sudo 1.9.8b3 released

"Todd C. Miller" <[email protected]> Thu, 26 Aug 2021 19:19:31 -0600
Newsgroups gmane.comp.tools.sudo.devel
Message-ID <[email protected]>
--===============5717233161873560654==
Content-Type: multipart/signed; protocol="application/pgp-signature";
  micalg=pgp-; boundary="42207_Thu_Aug_26_19_19_25_MDT_2021"

--42207_Thu_Aug_26_19_19_25_MDT_2021
Content-Type: text/plain; charset=us-ascii

The third beta release of sudo 1.9.8 is now available.

In addition to bug fixes, sudo 1.9.8 adds a new "intercept" mode
that can be used to intercept the execve() system call in the command
run by sudo and do a policy check on sub-commands before they are
executed.  Intercept mode uses LD_PRELOAD to communicate with the
main sudo process to perform the sudoers check.  As such, there are
some limitations.  See the sudoers man page for details.

Sudo 1.9.8 also includes a new sudoers setting, log_subcmds, which
works like intercept mode but only logs the command that was run
and does not validate it against the sudoers file.

Source:
    https://www.sudo.ws/dist/beta/sudo-1.9.8b3.tar.gz
    ftp://ftp.sudo.ws/pub/sudo/beta/sudo-1.9.8b3.tar.gz

SHA256 checksum:
    bb56424f8ee2c23249e0753e7f92c4a666499e17dadccbcf0f38952f1af2f929

MD5 checksum:
    aa07ae3089e92da7b3486ee75eeb527b

Binary packages:
    https://www.sudo.ws/dist/beta/packages/index.html#binary

For a list of download mirror sites, see:
    https://www.sudo.ws/download_mirrors.html

Sudo web site:
    https://www.sudo.ws/

Sudo web site mirrors:
    https://www.sudo.ws/mirrors.html

Major changes between sudo 1.9.8b3 and 1.9.8b2:

 * The log_children sudoers setting has been renamed to log_subcmds.

 * The execv() function can now be intercepted as well as execve.

 * Rewrote the sudo_intercept.so <-> sudo interprocess communication.
   It now uses a localhost TCP socket instead of an inherited file
   descriptor.  Some shells close all open file descriptors greater
   than 2 when they start up which did not work with the old scheme.
   In the new scheme, the inherited file descriptor is only used
   to retrieve a shared secret and port number, after which is is
   closed.  The actual policy decision is made over a new TCP
   connection in the intercepted execve() call.

 * Fixed formatting for bound defaults with multiple entries in the
   binding. The entries in the binding were separated with " ,"
   instead of ", ".

 * Fixed logging of the command name for "log_children".  Previously,
   the parent process name was logged (though the logged argv was
   correct).

 * Updated translations from translationproject.org.

Major changes between sudo 1.9.8b2 and 1.9.8b1:

 * Sudo will no longer permit a set-user-ID or set-group-ID program
   to be run in intercept mode unless the new "intercept_allow_setid"
   sudoers setting is enabled.

 * The mksigname and mksiglist helper programs are now built with
   the host compiler, not the target compiler, when cross-compiling.
   Bug #989.

Major changes between sudo 1.9.8b1 and 1.9.7p2:

 * It is now possible to transparently intercepting sub-commands
   executed by the original command run via sudo.  Intercept support
   is implemented using LD_PRELOAD (or the equivalent supported by
   the system) and so has some limitations.  The two main limitations
   are that only dynamic executables are supported and only the
   execve() system call is currently intercepted.  Its main use
   case is to support restricting privileged shells run via sudo.

   To support this, there is a new "intercept" Defaults setting and
   an INTERCEPT command tag that can be used in sudoers.  For example:

    Cmnd_Alias SHELLS=/bin/bash, /bin/sh, /bin/csh, /bin/ksh, /bin/zsh
    Defaults!SHELLS intercept

   would cause sudo to run the listed shells in intercept mode.
   This can also be set on a per-rule basis.  For example:

    Cmnd_Alias SHELLS=/bin/bash, /bin/sh, /bin/csh, /bin/ksh, /bin/zsh
    chuck ALL = INTERCEPT: SHELLS

   would only apply intercept mode to user "chuck" when running one
   of the listed shells.

 * The new "log_children" sudoers setting can be used to log commands
   run in a privileged shell.  It uses the same mechanism as the
   intercept support described above and has the same limitations.

 * Support for logging sudo_logsrvd errors via syslog or to a file.
   Previously, most sudo_logsrvd errors were only visible in the
   debug log.

 * Better diagnostics when there is a TLS certificate validation error.

 * Using the "+=" or "-=" operators in a Defaults setting that takes
   a string, not a list, now produces a warning from sudo and a
   syntax error from inside visudo.

 * Fixed a bug where the "iolog_mode" setting in sudoers and sudo_logsrvd
   had no effect when creating I/O log parent directories if the I/O log
   file name ended with the string "XXXXXX".

 * Fixed a bug in the sudoers custom prompt code where the size
   parameter that was passed to the strlcpy() function was incorrect.
   No overflow was possible since the correct amount of memory was
   already pre-allocated.

--42207_Thu_Aug_26_19_19_25_MDT_2021
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEWdHpzLorN2cE/dNbqfTAIc6kcPsFAmEoPZ0ACgkQqfTAIc6k
cPupWxAAgU9VowPpH1b3ER4nEFbBuZeM2ub5tVfd5fPEy6jIG8zdcbrX2D/vg4vo
lfIf/dFWjzGWMiLZHsgfoLFB6gvQnVC1Fk6hgvRF6k+ML6OJCyJ7IiCZltmVJkzI
Pc7/WviCdCuiceAYAWtQWTk9f8zRW7UhOeCzsqPiZ1RebA0N9unvOhdEN30teNiD
DfUrKhqRWQfouERgE3Sfso8fVBTqHZQUUvHeZ1KcKNanPFIaks8hZ2BpTcuN6jHk
6e5SEgaj68bmwNt7bCDx6svn+V/CJzkj19gZ/Yj19nVwyUAE+op9y6QMNcSpFwXR
O3OSbEEwUCLVkpw3l+WhVz7kTfHDExfncKLDHFCmXQHWcuQtcOC6cihxZk3Nrt3v
DOxPGozqPiZ1yWAWZUQ5IV3hxJuNYsk2g3xRy9CqruXfFOi/0aPcxt87IN25XVDS
ZzEPbpivKaVrLQt6lq2My7zT9iDNhouxV9UGO3u5dqjScY+iE8qUR9DDV1idBFUy
lVFiPZ3al42H0YXAZCRGwym6Njy+zf+x1+xWnL6HKLYzc53JueusynTrNdJ+JtP2
OX1jKswhzsn+yWUAYvTaznZx1otPP0ho/Xf2iC3eeuV3haMczZhdmIgja+nb7O1E
+eFbD/gr4uGLrYIs71VJolExj2RYlkHDsEatcigYzgFn/VGF8E8=
=kSZH
-----END PGP SIGNATURE-----

--42207_Thu_Aug_26_19_19_25_MDT_2021--


--===============5717233161873560654==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

____________________________________________________________
sudo-workers mailing list <[email protected]>
For list information, options, or to unsubscribe, visit:
https://www.sudo.ws/mailman/listinfo/sudo-workers

--===============5717233161873560654==--