]> granicus.if.org Git - sudo/log
sudo
11 years agoFix pasto; sudo_sss_extract_digest() not sudo_ldap_extract_digest().
Todd C. Miller [Tue, 9 Jul 2013 16:35:26 +0000 (10:35 -0600)]
Fix pasto; sudo_sss_extract_digest() not sudo_ldap_extract_digest().
From Dan Harnett.

11 years agoFix formatting typo; from Eric S. Raymond
Todd C. Miller [Tue, 18 Jun 2013 10:39:02 +0000 (06:39 -0400)]
Fix formatting typo; from Eric S. Raymond

11 years agoUse -gxcoff on aix so dbx can be used to debug sudo.
Todd C. Miller [Mon, 17 Jun 2013 20:48:32 +0000 (16:48 -0400)]
Use -gxcoff on aix so dbx can be used to debug sudo.

11 years agoFix typo; bug 605
Todd C. Miller [Wed, 12 Jun 2013 13:15:11 +0000 (09:15 -0400)]
Fix typo; bug 605

11 years agoRegen .mo files that were out of date.
Todd C. Miller [Tue, 4 Jun 2013 09:47:19 +0000 (05:47 -0400)]
Regen .mo files that were out of date.

11 years agoOn Solaris 11 and higher, tag binaries for ASLR if supported by the
Todd C. Miller [Thu, 30 May 2013 13:29:36 +0000 (09:29 -0400)]
On Solaris 11 and higher, tag binaries for ASLR if supported by the
linker.

11 years agoNo longer need to disable PIE on Solaris.
Todd C. Miller [Thu, 30 May 2013 13:11:30 +0000 (09:11 -0400)]
No longer need to disable PIE on Solaris.

11 years agoRestrict default creation of PIE binaries (-fPIE and -pie) to Linux.
Todd C. Miller [Tue, 28 May 2013 18:40:45 +0000 (14:40 -0400)]
Restrict default creation of PIE binaries (-fPIE and -pie) to Linux.
OpenBSD also supports PIE but enables it by default so we don't
need to do anything.  This fixes problems on systems with a version
of GNU ld that accepts -pie but where the run-time linker doesn't
actually support PIE.  Also verify that a trivial PIE binary works
unless PIE is explicitly enabled.

11 years agoAttempt to detect PIE failure on Solaris 10 with GNU as and GNU ld
Todd C. Miller [Fri, 24 May 2013 20:47:16 +0000 (16:47 -0400)]
Attempt to detect PIE failure on Solaris 10 with GNU as and GNU ld
where we can end up crashing due to malloc() failures.  Sems OK
when Using Sun as and ld.

11 years agoUpdate with final changes.
Todd C. Miller [Fri, 24 May 2013 15:26:41 +0000 (11:26 -0400)]
Update with final changes.

11 years agoAdd -fPIE to PIE_LDFLAGS as per gcc manual.
Todd C. Miller [Fri, 24 May 2013 02:47:28 +0000 (22:47 -0400)]
Add -fPIE to PIE_LDFLAGS as per gcc manual.

11 years agoAdd missing $(PIE_LDFLAGS) $(SSP_LDFLAGS) for test programs
Todd C. Miller [Wed, 22 May 2013 21:04:25 +0000 (17:04 -0400)]
Add missing $(PIE_LDFLAGS) $(SSP_LDFLAGS) for test programs

11 years agoReplace sequence number-based cycle detection in visudo with a
Todd C. Miller [Wed, 22 May 2013 15:32:08 +0000 (11:32 -0400)]
Replace sequence number-based cycle detection in visudo with a
"used" flag in struct alias.  The caller is required to call
alias_put() when it is done with the alias.  Inspired by a patch
from Daniel Kopecek.

11 years agoEliminate a few relocations related to sudoers_io.
Todd C. Miller [Mon, 20 May 2013 15:06:13 +0000 (11:06 -0400)]
Eliminate a few relocations related to sudoers_io.

11 years agoSync with translationproject.org
Todd C. Miller [Mon, 20 May 2013 14:20:04 +0000 (10:20 -0400)]
Sync with translationproject.org

11 years agoClarify a comment.
Todd C. Miller [Sat, 18 May 2013 08:38:26 +0000 (04:38 -0400)]
Clarify a comment.

11 years agoHandle d_type == DT_UNKNOWN when resolving the device to a name and
Todd C. Miller [Thu, 16 May 2013 14:18:13 +0000 (10:18 -0400)]
Handle d_type == DT_UNKNOWN when resolving the device to a name and
sprinkle some more debugging.

11 years agoAdd message about disabling PIE if sudo gets SIGSEGV.
Todd C. Miller [Fri, 3 May 2013 20:24:22 +0000 (16:24 -0400)]
Add message about disabling PIE if sudo gets SIGSEGV.

11 years agoNo longer store the ctime of a devpts tty. The handling of ctime
Todd C. Miller [Fri, 3 May 2013 20:14:12 +0000 (16:14 -0400)]
No longer store the ctime of a devpts tty.  The handling of ctime
on devpts in Linux has been changed to conform to POSIX.  As a
result we can no longer assume that the ctime will stay unchanged
throughout the life of the session.  We store the session ID in the
time stamp file so there is a much smaller chance of the time stamp
file being reused by a new login.  While here, store the uid/gid
in the timestamp file too for good measure.

11 years agoPIE is broken on FreeBSD/arm
Todd C. Miller [Fri, 3 May 2013 18:33:26 +0000 (14:33 -0400)]
PIE is broken on FreeBSD/arm

11 years agoAdd explicit sendmail path for Linux since we may not have sendmail
Todd C. Miller [Fri, 3 May 2013 14:51:04 +0000 (10:51 -0400)]
Add explicit sendmail path for Linux since we may not have sendmail
installed in the build chroot.

11 years agoQuiet a few -Wunused-result compiler warnings.
Todd C. Miller [Wed, 1 May 2013 15:02:09 +0000 (11:02 -0400)]
Quiet a few -Wunused-result compiler warnings.

11 years agoMention what SHA-2 formats are supported.
Todd C. Miller [Tue, 30 Apr 2013 15:44:01 +0000 (11:44 -0400)]
Mention what SHA-2 formats are supported.

11 years agoList code and translations separately.
Todd C. Miller [Tue, 30 Apr 2013 15:07:06 +0000 (11:07 -0400)]
List code and translations separately.

11 years agoSync with translationproject.org
Todd C. Miller [Mon, 29 Apr 2013 18:04:51 +0000 (14:04 -0400)]
Sync with translationproject.org

11 years agoregen
Todd C. Miller [Mon, 29 Apr 2013 18:02:23 +0000 (14:02 -0400)]
regen

11 years agoFix c-format for fatal/fatalx
Todd C. Miller [Mon, 29 Apr 2013 18:00:50 +0000 (14:00 -0400)]
Fix c-format for fatal/fatalx

11 years agoChange some error/errorx -> fatal/fatalx in comments and xgettext
Todd C. Miller [Fri, 26 Apr 2013 20:06:05 +0000 (16:06 -0400)]
Change some error/errorx -> fatal/fatalx in comments and xgettext
flags.

11 years agoThere is now a Turkish translation of sudoers.
Todd C. Miller [Fri, 26 Apr 2013 13:16:43 +0000 (09:16 -0400)]
There is now a Turkish translation of sudoers.

11 years agoUpdated translations from translationproject.org including new
Todd C. Miller [Fri, 26 Apr 2013 13:16:22 +0000 (09:16 -0400)]
Updated translations from translationproject.org including new
Turkish translation.

11 years agoDocument that sudoers will re-use existing I/O log paths unless
Todd C. Miller [Thu, 25 Apr 2013 19:11:06 +0000 (15:11 -0400)]
Document that sudoers will re-use existing I/O log paths unless
they are mktemp-style with trailing X's.

11 years agoAllow ldap_conf and ldap_secret to be specified as plugin arguments
Todd C. Miller [Thu, 25 Apr 2013 18:49:02 +0000 (14:49 -0400)]
Allow ldap_conf and ldap_secret to be specified as plugin arguments
in sudo.conf

11 years agosudoers_debug is now deprecated in favor of the sudo debugging
Todd C. Miller [Thu, 25 Apr 2013 14:22:11 +0000 (10:22 -0400)]
sudoers_debug is now deprecated in favor of the sudo debugging
framework.

11 years agoReplace DPRINTF with DPRINTF1 and DPRINTF2 macros that use
Todd C. Miller [Thu, 25 Apr 2013 14:12:42 +0000 (10:12 -0400)]
Replace DPRINTF with DPRINTF1 and DPRINTF2 macros that use
SUDO_DEBUG_DIAG and SUDO_DEBUG_INFO respectively for logging to the
debug file with the ldap subsystem.
The sudoers_debug setting in ldap.conf is still honored for now but
will be removed in a future release.

11 years agoAdd support for converting sudoers files with SHA-2 command digests.
Todd C. Miller [Wed, 24 Apr 2013 20:02:20 +0000 (16:02 -0400)]
Add support for converting sudoers files with SHA-2 command digests.

11 years agoAdd copyright notice to scripts
Todd C. Miller [Wed, 24 Apr 2013 19:47:39 +0000 (15:47 -0400)]
Add copyright notice to scripts

11 years agoAdd regress for SHA-2 digests.
Todd C. Miller [Wed, 24 Apr 2013 19:38:03 +0000 (15:38 -0400)]
Add regress for SHA-2 digests.

11 years agoSolaris maps negative gids to GID_NOBODY.
Todd C. Miller [Wed, 24 Apr 2013 19:24:24 +0000 (15:24 -0400)]
Solaris maps negative gids to GID_NOBODY.

11 years agoClear up an llvm checker warning which appears to be a false positive
Todd C. Miller [Wed, 24 Apr 2013 15:55:21 +0000 (11:55 -0400)]
Clear up an llvm checker warning which appears to be a false positive
and fix an old XXX while I'm at it.

11 years agoCorrect last change date
Todd C. Miller [Wed, 24 Apr 2013 15:14:06 +0000 (11:14 -0400)]
Correct last change date

11 years agoNo need to translate this error message.
Todd C. Miller [Wed, 24 Apr 2013 15:11:21 +0000 (11:11 -0400)]
No need to translate this error message.

11 years agoMention .sl vs. .so extension handling on HP-UX
Todd C. Miller [Wed, 24 Apr 2013 15:08:38 +0000 (11:08 -0400)]
Mention .sl vs. .so extension handling on HP-UX
Mention group membership changes
Fix typos

11 years agoUpdate copyright years.
Todd C. Miller [Wed, 24 Apr 2013 13:35:02 +0000 (09:35 -0400)]
Update copyright years.

11 years agoSystrace support was removed long ago.
Todd C. Miller [Wed, 24 Apr 2013 13:17:11 +0000 (09:17 -0400)]
Systrace support was removed long ago.

11 years agoRemove some files that were mistakenly added.
Todd C. Miller [Tue, 23 Apr 2013 20:37:52 +0000 (16:37 -0400)]
Remove some files that were mistakenly added.

11 years agoUse time(&now) instead of now = time(NULL) when storing the current
Todd C. Miller [Tue, 23 Apr 2013 17:15:22 +0000 (13:15 -0400)]
Use time(&now) instead of now = time(NULL) when storing the current
time in a time_t (better compiler error checking).
Better parsing and printing of 64-bit time_t on 32-bit platforms.

11 years agoDon't check the tty of the parent process. Now that we get the
Todd C. Miller [Sun, 21 Apr 2013 14:35:52 +0000 (10:35 -0400)]
Don't check the tty of the parent process.  Now that we get the
controlling tty device number from the kernel there is no need.  If
the process has really disassociated from the tty then reporting
"unknown" is appropriate.

11 years agoUse EXIT_FAILURE instead of 1 as the fatal() exit value.
Todd C. Miller [Sat, 20 Apr 2013 19:10:24 +0000 (15:10 -0400)]
Use EXIT_FAILURE instead of 1 as the fatal() exit value.

11 years agoChange remaining errorx -> fatalx
Todd C. Miller [Sat, 20 Apr 2013 19:09:47 +0000 (15:09 -0400)]
Change remaining errorx -> fatalx

11 years agoReplace sudo_fakepwnamid() with sudo_mkpwent() and don't return an
Todd C. Miller [Fri, 19 Apr 2013 18:48:23 +0000 (14:48 -0400)]
Replace sudo_fakepwnamid() with sudo_mkpwent() and don't return an
error if the entry already exists in the cache.

11 years agoChange "foo: failed" to just "foo" since we print the string form
Todd C. Miller [Fri, 19 Apr 2013 13:55:48 +0000 (09:55 -0400)]
Change "foo: failed" to just "foo" since we print the string form
of errno.  Gets rids of some useless translations.

11 years agoFix pasto in debug_decl
Todd C. Miller [Thu, 18 Apr 2013 19:05:23 +0000 (15:05 -0400)]
Fix pasto in debug_decl

11 years agoregen
Todd C. Miller [Thu, 18 Apr 2013 18:14:28 +0000 (14:14 -0400)]
regen

11 years agoRename log_error() -> log_warning() for consistency with warning()/fatal()
Todd C. Miller [Thu, 18 Apr 2013 18:14:03 +0000 (14:14 -0400)]
Rename log_error() -> log_warning() for consistency with warning()/fatal()

11 years agoThe NO_EXIT flag was removed a while ago.
Todd C. Miller [Thu, 18 Apr 2013 18:13:05 +0000 (14:13 -0400)]
The NO_EXIT flag was removed a while ago.

11 years agoRename error/errorx -> fatal/fatalx and remove the exit value as
Todd C. Miller [Thu, 18 Apr 2013 18:07:59 +0000 (14:07 -0400)]
Rename error/errorx -> fatal/fatalx and remove the exit value as
it was always 1.

11 years agodigests are supported in sudoers ldap too
Todd C. Miller [Thu, 18 Apr 2013 15:41:38 +0000 (11:41 -0400)]
digests are supported in sudoers ldap too

11 years agoPrint test failures to stdout like the final count so the outputis
Todd C. Miller [Thu, 18 Apr 2013 14:44:06 +0000 (10:44 -0400)]
Print test failures to stdout like the final count so the outputis
not displayed out of order.

11 years agoSync with translationproject.org
Todd C. Miller [Thu, 18 Apr 2013 13:41:11 +0000 (09:41 -0400)]
Sync with translationproject.org

11 years agoCheck for any uncommitted changes in dist target and add force-dist
Todd C. Miller [Thu, 18 Apr 2013 13:40:38 +0000 (09:40 -0400)]
Check for any uncommitted changes in dist target and add force-dist
target that omit check-dist.

11 years agoFix logic bug when checking tty via ttyname().
Todd C. Miller [Thu, 18 Apr 2013 01:16:30 +0000 (21:16 -0400)]
Fix logic bug when checking tty via ttyname().

11 years agoFix check for _BIG_ENDIAN and _LITTLE_ENDIAN (Solaris) and
Todd C. Miller [Wed, 17 Apr 2013 20:23:49 +0000 (16:23 -0400)]
Fix check for _BIG_ENDIAN and _LITTLE_ENDIAN (Solaris) and
__BIG_ENDIAN__ and __LITTLE_ENDIAN__ (HP-UX)

11 years agoregen
Todd C. Miller [Wed, 17 Apr 2013 19:55:17 +0000 (15:55 -0400)]
regen

11 years agoDocument digest support.
Todd C. Miller [Wed, 17 Apr 2013 19:42:28 +0000 (15:42 -0400)]
Document digest support.

11 years agoSimple bas64 decode unit test.
Todd C. Miller [Wed, 17 Apr 2013 16:54:33 +0000 (12:54 -0400)]
Simple bas64 decode unit test.

11 years agoMove base64_decode into its own source file.
Todd C. Miller [Wed, 17 Apr 2013 13:32:27 +0000 (09:32 -0400)]
Move base64_decode into its own source file.

11 years agoOnly check year against 2038 if time_t is 32-bit.
Todd C. Miller [Wed, 17 Apr 2013 13:31:26 +0000 (09:31 -0400)]
Only check year against 2038 if time_t is 32-bit.

11 years agoAdd digest support for sudoers in ldap and sss.
Todd C. Miller [Tue, 16 Apr 2013 20:03:37 +0000 (16:03 -0400)]
Add digest support for sudoers in ldap and sss.

11 years agoError out in configure if the compiler doesn't support "long long".
Todd C. Miller [Tue, 16 Apr 2013 18:36:42 +0000 (14:36 -0400)]
Error out in configure if the compiler doesn't support "long long".

11 years agoInclude stdint.h or inttypes.h before sha2.h
Todd C. Miller [Tue, 16 Apr 2013 16:16:41 +0000 (12:16 -0400)]
Include stdint.h or inttypes.h before sha2.h

11 years agoSimplify lbuf append functions by moving the realloc code into
Todd C. Miller [Tue, 16 Apr 2013 15:52:24 +0000 (11:52 -0400)]
Simplify lbuf append functions by moving the realloc code into
lbuf_expand().  We now expand as needed each time bytes need to be
written to the lbuf.  Also handle a NULL pointer being passed in
for paranoia's sake.

11 years agoZero out struct iolog_details early to avoid a potential (though
Todd C. Miller [Tue, 16 Apr 2013 15:06:55 +0000 (11:06 -0400)]
Zero out struct iolog_details early to avoid a potential (though
unlikely) dereference of stack garbage if we hit a fatal error
before iolog_deserialize_info() is called.

11 years agoUpdate copyright year.
Todd C. Miller [Mon, 15 Apr 2013 20:29:36 +0000 (16:29 -0400)]
Update copyright year.

11 years agoBump SUDOERS_GRAMMAR_VERSION for new digest support.
Todd C. Miller [Mon, 15 Apr 2013 19:14:07 +0000 (15:14 -0400)]
Bump SUDOERS_GRAMMAR_VERSION for new digest support.

11 years agoSanity check digest in parser so visudo can catch errors.
Todd C. Miller [Mon, 15 Apr 2013 19:12:00 +0000 (15:12 -0400)]
Sanity check digest in parser so visudo can catch errors.
Add base64 support

11 years agoFor big endian architectures just use memcpy() instead of BE macros
Todd C. Miller [Mon, 15 Apr 2013 15:05:52 +0000 (11:05 -0400)]
For big endian architectures just use memcpy() instead of BE macros
in a loop.

11 years agoInitial implementation of checksum support in sudoers.
Todd C. Miller [Sun, 14 Apr 2013 11:00:21 +0000 (07:00 -0400)]
Initial implementation of checksum support in sudoers.
Currently supports SHA-224, SHA-256, SHA-384, SHA-512.
TODO: checksum format validation in parser and base64 support.
      checksum support for ldap sudoers

11 years agoSHA-224, SHA-256, SHA-384 and SHA-512. Derived from the public
Todd C. Miller [Sat, 13 Apr 2013 11:05:06 +0000 (07:05 -0400)]
SHA-224, SHA-256, SHA-384 and SHA-512.  Derived from the public
domain SHA-1 and SHA-2 implementations by Steve Reid and Wei Dai
respectively.

11 years agoAdd sudo 1.8.6p8
Todd C. Miller [Thu, 11 Apr 2013 19:56:10 +0000 (15:56 -0400)]
Add sudo 1.8.6p8

11 years agoAdd missing "not" in error message when mixing standalone and
Todd C. Miller [Thu, 11 Apr 2013 19:55:32 +0000 (15:55 -0400)]
Add missing "not" in error message when mixing standalone and
non-standalone authentication methods.

11 years agoCheck for crypt() returning NULL. Traditionally, crypt() never returned
Todd C. Miller [Thu, 11 Apr 2013 17:10:40 +0000 (13:10 -0400)]
Check for crypt() returning NULL.  Traditionally, crypt() never returned
NULL but newer versions of eglibc have a crypt() that does.  Bug #598

11 years agoBetter PAM error messages
Todd C. Miller [Thu, 11 Apr 2013 13:09:53 +0000 (09:09 -0400)]
Better PAM error messages

11 years agoBetter error messages
Todd C. Miller [Thu, 11 Apr 2013 13:03:37 +0000 (09:03 -0400)]
Better error messages

11 years agoUse same error message for getauid() failure.
Todd C. Miller [Thu, 11 Apr 2013 12:54:39 +0000 (08:54 -0400)]
Use same error message for getauid() failure.

11 years agoStart warning with a lower case letter for consistency and to match
Todd C. Miller [Thu, 11 Apr 2013 10:38:12 +0000 (06:38 -0400)]
Start warning with a lower case letter for consistency and to match
existing translated strings.

11 years agoDisable PIE on Solaris where it is not really supported.
Todd C. Miller [Wed, 10 Apr 2013 20:26:41 +0000 (16:26 -0400)]
Disable PIE on Solaris where it is not really supported.

11 years agoAIX may have a 64-bit pr_ttydev that we need to convert to 32-bit
Todd C. Miller [Wed, 10 Apr 2013 16:30:16 +0000 (12:30 -0400)]
AIX may have a 64-bit pr_ttydev that we need to convert to 32-bit
before we try to match it against st_rdev.

11 years agoBreak out of the loop if sudo_ttyname_scan() returns non-NULL.
Todd C. Miller [Wed, 10 Apr 2013 16:11:12 +0000 (12:11 -0400)]
Break out of the loop if sudo_ttyname_scan() returns non-NULL.
Fixes a problem finding the tty name when it is not in /dev/pts.

11 years agoSupport %lld and %llu
Todd C. Miller [Wed, 10 Apr 2013 15:17:41 +0000 (11:17 -0400)]
Support %lld and %llu

11 years agoAdd ttyname test.
Todd C. Miller [Wed, 10 Apr 2013 13:39:49 +0000 (09:39 -0400)]
Add ttyname test.

11 years agoSync with translationproject.org
Todd C. Miller [Tue, 9 Apr 2013 18:39:44 +0000 (14:39 -0400)]
Sync with translationproject.org

11 years agoLog timestampfile to debug file.
Todd C. Miller [Tue, 9 Apr 2013 18:17:59 +0000 (14:17 -0400)]
Log timestampfile to debug file.

11 years agoDon't add the "Password: " string we look up in the PAM text domain
Todd C. Miller [Tue, 9 Apr 2013 13:40:36 +0000 (09:40 -0400)]
Don't add the "Password: " string we look up in the PAM text domain
to the sudoers.pot file.

11 years agoSynce with regcomp() error message change.
Todd C. Miller [Mon, 8 Apr 2013 19:41:55 +0000 (15:41 -0400)]
Synce with regcomp() error message change.

11 years agoBe consistent with error message when regcomp() fails.
Todd C. Miller [Mon, 8 Apr 2013 19:41:09 +0000 (15:41 -0400)]
Be consistent with error message when regcomp() fails.

11 years agoUse group -1 instead of 1 as the invalid group since the running
Todd C. Miller [Fri, 5 Apr 2013 12:17:19 +0000 (08:17 -0400)]
Use group -1 instead of 1 as the invalid group since the running
user might have group 1 as their default group.

11 years agoPWD may be a shell builtin, use CWD instead.
Todd C. Miller [Fri, 5 Apr 2013 12:05:35 +0000 (08:05 -0400)]
PWD may be a shell builtin, use CWD instead.

11 years agoSplit up check_user().
Todd C. Miller [Thu, 4 Apr 2013 14:04:22 +0000 (10:04 -0400)]
Split up check_user().

11 years agoCosmetic fixes in the comments.
Todd C. Miller [Wed, 3 Apr 2013 13:54:11 +0000 (09:54 -0400)]
Cosmetic fixes in the comments.

11 years agoUse AC_LINK_IFELSE instead of AC_TRY_LINK
Todd C. Miller [Tue, 2 Apr 2013 20:56:59 +0000 (16:56 -0400)]
Use AC_LINK_IFELSE instead of AC_TRY_LINK
Fix printing of status message for visibility checks when the test fails.