diff -uprk.orig Linux-PAM-0.80.orig/modules/pam_console/50-default.perms Linux-PAM-0.80/modules/pam_console/50-default.perms --- Linux-PAM-0.80.orig/modules/pam_console/50-default.perms 2005-07-14 13:14:27 +0000 +++ Linux-PAM-0.80/modules/pam_console/50-default.perms 2005-08-25 20:42:41 +0000 @@ -1,11 +1,12 @@ # device classes -- these are shell-style globs -=/dev/fd[0-1]* \ - /dev/floppy* /mnt/floppy* +=/dev/fd[0-7]* /dev/floppy/* /mnt/floppy* =/dev/dsp* /dev/audio* /dev/midi* \ - /dev/mixer* /dev/sequencer \ - /dev/sound/* /dev/beep \ - /dev/snd/* -=/dev/cdrom* /dev/cdroms/* /dev/cdwriter* /mnt/cdrom* + /dev/mixer* /dev/sequencer* /dev/admm* \ + /dev/adsp* /dev/aload* /dev/amidi* /dev/dmfm* \ + /dev/dmmidi* /dev/music /dev/patmgr* \ + /dev/sndstat /dev/snd/* /dev/sound/* /dev/beep +=/dev/dvd* /dev/cdrom* /dev/cdroms/* /mnt/cdrom* /mnt/dvd* +=/dev/scd* /dev/sr[0-7]* /dev/pcd* /dev/pg* /dev/cdwriter* =/dev/pilot =/mnt/jaz* =/mnt/pocketzip* /mnt/zip* /dev/zip* @@ -17,43 +18,45 @@ =/mnt/flash* /dev/flash* =/mnt/diskonkey* =/mnt/microdrive* -=/dev/fb /dev/fb[0-9]* \ - /dev/fb/* +=/dev/fb /dev/fb[0-9]* /dev/fb/* =/dev/kbd =/dev/js[0-9]* -=/dev/video* /dev/radio* /dev/winradio* /dev/vtx* /dev/vbi* \ - /dev/video/* +=/dev/video* /dev/video/* /dev/radio* /dev/winradio* /dev/vtx* /dev/vbi* /dev/vttuner =/dev/gpmctl =/dev/nvidia* /dev/3dfx* /dev/dri/card* =/dev/apm_bios =/dev/pmu =/dev/rfcomm* =/dev/raw1394 +=/dev/toshiba # permission definitions 0660 0660 root.floppy - 0600 0600 root - 0600 0660 root.disk - 0600 0660 root.uucp - 0600 0660 root.disk - 0600 0660 root.disk - 0600 0660 root.disk + 0660 0660 root.audio + 0640 0640 root.cdrom + 0660 0660 root.cdwriter + 0660 0660 root.uucp + 0660 0660 root.disk + 0660 0660 root.disk + 0660 0660 root.disk 0600 0600 root - 0600 0600 root.disk - 0600 0600 root.disk - 0600 0600 root.disk - 0600 0660 root.disk - 0600 0660 root.disk + 0660 0660 root.disk + 0660 0660 root.disk + 0660 0660 root.disk + 0660 0660 root.disk + 0660 0660 root.disk 0600 0600 root 0600 0600 root 0600 0600 root - 0600 0600 root - 0700 0700 root + 0660 0660 root.radio + 0700 0700 root 0600 0600 root - 0600 0600 root + 0660 0660 root.disk 0600 0600 root 0600 0600 root 0600 0600 root + 0600 0600 root + 0600 0600 root 0600 /dev/console 0600 root.root - 0600 0600 root + 0600 0600 root diff -uprk.orig Linux-PAM-0.80.orig/modules/pam_console/console.handlers Linux-PAM-0.80/modules/pam_console/console.handlers --- Linux-PAM-0.80.orig/modules/pam_console/console.handlers 2005-03-31 16:39:58 +0000 +++ Linux-PAM-0.80/modules/pam_console/console.handlers 2005-08-25 20:45:35 +0000 @@ -10,13 +10,13 @@ # See man console.handlers # # Example: -# console consoledevs tty[0-9][0-9]* vc/[0-9][0-9]* :[0-9]\.[0-9] :[0-9] +# console consoledevs (/dev/)?(tty|vc/)[0-9]+ :[0-9](\.[0-9])? # echo lock wait Locking console for user on tty # touch unlock wait /var/run/console-unlocked -console consoledevs tty[0-9][0-9]* vc/[0-9][0-9]* :[0-9]\.[0-9] :[0-9] +console consoledevs (/dev/)?(tty|vc/)[0-9]+ :[0-9](\.[0-9])? /sbin/pam_console_apply lock logfail wait -t tty -s /sbin/pam_console_apply unlock logfail wait -r -t tty -s # initialize dmix for alsa sound -/usr/bin/ainit lock user start -/usr/bin/ainit unlock user stop +#/usr/bin/ainit lock user start +#/usr/bin/ainit unlock user stop diff -uprk.orig Linux-PAM-0.80.orig/modules/pam_console/console.perms Linux-PAM-0.80/modules/pam_console/console.perms --- Linux-PAM-0.80.orig/modules/pam_console/console.perms 2005-07-14 13:13:44 +0000 +++ Linux-PAM-0.80/modules/pam_console/console.perms 2005-08-25 20:42:41 +0000 @@ -14,12 +14,12 @@ # For more information: # man 5 console.perms # -# This file should not be modified. # Rather a new file in the console.perms.d directory should be created. # file classes -- these are regular expressions -=tty[0-9][0-9]* vc/[0-9][0-9]* :[0-9]\.[0-9] :[0-9] +=(/dev/)?(tty|vc/)[0-9]+ :[0-9](\.[0-9])? =:[0-9]\.[0-9] :[0-9] +=(/dev/)?pts/[0-9]+ # device classes -- see console.perms.d/50-default.perms # permission definitions -- see console.perms.d/50-default.perms