Compare commits
11 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
4a38bfd993 | ||
|
|
6f3e82a06e | ||
|
|
27656ff04a | ||
|
|
2afce7309a | ||
|
|
89e79d5fa4 | ||
|
|
cc26f17cfe | ||
|
|
a3b3d5977e | ||
|
|
8d93f09269 | ||
|
|
b1ec1d2035 | ||
|
|
051f80c5d2 | ||
|
|
50dc239656 |
12 changed files with 167 additions and 513 deletions
31
.gitignore
vendored
31
.gitignore
vendored
|
|
@ -1,21 +1,10 @@
|
||||||
sudo-1.7.2p6.tar.gz
|
/sudo-1.8.16.tar.gz
|
||||||
sudo-1.7.2p2-sudoers
|
/sudo-1.8.17p1.tar.gz
|
||||||
/sudo-1.7.4p4.tar.gz
|
/sudo-1.8.18b2.tar.gz
|
||||||
/sudo-1.7.2p2-sudoers
|
/sudo-1.8.18rc2.tar.gz
|
||||||
/sudo-1.7.4p4-sudoers
|
/sudo-1.8.18rc4.tar.gz
|
||||||
/sudo-1.7.4p5.tar.gz
|
/sudo-1.8.18.tar.gz
|
||||||
/sudo-1.8.1p2.tar.gz
|
/sudo-1.8.18p1.tar.gz
|
||||||
/sudo-1.8.3p1.tar.gz
|
/sudo-1.8.19p2.tar.gz
|
||||||
/sudo-1.8.5.tar.gz
|
/sudo-1.8.20p1.tar.gz
|
||||||
/sudo-1.8.6.tar.gz
|
/sudo-1.8.20p2.tar.gz
|
||||||
/sudo-1.8.6p3.tar.gz
|
|
||||||
/sudo-1.8.6p7.tar.gz
|
|
||||||
/sudo-1.8.8.tar.gz
|
|
||||||
/sudo-1.8.8-sudoers
|
|
||||||
/sudo-1.8.11.tar.gz
|
|
||||||
/sudo-1.8.11p2.tar.gz
|
|
||||||
/sudo-1.8.12.tar.gz
|
|
||||||
/sudo-1.8.14b4.tar.gz
|
|
||||||
/sudo-1.8.14p1.tar.gz
|
|
||||||
/sudo-1.8.14p3.tar.gz
|
|
||||||
/sudo-1.8.15.tar.gz
|
|
||||||
|
|
|
||||||
3
sources
3
sources
|
|
@ -1,2 +1 @@
|
||||||
775b863cdff3a2ee2a26c2d53b51aff5 sudo-1.8.8-sudoers
|
SHA512 (sudo-1.8.20p2.tar.gz) = 8bf67e687f7a84605fdef8d547b5cd661141b6c8fd25820c33c7e37e97ca7f21f564c3bae691f8a8cd08df7d80338e36a8f06bb5086cc104509d71d6ab1bceda
|
||||||
7cf6b9b76d0478a572432bed481dd7b5 sudo-1.8.15.tar.gz
|
|
||||||
|
|
|
||||||
|
|
@ -1,12 +0,0 @@
|
||||||
diff -up sudo-1.7.2p1/configure.in.envdebug sudo-1.7.2p1/configure.in
|
|
||||||
--- sudo-1.7.2p1/configure.in.envdebug 2009-10-30 12:18:09.000000000 +0100
|
|
||||||
+++ sudo-1.7.2p1/configure.in 2009-10-30 12:19:01.000000000 +0100
|
|
||||||
@@ -1214,7 +1214,7 @@ AC_ARG_ENABLE(env_debug,
|
|
||||||
[AS_HELP_STRING([--enable-env-debug], [Whether to enable environment debugging.])],
|
|
||||||
[ case "$enableval" in
|
|
||||||
yes) AC_MSG_RESULT(yes)
|
|
||||||
- AC_DEFINE(ENV_DEBUG)
|
|
||||||
+ AC_DEFINE(ENV_DEBUG, [], [Environment debugging.])
|
|
||||||
;;
|
|
||||||
no) AC_MSG_RESULT(no)
|
|
||||||
;;
|
|
||||||
|
|
@ -1,17 +0,0 @@
|
||||||
diff -up sudo-1.8.11p2/plugins/sudoers/linux_audit.c.auditfix sudo-1.8.11p2/plugins/sudoers/linux_audit.c
|
|
||||||
--- sudo-1.8.11p2/plugins/sudoers/linux_audit.c.auditfix 2014-11-03 12:44:53.674230966 +0100
|
|
||||||
+++ sudo-1.8.11p2/plugins/sudoers/linux_audit.c 2014-11-03 12:45:13.407021599 +0100
|
|
||||||
@@ -57,10 +57,10 @@ linux_audit_open(void)
|
|
||||||
au_fd = audit_open();
|
|
||||||
if (au_fd == -1) {
|
|
||||||
/* Kernel may not have audit support. */
|
|
||||||
- if (errno != EINVAL && errno != EPROTONOSUPPORT && errno != EAFNOSUPPORT) {
|
|
||||||
- sudo_warn(U_("unable to open audit system"));
|
|
||||||
+ if (errno == EINVAL || errno == EPROTONOSUPPORT || errno == EAFNOSUPPORT)
|
|
||||||
au_fd = AUDIT_NOT_CONFIGURED;
|
|
||||||
- }
|
|
||||||
+ else
|
|
||||||
+ sudo_warn(U_("unable to open audit system"));
|
|
||||||
} else {
|
|
||||||
(void)fcntl(au_fd, F_SETFD, FD_CLOEXEC);
|
|
||||||
}
|
|
||||||
|
|
@ -1,38 +0,0 @@
|
||||||
diff -up sudo-1.8.14b4/doc/sudoers.cat.docpassexpire sudo-1.8.14b4/doc/sudoers.cat
|
|
||||||
--- sudo-1.8.14b4/doc/sudoers.cat.docpassexpire 2015-06-09 00:47:07.000000000 +0200
|
|
||||||
+++ sudo-1.8.14b4/doc/sudoers.cat 2015-07-14 13:11:11.116000185 +0200
|
|
||||||
@@ -1328,8 +1328,8 @@ SSUUDDOOEERRSS OOPPTTIIOONN
|
|
||||||
fractional component if minute granularity is
|
|
||||||
insufficient, for example 2.5. The default is 5. Set
|
|
||||||
this to 0 to always prompt for a password. If set to a
|
|
||||||
- value less than 0 the user's time stamp will never
|
|
||||||
- expire. This can be used to allow users to create or
|
|
||||||
+ value less than 0 the user's time stamp will not
|
|
||||||
+ expire until reboot. This can be used to allow users to create or
|
|
||||||
delete their own time stamps via ``sudo -v'' and ``sudo
|
|
||||||
-k'' respectively.
|
|
||||||
|
|
||||||
diff -up sudo-1.8.14b4/doc/sudoers.man.in.docpassexpire sudo-1.8.14b4/doc/sudoers.man.in
|
|
||||||
--- sudo-1.8.14b4/doc/sudoers.man.in.docpassexpire 2015-07-14 13:11:11.116000185 +0200
|
|
||||||
+++ sudo-1.8.14b4/doc/sudoers.man.in 2015-07-14 13:14:17.261222481 +0200
|
|
||||||
@@ -2822,7 +2822,7 @@ Set this to
|
|
||||||
to always prompt for a password.
|
|
||||||
If set to a value less than
|
|
||||||
\fR0\fR
|
|
||||||
-the user's time stamp will never expire.
|
|
||||||
+the user's time stamp will not expire until reboot.
|
|
||||||
This can be used to allow users to create or delete their own time stamps via
|
|
||||||
\(Lq\fRsudo -v\fR\(Rq
|
|
||||||
and
|
|
||||||
diff -up sudo-1.8.14b4/doc/sudoers.mdoc.in.docpassexpire sudo-1.8.14b4/doc/sudoers.mdoc.in
|
|
||||||
--- sudo-1.8.14b4/doc/sudoers.mdoc.in.docpassexpire 2015-04-07 18:15:50.000000000 +0200
|
|
||||||
+++ sudo-1.8.14b4/doc/sudoers.mdoc.in 2015-07-14 13:11:11.117000176 +0200
|
|
||||||
@@ -2647,7 +2647,7 @@ Set this to
|
|
||||||
to always prompt for a password.
|
|
||||||
If set to a value less than
|
|
||||||
.Li 0
|
|
||||||
-the user's time stamp will never expire.
|
|
||||||
+the user's time stamp will not expire until reboot.
|
|
||||||
This can be used to allow users to create or delete their own time stamps via
|
|
||||||
.Dq Li sudo -v
|
|
||||||
and
|
|
||||||
|
|
@ -1,55 +0,0 @@
|
||||||
diff -up sudo-1.8.14b3/plugins/sudoers/ldap.c.ldapconfpatch sudo-1.8.14b3/plugins/sudoers/ldap.c
|
|
||||||
--- sudo-1.8.14b3/plugins/sudoers/ldap.c.ldapconfpatch 2015-07-07 18:51:11.000000000 +0200
|
|
||||||
+++ sudo-1.8.14b3/plugins/sudoers/ldap.c 2015-07-09 11:03:25.686645581 +0200
|
|
||||||
@@ -1922,6 +1922,33 @@ sudo_check_krb5_ccname(const char *ccnam
|
|
||||||
}
|
|
||||||
#endif /* HAVE_LDAP_SASL_INTERACTIVE_BIND_S */
|
|
||||||
|
|
||||||
+/*
|
|
||||||
+ * Read a line of input, remove whole line comments and strip off leading
|
|
||||||
+ * and trailing spaces. Returns static storage that is reused.
|
|
||||||
+ */
|
|
||||||
+static char *
|
|
||||||
+sudo_ldap_parseln(fp)
|
|
||||||
+ FILE *fp;
|
|
||||||
+{
|
|
||||||
+ size_t len;
|
|
||||||
+ char *cp = NULL;
|
|
||||||
+ static char buf[LINE_MAX];
|
|
||||||
+
|
|
||||||
+ if (fgets(buf, sizeof(buf), fp) != NULL) {
|
|
||||||
+ /* Remove comments */
|
|
||||||
+ if (*buf == '#')
|
|
||||||
+ *buf = '\0';
|
|
||||||
+
|
|
||||||
+ /* Trim leading and trailing whitespace/newline */
|
|
||||||
+ len = strlen(buf);
|
|
||||||
+ while (len > 0 && isspace((unsigned char)buf[len - 1]))
|
|
||||||
+ buf[--len] = '\0';
|
|
||||||
+ for (cp = buf; isblank(*cp); cp++)
|
|
||||||
+ continue;
|
|
||||||
+ }
|
|
||||||
+ return(cp);
|
|
||||||
+}
|
|
||||||
+
|
|
||||||
static bool
|
|
||||||
sudo_ldap_read_config(void)
|
|
||||||
{
|
|
||||||
@@ -1955,7 +1982,7 @@ sudo_ldap_read_config(void)
|
|
||||||
if ((fp = fopen(path_ldap_conf, "r")) == NULL)
|
|
||||||
debug_return_bool(false);
|
|
||||||
|
|
||||||
- while (sudo_parseln(&line, &linesize, NULL, fp) != -1) {
|
|
||||||
+ while ((line = sudo_ldap_parseln(fp)) != NULL) {
|
|
||||||
if (*line == '\0')
|
|
||||||
continue; /* skip empty line */
|
|
||||||
|
|
||||||
@@ -1975,7 +2002,7 @@ sudo_ldap_read_config(void)
|
|
||||||
if (!sudo_ldap_parse_keyword(keyword, value, ldap_conf_global))
|
|
||||||
sudo_ldap_parse_keyword(keyword, value, ldap_conf_conn);
|
|
||||||
}
|
|
||||||
- free(line);
|
|
||||||
+
|
|
||||||
fclose(fp);
|
|
||||||
|
|
||||||
if (!ldap_conf.host) {
|
|
||||||
|
|
@ -1,122 +0,0 @@
|
||||||
diff -up ./lib/util/strsplit.c.initialization ./lib/util/strsplit.c
|
|
||||||
--- ./lib/util/strsplit.c.initialization 2015-07-22 14:22:49.000000000 +0200
|
|
||||||
+++ ./lib/util/strsplit.c 2015-08-18 13:28:28.141319501 +0200
|
|
||||||
@@ -37,6 +37,10 @@ sudo_strsplit_v1(const char *str, const
|
|
||||||
const char *cp, *s;
|
|
||||||
debug_decl(sudo_strsplit, SUDO_DEBUG_UTIL)
|
|
||||||
|
|
||||||
+ /* exclusion of two NULLs at the same time */
|
|
||||||
+ if (str == NULL && *last == NULL)
|
|
||||||
+ debug_return_ptr(NULL);
|
|
||||||
+
|
|
||||||
/* If no str specified, use last ptr (if any). */
|
|
||||||
if (str == NULL)
|
|
||||||
str = *last;
|
|
||||||
diff -up ./lib/util/sudo_conf.c.initialization ./lib/util/sudo_conf.c
|
|
||||||
--- ./lib/util/sudo_conf.c.initialization 2015-07-22 14:22:49.000000000 +0200
|
|
||||||
+++ ./lib/util/sudo_conf.c 2015-08-18 13:28:28.142319494 +0200
|
|
||||||
@@ -161,7 +161,7 @@ static int
|
|
||||||
parse_path(const char *entry, const char *conf_file, unsigned int lineno)
|
|
||||||
{
|
|
||||||
const char *entry_end = entry + strlen(entry);
|
|
||||||
- const char *ep, *name, *path;
|
|
||||||
+ const char *ep = NULL, *name, *path;
|
|
||||||
struct sudo_conf_path_table *cur;
|
|
||||||
size_t namelen;
|
|
||||||
debug_decl(parse_path, SUDO_DEBUG_UTIL)
|
|
||||||
@@ -208,7 +208,7 @@ parse_debug(const char *entry, const cha
|
|
||||||
{
|
|
||||||
struct sudo_conf_debug *debug_spec;
|
|
||||||
struct sudo_debug_file *debug_file = NULL;
|
|
||||||
- const char *ep, *path, *progname, *flags;
|
|
||||||
+ const char *ep = NULL, *path, *progname, *flags;
|
|
||||||
const char *entry_end = entry + strlen(entry);
|
|
||||||
size_t pathlen, prognamelen;
|
|
||||||
debug_decl(parse_debug, SUDO_DEBUG_UTIL)
|
|
||||||
@@ -278,7 +278,7 @@ static int
|
|
||||||
parse_plugin(const char *entry, const char *conf_file, unsigned int lineno)
|
|
||||||
{
|
|
||||||
struct plugin_info *info = NULL;
|
|
||||||
- const char *ep, *path, *symbol;
|
|
||||||
+ const char *ep = NULL, *path, *symbol;
|
|
||||||
const char *entry_end = entry + strlen(entry);
|
|
||||||
char **options = NULL;
|
|
||||||
size_t pathlen, symlen;
|
|
||||||
diff -up ./plugins/sudoers/editor.c.initialization ./plugins/sudoers/editor.c
|
|
||||||
--- ./plugins/sudoers/editor.c.initialization 2015-07-22 14:22:49.000000000 +0200
|
|
||||||
+++ ./plugins/sudoers/editor.c 2015-08-18 13:28:28.142319494 +0200
|
|
||||||
@@ -45,7 +45,7 @@ resolve_editor(const char *ed, size_t ed
|
|
||||||
int *argc_out, char ***argv_out, char * const *whitelist)
|
|
||||||
{
|
|
||||||
char **nargv, *editor, *editor_path = NULL;
|
|
||||||
- const char *cp, *ep, *tmp;
|
|
||||||
+ const char *cp, *ep = NULL, *tmp;
|
|
||||||
const char *edend = ed + edlen;
|
|
||||||
struct stat user_editor_sb;
|
|
||||||
int nargc;
|
|
||||||
diff -up ./plugins/sudoers/interfaces.c.initialization ./plugins/sudoers/interfaces.c
|
|
||||||
--- ./plugins/sudoers/interfaces.c.initialization 2015-07-22 14:22:50.000000000 +0200
|
|
||||||
+++ ./plugins/sudoers/interfaces.c 2015-08-18 13:28:28.142319494 +0200
|
|
||||||
@@ -109,7 +109,7 @@ get_interfaces(void)
|
|
||||||
void
|
|
||||||
dump_interfaces(const char *ai)
|
|
||||||
{
|
|
||||||
- const char *cp, *ep;
|
|
||||||
+ const char *cp, *ep = NULL;
|
|
||||||
const char *ai_end = ai + strlen(ai);
|
|
||||||
debug_decl(set_interfaces, SUDOERS_DEBUG_NETIF)
|
|
||||||
|
|
||||||
diff -up ./plugins/sudoers/sudoers.c.initialization ./plugins/sudoers/sudoers.c
|
|
||||||
--- ./plugins/sudoers/sudoers.c.initialization 2015-07-22 14:22:50.000000000 +0200
|
|
||||||
+++ ./plugins/sudoers/sudoers.c 2015-08-18 13:28:28.142319494 +0200
|
|
||||||
@@ -1186,7 +1186,7 @@ sudoers_cleanup(void)
|
|
||||||
static char *
|
|
||||||
find_editor(int nfiles, char **files, int *argc_out, char ***argv_out)
|
|
||||||
{
|
|
||||||
- const char *cp, *ep, *editor = NULL;
|
|
||||||
+ const char *cp, *ep = NULL, *editor = NULL;
|
|
||||||
char *editor_path = NULL, **ev, *ev0[4];
|
|
||||||
debug_decl(find_editor, SUDOERS_DEBUG_PLUGIN)
|
|
||||||
|
|
||||||
diff -up ./plugins/sudoers/sudoreplay.c.initialization ./plugins/sudoers/sudoreplay.c
|
|
||||||
--- ./plugins/sudoers/sudoreplay.c.initialization 2015-07-22 14:22:49.000000000 +0200
|
|
||||||
+++ ./plugins/sudoers/sudoreplay.c 2015-08-18 13:39:53.776411920 +0200
|
|
||||||
@@ -189,7 +189,7 @@ main(int argc, char *argv[])
|
|
||||||
int ch, idx, plen, exitcode = 0, rows = 0, cols = 0;
|
|
||||||
bool def_filter = true, listonly = false;
|
|
||||||
const char *decimal, *id, *user = NULL, *pattern = NULL, *tty = NULL;
|
|
||||||
- char *cp, *ep, path[PATH_MAX];
|
|
||||||
+ char *cp, *ep = NULL, path[PATH_MAX];
|
|
||||||
struct log_info *li;
|
|
||||||
double max_wait = 0;
|
|
||||||
debug_decl(main, SUDO_DEBUG_MAIN)
|
|
||||||
@@ -225,6 +225,8 @@ main(int argc, char *argv[])
|
|
||||||
/* Set the replay filter. */
|
|
||||||
def_filter = false;
|
|
||||||
for (cp = strtok_r(optarg, ",", &ep); cp; cp = strtok_r(NULL, ",", &ep)) {
|
|
||||||
+ if (ep == NULL)
|
|
||||||
+ sudo_fatalx(U_("invalid filter option: %s"), optarg);
|
|
||||||
if (strcmp(cp, "stdout") == 0)
|
|
||||||
io_log_files[IOFD_STDOUT].enabled = true;
|
|
||||||
else if (strcmp(cp, "stderr") == 0)
|
|
||||||
diff -up ./plugins/sudoers/visudo.c.initialization ./plugins/sudoers/visudo.c
|
|
||||||
--- ./plugins/sudoers/visudo.c.initialization 2015-07-22 14:22:50.000000000 +0200
|
|
||||||
+++ ./plugins/sudoers/visudo.c 2015-08-18 13:28:28.142319494 +0200
|
|
||||||
@@ -287,7 +287,7 @@ get_editor(int *editor_argc, char ***edi
|
|
||||||
|
|
||||||
/* Build up editor whitelist from def_editor unless env_editor is set. */
|
|
||||||
if (!def_env_editor) {
|
|
||||||
- const char *cp, *ep;
|
|
||||||
+ const char *cp, *ep = NULL;
|
|
||||||
const char *def_editor_end = def_editor + strlen(def_editor);
|
|
||||||
|
|
||||||
/* Count number of entries in whitelist and split into a list. */
|
|
||||||
@@ -325,7 +325,7 @@ get_editor(int *editor_argc, char ***edi
|
|
||||||
if (editor_path == NULL) {
|
|
||||||
/* def_editor could be a path, split it up, avoiding strtok() */
|
|
||||||
const char *def_editor_end = def_editor + strlen(def_editor);
|
|
||||||
- const char *cp, *ep;
|
|
||||||
+ const char *cp, *ep = NULL;
|
|
||||||
for (cp = sudo_strsplit(def_editor, def_editor_end, ":", &ep);
|
|
||||||
cp != NULL; cp = sudo_strsplit(NULL, def_editor_end, ":", &ep)) {
|
|
||||||
editor_path = resolve_editor(cp, (size_t)(ep - cp), 2, files,
|
|
||||||
|
|
@ -1,60 +0,0 @@
|
||||||
diff -up sudo-1.8.8/plugins/sudoers/auth/pam.c.clangbugs sudo-1.8.8/plugins/sudoers/auth/pam.c
|
|
||||||
--- sudo-1.8.8/plugins/sudoers/auth/pam.c.clangbugs 2013-09-30 23:41:07.899529555 +0200
|
|
||||||
+++ sudo-1.8.8/plugins/sudoers/auth/pam.c 2013-09-30 23:41:58.988707761 +0200
|
|
||||||
@@ -246,6 +246,7 @@ sudo_pam_begin_session(struct passwd *pw
|
|
||||||
(void) pam_end(pamh, *pam_status | PAM_DATA_SILENT);
|
|
||||||
pamh = NULL;
|
|
||||||
status = AUTH_FAILURE;
|
|
||||||
+ goto done;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
diff -up sudo-1.8.8/plugins/sudoers/sssd.c.clangbugs sudo-1.8.8/plugins/sudoers/sssd.c
|
|
||||||
--- sudo-1.8.8/plugins/sudoers/sssd.c.clangbugs 2013-09-30 23:44:20.404200629 +0200
|
|
||||||
+++ sudo-1.8.8/plugins/sudoers/sssd.c 2013-09-30 23:49:05.998194738 +0200
|
|
||||||
@@ -310,11 +310,10 @@ static int sudo_sss_close(struct sudo_ns
|
|
||||||
debug_decl(sudo_sss_close, SUDO_DEBUG_SSSD);
|
|
||||||
|
|
||||||
if (nss && nss->handle) {
|
|
||||||
- handle = nss->handle;
|
|
||||||
- dlclose(handle->ssslib);
|
|
||||||
+ handle = nss->handle;
|
|
||||||
+ dlclose(handle->ssslib);
|
|
||||||
+ efree(nss->handle);
|
|
||||||
}
|
|
||||||
-
|
|
||||||
- efree(nss->handle);
|
|
||||||
debug_return_int(0);
|
|
||||||
}
|
|
||||||
|
|
||||||
@@ -705,17 +704,21 @@ sudo_sss_result_get(struct sudo_nss *nss
|
|
||||||
sudo_sss_result_filterp, _SUDO_SSS_FILTER_INCLUDE, NULL);
|
|
||||||
|
|
||||||
if (f_sss_result != NULL) {
|
|
||||||
- if (f_sss_result->num_rules > 0) {
|
|
||||||
- if (state != NULL) {
|
|
||||||
- sudo_debug_printf(SUDO_DEBUG_DEBUG, "state |= HOSTMATCH");
|
|
||||||
- *state |= _SUDO_SSS_STATE_HOSTMATCH;
|
|
||||||
+ if (f_sss_result->num_rules > 0) {
|
|
||||||
+ if (state != NULL) {
|
|
||||||
+ sudo_debug_printf(SUDO_DEBUG_DEBUG, "state |= HOSTMATCH");
|
|
||||||
+ *state |= _SUDO_SSS_STATE_HOSTMATCH;
|
|
||||||
+ }
|
|
||||||
}
|
|
||||||
- }
|
|
||||||
- }
|
|
||||||
|
|
||||||
- sudo_debug_printf(SUDO_DEBUG_DEBUG,
|
|
||||||
- "u_sss_result=(%p, %u) => f_sss_result=(%p, %u)", u_sss_result,
|
|
||||||
- u_sss_result->num_rules, f_sss_result, f_sss_result->num_rules);
|
|
||||||
+ sudo_debug_printf(SUDO_DEBUG_DEBUG,
|
|
||||||
+ "u_sss_result=(%p, %u) => f_sss_result=(%p, %u)", u_sss_result,
|
|
||||||
+ u_sss_result->num_rules, f_sss_result, f_sss_result->num_rules);
|
|
||||||
+ } else {
|
|
||||||
+ sudo_debug_printf(SUDO_DEBUG_DEBUG,
|
|
||||||
+ "u_sss_result=(%p, %u) => f_sss_result=NULL",
|
|
||||||
+ u_sss_result, u_sss_result->num_rules);
|
|
||||||
+ }
|
|
||||||
|
|
||||||
handle->fn_free_result(u_sss_result);
|
|
||||||
|
|
||||||
|
|
@ -1,119 +0,0 @@
|
||||||
diff -up sudo-1.8.8/plugins/sudoers/sssd.c.sssdfixes sudo-1.8.8/plugins/sudoers/sssd.c
|
|
||||||
--- sudo-1.8.8/plugins/sudoers/sssd.c.sssdfixes 2013-09-30 23:18:49.641913457 +0200
|
|
||||||
+++ sudo-1.8.8/plugins/sudoers/sssd.c 2013-09-30 23:25:54.819376696 +0200
|
|
||||||
@@ -534,30 +534,31 @@ sudo_sss_check_runas_group(struct sudo_s
|
|
||||||
* Walk through search results and return true if we have a runas match,
|
|
||||||
* else false. RunAs info is optional.
|
|
||||||
*/
|
|
||||||
-static int
|
|
||||||
+static bool
|
|
||||||
sudo_sss_check_runas(struct sudo_sss_handle *handle, struct sss_sudo_rule *rule)
|
|
||||||
{
|
|
||||||
- int ret;
|
|
||||||
+ bool ret;
|
|
||||||
debug_decl(sudo_sss_check_runas, SUDO_DEBUG_SSSD);
|
|
||||||
|
|
||||||
if (rule == NULL)
|
|
||||||
- debug_return_int(false);
|
|
||||||
+ debug_return_bool(false);
|
|
||||||
|
|
||||||
ret = sudo_sss_check_runas_user(handle, rule) != false &&
|
|
||||||
sudo_sss_check_runas_group(handle, rule) != false;
|
|
||||||
|
|
||||||
- debug_return_int(ret);
|
|
||||||
+ debug_return_bool(ret);
|
|
||||||
}
|
|
||||||
|
|
||||||
-static int
|
|
||||||
+static bool
|
|
||||||
sudo_sss_check_host(struct sudo_sss_handle *handle, struct sss_sudo_rule *rule)
|
|
||||||
{
|
|
||||||
char **val_array, *val;
|
|
||||||
- int ret = false, i;
|
|
||||||
+ bool ret = false;
|
|
||||||
+ int i;
|
|
||||||
debug_decl(sudo_sss_check_host, SUDO_DEBUG_SSSD);
|
|
||||||
|
|
||||||
if (rule == NULL)
|
|
||||||
- debug_return_int(ret);
|
|
||||||
+ debug_return_bool(ret);
|
|
||||||
|
|
||||||
/* get the values from the rule */
|
|
||||||
switch (handle->fn_get_values(rule, "sudoHost", &val_array))
|
|
||||||
@@ -566,10 +567,10 @@ sudo_sss_check_host(struct sudo_sss_hand
|
|
||||||
break;
|
|
||||||
case ENOENT:
|
|
||||||
sudo_debug_printf(SUDO_DEBUG_INFO, "No result.");
|
|
||||||
- debug_return_int(false);
|
|
||||||
+ debug_return_bool(false);
|
|
||||||
default:
|
|
||||||
sudo_debug_printf(SUDO_DEBUG_INFO, "handle->fn_get_values(sudoHost): != 0");
|
|
||||||
- debug_return_int(ret);
|
|
||||||
+ debug_return_bool(ret);
|
|
||||||
}
|
|
||||||
|
|
||||||
/* walk through values */
|
|
||||||
@@ -589,7 +590,52 @@ sudo_sss_check_host(struct sudo_sss_hand
|
|
||||||
|
|
||||||
handle->fn_free_values(val_array);
|
|
||||||
|
|
||||||
- debug_return_int(ret);
|
|
||||||
+ debug_return_bool(ret);
|
|
||||||
+}
|
|
||||||
+
|
|
||||||
+/*
|
|
||||||
+ * Look for netgroup specifcations in the sudoUser attribute and
|
|
||||||
+ * if found, filter according to netgroup membership.
|
|
||||||
+ * returns:
|
|
||||||
+ * true -> netgroup spec found && negroup member
|
|
||||||
+ * false -> netgroup spec found && not a meber of netgroup
|
|
||||||
+ * true -> netgroup spec not found (filtered by SSSD already, netgroups are an exception)
|
|
||||||
+ */
|
|
||||||
+bool sudo_sss_filter_user_netgroup(struct sudo_sss_handle *handle, struct sss_sudo_rule *rule)
|
|
||||||
+{
|
|
||||||
+ bool ret = false, netgroup_spec_found = false;
|
|
||||||
+ char **val_array, *val;
|
|
||||||
+ int i;
|
|
||||||
+ debug_decl(sudo_sss_check_user_netgroup, SUDO_DEBUG_SSSD);
|
|
||||||
+
|
|
||||||
+ if (!handle || !rule)
|
|
||||||
+ debug_return_bool(ret);
|
|
||||||
+
|
|
||||||
+ switch (handle->fn_get_values(rule, "sudoUser", &val_array)) {
|
|
||||||
+ case 0:
|
|
||||||
+ break;
|
|
||||||
+ case ENOENT:
|
|
||||||
+ sudo_debug_printf(SUDO_DEBUG_INFO, "No result.");
|
|
||||||
+ debug_return_bool(ret);
|
|
||||||
+ default:
|
|
||||||
+ sudo_debug_printf(SUDO_DEBUG_INFO, "handle->fn_get_values(sudoUser): != 0");
|
|
||||||
+ debug_return_bool(ret);
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
+ for (i = 0; val_array[i] != NULL && !ret; ++i) {
|
|
||||||
+ val = val_array[i];
|
|
||||||
+ if (*val == '+') {
|
|
||||||
+ netgroup_spec_found = true;
|
|
||||||
+ }
|
|
||||||
+ sudo_debug_printf(SUDO_DEBUG_DEBUG, "val[%d]=%s", i, val);
|
|
||||||
+ if (strcmp(val, "ALL") == 0 || netgr_matches(val, NULL, NULL, user_name)) {
|
|
||||||
+ ret = true;
|
|
||||||
+ sudo_debug_printf(SUDO_DEBUG_DIAG,
|
|
||||||
+ "sssd/ldap sudoUser '%s' ... MATCH! (%s)", val, user_name);
|
|
||||||
+ }
|
|
||||||
+ }
|
|
||||||
+ handle->fn_free_values(val_array);
|
|
||||||
+ debug_return_bool(netgroup_spec_found ? ret : true);
|
|
||||||
}
|
|
||||||
|
|
||||||
static int
|
|
||||||
@@ -599,7 +645,8 @@ sudo_sss_result_filterp(struct sudo_sss_
|
|
||||||
(void)unused;
|
|
||||||
debug_decl(sudo_sss_result_filterp, SUDO_DEBUG_SSSD);
|
|
||||||
|
|
||||||
- if (sudo_sss_check_host(handle, rule))
|
|
||||||
+ if (sudo_sss_check_host(handle, rule) &&
|
|
||||||
+ sudo_sss_filter_user_netgroup(handle, rule))
|
|
||||||
debug_return_int(1);
|
|
||||||
else
|
|
||||||
debug_return_int(0);
|
|
||||||
|
|
@ -1,53 +0,0 @@
|
||||||
diff -up sudo-1.8.8/plugins/sudoers/match.c.strictuidgid sudo-1.8.8/plugins/sudoers/match.c
|
|
||||||
--- sudo-1.8.8/plugins/sudoers/match.c.strictuidgid 2013-09-30 23:30:12.359263967 +0200
|
|
||||||
+++ sudo-1.8.8/plugins/sudoers/match.c 2013-09-30 23:31:04.335443002 +0200
|
|
||||||
@@ -777,14 +777,16 @@ hostname_matches(char *shost, char *lhos
|
|
||||||
bool
|
|
||||||
userpw_matches(char *sudoers_user, char *user, struct passwd *pw)
|
|
||||||
{
|
|
||||||
- debug_decl(userpw_matches, SUDO_DEBUG_MATCH)
|
|
||||||
-
|
|
||||||
- if (pw != NULL && *sudoers_user == '#') {
|
|
||||||
- uid_t uid = (uid_t) atoi(sudoers_user + 1);
|
|
||||||
- if (uid == pw->pw_uid)
|
|
||||||
- debug_return_bool(true);
|
|
||||||
- }
|
|
||||||
- debug_return_bool(strcmp(sudoers_user, user) == 0);
|
|
||||||
+ debug_decl(userpw_matches, SUDO_DEBUG_MATCH)
|
|
||||||
+ if (pw != NULL && *sudoers_user == '#') {
|
|
||||||
+ char *end = NULL;
|
|
||||||
+ uid_t uid = (uid_t) strtol(sudoers_user + 1, &end, 10);
|
|
||||||
+ if (end != NULL && (sudoers_user[1] != '\0' && *end == '\0')) {
|
|
||||||
+ if (uid == pw->pw_uid)
|
|
||||||
+ debug_return_bool(true);
|
|
||||||
+ }
|
|
||||||
+ }
|
|
||||||
+ debug_return_bool(strcmp(sudoers_user, user) == 0);
|
|
||||||
}
|
|
||||||
|
|
||||||
/*
|
|
||||||
@@ -794,14 +796,16 @@ userpw_matches(char *sudoers_user, char
|
|
||||||
bool
|
|
||||||
group_matches(char *sudoers_group, struct group *gr)
|
|
||||||
{
|
|
||||||
- debug_decl(group_matches, SUDO_DEBUG_MATCH)
|
|
||||||
-
|
|
||||||
- if (*sudoers_group == '#') {
|
|
||||||
- gid_t gid = (gid_t) atoi(sudoers_group + 1);
|
|
||||||
- if (gid == gr->gr_gid)
|
|
||||||
- debug_return_bool(true);
|
|
||||||
- }
|
|
||||||
- debug_return_bool(strcmp(gr->gr_name, sudoers_group) == 0);
|
|
||||||
+ debug_decl(group_matches, SUDO_DEBUG_MATCH)
|
|
||||||
+ if (*sudoers_group == '#') {
|
|
||||||
+ char *end = NULL;
|
|
||||||
+ gid_t gid = (gid_t) strtol(sudoers_group + 1, &end, 10);
|
|
||||||
+ if (end != NULL && (sudoers_group[1] != '\0' && *end == '\0')) {
|
|
||||||
+ if (gid == gr->gr_gid)
|
|
||||||
+ debug_return_bool(true);
|
|
||||||
+ }
|
|
||||||
+ }
|
|
||||||
+ debug_return_bool(strcmp(gr->gr_name, sudoers_group) == 0);
|
|
||||||
}
|
|
||||||
|
|
||||||
/*
|
|
||||||
74
sudo.spec
74
sudo.spec
|
|
@ -1,12 +1,12 @@
|
||||||
Summary: Allows restricted root access for specified users
|
Summary: Allows restricted root access for specified users
|
||||||
Name: sudo
|
Name: sudo
|
||||||
Version: 1.8.15
|
Version: 1.8.20p2
|
||||||
Release: 2%{?dist}
|
Release: 1%{?dist}
|
||||||
License: ISC
|
License: ISC
|
||||||
Group: Applications/System
|
Group: Applications/System
|
||||||
URL: http://www.courtesan.com/sudo/
|
URL: https://www.sudo.ws/
|
||||||
Source0: http://www.courtesan.com/sudo/dist/sudo-%{version}.tar.gz
|
Source0: https://www.sudo.ws/dist/%{name}-%{version}.tar.gz
|
||||||
Source1: sudo-1.8.8-sudoers
|
Source1: sudoers
|
||||||
Buildroot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n)
|
Buildroot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n)
|
||||||
Requires: /etc/pam.d/system-auth
|
Requires: /etc/pam.d/system-auth
|
||||||
Requires: /usr/bin/vi
|
Requires: /usr/bin/vi
|
||||||
|
|
@ -26,12 +26,6 @@ BuildRequires: zlib-devel
|
||||||
|
|
||||||
# don't strip
|
# don't strip
|
||||||
Patch1: sudo-1.6.7p5-strip.patch
|
Patch1: sudo-1.6.7p5-strip.patch
|
||||||
# Patch to read ldap.conf more closely to nss_ldap
|
|
||||||
Patch2: sudo-1.8.14p1-ldapconfpatch.patch
|
|
||||||
# Patch makes changes in documentation bz:1162070
|
|
||||||
Patch3: sudo-1.8.14p1-docpassexpire.patch
|
|
||||||
# Patch initialize variable before executing sudo_strsplit
|
|
||||||
Patch4: sudo-1.8.14p3-initialization.patch
|
|
||||||
|
|
||||||
%description
|
%description
|
||||||
Sudo (superuser do) allows a system administrator to give certain
|
Sudo (superuser do) allows a system administrator to give certain
|
||||||
|
|
@ -57,9 +51,6 @@ plugins that use %{name}.
|
||||||
%setup -q
|
%setup -q
|
||||||
|
|
||||||
%patch1 -p1 -b .strip
|
%patch1 -p1 -b .strip
|
||||||
%patch2 -p1 -b .ldapconfpatch
|
|
||||||
%patch3 -p1 -b .docpassexpire
|
|
||||||
%patch4 -p1 -b .initialization
|
|
||||||
|
|
||||||
%build
|
%build
|
||||||
# Remove bundled copy of zlib
|
# Remove bundled copy of zlib
|
||||||
|
|
@ -79,6 +70,7 @@ export CFLAGS="$RPM_OPT_FLAGS $F_PIE" LDFLAGS="-pie -Wl,-z,relro -Wl,-z,now"
|
||||||
--sbindir=%{_sbindir} \
|
--sbindir=%{_sbindir} \
|
||||||
--libdir=%{_libdir} \
|
--libdir=%{_libdir} \
|
||||||
--docdir=%{_pkgdocdir} \
|
--docdir=%{_pkgdocdir} \
|
||||||
|
--disable-root-mailer \
|
||||||
--with-logging=syslog \
|
--with-logging=syslog \
|
||||||
--with-logfac=authpriv \
|
--with-logfac=authpriv \
|
||||||
--with-pam \
|
--with-pam \
|
||||||
|
|
@ -105,8 +97,15 @@ make install DESTDIR="$RPM_BUILD_ROOT" install_uid=`id -u` install_gid=`id -g` s
|
||||||
|
|
||||||
chmod 755 $RPM_BUILD_ROOT%{_bindir}/* $RPM_BUILD_ROOT%{_sbindir}/*
|
chmod 755 $RPM_BUILD_ROOT%{_bindir}/* $RPM_BUILD_ROOT%{_sbindir}/*
|
||||||
install -p -d -m 700 $RPM_BUILD_ROOT/var/db/sudo
|
install -p -d -m 700 $RPM_BUILD_ROOT/var/db/sudo
|
||||||
|
install -p -d -m 700 $RPM_BUILD_ROOT/var/db/sudo/lectured
|
||||||
install -p -d -m 750 $RPM_BUILD_ROOT/etc/sudoers.d
|
install -p -d -m 750 $RPM_BUILD_ROOT/etc/sudoers.d
|
||||||
install -p -c -m 0440 %{SOURCE1} $RPM_BUILD_ROOT/etc/sudoers
|
install -p -c -m 0440 %{SOURCE1} $RPM_BUILD_ROOT/etc/sudoers
|
||||||
|
#add sudo to protected packages
|
||||||
|
install -p -d -m 755 $RPM_BUILD_ROOT/etc/yum/protected.d/
|
||||||
|
touch sudo.conf
|
||||||
|
echo sudo > sudo.conf
|
||||||
|
install -p -c -m 0644 sudo.conf $RPM_BUILD_ROOT/etc/yum/protected.d/
|
||||||
|
rm -f sudo.conf
|
||||||
|
|
||||||
chmod +x $RPM_BUILD_ROOT%{_libexecdir}/sudo/*.so # for stripping, reset in %%files
|
chmod +x $RPM_BUILD_ROOT%{_libexecdir}/sudo/*.so # for stripping, reset in %%files
|
||||||
|
|
||||||
|
|
@ -122,6 +121,9 @@ rm -rf $RPM_BUILD_ROOT%{_datadir}/examples/sudo
|
||||||
#Remove all .la files
|
#Remove all .la files
|
||||||
find $RPM_BUILD_ROOT -name '*.la' -exec rm -f {} ';'
|
find $RPM_BUILD_ROOT -name '*.la' -exec rm -f {} ';'
|
||||||
|
|
||||||
|
# Remove sudoers.dist
|
||||||
|
rm -f $RPM_BUILD_ROOT%{_sysconfdir}/sudoers.dist
|
||||||
|
|
||||||
%find_lang sudo
|
%find_lang sudo
|
||||||
%find_lang sudoers
|
%find_lang sudoers
|
||||||
|
|
||||||
|
|
@ -159,7 +161,9 @@ rm -rf $RPM_BUILD_ROOT
|
||||||
%config(noreplace) /etc/pam.d/sudo
|
%config(noreplace) /etc/pam.d/sudo
|
||||||
%config(noreplace) /etc/pam.d/sudo-i
|
%config(noreplace) /etc/pam.d/sudo-i
|
||||||
%attr(0644,root,root) %{_tmpfilesdir}/sudo.conf
|
%attr(0644,root,root) %{_tmpfilesdir}/sudo.conf
|
||||||
|
%attr(0644,root,root) /etc/yum/protected.d/sudo.conf
|
||||||
%dir /var/db/sudo
|
%dir /var/db/sudo
|
||||||
|
%dir /var/db/sudo/lectured
|
||||||
%attr(4111,root,root) %{_bindir}/sudo
|
%attr(4111,root,root) %{_bindir}/sudo
|
||||||
%{_bindir}/sudoedit
|
%{_bindir}/sudoedit
|
||||||
%attr(0111,root,root) %{_bindir}/sudoreplay
|
%attr(0111,root,root) %{_bindir}/sudoreplay
|
||||||
|
|
@ -198,6 +202,48 @@ rm -rf $RPM_BUILD_ROOT
|
||||||
%{_libexecdir}/sudo/libsudo_util.so
|
%{_libexecdir}/sudo/libsudo_util.so
|
||||||
|
|
||||||
%changelog
|
%changelog
|
||||||
|
* Thu Jun 01 2017 Daniel Kopecek <dkopecek@redhat.com> 1.8.20p2-1
|
||||||
|
- update to 1.8.20p2
|
||||||
|
- added sudo to dnf/yum protected packages
|
||||||
|
|
||||||
|
* Wed May 31 2017 Daniel Kopecek <dkopecek@redhat.com> 1.8.20p1-1
|
||||||
|
- update to 1.8.20p1
|
||||||
|
- fixes CVE-2017-1000367
|
||||||
|
Resolves: rhbz#1456884
|
||||||
|
|
||||||
|
* Mon Apr 03 2017 Jiri Vymazal <jvymazal@redhat.com> 1.8.19p2-1
|
||||||
|
- update to 1.8.19p2
|
||||||
|
- updated URL and source0 as upstream changed domain
|
||||||
|
|
||||||
|
* Tue Nov 08 2016 Daniel Kopecek <dkopecek@redhat.com> 1.8.18p1-1
|
||||||
|
- update to 1.8.18p1
|
||||||
|
- fixes CVE-2016-7076
|
||||||
|
|
||||||
|
* Wed Sep 21 2016 Radovan Sroka <rsroka@redhat.com> 1.8.18-1
|
||||||
|
- update to 1.8.18
|
||||||
|
- dropped sudo-1.8.14p1-ldapconfpatch.patch
|
||||||
|
upstreamed --> https://www.sudo.ws/pipermail/sudo-workers/2016-September/001006.html
|
||||||
|
- added --disable-root-mailer as configure option
|
||||||
|
Resolves: rhbz#1324091
|
||||||
|
|
||||||
|
* Fri Jun 24 2016 Daniel Kopecek <dkopecek@redhat.com> 1.8.17p1-1
|
||||||
|
- update to 1.8.17p1
|
||||||
|
- install the /var/db/sudo/lectured
|
||||||
|
Resolves: rhbz#1321414
|
||||||
|
|
||||||
|
* Tue May 31 2016 Daniel Kopecek <dkopecek@redhat.com> 1.8.16-4
|
||||||
|
- removed INPUTRC from env_keep to prevent a possible info leak
|
||||||
|
Resolves: rhbz#1340701
|
||||||
|
|
||||||
|
* Fri May 13 2016 Daniel Kopecek <dkopecek@redhat.com> 1.8.16-3
|
||||||
|
- fixed upstream patch for rhbz#1335401
|
||||||
|
|
||||||
|
* Thu May 12 2016 Daniel Kopecek <dkopecek@redhat.com> 1.8.16-2
|
||||||
|
- fixed invalid sesh argument array construction
|
||||||
|
|
||||||
|
* Mon Apr 04 2016 Daniel Kopecek <dkopecek@redhat.com> 1.8.16-1
|
||||||
|
- update to 1.8.16
|
||||||
|
|
||||||
* Fri Feb 05 2016 Fedora Release Engineering <releng@fedoraproject.org> - 1.8.15-2
|
* Fri Feb 05 2016 Fedora Release Engineering <releng@fedoraproject.org> - 1.8.15-2
|
||||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild
|
||||||
|
|
||||||
|
|
|
||||||
96
sudoers
Normal file
96
sudoers
Normal file
|
|
@ -0,0 +1,96 @@
|
||||||
|
## Sudoers allows particular users to run various commands as
|
||||||
|
## the root user, without needing the root password.
|
||||||
|
##
|
||||||
|
## Examples are provided at the bottom of the file for collections
|
||||||
|
## of related commands, which can then be delegated out to particular
|
||||||
|
## users or groups.
|
||||||
|
##
|
||||||
|
## This file must be edited with the 'visudo' command.
|
||||||
|
|
||||||
|
## Host Aliases
|
||||||
|
## Groups of machines. You may prefer to use hostnames (perhaps using
|
||||||
|
## wildcards for entire domains) or IP addresses instead.
|
||||||
|
# Host_Alias FILESERVERS = fs1, fs2
|
||||||
|
# Host_Alias MAILSERVERS = smtp, smtp2
|
||||||
|
|
||||||
|
## User Aliases
|
||||||
|
## These aren't often necessary, as you can use regular groups
|
||||||
|
## (ie, from files, LDAP, NIS, etc) in this file - just use %groupname
|
||||||
|
## rather than USERALIAS
|
||||||
|
# User_Alias ADMINS = jsmith, mikem
|
||||||
|
|
||||||
|
|
||||||
|
## Command Aliases
|
||||||
|
## These are groups of related commands...
|
||||||
|
|
||||||
|
## Networking
|
||||||
|
# Cmnd_Alias NETWORKING = /sbin/route, /sbin/ifconfig, /bin/ping, /sbin/dhclient, /usr/bin/net, /sbin/iptables, /usr/bin/rfcomm, /usr/bin/wvdial, /sbin/iwconfig, /sbin/mii-tool
|
||||||
|
|
||||||
|
## Installation and management of software
|
||||||
|
# Cmnd_Alias SOFTWARE = /bin/rpm, /usr/bin/up2date, /usr/bin/yum
|
||||||
|
|
||||||
|
## Services
|
||||||
|
# Cmnd_Alias SERVICES = /sbin/service, /sbin/chkconfig
|
||||||
|
|
||||||
|
## Updating the locate database
|
||||||
|
# Cmnd_Alias LOCATE = /usr/bin/updatedb
|
||||||
|
|
||||||
|
## Storage
|
||||||
|
# Cmnd_Alias STORAGE = /sbin/fdisk, /sbin/sfdisk, /sbin/parted, /sbin/partprobe, /bin/mount, /bin/umount
|
||||||
|
|
||||||
|
## Delegating permissions
|
||||||
|
# Cmnd_Alias DELEGATING = /usr/sbin/visudo, /bin/chown, /bin/chmod, /bin/chgrp
|
||||||
|
|
||||||
|
## Processes
|
||||||
|
# Cmnd_Alias PROCESSES = /bin/nice, /bin/kill, /usr/bin/kill, /usr/bin/killall
|
||||||
|
|
||||||
|
## Drivers
|
||||||
|
# Cmnd_Alias DRIVERS = /sbin/modprobe
|
||||||
|
|
||||||
|
# Defaults specification
|
||||||
|
|
||||||
|
#
|
||||||
|
# Refuse to run if unable to disable echo on the tty.
|
||||||
|
#
|
||||||
|
Defaults !visiblepw
|
||||||
|
|
||||||
|
Defaults env_reset
|
||||||
|
Defaults env_keep = "COLORS DISPLAY HOSTNAME HISTSIZE KDEDIR LS_COLORS"
|
||||||
|
Defaults env_keep += "MAIL PS1 PS2 QTDIR USERNAME LANG LC_ADDRESS LC_CTYPE"
|
||||||
|
Defaults env_keep += "LC_COLLATE LC_IDENTIFICATION LC_MEASUREMENT LC_MESSAGES"
|
||||||
|
Defaults env_keep += "LC_MONETARY LC_NAME LC_NUMERIC LC_PAPER LC_TELEPHONE"
|
||||||
|
Defaults env_keep += "LC_TIME LC_ALL LANGUAGE LINGUAS _XKB_CHARSET XAUTHORITY"
|
||||||
|
|
||||||
|
Defaults secure_path = /sbin:/bin:/usr/sbin:/usr/bin
|
||||||
|
|
||||||
|
## Next comes the main part: which users can run what software on
|
||||||
|
## which machines (the sudoers file can be shared between multiple
|
||||||
|
## systems).
|
||||||
|
## Syntax:
|
||||||
|
##
|
||||||
|
## user MACHINE=COMMANDS
|
||||||
|
##
|
||||||
|
## The COMMANDS section may have other options added to it.
|
||||||
|
##
|
||||||
|
## Allow root to run any commands anywhere
|
||||||
|
root ALL=(ALL) ALL
|
||||||
|
|
||||||
|
## Allows members of the 'sys' group to run networking, software,
|
||||||
|
## service management apps and more.
|
||||||
|
# %sys ALL = NETWORKING, SOFTWARE, SERVICES, STORAGE, DELEGATING, PROCESSES, LOCATE, DRIVERS
|
||||||
|
|
||||||
|
## Allows people in group wheel to run all commands
|
||||||
|
%wheel ALL=(ALL) ALL
|
||||||
|
|
||||||
|
## Same thing without a password
|
||||||
|
# %wheel ALL=(ALL) NOPASSWD: ALL
|
||||||
|
|
||||||
|
## Allows members of the users group to mount and unmount the
|
||||||
|
## cdrom as root
|
||||||
|
# %users ALL=/sbin/mount /mnt/cdrom, /sbin/umount /mnt/cdrom
|
||||||
|
|
||||||
|
## Allows members of the users group to shutdown this system
|
||||||
|
# %users localhost=/sbin/shutdown -h now
|
||||||
|
|
||||||
|
## Read drop-in files from /etc/sudoers.d (the # here does not mean a comment)
|
||||||
|
#includedir /etc/sudoers.d
|
||||||
Loading…
Add table
Add a link
Reference in a new issue