unix_chkpwd is designed to have a suid bit, but it's not possible to set it for files in the store. This patch tells unix_pam.so to look for unix_chkpwd in setuid program directory on Guix System. --- a/modules/pam_unix/Makefile.in +++ b/modules/pam_unix/Makefile.in @@ -651,1 +651,1 @@ - -DCHKPWD_HELPER=\"$(sbindir)/unix_chkpwd\" \ + -DCHKPWD_HELPER=\"/run/setuid-programs/unix_chkpwd\" \ ='2'>cgit logo index : guix
Wojtek's customized Guix
aboutsummaryrefslogtreecommitdiff
path: root/etc/guix-daemon.cil.in
AgeCommit message (Expand)Author
2023-05-25etc: SELinux: Update policy file....Ludovic Courtès
2022-12-23etc: SELinux: Allow init process to setattr on profile directories....Ricardo Wurmus
2022-12-23etc: SELinux: Allow daemon to search run state directories....Ricardo Wurmus
2022-12-23etc: SELinux: Label guix-daemon executable in profile....Ricardo Wurmus
2022-01-26etc: Remove redundant SELinux permissions block....Marius Bakke
2022-01-24etc: Add more SELinux permissions for the daemon....Marius Bakke
2021-05-22etc: Add more SELinux permissions for the daemon....Marius Bakke