Commit Graph

85 Commits

Author SHA1 Message Date
millert cf6bdf9cbc Update to sudo 1.9.16p1 2024-11-13 02:58:52 +00:00
sthen 384eb28542 bump REVISION for py3.10 -> py3.11 switch 2024-05-06 12:23:55 +00:00
millert d352089b27 Update to sudo 1.9.15p5; bug fix release 2023-12-30 23:58:59 +00:00
millert 4e66ac00ff Update to sudo 1.9.15p5; bug fix release 2023-12-30 18:30:30 +00:00
millert 925b68bf03 Update to sudo 1.9.15p4; fixes several bugs introduced in 1.9.15. 2023-12-15 20:48:31 +00:00
millert 84de991af8 Update to sudo 1.9.15p2; fixes a bug on terminals with parity enabled. 2023-11-09 20:04:22 +00:00
millert 2eff52525b Update to sudo 1.9.15p1, which fixes a problem reading ldap.conf. 2023-11-07 21:37:34 +00:00
millert dcc00c04c0 Update to sudo 1.9.15 2023-11-06 18:02:04 +00:00
espie 8ca1dc5576 MASTER_SITES -> SITES 2023-09-27 16:34:29 +00:00
millert 66e818e4b2 Update to sudo 1.9.14p2 2023-07-17 17:19:32 +00:00
millert a44c903b43 Update checksums for 1.9.14p1 2023-07-12 13:45:19 +00:00
millert 3752ec479c Update to sudo 1.9.14p1 2023-07-11 22:51:49 +00:00
millert 7a8141790e Update to sudo 1.9.14 and remove a dead mirror. 2023-06-28 01:58:15 +00:00
millert 0ac88a6d61 Update to sudo 1.9.13p2 2023-03-06 17:27:18 +00:00
millert 5533c165ad Update to sudo 1.9.13p2 2023-02-27 16:18:55 +00:00
millert 366ce61669 Update to sudo 1.9.13 2023-02-14 19:28:08 +00:00
millert 62656c9b83 Update to sudo 1.9.12p2, which includes a fix for CVE-2023-22809.
Fixes a bug that could allow a user with "sudoedit" privileges to
edit arbitrary files.
2023-01-18 16:02:36 +00:00
sthen 1427b990d1 bump for MODPY_DEFAULT_VERSION_3 change 2022-11-13 15:29:41 +00:00
millert fcbabdd359 Update to 1.9.12 2022-10-27 16:34:07 +00:00
millert 32084bb5f9 Update to 1.9.11p2 2022-06-12 21:11:31 +00:00
millert 9f32c334f5 Update to 1.9.11p1 2022-06-08 17:08:58 +00:00
naddy 8c0294c2fa drop RCS Ids 2022-03-11 19:53:16 +00:00
millert 18407824d0 Update to sudo 1.9.10 2022-03-04 17:54:43 +00:00
sthen 29389da44c bump REVISION for switch from Python 3.8 -> 3.9 2021-11-02 00:02:15 +00:00
millert 4ef54729ab Update to sudo 1.9.7p2 2021-07-28 18:46:51 +00:00
millert e59c3ee517 Update to sudo 1.9.7p1 2021-06-11 21:49:41 +00:00
millert 443a01a3dc Update to sudo 1.9.7 2021-05-12 13:02:09 +00:00
millert 06641650cf Update to sudo 1.9.6p1 2021-03-15 18:49:47 +00:00
sthen 745105c362 automatically handle ports which use the python module and have flavours
other than the usual "python3/<blank>" python version selection and
remove setting MODPY_VERSION=${MODPY_DEFAULT_VERSION_3} again from the
affected ports.
2021-02-23 22:04:35 +00:00
sthen 761c9f34ff ports which use the python module and have flavours other than the
usual "python3/<blank>" python version selection still require setting
MODPY_VERSION for now.
2021-02-23 21:45:49 +00:00
sthen 3cbe1c2f30 Reverse the polarity of MODPY_VERSION; default is now 3.x,
if a port needs 2.x then set MODPY_VERSION=${MODPY_DEFAULT_VERSION_2}.

This commit doesn't change any versions currently used; it may be that
some ports have MODPY_DEFAULT_VERSION_2 but don't require it, those
should be cleaned up in the course of updating ports where possible.

Python module ports providing py3-* packages should still use
FLAVOR=python3 so that we don't have a mixture of dependencies some
using ${MODPY_FLAVOR} and others not.
2021-02-23 19:39:08 +00:00
sthen 053c6189b6 add FLAVOR_STRING to SUBST_VARS, fixing an issue with updates from pre-
multipackage versions reported by danj@ and reproduced by tb@
2021-01-26 21:18:35 +00:00
millert d69645e849 Update to sudo 1.9.5p2; fixes CVE-2021-3156 2021-01-26 18:19:19 +00:00
millert e33586a494 Update to sudo 1.9.5p1 2021-01-12 02:19:47 +00:00
millert 1743229737 Update to sudo 1.9.5 2021-01-11 14:55:29 +00:00
millert 2a4d24eafd Update to sudo 1.9.4p2 2020-12-20 17:37:48 +00:00
millert fb7d438e34 Update to sudo 1.9.4p1 2020-12-18 17:31:32 +00:00
millert b684478c92 Update to sudo 1.9.4 2020-11-30 17:04:34 +00:00
danj 0529b6ba4e Improve PKGNAME handling
ok millert@ (maintainer)
2020-09-24 02:44:14 +00:00
millert 0993824974 Update to sudo 1.9.3p1. 2020-09-24 02:16:12 +00:00
millert 50865a7200 Update to sudo 1.9.3p1. 2020-09-24 01:38:42 +00:00
sthen d9cfe4113e bump REVISION; python 3 default changed to 3.8 2020-07-03 21:12:24 +00:00
sthen 932c9dac61 append the flavour to the @pkgpath marker, otherwise all flavoured packages
have @pkgpath security/sudo and act as candidates for each other, i.e. to
stop all pkg_add -u runs from asking which flavour to use.  ok millert@
2020-06-26 20:23:54 +00:00
millert 25560ca07a @sample lines need to come immediately after the file they are sampling.
From deserter666 AT danwin1210
2020-06-24 15:58:21 +00:00
sthen e4b68d0789 sudo needs @pkgpath so that updates work (package path for the main
package changed security/sudo -> security/sudo,-main so without this
it's not considered a valid update candidate)
2020-06-21 12:38:52 +00:00
millert 3052f16def Update to sudo 1.9.1.
This adds a new sub-package for the optional Python plugin support,
which can be disabled via the no_python pseudo-flavor.
Thanks to sthen@ and ajacoutot@ for their help.
2020-06-21 12:03:33 +00:00
millert 8fec1b1efc Update sudo to 1.8.31:
* Fixed CVE-2019-18634, a buffer overflow when the "pwfeedback"
   sudoers option is enabled on systems with uni-directional pipes.

 * The "sudoedit_checkdir" option now treats a user-owned directory
   as writable, even if it does not have the write bit set at the
   time of check.  Symbolic links will no longer be followed by
   sudoedit in any user-owned directory.  Bug #912

 * Fixed sudoedit on macOS 10.15 and above where the root file system
   is mounted read-only.  Bug #913.

 * Fixed a crash introduced in sudo 1.8.30 when suspending sudo
   at the password prompt.  Bug #914.

 * Fixed compilation on systems where the mmap MAP_ANON flag
   is not available.  Bug #915.
2020-01-30 18:47:11 +00:00
millert 324a4383d7 Update sudo to 1.8.30:
* Fixed a warning on macOS introduced in sudo 1.8.29 when sudo
   attempts to set the open file limit to unlimited.  Bug #904.

 * Sudo now closes file descriptors before changing uids.  This
   prevents a non-root process from interfering with sudo's ability
   to close file descriptors on systems that support the prlimit(2)
   system call.

 * Sudo now treats an attempt to run "sudo sudoedit" as simply
   "sudoedit".  If the sudoers file contains a fully-qualified path
   to sudoedit, sudo will now treat it simply as "sudoedit" (with
   no path).  Visudo will will now treat a fully-qualified path
   to sudoedit as an error.  Bug #871.

 * Fixed a bug introduced in sudo 1.8.28 where sudo would warn about
   a missing /etc/environment file on AIX and Linux when PAM is not
   enabled.  Bug #907

 * Fixed a bug on Linux introduced in sudo 1.8.29 that prevented
   the askpass program from running due to an unlimited stack size
   resource limit.  Bug #908.

 * If a group provider plugin has optional arguments, the argument list
   passed to the plugin is now NULL terminated as per the documentation.

 * The user's time stamp file is now only updated if both authentication
   and approval phases succeed.  This is consistent with the behavior
   of sudo prior to version 1.8.23.  Bug #910

 * The new allow_unknown_runas_id sudoers setting can be used to
   enable or disable the use of unknown user or group IDs.  Previously,
   sudo would always allow unknown user or group IDs if the sudoers
   entry permitted it, including via the "ALL" alias.  As of sudo
   1.8.30, the admin must explicitly enable support for unknown IDs.

 * The new runas_check_shell sudoers setting can be used to require
   that the runas user have a shell listed in the /etc/shells file.
   On many systems, users such as "bin", do not have a valid shell
   and this flag can be used to prevent commands from being run as
   those users.

 * Fixed a problem restoring the SELinux tty context during reboot
   if mctransd is killed before sudo finishes.  GitHub Issue #17.

 * Fixed an intermittent warning on NetBSD when sudo restores the
   initial stack size limit.
2019-12-31 21:54:25 +00:00
millert f9dd2cf493 Update sudo to 1.8.29:
* The cvtsudoers command will now reject non-LDIF input when converting
   from LDIF format to sudoers or JSON formats.

 * The new log_allowed and log_denied sudoers settings make it possible
   to disable logging and auditing of allowed and/or denied commands.

 * The umask is now handled differently on systems with PAM or login.conf.
   If the umask is explicitly set in sudoers, that value is used regardless
   of what PAM or login.conf may specify.  However, if the umask is not
   explicitly set in sudoers, PAM or login.conf may now override the default
   sudoers umask.  Bug #900.

 * For "make install", the sudoers file is no longer checked for syntax
   errors when DESTDIR is set.  The default sudoers file includes the
   contents of /etc/sudoers.d which may not be readable as non-root.
   Bug #902.

 * Sudo now sets most resource limits to their maximum value to avoid
   problems caused by insufficient resources, such as an inability to
   allocate memory or open files and pipes.

 * Fixed a regression introduced in sudo 1.8.28 where sudo would refuse
   to run if the parent process was not associated with a session.
   This was due to sudo passing a session ID of -1 to the plugin.
2019-10-28 15:02:49 +00:00
sthen 9fe02b340e bump REVISION for -current sudo to take it to the same version as 6.6-stable 2019-10-22 09:36:21 +00:00