sudo 1.9.9b2 released

"Todd C. Miller" <[email protected]> Mon, 13 Dec 2021 11:06:02 -0700
Newsgroups gmane.comp.tools.sudo.devel
Message-ID <[email protected]>
--===============3537337819250624820==
Content-Type: multipart/signed; protocol="application/pgp-signature";
  micalg=pgp-; boundary="62669_Mon_Dec_13_11_05_44_MST_2021"

--62669_Mon_Dec_13_11_05_44_MST_2021
Content-Type: text/plain; charset=us-ascii

The second beta release of sudo 1.9.9 is now available.

In addition to bug fixes, sudo 1.9.9 extends the cvtsudoers utility
in several ways.  With sudo 1.9.9, cvtsudoers now supports csv
output, can merge multiple sudoers files and can perform filtering
based on commands.

Source:
    https://www.sudo.ws/dist/beta/sudo-1.9.9b2.tar.gz
    ftp://ftp.sudo.ws/pub/sudo/beta/sudo-1.9.9b2.tar.gz

SHA256 checksum:
    78b66ff782e6d0ba7331b4ad49a629aba8fa37db7eb6f3dd6b01244d08f995b1

MD5 checksum:
    754035148b9c9ffc523cef945884129c

Binary packages:
    https://www.sudo.ws/dist/beta/packages/

For a list of download mirror sites, see:
    https://www.sudo.ws/getting/download_mirrors/

Sudo web site:
    https://www.sudo.ws/

Major changes between sudo 1.9.9b2 and 1.9.9b1:

 * Sudo was parsing but not applying the "deref" and "tls_reqcert"
   ldap.conf settings.  This meant the options were effectively
   ignored which broke dereferencing of aliases in LDAP.  Bug #1013.

 * Clarified in the sudo man page that the security policy may
   override the user's PATH environment variable.  Bug #1014.

 * Silenced CodeQL "Multiplication result converted to larger type"
   warnings.

 * Fixed a potential TOCTOU issue in sudo_mkdir_parents() when
   creating the final directory component.  This is not a problem
   in practice since the directory is root-owned.

 * Updated translations from https://translationproject.org.

Major changes between sudo 1.9.9 and 1.9.8p2:

 * Sudo can now be built with OpenSSL 3.0 without generating warnings
   about deprecated OpenSSL APIs.

 * A digest can now be specified along with the "ALL" command in
   the LDAP and SSSD back-ends.  Sudo 1.9.0 introduced support for
   this in the sudoers file but did not include corresponding changes
   for the other back-ends.

 * visudo now only warns about an undefined alias or a cycle in an
   alias once for each alias.

 * The sudoRole cn was truncated by a single character in warning messages.
   GitHub issue #115.

 * The cvtsudoers utility has new --group-file and --passwd-file options
   to use a custom passwd or group file when the --match-local option is
   also used.

 * The cvtsudoers utility can now filter or match based on a command.

 * The cvtsudoers utility can now produce output in csv (comma-separated
   value) format.  This can be used to help generate entitlement reports.

 * Fixed a bug in sudo_logsrvd that could result in the connection being
   dropped for very long command lines.

 * Fixed a bug where sudo_logsrvd would not accept a restore point
   of zero.

 * Fixed a bug in visudo where the value of the "editor" setting was not
   used if it did not match the user's EDITOR environment variable.
   This was only a problem if the "env_editor" setting was not enabled.
   Bug #1000.

 * Sudo now builds with the -fcf-protection compiler option and the
   "-z now" linker option if supported.

 * The output of "sudoreplay -l" now more closely matches the
   traditional sudo log format.

 * The sudo_sendlog utility will now use the full contents of the log.json
   file, if present.  This makes it possible to send sudo-format I/O logs
   that use the newer log.json format to sudo_logsrvd without losing any
   information.

 * Fixed compilation of the arc4random_buf() replacement on systems with
   arc4random() but no arc4random_buf().  Bug #1008.

 * Sudo now uses its own getentropy() by default on Linux.  The GNU libc
   version of getentropy() will fail on older kernels that don't support
   the getrandom() system call.

 * It is now possible to build sudo with WolfSSL's OpenSSL compatibility
   layer by using the --enable-wolfssl configure option.

 * Fixed a bug related to Daylight Saving Time when parsing timestamps
   in Generalized Time format.  This affected the NOTBEFORE and
   NOTAFTER options in sudoers.  Bug #1006

 * On systems where SELinux is enabled and sudo is built with SELinux
   support, if the user's role is not "unconfined_r" sudo will always
   execute commands via the "sesh" helper program.  Previously, commands
   were only executed via "sesh" if a role was specified in the sudoers
   file rule or by the user on the command line.

 * Added the -O and -P options to visudo, which can be used to check
   or set the owner and permissions.  This can be used in conjunction
   with the -c option to check that the sudoers file ownership and
   permissions are correct.  Bug #1007.

 * It is now possible to set resource limits in the sudoers file itself.
   The special values "default" and "user" refer to the default system
   limit and invoking user limit respectively.  The core dump size limit
   is now set to 0 by default unless overridden by the sudoers file.

 * The cvtsudoers utility can now merge multiple sudoers sources into
   a single, combined sudoers file.  If there are conflicting entries,
   cvtsudoers will attempt to resolve them but manual intervention
   may be required.  The merging of sudoers rules is currently fairly
   simplistic but will be improved in a future release.

--62669_Mon_Dec_13_11_05_44_MST_2021
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEWdHpzLorN2cE/dNbqfTAIc6kcPsFAmG3i3gACgkQqfTAIc6k
cPsxVRAAn7eEHYlhQ5CQ8qKP+izcTM96XztO1sbNYqtbV/b7mk5Si2whSe7y3V4T
qDQkA4XyC1JdhZ+YgFx240EG6VbXRdrgOoFiqVAYpxZp/jhuUgQ2LSC1PyXp8HnC
CZijwJZF12tLm2WYiaM+41eqKcU8AgrbthzZ3MX3DnlEoenCDWReo5LHixOuvD6g
OCEkn8IRape2/3WvISH9nEpn3iOk/GM7Dsy5Ev67KijRkG4IJ23iImwRcuqsxHeY
synY13SKX1uggwPiNk2Fcf3Jdi7Lw72g4eiVA+dc6FU503f8nk/H9MQ7r+OfgWr9
i23CyVKRpMIcu1NCxfi0PBWE15FG1UL75gYqon6rjCyGea+kItNh7gpEbagRk/mF
tYb9ehqL4Th+DK07pgsS0DmrJPvxHe+hlGO6bwrdDEs6AuqDIgsUsDcq1eE3kcT5
W5JKAP2RZ95fos9qD5JxXRa+AB8+Jd2R7s4LLR7xKsfyyH+1L7g0RIF+2VonIFIM
+5d4H0RZ9hkZLiMGGHFQO9a2DLPj/2vS8oGhsBiraYbiQ8VC3kbNQwthOmiIDU83
AWZYqGprntsKj5M+CXIgcTNNQNCZ2MsruBAa8hP6emjyriNrHBjQKi9hED3NbEGK
JFHN6fC+R+qaCn14yJ8FUGCJOMnlslUDTPekez3x/6gryXfRhG8=
=hBYr
-----END PGP SIGNATURE-----

--62669_Mon_Dec_13_11_05_44_MST_2021--


--===============3537337819250624820==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

____________________________________________________________
sudo-workers mailing list <[email protected]>
For list information, options, or to unsubscribe, visit:
https://www.sudo.ws/mailman/listinfo/sudo-workers

--===============3537337819250624820==--