On Mon, 2010-02-22 at 09:41 -0500, P. Levine wrote: > Attached is the final version of the chroot patch. I'll submit it in > the next few days. > > It seems absurd to add support for chroot() in useradd and groupadd > without userdel and groupdel, so the patch includes support for them. > Also, to create a smaller footprint, I've combined all applicable > functions into one file. The downside is more complex macro expansions > (comments included, though), but it allows for a more integrated > interface (generated function xfgetXXbyYY calls generated functions > xfsetXXent, xfgetXXent, and xfendXXent), and less alteration of shadow's > own code. > PAM isn't a concern because chroot() only strictly works in a process > with an su uid. And a function to parse the chroot flag before any > others (leaving argv and argc in a pristine state) is included. > > -- Peter Levine
This seems a major improvement over the previous from quickly glancing over the code. In no time at all I'm sure you will be ready to re hit upstream. Q: If the end user is using Linux-Pam on his/her host system and they run this. It will ignore loading extra pam modules when entering the chroot? Or do they flat out need to disable pam on the host so they can take advantage of this for the chroot?
