X-BeenThere": "buildroot@busybox.net", "X-Mailman-Version": "2.1.18-1", "Precedence": "list", "List-Id": "Discussion and development of buildroot <buildroot.busybox.net>", "List-Unsubscribe": "<http://lists.busybox.net/mailman/options/buildroot>,\n\t<mailto:buildroot-request@busybox.net?subject=unsubscribe>", "List-Archive": "<http://lists.busybox.net/pipermail/buildroot/>", "List-Post": "<mailto:buildroot@busybox.net>", "List-Help": "<mailto:buildroot-request@busybox.net?subject=help>", "List-Subscribe": "<http://lists.busybox.net/mailman/listinfo/buildroot>,\n\t<mailto:buildroot-request@busybox.net?subject=subscribe>", "MIME-Version": "1.0", "Content-Type": "text/plain; charset=\"us-ascii\"", "Content-Transfer-Encoding": "7bit", "Errors-To": "buildroot-bounces@busybox.net", "Sender": "\"buildroot\" <buildroot-bounces@busybox.net>" }, "content": "From: Niranjan <niranjan.reddy@rockwellcollins.com>\n\nThis patch creates system-auth.pamd file for pam services\nand adds host-linux-pam variant for creating pam.d files.\n\nSigned-off-by: Matthew Weber <matthew.weber@rockwellcollins.com>\nReviewed-by: Samuel Martin <s.martin49@gmail.com>\nSigned-off-by: Niranjan Reddy <niranjan.reddy@rockwellcollins.com>\n\n---\nChanges v12 -> v13:\n - No changes\n\nChanges v11 -> v12:\n - No changes\n\nChanges v10 -> v11:\n - Added host-linux-pam variant as it is the dependency for creating pam_conv1 files.\n - Removed semicolon at the end of if condition (after fi).\n - Merged system auth patch with host selinux dependencies patch\n\nChanges v9 -> v10:\n - Dropped host linux-pam variant,optional selinux and audit dependencies and created seperate\n Patches (Suggedted by Thomas).\n\nChanges v8 -> v9:\n - No changes\n\nChanges v7 -> v8:\n - Removed sub-shell around the config file install block and\n refactored the block to use absolute paths for the copying\n (Suggested by Samuel)\n - Changed the enable-db=no configure option to disable-db to be\n consistent with the rest of the configure options (Suggested by\n Samuel)\n\nChanges v6 -> v7:\n - Added missing host-pkgconf dependency and removed unneeded\n host-autoconf dependency(Clayton S.)\n\nChanges v5 -> v6:\n - No changes\n\nChanges v4 -> v5:\n - Dropping unneeded patch (Clayton S.)\n\nChanges v1 -> v4:\n - Did not exist\n---\n package/linux-pam/linux-pam.mk | 41 +++++++++++++++++++++++++++++++++++++-\n package/linux-pam/system-auth.pamd | 15 ++++++++++++++\n 2 files changed, 55 insertions(+), 1 deletion(-)\n create mode 100644 package/linux-pam/system-auth.pamd", "diff": "diff --git a/package/linux-pam/linux-pam.mk b/package/linux-pam/linux-pam.mk\nindex 6ce3839..57c2be2 100644\n--- a/package/linux-pam/linux-pam.mk\n+++ b/package/linux-pam/linux-pam.mk\n@@ -8,15 +8,18 @@ LINUX_PAM_VERSION = 1.3.0\n LINUX_PAM_SOURCE = Linux-PAM-$(LINUX_PAM_VERSION).tar.bz2\n LINUX_PAM_SITE = http://linux-pam.org/library\n LINUX_PAM_INSTALL_STAGING = YES\n+# disable cracklib in linux pam config options\n LINUX_PAM_CONF_OPTS = \\\n \t--disable-prelude \\\n \t--disable-isadir \\\n \t--disable-nis \\\n \t--disable-db \\\n+\t--disable-cracklib \\\n \t--disable-regenerate-docu \\\n \t--enable-securedir=/lib/security \\\n \t--libdir=/lib\n-LINUX_PAM_DEPENDENCIES = flex host-flex host-pkgconf\n+# host-linux-pam is needed for creating pam conf files\n+LINUX_PAM_DEPENDENCIES = flex host-flex host-pkgconf host-linux-pam\n LINUX_PAM_AUTORECONF = YES\n LINUX_PAM_LICENSE = BSD-3c\n LINUX_PAM_LICENSE_FILES = Copyright\n@@ -48,6 +51,42 @@ define LINUX_PAM_INSTALL_CONFIG\n \t\t$(TARGET_DIR)/etc/pam.d/other\n endef\n \n+# Use the host-pam pam_conv1 app to create the pam.d files\n+define LINUX_PAM_CONFIG_FILE_TARGET_INSTALL\n+\tif [ -d $(TARGET_DIR)/etc/pam.d/ ]; then \\\n+\t\tmv $(TARGET_DIR)/etc/pam.d/ $(TARGET_DIR)/etc/pam.d.orig/; \\\n+\tfi\n+\tcd $(TARGET_DIR)/etc/ && cat $(@D)/conf/pam.conf | $(HOST_DIR)/usr/bin/pam_conv1; \\\n+\tif [ -d $(TARGET_DIR)/etc/pam.d.orig ]; then \\\n+\t\tcp -a $(TARGET_DIR)/etc/pam.d/* $(TARGET_DIR)/etc/pam.d.orig/; \\\n+\t\trm -rf $(TARGET_DIR)/etc/pam.d/; \\\n+\t\tmv $(TARGET_DIR)/etc/pam.d.orig/ $(TARGET_DIR)/etc/pam.d/; \\\n+\tfi\n+\t$(INSTALL) -D -m 0644 package/linux-pam/system-auth.pamd $(TARGET_DIR)/etc/pam.d/system-auth\n+endef\n+\n+LINUX_PAM_POST_INSTALL_TARGET_HOOKS += LINUX_PAM_CONFIG_FILE_TARGET_INSTALL\n LINUX_PAM_POST_INSTALL_TARGET_HOOKS += LINUX_PAM_INSTALL_CONFIG\n \n+HOST_LINUX_PAM_DEPENDENCIES = host-flex host-pkgconf\n+\n+HOST_LINUX_PAM_CONF_OPTS = \\\n+\t--disable-rpath \\\n+\t--enable-read-both-confs \\\n+\t--disable-regenerate-docu \\\n+\t--disable-isadir \\\n+\t--disable-nis \\\n+\t--enable-securedir=/lib/security \\\n+\t--disable-prelude \\\n+\t--disable-cracklib \\\n+\t--disable-lckpwdf \\\n+\t--disable-db \\\n+\t--disable-selinux \\\n+\t--disable-audit \\\n+\n+define HOST_LINUX_PAM_INSTALL_CMDS\n+\t$(INSTALL) -D -m 755 $(@D)/conf/pam_conv1/pam_conv1 $(HOST_DIR)/usr/bin/pam_conv1\n+endef\n+\n $(eval $(autotools-package))\n+$(eval $(host-autotools-package))\ndiff --git a/package/linux-pam/system-auth.pamd b/package/linux-pam/system-auth.pamd\nnew file mode 100644\nindex 0000000..2fa116a\n--- /dev/null\n+++ b/package/linux-pam/system-auth.pamd\n@@ -0,0 +1,15 @@\n+#%PAM-1.0\n+auth required pam_env.so\n+auth sufficient pam_unix.so\n+auth required pam_deny.so\n+\n+account required pam_unix.so\n+\n+#password required pam_cracklib.so try_first_pass retry=3\n+password sufficient pam_unix.so md5 shadow try_first_pass\n+password required pam_deny.so\n+\n+session optional pam_keyinit.so revoke\n+session required pam_limits.so\n+session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid\n+session required pam_unix.so\n", "prefixes": [ "v13", "3/8" ] }