diff options
| -rw-r--r-- | doc/guix.texi | 19 | ||||
| -rw-r--r-- | gnu/services/dbus.scm | 13 | ||||
| -rw-r--r-- | gnu/services/desktop.scm | 26 | ||||
| -rw-r--r-- | gnu/services/docker.scm | 9 | ||||
| -rw-r--r-- | gnu/services/xorg.scm | 4 | ||||
| -rw-r--r-- | gnu/system.scm | 33 |
6 files changed, 62 insertions, 42 deletions
diff --git a/doc/guix.texi b/doc/guix.texi index 3c23ae46c00..2298d512a1e 100644 --- a/doc/guix.texi +++ b/doc/guix.texi | |||
| @@ -13905,8 +13905,8 @@ Linux @dfn{pluggable authentication module} (PAM) services. | |||
| 13905 | @c FIXME: Add xref to PAM services section. | 13905 | @c FIXME: Add xref to PAM services section. |
| 13906 | 13906 | ||
| 13907 | @item @code{setuid-programs} (default: @code{%setuid-programs}) | 13907 | @item @code{setuid-programs} (default: @code{%setuid-programs}) |
| 13908 | List of string-valued G-expressions denoting setuid programs. | 13908 | List of @code{<setuid-program>}. @xref{Setuid Programs}, for more |
| 13909 | @xref{Setuid Programs}. | 13909 | information. |
| 13910 | 13910 | ||
| 13911 | @item @code{sudoers-file} (default: @code{%sudoers-specification}) | 13911 | @item @code{sudoers-file} (default: @code{%sudoers-specification}) |
| 13912 | @cindex sudoers file | 13912 | @cindex sudoers file |
| @@ -32389,13 +32389,15 @@ the store, we let the system administrator @emph{declare} which programs | |||
| 32389 | should be setuid root. | 32389 | should be setuid root. |
| 32390 | 32390 | ||
| 32391 | The @code{setuid-programs} field of an @code{operating-system} | 32391 | The @code{setuid-programs} field of an @code{operating-system} |
| 32392 | declaration contains a list of G-expressions denoting the names of | 32392 | declaration contains a list of @code{<setuid-program>} denoting the |
| 32393 | programs to be setuid-root (@pxref{Using the Configuration System}). | 32393 | names of programs to have a setuid or setgid bit set (@pxref{Using the |
| 32394 | For instance, the @command{passwd} program, which is part of the Shadow | 32394 | Configuration System}). For instance, the @command{passwd} program, |
| 32395 | package, can be designated by this G-expression (@pxref{G-Expressions}): | 32395 | which is part of the Shadow package, with a setuid root can be |
| 32396 | designated like this: | ||
| 32396 | 32397 | ||
| 32397 | @example | 32398 | @example |
| 32398 | #~(string-append #$shadow "/bin/passwd") | 32399 | (setuid-program |
| 32400 | (program (file-append #$shadow "/bin/passwd"))) | ||
| 32399 | @end example | 32401 | @end example |
| 32400 | 32402 | ||
| 32401 | @deftp {Data Type} setuid-program | 32403 | @deftp {Data Type} setuid-program |
| @@ -32426,7 +32428,8 @@ A default set of setuid programs is defined by the | |||
| 32426 | @code{%setuid-programs} variable of the @code{(gnu system)} module. | 32428 | @code{%setuid-programs} variable of the @code{(gnu system)} module. |
| 32427 | 32429 | ||
| 32428 | @defvr {Scheme Variable} %setuid-programs | 32430 | @defvr {Scheme Variable} %setuid-programs |
| 32429 | A list of G-expressions denoting common programs that are setuid-root. | 32431 | A list of @code{<setuid-program>} denoting common programs that are |
| 32432 | setuid-root. | ||
| 32430 | 32433 | ||
| 32431 | The list includes commands such as @command{passwd}, @command{ping}, | 32434 | The list includes commands such as @command{passwd}, @command{ping}, |
| 32432 | @command{su}, and @command{sudo}. | 32435 | @command{su}, and @command{sudo}. |
diff --git a/gnu/services/dbus.scm b/gnu/services/dbus.scm index af1a1e4c3a4..e7b3dac1668 100644 --- a/gnu/services/dbus.scm +++ b/gnu/services/dbus.scm | |||
| @@ -2,6 +2,7 @@ | |||
| 2 | ;;; Copyright © 2013, 2014, 2015, 2016, 2017, 2019, 2020 Ludovic Courtès <ludo@gnu.org> | 2 | ;;; Copyright © 2013, 2014, 2015, 2016, 2017, 2019, 2020 Ludovic Courtès <ludo@gnu.org> |
| 3 | ;;; Copyright © 2015 Sou Bunnbu <iyzsong@gmail.com> | 3 | ;;; Copyright © 2015 Sou Bunnbu <iyzsong@gmail.com> |
| 4 | ;;; Copyright © 2021 Maxime Devos <maximedevos@telenet.be> | 4 | ;;; Copyright © 2021 Maxime Devos <maximedevos@telenet.be> |
| 5 | ;;; Copyright © 2021 Brice Waegeneire <brice@waegenei.re> | ||
| 5 | ;;; | 6 | ;;; |
| 6 | ;;; This file is part of GNU Guix. | 7 | ;;; This file is part of GNU Guix. |
| 7 | ;;; | 8 | ;;; |
| @@ -21,6 +22,7 @@ | |||
| 21 | (define-module (gnu services dbus) | 22 | (define-module (gnu services dbus) |
| 22 | #:use-module (gnu services) | 23 | #:use-module (gnu services) |
| 23 | #:use-module (gnu services shepherd) | 24 | #:use-module (gnu services shepherd) |
| 25 | #:use-module (gnu system setuid) | ||
| 24 | #:use-module (gnu system shadow) | 26 | #:use-module (gnu system shadow) |
| 25 | #:use-module (gnu system pam) | 27 | #:use-module (gnu system pam) |
| 26 | #:use-module ((gnu packages glib) #:select (dbus)) | 28 | #:use-module ((gnu packages glib) #:select (dbus)) |
| @@ -156,10 +158,12 @@ includes the @code{etc/dbus-1/system.d} directories of each package listed in | |||
| 156 | (shell (file-append shadow "/sbin/nologin"))))) | 158 | (shell (file-append shadow "/sbin/nologin"))))) |
| 157 | 159 | ||
| 158 | (define dbus-setuid-programs | 160 | (define dbus-setuid-programs |
| 159 | ;; Return the file name of the setuid program that we need. | 161 | ;; Return a list of <setuid-program> for the program that we need. |
| 160 | (match-lambda | 162 | (match-lambda |
| 161 | (($ <dbus-configuration> dbus services) | 163 | (($ <dbus-configuration> dbus services) |
| 162 | (list (file-append dbus "/libexec/dbus-daemon-launch-helper"))))) | 164 | (list (setuid-program |
| 165 | (program (file-append | ||
| 166 | dbus "/libexec/dbus-daemon-launch-helper"))))))) | ||
| 163 | 167 | ||
| 164 | (define (dbus-activation config) | 168 | (define (dbus-activation config) |
| 165 | "Return an activation gexp for D-Bus using @var{config}." | 169 | "Return an activation gexp for D-Bus using @var{config}." |
| @@ -335,8 +339,9 @@ tuples, are all set as environment variables when the bus daemon launches it." | |||
| 335 | (define polkit-setuid-programs | 339 | (define polkit-setuid-programs |
| 336 | (match-lambda | 340 | (match-lambda |
| 337 | (($ <polkit-configuration> polkit) | 341 | (($ <polkit-configuration> polkit) |
| 338 | (list (file-append polkit "/lib/polkit-1/polkit-agent-helper-1") | 342 | (map file-like->setuid-program |
| 339 | (file-append polkit "/bin/pkexec"))))) | 343 | (list (file-append polkit "/lib/polkit-1/polkit-agent-helper-1") |
| 344 | (file-append polkit "/bin/pkexec")))))) | ||
| 340 | 345 | ||
| 341 | (define polkit-service-type | 346 | (define polkit-service-type |
| 342 | (service-type (name 'polkit) | 347 | (service-type (name 'polkit) |
diff --git a/gnu/services/desktop.scm b/gnu/services/desktop.scm index cd800fcc2bd..64d0e85301a 100644 --- a/gnu/services/desktop.scm +++ b/gnu/services/desktop.scm | |||
| @@ -12,6 +12,7 @@ | |||
| 12 | ;;; Copyright © 2019 David Wilson <david@daviwil.com> | 12 | ;;; Copyright © 2019 David Wilson <david@daviwil.com> |
| 13 | ;;; Copyright © 2020 Tobias Geerinckx-Rice <me@tobias.gr> | 13 | ;;; Copyright © 2020 Tobias Geerinckx-Rice <me@tobias.gr> |
| 14 | ;;; Copyright © 2020 Reza Alizadeh Majd <r.majd@pantherx.org> | 14 | ;;; Copyright © 2020 Reza Alizadeh Majd <r.majd@pantherx.org> |
| 15 | ;;; Copyright © 2021 Brice Waegeneire <brice@waegenei.re> | ||
| 15 | ;;; | 16 | ;;; |
| 16 | ;;; This file is part of GNU Guix. | 17 | ;;; This file is part of GNU Guix. |
| 17 | ;;; | 18 | ;;; |
| @@ -40,6 +41,7 @@ | |||
| 40 | #:use-module ((gnu system file-systems) | 41 | #:use-module ((gnu system file-systems) |
| 41 | #:select (%elogind-file-systems file-system)) | 42 | #:select (%elogind-file-systems file-system)) |
| 42 | #:use-module (gnu system) | 43 | #:use-module (gnu system) |
| 44 | #:use-module (gnu system setuid) | ||
| 43 | #:use-module (gnu system shadow) | 45 | #:use-module (gnu system shadow) |
| 44 | #:use-module (gnu system pam) | 46 | #:use-module (gnu system pam) |
| 45 | #:use-module (gnu packages glib) | 47 | #:use-module (gnu packages glib) |
| @@ -1034,14 +1036,15 @@ rules." | |||
| 1034 | 1036 | ||
| 1035 | (define (enlightenment-setuid-programs enlightenment-desktop-configuration) | 1037 | (define (enlightenment-setuid-programs enlightenment-desktop-configuration) |
| 1036 | (match-record enlightenment-desktop-configuration | 1038 | (match-record enlightenment-desktop-configuration |
| 1037 | <enlightenment-desktop-configuration> | 1039 | <enlightenment-desktop-configuration> |
| 1038 | (enlightenment) | 1040 | (enlightenment) |
| 1039 | (list (file-append enlightenment | 1041 | (map file-like->setuid-program |
| 1040 | "/lib/enlightenment/utils/enlightenment_sys") | 1042 | (list (file-append enlightenment |
| 1041 | (file-append enlightenment | 1043 | "/lib/enlightenment/utils/enlightenment_sys") |
| 1042 | "/lib/enlightenment/utils/enlightenment_system") | 1044 | (file-append enlightenment |
| 1043 | (file-append enlightenment | 1045 | "/lib/enlightenment/utils/enlightenment_system") |
| 1044 | "/lib/enlightenment/utils/enlightenment_ckpasswd")))) | 1046 | (file-append enlightenment |
| 1047 | "/lib/enlightenment/utils/enlightenment_ckpasswd"))))) | ||
| 1045 | 1048 | ||
| 1046 | (define enlightenment-desktop-service-type | 1049 | (define enlightenment-desktop-service-type |
| 1047 | (service-type | 1050 | (service-type |
| @@ -1204,8 +1207,11 @@ or setting its password with passwd."))) | |||
| 1204 | ;; Allow desktop users to also mount NTFS and NFS file systems | 1207 | ;; Allow desktop users to also mount NTFS and NFS file systems |
| 1205 | ;; without root. | 1208 | ;; without root. |
| 1206 | (simple-service 'mount-setuid-helpers setuid-program-service-type | 1209 | (simple-service 'mount-setuid-helpers setuid-program-service-type |
| 1207 | (list (file-append nfs-utils "/sbin/mount.nfs") | 1210 | (map (lambda (program) |
| 1208 | (file-append ntfs-3g "/sbin/mount.ntfs-3g"))) | 1211 | (setuid-program |
| 1212 | (program program))) | ||
| 1213 | (list (file-append nfs-utils "/sbin/mount.nfs") | ||
| 1214 | (file-append ntfs-3g "/sbin/mount.ntfs-3g")))) | ||
| 1209 | 1215 | ||
| 1210 | ;; The global fontconfig cache directory can sometimes contain | 1216 | ;; The global fontconfig cache directory can sometimes contain |
| 1211 | ;; stale entries, possibly referencing fonts that have been GC'd, | 1217 | ;; stale entries, possibly referencing fonts that have been GC'd, |
diff --git a/gnu/services/docker.scm b/gnu/services/docker.scm index be85316180a..ef551480aad 100644 --- a/gnu/services/docker.scm +++ b/gnu/services/docker.scm | |||
| @@ -4,6 +4,7 @@ | |||
| 4 | ;;; Copyright © 2020, 2021 Maxim Cournoyer <maxim.cournoyer@gmail.com> | 4 | ;;; Copyright © 2020, 2021 Maxim Cournoyer <maxim.cournoyer@gmail.com> |
| 5 | ;;; Copyright © 2020 Efraim Flashner <efraim@flashner.co.il> | 5 | ;;; Copyright © 2020 Efraim Flashner <efraim@flashner.co.il> |
| 6 | ;;; Copyright © 2020 Jesse Dowell <jessedowell@gmail.com> | 6 | ;;; Copyright © 2020 Jesse Dowell <jessedowell@gmail.com> |
| 7 | ;;; Copyright © 2021 Brice Waegeneire <brice@waegenei.re> | ||
| 7 | ;;; | 8 | ;;; |
| 8 | ;;; This file is part of GNU Guix. | 9 | ;;; This file is part of GNU Guix. |
| 9 | ;;; | 10 | ;;; |
| @@ -26,6 +27,7 @@ | |||
| 26 | #:use-module (gnu services base) | 27 | #:use-module (gnu services base) |
| 27 | #:use-module (gnu services dbus) | 28 | #:use-module (gnu services dbus) |
| 28 | #:use-module (gnu services shepherd) | 29 | #:use-module (gnu services shepherd) |
| 30 | #:use-module (gnu system setuid) | ||
| 29 | #:use-module (gnu system shadow) | 31 | #:use-module (gnu system shadow) |
| 30 | #:use-module (gnu packages docker) | 32 | #:use-module (gnu packages docker) |
| 31 | #:use-module (gnu packages linux) ;singularity | 33 | #:use-module (gnu packages linux) ;singularity |
| @@ -195,9 +197,10 @@ bundles in Docker containers.") | |||
| 195 | "-helper"))) | 197 | "-helper"))) |
| 196 | '("action" "mount" "start"))))) | 198 | '("action" "mount" "start"))))) |
| 197 | 199 | ||
| 198 | (list (file-append helpers "/singularity-action-helper") | 200 | (map file-like->setuid-program |
| 199 | (file-append helpers "/singularity-mount-helper") | 201 | (list (file-append helpers "/singularity-action-helper") |
| 200 | (file-append helpers "/singularity-start-helper"))) | 202 | (file-append helpers "/singularity-mount-helper") |
| 203 | (file-append helpers "/singularity-start-helper")))) | ||
| 201 | 204 | ||
| 202 | (define singularity-service-type | 205 | (define singularity-service-type |
| 203 | (service-type (name 'singularity) | 206 | (service-type (name 'singularity) |
diff --git a/gnu/services/xorg.scm b/gnu/services/xorg.scm index 8ffea3b9dd0..d95f8beb7a0 100644 --- a/gnu/services/xorg.scm +++ b/gnu/services/xorg.scm | |||
| @@ -8,6 +8,7 @@ | |||
| 8 | ;;; Copyright © 2020 shtwzrd <shtwzrd@protonmail.com> | 8 | ;;; Copyright © 2020 shtwzrd <shtwzrd@protonmail.com> |
| 9 | ;;; Copyright © 2020 Jakub Kądziołka <kuba@kadziolka.net> | 9 | ;;; Copyright © 2020 Jakub Kądziołka <kuba@kadziolka.net> |
| 10 | ;;; Copyright © 2020 Alex Griffin <a@ajgrf.com> | 10 | ;;; Copyright © 2020 Alex Griffin <a@ajgrf.com> |
| 11 | ;;; Copyright © 2021 Brice Waegeneire <brice@waegenei.re> | ||
| 11 | ;;; | 12 | ;;; |
| 12 | ;;; This file is part of GNU Guix. | 13 | ;;; This file is part of GNU Guix. |
| 13 | ;;; | 14 | ;;; |
| @@ -29,6 +30,7 @@ | |||
| 29 | #:use-module (gnu services) | 30 | #:use-module (gnu services) |
| 30 | #:use-module (gnu services shepherd) | 31 | #:use-module (gnu services shepherd) |
| 31 | #:use-module (gnu system pam) | 32 | #:use-module (gnu system pam) |
| 33 | #:use-module (gnu system setuid) | ||
| 32 | #:use-module (gnu system keyboard) | 34 | #:use-module (gnu system keyboard) |
| 33 | #:use-module (gnu services base) | 35 | #:use-module (gnu services base) |
| 34 | #:use-module (gnu services dbus) | 36 | #:use-module (gnu services dbus) |
| @@ -681,7 +683,7 @@ reboot_cmd " shepherd "/sbin/reboot\n" | |||
| 681 | #:allow-empty-passwords? empty?))))) | 683 | #:allow-empty-passwords? empty?))))) |
| 682 | 684 | ||
| 683 | (define screen-locker-setuid-programs | 685 | (define screen-locker-setuid-programs |
| 684 | (compose list screen-locker-program)) | 686 | (compose list file-like->setuid-program screen-locker-program)) |
| 685 | 687 | ||
| 686 | (define screen-locker-service-type | 688 | (define screen-locker-service-type |
| 687 | (service-type (name 'screen-locker) | 689 | (service-type (name 'screen-locker) |
diff --git a/gnu/system.scm b/gnu/system.scm index 11e7152be1b..7e11d38c59c 100644 --- a/gnu/system.scm +++ b/gnu/system.scm | |||
| @@ -1074,22 +1074,23 @@ use 'plain-file' instead~%") | |||
| 1074 | (define %setuid-programs | 1074 | (define %setuid-programs |
| 1075 | ;; Default set of setuid-root programs. | 1075 | ;; Default set of setuid-root programs. |
| 1076 | (let ((shadow (@ (gnu packages admin) shadow))) | 1076 | (let ((shadow (@ (gnu packages admin) shadow))) |
| 1077 | (list (file-append shadow "/bin/passwd") | 1077 | (map file-like->setuid-program |
| 1078 | (file-append shadow "/bin/sg") | 1078 | (list (file-append shadow "/bin/passwd") |
| 1079 | (file-append shadow "/bin/su") | 1079 | (file-append shadow "/bin/sg") |
| 1080 | (file-append shadow "/bin/newgrp") | 1080 | (file-append shadow "/bin/su") |
| 1081 | (file-append shadow "/bin/newuidmap") | 1081 | (file-append shadow "/bin/newgrp") |
| 1082 | (file-append shadow "/bin/newgidmap") | 1082 | (file-append shadow "/bin/newuidmap") |
| 1083 | (file-append inetutils "/bin/ping") | 1083 | (file-append shadow "/bin/newgidmap") |
| 1084 | (file-append inetutils "/bin/ping6") | 1084 | (file-append inetutils "/bin/ping") |
| 1085 | (file-append sudo "/bin/sudo") | 1085 | (file-append inetutils "/bin/ping6") |
| 1086 | (file-append sudo "/bin/sudoedit") | 1086 | (file-append sudo "/bin/sudo") |
| 1087 | (file-append fuse "/bin/fusermount") | 1087 | (file-append sudo "/bin/sudoedit") |
| 1088 | 1088 | (file-append fuse "/bin/fusermount") | |
| 1089 | ;; To allow mounts with the "user" option, "mount" and "umount" must | 1089 | |
| 1090 | ;; be setuid-root. | 1090 | ;; To allow mounts with the "user" option, "mount" and "umount" must |
| 1091 | (file-append util-linux "/bin/mount") | 1091 | ;; be setuid-root. |
| 1092 | (file-append util-linux "/bin/umount")))) | 1092 | (file-append util-linux "/bin/mount") |
| 1093 | (file-append util-linux "/bin/umount"))))) | ||
| 1093 | 1094 | ||
| 1094 | (define %sudoers-specification | 1095 | (define %sudoers-specification |
| 1095 | ;; Default /etc/sudoers contents: 'root' and all members of the 'wheel' | 1096 | ;; Default /etc/sudoers contents: 'root' and all members of the 'wheel' |
