Commit Graph

406 Commits

Author SHA256 Message Date
Matthias Gerstner
75eab2a589 - Update to version 20220309:
* apptainer whitelisting (bsc#1196145)

- Update to version 20220202:
  * mount.nfs: switch from migration mode to fixed path in /usr/sbin
  * changed gendered pronouns
  * mgetty: faxq-helper now finally reside in /usr/libexec

OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=300
2022-03-11 11:16:53 +00:00
Dominique Leuenberger
1485343c01 Accepting request 915438 from Base:System
- Update to version 20210901:
  * libksysguard5: Updated path for ksgrd_network_helper
  * kdesu: Updated path for kdesud
  * sbin_dirs cleanup: these binaries have already been moved to /usr/sbin
  * mariadb: revert auth_pam_tool to /usr/lib{,64} again
  * cleanup: revert virtualbox back to plain /usr/lib
  * cleanup: remove deprecated /etc/ssh/sshd_config
  * hawk_invoke is not part of newer hawk2 packages anymore
  * cleanup: texlive-filesystem: public now resides in libexec
  * cleanup: authbind: helper now resides in libexec
  * cleanup: polkit: the agent now also resides in libexec
  * libexec cleanup: 'inn' news binaries now reside in libexec

OBS-URL: https://build.opensuse.org/request/show/915438
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/permissions?expand=0&rev=149
2021-09-06 13:57:50 +00:00
Matthias Gerstner
58b6579089 OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=299 2021-09-01 08:07:14 +00:00
Matthias Gerstner
e5129cd8f6 - Update to version 20210901:
* libksysguard5: Updated path for ksgrd_network_helper
  * kdesu: Updated path for kdesud
  * sbin_dirs cleanup: these binaries have already been moved to /usr/sbin
  * mariadb: revert auth_pam_tool to /usr/lib{,64} again
  * cleanup: revert virtualbox back to plain /usr/lib
  * cleanup: remove deprecated /etc/ssh/sshd_config
  * hawk_invoke is not part of newer hawk2 packages anymore
  * cleanup: texlive-filesystem: public now resides in libexec
  * cleanup: authbind: helper now resides in libexec
  * cleanup: polkit: the agent now also resides in libexec
  * libexec cleanup: 'inn' news binaries now reside in libexec

OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=298
2021-09-01 07:35:31 +00:00
Dominique Leuenberger
02fa63bac3 Accepting request 894035 from Base:System
- Update to version 20210518:
  * whitelist please (bsc#1183669)

- Update to version 20210518:
  * Fix enlightenment paths for 32-bit architectures

OBS-URL: https://build.opensuse.org/request/show/894035
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/permissions?expand=0&rev=148
2021-05-21 19:49:44 +00:00
Matthias Gerstner
ff0b388651 - Update to version 20210518:
* whitelist please (bsc#1183669)

OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=296
2021-05-18 11:16:38 +00:00
Matthias Gerstner
f28bbb953b OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=295 2021-05-18 09:06:14 +00:00
Matthias Gerstner
e377ed99a1 - Update to version 20210518:
* Fix enlightenment paths for 32-bit architectures

OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=294
2021-05-18 08:03:13 +00:00
Dominique Leuenberger
419195611e Accepting request 866579 from Base:System
- Update to version 20210125:
  * usbauth: drop compatibility variable for libexec
  * usbauth: Updated path for usbauth-npriv
  * profiles: finish usage of variable for polkit-agent-helper-1

OBS-URL: https://build.opensuse.org/request/show/866579
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/permissions?expand=0&rev=147
2021-02-01 12:25:09 +00:00
Matthias Gerstner
818fcee281 - Update to version 20210125:
* usbauth: drop compatibility variable for libexec
  * usbauth: Updated path for usbauth-npriv
  * profiles: finish usage of variable for polkit-agent-helper-1

OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=292
2021-01-25 12:15:26 +00:00
Dominique Leuenberger
6b6f3114f7 Accepting request 853596 from Base:System
move man page to where the documented files are

A separate package for a single man page really is overkill.

See also discussion at 
https://lists.opensuse.org/archives/list/packaging@lists.opensuse.org/message/5FSP57UVYLS7BNBDNF4EGHW5TEEZUS5D/ (forwarded request 853107 from lnussel)

OBS-URL: https://build.opensuse.org/request/show/853596
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/permissions?expand=0&rev=146
2021-01-10 18:37:58 +00:00
Matthias Gerstner
172fdb46a3 Accepting request 853107 from home:lnussel:branches:Base:System
move man page to where the documented files are

A separate package for a single man page really is overkill.

See also discussion at 
https://lists.opensuse.org/archives/list/packaging@lists.opensuse.org/message/5FSP57UVYLS7BNBDNF4EGHW5TEEZUS5D/

OBS-URL: https://build.opensuse.org/request/show/853107
OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=290
2020-12-07 13:52:52 +00:00
Johannes Segitz
c6c0f68644 Accepting request 847754 from home:mgerstner:branches:Base:System
- Update to version 20201111:
  * squid: remove basic_pam_auth which doesn't need special perms (bsc#1171569)
  * mgetty: remove long dead (or never existing) locks directory (bsc#1171882)
  * adjust squid pinger path (bsc#1171569)
  * profiles: remove now superfluous squid pinger paths (bsc#1171569)
  * ksgrd_network_helper: remove obviously wrong path
  * etc/permissions: remove unnecessary, duplicate, outdated entries
  * chkstat: implement support for variables in profile paths in new
    variables.conf
  * man pages: add documentation about variables, update copyrights
  * profiles: use new variables feature to remove redundant entries
  * profiles: prepare /usr/sbin versions of profile entries (bsc#1029961)
  * Makefile: support CXXFLAGS and LDFLAGS override / extension via make/env variables (bsc#1178475)
  * Makefile: compile with LFO support to fix 32-bit emulation on 64-bit hosts (bsc#1178476)
  * README: added information about know limitations of this approach
- adjusted spec file:
  - package new variables.conf
  - apply %{optflags} correctly via CXXFLAGS variable
  - drop FSCAPS_DEFAULT_ENABLED which isn't recognized anymore by the
    refactored chkstat sources. This is now the default.

OBS-URL: https://build.opensuse.org/request/show/847754
OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=289
2020-11-11 10:46:39 +00:00
Dominique Leuenberger
c95a42da17 Accepting request 840211 from Base:System
- Update to version 20201008:
  * cleanup now useless /usr/lib entries after move to /usr/libexec (bsc#1171164)
  * drop (f)ping capabilities in favor of ICMP_PROTO sockets (bsc#1174504)

OBS-URL: https://build.opensuse.org/request/show/840211
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/permissions?expand=0&rev=145
2020-10-15 11:43:38 +00:00
Matthias Gerstner
5d5b938d79 - Update to version 20201008:
* cleanup now useless /usr/lib entries after move to /usr/libexec (bsc#1171164)
  * drop (f)ping capabilities in favor of ICMP_PROTO sockets (bsc#1174504)

OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=287
2020-10-08 09:20:05 +00:00
Dominique Leuenberger
3baec52155 Accepting request 838733 from Base:System
- Update to version 20200930:
  * whitelist Xorg setuid-root wrapper (bsc#1175867)

OBS-URL: https://build.opensuse.org/request/show/838733
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/permissions?expand=0&rev=144
2020-10-04 15:30:04 +00:00
Matthias Gerstner
802df35b01 OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=285 2020-09-30 09:56:48 +00:00
Matthias Gerstner
8f56b3bee2 - Update to version 20200930:
* whitelist Xorg setuid-root wrapper (bsc#1175867)

OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=284
2020-09-30 09:28:18 +00:00
Dominique Leuenberger
bbf0dfcc04 Accepting request 833221 from Base:System
- Update to version 20200909:
  * screen: remove /run/uscreens covered by systemd-tmpfiles (bsc#1171879)

OBS-URL: https://build.opensuse.org/request/show/833221
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/permissions?expand=0&rev=143
2020-09-14 10:02:03 +00:00
Matthias Gerstner
6b2d70fbf8 - Update to version 20200909:
* screen: remove /run/uscreens covered by systemd-tmpfiles (bsc#1171879)

OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=282
2020-09-09 10:01:23 +00:00
Dominique Leuenberger
994bbe18e7 Accepting request 832056 from Base:System
- Update to version 20200904:
  * Add /usr/libexec for cockpit-session as new path
  * physlock: whitelist with tight restrictions (bsc#1175720)

OBS-URL: https://build.opensuse.org/request/show/832056
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/permissions?expand=0&rev=142
2020-09-08 20:55:18 +00:00
Matthias Gerstner
9d0d5227c9 - Update to version 20200904:
* Add /usr/libexec for cockpit-session as new path
  * physlock: whitelist with tight restrictions (bsc#1175720)

OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=280
2020-09-04 10:58:24 +00:00
Dominique Leuenberger
8f6334b1fd Accepting request 829800 from Base:System
- Update to version 20200826:
  * mtr-packet: stop requiring dialout group
  * etc/permissions: fix mtr permission
  * list_permissions: improve output format
  * list_permissions: support globbing in --path argument
  * list_permissions: implement simplifications suggested in PR#92
  * list_permissions: new tool for better path configuration overview

OBS-URL: https://build.opensuse.org/request/show/829800
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/permissions?expand=0&rev=141
2020-08-31 14:47:18 +00:00
Malte Kraus
ddf46a06b6 - Update to version 20200826:
* mtr-packet: stop requiring dialout group
  * etc/permissions: fix mtr permission
  * list_permissions: improve output format
  * list_permissions: support globbing in --path argument
  * list_permissions: implement simplifications suggested in PR#92
  * list_permissions: new tool for better path configuration overview

OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=278
2020-08-26 15:38:36 +00:00
Dominique Leuenberger
8854dfa5fb Accepting request 825923 from Base:System
- Update to version 20200811:
  * regtest: support new getcap output format in libcap-2.42
  * regtest: print individual test case errors to stderr

OBS-URL: https://build.opensuse.org/request/show/825923
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/permissions?expand=0&rev=140
2020-08-17 09:59:54 +00:00
Matthias Gerstner
1226549810 - Update to version 20200811:
* regtest: support new getcap output format in libcap-2.42
  * regtest: print individual test case errors to stderr

OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=276
2020-08-11 12:07:22 +00:00
Dominique Leuenberger
488a572e21 Accepting request 822971 from Base:System
- Update to version 20200727:
  * etc/permissions: remove static /var/spool/* dirs
  * etc/permissions: remove outdated entries
  * etc/permissions: remove unnecessary static dirs and devices
  * screen: remove now unused /var/run/uscreens

OBS-URL: https://build.opensuse.org/request/show/822971
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/permissions?expand=0&rev=139
2020-07-30 07:55:40 +00:00
Matthias Gerstner
8d415c2c98 - Update to version 20200727:
* etc/permissions: remove static /var/spool/* dirs
  * etc/permissions: remove outdated entries
  * etc/permissions: remove unnecessary static dirs and devices
  * screen: remove now unused /var/run/uscreens

OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=274
2020-07-27 12:19:56 +00:00
Dominique Leuenberger
744575cb77 Accepting request 819968 from Base:System
- Update to version 20200710:
  * Revert "etc/permissions: remove entries for bind-chrootenv". This
    currently conflicts with the way the CheckSUIDPermissions rpmlint-check is
    implemented.

- Removed dbus-libexec.patch: contained in upstream

- Update to version 20200624:
  * rework permissions.local text (boo#1173221)
  * dbus-1: adjust to new libexec dir location (bsc#1171164)
  * permission profiles: reinstate kdesud for kde5
  * etc/permissions: remove entries for bind-chrootenv
  * etc/permissions: remove traceroute entry
  * VirtualBox: remove outdated entry which is only a symlink any more
  * /bin/su: remove path refering to symlink
  * etc/permissions: remove legacy RPM directory entries
  * /etc/permissions: remove outdated sudo directories
  * singularity: remove outdated setuid-binary entries
  * chromium: remove now unneeded chrome_sandbox entry (bsc#1163588)
  * dbus-1: remove deprecated alternative paths
  * PolicyKit: remove outdated entries last used in SLE-11
  * pcp: remove no longer needed / conflicting entries
  * gnats: remove entries for package removed from Factory
  * kdelibs4: remove entries for package removed from Factory
  * v4l-base: remove entries for package removed from Factory
  * mailman: remove entries for package deleted from Factory
  * gnome-pty-helper: remove dead entry no longer part of the vte package
  * gnokii: remove entries for package no longer in Factory
  * xawtv (v4l-conf): correct group ownership in easy profile
  * systemd-journal: remove unnecessary profile entries

OBS-URL: https://build.opensuse.org/request/show/819968
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/permissions?expand=0&rev=138
2020-07-15 09:12:57 +00:00
Matthias Gerstner
1490c88424 OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=272 2020-07-10 09:53:12 +00:00
Matthias Gerstner
79548e974d - Update to version 20200710:
* Revert "etc/permissions: remove entries for bind-chrootenv". This
    currently conflicts with the way the CheckSUIDPermissions rpmlint-check is
    implemented.

OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=271
2020-07-10 09:51:12 +00:00
Matthias Gerstner
128acfff3a Accepting request 819264 from home:gmbr3:Active
- Removed dbus-libexec.patch: contained in upstream

OBS-URL: https://build.opensuse.org/request/show/819264
OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=270
2020-07-08 07:50:44 +00:00
Matthias Gerstner
71f7833b2a OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=269 2020-07-07 14:32:39 +00:00
Matthias Gerstner
af3b1d9d0a - Update to version 20200624:
* rework permissions.local text (boo#1173221)
  * dbus-1: adjust to new libexec dir location (bsc#1171164)
  * permission profiles: reinstate kdesud for kde5
  * etc/permissions: remove entries for bind-chrootenv
  * etc/permissions: remove traceroute entry
  * VirtualBox: remove outdated entry which is only a symlink any more
  * /bin/su: remove path refering to symlink
  * etc/permissions: remove legacy RPM directory entries
  * /etc/permissions: remove outdated sudo directories
  * singularity: remove outdated setuid-binary entries
  * chromium: remove now unneeded chrome_sandbox entry (bsc#1163588)
  * dbus-1: remove deprecated alternative paths
  * PolicyKit: remove outdated entries last used in SLE-11
  * pcp: remove no longer needed / conflicting entries
  * gnats: remove entries for package removed from Factory
  * kdelibs4: remove entries for package removed from Factory
  * v4l-base: remove entries for package removed from Factory
  * mailman: remove entries for package deleted from Factory
  * gnome-pty-helper: remove dead entry no longer part of the vte package
  * gnokii: remove entries for package no longer in Factory
  * xawtv (v4l-conf): correct group ownership in easy profile
  * systemd-journal: remove unnecessary profile entries
  * thttp: make makeweb entry usable in the secure profile (bsc#1171580)

OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=268
2020-07-07 14:19:17 +00:00
Dominique Leuenberger
bf581cbf30 Accepting request 815295 from Base:System
- dbus-1: adjust to new libexec dir location (bsc#1171164). This is
  temporarily done through the patch in dbus-libexec.patch because
  we are not completely certain the stability of current git.
- run chkstat test suite during RPM build

OBS-URL: https://build.opensuse.org/request/show/815295
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/permissions?expand=0&rev=137
2020-06-24 13:47:27 +00:00
Malte Kraus
c23ecff997 Accepting request 815294 from home:mkraus:branches:Base:System
- dbus-1: adjust to new libexec dir location (bsc#1171164). This is
  temporarily done through the patch in dbus-libexec.patch because
  we are not completely certain the stability of current git.
- run chkstat test suite during RPM build

OBS-URL: https://build.opensuse.org/request/show/815294
OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=266
2020-06-16 16:20:27 +00:00
Dominique Leuenberger
ee8dd62848 Accepting request 810755 from Base:System
- Update to version 20200526:
  * profiles: add entries for enlightenment (bsc#1171686)

OBS-URL: https://build.opensuse.org/request/show/810755
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/permissions?expand=0&rev=136
2020-06-11 12:40:46 +00:00
Yuchen Lin
b1726c7dd0 Accepting request 807568 from Base:System
- Update to version 20200520:
  * permissions fixed profile: utempter: reinstate libexec compatibility entry (forwarded request 807566 from mgerstner)

OBS-URL: https://build.opensuse.org/request/show/807568
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/permissions?expand=0&rev=135
2020-05-29 19:19:46 +00:00
Matthias Gerstner
2c673b8f18 - Update to version 20200526:
* profiles: add entries for enlightenment (bsc#1171686)

OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=263
2020-05-26 13:04:28 +00:00
Matthias Gerstner
3cb7f26448 Accepting request 807566 from home:mgerstner:branches:Base:System
- Update to version 20200520:
  * permissions fixed profile: utempter: reinstate libexec compatibility entry

OBS-URL: https://build.opensuse.org/request/show/807566
OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=262
2020-05-20 10:22:24 +00:00
Malte Kraus
b3c2250df9 Accepting request 807173 from home:mgerstner:branches:Base:System
- Update to version 20200519:
  * chkstat: fix sign conversion warnings on 32-bit architectures
  * chkstat: allow simultaneous use of `--set` and `--system`
  * regtest: adjust TestUnkownOwnership test to new warning output behaviour

OBS-URL: https://build.opensuse.org/request/show/807173
OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=261
2020-05-19 09:32:14 +00:00
Malte Kraus
5ae3717c19 - Update to version 20200518:
* whitelist texlive public binary (bsc#1171686)

OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=260
2020-05-18 12:07:18 +00:00
Malte Kraus
4445ad42e7 Accepting request 805788 from home:mgerstner:branches:Base:System
- Update to version 20200514:
  * fixed permissions: adjust to new libexec dir location (bsc#1171164)
    (affects utempter path)
- Update to version 20200513:
  * major rewrite of the chkstat tool
  * setuid bit for cockpit (bsc#1169614)

OBS-URL: https://build.opensuse.org/request/show/805788
OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=259
2020-05-18 11:33:57 +00:00
Dominique Leuenberger
3b5b9f159c Accepting request 801106 from Base:System
- Update to version 20200506:
  * add whitelist for files in /usr/lib to be also allowed in
    /usr/libexec (bsc#1171164)

OBS-URL: https://build.opensuse.org/request/show/801106
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/permissions?expand=0&rev=134
2020-05-12 20:25:21 +00:00
Malte Kraus
50981bbfa3 OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=257 2020-05-07 10:01:14 +00:00
Malte Kraus
5e5838f434 - Update to version 20200506:
* add whitelist for files in /usr/lib to be also allowed in
    /usr/libexec (bsc#1171164)

OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=256
2020-05-07 10:00:31 +00:00
Dominique Leuenberger
488befb29d Accepting request 787823 from Base:System
OBS-URL: https://build.opensuse.org/request/show/787823
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/permissions?expand=0&rev=133
2020-03-30 20:50:49 +00:00
Johannes Segitz
7dcf78b266 Accepting request 787822 from home:jsegitz:branches:Base:System
- Update to version 20200324:
  * whitelist s390-tools setgid bit on log directory (bsc#1167163)
  * whitelist WMP (bsc#1161335)
  * regtest: improve readability of path variables by using literals
  * regtest: adjust test suite to new path locations in /usr/share/permissions
  * regtest: only catch explicit FileNotFoundError
  * regtest: provide valid home directory in /root
  * regtest: mount permissions src repository in /usr/src/permissions
  * regtest: move initialialization of TestBase paths into the prepare() function
  * chkstat: suppport new --config-root command line option
  * fix spelling of icingacmd group

OBS-URL: https://build.opensuse.org/request/show/787822
OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=254
2020-03-24 14:13:59 +00:00
Dominique Leuenberger
023c747578 Accepting request 780979 from Base:System
- Update to version 20200228:
  * chkstat: fix readline() on platforms with unsigned char

- Update to version 20200227:
  * remove capability whitelisting for radosgw
  * whitelist ceph log directory (bsc#1150366)
  * adjust testsuite to post CVE-2020-8013 link handling
  * testsuite: add option to not mount /proc
  * do not follow symlinks that are the final path element: CVE-2020-8013
  * add a test for symlinked directories
  * fix relative symlink handling
  * include cpp compat headers, not C headers
  * Move permissions and permissions.* except .local to /usr/share/permissions
  * regtest: fix the static PATH list which was missing /usr/bin
  * regtest: also unshare the PID namespace to support /proc mounting
  * regtest: bindMount(): explicitly reject read-only recursive mounts
  * Makefile: force remove upon clean target to prevent bogus errors
  * regtest: by default automatically (re)build chkstat before testing
  * regtest: add test for symlink targets
  * regtest: make capability setting tests optional
  * regtest: fix capability assertion helper logic
  * regtests: add another test case that catches set*id or caps in world-writable sub-trees
  * regtest: add another test that catches when privilege bits are set for special files
  * regtest: add test case for user owned symlinks
  * regtest: employ subuid and subgid feature in user namespace
  * regtest: add another test case that covers unknown user/group config
  * regtest: add another test that checks rejection of insecure mixed-owner paths
  * regtest: add test that checks for rejection of world-writable paths
  * regtest: add test for detection of unexpected parent directory ownership
  * regtest: add further helper functions, allow access to main instance (forwarded request 780264 from mkraus)

OBS-URL: https://build.opensuse.org/request/show/780979
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/permissions?expand=0&rev=132
2020-03-06 20:23:21 +00:00
Matthias Gerstner
c1a2fada58 Accepting request 780264 from home:mkraus:branches:Base:System
- Update to version 20200228:
  * chkstat: fix readline() on platforms with unsigned char

- Update to version 20200227:
  * remove capability whitelisting for radosgw
  * whitelist ceph log directory (bsc#1150366)
  * adjust testsuite to post CVE-2020-8013 link handling
  * testsuite: add option to not mount /proc
  * do not follow symlinks that are the final path element: CVE-2020-8013
  * add a test for symlinked directories
  * fix relative symlink handling
  * include cpp compat headers, not C headers
  * Move permissions and permissions.* except .local to /usr/share/permissions
  * regtest: fix the static PATH list which was missing /usr/bin
  * regtest: also unshare the PID namespace to support /proc mounting
  * regtest: bindMount(): explicitly reject read-only recursive mounts
  * Makefile: force remove upon clean target to prevent bogus errors
  * regtest: by default automatically (re)build chkstat before testing
  * regtest: add test for symlink targets
  * regtest: make capability setting tests optional
  * regtest: fix capability assertion helper logic
  * regtests: add another test case that catches set*id or caps in world-writable sub-trees
  * regtest: add another test that catches when privilege bits are set for special files
  * regtest: add test case for user owned symlinks
  * regtest: employ subuid and subgid feature in user namespace
  * regtest: add another test case that covers unknown user/group config
  * regtest: add another test that checks rejection of insecure mixed-owner paths
  * regtest: add test that checks for rejection of world-writable paths
  * regtest: add test for detection of unexpected parent directory ownership
  * regtest: add further helper functions, allow access to main instance

OBS-URL: https://build.opensuse.org/request/show/780264
OBS-URL: https://build.opensuse.org/package/show/Base:System/permissions?expand=0&rev=252
2020-03-02 13:50:40 +00:00