Overview

Request 765745 accepted

- Set 0755 for chpasswd, groupadd, groupdel, groupmod, newusers,
useradd, userdel, usermod explicitly.

- bsc#1160729: Make valid shell check only a warning
* Add shadow-4.8-shell-check.patch

- Update to 4.8:
* Initial optional bcrypt support.
* Make build/install of 'su' optional.
* Fix for vipw not resuming correctly when suspended
* Sync password field descriptions in manpages
* Check for valid shell argument in useradd
* Allow translation of new strings through POTFILES.in
* Migrate to itstool for translations
* Migrate to new SELinux api
* Support --enable-vendordir
* pwck: Only check homedir if set and not a system user
* Support nonstandard usernames
* sget{pw,gr}ent: check for data at EOL
* Add YYY-MM-DD support in chage
* Fix failing chmod calls for suidubins
* Fix --sbindir and --bindir for binary installations
* Fix LASTLOG_UID_MAX in login.defs
* Fix configure error with dash
- Remove because upstreamed:
* libeconf.patch
* shadow-usermod-variable.patch
- Rebase:
* shadow-login_defs-unused-by-pam.patch
* chkname-regex.patch

Loading...

Dominique Leuenberger's avatar
[  120s] shadow.x86_64: E: permissions-file-setuid-bit (Badness: 10000) /usr/sbin/chpasswd is packaged with setuid/setgid bits (04755)
[  120s] shadow.x86_64: E: permissions-file-setuid-bit (Badness: 10000) /usr/sbin/groupadd is packaged with setuid/setgid bits (04755)
[  120s] shadow.x86_64: E: permissions-file-setuid-bit (Badness: 10000) /usr/sbin/groupdel is packaged with setuid/setgid bits (04755)
[  120s] shadow.x86_64: E: permissions-file-setuid-bit (Badness: 10000) /usr/sbin/groupmod is packaged with setuid/setgid bits (04755)
[  120s] shadow.x86_64: E: permissions-file-setuid-bit (Badness: 10000) /usr/sbin/newusers is packaged with setuid/setgid bits (04755)
[  120s] shadow.x86_64: E: permissions-file-setuid-bit (Badness: 10000) /usr/sbin/useradd is packaged with setuid/setgid bits (04755)
[  120s] shadow.x86_64: E: permissions-file-setuid-bit (Badness: 10000) /usr/sbin/userdel is packaged with setuid/setgid bits (04755)
[  120s] shadow.x86_64: E: permissions-file-setuid-bit (Badness: 10000) /usr/sbin/usermod is packaged with setuid/setgid bits (04755)

Please link-up with sec team about that


Dominique Leuenberger's avatar

Need sec involvement for suid binaries (or packaging change)

Request History
Michael Vetter's avatar

jubalh created request

- Set 0755 for chpasswd, groupadd, groupdel, groupmod, newusers,
useradd, userdel, usermod explicitly.

- bsc#1160729: Make valid shell check only a warning
* Add shadow-4.8-shell-check.patch

- Update to 4.8:
* Initial optional bcrypt support.
* Make build/install of 'su' optional.
* Fix for vipw not resuming correctly when suspended
* Sync password field descriptions in manpages
* Check for valid shell argument in useradd
* Allow translation of new strings through POTFILES.in
* Migrate to itstool for translations
* Migrate to new SELinux api
* Support --enable-vendordir
* pwck: Only check homedir if set and not a system user
* Support nonstandard usernames
* sget{pw,gr}ent: check for data at EOL
* Add YYY-MM-DD support in chage
* Fix failing chmod calls for suidubins
* Fix --sbindir and --bindir for binary installations
* Fix LASTLOG_UID_MAX in login.defs
* Fix configure error with dash
- Remove because upstreamed:
* libeconf.patch
* shadow-usermod-variable.patch
- Rebase:
* shadow-login_defs-unused-by-pam.patch
* chkname-regex.patch


Factory Auto's avatar

factory-auto added opensuse-review-team as a reviewer

Please review sources


Factory Auto's avatar

factory-auto accepted review

Check script succeeded


Saul Goodman's avatar

licensedigger accepted review

ok


Ismail Dönmez's avatar

namtrac accepted review


Staging Bot's avatar

staging-bot set openSUSE:Factory:Staging:C as a staging project

Being evaluated by staging project "openSUSE:Factory:Staging:C"


Staging Bot's avatar

staging-bot accepted review

Picked "openSUSE:Factory:Staging:C"


Dominique Leuenberger's avatar

dimstar_suse accepted review

Staging Project openSUSE:Factory:Staging:C got accepted.


Dominique Leuenberger's avatar

dimstar_suse approved review

Staging Project openSUSE:Factory:Staging:C got accepted.


Dominique Leuenberger's avatar

dimstar_suse accepted request

Staging Project openSUSE:Factory:Staging:C got accepted.

openSUSE Build Service is sponsored by