]> git.saurik.com Git - apt.git/commitdiff
Ensure /etc/apt/auth.conf has _apt:root owner
authorMichael Vogt <mvo@debian.org>
Tue, 21 Oct 2014 15:19:45 +0000 (11:19 -0400)
committerMichael Vogt <mvo@debian.org>
Tue, 21 Oct 2014 15:19:45 +0000 (11:19 -0400)
Ensure in SetupAPTPartialDirectory() that the /etc/apt/auth.conf file
can be read by the priv sep apt methods.

apt-pkg/acquire.cc
debian/apt.postinst

index 1aa709381b98f8a362ef3eb761024d959b44437b..033fa9bd3caabed826cc86744d6e1cb8ad0a0fdc 100644 (file)
@@ -86,8 +86,16 @@ static bool SetupAPTPartialDirectory(std::string const &grand, std::string const
       std::string SandboxUser = _config->Find("APT::Sandbox::User");
       struct passwd *pw = getpwnam(SandboxUser.c_str());
       struct group *gr = getgrnam("root");
-      if (pw != NULL && gr != NULL && chown(partial.c_str(), pw->pw_uid, gr->gr_gid) != 0)
-        _error->WarningE("SetupAPTPartialDirectory", "chown to %s:root of directory %s failed", SandboxUser.c_str(), partial.c_str());
+      if (pw != NULL && gr != NULL)
+      {
+         // chown the partial dir
+         if(chown(partial.c_str(), pw->pw_uid, gr->gr_gid) != 0)
+            _error->WarningE("SetupAPTPartialDirectory", "chown to %s:root of directory %s failed", SandboxUser.c_str(), partial.c_str());
+         // chown the auth.conf file
+         std::string AuthConf = _config->FindFile("Dir::Etc::netrc");
+         if(chown(AuthConf.c_str(), pw->pw_uid, gr->gr_gid) != 0)
+            _error->WarningE("SetupAPTPartialDirectory", "chown to %s:root of file %s failed", SandboxUser.c_str(), AuthConf.c_str());
+      }
    }
    if (chmod(partial.c_str(), 0700) != 0)
       _error->WarningE("SetupAPTPartialDirectory", "chmod 0700 of directory %s failed", partial.c_str());
index bcc18b4e5306b03443089b1a2ed3f04ebc6ec7fb..b0a5da7d85d7cb5c5ba46c65a15b63fc83be6f0c 100755 (executable)
@@ -43,11 +43,6 @@ case "$1" in
        adduser --force-badname --system -home /var/empty \
            --no-create-home --quiet _apt || true
 
-        # ensure the passwords can still be read by the methods
-        if [ -e /etc/apt/auth.conf ]; then
-            chown _apt:root /etc/apt/auth.conf
-        fi
-
        # deal with upgrades from experimental
        if dpkg --compare-versions "$2" 'eq' '1.1~exp3'; then
            # libapt will setup partial/ at runtime