sudo 1.9.4b2 released

"Todd C. Miller" <[email protected]> Tue, 17 Nov 2020 16:33:54 -0700
Newsgroups gmane.comp.tools.sudo.devel
Message-ID <[email protected]>
The second beta version of sudo 1.9.4 is now available.  In addition
to bug fixes, Sudo 1.9.4 adds support for JSON-formatted logs as
well as sending log messages to sudo_logsrvd even when I/O logging
is not in use.

Source:
    https://www.sudo.ws/dist/beta/sudo-1.9.4b2.tar.gz
    ftp://ftp.sudo.ws/pub/sudo/beta/sudo-1.9.4b2.tar.gz

SHA256 checksum:
    1027b87e8f4776c2547e4340d7c821ba06b6c017165a82b6d5e17f819f65472b

MD5 checksum:
    0b6baf99756d1f306737ec8f37de9004

Binary packages:
    https://www.sudo.ws/dist/beta/packages/index.html#binary

For a list of download mirror sites, see:
    https://www.sudo.ws/download_mirrors.html

Sudo web site:
    https://www.sudo.ws/

Sudo web site mirrors:
    https://www.sudo.ws/mirrors.html

Major changes between sudo 1.9.4b2 and 1.9.4b1:

 * The sudoers plugin now defaults to sudo-format logs by default,
   as per the documentation (and historical behavior).

 * Fixed a crash in the sudoers plugin when an I/O plugin logging
   function returned an error.

Major changes between sudo 1.9.4b1 and 1.9.3p1:

 * The sudoers parser will now detect when an upper-case reserved
   word is used when declaring an alias.  Now instead of "syntax
   error, unexpected CHROOT, expecting ALIAS" the message will be
   "syntax error, reserved word CHROOT used as an alias name".
   Bug #941.

 * Better handling of sudoers files without a final newline.
   The parser now adds a newline at end-of-file automatically which
   removes the need for special cases in the parser.

 * Fixed a regression introduced in sudo 1.9.1 in the sssd back-end
   where an uninitialized pointer could be freed on an error path.
   GitHub issue #67.

 * The core logging code is now shared between sudo_logsrvd and
   the sudoers plugin.

 * JSON log entries sent to syslog now use "minimal" JSON which
   skips all non-essention whitespace.

 * The sudoers plugin can now produce JSON-formatted logs.  The
   "log_format" sudoers option can be used to select sudo or json
   format logs.  The default is sudo format logs.

 * The sudoers plugin and visudo now display the column number in
   syntax error messages in addition to the line number.  Bug #841.

 * If I/O logging is not enabled but "log_servers" is set, the
   sudoers plugin will now log accept events to sudo_logsrvd.
   Previously, the accept event was only sent when I/O logging was
   enabled.  The sudoers plugin now sends reject and alert events too.

 * The sudo logsrv protocol has been extended to allow an AlertMessage
   to contain an optional array of InfoMessage, as AcceptMessage
   and RejectMessage already do.

 * Fixed a bug in sudo_logsrvd where receipt of SIGHUP would result
   in duplicate entries in the debug log when debugging was enabled.

 * The visudo utility now supports EDITOR environment variables
   that use single or double quotes in the command arguments.
   Bug #942.

 * The PAM session modules now run when sudo is set-user-ID root,
   which allows a module to determine the original user-ID.
   Bug #944.

 * Fixed a regression introduced in sudo 1.8.24 in the LDAP back-end
   where sudoNotBefore and sudoNotAfter were applied even when the
   SUDOERS_TIMED setting was not present in ldap.conf.  Bug #945.

 * Sudo packages for macOS 11 now contain universal binaries that
   support both Intel and Apple Silicon CPUs.

____________________________________________________________
sudo-workers mailing list <[email protected]>
For list information, options, or to unsubscribe, visit:
https://www.sudo.ws/mailman/listinfo/sudo-workers
signature.asc (application/pgp-signature, 801 B)
-----BEGIN PGP SIGNATURE-----

iQIcBAEBCAAGBQJftF3aAAoJEKn0wCHOpHD7FqEP/i6X7hc+E0XuyFDB9NmXa5Jo
E1HEjLxXpMzkWC1+/WoT7sdbhd7YDxsIjwsD6g1EPRUCsNq6tHKtnAaBpGFag9zh
k3ksEAeOyhx0HaAxCESN0Hma3gebwZfpedGymKN913kpKUox2bMfseDAABOodAMM
hIbdKeVKpZhulqSjMcekzxUKai0ALUpOHpe0ptIO/oAu0T7L3n59SsSwuHdSt1Ug
dAGOGqMit2JV7qlNWuNwF1Fu8/iFDOnmn+q75hhdIwftFypjmmcefFYrHtnKuqQL
pqMymXYncg/HQauDgnJxlVRinIEmXtN1Zl1N2n50cvZGF1qwIohgIM4+ZSfpHIAn
HQHMOwHts3Es4bAwp1mCjtU0dbTGLWqO0atp9MmH6vpKlDEK7X0XSd4vRAFgpNSM
hAX5HIwW1layWNqGwiLwzGA35zR8UxZrrIbjiD8u+ablqyXsSLKw52dXjdsGH0w7
IH6+N+336MCMYvZhciCTfk3jPAxpVawYmlwTlyq55eHgDNuQF56FLEK1sdfTRo8b
e5Ar/MOepU58Mt6RVWichbiLDwCfH4RVx/6or0vEwGwc5aobhqzty9qNDByJ8dKC
W7lQS7+hWzTDB45zMb3+NlV8aY1YkCiTJjjIPcgWX25t6J2n+indHqAhKBU1v3nd
uRYTFQyQVHs73x9uFF7i
=kM21
-----END PGP SIGNATURE-----