From patchwork Tue Dec 6 20:27:03 2016 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Thomas Petazzoni X-Patchwork-Id: 703332 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Received: from whitealder.osuosl.org (smtp1.osuosl.org [140.211.166.138]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 3tYCq14znpz9srZ for ; Wed, 7 Dec 2016 07:27:25 +1100 (AEDT) Received: from localhost (localhost [127.0.0.1]) by whitealder.osuosl.org (Postfix) with ESMTP id E229E8514B; Tue, 6 Dec 2016 20:27:23 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from whitealder.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YrOe5gYQJ126; Tue, 6 Dec 2016 20:27:22 +0000 (UTC) Received: from ash.osuosl.org (ash.osuosl.org [140.211.166.34]) by whitealder.osuosl.org (Postfix) with ESMTP id 98F3D85017; Tue, 6 Dec 2016 20:27:22 +0000 (UTC) X-Original-To: buildroot@lists.busybox.net Delivered-To: buildroot@osuosl.org Received: from hemlock.osuosl.org (smtp2.osuosl.org [140.211.166.133]) by ash.osuosl.org (Postfix) with ESMTP id 8CE731C0169 for ; Tue, 6 Dec 2016 20:27:21 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by hemlock.osuosl.org (Postfix) with ESMTP id 898FA8584F for ; Tue, 6 Dec 2016 20:27:21 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from hemlock.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xuNOmXczFyJd for ; Tue, 6 Dec 2016 20:27:20 +0000 (UTC) X-Greylist: domain auto-whitelisted by SQLgrey-1.7.6 Received: from mail.free-electrons.com (mail.free-electrons.com [62.4.15.54]) by hemlock.osuosl.org (Postfix) with ESMTP id 6E27A856C2 for ; Tue, 6 Dec 2016 20:27:20 +0000 (UTC) Received: by mail.free-electrons.com (Postfix, from userid 110) id 39A8020D99; Tue, 6 Dec 2016 21:27:19 +0100 (CET) Received: from localhost (LFbn-1-6691-76.w90-120.abo.wanadoo.fr [90.120.129.76]) by mail.free-electrons.com (Postfix) with ESMTPSA id 0DC65207C2; Tue, 6 Dec 2016 21:27:19 +0100 (CET) From: Thomas Petazzoni To: Buildroot List Date: Tue, 6 Dec 2016 21:27:03 +0100 Message-Id: <1481056025-28891-1-git-send-email-thomas.petazzoni@free-electrons.com> X-Mailer: git-send-email 2.7.4 In-Reply-To: <1477423570-15694-3-git-send-email-bryce.ferguson@rockwellcollins.com> References: <1477423570-15694-3-git-send-email-bryce.ferguson@rockwellcollins.com> Cc: Bryce Ferguson , Thomas Petazzoni , Niranjan Subject: [Buildroot] [PATCH 1/2] linux-pam: adjust login pam file for SELinux X-BeenThere: buildroot@busybox.net X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: Discussion and development of buildroot List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Errors-To: buildroot-bounces@busybox.net Sender: "buildroot" When SELinux support is enabled, the login pam file installed by linux-pam should be adjusted to use the pam_selinux.so module. To achieve this in a reasonably simple manner, we introduce the SELinux related lines in login.pam as comments, and if SELinux support is enabled, turn those commented lines into real lines. Signed-off-by: Thomas Petazzoni Tested-by: Bryce Ferguson --- package/linux-pam/linux-pam.mk | 5 +++++ package/linux-pam/login.pam | 2 ++ 2 files changed, 7 insertions(+) diff --git a/package/linux-pam/linux-pam.mk b/package/linux-pam/linux-pam.mk index 6ce3839..c8ba30f 100644 --- a/package/linux-pam/linux-pam.mk +++ b/package/linux-pam/linux-pam.mk @@ -29,6 +29,10 @@ endif ifeq ($(BR2_PACKAGE_LIBSELINUX),y) LINUX_PAM_CONF_OPTS += --enable-selinux LINUX_PAM_DEPENDENCIES += libselinux +define LINUX_PAM_SELINUX_PAMFILE_TWEAK + $(SED) 's/^# \(.*pam_selinux.so.*\)$$/\1/' \ + $(TARGET_DIR)/etc/pam.d/login +endef else LINUX_PAM_CONF_OPTS += --disable-selinux endif @@ -46,6 +50,7 @@ define LINUX_PAM_INSTALL_CONFIG $(TARGET_DIR)/etc/pam.d/login $(INSTALL) -m 0644 -D package/linux-pam/other.pam \ $(TARGET_DIR)/etc/pam.d/other + $(LINUX_PAM_SELINUX_PAMFILE_TWEAK) endef LINUX_PAM_POST_INSTALL_TARGET_HOOKS += LINUX_PAM_INSTALL_CONFIG diff --git a/package/linux-pam/login.pam b/package/linux-pam/login.pam index 01f5632..5df7db6 100644 --- a/package/linux-pam/login.pam +++ b/package/linux-pam/login.pam @@ -4,7 +4,9 @@ account required pam_unix.so password required pam_unix.so nullok +# session required pam_selinux.so close session required pam_limits.so session required pam_env.so session required pam_unix.so session optional pam_lastlog.so +# session required pam_selinux.so open