From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id F41161FF0AA for ; Tue, 06 Oct 2026 10:22:08 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 2D11321488; Tue, 06 Oct 2026 10:22:05 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dualfroz.com; s=dkim; t=1791274917; h=from:subject:date:message-id:to:mime-version: content-transfer-encoding; bh=THMC8DSwU+3kSlu3mN2pUQnuPLjYS/CwA4aY2iLmVjo=; b=kPymReKP0rTcv4Szd50HAwduCF6P8fTKTWSN3yNrRGOb1Q0kZ3oh+treIICkHeC3SoJIOt GRGNl0kfyQ+yU3qcqB96ZDkXVGVuuZrSb/PAHazrhCU2+1JuhI08dtVRCrT2oWVIStpzaG G/li9BJp5S3uYYC9B5Vns2B2Fejl6xJz4A5kkEtciL2X6VscxUtCJpdffBl1kiO+HnEnhW NV4PmA9b7DmFHmOxXduj+3k5iggaZU54CgX6R3GiC6oCBOZ+chDlxjFmA+IA0JvyL3JesY OaC2EWKUGpwRrI7oRbssJY6AFURzyFgSQw4sFr4TK6Cp4Da71T47mVHfwxnbWg== From: Michal Fox To: pve-devel@lists.proxmox.com Subject: [PATCH access-control] fix #5368: pam: say that a failed password change is about the host user Date: Tue, 6 Oct 2026 08:21:54 +0000 Message-ID: <20261006082154.7-1-me@dualfroz.com> X-Mailer: git-send-email 2.47.3 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Last-TLS-Session-Version: TLSv1.3 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.147 Adjusted score from AWL reputation of From: address DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature DKIM_VALID_AU -0.1 Message has a valid DKIM or DK signature from author's domain DKIM_VALID_EF -0.1 Message has a valid DKIM or DK signature from envelope-from domain DMARC_PASS -0.1 DMARC pass policy SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: AJBK3HPVSQ7HIFUFHSB5FG456XIGXDMJ X-Message-ID-Hash: AJBK3HPVSQ7HIFUFHSB5FG456XIGXDMJ X-MailFrom: me@dualfroz.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Users of the PAM realm are users of the host system, and setting their password runs usermod on the node handling the request. If the user only got added to the PAM realm, but does not exist on the host, this failed with: change password failed: user 'jdoe' does not exist which is confusing, as the user is shown in the user list of the web UI and the message does not say that the user on the host is meant. Mention the PAM user and the host system in the error message, so that it reads: changing the password of the PAM user 'jdoe' on the host system failed: user 'jdoe' does not exist The output of usermod is still added at the end, so this helps with its other errors too. Signed-off-by: Michal Fox --- Notes: tested by calling store_password() as root in a Debian trixie container, for a missing user, which gave the error above, and for an existing user, whose password got changed. 'make test' in src passes. the errors of the PAM authentication itself are left as they are, they already are PAM's own messages like 'Authentication failure'. src/PVE/Auth/PAM.pm | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/src/PVE/Auth/PAM.pm b/src/PVE/Auth/PAM.pm index 8586da5..c2b767d 100755 --- a/src/PVE/Auth/PAM.pm +++ b/src/PVE/Auth/PAM.pm @@ -89,7 +89,10 @@ sub store_password { push @$cmd, '-p', $epw, $username; - run_command($cmd, errmsg => 'change password failed'); + run_command( + $cmd, + errmsg => "changing the password of the PAM user '$username' on the host system failed", + ); } 1; -- 2.43.0