/[path-sandbox]/trunk/ChangeLog.0
Gentoo

Diff of /trunk/ChangeLog.0

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

Revision 47 Revision 115
1# ChangeLog for Path Sandbox 1# ChangeLog for Path Sandbox
2# Copyright 1999-2004 Gentoo Foundation; Distributed under the GPL v2 2# Copyright 1999-2005 Gentoo Foundation; Distributed under the GPL v2
3# $Header$ 3# $Header$
4
5* sandbox-1.2.9 (2005/06/09)
6
7 09 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
8 Move symlink hack down a bit to try and minimize on the amount of lstat()
9 calls we do.
10
11 09 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c, sandbox.c:
12 Add hack to allow writing to /proc/self/fd (or /dev/fd), bug #91516.
13
14 09 June 2005; Martin Schlemmer <azarah@gentoo.org> symbols.in, libsandbox.c:
15 Add wrapper for access() function, bug #85413.
16
17 09 June 2005; Martin Schlemmer <azarah@gentoo.org> getcwd.c:
18 Use generic getcwd() implementation from uclibc - should be more portable
19 and looks a bit cleaner.
20
21 09 June 2005; Martin Schlemmer <azarah@gentoo.org> getcwd.c, libsandbox.c:
22 Make sure our true_* pointers are initialized to NULL, and that we check for
23 all references that they are valid.
24
25 09 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
26 Be default we will fail if the path name we try to canonicalize is too long.
27 This however could cause issues with some things (bug #94630 and #21766), so
28 if fail_nametoolong == 0, canonicalize() will return a null length string and
29 do not fail.
30
31 08 June 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox_futils.c:
32 Do not abort if TMPDIR is not valid, but rather use '/tmp', bug #94360. Also
33 make sure we re-export the new TMPDIR environment variable.
34
35 08 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
36 Fix incorrect free of non-malloc'd array, bug #92313 and #94020. Fix noted
37 by Marcus D. Hanwell <cryos@gentoo.org>.
38
39 08 June 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
40 Add /dev/console to write list, bug #38588.
41
42* sandbox-1.2.8 (2005/05/13)
43
44 13 May 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c, sandbox.c,
45 sandbox.h, sandbox_futils.c:
46 General cleanups.
47
48 13 May 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c, sandbox.c,
49 sandbox.h:
50 Various LD_PRELOAD cleanups. Do not unset LD_PRELOAD for parent.
51
52 13 May 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c, sandbox.c,
53 sandbox.h, sandbox_futils.c:
54 Modify get_sandbox_pids_file(), get_sandbox_log() and get_sandbox_debug_log()
55 to use TMPDIR if present in environment.
56
57 13 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
58 Remove sandbox_log_file from main() as its no longer used.
59
60 13 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h,
61 sandbox_futils.c:
62 Add get_sandbox_debug_log(), and use it (add behaviour similar to SANDBOX_LOG
63 if already exported when sandbox started). Fix get_sandbox_log() and new
64 get_sandbox_debug_log() to not use already exported environment variables if
65 they have '/' in them. Use snprintf()'s instead of strncpy()'s. More
66 SB_PATH_MAX fixes.
67
68* sandbox-1.2.7 (2005/05/12)
69
70 12 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h,
71 sandbox_futils.c:
72 More path limit fixes. Declare SB_BUF_LEN global and use it where needed.
73
74 12 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox_futils.c:
75 Fix paths limited to 255 chars. Fix get_sandbox_dir() returning a string
76 with '(null)' in it if we did not call sandbox with absolute path.
77
78 12 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
79 Set SANDBOX_ON *before* doing the child's env stuff, else its not set
80 for the child.
81
82 12 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
83 Remove global preload_adaptable as it is no longer used.
84
85 12 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
86 Rewrite environment stuff to only be set when execve'ing the child process
87 to try and avoid issues like bug #91541 that causes sandbox to crash if
88 we set LD_PRELOAD sandbox side already.
89
90 11 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
91 Move print_sandbox_log() up to make things neater.
92
93 11 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
94 Remove load_preload_libs(), as its not used anymore.
95
96 11 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h:
97 Remove NO_FORK stuff, as its not used, and 'strace -f' works just fine.
98
99 11 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h:
100 Remove USE_SYSTEM_SHELL stuff, as it is not secure, and not in use.
101
102 11 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h:
103 Remove ld.so.preload crap - we are not going to use it again.
104
105 10 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox_futils.c:
106 Fix typo in code that checks if we got valid group information, causing a
107 segmentation fault, bug #91637.
108
109* sandbox-1.2.6 (2005/05/10)
110
111 10 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
112 Do not use LD_PRELOAD if it contains libtsocks.so, as it breaks sandbox
113 for some odd reason, bug #91541.
114
115 09 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
116 Fix typo (sizeof -> strlen).
117
118 08 May 2005; Brian Harring <ferringb@gentoo.org> libsandbox.c:
119 rewrote the sbcontext caching code so it accounts for env changes since lib
120 initialization.
121
122 05 May 2005; Martin Schlemmer <azarah@gentoo.org> configure.in, libctest.c:
123 We create libctest.c via configure, so no need to keep it around. Do some
124 cleanup related to libctest.c and libctest during configure.
125
126 04 May 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
127 Add rename support of symlinks pointing to protected files/directories.
128
129* sandbox-1.2.5 (2005/05/04)
130
131 04 May 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c, sandbox.c,
132 sandbox.bashrc:
133 Do not reset already set LD_PRELOAD when starting sandbox. If LD_PRELOAD is
134 already set, init of the env vars fails for some reason, so do this later on,
135 and do not warn (bug #91431).
136
137 03 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h,
138 sandbox.bashrc:
139 Fixup sandbox and sandbox.bashrc to call bash with the proper .bashrc.
140
141* sandbox-1.2.4 (2005/05/03)
142
143 03 May 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
144 Do not init the env entries with each call, as it creates too many calls to
145 lstat, etc. Should speedup things a bit, bug #91040.
146
147 03 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
148 Add /dev/pty to default write list. Noticed by Morfic.
149
150 02 May 2005; Mike Frysinger <vapier@gentoo.org> configure.in, localdecls.h,
151 sandbox.h:
152 uClibc doesn't support dlvsym() so add a configure check to make sure it doesn't
153 exist. Also update localdecls.h so BROKEN_RTLD_NEXT isn't defined in uClibc.
154
155* sandbox-1.2.3 (2005/04/29)
156
157 29 Apr 2005; Martin Schlemmer <azarah@gentoo.org> configure.in:
158 Do not check for (*&#$(* CXX or F77.
159
160 29 Apr 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
161 Do not append '/' to pathname in filter_path() if it already ends with it.
162
163 28 Apr 2005; Mike Frysinger <vapier@gentoo.org> Makefile.am, configure.in:
164 With az's help, clean up autotools to work with cross-compiling.
165
166* sandbox-1.2.2 (2005/04/28)
4 167
5 28 Apr 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c: 168 28 Apr 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
6 Only check for /dev/{null,zero} for unlink hack, else ricers using /dev/shm 169 Only check for /dev/{null,zero} for unlink hack, else ricers using /dev/shm
7 have issues; bug #90592. 170 have issues; bug #90592.
8 171
9* sandbox-1.2.1 172* sandbox-1.2.1 (2005/04/23)
10 173
11 23 Apr 2005; Martin Schlemmer <azarah@gentoo.org> Makefile.am, canonicalize.c, 174 23 Apr 2005; Martin Schlemmer <azarah@gentoo.org> Makefile.am, canonicalize.c,
12 getcwd.c, libsandbox.c, localdecls.h, sandbox.h, sandbox_futils.c: 175 getcwd.c, libsandbox.c, localdecls.h, sandbox.h, sandbox_futils.c:
13 Make sure all functions used in libsandbox.c is declared static. Define 176 Make sure all functions used in libsandbox.c is declared static. Define
14 SB_STATIC in localdecls.h for this. Include sandbox_futils.c rather than 177 SB_STATIC in localdecls.h for this. Include sandbox_futils.c rather than
15 linking with its object. Hopefully this will fix bug #90153. 178 linking with its object. Hopefully this will fix bug #90153.
16 179
17* sandbox-1.2 180* sandbox-1.2 (2005/04/23)
18 181
19 22 Mar 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c: 182 22 Mar 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
20 Allow lchown a symlink in write-allowed path pointing to write-denied 183 Allow lchown a symlink in write-allowed path pointing to write-denied
21 target. 184 target.
22 185

Legend:
Removed from v.47  
changed lines
  Added in v.115

  ViewVC Help
Powered by ViewVC 1.1.20