[systemd-bugs] [Bug 65409] logind sessions don't follow nested audit sessions

bugzilla-daemon at freedesktop.org bugzilla-daemon at freedesktop.org
Wed Jun 5 23:05:36 PDT 2013


https://bugs.freedesktop.org/show_bug.cgi?id=65409

--- Comment #2 from Marius Vollmer <marius.vollmer at redhat.com> ---
(In reply to comment #1)
> In newer fedora the session ID is actually sealed off, so this wouldn't work
> anymore.

Hmm, what is "this" here?  Running sshd from within an already existing
session?  What would fail?  pam_loginuid?

> Also, the way we see it we initialize from the audit ID when we can, but we
> wouldn't always gurantee its equal.

I'd say that as long as a process has /proc/self/sessionid at all, the logind
session if should be guaranteed to follow it.  As far as I can see, this should
always be possible, by creating a new session if necessary.  If you don't want
nested sessions, that probably needs to be blocked in pam_loginuid, no?

-- 
You are receiving this mail because:
You are the QA Contact for the bug.
You are the assignee for the bug.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.freedesktop.org/archives/systemd-bugs/attachments/20130606/9b3f629b/attachment.html>


More information about the systemd-bugs mailing list