sudo 1.9.10rc1 released
"Todd C. Miller" <[email protected]> Mon, 28 Feb 2022 07:40:11 -0700
| Newsgroups | gmane.comp.tools.sudo.devel |
|---|---|
| Message-ID | <[email protected]> |
--===============3860202458045338104==
Content-Type: multipart/signed; protocol="application/pgp-signature";
micalg=pgp-; boundary="66237_Mon_Feb_28_07_40_02_MST_2022"
--66237_Mon_Feb_28_07_40_02_MST_2022
Content-Type: text/plain; charset=us-ascii
The first release candidate for sudo 1.9.10 is now available.
In addition to bug fixes, sudo 1.9.10 introduces support for using
regular expressions in the sudoers file. Either the command, the
arguments, or both may be (separate) regular expressions.
Source:
https://www.sudo.ws/dist/beta/sudo-1.9.10rc1.tar.gz
ftp://ftp.sudo.ws/pub/sudo/beta/sudo-1.9.10rc1.tar.gz
SHA256 checksum:
f3e3cd24e28e16410354a661294b47d458bd1d10d0f092cff48bc4622d089b64
MD5 checksum:
abe7e9495459b4188382ccf28fd179aa
Binary packages:
https://www.sudo.ws/getting/beta_packages/
For a list of download mirror sites, see:
https://www.sudo.ws/getting/download_mirrors/
Sudo web site:
https://www.sudo.ws/
Major changes between sudo 1.9.10rc1 and 1.9.10b4:
* Fixed a test failure on Alpine Linux.
* In fuzz_logsrvd_conf, avoid fuzzing the system's regular expression
implementation.
* Added a configure check for gzclearerr() when using the system zlib.
Older versions of zlib do not include gzclearerr() but sudo now needs it.
Major changes between sudo 1.9.10b4 and 1.9.10b3:
* Fixed issues found by the Coverity Scan static analyzer,
https://scan.coverity.com/.
Major changes between sudo 1.9.10b3 and 1.9.10b2:
* Restored the warning when a user is not allowed to run a command.
Previously, the warning was displayed when a user was not in the
sudoers file, or was present but not listed for the local host. The
new behavior is to display the warning if a command is denied *and*
mail is sent to the administrator. Whether or not mail is sent is
controlled by the "mail_*" flags in sudoers. The warning text is now
"This incident has been reported to the administrator." which is
hopefully less confusing. The message will not be printed if either
the "mailto" or "mailerpath" sudoers settings are disabled.
* The sudo lecture is now displayed immediately before the password
prompt. As a result, sudo will no longer display the lecture
unless the user needs to enter a password. Authentication methods
that don't interact with the user via a terminal do not trigger
the lecture.
Major changes between sudo 1.9.10b2 and 1.9.10b1:
* A user may now only run "sudo -U otheruser -l" if they have a
"sudo ALL" privilege where the RunAs user contains either "root"
or "otheruser". Previously, having "sudo ALL" was sufficient,
regardless of the RunAs user. GitHub issue #134.
* Documentation updates.
* Fixed a bug in the heuristic used to decide when to disable
password filtering when "log_input" is enabled and "log_passwords"
is disabled. Also added regession tests for password filtering.
* Updated translations from translationproject.org.
Major changes between sudo 1.9.10b1 and 1.9.9:
* Added new "log_passwords" and "passprompt_regex" sudoers options.
If "log_passwords" is disabled, sudo will attempt to prevent passwords
from being logged. If sudo detects any of the regular expressions in
the "passprompt_regex" list in the terminal output, sudo will log '*'
characters instead of the terminal input until a newline or carriage
return is found in the input or an output character is received.
* Added new "log_passwords" and "passprompt_regex" settings to
sudo_logsrvd that operate like the sudoers options when logging
terminal input.
* Fixed several few bugs in the cvtsudoers utility when merging
multiple sudoers sources.
* Fixed a bug in sudo_logsrvd when parsing the sudo_logsrvd.conf
file, where the "retry_interval" in the [relay] section was not
being recognized.
* Restored the pre-1.9.9 behavior of not performing authentication
when sudo's -n option is specified. A new "noninteractive_auth"
sudoers option has been added to enable PAM authentication in
non-interactive mode. GitHub issue #131.
* On systems with /proc, if the /proc/self/stat (Linux) or
/proc/pid/psinfo (other systems) file is missing or invalid,
sudo will now check file descriptors 0-2 to determine the user's
terminal. Bug #1020.
* Fixed a compilation problem on Debian kFreeBSD. Bug #1021.
* Fixed a crash in sudo_logsrvd when running in relay mode if
an alert message is received.
* Fixed an issue that resulting in "problem with defaults entries"
email to be sent if a user ran sudo when the sudoers entry in
the nsswitch.conf file includes "sss" but no sudo provider is
configured in /etc/sssd/sssd.conf. Bug #1022.
* Removed the text "This incident will be reported." from warnings
when the invoking user is not listed in sudoers. This warning
is confusing to users and may not be accurate now that the email
settings are configurable in the sudoers file. GitHub issue #48.
* Fixed a bug where the user-specified command timeout was not
being honored if the sudoers rule did not also specify a timeout.
* Added support for using POSIX extended regular expressions in
sudoers rules. A command and/or arguments in sudoers are treated
as a regular expression if they start with a '^' character and
end with a '$'. The command and arguments are matched separately,
either one (or both) may be a regular expression.
Bug #578, GitHub issue #15.
--66237_Mon_Feb_28_07_40_02_MST_2022
Content-Type: application/pgp-signature
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEWdHpzLorN2cE/dNbqfTAIc6kcPsFAmIc3sIACgkQqfTAIc6k
cPuTMw/8Dqi9qzIJYKVVF3IfCUPIT0lmsDPrhd7d3I74UIAdtfrRP5y5MXLNolTE
cSeIY/bWhhuFRVSLjyEvkeYYrFBPANchvP46+WhxGN26HdCD/kP/ibuYBDHiUJUl
WY26O4310k8LRAZdYq4y75lOhJ52JK7/EFoZ/3GO3pSegVgIxYTZaF/4vu/6RsPm
L92qqSYr4+M71sZa897fksQil63tv3QK3TTpHQu+cW9D4dmxpHTw5CV7RAU3zWCr
SMS2rbaO7vZtRLg8YLfg1fpIJbltSFxPpyZ5NtDX+l1CKtaRdOX7zE0l7GgRBl7v
j6MszxNps41AeZU1l1zLY8YT/GUx0RNinXzXE/h7+7MPZDb6TW19FnEqt5ZT/i5T
CM/mH33EFF3qIfd+X5lVttNpwR6aj+Lh/eN2rtS2ULIxellpRGm/NSEaHxruDVVt
UwVwlOyMl5pSIbgRtpnDq/srCJnTxRFHH6g7eAfQoSU8HuFB2YE6hjNTfKljno2e
4Qk1mIcnRWbVwuTeV0kgeqrGC5+Pk+VqeIq9zChh4VTqloO8DiY4QvLklVr9/1LF
paH2GTOe+002ZlkHtPpSYeksDzhNHj5/IG+KAVds8eHclaG97zRvT1stSc7/a6s0
6uz4T2FDNSbsIhD7tEfQA6/tHpJyWpxXazrl47xREKE7TvW2fjs=
=o5A9
-----END PGP SIGNATURE-----
--66237_Mon_Feb_28_07_40_02_MST_2022--
--===============3860202458045338104==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
____________________________________________________________
sudo-workers mailing list <[email protected]>
For list information, options, or to unsubscribe, visit:
https://www.sudo.ws/mailman/listinfo/sudo-workers
--===============3860202458045338104==--