From savko@tophouse.ru Wed Feb 4 11:48:37 2015 Received: (at submit) by bugs.x2go.org; 4 Feb 2015 10:48:38 +0000 X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on ymir.das-netzwerkteam.de X-Spam-Level: X-Spam-Status: No, score=0.8 required=5.0 tests=BAYES_50,URIBL_BLOCKED autolearn=ham version=3.3.2 X-Greylist: delayed 536 seconds by postgrey-1.34 at ymir.das-netzwerkteam.de; Wed, 04 Feb 2015 11:48:36 CET Received: from m.tophouse.ru (m.tophouse.ru [178.238.31.85]) by ymir.das-netzwerkteam.de (Postfix) with ESMTP id EE7AF5E073 for ; Wed, 4 Feb 2015 11:48:36 +0100 (CET) Received: from localhost (localhost.localdomain [127.0.0.1]) by m.tophouse.ru (Postfix) with ESMTP id C8BDB46423A for ; Wed, 4 Feb 2015 13:41:36 +0300 (MSK) Received: from m.tophouse.ru ([127.0.0.1]) by localhost (m.tophouse.ru [127.0.0.1]) (amavisd-new, port 10032) with ESMTP id U1JqZQO3oShX for ; Wed, 4 Feb 2015 13:41:36 +0300 (MSK) Received: from localhost (localhost.localdomain [127.0.0.1]) by m.tophouse.ru (Postfix) with ESMTP id E560A46424E for ; Wed, 4 Feb 2015 13:41:35 +0300 (MSK) X-Virus-Scanned: amavisd-new at m.tophouse.ru Received: from m.tophouse.ru ([127.0.0.1]) by localhost (m.tophouse.ru [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id 95yjSNL0Xl0S for ; Wed, 4 Feb 2015 13:41:35 +0300 (MSK) Received: from m.tophouse.ru (m.tophouse.ru [178.238.31.85]) by m.tophouse.ru (Postfix) with ESMTP id 9211546424A for ; Wed, 4 Feb 2015 13:41:35 +0300 (MSK) Date: Wed, 4 Feb 2015 14:41:35 +0400 (MSK) From: Sergey Savko To: submit@bugs.x2go.org Message-ID: <1445793820.50897.1423046495131.JavaMail.zimbra@tophouse.ru> In-Reply-To: <1249362733.50203.1423045063015.JavaMail.zimbra@tophouse.ru> Subject: x2goclient in broker mode with --broker-noauth MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="----=_Part_50895_1656359125.1423046495129" X-Mailer: Zimbra 8.0.8_GA_6184 (ZimbraWebClient - GC39 (Linux)/8.0.8_GA_6184) Thread-Topic: x2goclient in broker mode with --broker-noauth Thread-Index: 5FGeIuGQmN/z38S7kfGpdOR3YexZdw== ------=_Part_50895_1656359125.1423046495129 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit Package: x2goclient Version: 4.0.3.1 Tag: patch If x2goclient started in broker mode without pass-through authentication (--broker-noauth) and authentication on the server, x2goclient connected from the user who started the x2goclient. That isn't right, we can run x2goclient from any user and connect to the servers as a different user. Just x2goclient can't restore session from suspend. This patch allows you to start x2goclient from any user on the local system and connect to the server by the user that was entered in the authentication window. -- Yours truly, Sergey Savko. ------=_Part_50895_1656359125.1423046495129 Content-Type: text/x-patch; name=0001-x2goclient-broker-noauth-patch.patch Content-Disposition: attachment; filename=0001-x2goclient-broker-noauth-patch.patch Content-Transfer-Encoding: base64 RnJvbSAyNzBlNTgzNWZlNDllMDg0NDg3NGI5Nzc2OWU4ZGUxNTMyYTJhMDM5IE1vbiBTZXAgMTcg MDA6MDA6MDAgMjAwMQpGcm9tOiBTZXJnZXlfU2F2a28gPHNhdmtvQHRvcGhvdXNlLnJ1PgpEYXRl OiBXZWQsIDQgRmViIDIwMTUgMTI6MjQ6MTggKzAzMDAKU3ViamVjdDogW1BBVENIXSB4MmdvY2xp ZW50IC0tYnJva2VyLW5vYXV0aCBwYXRjaAoKLS0tCiBvbm1haW53aW5kb3cuY3BwIHwgICAgMyAr KysKIDEgZmlsZSBjaGFuZ2VkLCAzIGluc2VydGlvbnMoKykKCmRpZmYgLS1naXQgYS9vbm1haW53 aW5kb3cuY3BwIGIvb25tYWlud2luZG93LmNwcAppbmRleCA1YzM0NmU2Li44Mjg5NzVmIDEwMDY0 NAotLS0gYS9vbm1haW53aW5kb3cuY3BwCisrKyBiL29ubWFpbndpbmRvdy5jcHAKQEAgLTMwMzEs NiArMzAzMSw5IEBAIHZvaWQgT05NYWluV2luZG93OjpzbG90U2Vzc0VudGVyKCkKIAogICAgIGlm KGJyb2tlck1vZGUpCiAgICAgeworICAgICAgICBpZiAoY29uZmlnLmJyb2tlck5vQXV0aCkgewor CSAgICBjb25maWcuYnJva2VyVXNlciA9IGxvZ2luLT50ZXh0KCk7CisgICAgICAgIH0KICAgICAg ICAgYnJva2VyLT5zZWxlY3RVc2VyU2Vzc2lvbihzZXNzaW9uRXhwbG9yZXItPmdldExhc3RTZXNz aW9uKCktPmlkKCkpOwogICAgICAgICBjb25maWcuc2Vzc2lvbj1zZXNzaW9uRXhwbG9yZXItPmdl dExhc3RTZXNzaW9uKCktPmlkKCk7CiAgICAgICAgIHNldFN0YXRTdGF0dXMgKCB0ciAoICJDb25u ZWN0aW5nIHRvIGJyb2tlciIgKSApOwotLSAKMS43LjEwLjQKCg== ------=_Part_50895_1656359125.1423046495129-- From mike.gabriel@das-netzwerkteam.de Wed Feb 4 15:59:08 2015 Received: (at 781) by bugs.x2go.org; 4 Feb 2015 14:59:16 +0000 X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on ymir.das-netzwerkteam.de X-Spam-Level: X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,URIBL_BLOCKED autolearn=unavailable version=3.3.2 Received: from freya.das-netzwerkteam.de (freya.das-netzwerkteam.de [88.198.48.199]) by ymir.das-netzwerkteam.de (Postfix) with ESMTPS id 55F955E073; Wed, 4 Feb 2015 15:59:08 +0100 (CET) Received: from grimnir.das-netzwerkteam.de (grimnir.das-netzwerkteam.de [78.46.204.98]) by freya.das-netzwerkteam.de (Postfix) with ESMTPS id 038CE38C; Wed, 4 Feb 2015 15:59:08 +0100 (CET) Received: from localhost (localhost [127.0.0.1]) by grimnir.das-netzwerkteam.de (Postfix) with ESMTP id DE85A3C06B; Wed, 4 Feb 2015 15:59:07 +0100 (CET) X-Virus-Scanned: Debian amavisd-new at grimnir.das-netzwerkteam.de Received: from grimnir.das-netzwerkteam.de ([127.0.0.1]) by localhost (grimnir.das-netzwerkteam.de [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7sdgtRq2TZbe; Wed, 4 Feb 2015 15:59:07 +0100 (CET) Received: from grimnir.das-netzwerkteam.de (localhost [127.0.0.1]) by grimnir.das-netzwerkteam.de (Postfix) with ESMTPS id 8391C3BA69; Wed, 4 Feb 2015 15:59:07 +0100 (CET) Received: from m-097.informatik.uni-kiel.de (m-097.informatik.uni-kiel.de [134.245.254.97]) by mail.das-netzwerkteam.de (Horde Framework) with HTTP; Wed, 04 Feb 2015 14:59:07 +0000 Date: Wed, 04 Feb 2015 14:59:07 +0000 Message-ID: <20150204145907.Horde.gQHo-olBJ8GjQQL7uzk4_Q2@mail.das-netzwerkteam.de> From: Mike Gabriel To: Sergey Savko , 781@bugs.x2go.org Cc: 781-submitter@bugs.x2go.org Subject: Re: [X2Go-Dev] Bug#781: x2goclient in broker mode with --broker-noauth References: <1249362733.50203.1423045063015.JavaMail.zimbra@tophouse.ru> <1445793820.50897.1423046495131.JavaMail.zimbra@tophouse.ru> In-Reply-To: <1445793820.50897.1423046495131.JavaMail.zimbra@tophouse.ru> User-Agent: Internet Messaging Program (IMP) H5 (6.2.2) Accept-Language: de,en Organization: DAS-NETZWERKTEAM X-Originating-IP: 134.245.254.97 X-Remote-Browser: Mozilla/5.0 (X11; Linux x86_64; rv:32.0) Gecko/20100101 Firefox/32.0 Iceweasel/32.0 Content-Type: multipart/signed; boundary="=_bzoSvBNw30uAHM7cUU9TPw1"; protocol="application/pgp-signature"; micalg=pgp-sha1 MIME-Version: 1.0 This message is in MIME format and has been PGP signed. --=_bzoSvBNw30uAHM7cUU9TPw1 Content-Type: text/plain; charset=utf-8; format=flowed; DelSp=Yes Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Hi Alex, On Mi 04 Feb 2015 11:41:35 CET, Sergey Savko wrote: > Package: x2goclient > Version: 4.0.3.1 > Tag: patch > > If x2goclient started in broker mode without pass-through=20=20 >=20authentication (--broker-noauth) and authentication on the server,=20= =20 >=20x2goclient connected from the user who started the x2goclient. > That isn't right, we can run x2goclient from any user and connect to=20= =20 >=20the servers as a different user. Just x2goclient can't restore=20=20 >=20session from suspend. > This patch allows you to start x2goclient from any user on the local=20= =20 >=20system and connect to the server by the user that was entered in the=20= =20 >=20authentication window. can you please review Sergey's patch attached to #781? Would switching=20= =20 to=20the X2Go Server username for the "selectsession" broker task break=20= =20 any=20of your deployed setups? Optionally, I would suggest adding a cmdline option=20=20 (--broker-noauth-with-session-username=20or such) that enables the=20=20 provided=20patch (which makes sense from my point of view). Greets, Mike --=20 DAS-NETZWERKTEAM mike=20gabriel, herweg 7, 24357 fleckeby fon: +49 (1520) 1976 148 GnuPG Key ID 0x25771B31 mail: mike.gabriel@das-netzwerkteam.de, http://das-netzwerkteam.de freeBusy: https://mail.das-netzwerkteam.de/freebusy/m.gabriel%40das-netzwerkteam.de.x= fb --=_bzoSvBNw30uAHM7cUU9TPw1 Content-Type: application/pgp-signature Content-Description: Digitale PGP-Signatur Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAABAgAGBQJU0jO7AAoJEJr0azAldxsxgGkP/iACTWJbG04cWu5+5f1uaruS oBjc7IS8aMQQX2SsW1vdzJadJE8I8yzP2rKVC7VetGTPPA23hY1KcOugt4DZx5g5 OkWBS00G92zAFow6sZB7LUFpwPCLUklJ3XDnMGVuGCq7QqQkYF71MCoze1rmFQYm 6Ucvx/4HqzyU+cYwIjqp2T9TQa5pgzfSN+mVOBJV84hsR//KReTljtIts85MTyyL p3UlXf36hocfNwzBTFvr9ls0nVMnKiD8JhorPnVprN0bKlPPf7L0G9Exf/+kdcf4 FJ91wNo61LxMKV/qJh0kjlT/6f2HPHVzWOAH4xd3jlitvwRcYjs5KETfa1vUve6/ 24RgXoeCYgYRlojfvbwXjl/Ff8+VtG1qQ16pNrSZNeGxEL+4aZ70T9i0N6ZwN3D0 by6VlNZ4FrkUrAb9hSctM2OlAgm7ONzr2sEaqWC2gk5DE1vzFQQubzcn3tUDFB8Q eGS2UEtYi7JfxStimQIqbMNAkcH9UfO1qX8s1STO8mSvlO/Dtvchi85Ws24WDFHN +vAh+xqgQ9huX/cHnjewC4+cAQdMeJuI40E9xN/P0mMZHUVl/8IkAFKR/t6cRNY+ iNemQTyTA2HYsvbaVosk1sfBTNaPNo6UZw4RtL/OM3VSs0qV15qVhx05pbdhcF3q vl9bOuJrr933JBfLANl3 =z3Dd -----END PGP SIGNATURE----- --=_bzoSvBNw30uAHM7cUU9TPw1-- From savko@tophouse.ru Fri Feb 6 12:23:36 2015 Received: (at 781) by bugs.x2go.org; 6 Feb 2015 11:23:38 +0000 X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on ymir.das-netzwerkteam.de X-Spam-Level: X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,URIBL_BLOCKED autolearn=ham version=3.3.2 X-Greylist: delayed 303 seconds by postgrey-1.34 at ymir.das-netzwerkteam.de; Fri, 06 Feb 2015 12:23:36 CET Received: from m.tophouse.ru (m.tophouse.ru [178.238.31.85]) by ymir.das-netzwerkteam.de (Postfix) with ESMTP id 6D4495DB49 for <781@bugs.x2go.org>; Fri, 6 Feb 2015 12:23:36 +0100 (CET) Received: from localhost (localhost.localdomain [127.0.0.1]) by m.tophouse.ru (Postfix) with ESMTP id 7E698466BE3; Fri, 6 Feb 2015 14:20:30 +0300 (MSK) Received: from m.tophouse.ru ([127.0.0.1]) by localhost (m.tophouse.ru [127.0.0.1]) (amavisd-new, port 10032) with ESMTP id 91WntSlou-ps; Fri, 6 Feb 2015 14:20:29 +0300 (MSK) Received: from localhost (localhost.localdomain [127.0.0.1]) by m.tophouse.ru (Postfix) with ESMTP id 8F84A466BF3; Fri, 6 Feb 2015 14:20:29 +0300 (MSK) X-Virus-Scanned: amavisd-new at m.tophouse.ru Received: from m.tophouse.ru ([127.0.0.1]) by localhost (m.tophouse.ru [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id 3ePe4j5bHJhD; Fri, 6 Feb 2015 14:20:29 +0300 (MSK) Received: from m.tophouse.ru (m.tophouse.ru [178.238.31.85]) by m.tophouse.ru (Postfix) with ESMTP id 4FC5D466BE6; Fri, 6 Feb 2015 14:20:29 +0300 (MSK) Date: Fri, 6 Feb 2015 15:20:29 +0400 (MSK) From: Sergey Savko To: 781@bugs.x2go.org, mike.gabriel@das-netzwerkteam.de Message-ID: <1582476221.87898.1423221629013.JavaMail.zimbra@tophouse.ru> In-Reply-To: <264480976.86214.1423221542377.JavaMail.zimbra@tophouse.ru> Subject: second patch MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="----=_Part_87896_1835545520.1423221629011" X-Mailer: Zimbra 8.0.8_GA_6184 (ZimbraWebClient - GC39 (Linux)/8.0.8_GA_6184) Thread-Topic: second patch Thread-Index: qxDeZEccRueXpv2M6/Q+FKSmoJZKrQ== ------=_Part_87896_1835545520.1423221629011 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit -- Yours truly, Sergey Savko. ------=_Part_87896_1835545520.1423221629011 Content-Type: text/x-patch; name=0001-x2goclient-broker-noauth-patch.patch Content-Disposition: attachment; filename=0001-x2goclient-broker-noauth-patch.patch Content-Transfer-Encoding: base64 RnJvbSBlNDlmYzkyOGUzOGFhOTIwMmYwYzJiYmI2ZTFhNDQ4MWRlOWJlZmM0IE1vbiBTZXAgMTcg MDA6MDA6MDAgMjAwMQpGcm9tOiBTZXJnZXlfU2F2a28gPHNhdmtvQHRvcGhvdXNlLnJ1PgpEYXRl OiBGcmksIDYgRmViIDIwMTUgMTQ6MTU6NTMgKzAzMDAKU3ViamVjdDogW1BBVENIXSB4MmdvY2xp ZW50IGJyb2tlciBub2F1dGggcGF0Y2gKCi0tLQogbWFuL21hbjEveDJnb2NsaWVudC4xIHwgICAg MyArKysKIG9ubWFpbndpbmRvdy5jcHAgICAgICB8ICAgMTAgKysrKysrKysrKwogb25tYWlud2lu ZG93LmggICAgICAgIHwgICAgMSArCiAzIGZpbGVzIGNoYW5nZWQsIDE0IGluc2VydGlvbnMoKykK CmRpZmYgLS1naXQgYS9tYW4vbWFuMS94MmdvY2xpZW50LjEgYi9tYW4vbWFuMS94MmdvY2xpZW50 LjEKaW5kZXggZDc4NWU5YS4uMGJjNDM1NCAxMDA2NDQKLS0tIGEvbWFuL21hbjEveDJnb2NsaWVu dC4xCisrKyBiL21hbi9tYW4xL3gyZ29jbGllbnQuMQpAQCAtMjYxLDYgKzI2MSw5IEBAIFJ1biBh IGNvbm5lY3Rpdml0eSB0ZXN0IGFnYWluc3QgWDJHbyBTZXNzaW9uIEJyb2tlci4gTm90IHN1cHBv cnRlZCBieSBhbGwgYnJva2VyCiAuVFAKIFwqKFQ8XGZCXC1cLWNoYW5nZS1icm9rZXItcGFzc1xm UlwqKFQ+CiBTZW5kIGEgY2hhbmdlLXBhc3N3b3JkIHJlcXVlc3QgdG8gYW4gWDJHbyBTZXNzaW9u IEJyb2tlci4gTm90IHN1cHBvcnRlZCBieSBhbGwgYnJva2VyIGltcGxlbWVudGF0aW9ucy4KKy5U UAorXCooVDxcZkJcLVwtYnJva2VyLW5vYXV0aC13aXRoLXNlc3Npb24tdXNlcm5hbWVcZlJcKihU PgorSW5mb3JtcyB0aGUgYnJva2VyIHRvIHVzZSB0aGUgdXNlcm5hbWUgeW91IGVudGVyZWQgd2hl biBhdXRoZW50aWNhdGluZy4KIAogLlNIIExEQVAgT1BUSU9OUyAoZGVwcmVjYXRlZCkKIE5PVEU6 IExEQVAgc3VwcG9ydCB3b24ndCBiZSBjb250aW51ZWQgaW4gWDJHbyBDbGllbnQgMiAobmV4dCBn ZW5lcmF0aW9uIG9mIFgyR28gQ2xpZW50KS4gCmRpZmYgLS1naXQgYS9vbm1haW53aW5kb3cuY3Bw IGIvb25tYWlud2luZG93LmNwcAppbmRleCA1YzM0NmU2Li44YmFjZTA3IDEwMDY0NAotLS0gYS9v bm1haW53aW5kb3cuY3BwCisrKyBiL29ubWFpbndpbmRvdy5jcHAKQEAgLTcxLDYgKzcxLDcgQEAg T05NYWluV2luZG93OjpPTk1haW5XaW5kb3cgKCBRV2lkZ2V0ICpwYXJlbnQgKSA6UU1haW5XaW5k b3cgKCBwYXJlbnQgKQogICAgIHN0YXJ0SGlkZGVuPWZhbHNlOwogICAgIGtlZXBUcmF5SWNvbj1m YWxzZTsKICAgICBoaWRlRm9sZGVyU2hhcmluZz1mYWxzZTsKKyAgICBicm9rZXJOb2F1dGhXaXRo U2Vzc2lvbj1mYWxzZTsKICAgICB0aGluTW9kZT1mYWxzZTsKICAgICBjbG9zZURpc2Nvbm5lY3Q9 ZmFsc2U7CiAgICAgc2hvd0hhbHRCdG49ZmFsc2U7CkBAIC0zMDMxLDYgKzMwMzIsOSBAQCB2b2lk IE9OTWFpbldpbmRvdzo6c2xvdFNlc3NFbnRlcigpCiAKICAgICBpZihicm9rZXJNb2RlKQogICAg IHsKKwlpZiAoY29uZmlnLmJyb2tlck5vQXV0aCAmJiBicm9rZXJOb2F1dGhXaXRoU2Vzc2lvbikg eworICAgICAgICAgICAgY29uZmlnLmJyb2tlclVzZXIgPSBsb2dpbi0+dGV4dCgpOworICAgICAg ICB9CiAgICAgICAgIGJyb2tlci0+c2VsZWN0VXNlclNlc3Npb24oc2Vzc2lvbkV4cGxvcmVyLT5n ZXRMYXN0U2Vzc2lvbigpLT5pZCgpKTsKICAgICAgICAgY29uZmlnLnNlc3Npb249c2Vzc2lvbkV4 cGxvcmVyLT5nZXRMYXN0U2Vzc2lvbigpLT5pZCgpOwogICAgICAgICBzZXRTdGF0U3RhdHVzICgg dHIgKCAiQ29ubmVjdGluZyB0byBicm9rZXIiICkgKTsKQEAgLTY2NjEsNiArNjY2NSwxMiBAQCBi b29sIE9OTWFpbldpbmRvdzo6cGFyc2VQYXJhbWV0ZXIgKCBRU3RyaW5nIHBhcmFtICkKICAgICAg ICAgY29uZmlnLmJyb2tlck5vQXV0aD10cnVlOwogICAgICAgICByZXR1cm4gdHJ1ZTsKICAgICB9 CisgICAgCisgICAgaWYgKCBwYXJhbT09Ii0tYnJva2VyLW5vYXV0aC13aXRoLXNlc3Npb24tdXNl cm5hbWUiICkKKyAgICB7CisgICAgICAgIGJyb2tlck5vYXV0aFdpdGhTZXNzaW9uPXRydWU7Cisg ICAgICAgIHJldHVybiB0cnVlOworICAgIH0KIAogICAgIC8vZm9yY2UgdG8gc2hvdyB0cmF5aWNv bgogICAgIGlmIChwYXJhbSA9PSAiLS10cmF5LWljb24iKQpkaWZmIC0tZ2l0IGEvb25tYWlud2lu ZG93LmggYi9vbm1haW53aW5kb3cuaAppbmRleCAxNDk4ZTE2Li41YTZkYzBkIDEwMDY0NAotLS0g YS9vbm1haW53aW5kb3cuaAorKysgYi9vbm1haW53aW5kb3cuaApAQCAtNTkyLDYgKzU5Miw3IEBA IHByaXZhdGU6CiAgICAgYm9vbCBzdGFydEhpZGRlbjsKICAgICBib29sIGtlZXBUcmF5SWNvbjsK ICAgICBib29sIGhpZGVGb2xkZXJTaGFyaW5nOworICAgIGJvb2wgYnJva2VyTm9hdXRoV2l0aFNl c3Npb247CiAgICAgYm9vbCBkZWZhdWx0VXNlU291bmQ7CiAgICAgYm9vbCBkZWZhdWx0WGluZXJh bWE7CiAgICAgYm9vbCBjYXJkU3RhcnRlZDsKLS0gCjEuNy4xMC40Cgo= ------=_Part_87896_1835545520.1423221629011-- From x2go@ymir.das-netzwerkteam.de Fri Feb 6 14:13:52 2015 Received: (at 781) by bugs.x2go.org; 6 Feb 2015 13:13:53 +0000 X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on ymir.das-netzwerkteam.de X-Spam-Level: X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,NO_RELAYS, URIBL_BLOCKED autolearn=ham version=3.3.2 Received: by ymir.das-netzwerkteam.de (Postfix, from userid 1005) id 24BC83BC8A; Fri, 6 Feb 2015 14:13:51 +0100 (CET) From: Mike Gabriel To: 781-submitter@bugs.x2go.org Cc: control@bugs.x2go.org, 781@bugs.x2go.org Subject: X2Go issue (in src:x2goclient) has been marked as pending for release Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit X-Mailer: http://snipr.com/post-receive-tag-pending Message-Id: <20150206131352.24BC83BC8A@ymir.das-netzwerkteam.de> Date: Fri, 6 Feb 2015 14:13:51 +0100 (CET) tag #781 pending fixed #781 4.0.3.2 thanks Hello, X2Go issue #781 (src:x2goclient) reported by you has been fixed in X2Go Git. You can see the changelog below, and you can check the diff of the fix at: http://code.x2go.org/gitweb?p=x2goclient.git;a=commitdiff;h=58e4845 The issue will most likely be fixed in src:x2goclient (4.0.3.2). light+love X2Go Git Admin (on behalf of the sender of this mail) --- commit 58e4845eb5ccb9ce9d3baca75698c91f7e71377d Author: Sergey_Savko Date: Fri Feb 6 14:15:53 2015 +0300 Add new cmdline option --broker-noauth-use-session-username. When --broker-noauth is used, the broker does not know on behalf of which user to operate. This new option enables username syncing. When logging into X2Go Server, that username will be sent to the broker and be used for querying X2Go Broker Agents etc. (Fixes: #781). diff --git a/debian/changelog b/debian/changelog index c6fe947..c40f3ab 100644 --- a/debian/changelog +++ b/debian/changelog @@ -39,6 +39,11 @@ x2goclient (4.0.3.2-0x2go1) UNRELEASED; urgency=medium * New upstream release (4.0.3.2): - Prevent passwordless re-logins into X2Go Session Broker if --broker-autologoff is used on the cmdline. (Fixes: #782). + - Add new cmdline option --broker-noauth-use-session-username. + When --broker-noauth is used, the broker does not know on behalf + of which user to operate. This new option enables username syncing. + When logging into X2Go Server, that username will be sent to the + broker and be used for querying X2Go Broker Agents etc. (Fixes: #781). [ Heinrich Schuchardt ] * New upstream release (4.0.3.2): From x2go@ymir.das-netzwerkteam.de Thu Feb 19 12:58:02 2015 Received: (at 781) by bugs.x2go.org; 19 Feb 2015 11:58:19 +0000 X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on ymir.das-netzwerkteam.de X-Spam-Level: X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,NO_RELAYS, URIBL_BLOCKED autolearn=unavailable version=3.3.2 Received: by ymir.das-netzwerkteam.de (Postfix, from userid 1005) id D9C0B5E156; Thu, 19 Feb 2015 12:58:00 +0100 (CET) From: X2Go Release Manager To: 781-submitter@bugs.x2go.org Cc: control@bugs.x2go.org, 781@bugs.x2go.org Subject: X2Go issue (in src:x2goclient) has been marked as closed Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit Message-Id: <20150219115801.D9C0B5E156@ymir.das-netzwerkteam.de> Date: Thu, 19 Feb 2015 12:58:00 +0100 (CET) close #781 thanks Hello, we are very hopeful that X2Go issue #781 reported by you has been resolved in the new release (4.0.3.2) of the X2Go source project »src:x2goclient«. You can view the complete changelog entry of src:x2goclient (4.0.3.2) below, and you can use the following link to view all the code changes between this and the last release of src:x2goclient. http://code.x2go.org/gitweb?p=x2goclient.git;a=commitdiff;h=3b7ca68412005521d45d9751a370549ab1c80e58;hp=5290218751cc68a1fc1711ebd169e195eb3daeed If you feel that the issue has not been resolved satisfyingly, feel free to reopen this bug report or submit a follow-up report with further observations described based on the new released version of src:x2goclient. Thanks a lot for contributing to X2Go!!! light+love X2Go Git Admin (on behalf of the sender of this mail) --- X2Go Component: src:x2goclient Version: 4.0.3.2-0x2go1 Status: RELEASE Date: Thu, 19 Feb 2015 12:49:22 +0100 Fixes: 616 642 681 702 705 713 720 742 781 782 Changes: x2goclient (4.0.3.2-0x2go1) RELEASED; urgency=medium . [ Oleksandr Shneyder ] * New upstream release (4.0.3.2): - Fix placement of session folders in session card column. (Fixes: #681). - Send empty message in x2gohelper to stop AppStarting cursor. (Fixes: #616). - Fix multiple creations of modmap timer (OS_DARWIN). . [ Mike Gabriel ] * New upstream release (4.0.3.2): - Add several info/error/debug log message while hunting down #702. - Use app.setQuitOnLastWindowClosed(false) for the X2Go Client QtApplication to assure that X2Go Client does not arbitrarily exit during a running session. This fixes X2Go Client crashes that occur when printing via the CUPS-X2Go printing mechanism with activate print dialog popup on incoming print jobs and minimized main window. (Fixes: #702). - Be more exact when reporting rev forwarding tunnel request failures to the GUI user. Include the purpose of the tunnel (NX, audio, foldersharing) in the error message. - Enable debugging in sshprocess.cpp and sshmasterconnection.cpp if --debug is given. - sshmasterconnection.cpp: Fix several grammar issues in error messages. - When sharing a client-side folder, do not write the SSH pub key to client-side authorized_keys file if the folder-to-be-shared does not exist on the client. (Partially solves #405). - Fix string concatenation/layout of error message when tunnel I/O errors occur. - Improve debugging/logging the SSH connections made by X2Go Client. - Fix quotes when calling remote commands via SSH (esp. allow same quoting/ escaping style for libssh and openSSH+Krb based connections). (Fixes: #720). - FIXME: Disable PubkeyAuthentication _and_ PasswordAuthentication if GSSAPI authentication is activated. This is counter intuitive, though, and requires several other fixes in the authentication code. * x2goclient.spec: - Always set BuildRoot: parameter. . [ Sergey Savko ] * New upstream release (4.0.3.2): - Prevent passwordless re-logins into X2Go Session Broker if --broker-autologoff is used on the cmdline. (Fixes: #782). - Add new cmdline option --broker-noauth-use-session-username. When --broker-noauth is used, the broker does not know on behalf of which user to operate. This new option enables username syncing. When logging into X2Go Server, that username will be sent to the broker and be used for querying X2Go Broker Agents etc. (Fixes: #781). . [ Heinrich Schuchardt ] * New upstream release (4.0.3.2): - Base the layout dialogue "Session ID" (which shows up when starting a connection) on typographic points (instead of pixels). (Fixes: #713). . [ Jason Alavaliant ] * New upstream verson (4.0.3.2): - Use QUrl::toPercentEncoding() method to properly encode passwords sent to X2Go Session Broker. (Fixes: #705). . [ Mike DePaulo ] * New upstream release (4.0.3.2): - Windows: Win32 OpenSSL updates from 1.0.1j to 1.0.1L, which fixes the CVEs announced on 2015-01-08. - Windows: Cygwin OpenSSL updated from 1.0.1j-1 to 1.0.1k-1, which fixes the CVEs announced on 2015-01-08. - Windows: Bundle new version of VcXsrv: 1.15.2.2-xp+vc2013+x2go1. The differences from 1.15.2.1-xp+vc2013+x2go1 are that its bundled OpenSSL has been updated to 1.0.1k, and that xorg-server CVE-2014-8091..8103 have been fixed. - Windows: Update libssh from 0.6.3 to 0.6.4 (while maintaining Pageant support). This fixes CVE-2014-8132, which shouldn't affect x2goclient because x2goclient uses the SSH client functionality, not the SSH server functionality. 0.6.4 also added 4 features related to ECDSA keys. - Windows: Fix compatibility with PulseAudio 6.0 - Windows: Remove workaround for audio input with old versions of PulseAudio (calling parec once per second) (Fixes: #742) Thanks George Trakatelis (uom.edu.gr) for submitting this change. - Windows: Enable X2Go Client for Windows to build under VS2010 nmake (but not the VS2010 IDE due to a Qt4 Visual Studio Add-in limitation) Note that the official builds are still build under MinGW. (Fixes: #642) Thanks George Trakatelis (uom.edu.gr) for submitting this feature. - Windows: Make builds easier, and updating bundled dependencies easier, by adding copy-deps-win32.bat. It copies the exact version of each dependency (DLL, executable, data, folder, etc) from x2goclient-contrib.git. . [ Kaan Ozdincer ] * New upstream version (4.0.3.2): - Add Turkish translation file. From unknown Thu Mar 28 09:16:18 2024 MIME-Version: 1.0 X-Mailer: MIME-tools 5.502 (Entity 5.502) X-Loop: owner@bugs.x2go.org From: owner@bugs.x2go.org (X2Go Bug Tracking System) Subject: Bug#781 closed by X2Go Release Manager (X2Go issue (in src:x2goclient) has been marked as closed) Message-ID: References: <20150219115801.D9C0B5E156@ymir.das-netzwerkteam.de> X-X2go-PR-Keywords: pending X-X2go-PR-Message: they-closed 781 X-X2go-PR-Package: x2goclient X-X2go-PR-Source: x2goclient Date: Thu, 19 Feb 2015 12:00:22 +0000 Content-Type: multipart/mixed; boundary="----------=_1424347222-20582-0" This is a multi-part message in MIME format... ------------=_1424347222-20582-0 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=utf-8 This is an automatic notification regarding your Bug report which was filed against the x2goclient package: #781: x2goclient in broker mode with --broker-noauth It has been closed by X2Go Release Manager . Their explanation is attached below along with your original report. If this explanation is unsatisfactory and you have not received a better one in a separate message then please contact X2Go Release Manager <= git-admin@x2go.org> by replying to this email. --=20 X2Go Bug Tracking System Contact owner@bugs.x2go.org with problems ------------=_1424347222-20582-0 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at control) by bugs.x2go.org; 19 Feb 2015 11:58:31 +0000 X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on ymir.das-netzwerkteam.de X-Spam-Level: X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,NO_RELAYS, URIBL_BLOCKED autolearn=unavailable version=3.3.2 Received: by ymir.das-netzwerkteam.de (Postfix, from userid 1005) id D9C0B5E156; Thu, 19 Feb 2015 12:58:00 +0100 (CET) From: X2Go Release Manager To: 781-submitter@bugs.x2go.org Cc: control@bugs.x2go.org, 781@bugs.x2go.org Subject: X2Go issue (in src:x2goclient) has been marked as closed Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit Message-Id: <20150219115801.D9C0B5E156@ymir.das-netzwerkteam.de> Date: Thu, 19 Feb 2015 12:58:00 +0100 (CET) close #781 thanks Hello, we are very hopeful that X2Go issue #781 reported by you has been resolved in the new release (4.0.3.2) of the X2Go source project »src:x2goclient«. You can view the complete changelog entry of src:x2goclient (4.0.3.2) below, and you can use the following link to view all the code changes between this and the last release of src:x2goclient. http://code.x2go.org/gitweb?p=x2goclient.git;a=commitdiff;h=3b7ca68412005521d45d9751a370549ab1c80e58;hp=5290218751cc68a1fc1711ebd169e195eb3daeed If you feel that the issue has not been resolved satisfyingly, feel free to reopen this bug report or submit a follow-up report with further observations described based on the new released version of src:x2goclient. Thanks a lot for contributing to X2Go!!! light+love X2Go Git Admin (on behalf of the sender of this mail) --- X2Go Component: src:x2goclient Version: 4.0.3.2-0x2go1 Status: RELEASE Date: Thu, 19 Feb 2015 12:49:22 +0100 Fixes: 616 642 681 702 705 713 720 742 781 782 Changes: x2goclient (4.0.3.2-0x2go1) RELEASED; urgency=medium . [ Oleksandr Shneyder ] * New upstream release (4.0.3.2): - Fix placement of session folders in session card column. (Fixes: #681). - Send empty message in x2gohelper to stop AppStarting cursor. (Fixes: #616). - Fix multiple creations of modmap timer (OS_DARWIN). . [ Mike Gabriel ] * New upstream release (4.0.3.2): - Add several info/error/debug log message while hunting down #702. - Use app.setQuitOnLastWindowClosed(false) for the X2Go Client QtApplication to assure that X2Go Client does not arbitrarily exit during a running session. This fixes X2Go Client crashes that occur when printing via the CUPS-X2Go printing mechanism with activate print dialog popup on incoming print jobs and minimized main window. (Fixes: #702). - Be more exact when reporting rev forwarding tunnel request failures to the GUI user. Include the purpose of the tunnel (NX, audio, foldersharing) in the error message. - Enable debugging in sshprocess.cpp and sshmasterconnection.cpp if --debug is given. - sshmasterconnection.cpp: Fix several grammar issues in error messages. - When sharing a client-side folder, do not write the SSH pub key to client-side authorized_keys file if the folder-to-be-shared does not exist on the client. (Partially solves #405). - Fix string concatenation/layout of error message when tunnel I/O errors occur. - Improve debugging/logging the SSH connections made by X2Go Client. - Fix quotes when calling remote commands via SSH (esp. allow same quoting/ escaping style for libssh and openSSH+Krb based connections). (Fixes: #720). - FIXME: Disable PubkeyAuthentication _and_ PasswordAuthentication if GSSAPI authentication is activated. This is counter intuitive, though, and requires several other fixes in the authentication code. * x2goclient.spec: - Always set BuildRoot: parameter. . [ Sergey Savko ] * New upstream release (4.0.3.2): - Prevent passwordless re-logins into X2Go Session Broker if --broker-autologoff is used on the cmdline. (Fixes: #782). - Add new cmdline option --broker-noauth-use-session-username. When --broker-noauth is used, the broker does not know on behalf of which user to operate. This new option enables username syncing. When logging into X2Go Server, that username will be sent to the broker and be used for querying X2Go Broker Agents etc. (Fixes: #781). . [ Heinrich Schuchardt ] * New upstream release (4.0.3.2): - Base the layout dialogue "Session ID" (which shows up when starting a connection) on typographic points (instead of pixels). (Fixes: #713). . [ Jason Alavaliant ] * New upstream verson (4.0.3.2): - Use QUrl::toPercentEncoding() method to properly encode passwords sent to X2Go Session Broker. (Fixes: #705). . [ Mike DePaulo ] * New upstream release (4.0.3.2): - Windows: Win32 OpenSSL updates from 1.0.1j to 1.0.1L, which fixes the CVEs announced on 2015-01-08. - Windows: Cygwin OpenSSL updated from 1.0.1j-1 to 1.0.1k-1, which fixes the CVEs announced on 2015-01-08. - Windows: Bundle new version of VcXsrv: 1.15.2.2-xp+vc2013+x2go1. The differences from 1.15.2.1-xp+vc2013+x2go1 are that its bundled OpenSSL has been updated to 1.0.1k, and that xorg-server CVE-2014-8091..8103 have been fixed. - Windows: Update libssh from 0.6.3 to 0.6.4 (while maintaining Pageant support). This fixes CVE-2014-8132, which shouldn't affect x2goclient because x2goclient uses the SSH client functionality, not the SSH server functionality. 0.6.4 also added 4 features related to ECDSA keys. - Windows: Fix compatibility with PulseAudio 6.0 - Windows: Remove workaround for audio input with old versions of PulseAudio (calling parec once per second) (Fixes: #742) Thanks George Trakatelis (uom.edu.gr) for submitting this change. - Windows: Enable X2Go Client for Windows to build under VS2010 nmake (but not the VS2010 IDE due to a Qt4 Visual Studio Add-in limitation) Note that the official builds are still build under MinGW. (Fixes: #642) Thanks George Trakatelis (uom.edu.gr) for submitting this feature. - Windows: Make builds easier, and updating bundled dependencies easier, by adding copy-deps-win32.bat. It copies the exact version of each dependency (DLL, executable, data, folder, etc) from x2goclient-contrib.git. . [ Kaan Ozdincer ] * New upstream version (4.0.3.2): - Add Turkish translation file. ------------=_1424347222-20582-0 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at submit) by bugs.x2go.org; 4 Feb 2015 10:48:38 +0000 X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on ymir.das-netzwerkteam.de X-Spam-Level: X-Spam-Status: No, score=0.8 required=5.0 tests=BAYES_50,URIBL_BLOCKED autolearn=ham version=3.3.2 X-Greylist: delayed 536 seconds by postgrey-1.34 at ymir.das-netzwerkteam.de; Wed, 04 Feb 2015 11:48:36 CET Received: from m.tophouse.ru (m.tophouse.ru [178.238.31.85]) by ymir.das-netzwerkteam.de (Postfix) with ESMTP id EE7AF5E073 for ; Wed, 4 Feb 2015 11:48:36 +0100 (CET) Received: from localhost (localhost.localdomain [127.0.0.1]) by m.tophouse.ru (Postfix) with ESMTP id C8BDB46423A for ; Wed, 4 Feb 2015 13:41:36 +0300 (MSK) Received: from m.tophouse.ru ([127.0.0.1]) by localhost (m.tophouse.ru [127.0.0.1]) (amavisd-new, port 10032) with ESMTP id U1JqZQO3oShX for ; Wed, 4 Feb 2015 13:41:36 +0300 (MSK) Received: from localhost (localhost.localdomain [127.0.0.1]) by m.tophouse.ru (Postfix) with ESMTP id E560A46424E for ; Wed, 4 Feb 2015 13:41:35 +0300 (MSK) X-Virus-Scanned: amavisd-new at m.tophouse.ru Received: from m.tophouse.ru ([127.0.0.1]) by localhost (m.tophouse.ru [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id 95yjSNL0Xl0S for ; Wed, 4 Feb 2015 13:41:35 +0300 (MSK) Received: from m.tophouse.ru (m.tophouse.ru [178.238.31.85]) by m.tophouse.ru (Postfix) with ESMTP id 9211546424A for ; Wed, 4 Feb 2015 13:41:35 +0300 (MSK) Date: Wed, 4 Feb 2015 14:41:35 +0400 (MSK) From: Sergey Savko To: submit@bugs.x2go.org Message-ID: <1445793820.50897.1423046495131.JavaMail.zimbra@tophouse.ru> In-Reply-To: <1249362733.50203.1423045063015.JavaMail.zimbra@tophouse.ru> Subject: x2goclient in broker mode with --broker-noauth MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="----=_Part_50895_1656359125.1423046495129" X-Mailer: Zimbra 8.0.8_GA_6184 (ZimbraWebClient - GC39 (Linux)/8.0.8_GA_6184) Thread-Topic: x2goclient in broker mode with --broker-noauth Thread-Index: 5FGeIuGQmN/z38S7kfGpdOR3YexZdw== ------=_Part_50895_1656359125.1423046495129 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit Package: x2goclient Version: 4.0.3.1 Tag: patch If x2goclient started in broker mode without pass-through authentication (--broker-noauth) and authentication on the server, x2goclient connected from the user who started the x2goclient. That isn't right, we can run x2goclient from any user and connect to the servers as a different user. Just x2goclient can't restore session from suspend. This patch allows you to start x2goclient from any user on the local system and connect to the server by the user that was entered in the authentication window. -- Yours truly, Sergey Savko. ------=_Part_50895_1656359125.1423046495129 Content-Type: text/x-patch; name=0001-x2goclient-broker-noauth-patch.patch Content-Disposition: attachment; filename=0001-x2goclient-broker-noauth-patch.patch Content-Transfer-Encoding: base64 RnJvbSAyNzBlNTgzNWZlNDllMDg0NDg3NGI5Nzc2OWU4ZGUxNTMyYTJhMDM5IE1vbiBTZXAgMTcg MDA6MDA6MDAgMjAwMQpGcm9tOiBTZXJnZXlfU2F2a28gPHNhdmtvQHRvcGhvdXNlLnJ1PgpEYXRl OiBXZWQsIDQgRmViIDIwMTUgMTI6MjQ6MTggKzAzMDAKU3ViamVjdDogW1BBVENIXSB4MmdvY2xp ZW50IC0tYnJva2VyLW5vYXV0aCBwYXRjaAoKLS0tCiBvbm1haW53aW5kb3cuY3BwIHwgICAgMyAr KysKIDEgZmlsZSBjaGFuZ2VkLCAzIGluc2VydGlvbnMoKykKCmRpZmYgLS1naXQgYS9vbm1haW53 aW5kb3cuY3BwIGIvb25tYWlud2luZG93LmNwcAppbmRleCA1YzM0NmU2Li44Mjg5NzVmIDEwMDY0 NAotLS0gYS9vbm1haW53aW5kb3cuY3BwCisrKyBiL29ubWFpbndpbmRvdy5jcHAKQEAgLTMwMzEs NiArMzAzMSw5IEBAIHZvaWQgT05NYWluV2luZG93OjpzbG90U2Vzc0VudGVyKCkKIAogICAgIGlm KGJyb2tlck1vZGUpCiAgICAgeworICAgICAgICBpZiAoY29uZmlnLmJyb2tlck5vQXV0aCkgewor CSAgICBjb25maWcuYnJva2VyVXNlciA9IGxvZ2luLT50ZXh0KCk7CisgICAgICAgIH0KICAgICAg ICAgYnJva2VyLT5zZWxlY3RVc2VyU2Vzc2lvbihzZXNzaW9uRXhwbG9yZXItPmdldExhc3RTZXNz aW9uKCktPmlkKCkpOwogICAgICAgICBjb25maWcuc2Vzc2lvbj1zZXNzaW9uRXhwbG9yZXItPmdl dExhc3RTZXNzaW9uKCktPmlkKCk7CiAgICAgICAgIHNldFN0YXRTdGF0dXMgKCB0ciAoICJDb25u ZWN0aW5nIHRvIGJyb2tlciIgKSApOwotLSAKMS43LjEwLjQKCg== ------=_Part_50895_1656359125.1423046495129-- ------------=_1424347222-20582-0-- From unknown Thu Mar 28 09:16:18 2024 Received: (at fakecontrol) by fakecontrolmessage; To: internal_control@bugs.x2go.org From: Debbugs Internal Request Subject: Internal Control Message-Id: Bug archived. Date: Fr, 20 =?UTF-8?Q?M=C3=83=C2=A4r?= 2015 06:24:01 +0000 User-Agent: Fakemail v42.6.9 # A New Hope # A long time ago, in a galaxy far, far away # something happened. # # Magically this resulted in the following # action being taken, but this fake control # message doesn't tell you why it happened # # The action: # Bug archived. thanks # This fakemail brought to you by your local debbugs # administrator