Debian Bug report logs - #261980
gnome-session: Shutdown/reboot option does not ask for password

version graph

Package: gdm; Maintainer for gdm is (unknown);

Reported by: Jaume <j2003gi@yahoo.es>

Date: Thu, 29 Jul 2004 11:03:03 UTC

Severity: important

Merged with 265535

Fixed in version gdm/2.13.0.10-1

Done: Ryan Murray <rmurray@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Josselin Mouette <joss@debian.org>:
Bug#261980; Package gnome-session. (full text, mbox, link).


Acknowledgement sent to Jaume <j2003gi@yahoo.es>:
New Bug report received and forwarded. Copy sent to Josselin Mouette <joss@debian.org>. (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Jaume <j2003gi@yahoo.es>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: gnome-session: Shutdown/reboot option does not ask for password
Date: Thu, 29 Jul 2004 12:53:03 +0200
Package: gnome-session
Version: 2.6.2-4
Severity: important

Dear Debian Developers,

The new feature to shutdown/reboot the machine on the logout does not ask
for the root password.

.- Behaviour: 
   1.- I logout from my gnome session (or run gnome-session-save --kill), 
   2.- A menu is shown asking whether logout/shutdown/reboot
   3.- I choose reboot
   4.- The machine reboots without asking for a password 

.- Expected behaviour:
   .- After point 3 above, I should be asked for the root password, in order
      to proceed with the reboot (and the machine should not reboot if the
      password is wrong).

This could cause data loss, if some other user is logged in remotelly (via ssh) 
or in a text console. Only users authorised by root should be able to reboot
the machine. (NOTE: gdm allows me to reboot the machine, but it asks for the
root password before proceeding)

Best regards, and thank you for your work,

Jaume

-- System Information:
Debian Release: 3.1
  APT prefers testing
  APT policy: (500, 'testing'), (105, 'unstable')
Architecture: i386 (i686)
Kernel: Linux 2.6.7alcatel
Locale: LANG=C, LC_CTYPE=C

Versions of packages gnome-session depends on:
ii  desktop-base              0.3.14         common files for the Debian Deskto
ii  libart-2.0-2              2.3.16-6       Library of functions for 2D graphi
ii  libatk1.0-0               1.6.1-2        The ATK accessibility toolkit
ii  libaudiofile0             0.2.6-4        Open-source version of SGI's audio
ii  libbonobo2-0              2.6.2-5        Bonobo CORBA interfaces library
ii  libbonoboui2-0            2.6.1-1        The Bonobo UI library
ii  libc6                     2.3.2.ds1-13   GNU C Library: Shared libraries an
ii  libesd0                   0.2.29-1       Enlightened Sound Daemon - Shared 
ii  libgconf2-4               2.6.2-1        GNOME configuration database syste
ii  libglib2.0-0              2.4.4-1        The GLib library of C routines
ii  libgnome2-0               2.6.1-8        The GNOME 2 library - runtime file
ii  libgnomecanvas2-0         2.6.1.1-2      A powerful object-oriented display
ii  libgnomeui-0              2.6.1.1-3      The GNOME 2 libraries (User Interf
ii  libgnomevfs2-0            2.6.1.1-5      The GNOME virtual file-system libr
ii  libgtk2.0-0               2.4.4-1        The GTK+ graphical user interface 
ii  libice6                   4.3.0.dfsg.1-6 Inter-Client Exchange library
ii  liborbit2                 1:2.10.2-1.1   libraries for ORBit2 - a CORBA ORB
ii  libpango1.0-0             1.4.0-4        Layout and rendering of internatio
ii  libpopt0                  1.7-4          lib for parsing cmdline parameters
ii  libsm6                    4.3.0.dfsg.1-6 X Window System Session Management
ii  libwrap0                  7.6.dbs-4      Wietse Venema's TCP wrappers libra
ii  libx11-6                  4.3.0.dfsg.1-6 X Window System protocol client li
ii  libxml2                   2.6.11-2       GNOME XML library
ii  libxmu6                   4.3.0.dfsg.1-6 X Window System miscellaneous util
ii  libxrandr2                4.3.0.dfsg.1-6 X Window System Resize, Rotate and
ii  libxrender1               0.8.3-7        X Rendering Extension client libra
ii  libxt6                    4.3.0.dfsg.1-6 X Toolkit Intrinsics
ii  xlibs                     4.3.0.dfsg.1-6 X Window System client libraries m
ii  zlib1g                    1:1.2.1.1-5    compression library - runtime

-- no debconf information



Information forwarded to debian-bugs-dist@lists.debian.org:
Bug#261980; Package gnome-session. (full text, mbox, link).


Acknowledgement sent to Josselin Mouette <joss@debian.org>:
Extra info received and forwarded to list. (full text, mbox, link).


Message #10 received at 261980@bugs.debian.org (full text, mbox, reply):

From: Josselin Mouette <joss@debian.org>
To: Jaume <j2003gi@yahoo.es>, 261980@bugs.debian.org
Cc: gdm@packages.debian.org
Subject: Re: Bug#261980: gnome-session: Shutdown/reboot option does not ask for password
Date: Sat, 31 Jul 2004 11:53:12 +0200
[Message part 1 (text/plain, inline)]
reassign 261980 gdm
thanks

On jeu, 2004-07-29 at 12:53 +0200, Jaume wrote:

> The new feature to shutdown/reboot the machine on the logout does not ask
> for the root password.

> This could cause data loss, if some other user is logged in remotelly (via ssh) 
> or in a text console. Only users authorised by root should be able to reboot
> the machine. (NOTE: gdm allows me to reboot the machine, but it asks for the
> root password before proceeding)

All the security is delegated to GDM, as this feature only calls
gdmflexiserver and asks for shutdown using the SUP protocol. As such,
this should probably be handled by GDM.
-- 
 .''`.           Josselin Mouette        /\./\
: :' :           josselin.mouette@ens-lyon.org
`. `'                        joss@debian.org
  `-  Debian GNU/Linux -- The power of freedom
[signature.asc (application/pgp-signature, inline)]

Bug reassigned from package `gnome-session' to `gdm'. Request was from Josselin Mouette <joss@debian.org> to control@bugs.debian.org. (full text, mbox, link).


Merged 261980 265535. Request was from Josselin Mouette <joss@debian.org> to control@bugs.debian.org. (full text, mbox, link).


Noted your statement that Bug has been forwarded to http://bugzilla.gnome.org/show_bug.cgi?id=309627. Request was from Loïc Minier <lool@dooz.org> to control@bugs.debian.org. (full text, mbox, link).


Removed annotation that Bug had been forwarded to http://bugzilla.gnome.org/show_bug.cgi?id=309627. Request was from Loïc Minier <lool@dooz.org> to control@bugs.debian.org. (full text, mbox, link).


Reply sent to Ryan Murray <rmurray@debian.org>:
You have taken responsibility. (full text, mbox, link).


Notification sent to Jaume <j2003gi@yahoo.es>:
Bug acknowledged by developer. (full text, mbox, link).


Message #23 received at 261980-close@bugs.debian.org (full text, mbox, reply):

From: Ryan Murray <rmurray@debian.org>
To: 261980-close@bugs.debian.org
Subject: Bug#261980: fixed in gdm 2.13.0.10-1
Date: Sun, 12 Mar 2006 21:47:08 -0800
Source: gdm
Source-Version: 2.13.0.10-1

We believe that the bug you reported is fixed in the latest version of
gdm, which is due to be installed in the Debian FTP archive:

gdm_2.13.0.10-1.diff.gz
  to pool/main/g/gdm/gdm_2.13.0.10-1.diff.gz
gdm_2.13.0.10-1.dsc
  to pool/main/g/gdm/gdm_2.13.0.10-1.dsc
gdm_2.13.0.10-1_i386.deb
  to pool/main/g/gdm/gdm_2.13.0.10-1_i386.deb
gdm_2.13.0.10.orig.tar.gz
  to pool/main/g/gdm/gdm_2.13.0.10.orig.tar.gz



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 261980@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Ryan Murray <rmurray@debian.org> (supplier of updated gdm package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Sat, 11 Mar 2006 14:51:15 -0800
Source: gdm
Binary: gdm
Architecture: source i386
Version: 2.13.0.10-1
Distribution: unstable
Urgency: low
Maintainer: Ryan Murray <rmurray@debian.org>
Changed-By: Ryan Murray <rmurray@debian.org>
Description: 
 gdm        - GNOME Display Manager
Closes: 252543 261980 277953 284613 340840 342113 344910 346096 348872
Changes: 
 gdm (2.13.0.10-1) unstable; urgency=low
 .
   * New upstream release
     + two-level config (closes: #252543)
   * Add build-depends on libxdmcp-dev, libxinerama-dev (closes: #340840, #342113)
   * Relibtoolize (closes: #344910)
   * Add dependency on lsb-base (closes: #346096)
   * Add "Display Manager" hint to menu file (closes: #284613)
   * Depend on librsvg2-common (closes: #348872)
   * Update debconf template translations
   * Update locale.conf against locales 2.3.6-3
   * Take patch to XKeepsCrashing from Ubuntu that restores the keyboard
     to xlate mode before trying to interact with the user.
   * Drop ungnomeish SecureSysMenu patch. (closes: #261980)
   * Set $HOME to /etc/X11 when starting the X server, causing the code
     that looks for $HOME/xorg.conf before other files in /etc to look
     at our configfile, and not one that might be in root's homedir.
     (closes #250438)
   * Confirmed that the new version correctly works with utf-8 locales
     (closes: #277953)
Files: 
 dc2faa55618c7d7a17b08dca412f1f43 752 gnome optional gdm_2.13.0.10-1.dsc
 72a84d9298f099e41c284d1c9eef25ae 4492917 gnome optional gdm_2.13.0.10.orig.tar.gz
 cd69864a7716f8fef5796fd77b353336 252651 gnome optional gdm_2.13.0.10-1.diff.gz
 39af0d3c9858f69ad78bd8aa1a627e8e 3676330 gnome optional gdm_2.13.0.10-1_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)

iD8DBQFEFQNHN2Dbz/1mRasRAsyaAKDkY2ursznPOfMK3pV5Ab/T5ScoWgCghZCp
E5Zk2CggrujBhYx/5MPXEB8=
=lYJx
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Mon, 25 Jun 2007 04:50:28 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Sun Jun 4 20:14:42 2023; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.