0ee1abe
From 4c70ae807156099bf027b57a94b7eae0a810b947 Mon Sep 17 00:00:00 2001
0ee1abe
From: Peter Jones <pjones@redhat.com>
0ee1abe
Date: Fri, 20 Nov 2015 19:19:49 -0500
2380830
Subject: [PATCH 3/5] Don't setfacl when the socket or dir aren't there.
0ee1abe
0ee1abe
Signed-off-by: Peter Jones <pjones@redhat.com>
0ee1abe
---
0ee1abe
 src/pesign-authorize-groups | 10 ++++++----
0ee1abe
 src/pesign-authorize-users  | 10 ++++++----
0ee1abe
 2 files changed, 12 insertions(+), 8 deletions(-)
0ee1abe
0ee1abe
diff --git a/src/pesign-authorize-groups b/src/pesign-authorize-groups
0ee1abe
index 2236bea..2222809 100644
0ee1abe
--- a/src/pesign-authorize-groups
0ee1abe
+++ b/src/pesign-authorize-groups
0ee1abe
@@ -11,9 +11,11 @@
0ee1abe
 
0ee1abe
 if [[ -r /etc/pesign/groups ]]; then
0ee1abe
     for group in $(cat /etc/pesign/groups); do
0ee1abe
-        setfacl -m g:${group}:rx /var/run/pesign
0ee1abe
-        setfacl -m g:${group}:rw /var/run/pesign/socket
0ee1abe
-        setfacl -m g:${username}:rx /etc/pki/pesign
0ee1abe
-        setfacl -m g:${username}:r /etc/pki/pesign/{cert8,key3,secmod}.db
0ee1abe
+	if [ -d /var/run/pesign ]; then
0ee1abe
+	    setfacl -m g:${group}:rx /var/run/pesign
0ee1abe
+	    if [ -e /var/run/pesign/socket ]; then
0ee1abe
+		setfacl -m g:${group}:rw /var/run/pesign/socket
0ee1abe
+	    fi
0ee1abe
+	fi
0ee1abe
     done
0ee1abe
 fi
0ee1abe
diff --git a/src/pesign-authorize-users b/src/pesign-authorize-users
0ee1abe
index 9c38a25..22bddec 100644
0ee1abe
--- a/src/pesign-authorize-users
0ee1abe
+++ b/src/pesign-authorize-users
0ee1abe
@@ -11,9 +11,11 @@
0ee1abe
 
0ee1abe
 if [[ -r /etc/pesign/users ]]; then
0ee1abe
     for username in $(cat /etc/pesign/users); do
0ee1abe
-        setfacl -m u:${username}:rx /var/run/pesign
0ee1abe
-        setfacl -m u:${username}:rw /var/run/pesign/socket
0ee1abe
-        setfacl -m u:${username}:rx /etc/pki/pesign
0ee1abe
-        setfacl -m u:${username}:r /etc/pki/pesign/{cert8,key3,secmod}.db
0ee1abe
+	if [ -d /var/run/pesign ]; then
0ee1abe
+	    setfacl -m g:${username}:rx /var/run/pesign
0ee1abe
+	    if [ -e /var/run/pesign/socket ]; then
0ee1abe
+		setfacl -m g:${username}:rw /var/run/pesign/socket
0ee1abe
+	    fi
0ee1abe
+	fi
0ee1abe
     done
0ee1abe
 fi
0ee1abe
-- 
0ee1abe
2.5.0
0ee1abe