重建具有更大限制的 PAM

重建具有更大限制的 PAM

no_proxy我的 /etc/environment /变量中有一个很长的主机名和 IP 列表(超过 1013 个字符)NO_PROXY,因为我的公司代理不知道它们。我的本地 Unbound DNS 可以。只有部分主机名和 IP 有效。

看起来像pam_env该包将var=value(例如no_proxy="blah")分配限制为每个 1024 字节。

  1. 我如何获得来源(apt-get source libpam-modules)?deb-src我需要哪些 /etc/apt/sources.list条目?
  2. pam_env.c 在哪个路径中,我可以编辑它吗?有updatedb && locate pam_env.c帮助吗?
  3. 如何构建它并将其集成到 Ubuntu 14.04 和 Ubuntu 16.04 中?

答案1

重建具有更大限制的 PAM

以具有 sudo 权限的普通用户身份执行脚本。

使用 BZR (= Bazaar) 的 Ubuntu 脚本(确实未经测试!)

使用 创建文件vi build_pam_via_ubuntu_and_bzr.sh,将脚本放入其中(见下文),使文件可执行chmod +x build_pam_via_ubuntu_and_bzr.sh并使用./build_pam_via_ubuntu_and_bzr.sh

#!/usr/bin/env bash

# Stop when folder exists (please delete manually):
[ -e /opt/bzr/pam/ ] && exit 0

# Update sources:
sudo apt-get update || exit 1

# Install source control:
sudo apt-get install bzr bzr-builddeb -y || exit 1

# Create folder:
sudo mkdir -p /opt/bzr/pam/ || exit 1

# Change owner and group:
sudo chown -R $(id -u):$(id -g) /opt/bzr/pam/  || exit 1

# Enter folder:
cd /opt/bzr/pam/ || exit 1

# Clone PAM repo
bzr branch lp:ubuntu/vivid/pam || exit 1

# Join folder:
cd /opt/bzr/pam/ubuntu/ || exit 1

# Main point: Change BUF_SIZE limit:
sed -i "s/#define BUF_SIZE 1024/#define BUF_SIZE 8192/" modules/pam_env/pam_env.c || exit 1

# Add new version number to debian/changelog:
dch -n "Change environment variable limit from 1024 to 8192." || exit 1

# `bzr builddeb -- -uc -us` will fail with `unmet build dependencies`, install them:
sudo apt-get install libcrack2-dev debhelper quilt flex bison libfl-dev libdb-dev libselinux1-dev po-debconf dh-autoreconf autopoint libaudit-dev pkg-config xsltproc libxml2-utils docbook-xml docbook-xsl w3m -y || exit 1

# Another error lead me to remove fop (maybe not necessary):
###sudo apt-get remove fop || exit 1

# Build packages without signing them (takes ~ 20 minutes):
bzr builddeb -- -uc -us || exit 1

# Install local packages and dependencies with apt-get (possible since Ubuntu 16.04)
# Otherwise (Ubuntu 14.04) use dpkg
sudo apt-get install /opt/bzr/pam/*.deb || sudo dpkg --force-all -i /opt/bzr/pam/*.deb || exit 1

# Now you can have env variables with ~ 8192 chars:
sudo bash -c "echo 'BLUBB123=\"'$(tr -dc 'a-z0-9' < /dev/urandom | head -c8000)'\"' >> /etc/environment" || exit 1

Ubuntu 14.04.5 的 Git 脚本(已测试)

使用 创建文件vi build_pam_via_trusty_and_git.sh,将脚本放入其中(见下文),使文件可执行chmod +x build_pam_via_trusty_and_git.sh并使用./build_pam_via_trusty_and_git.sh

#!/usr/bin/env bash

# Stop when folder exists (please delete manually):
[ -e /opt/git/pam/ ] && exit 0

# Update sources:
sudo apt-get update || exit 1

# Install source control:
sudo apt-get install git git-buildpackage -y || exit 1

# Create folder:
sudo mkdir -p /opt/git/pam/ || exit 1

# Change owner and group:
sudo chown -R $(id -u):$(id -g) /opt/git/pam/  || exit 1

# Enter folder:
cd /opt/git/pam/ || exit 1

# Clone PAM repo
git clone -b ubuntu/trusty-security https://git.launchpad.net/~usd-import-team/ubuntu/+source/pam || exit 1

# Join folder:
cd /opt/git/pam/pam/ || exit 1

# Main point: Change BUF_SIZE limit:
sed -i "s/#define BUF_SIZE 1024/#define BUF_SIZE 8192/" modules/pam_env/pam_env.c || exit 1

# Add new version number to debian/changelog (coming from 1.1.8-1ubuntu2.2):
dch -n "Change environment variable limit from 1024 to 8192." || exit 1

# Add changed files to Git index:
git add /opt/git/pam/pam/modules/pam_env/pam_env.c || exit 1
git add /opt/git/pam/pam/debian/changelog || exit 1

# Commit Git index:
git commit -m "Change environment variable limit from 1024 to 8192." || exit 1

sudo apt-get install libcrack2-dev debhelper quilt flex bison libfl-dev libdb-dev libselinux1-dev po-debconf dh-autoreconf autopoint libaudit-dev pkg-config xsltproc libxml2-utils docbook-xml docbook-xsl w3m -y || exit 1

# Another error lead me to remove fop (maybe not necessary):
###sudo apt-get remove fop || exit 1

# Build packages without signing them (takes ~ 20 minutes):
gbp buildpackage --git-debian-branch="ubuntu/trusty-security" --git-ignore-new --git-upstream-tree="ubuntu/trusty-security" -uc -us || exit 1

# Install local packages:
sudo dpkg --force-all -i /opt/git/pam/*.deb || exit 1

# Now you can have env variables with ~ 8192 chars:
sudo bash -c "echo 'BLUBB123=\"'$(tr -dc 'a-z0-9' < /dev/urandom | head -c8000)'\"' >> /etc/environment" || exit 1

Ubuntu 16.04.4 的 Git 脚本(已测试)

使用 创建文件vi build_pam_via_xenial_and_git.sh,将脚本放入其中(见下文),使文件可执行chmod +x build_pam_via_xenial_and_git.sh并使用./build_pam_via_xenial_and_git.sh

#!/usr/bin/env bash

# Stop when folder exists (please delete manually):
[ -e /opt/git/pam/ ] && exit 0

# Update sources:
sudo apt-get update || exit 1

# Install source control:
sudo apt-get install git git-buildpackage -y || exit 1

# Create folder:
sudo mkdir -p /opt/git/pam/ || exit 1

# Change owner and group:
sudo chown -R $(id -u):$(id -g) /opt/git/pam/  || exit 1

# Enter folder:
cd /opt/git/pam/ || exit 1

# Clone PAM repo
git clone -b ubuntu/xenial https://git.launchpad.net/~usd-import-team/ubuntu/+source/pam || exit 1

# Join folder:
cd /opt/git/pam/pam/ || exit 1

# Main point: Change BUF_SIZE limit:
sed -i "s/#define BUF_SIZE 1024/#define BUF_SIZE 8192/" modules/pam_env/pam_env.c || exit 1

# Add new version number to debian/changelog (coming from 1.1.8-3.2ubuntu2.1):
dch --distribution unstable --package "pam" --newversion "1.1.8-3.2ubuntu2.2" "Change environment variable limit from 1024 to 8192." || exit 1
# dch -n "Change environment variable limit from 1024 to 8192." || exit 1

# Add changed files to Git index:
git add /opt/git/pam/pam/modules/pam_env/pam_env.c || exit 1
git add /opt/git/pam/pam/debian/changelog || exit 1

# Commit Git index:
git commit -m "Change environment variable limit from 1024 to 8192." || exit 1

sudo apt-get install libcrack2-dev debhelper quilt flex bison libfl-dev libdb-dev libselinux1-dev po-debconf dh-autoreconf autopoint libaudit-dev pkg-config xsltproc libxml2-utils docbook-xml docbook-xsl w3m -y || exit 1

# Another error lead me to remove fop (maybe not necessary):
###sudo apt-get remove fop || exit 1

# Build packages without signing them (takes ~ 20 minutes):
gbp buildpackage --git-debian-branch="ubuntu/xenial" --git-ignore-new --git-upstream-tree="ubuntu/xenial" -uc -us || exit 1

# Install local packages and dependencies with apt-get (possible since Ubuntu 16.04):
sudo apt-get install /opt/git/pam/*.deb -y || exit 1

# Now you can have env variables with ~ 8192 chars:
sudo bash -c "echo 'BLUBB123=\"'$(tr -dc 'a-z0-9' < /dev/urandom | head -c8000)'\"' >> /etc/environment" || exit 1

测试

重新启动您的机器(也许没有必要):

sudo reboot

检查安装的版本号:

sudo apt install apt-show-versions
sudo apt-show-versions libpam-modules

返回类似的东西

libpam-modules:amd64 1.1.8-3.2ubuntu2.1 newer than version in archive
libpam-modules:i386 not installed

哪个是对的。

重新连接并显示包含 8000 个字符的环境变量 BLUBB123:

echo $BLUBB123

相关:

  1. https://github.com/linux-pam/linux-pam/issues/31
  2. 当我`apt dist-upgrade`时,自建包会发生什么?

相关内容