<feed xmlns='http://www.w3.org/2005/Atom'>
<title>ports/security/sudo, branch 2023Q4</title>
<subtitle>FreeBSD ports tree</subtitle>
<id>https://cgit-dev.freebsd.org/ports/atom?h=2023Q4</id>
<link rel='self' href='https://cgit-dev.freebsd.org/ports/atom?h=2023Q4'/>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/'/>
<updated>2023-12-19T00:27:38Z</updated>
<entry>
<title>security/sudo: Update to 1.9.15p4</title>
<updated>2023-12-19T00:27:38Z</updated>
<author>
<name>Cy Schubert</name>
<email>cy@FreeBSD.org</email>
</author>
<published>2023-12-16T04:26:12Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=adf40a74d09ed97816fec107db15c29a11641770'/>
<id>urn:sha1:adf40a74d09ed97816fec107db15c29a11641770</id>
<content type='text'>
Major changes between sudo 1.9.15p4 and 1.9.15p3:

 * Fixed a bug introduced in sudo 1.9.15 that could prevent a user's
   privileges from being listed by "sudo -l" if the sudoers entry
   in /etc/nsswitch.conf contains "[SUCCESS=return]".  This did not
   affect the ability to run commands via sudo.  Bug #1063.

PR:		275788
Approved by:	garga (maintainer)
MFH:		2023Q4

(cherry picked from commit fb89252c2f3e07499ec865910e9c6645e5f1a13d)
</content>
</entry>
<entry>
<title>security/sudo: Update to 1.9.15p3</title>
<updated>2023-12-14T14:00:00Z</updated>
<author>
<name>Cy Schubert</name>
<email>cy@FreeBSD.org</email>
</author>
<published>2023-12-13T22:50:25Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=82cd9878d19a9ef58caf54e9bcfda16f6b0e0305'/>
<id>urn:sha1:82cd9878d19a9ef58caf54e9bcfda16f6b0e0305</id>
<content type='text'>
Major changes between sudo 1.9.15p3 and 1.9.15p2:

 * Always disable core dumps when sudo sends itself a fatal signal.
   Fixes a problem where sudo could potentially dump core dump when
   it re-sends the fatal signal to itself.  This is only an issue
   if the command received a signal that would normally result in
   a core dump but the command did not actually dump core.

 * Fixed a bug matching a command with a relative path name when
   the sudoers rule uses shell globbing rules for the path name.
   Bug #1062.

 * Permit visudo to be run even if the local host name is not set.
   GitHub issue #332.

 * Fixed an editing error introduced in sudo 1.9.15 that could
   prevent sudoreplay from replaying sessions correctly.
   GitHub issue #334.

 * Fixed a bug introduced in sudo 1.9.15 where "sudo -l &gt; /dev/null"
   could hang on Linux systems.  GitHub issue #335.

 * Fixed a bug introduced in sudo 1.9.15 where Solaris privileges
   specified in sudoers were not applied to the command being run.

PR:		275754
Approved by:	garga (maintainer)

(cherry picked from commit 003e8e2292ca05aadc4c4f03b82207337e644e15)
</content>
</entry>
<entry>
<title>security/sudo: Update to 1.9.15p2</title>
<updated>2023-11-09T18:00:51Z</updated>
<author>
<name>Renato Botelho</name>
<email>garga@FreeBSD.org</email>
</author>
<published>2023-11-09T17:59:38Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=1a1036865348b9e0c9966c167734c5518fc2e1ca'/>
<id>urn:sha1:1a1036865348b9e0c9966c167734c5518fc2e1ca</id>
<content type='text'>
* Fixed a bug on BSD systems where sudo would not restore the
  terminal settings on exit if the terminal had parity enabled.
  GitHub issue #326.

Sponsored by:	Rubicon Communications, LLC ("Netgate")

(cherry picked from commit d4203eed6617d3378821d165d72fbce4aa5cb74c)
</content>
</entry>
<entry>
<title>security/sudo: Update to 1.9.15p1</title>
<updated>2023-11-08T11:19:27Z</updated>
<author>
<name>Renato Botelho</name>
<email>garga@FreeBSD.org</email>
</author>
<published>2023-11-08T11:17:57Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=46adc0bb9791176442ceab70cf765d1af13cdfcc'/>
<id>urn:sha1:46adc0bb9791176442ceab70cf765d1af13cdfcc</id>
<content type='text'>
* Fixed a bug introduced in sudo 1.9.15 that prevented LDAP-based
  sudoers from being able to read the ldap.conf file.
  GitHub issue #325.

PR:		274960
Reported by:	Daniel Porsch &lt;daniel.porsch@loopia.se&gt;
Sponsored by:	Rubicon Communications, LLC ("Netgate")

(cherry picked from commit 2c9adde974c38bfec592ce77ed23aeba0887cc5e)
</content>
</entry>
<entry>
<title>security/sudo: Update to 1.9.15</title>
<updated>2023-11-06T18:13:54Z</updated>
<author>
<name>Renato Botelho</name>
<email>garga@FreeBSD.org</email>
</author>
<published>2023-10-31T13:45:14Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=577cb7aaf28306abca03274ec38d295700b5bc9b'/>
<id>urn:sha1:577cb7aaf28306abca03274ec38d295700b5bc9b</id>
<content type='text'>
While here:

- Prevent combination of SSSD and GSSAPI_HEIMDAL because sssd port
  requires MIT kerberos and it will conflict with heimdal
- Removed SSSD_DEVEL option because sssd-devel port requires sudo and it
  creates a circular dependency
- Fix OPIE on FreeBSD versions after it was removed from base

Sponsored by:	Rubicon Communications, LLC ("Netgate")

(cherry picked from commit dd773c1540388b14692001643e323a556ed2d445)
</content>
</entry>
<entry>
<title>security/sudo: Fix build with openssl from ports</title>
<updated>2023-11-01T12:08:44Z</updated>
<author>
<name>Renato Botelho</name>
<email>garga@FreeBSD.org</email>
</author>
<published>2023-10-31T22:07:56Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=005d8c15b8027330dd27d66caaf97dc8a85f034a'/>
<id>urn:sha1:005d8c15b8027330dd27d66caaf97dc8a85f034a</id>
<content type='text'>
Since SSL support is being changed and sudo can be built without it, add
a new SSL option, on by default.

When option is enabled, use --enable-openssl=${OPENSSLBASE} to make sure
it consumes desired OpenSSL implementation.  Also add pkgconfig
dependency because configure script rely on it to detect openssl
details.

PR:		274753
Reported by:	tburns@hrsd.com
Sponsored by:	Rubicon Communications, LLC ("Netgate")

(cherry picked from commit dbc4e4daf752173acb868fc595ae9fa42f972aef)
</content>
</entry>
<entry>
<title>security/sudo: Update to 1.9.14p3</title>
<updated>2023-07-25T13:44:22Z</updated>
<author>
<name>Cy Schubert</name>
<email>cy@FreeBSD.org</email>
</author>
<published>2023-07-25T01:49:28Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=2e3e2b5782a76383d5c8a62a5753b9d95cd1ba68'/>
<id>urn:sha1:2e3e2b5782a76383d5c8a62a5753b9d95cd1ba68</id>
<content type='text'>
Major changes between sudo 1.9.14p3 and 1.9.14p2:

 * Fixed a crash with Python 3.12 when the sudo Python python is
   unloaded.  This only affects "make check" for the Python plugin.

 * Adapted the sudo Python plugin test output to match Python 3.12.

PR:		272707
Approved by:	garga (maintainer)
MFH:		2023Q3
</content>
</entry>
<entry>
<title>security/sudo: Update to 1.9.14p2</title>
<updated>2023-07-17T14:20:56Z</updated>
<author>
<name>Renato Botelho</name>
<email>garga@FreeBSD.org</email>
</author>
<published>2023-07-17T14:20:22Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=bc8853e5af6c9c507dbc1898501d9b85ea894348'/>
<id>urn:sha1:bc8853e5af6c9c507dbc1898501d9b85ea894348</id>
<content type='text'>
Sponsored by:	Rubicon Communications, LLC ("Netgate")
</content>
</entry>
<entry>
<title>security/sudo: add sssd-devel option</title>
<updated>2023-07-14T13:06:49Z</updated>
<author>
<name>Dan Langille</name>
<email>dvl@FreeBSD.org</email>
</author>
<published>2023-07-14T13:05:34Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=c90c4cc7030b96337f094c4f72c1708cf89381b7'/>
<id>urn:sha1:c90c4cc7030b96337f094c4f72c1708cf89381b7</id>
<content type='text'>
security/sudo already allows for the use of security/sssd (SSSD)

This patch allows for selecting security/sssd-devel (SSSD_DEVEL)
instead.

PR:		272488
</content>
</entry>
<entry>
<title>security/sudo: Update to 1.9.14p1</title>
<updated>2023-07-12T12:46:27Z</updated>
<author>
<name>Cy Schubert</name>
<email>cy@FreeBSD.org</email>
</author>
<published>2023-07-11T23:04:28Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=7bc586ab264043f17bef7d49222be0602f3b44f8'/>
<id>urn:sha1:7bc586ab264043f17bef7d49222be0602f3b44f8</id>
<content type='text'>
Major changes between sudo 1.9.14p1 and 1.9.14:

 * Fixed an "invalid free" bug in sudo_logsrvd that was introduced
   in version 1.9.14 which could cause sudo_logsrvd to crash.

 * The sudoers plugin no longer tries to send the terminal name
   to the log server when no terminal is present.  This bug was
   introduced in version 1.9.14.

PR:             272456
Approved by:    garga (maintainer)
MFH:            2023Q3
</content>
</entry>
</feed>
