summaryrefslogtreecommitdiff
path: root/security/sudo
AgeCommit message (Collapse)AuthorFilesLines
2001-08-02Mark as USE_BUILDLINK_ONLY.jlam1-1/+2
2001-07-13In package Makefiles, create FILES_SUBST instead of duplicating sedjlam3-12/+40
expression for substituting in DEINSTALL/INSTALL scripts. Use "${CMP} -s" instead of "diff -q" since the former is more portable across OSes.
2001-06-26Remove build time dependency on autoconf by adding a patch for configure.wiz3-9/+72
Fixes pkg/13004.
2001-04-19Move to sha1 digests, add distfile sizes.agc1-1/+2
2001-04-17+ move the distfile digest/checksum value from files/md5 to distinfoagc3-8/+6
+ move the patch digest/checksum values from files/patch-sum to distinfo
2001-04-08upgrade to 1.6.3p7. p6 is no longer available.itojun2-4/+4
416) Fix negation of path-type Defaults entries in a boolean context.
2001-03-27Change BUILD_DEPENDS semantics:hubertf1-2/+2
first component is now a package name+version/pattern, no more executable/patchname/whatnot. While there, introduce BUILD_USES_MSGFMT as shorthand to pull in devel/gettext unless /usr/bin/msgfmt exists (i.e. on post-1.5 -current). Patch by Alistair Crooks <agc@netbsd.org>
2001-03-04turn KERBEROS into a binary switchassar1-11/+4
2001-02-23upgrade to 1.6.3p6. (security fix)itojun2-4/+4
415) Fix word splitting bug that caused a segv for very long command line args.
2001-02-17Update to new COMMENT style: COMMENT var in Makefile instead of pkg/COMMENT.wiz2-2/+2
2001-02-05Use full pathname "${LOCALBASE}/bin/auto..." in dependences and maketron1-3/+3
targets. This includes a fix for PR pkg/12125 by Tomasz Luchowski.
2001-01-29Add automatic ${VARIABLE} handling for MESSAGE files.wiz2-8/+3
Convert most MESSAGE files to new syntax (${VARIABLE} gets replaced, not @VARIABLE@, nor @@VARIABLE@@). By default, substitutions are done for LOCALBASE, PKGNAME, PREFIX, X11BASE, X11PREFIX; additional patterns can be added via MESSAGE_SUBST. Clean up some packages while I'm there; add RCS tags to most MESSAGEs. Remove some uninteresting MESSAGEs.
2000-12-06Look for build dependency in path instead.jlam1-2/+2
2000-12-06* Cosmetic changes to Makefile.jlam5-35/+159
* Use DEINSTALL/INSTALL scripts to handle config files. * Install the UPGRADE file and add a MESSAGE file to refer to it, instead of spewing a big file every time sudo is installed.
2000-12-05Update sudo to 1.6.3p5. Changes from version 1.6.3p4:jlam2-4/+4
* Fixed listpw and verifypw sudoers options. * Do not write NUL when writing passwd prompt.
2000-08-10Don't syslog krb5_init_context() failure. It can happen ifthorpej2-7/+17
Kerberos is simply not configured on the system.
2000-08-10Make this work with Heimdal Kerberos 5. Requires fleshed-out MCCthorpej3-5/+48
support in Heimdal.
2000-08-09Remove a commend/if clause which turns out to not actuallythorpej1-4/+1
be true.
2000-07-26Make it work on Solaris.veego4-5/+13
2000-06-06Update to 1.6.3p4. Notable changes:mjl4-22/+13
393) Users in the 'exempt' group shouldn't get their $PATH overridden by 'secure-path'. Patch from jmknoble@pobox.com. 395) Fixed a bug that caused an infinite loop when the password timeout was disabled. 396) It is now possible to set the path to the editor for visudo as well as the flag that determines whether or not visudo will look at $EDITOR in the sudoers file. 398) Added rootpw, runaspw, and targetpw to prompt for the root, runas_default and target user's passwords respectively (instead of the invoking user's password). 399) Added -S flag to force password read from stdin. 400) Restore coredumpsize resource limit before exec'ing the child process (sudo sets it to 0 internally). 404) Fixed a bug where sudo would hang around and consume CPU if we spawn a long-running process. 406) Added set_logname run-time option. When unset, sudo will not set the USER and LOGNAME environment variables. 407) Wildcards are now allowed in the hostnames specified in sudoers. The 'fqdn' option is often required for this to be useful. 408) Fixed a bug where host and user qualifiers in a Defaults entry were not being used correctly and the entry was being applied globally. 409) Fixed targetpw, rootpw, and runaspw options when used with non-passwd authentication (pam, etc). 410) When the targetpw flag is set, use the target username as part of the timestamp path. 411) Fixed a bug that prevented the -H option from being useful. 412) Fixed a case where a string was used after it has been freed.
2000-02-28Only enable Kerberos 5 support if USE_HEIMDAL is set; sudo uses APIthorpej1-1/+4
features present in Heimdal but NOT present in MIT Kerberos (one more reason to ditch MIT, I guess).
2000-02-27Find krb5 includes/libraries as installed in a crypto-aware NetBSDthorpej2-13/+35
installation. Still doesn't work; MIT Kerberos 5 is missing some calls that sudo wants (tho Heimdal has them).
2000-01-28Update to sudo-1.6.2p1. Changes from 1.6.2 (committed yesterday!):jlam2-5/+7
393) Users in the 'exempt' group shouldn't get their $PATH overridden by 'secure-path'. Patch from jmknoble@pobox.com. 394) Pam now works on HP-UX 11.0, thanks to Jeff A. Earickson.
2000-01-28Update to sudo-1.6.2. This is a bugfix release over sudo-1.6.1.jlam2-4/+4
Changes from Sudo 1.6.1: 383) Better behavior for -l and -v flags in conjunction with NOPASSWD and added "verifypw" and "listpw" options. 384) For HP-UX with cc, add the -Aa flag along with -D_HPUX_SOURCE. 385) Fix compilation with K&R compilers. 386) For netgroup host matching, match against the short version of the hostname as well as the long one if they are different. 387) Terminate passwd reading on '\r' in addition to '\n' 388) Visudo used to loop endlessly if a user entered ^D at the whatnow prompt. EOF is now treaded as 'x' (exit w/o saving changes). 389) The 'shell_noargs' runtime option is back based on a patch from bguillory@email.com. 390) Systems that return RLIM_INFINITY for RLIMIT_NOFILE (like AIX) would loop for a very loing time during sudo startup. A value of RLIM_INFINITY is now ignored (getdtablesize/sysconf is used instead). 391) Locking in visudo was broken. We now lock the sudoers file, not the sudoers temp file, which should be safe. 392) PAM fixups: custom prompts now work correctly and errors are dealt with more sanely. Patches from Cloyce D. Spradling.
2000-01-05Strip trailing '.', and/or leading '(a|an) 'abs1-1/+1
1999-12-30CHANGESjlam7-115/+54
1999-09-14Change how Kerberos support is enabled in pkgsrc.kim1-5/+9
Quick guide for compiling packages: - set KERBEROS=4 or KERBEROS=5 in /etc/mk.conf Quick guide for configuring Kerberos support in a package Makefile: - test for KERBEROS value and enable the appropriate version with CONFIGURE_ARGS or other means and set USE_KERBEROS=yes - make sure to disable Kerberos support otherwise (especially if using configure, which might automatically detect it) - BUILD_DEFS and RESTRICTED are set automatically in bsd.pkg.mk when USE_KERBEROS=yes is set
1999-09-13Got some coffee, feel much better now. Thank you.kim1-3/+3
1999-09-13Add Kerberos V support, record Kerberos options.kim1-1/+7
1999-09-13Use Kerberos IV where appropriate.kim1-5/+10
1999-08-31Update sudo to 1.5.9p4. It's the latest stable security release.jlam10-3526/+63
1999-07-09Add package patch checksum files.agc1-0/+8
1999-05-09Update sudo to 1.5.9p1.frueauf4-1072/+1600
1999-03-30Make this work on Solaris.agc1-2/+16
Substitute ${LOCALBASE} for the hardcoded value in the manual pages.
1999-02-20Fix CONFLICTS (remove redundancy, mostly)hubertf1-3/+1
1998-12-14pkglint: move WRKSRC where it belongs.frueauf1-2/+2
1998-12-13Update sudo to 1.5.7p4.frueauf4-836/+1850
Changes since 1.5.6: - Various bug fixes (not security related). - All compile-time options are now set via options to the configure script. - visudo is now installed in /usr/local/sbin where it belongs. [of course this is ${PREFIX}/sbin in our package for a long time - TF] - two problems with tgetpass() have been fixed. In one case the user was not always given a chance to enter a password. In the other a newline was not always printed after the password was entered on Linux. - Added support for Digital UNIX SIA (Security Integration Architecture). - %groups now work as RunAs specifiers like the man page says. - Sudo now sets the USER environment variable to the target user (root unless -u is specified). - Sudo will print "command not found" unless configure was run with --disable-path-info. Also, tell user when we ignore '.' in their path and it would have been used but for --with-ignore-dot. This means that sudo can be used to gather information about the existence of executable in directories not accessible by a normal user. If this bothers you, run configure with --disable-path-info. [in our package --disable-path-info is default - TF] - A longstanding bug wrt "sudo -l" has been fixed that could cause "sudo -l" to complain about non-existent syntax errors. - When configured with --with-tty-tickets the filename is now "user:tty" (was "user.tty") since a username could have a '.' in it.
1998-09-28Update sudo to 1.5.6p2.frueauf5-41/+1899
1998-08-07Add NetBSD RCS Ids.agc1-0/+2
1998-08-07Add NetBSD RCS Ids.agc5-0/+10
1998-07-01Update to sudo-1.5.4p1.frueauf6-144/+107
1998-06-22Update package Makefiles for automatic manual page handling.agc1-3/+1
1998-04-15Use the bsd.pkg.mk and bsd.pkg.subdir.mk files in the pkgsrc tree.agc1-7/+2
Remove redundant (and sometimes erroneous) comments.
1998-01-24portlint: add RCS Idhubertf1-0/+1
1998-01-24portlint: use command macroshubertf1-2/+2
1997-12-22Fix setting CONFIGURE_ARGS ("=" -> "+=")hubertf1-2/+2
1997-12-14Update for NetBSD, mostly by Soren S. Jorvang <soren@t.dk>hubertf5-27/+24
1997-12-14Import vanialla FreeBSD sudo.hubertf10-0/+257