Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 564674 - sys-libs/pam-1.2.1 - pam_wheel root_only documentation very confusing
Summary: sys-libs/pam-1.2.1 - pam_wheel root_only documentation very confusing
Status: RESOLVED UPSTREAM
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: AMD64 Linux
: Normal enhancement (vote)
Assignee: PAM Gentoo Team (OBSOLETE)
URL: https://github.com/linux-pam/linux-pa...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-11-02 02:38 UTC by Christopher Head
Modified: 2018-09-26 04:54 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Christopher Head 2015-11-02 02:38:57 UTC
In the man page for pam_wheel, the root_only option is documented as meaning simply, “The check for wheel membership is done only.”. What does this mean? It makes no sense at all.

What the option actually does is it only checks for wheel membership *if the request is to become root*, but not when trying to become any other user. Counterintuitively, the DESCRIPTION section states that that’s what the module always does (“By default it permits root access to the system if the applicant user is a member of the wheel group.”); in reality, by default, pam_wheel denies all access (not just root access) unless the applicant is a member of wheel.

It looks as if some text might be missing (maybe it’s supposed to say “The check for wheel membership is done only *if authenticating to the root user*.” or something similar), but the DESCRIPTION section is still incorrect in that case.

Reproducible: Always
Comment 1 Pacho Ramos gentoo-dev 2018-09-24 13:32:29 UTC
this is really an upstream issue -> https://github.com/linux-pam/linux-pam/issues 

Please report there that man page needs to be updated to get it solved for future versions (for the case 1.3.0-r2 still has this issue)
Comment 2 Christopher Head 2018-09-26 04:54:25 UTC
Upstream already appears to have fixed the missing root_only text in commit c9c2f0b5a4209b266040a2d4384a65e901443394, April 19, 2016. I suppose that will show up in a future release, and eventually make its way into Gentoo.

The remaining part is now in PR form against the linux-pam repo.