Type:
Bug
Priority:
Critical
Resolution:
Fixed
Affects Version/s:
10.5.18 , 10.9.4 , 10.11.2 , 11.0.1 , 10.5.19 , 10.6.12 , 10.7.8 , 10.8.7 , 10.10.3
Our MariaDB-server RPM creates auth_pam_tool_dir with owner root, and only later in the post install hook script change the ownership to the mysql system user.
When running
rpm --setguids MariaDB-server
the directory owner is reset from "mysql" to "root", and with that and the "owner only" permissions of that directory, the auth_pam_tool utility contained by it can no longer be executed by the server, so breaking PAM authentication completely.
Looking at the plugin/auth_pam/CMakeLists.txt file I can see:
SET(CPACK_RPM_server_USER_FILELIST ${CPACK_RPM_server_USER_FILELIST}
"%attr(700,-,-) ${INSTALL_PLUGINDIRABS}/auth_pam_tool_dir"
"%attr(4755,-,-) ${INSTALL_PLUGINDIRABS}/auth_pam_tool_dir/auth_pam_tool")
So the directory permissions are set there, but not the owner. By changing this to
SET(CPACK_RPM_server_USER_FILELIST ${CPACK_RPM_server_USER_FILELIST}
"%attr(700,mysql,-) ${INSTALL_PLUGINDIRABS}/auth_pam_tool_dir"
"%attr(4755,-,-) ${INSTALL_PLUGINDIRABS}/auth_pam_tool_dir/auth_pam_tool")
the explicit chmod in the post install hook script should no longer be needed, and "rpm -setugids" should keep the correct ownership intact.
Julien Fritsch
made changes -
2023-03-23 16:37
Field
Original Value
New Value
Fix Version/s
10.4
[ 22408
]
Fix Version/s
10.5
[ 23123
]
Fix Version/s
10.6
[ 24028
]
Fix Version/s
10.3
[ 22126
]
Sergei Golubchik
made changes -
2023-03-27 12:23
Assignee
Julien Fritsch
[ julien.fritsch
]
Julien Fritsch
made changes -
2023-03-27 12:27
Fix Version/s
10.3
[ 22126
]
Fix Version/s
10.4
[ 22408
]
Fix Version/s
10.6
[ 24028
]
Julien Fritsch
made changes -
2023-03-27 12:27
Assignee
Julien Fritsch
[ julien.fritsch
]
Sergei Golubchik
[ serg
]
Hartmut Holzgraefe
made changes -
2023-03-27 13:05
Affects Version/s
10.10.3
[ 28521
]
Affects Version/s
10.8.7
[ 28517
]
Affects Version/s
10.7.8
[ 28515
]
Affects Version/s
10.6.12
[ 28513
]
Affects Version/s
10.5.19
[ 28511
]
Affects Version/s
10.9.4
[ 28444
]
Affects Version/s
11.0.1
[ 28548
]
Affects Version/s
10.11.2
[ 28523
]
Julien Fritsch
made changes -
2023-03-27 13:08
Fix Version/s
10.9
[ 26905
]
Fix Version/s
10.11
[ 27614
]
Fix Version/s
11.0
[ 28320
]
Julien Fritsch
made changes -
2023-03-27 13:08
Fix Version/s
10.6
[ 24028
]
Fix Version/s
10.7
[ 24805
]
Fix Version/s
10.8
[ 26121
]
Julien Fritsch
made changes -
2023-04-03 07:15
Fix Version/s
10.7
[ 24805
]
Julien Fritsch
made changes -
2023-04-27 14:45
Fix Version/s
10.8
[ 26121
]
Sergei Golubchik
made changes -
2023-06-27 17:16
Status
Open
[ 1
]
Needs Feedback
[ 10501
]
Julien Fritsch
made changes -
2023-07-24 07:29
Priority
Major
[ 3
]
Critical
[ 2
]
Sergei Golubchik
made changes -
2023-08-02 13:55
Status
Needs Feedback
[ 10501
]
Open
[ 1
]
Sergei Golubchik
made changes -
2023-08-07 19:02
Status
Open
[ 1
]
In Progress
[ 3
]
Sergei Golubchik
made changes -
2023-08-07 19:02
Status
In Progress
[ 3
]
Stalled
[ 10000
]
Sergei Golubchik
made changes -
2023-08-07 19:02
Status
Stalled
[ 10000
]
In Testing
[ 10301
]
Sergei Golubchik
made changes -
2023-09-07 07:24
Fix Version/s
10.4.32
[ 29300
]
Fix Version/s
10.5.23
[ 29012
]
Fix Version/s
10.6.16
[ 29014
]
Fix Version/s
10.10.7
[ 29018
]
Fix Version/s
10.11.6
[ 29020
]
Fix Version/s
11.0.4
[ 29021
]
Fix Version/s
11.1.3
[ 29023
]
Fix Version/s
10.4
[ 22408
]
Fix Version/s
10.5
[ 23123
]
Fix Version/s
10.6
[ 24028
]
Fix Version/s
10.9
[ 26905
]
Fix Version/s
10.11
[ 27614
]
Fix Version/s
11.0
[ 28320
]
Resolution
Fixed
[ 1
]
Status
In Testing
[ 10301
]
Closed
[ 6
]
{"report":{"fcp":1718.2999997138977,"ttfb":520.5,"pageVisibility":"visible","entityId":120440,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":0.5,"journeyId":"acedfd40-6a64-49ac-ab43-744ac7a16c6c","navigationType":0,"readyForUser":1806.0999999046326,"redirectCount":0,"resourceLoadedEnd":1418.4000000953674,"resourceLoadedStart":526.9000000953674,"resourceTiming":[{"duration":198.39999961853027,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":526.9000000953674,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":526.9000000953674,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":725.2999997138977,"responseStart":0,"secureConnectionStart":0},{"duration":199.5,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":527.1999998092651,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":527.1999998092651,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":726.6999998092651,"responseStart":0,"secureConnectionStart":0},{"duration":511.7999997138977,"initiatorType":"script","name":"https://jira.mariadb.org/s/0917945aaa57108d00c5076fea35e069-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":527.4000000953674,"connectEnd":527.4000000953674,"connectStart":527.4000000953674,"domainLookupEnd":527.4000000953674,"domainLookupStart":527.4000000953674,"fetchStart":527.4000000953674,"redirectEnd":0,"redirectStart":0,"requestStart":730.5,"responseEnd":1039.1999998092651,"responseStart":751.2999997138977,"secureConnectionStart":527.4000000953674},{"duration":804.0999999046326,"initiatorType":"script","name":"https://jira.mariadb.org/s/2d8175ec2fa4c816e8023260bd8c1786-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true&whisper-enabled=true","startTime":527.5999999046326,"connectEnd":527.5999999046326,"connectStart":527.5999999046326,"domainLookupEnd":527.5999999046326,"domainLookupStart":527.5999999046326,"fetchStart":527.5999999046326,"redirectEnd":0,"redirectStart":0,"requestStart":733.7999997138977,"responseEnd":1331.6999998092651,"responseStart":756.5,"secureConnectionStart":527.5999999046326},{"duration":232.7000002861023,"initiatorType":"script","name":"https://jira.mariadb.org/s/a9324d6758d385eb45c462685ad88f1d-CDN/lu2cib/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":527.7999997138977,"connectEnd":527.7999997138977,"connectStart":527.7999997138977,"domainLookupEnd":527.7999997138977,"domainLookupStart":527.7999997138977,"fetchStart":527.7999997138977,"redirectEnd":0,"redirectStart":0,"requestStart":734,"responseEnd":760.5,"responseStart":758.5,"secureConnectionStart":527.7999997138977},{"duration":232.59999990463257,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":528,"connectEnd":528,"connectStart":528,"domainLookupEnd":528,"domainLookupStart":528,"fetchStart":528,"redirectEnd":0,"redirectStart":0,"requestStart":734.0999999046326,"responseEnd":760.5999999046326,"responseStart":759,"secureConnectionStart":528},{"duration":236.7000002861023,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":528.1999998092651,"connectEnd":528.1999998092651,"connectStart":528.1999998092651,"domainLookupEnd":528.1999998092651,"domainLookupStart":528.1999998092651,"fetchStart":528.1999998092651,"redirectEnd":0,"redirectStart":0,"requestStart":738.2999997138977,"responseEnd":764.9000000953674,"responseStart":762.2999997138977,"secureConnectionStart":528.1999998092651},{"duration":206.69999980926514,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2cib/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":528.4000000953674,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":528.4000000953674,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":735.0999999046326,"responseStart":0,"secureConnectionStart":0},{"duration":207.09999990463257,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":528.5999999046326,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":528.5999999046326,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":735.6999998092651,"responseStart":0,"secureConnectionStart":0},{"duration":236.5,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":528.5999999046326,"connectEnd":528.5999999046326,"connectStart":528.5999999046326,"domainLookupEnd":528.5999999046326,"domainLookupStart":528.5999999046326,"fetchStart":528.5999999046326,"redirectEnd":0,"redirectStart":0,"requestStart":738.5999999046326,"responseEnd":765.0999999046326,"responseStart":762.6999998092651,"secureConnectionStart":528.5999999046326},{"duration":238.40000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/s/5d5e8fe91fbc506585e83ea3b62ccc4b-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":528.7999997138977,"connectEnd":528.7999997138977,"connectStart":528.7999997138977,"domainLookupEnd":528.7999997138977,"domainLookupStart":528.7999997138977,"fetchStart":528.7999997138977,"redirectEnd":0,"redirectStart":0,"requestStart":743,"responseEnd":767.1999998092651,"responseStart":763.4000000953674,"secureConnectionStart":528.7999997138977},{"duration":878.3000001907349,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":529.6999998092651,"connectEnd":529.6999998092651,"connectStart":529.6999998092651,"domainLookupEnd":529.6999998092651,"domainLookupStart":529.6999998092651,"fetchStart":529.6999998092651,"redirectEnd":0,"redirectStart":0,"requestStart":1017.7999997138977,"responseEnd":1408,"responseStart":1375.5,"secureConnectionStart":529.6999998092651},{"duration":883.7000002861023,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":534.6999998092651,"connectEnd":534.6999998092651,"connectStart":534.6999998092651,"domainLookupEnd":534.6999998092651,"domainLookupStart":534.6999998092651,"fetchStart":534.6999998092651,"redirectEnd":0,"redirectStart":0,"requestStart":1336.7999997138977,"responseEnd":1418.4000000953674,"responseStart":1403.5,"secureConnectionStart":534.6999998092651},{"duration":233.7999997138977,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":1213,"connectEnd":1213,"connectStart":1213,"domainLookupEnd":1213,"domainLookupStart":1213,"fetchStart":1213,"redirectEnd":0,"redirectStart":0,"requestStart":1407.7999997138977,"responseEnd":1446.7999997138977,"responseStart":1445.5,"secureConnectionStart":1213},{"duration":419.40000009536743,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":1604.0999999046326,"connectEnd":1604.0999999046326,"connectStart":1604.0999999046326,"domainLookupEnd":1604.0999999046326,"domainLookupStart":1604.0999999046326,"fetchStart":1604.0999999046326,"redirectEnd":0,"redirectStart":0,"requestStart":1991.2999997138977,"responseEnd":2023.5,"responseStart":2022.4000000953674,"secureConnectionStart":1604.0999999046326}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":243,"responseStart":520,"responseEnd":528,"domLoading":524,"domInteractive":1903,"domContentLoadedEventStart":1903,"domContentLoadedEventEnd":1993,"domComplete":3243,"loadEventStart":3243,"loadEventEnd":3244,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":1859.9000000953674},{"name":"bigPipe.sidebar-id.end","time":1860.6999998092651},{"name":"bigPipe.activity-panel-pipe-id.start","time":1861},{"name":"bigPipe.activity-panel-pipe-id.end","time":1868.5999999046326},{"name":"activityTabFullyLoaded","time":2025.5999999046326}],"measures":[],"correlationId":"b1c6314c506cb3","effectiveType":"4g","downlink":10,"rtt":0,"serverDuration":207,"dbReadsTimeInMs":31,"dbConnsTimeInMs":42,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}
Affected versions determined by checking that respective versions support-files/rpm/server-postin.sh contains a chown for auth_pam_tool_dir