Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package google-guest-oslogin for 
openSUSE:Factory checked in at 2026-08-05 17:48:15
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/google-guest-oslogin (Old)
 and      /work/SRC/openSUSE:Factory/.google-guest-oslogin.new.16738 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "google-guest-oslogin"

Wed Aug  5 17:48:15 2026 rev:39 rq:1369489 version:20260731.00

Changes:
--------
--- 
/work/SRC/openSUSE:Factory/google-guest-oslogin/google-guest-oslogin.changes    
    2026-05-07 15:47:17.556830373 +0200
+++ 
/work/SRC/openSUSE:Factory/.google-guest-oslogin.new.16738/google-guest-oslogin.changes
     2026-08-05 17:48:57.010992147 +0200
@@ -1,0 +2,13 @@
+Tue Aug  4 08:10:28 UTC 2026 - John Paul Adrian Glaubitz 
<[email protected]>
+
+- Update to version 20260731.00
+  * Restore Makefiles, .gitignore, and repository metadata
+  * No public description
+- from version 20260626.00
+  * Check and properly pad the buffer used for usernames in the
+    NSS module, properly support buffer size negotiation. (#184)
+- from version 20260605.00
+  * Add two new types to the SELinux policy: sshd_session_t, and
+    systemd_userdbd_t, both added in newer EL versions. (#186)
+
+-------------------------------------------------------------------

Old:
----
  google-guest-oslogin-20260430.00.tar.gz

New:
----
  google-guest-oslogin-20260731.00.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ google-guest-oslogin.spec ++++++
--- /var/tmp/diff_new_pack.qdknC5/_old  2026-08-05 17:48:59.335073566 +0200
+++ /var/tmp/diff_new_pack.qdknC5/_new  2026-08-05 17:48:59.375074967 +0200
@@ -26,7 +26,7 @@
 %{!?_pam_moduledir: %define _pam_moduledir %{_pamdir}}
 
 Name:           google-guest-oslogin
-Version:        20260430.00
+Version:        20260731.00
 Release:        0
 Summary:        Google Cloud Guest OS Login
 License:        Apache-2.0

++++++ google-guest-oslogin-20260430.00.tar.gz -> 
google-guest-oslogin-20260731.00.tar.gz ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/guest-oslogin-20260430.00/.gitignore 
new/guest-oslogin-20260731.00/.gitignore
--- old/guest-oslogin-20260430.00/.gitignore    2026-04-30 21:43:03.000000000 
+0200
+++ new/guest-oslogin-20260731.00/.gitignore    2026-07-31 23:23:37.000000000 
+0200
@@ -3,10 +3,12 @@
 google_authorized_keys
 google_authorized_keys_sk
 google_oslogin_nss_cache
+test/nss_test_runner
 test/sshca_runner
 test/test_detail.xml
 selinux/oslogin.mod
 selinux/oslogin.pp
+test/cache_test_runner
 test/new_test_runner
 test/test_runner
 src/google_authorized_principals
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/guest-oslogin-20260430.00/LICENSE 
new/guest-oslogin-20260731.00/LICENSE
--- old/guest-oslogin-20260430.00/LICENSE       2026-04-30 21:43:03.000000000 
+0200
+++ new/guest-oslogin-20260731.00/LICENSE       2026-07-31 23:23:37.000000000 
+0200
@@ -1,3 +1,77 @@
+Files: src/nss/compat/getpwent_r.c
+
+
+----------------------------------------------------------------------
+Copyright © 2005-2014 Rich Felker, et al.
+
+Permission is hereby granted, free of charge, to any person obtaining
+a copy of this software and associated documentation files (the
+"Software"), to deal in the Software without restriction, including
+without limitation the rights to use, copy, modify, merge, publish,
+distribute, sublicense, and/or sell copies of the Software, and to
+permit persons to whom the Software is furnished to do so, subject to
+the following conditions:
+
+The above copyright notice and this permission notice shall be
+included in all copies or substantial portions of the Software.
+
+THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
+EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
+MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT.
+IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY
+CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT,
+TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE
+SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
+----------------------------------------------------------------------
+
+Copyright © 2015 Kevin Bowling <[email protected]>
+
+---
+
+Files: src/openbsd-compat/base64.h
+
+Copyright (c) 1996 by Internet Software Consortium.
+
+Permission to use, copy, modify, and distribute this software for any
+purpose with or without fee is hereby granted, provided that the above
+copyright notice and this permission notice appear in all copies.
+
+THE SOFTWARE IS PROVIDED "AS IS" AND INTERNET SOFTWARE CONSORTIUM DISCLAIMS
+ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES
+OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL INTERNET SOFTWARE
+CONSORTIUM BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL
+DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR
+PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS
+ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS
+SOFTWARE.
+
+Portions Copyright (c) 1995 by International Business Machines, Inc.
+
+International Business Machines, Inc. (hereinafter called IBM) grants
+permission under its copyrights to use, copy, modify, and distribute this
+Software with or without fee, provided that the above copyright notice and
+all paragraphs of this notice appear in all copies, and that the name of IBM
+not be used in connection with the marketing of any product incorporating
+the Software or modifications thereof, without specific, written prior
+permission.
+
+To the extent it has a right to do so, IBM grants an immunity from suit
+under its patents, if any, for the use, sale or manufacture of products to
+the extent that such products are used for performing Domain Name System
+dynamic updates in TCP/IP networks by means of the Software.  No immunity is
+granted for any product per se or for any other function of any product.
+
+THE SOFTWARE IS PROVIDED "AS IS", AND IBM DISCLAIMS ALL WARRANTIES,
+INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
+PARTICULAR PURPOSE.  IN NO EVENT SHALL IBM BE LIABLE FOR ANY SPECIAL,
+DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER ARISING
+OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE, EVEN
+IF IBM IS APPRISED OF THE POSSIBILITY OF SUCH DAMAGES.
+
+---
+
+Files: all other files not named above
+
                                  Apache License
                            Version 2.0, January 2004
                         http://www.apache.org/licenses/
@@ -81,7 +155,7 @@
       with the Work to which such Contribution(s) was submitted. If You
       institute patent litigation against any entity (including a
       cross-claim or counterclaim in a lawsuit) alleging that the Work
-      or a Contribution incorporated within the Work constitutes direct
+      or a Conribution incorporated within the Work constitutes direct
       or contributory patent infringement, then any patent licenses
       granted to You under this License for that Work shall terminate
       as of the date such litigation is filed.
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/guest-oslogin-20260430.00/README.md 
new/guest-oslogin-20260731.00/README.md
--- old/guest-oslogin-20260430.00/README.md     2026-04-30 21:43:03.000000000 
+0200
+++ new/guest-oslogin-20260731.00/README.md     2026-07-31 23:23:37.000000000 
+0200
@@ -38,6 +38,16 @@
 The **packaging** directory also contains files used to generate `.deb` and
 `.rpm` packages for the OS Login components.
 
+## Contributing
+
+**Googlers:** Please contribute to this repository via our internal version
+control system. We automatically copy internal changes out to GitHub after they
+are merged internally.
+
+**External Contributors:** We welcome external contributions! Please open a 
Pull
+Request on GitHub, and our team will review and import it into our internal
+repository.
+
 ## Components
 
 #### Authorized Keys Command
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/guest-oslogin-20260430.00/selinux/oslogin.te 
new/guest-oslogin-20260731.00/selinux/oslogin.te
--- old/guest-oslogin-20260430.00/selinux/oslogin.te    2026-04-30 
21:43:03.000000000 +0200
+++ new/guest-oslogin-20260731.00/selinux/oslogin.te    2026-07-31 
23:23:37.000000000 +0200
@@ -1,27 +1,49 @@
-
 module oslogin 1.0;
 
-
 require {
-       attribute file_type;
-       attribute non_security_file_type;
-       type http_port_t;
-       type sshd_t;
-       type sshd_key_t;
-       class tcp_socket name_connect;
-       class file { create getattr setattr write open read unlink };
-       class dir { search write read remove_name add_name };
-       class fifo_file { getattr open read };
+ attribute file_type;
+ attribute non_security_file_type;
+ type http_port_t;
+ type sshd_t;
+ type sshd_key_t;
+ class tcp_socket name_connect;
+ class file { create getattr setattr write open read unlink };
+ class dir { search write read remove_name add_name };
+ class fifo_file { getattr open read };
 }
 
 #============= types ==============
 
-type google_t;  # defined in oslogin.fc
+type google_t; # defined in oslogin.fc
 typeattribute google_t file_type, non_security_file_type;
 
-#============= sshd_t ==============
+#============= sshd_t (RHEL 7/8/9/10 legacy support) ==============
 
 allow sshd_t google_t:file { create getattr setattr write open read unlink };
 allow sshd_t google_t:dir { search write read remove_name add_name };
 allow sshd_t http_port_t:tcp_socket name_connect;
 allow sshd_t sshd_key_t:fifo_file { getattr open read };
+
+#============= sshd_session_t (RHEL 9/10 support) ==============
+# Required for the modern split-process OpenSSH architecture where
+# authorized keys command execution and user profile lookup happen
+# in the session domain.
+
+optional {
+    require {
+        type sshd_session_t;
+    }
+    allow sshd_session_t google_t:file { create getattr setattr write open 
read unlink };
+    allow sshd_session_t google_t:dir { search write read remove_name add_name 
};
+    allow sshd_session_t http_port_t:tcp_socket name_connect;
+}
+
+#============= systemd_userdbd_t (RHEL 8/9/10 support) ==============
+# Required for NSS lookups proxied through the systemd-userdbd daemon.
+
+optional {
+    require {
+        type systemd_userdbd_t;
+    }
+    allow systemd_userdbd_t http_port_t:tcp_socket name_connect;
+}
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/guest-oslogin-20260430.00/src/nss/nss_cache_oslogin.c 
new/guest-oslogin-20260731.00/src/nss/nss_cache_oslogin.c
--- old/guest-oslogin-20260430.00/src/nss/nss_cache_oslogin.c   2026-04-30 
21:43:03.000000000 +0200
+++ new/guest-oslogin-20260731.00/src/nss/nss_cache_oslogin.c   2026-07-31 
23:23:37.000000000 +0200
@@ -366,6 +366,11 @@
   return ret;
 }
 
+#define CALCULATE_PADDING_FOR_ALIGNMENT(buf_addr, bytes_to_write)              
\
+  ((__alignof__(char *) -                                                      
\
+    (((size_t)(buf_addr) + (bytes_to_write)) % __alignof__(char *))) %         
\
+   __alignof__(char *))
+
 // _nss_cache_oslogin_getgrgid_r()
 // Find a group by gid
 
@@ -380,6 +385,16 @@
   char userbuf[userbuflen];
   ret = _nss_cache_oslogin_getpwuid_r(gid, &user, userbuf, userbuflen, errnop);
   if (ret == NSS_STATUS_SUCCESS && user.pw_gid == user.pw_uid) {
+    size_t name_len = strlen(user.pw_name) + 1;
+    size_t bytes_needed = 2 + name_len;
+    size_t padding = CALCULATE_PADDING_FOR_ALIGNMENT(buffer, bytes_needed);
+    bytes_needed += padding + 2 * sizeof(char *);
+
+    if (buflen < bytes_needed) {
+      *errnop = ERANGE;
+      return NSS_STATUS_TRYAGAIN;
+    }
+
     result->gr_gid = user.pw_gid;
 
     // store "x" for password.
@@ -389,12 +404,11 @@
 
     // store name.
     string = (char *)((size_t) string + 2);
-    size_t name_len = strlen(user.pw_name)+1;
     strncpy(string, user.pw_name, name_len);
     result->gr_name = string;
 
     // member array starts past strings.
-    char **strarray = (char **)((size_t) string + name_len);
+    char **strarray = (char **)((size_t) string + name_len + padding);
     strarray[0] = string;
     strarray[1] = NULL;
     result->gr_mem = strarray;
@@ -432,6 +446,16 @@
   char userbuf[userbuflen];
   ret = _nss_cache_oslogin_getpwnam_r(name, &user, userbuf, userbuflen, 
errnop);
   if (ret == NSS_STATUS_SUCCESS && user.pw_gid == user.pw_uid) {
+    size_t name_len = strlen(user.pw_name) + 1;
+    size_t bytes_needed = 2 + name_len;
+    size_t padding = CALCULATE_PADDING_FOR_ALIGNMENT(buffer, bytes_needed);
+    bytes_needed += padding + 2 * sizeof(char *);
+
+    if (buflen < bytes_needed) {
+      *errnop = ERANGE;
+      return NSS_STATUS_TRYAGAIN;
+    }
+
     result->gr_gid = user.pw_gid;
 
     // store "x" for password.
@@ -441,12 +465,11 @@
 
     // store name.
     string = (char *)((size_t) string + 2);
-    size_t name_len = strlen(user.pw_name)+1;
     strncpy(string, user.pw_name, name_len);
     result->gr_name = string;
 
     // member array starts past strings.
-    char **strarray = (char **)((size_t) string + name_len);
+    char **strarray = (char **)((size_t) string + name_len + padding);
     strarray[0] = string;
     strarray[1] = NULL;
     result->gr_mem = strarray;
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/guest-oslogin-20260430.00/test/Makefile 
new/guest-oslogin-20260731.00/test/Makefile
--- old/guest-oslogin-20260430.00/test/Makefile 2026-04-30 21:43:03.000000000 
+0200
+++ new/guest-oslogin-20260731.00/test/Makefile 2026-07-31 23:23:37.000000000 
+0200
@@ -41,6 +41,9 @@
 sshca_runner: oslogin_sshca_test.o $(TOPDIR)/src/oslogin_utils.o 
$(TOPDIR)/src/oslogin_sshca.o gtest-all.o gtest_main.o
        $(CXX) $(CXXFLAGS) $(CPPFLAGS) $^ -o $@ $(LDLIBS)
 
+nss_test_runner: nss_cache_oslogin_test.o nss_cache_oslogin.o gtest-all.o 
gtest_main.o
+       $(CXX) $(CXXFLAGS) $(CPPFLAGS) $^ -o $@ $(LDLIBS)
+
 sshca_tests: sshca_runner
        $(SSHCA_TEST_RUNNER)
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/guest-oslogin-20260430.00/test/nss_cache_oslogin_test.cc 
new/guest-oslogin-20260731.00/test/nss_cache_oslogin_test.cc
--- old/guest-oslogin-20260430.00/test/nss_cache_oslogin_test.cc        
1970-01-01 01:00:00.000000000 +0100
+++ new/guest-oslogin-20260731.00/test/nss_cache_oslogin_test.cc        
2026-07-31 23:23:37.000000000 +0200
@@ -0,0 +1,97 @@
+#include <gtest/gtest.h>
+#include <gmock/gmock.h>
+#include <grp.h>
+#include <nss.h>
+#include <pwd.h>
+#include <errno.h>
+#include <stdint.h>
+
+// Include the header to get the correct types.
+#include "../src/include/oslogin_passwd_cache_reader.h"
+
+extern "C" {
+enum nss_status _nss_cache_oslogin_getgrgid_r(gid_t gid, struct group *result,
+                                              char *buffer, size_t buflen,
+                                              int *errnop);
+}
+
+extern "C" {
+// Implement the mocked functions.
+PasswdCache* open_passwd_cache(const char* filename) {
+  return reinterpret_cast<PasswdCache*>(0x1234);
+}
+
+void close_passwd_cache(PasswdCache* cache) {}
+
+struct passwd mock_user;
+enum nss_status mock_lookup_status = NSS_STATUS_SUCCESS;
+
+enum nss_status lookup_passwd_by_uid_r(PasswdCache* cache, uid_t uid,
+                                       struct passwd* result, char* buffer,
+                                       size_t buflen, int* errnop) {
+  if (mock_lookup_status == NSS_STATUS_SUCCESS) {
+    *result = mock_user;
+  }
+  return mock_lookup_status;
+}
+
+// Additional stubs to fix linker errors.
+void passwd_cache_iter_begin(PasswdCache* cache, PasswdCacheIter* iter) {}
+
+enum nss_status passwd_cache_iter_next_r(PasswdCache* cache,
+                                         PasswdCacheIter* iter,
+                                         struct passwd* result, char* buffer,
+                                         size_t buflen, int* errnop) {
+  return NSS_STATUS_NOTFOUND;
+}
+
+enum nss_status lookup_passwd_by_name_r(PasswdCache* cache, const char* name,
+                                        struct passwd* result, char* buffer,
+                                        size_t buflen, int* errnop) {
+  return NSS_STATUS_NOTFOUND;
+}
+}
+
+class NssCacheOsloginTest : public ::testing::Test {
+ protected:
+  void SetUp() override {
+    mock_lookup_status = NSS_STATUS_SUCCESS;
+    memset(&mock_user, 0, sizeof(mock_user));
+  }
+};
+
+TEST_F(NssCacheOsloginTest, GetgrgidSelfGroupBufferTooSmall) {
+  static char username[] = "testuser";
+  mock_user.pw_name = username;
+  mock_user.pw_uid = 1001;
+  mock_user.pw_gid = 1001;
+
+  struct group result;
+  char buffer[1];
+  int errnop = 0;
+  
+  enum nss_status status = _nss_cache_oslogin_getgrgid_r(1001, &result, 
buffer, sizeof(buffer), &errnop);
+  
+  EXPECT_EQ(status, NSS_STATUS_TRYAGAIN);
+  EXPECT_EQ(errnop, ERANGE);
+}
+
+TEST_F(NssCacheOsloginTest, GetgrgidSelfGroupSuccess) {
+  static char username[] = "testuser";
+  mock_user.pw_name = username;
+  mock_user.pw_uid = 1001;
+  mock_user.pw_gid = 1001;
+
+  struct group result;
+  char buffer[1024];
+  int errnop = 0;
+  
+  enum nss_status status = _nss_cache_oslogin_getgrgid_r(1001, &result, 
buffer, sizeof(buffer), &errnop);
+  
+  EXPECT_EQ(status, NSS_STATUS_SUCCESS);
+  EXPECT_STREQ(result.gr_name, "testuser");
+  EXPECT_STREQ(result.gr_passwd, "x");
+  EXPECT_EQ(result.gr_gid, 1001);
+  EXPECT_STREQ(result.gr_mem[0], "testuser");
+  EXPECT_TRUE(result.gr_mem[1] == NULL);
+}

Reply via email to