public inbox for pve-devel@lists.proxmox.com
 help / color / mirror / Atom feed
From: Michal Fox <me@dualfroz.com>
To: pve-devel@lists.proxmox.com
Subject: [PATCH access-control] fix #5368: pam: say that a failed password change is about the host user
Date: Tue,  6 Oct 2026 08:21:54 +0000	[thread overview]
Message-ID: <20261006082154.7-1-me@dualfroz.com> (raw)

Users of the PAM realm are users of the host system, and setting their
password runs usermod on the node handling the request. If the user
only got added to the PAM realm, but does not exist on the host, this
failed with:

  change password failed: user 'jdoe' does not exist

which is confusing, as the user is shown in the user list of the web UI
and the message does not say that the user on the host is meant.

Mention the PAM user and the host system in the error message, so that
it reads:

  changing the password of the PAM user 'jdoe' on the host system
  failed: user 'jdoe' does not exist

The output of usermod is still added at the end, so this helps with its
other errors too.

Signed-off-by: Michal Fox <me@dualfroz.com>
---

Notes:
    tested by calling store_password() as root in a Debian trixie container,
    for a missing user, which gave the error above, and for an existing
    user, whose password got changed. 'make test' in src passes.
    
    the errors of the PAM authentication itself are left as they are, they
    already are PAM's own messages like 'Authentication failure'.

 src/PVE/Auth/PAM.pm | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/src/PVE/Auth/PAM.pm b/src/PVE/Auth/PAM.pm
index 8586da5..c2b767d 100755
--- a/src/PVE/Auth/PAM.pm
+++ b/src/PVE/Auth/PAM.pm
@@ -89,7 +89,10 @@ sub store_password {
 
     push @$cmd, '-p', $epw, $username;
 
-    run_command($cmd, errmsg => 'change password failed');
+    run_command(
+        $cmd,
+        errmsg => "changing the password of the PAM user '$username' on the host system failed",
+    );
 }
 
 1;
-- 
2.43.0




                 reply	other threads:[~2026-10-06  8:22 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261006082154.7-1-me@dualfroz.com \
    --to=me@dualfroz.com \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal