Debian Bug report logs -
#261980
gnome-session: Shutdown/reboot option does not ask for password
Reported by: Jaume <j2003gi@yahoo.es>
Date: Thu, 29 Jul 2004 11:03:03 UTC
Severity: important
Merged with 265535
Fixed in version gdm/2.13.0.10-1
Done: Ryan Murray <rmurray@debian.org>
Bug is archived. No further changes may be made.
Toggle useless messages
Report forwarded to debian-bugs-dist@lists.debian.org, Josselin Mouette <joss@debian.org>:
Bug#261980; Package gnome-session.
(full text, mbox, link).
Acknowledgement sent to Jaume <j2003gi@yahoo.es>:
New Bug report received and forwarded. Copy sent to Josselin Mouette <joss@debian.org>.
(full text, mbox, link).
Message #5 received at submit@bugs.debian.org (full text, mbox, reply):
Package: gnome-session
Version: 2.6.2-4
Severity: important
Dear Debian Developers,
The new feature to shutdown/reboot the machine on the logout does not ask
for the root password.
.- Behaviour:
1.- I logout from my gnome session (or run gnome-session-save --kill),
2.- A menu is shown asking whether logout/shutdown/reboot
3.- I choose reboot
4.- The machine reboots without asking for a password
.- Expected behaviour:
.- After point 3 above, I should be asked for the root password, in order
to proceed with the reboot (and the machine should not reboot if the
password is wrong).
This could cause data loss, if some other user is logged in remotelly (via ssh)
or in a text console. Only users authorised by root should be able to reboot
the machine. (NOTE: gdm allows me to reboot the machine, but it asks for the
root password before proceeding)
Best regards, and thank you for your work,
Jaume
-- System Information:
Debian Release: 3.1
APT prefers testing
APT policy: (500, 'testing'), (105, 'unstable')
Architecture: i386 (i686)
Kernel: Linux 2.6.7alcatel
Locale: LANG=C, LC_CTYPE=C
Versions of packages gnome-session depends on:
ii desktop-base 0.3.14 common files for the Debian Deskto
ii libart-2.0-2 2.3.16-6 Library of functions for 2D graphi
ii libatk1.0-0 1.6.1-2 The ATK accessibility toolkit
ii libaudiofile0 0.2.6-4 Open-source version of SGI's audio
ii libbonobo2-0 2.6.2-5 Bonobo CORBA interfaces library
ii libbonoboui2-0 2.6.1-1 The Bonobo UI library
ii libc6 2.3.2.ds1-13 GNU C Library: Shared libraries an
ii libesd0 0.2.29-1 Enlightened Sound Daemon - Shared
ii libgconf2-4 2.6.2-1 GNOME configuration database syste
ii libglib2.0-0 2.4.4-1 The GLib library of C routines
ii libgnome2-0 2.6.1-8 The GNOME 2 library - runtime file
ii libgnomecanvas2-0 2.6.1.1-2 A powerful object-oriented display
ii libgnomeui-0 2.6.1.1-3 The GNOME 2 libraries (User Interf
ii libgnomevfs2-0 2.6.1.1-5 The GNOME virtual file-system libr
ii libgtk2.0-0 2.4.4-1 The GTK+ graphical user interface
ii libice6 4.3.0.dfsg.1-6 Inter-Client Exchange library
ii liborbit2 1:2.10.2-1.1 libraries for ORBit2 - a CORBA ORB
ii libpango1.0-0 1.4.0-4 Layout and rendering of internatio
ii libpopt0 1.7-4 lib for parsing cmdline parameters
ii libsm6 4.3.0.dfsg.1-6 X Window System Session Management
ii libwrap0 7.6.dbs-4 Wietse Venema's TCP wrappers libra
ii libx11-6 4.3.0.dfsg.1-6 X Window System protocol client li
ii libxml2 2.6.11-2 GNOME XML library
ii libxmu6 4.3.0.dfsg.1-6 X Window System miscellaneous util
ii libxrandr2 4.3.0.dfsg.1-6 X Window System Resize, Rotate and
ii libxrender1 0.8.3-7 X Rendering Extension client libra
ii libxt6 4.3.0.dfsg.1-6 X Toolkit Intrinsics
ii xlibs 4.3.0.dfsg.1-6 X Window System client libraries m
ii zlib1g 1:1.2.1.1-5 compression library - runtime
-- no debconf information
Information forwarded to debian-bugs-dist@lists.debian.org:
Bug#261980; Package gnome-session.
(full text, mbox, link).
Acknowledgement sent to Josselin Mouette <joss@debian.org>:
Extra info received and forwarded to list.
(full text, mbox, link).
Message #10 received at 261980@bugs.debian.org (full text, mbox, reply):
[Message part 1 (text/plain, inline)]
reassign 261980 gdm
thanks
On jeu, 2004-07-29 at 12:53 +0200, Jaume wrote:
> The new feature to shutdown/reboot the machine on the logout does not ask
> for the root password.
> This could cause data loss, if some other user is logged in remotelly (via ssh)
> or in a text console. Only users authorised by root should be able to reboot
> the machine. (NOTE: gdm allows me to reboot the machine, but it asks for the
> root password before proceeding)
All the security is delegated to GDM, as this feature only calls
gdmflexiserver and asks for shutdown using the SUP protocol. As such,
this should probably be handled by GDM.
--
.''`. Josselin Mouette /\./\
: :' : josselin.mouette@ens-lyon.org
`. `' joss@debian.org
`- Debian GNU/Linux -- The power of freedom
[signature.asc (application/pgp-signature, inline)]
Reply sent to Ryan Murray <rmurray@debian.org>:
You have taken responsibility.
(full text, mbox, link).
Notification sent to Jaume <j2003gi@yahoo.es>:
Bug acknowledged by developer.
(full text, mbox, link).
Message #23 received at 261980-close@bugs.debian.org (full text, mbox, reply):
Source: gdm
Source-Version: 2.13.0.10-1
We believe that the bug you reported is fixed in the latest version of
gdm, which is due to be installed in the Debian FTP archive:
gdm_2.13.0.10-1.diff.gz
to pool/main/g/gdm/gdm_2.13.0.10-1.diff.gz
gdm_2.13.0.10-1.dsc
to pool/main/g/gdm/gdm_2.13.0.10-1.dsc
gdm_2.13.0.10-1_i386.deb
to pool/main/g/gdm/gdm_2.13.0.10-1_i386.deb
gdm_2.13.0.10.orig.tar.gz
to pool/main/g/gdm/gdm_2.13.0.10.orig.tar.gz
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 261980@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Ryan Murray <rmurray@debian.org> (supplier of updated gdm package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Sat, 11 Mar 2006 14:51:15 -0800
Source: gdm
Binary: gdm
Architecture: source i386
Version: 2.13.0.10-1
Distribution: unstable
Urgency: low
Maintainer: Ryan Murray <rmurray@debian.org>
Changed-By: Ryan Murray <rmurray@debian.org>
Description:
gdm - GNOME Display Manager
Closes: 252543 261980 277953 284613 340840 342113 344910 346096 348872
Changes:
gdm (2.13.0.10-1) unstable; urgency=low
.
* New upstream release
+ two-level config (closes: #252543)
* Add build-depends on libxdmcp-dev, libxinerama-dev (closes: #340840, #342113)
* Relibtoolize (closes: #344910)
* Add dependency on lsb-base (closes: #346096)
* Add "Display Manager" hint to menu file (closes: #284613)
* Depend on librsvg2-common (closes: #348872)
* Update debconf template translations
* Update locale.conf against locales 2.3.6-3
* Take patch to XKeepsCrashing from Ubuntu that restores the keyboard
to xlate mode before trying to interact with the user.
* Drop ungnomeish SecureSysMenu patch. (closes: #261980)
* Set $HOME to /etc/X11 when starting the X server, causing the code
that looks for $HOME/xorg.conf before other files in /etc to look
at our configfile, and not one that might be in root's homedir.
(closes #250438)
* Confirmed that the new version correctly works with utf-8 locales
(closes: #277953)
Files:
dc2faa55618c7d7a17b08dca412f1f43 752 gnome optional gdm_2.13.0.10-1.dsc
72a84d9298f099e41c284d1c9eef25ae 4492917 gnome optional gdm_2.13.0.10.orig.tar.gz
cd69864a7716f8fef5796fd77b353336 252651 gnome optional gdm_2.13.0.10-1.diff.gz
39af0d3c9858f69ad78bd8aa1a627e8e 3676330 gnome optional gdm_2.13.0.10-1_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)
iD8DBQFEFQNHN2Dbz/1mRasRAsyaAKDkY2ursznPOfMK3pV5Ab/T5ScoWgCghZCp
E5Zk2CggrujBhYx/5MPXEB8=
=lYJx
-----END PGP SIGNATURE-----
Bug archived.
Request was from Debbugs Internal Request <owner@bugs.debian.org>
to internal_control@bugs.debian.org.
(Mon, 25 Jun 2007 04:50:28 GMT) (full text, mbox, link).
Send a report that this bug log contains spam.
Debian bug tracking system administrator <owner@bugs.debian.org>.
Last modified:
Sun Jun 4 20:14:42 2023;
Machine Name:
buxtehude
Debian Bug tracking system
Debbugs is free software and licensed under the terms of the GNU
Public License version 2. The current version can be obtained
from https://bugs.debian.org/debbugs-source/.
Copyright © 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd,
1994-97 Ian Jackson,
2005-2017 Don Armstrong, and many other contributors.