Todd C. Miller [Fri, 13 Apr 2012 18:17:26 +0000 (14:17 -0400)]
sync with translationproject.org
Todd C. Miller [Fri, 13 Apr 2012 18:15:22 +0000 (14:15 -0400)]
New Croatian and Galician translations from translationproject.org
Todd C. Miller [Fri, 13 Apr 2012 16:54:03 +0000 (12:54 -0400)]
Add depth-first traversal of /dev/ for the /proc case when not /dev/pts/N
Todd C. Miller [Fri, 13 Apr 2012 12:36:58 +0000 (08:36 -0400)]
If struct dirent has d_type, use it to avoid an extra stat().
Todd C. Miller [Fri, 13 Apr 2012 12:35:19 +0000 (08:35 -0400)]
Sort output of "sudoreplay -l"
Todd C. Miller [Thu, 12 Apr 2012 19:17:00 +0000 (15:17 -0400)]
Fix duplicate free introduced in last rev
Todd C. Miller [Wed, 11 Apr 2012 23:51:56 +0000 (19:51 -0400)]
Instead of treating ^C from tgetpass() specially, always
return AUTH_INTR if tgetpass() returned NULL.
Treat PAM_AUTHINFO_UNAVAIL like PAM_AUTH_ERR which Mac OS X
returns this when there is no tty.
Todd C. Miller [Wed, 11 Apr 2012 18:48:08 +0000 (14:48 -0400)]
Rototill code to determine the tty. For Linux, we now look up the
tty device in /proc/pid/stat instead of trying to open /proc/pid/fd/[0-2].
The sudo_ttyname_dev() function maps the given device number to a
string. On BSD, we can use devname(). On Solaris, _ttyname_dev()
does what we want.
TODO: write /dev/ traversal code for the generic sudo_ttyname_dev().
Todd C. Miller [Tue, 10 Apr 2012 20:12:08 +0000 (16:12 -0400)]
Define PRNODEV for those w/o it.
Todd C. Miller [Tue, 10 Apr 2012 19:53:41 +0000 (15:53 -0400)]
Check for SVR4-style struct psinfo.pr_ttydev and use that to determine
the tty if std{in,out,err} are not ttys.
Todd C. Miller [Tue, 10 Apr 2012 18:35:30 +0000 (14:35 -0400)]
Better support for SVR4-style /proc entries where we can't use
ttyname() on the /proc/pid/fd/[0-2] entries. We can, however,
attempt to map the device number back to the correct pseudo-tty
slave device.
Todd C. Miller [Tue, 10 Apr 2012 17:49:49 +0000 (13:49 -0400)]
When trying to determine the tty name, check parent's stderr in
addition to its stdin and stdout.
Todd C. Miller [Tue, 10 Apr 2012 14:18:59 +0000 (10:18 -0400)]
Treat a tty read failure like EOF as it usually means the pty has
gone away. Handle write() on the tty returning EIO.
Todd C. Miller [Tue, 10 Apr 2012 14:18:39 +0000 (10:18 -0400)]
Linux select() may return ENOMEM if there is a kernel resource
shortage. Older Solaris select() may return EIO instead of EBADF
when the tty goes away. If we get an unhandled select() failure,
kill the child and exit cleanly.
Todd C. Miller [Tue, 10 Apr 2012 13:26:52 +0000 (09:26 -0400)]
Open /proc/pid/fd/[0-2] in non-blocking mode just in case we might
block in open.
Todd C. Miller [Mon, 9 Apr 2012 19:39:01 +0000 (15:39 -0400)]
Fix restoration of AIX permissions.
Todd C. Miller [Mon, 9 Apr 2012 18:27:33 +0000 (14:27 -0400)]
Allow the -k flag to be used along with the -i and -s flags.
Todd C. Miller [Mon, 9 Apr 2012 13:14:53 +0000 (09:14 -0400)]
Plug memory leak in parse_logfile() in the error path.
Todd C. Miller [Mon, 9 Apr 2012 13:09:13 +0000 (09:09 -0400)]
sync with translationproject.org
Todd C. Miller [Sun, 8 Apr 2012 22:00:31 +0000 (18:00 -0400)]
Do not use GLOB_BRACE or GLOB_TILDE flags to glob()--we want the
glob() and fnmatch() results to be consistent.
Todd C. Miller [Fri, 6 Apr 2012 20:41:08 +0000 (16:41 -0400)]
Move ttysize.c to common so sudoreplay can use it.
Todd C. Miller [Fri, 6 Apr 2012 20:37:40 +0000 (16:37 -0400)]
If I/O log file includes rows + cols, warn if the user's tty is
not big enough.
Todd C. Miller [Fri, 6 Apr 2012 20:34:43 +0000 (16:34 -0400)]
Fix printing of TSID in "sudoreplay -l"
Todd C. Miller [Fri, 6 Apr 2012 19:20:16 +0000 (15:20 -0400)]
Log the process id in the debug file output. Since we don't want
to keep calling getpid(), stash the value at init time and when we
fork().
Todd C. Miller [Fri, 6 Apr 2012 16:45:30 +0000 (12:45 -0400)]
Ignore SIGTTIN and SIGTTOU in main sudo process when I/O logging.
It is better to receive EIO from read()/write() than to be suspended
when we don't expect it. Fixes a problem when our terminal is
revoked which can happen when, e.g. our sshd is killed unceremoniously.
Also, only change the value of "alive" from true to false, never
from false to true. It is possible for us to receive notification
of the child having stopped after it is already dead. This does
not mean it has risen from the grave.
Todd C. Miller [Fri, 6 Apr 2012 16:40:13 +0000 (12:40 -0400)]
Distinguish between signals we received from the parent vs. those
delivered explicitly to the monitor process in debugging info.
Todd C. Miller [Thu, 5 Apr 2012 17:21:22 +0000 (13:21 -0400)]
In Solaris 11, /dev/pts under the "dev" filesystem, not "devices".
Update tty_is_devpts() to match so we can determine when the tty
has been reused.
Todd C. Miller [Thu, 5 Apr 2012 17:04:00 +0000 (13:04 -0400)]
Always pass __func__, __FILE__ and __LINE__ in sudo_debug_printf()
and use a new flag, SUDO_DEBUG_FILENO to specify when to use it.
This allows consumers of sudo_debug_printf() to log that data without
having to specify it manually.
Todd C. Miller [Thu, 5 Apr 2012 16:59:26 +0000 (12:59 -0400)]
Make this compile after last change.
Todd C. Miller [Thu, 5 Apr 2012 16:40:51 +0000 (12:40 -0400)]
Don't try to restore the terminal if we are not the foreground
process. Otherwise, we may be stopped by SIGTTOU when we try to
update the terminal settings when cleaning up.
Todd C. Miller [Thu, 5 Apr 2012 16:39:46 +0000 (12:39 -0400)]
If select() return EBADF in the main event loop, one of the ttys
must have gone away so perform any I/O we can and close the bad
fds.
Todd C. Miller [Thu, 5 Apr 2012 16:37:15 +0000 (12:37 -0400)]
Log warning() at SUDO_DEBUG_WARN not SUDO_DEBUG_ERROR.
Log the function, file and line number in the debug log for warning()
and error().
Todd C. Miller [Wed, 4 Apr 2012 20:59:31 +0000 (16:59 -0400)]
Add SUDO_DEBUG_ERRNO flag to debug functions so we can log errno.
Use this flag when wrapping error() and warning() so the debug
output includes the error string.
Todd C. Miller [Fri, 30 Mar 2012 19:55:24 +0000 (15:55 -0400)]
Update for sudo 1.8.5
Todd C. Miller [Fri, 30 Mar 2012 19:45:11 +0000 (15:45 -0400)]
regen
Todd C. Miller [Fri, 30 Mar 2012 19:44:23 +0000 (15:44 -0400)]
sync
Todd C. Miller [Fri, 30 Mar 2012 19:25:15 +0000 (15:25 -0400)]
Use ecalloc()
Todd C. Miller [Fri, 30 Mar 2012 18:59:27 +0000 (14:59 -0400)]
Don't need zero_bytes() after ecalloc()
Todd C. Miller [Fri, 30 Mar 2012 13:36:30 +0000 (09:36 -0400)]
Add execvpe(), exect(), posix_spawn() and posix_spawnp() wrappers
to sudo_noexec.c.
Todd C. Miller [Fri, 30 Mar 2012 11:55:49 +0000 (07:55 -0400)]
Fix compat setutxent and endutxent macros for systems with
setutent() but not setutxent(). From Gustavo Zacarias
Todd C. Miller [Thu, 29 Mar 2012 17:13:38 +0000 (13:13 -0400)]
Add ignore_result definition to AH_BOTTOM
Todd C. Miller [Thu, 29 Mar 2012 14:33:40 +0000 (10:33 -0400)]
Fix compiler warnings on some platforms and provide a better method
of defeating gcc's warn_unused_result attribute.
Todd C. Miller [Thu, 29 Mar 2012 14:32:29 +0000 (10:32 -0400)]
Fix building the builtin zlib from a build dir.
When a zlib dir was specified, prepend its include path instead of
appending so we get the right zlib headers.
Todd C. Miller [Thu, 29 Mar 2012 14:28:17 +0000 (10:28 -0400)]
Update zlib to version 1.2.6
Todd C. Miller [Wed, 28 Mar 2012 21:07:29 +0000 (17:07 -0400)]
g/c __unused which is no longer used
Todd C. Miller [Wed, 28 Mar 2012 19:27:27 +0000 (15:27 -0400)]
Fix compilation if RTLD_NEXT is not defined.
Todd C. Miller [Wed, 28 Mar 2012 18:22:09 +0000 (14:22 -0400)]
sync with translationproject.org
Todd C. Miller [Wed, 28 Mar 2012 18:10:18 +0000 (14:10 -0400)]
regen
Todd C. Miller [Wed, 28 Mar 2012 18:08:28 +0000 (14:08 -0400)]
regen
Todd C. Miller [Wed, 28 Mar 2012 18:05:49 +0000 (14:05 -0400)]
Ignore Project-Id-Version when comparing pot files.
Todd C. Miller [Wed, 28 Mar 2012 17:47:49 +0000 (13:47 -0400)]
Use error() instead of log_fatal()
Todd C. Miller [Wed, 28 Mar 2012 17:39:37 +0000 (13:39 -0400)]
Fix signedness of didvar in env_update_didvar()
Todd C. Miller [Wed, 28 Mar 2012 17:17:11 +0000 (13:17 -0400)]
Quiet a compiler warning on some platforms.
Todd C. Miller [Wed, 28 Mar 2012 17:07:54 +0000 (13:07 -0400)]
cast ctype(3) function/macro arguments from char to unsigned char
to avoid potential negative subscripting.
Todd C. Miller [Wed, 28 Mar 2012 15:14:22 +0000 (11:14 -0400)]
Quiet a warning on systems where the gids array in setgroups() is
not prototyped as being const, even though it really is.
Todd C. Miller [Wed, 28 Mar 2012 14:58:02 +0000 (10:58 -0400)]
Quiet a compiler warning on systems where the argument to putenv(3)
is const.
Todd C. Miller [Wed, 28 Mar 2012 14:51:22 +0000 (10:51 -0400)]
Undo an incorrect int -> bool conversion.
Todd C. Miller [Wed, 28 Mar 2012 13:56:26 +0000 (09:56 -0400)]
Add Swedish sudo and sudoers translations from translationproject.org
Todd C. Miller [Wed, 28 Mar 2012 12:18:26 +0000 (08:18 -0400)]
No need to preserve ODMDIR on AIX now that we always read
/etc/environment.
Todd C. Miller [Tue, 27 Mar 2012 22:57:11 +0000 (18:57 -0400)]
When initializing the environment for env_reset, start out with
the contents of /etc/environment on AIX and login.conf on BSD.
Todd C. Miller [Tue, 27 Mar 2012 17:57:03 +0000 (13:57 -0400)]
If we are not running with an effective uid of 0, try to give the
user enough information to debug the problem.
Todd C. Miller [Tue, 27 Mar 2012 17:01:45 +0000 (13:01 -0400)]
Quiet a clang-analyzer false positive.
Todd C. Miller [Tue, 27 Mar 2012 16:41:28 +0000 (12:41 -0400)]
If there is nothing to read from the askpass program, set errno to
EINTR. This makes the cancel button behave like the user entered
^C at the password prompt when PAM is used.
Todd C. Miller [Tue, 27 Mar 2012 16:25:04 +0000 (12:25 -0400)]
Fetch the value of "askpass" from the sudo conf struct.
Todd C. Miller [Tue, 27 Mar 2012 16:24:39 +0000 (12:24 -0400)]
Fix matching of "Path askpass" and "Path noexec"
Todd C. Miller [Mon, 26 Mar 2012 15:03:23 +0000 (11:03 -0400)]
Quiet a clang-analyzer dead store warning.
Todd C. Miller [Mon, 26 Mar 2012 15:02:06 +0000 (11:02 -0400)]
If the "timestampowner" user cannot be resolved, use ROOT_UID instead
of exiting with a fatal error.
Todd C. Miller [Mon, 26 Mar 2012 14:59:14 +0000 (10:59 -0400)]
Remove the NO_EXIT flag to log_error() and add a log_fatal() function
that exits and is marked no_return. Fixes false positives from
static analyzers and is easier for humans to read too.
Todd C. Miller [Sat, 24 Mar 2012 17:38:38 +0000 (13:38 -0400)]
sync with translationproject.org
Todd C. Miller [Tue, 20 Mar 2012 18:38:30 +0000 (14:38 -0400)]
sync with translationproject.org
Todd C. Miller [Tue, 20 Mar 2012 18:08:58 +0000 (14:08 -0400)]
sync with translationproject.org
Todd C. Miller [Mon, 19 Mar 2012 15:25:07 +0000 (11:25 -0400)]
sync with translationproject.org
Todd C. Miller [Mon, 19 Mar 2012 15:24:24 +0000 (11:24 -0400)]
Use ecalloc() when allocating structs.
Todd C. Miller [Mon, 19 Mar 2012 15:23:25 +0000 (11:23 -0400)]
Add ecalloc() and commented out recalloc().
Use inline strnlen() instead of strlen() in estrndup().
Todd C. Miller [Sun, 18 Mar 2012 16:47:27 +0000 (12:47 -0400)]
sync with translationproject.org
Todd C. Miller [Sat, 17 Mar 2012 00:13:43 +0000 (20:13 -0400)]
Remove unused label
Todd C. Miller [Fri, 16 Mar 2012 18:39:12 +0000 (14:39 -0400)]
Document what changed in each plugin API revision
Todd C. Miller [Fri, 16 Mar 2012 16:00:32 +0000 (12:00 -0400)]
Remove bogus optimization that could lead to a double free of the
group list.
Todd C. Miller [Thu, 15 Mar 2012 19:25:13 +0000 (15:25 -0400)]
Expand AIX /etc/security/privcmds entry.
Todd C. Miller [Thu, 15 Mar 2012 16:32:56 +0000 (12:32 -0400)]
Update for sudo 1.8.5
Todd C. Miller [Thu, 15 Mar 2012 16:32:31 +0000 (12:32 -0400)]
Rename plugin "args" to "options"
Todd C. Miller [Thu, 15 Mar 2012 16:21:36 +0000 (12:21 -0400)]
Add Lithuanian and Vietnamese translators
Todd C. Miller [Thu, 15 Mar 2012 15:44:35 +0000 (11:44 -0400)]
Ignore comments when comparing new and old pot files.
Todd C. Miller [Thu, 15 Mar 2012 13:19:28 +0000 (09:19 -0400)]
regen
Todd C. Miller [Thu, 15 Mar 2012 13:18:50 +0000 (09:18 -0400)]
regen
Todd C. Miller [Thu, 15 Mar 2012 13:18:36 +0000 (09:18 -0400)]
Pass a pointer to user_env in to the init_session policy plugin
function so session setup can modify the user environment as needed.
For PAM authentication, merge the PAM environment with the user
environment at init_session time. We no longer need to swap in the
user_env for environ during session init, nor do we need to disable
the env hooks at init_session time.
Todd C. Miller [Thu, 15 Mar 2012 13:02:19 +0000 (09:02 -0400)]
Add explicit NULL entries for init_session, register_hooks and
deregister_hooks with appropriate comments.
Todd C. Miller [Thu, 15 Mar 2012 12:56:12 +0000 (08:56 -0400)]
Quiet a gcc "used uninitialized in this function" false positive.
Todd C. Miller [Thu, 15 Mar 2012 12:47:23 +0000 (08:47 -0400)]
We should always call warning() with a format string or a string literal.
In this case, the argument (path) is not user-controlled.
Todd C. Miller [Thu, 15 Mar 2012 01:52:31 +0000 (21:52 -0400)]
Include sudo_exec.h for the sudo_execve() prototype.
Todd C. Miller [Thu, 15 Mar 2012 00:55:11 +0000 (20:55 -0400)]
Add check for pam_getenvlist()
Todd C. Miller [Wed, 14 Mar 2012 19:07:50 +0000 (15:07 -0400)]
Set args to NULL in default plugin info struct when there is no
Plugin line in sudo.conf.
Todd C. Miller [Wed, 14 Mar 2012 18:20:55 +0000 (14:20 -0400)]
regen
Todd C. Miller [Wed, 14 Mar 2012 18:20:16 +0000 (14:20 -0400)]
regen
Todd C. Miller [Wed, 14 Mar 2012 18:17:44 +0000 (14:17 -0400)]
Bump version to 1.8.5
Todd C. Miller [Wed, 14 Mar 2012 18:11:18 +0000 (14:11 -0400)]
Document hooks API
Todd C. Miller [Tue, 13 Mar 2012 21:38:03 +0000 (17:38 -0400)]
Make sudoersdir relative to PKG_INSTALL_ROOT for Solaris.
Todd C. Miller [Tue, 13 Mar 2012 21:32:50 +0000 (17:32 -0400)]
Use sudo_hook_fn_t in struct sudo_hook.
Todd C. Miller [Tue, 13 Mar 2012 15:01:23 +0000 (11:01 -0400)]
If cross compiling, --host must include the OS in the tuple.
E.g. --host powerpc-unknown-linux
Todd C. Miller [Mon, 12 Mar 2012 23:34:19 +0000 (19:34 -0400)]
Fix bogus int -> bool conversion; tags can have a value of -1.