Blame SOURCES/sudo-1.8.23-Ignore-PAM_NEW_AUTHTOK_REQD-and-PAM_AUTHTOK_EXPIRED.patch

46eb58
From 0f303a2de843c31afb03b558dfb7287be79e6e17 Mon Sep 17 00:00:00 2001
46eb58
From: "Todd C. Miller" <Todd.Miller@sudo.ws>
46eb58
Date: Thu, 26 Jul 2018 12:31:29 -0600
46eb58
Subject: [PATCH] Ignore PAM_NEW_AUTHTOK_REQD and PAM_AUTHTOK_EXPIRED errors
46eb58
 from pam_acct_mgmt() if authentication is disabled for the user. Bug #843
46eb58
46eb58
---
46eb58
 plugins/sudoers/auth/bsdauth.c   |  2 +-
46eb58
 plugins/sudoers/auth/pam.c       | 10 +++++++++-
46eb58
 plugins/sudoers/auth/sudo_auth.c |  4 ++--
46eb58
 plugins/sudoers/auth/sudo_auth.h |  6 +++---
46eb58
 plugins/sudoers/check.c          |  4 +++-
46eb58
 plugins/sudoers/sudoers.h        |  2 +-
46eb58
 6 files changed, 19 insertions(+), 9 deletions(-)
46eb58
46eb58
diff --git a/plugins/sudoers/auth/bsdauth.c b/plugins/sudoers/auth/bsdauth.c
46eb58
index 444cd337..390263d3 100644
46eb58
--- a/plugins/sudoers/auth/bsdauth.c
46eb58
+++ b/plugins/sudoers/auth/bsdauth.c
46eb58
@@ -168,7 +168,7 @@ bsdauth_verify(struct passwd *pw, char *prompt, sudo_auth *auth, struct sudo_con
46eb58
 }
46eb58
 
46eb58
 int
46eb58
-bsdauth_approval(struct passwd *pw, sudo_auth *auth)
46eb58
+bsdauth_approval(struct passwd *pw, sudo_auth *auth, bool exempt)
46eb58
 {
46eb58
     struct bsdauth_state *state = auth->data;
46eb58
     debug_decl(bsdauth_approval, SUDOERS_DEBUG_AUTH)
46eb58
diff --git a/plugins/sudoers/auth/pam.c b/plugins/sudoers/auth/pam.c
46eb58
index 347289da..a4749448 100644
46eb58
--- a/plugins/sudoers/auth/pam.c
46eb58
+++ b/plugins/sudoers/auth/pam.c
46eb58
@@ -202,7 +202,7 @@ sudo_pam_verify(struct passwd *pw, char *prompt, sudo_auth *auth, struct sudo_co
46eb58
 }
46eb58
 
46eb58
 int
46eb58
-sudo_pam_approval(struct passwd *pw, sudo_auth *auth)
46eb58
+sudo_pam_approval(struct passwd *pw, sudo_auth *auth, bool exempt)
46eb58
 {
46eb58
     const char *s;
46eb58
     int *pam_status = (int *) auth->data;
46eb58
@@ -217,6 +217,10 @@ sudo_pam_approval(struct passwd *pw, sudo_auth *auth)
46eb58
 		"is your account locked?"));
46eb58
 	    debug_return_int(AUTH_FATAL);
46eb58
 	case PAM_NEW_AUTHTOK_REQD:
46eb58
+	    /* Ignore if user is exempt from password restrictions. */
46eb58
+	    if (exempt)
46eb58
+		debug_return_int(AUTH_SUCCESS);
46eb58
+	    /* New password required, try to change it. */
46eb58
 	    log_warningx(0, N_("Account or password is "
46eb58
 		"expired, reset your password and try again"));
46eb58
 	    *pam_status = pam_chauthtok(pamh,
46eb58
@@ -229,6 +233,10 @@ sudo_pam_approval(struct passwd *pw, sudo_auth *auth)
46eb58
 		N_("unable to change expired password: %s"), s);
46eb58
 	    debug_return_int(AUTH_FAILURE);
46eb58
 	case PAM_AUTHTOK_EXPIRED:
46eb58
+	    /* Ignore if user is exempt from password restrictions. */
46eb58
+	    if (exempt)
46eb58
+		debug_return_int(AUTH_SUCCESS);
46eb58
+	    /* Password expired, cannot be updated by user. */
46eb58
 	    log_warningx(0,
46eb58
 		N_("Password expired, contact your system administrator"));
46eb58
 	    debug_return_int(AUTH_FATAL);
46eb58
diff --git a/plugins/sudoers/auth/sudo_auth.c b/plugins/sudoers/auth/sudo_auth.c
46eb58
index 6ef9bd72..5d9382dc 100644
46eb58
--- a/plugins/sudoers/auth/sudo_auth.c
46eb58
+++ b/plugins/sudoers/auth/sudo_auth.c
46eb58
@@ -163,7 +163,7 @@ sudo_auth_init(struct passwd *pw)
46eb58
  * Returns true on success, false on failure and -1 on error.
46eb58
  */
46eb58
 int
46eb58
-sudo_auth_approval(struct passwd *pw, int validated)
46eb58
+sudo_auth_approval(struct passwd *pw, int validated, bool exempt)
46eb58
 {
46eb58
     sudo_auth *auth;
46eb58
     debug_decl(sudo_auth_approval, SUDOERS_DEBUG_AUTH)
46eb58
@@ -171,7 +171,7 @@ sudo_auth_approval(struct passwd *pw, int validated)
46eb58
     /* Call approval routines. */
46eb58
     for (auth = auth_switch; auth->name; auth++) {
46eb58
 	if (auth->approval && !IS_DISABLED(auth)) {
46eb58
-	    int status = (auth->approval)(pw, auth);
46eb58
+	    int status = (auth->approval)(pw, auth, exempt);
46eb58
 	    if (status != AUTH_SUCCESS) {
46eb58
 		/* Assume error msg already printed. */
46eb58
 		log_auth_failure(validated, 0);
46eb58
diff --git a/plugins/sudoers/auth/sudo_auth.h b/plugins/sudoers/auth/sudo_auth.h
46eb58
index ea5ed9cd..9ae69cd5 100644
46eb58
--- a/plugins/sudoers/auth/sudo_auth.h
46eb58
+++ b/plugins/sudoers/auth/sudo_auth.h
46eb58
@@ -31,7 +31,7 @@ typedef struct sudo_auth {
46eb58
     int (*init)(struct passwd *pw, struct sudo_auth *auth);
46eb58
     int (*setup)(struct passwd *pw, char **prompt, struct sudo_auth *auth);
46eb58
     int (*verify)(struct passwd *pw, char *p, struct sudo_auth *auth, struct sudo_conv_callback *callback);
46eb58
-    int (*approval)(struct passwd *pw, struct sudo_auth *auth);
46eb58
+    int (*approval)(struct passwd *pw, struct sudo_auth *auth, bool exempt);
46eb58
     int (*cleanup)(struct passwd *pw, struct sudo_auth *auth);
46eb58
     int (*begin_session)(struct passwd *pw, char **user_env[], struct sudo_auth *auth);
46eb58
     int (*end_session)(struct passwd *pw, struct sudo_auth *auth);
46eb58
@@ -56,7 +56,7 @@ extern sudo_conv_t sudo_conv;
46eb58
 /* Prototypes for standalone methods */
46eb58
 int bsdauth_init(struct passwd *pw, sudo_auth *auth);
46eb58
 int bsdauth_verify(struct passwd *pw, char *prompt, sudo_auth *auth, struct sudo_conv_callback *callback);
46eb58
-int bsdauth_approval(struct passwd *pw, sudo_auth *auth);
46eb58
+int bsdauth_approval(struct passwd *pw, sudo_auth *auth, bool exempt);
46eb58
 int bsdauth_cleanup(struct passwd *pw, sudo_auth *auth);
46eb58
 int sudo_aix_init(struct passwd *pw, sudo_auth *auth);
46eb58
 int sudo_aix_verify(struct passwd *pw, char *pass, sudo_auth *auth, struct sudo_conv_callback *callback);
46eb58
@@ -67,7 +67,7 @@ int sudo_fwtk_cleanup(struct passwd *pw, sudo_auth *auth);
46eb58
 int sudo_pam_init(struct passwd *pw, sudo_auth *auth);
46eb58
 int sudo_pam_init_quiet(struct passwd *pw, sudo_auth *auth);
46eb58
 int sudo_pam_verify(struct passwd *pw, char *prompt, sudo_auth *auth, struct sudo_conv_callback *callback);
46eb58
-int sudo_pam_approval(struct passwd *pw, sudo_auth *auth);
46eb58
+int sudo_pam_approval(struct passwd *pw, sudo_auth *auth, bool exempt);
46eb58
 int sudo_pam_cleanup(struct passwd *pw, sudo_auth *auth);
46eb58
 int sudo_pam_begin_session(struct passwd *pw, char **user_env[], sudo_auth *auth);
46eb58
 int sudo_pam_end_session(struct passwd *pw, sudo_auth *auth);
46eb58
diff --git a/plugins/sudoers/check.c b/plugins/sudoers/check.c
46eb58
index ed49d63a..486a80d8 100644
46eb58
--- a/plugins/sudoers/check.c
46eb58
+++ b/plugins/sudoers/check.c
46eb58
@@ -175,6 +175,7 @@ check_user(int validated, int mode)
46eb58
 {
46eb58
     struct passwd *auth_pw;
46eb58
     int ret = -1;
46eb58
+    bool exempt = false;
46eb58
     debug_decl(check_user, SUDOERS_DEBUG_AUTH)
46eb58
 
46eb58
     /*
46eb58
@@ -194,6 +195,7 @@ check_user(int validated, int mode)
46eb58
 	sudo_debug_printf(SUDO_DEBUG_INFO, "%s: %s", __func__,
46eb58
 	    !def_authenticate ? "authentication disabled" :
46eb58
 	    "user exempt from authentication");
46eb58
+	exempt = true;
46eb58
 	ret = true;
46eb58
 	goto done;
46eb58
     }
46eb58
@@ -218,7 +220,7 @@ check_user(int validated, int mode)
46eb58
 done:
46eb58
     if (ret == true) {
46eb58
 	/* The approval function may disallow a user post-authentication. */
46eb58
-	ret = sudo_auth_approval(auth_pw, validated);
46eb58
+	ret = sudo_auth_approval(auth_pw, validated, exempt);
46eb58
     }
46eb58
     sudo_auth_cleanup(auth_pw);
46eb58
     sudo_pw_delref(auth_pw);
46eb58
diff --git a/plugins/sudoers/sudoers.h b/plugins/sudoers/sudoers.h
46eb58
index 57db74c1..956cb084 100644
46eb58
--- a/plugins/sudoers/sudoers.h
46eb58
+++ b/plugins/sudoers/sudoers.h
46eb58
@@ -265,7 +265,7 @@ int verify_user(struct passwd *pw, char *prompt, int validated, struct sudo_conv
46eb58
 int sudo_auth_begin_session(struct passwd *pw, char **user_env[]);
46eb58
 int sudo_auth_end_session(struct passwd *pw);
46eb58
 int sudo_auth_init(struct passwd *pw);
46eb58
-int sudo_auth_approval(struct passwd *pw, int validated);
46eb58
+int sudo_auth_approval(struct passwd *pw, int validated, bool exempt);
46eb58
 int sudo_auth_cleanup(struct passwd *pw);
46eb58
 
46eb58
 /* set_perms.c */
46eb58
-- 
46eb58
2.13.6
46eb58