/[path-sandbox]/trunk/ChangeLog.0
Gentoo

Diff of /trunk/ChangeLog.0

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

Revision 47 Revision 147
1# ChangeLog for Path Sandbox 1# ChangeLog for Path Sandbox
2# Copyright 1999-2004 Gentoo Foundation; Distributed under the GPL v2 2# Copyright 1999-2005 Gentoo Foundation; Distributed under the GPL v2
3# $Header$ 3# $Header$
4
5 08 July 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox_futils.c,
6 libsandbox.c:
7 - Try to cleanup and make error handling/printing consistent.
8 - Remove old logs if present and conflicting with current.
9 - Fix compile error with previous change, and return rather then exit().
10
11 07 July 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c, sandbox.c,
12 sandbox.h, sandbox_futils.c:
13 - Fix possible segfault in env init code.
14 - Major cleanup of sandbox_futils.c. Removed most of the functions as we now
15 write to /var/log/sandbox/, so in theory do not need all that.
16 - Redo the interface of the get_* functions so that we do not leak memory.
17 - Remove sandbox_dir and co - we are not using it anymore.
18 - Remove unused includes and variables.
19 - Only declare functions in sandbox_futils.c that are used in libsandbox.c when
20 OUTSIDE_LIBSANDBOX is not defined.
21 - Cleanup access/log printing. Make access printing honour NOCOLOR. Fix log
22 printing's last line not honouring NOCOLOR.
23
24 06 July 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.h, sandbox_futils.c,
25 libsandbox.c:
26 - Change log dir to /var/log/sandbox/. Make sure the sandboxed process cannot
27 write to it.
28 - Clean up logging in libsandbox.c, and hopefully make it more consistant.
29 - Add check_prefixes() with major cleanup on check_access().
30 - Cleanup init_env_entries() and check_prefixes().
31
32 05 July 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h,
33 sandbox_futils.c, libsandbox.c:
34 Remove unused 'pids file' code.
35
36* sandbox-1.2.10 (2005/07/03)
37
38 03 July 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
39 Add PREDICT items for nss-db, bug #92079. Patch from Robin Johnson.
40
41 17 June 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
42 General cleanups:
43 - Remove fooling around with exit codes - we error out on presence of a log
44 anyhow.
45 - Move get_sandbox_*_envvar() to sandbox_setup_environ(), as its more
46 appropriate there.
47
48 12 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
49 Cleanup the fail_nametoolong stuff a bit more.
50
51 11 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
52 Remove hopefully the last ld.so.preload bits we do not use anymore.
53
54 11 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
55 Remove the unneeded canonicalize() calls in the wrappers - we do it anyhow
56 in check_syscall(). Should speed things up a bit (at least for the getcwd()
57 and long path name test it goes down to under a second, and not 10+ seconds
58 like before). Also warn if we skip checking due to the canonicalized path
59 being too long.
60
61 11 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
62 More comment/readability cleanups.
63
64 10 June 2005; Martin Schlemmer <azarah@gentoo.org> canonicalize.c, getcwd.c,
65 sandbox_futils.c, libsandbox.c:
66 Some strncpy/strncat and other cleanups.
67
68* sandbox-1.2.9 (2005/06/09)
69
70 09 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
71 Move symlink hack down a bit to try and minimize on the amount of lstat()
72 calls we do.
73
74 09 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c, sandbox.c:
75 Add hack to allow writing to /proc/self/fd (or /dev/fd), bug #91516.
76
77 09 June 2005; Martin Schlemmer <azarah@gentoo.org> symbols.in, libsandbox.c:
78 Add wrapper for access() function, bug #85413.
79
80 09 June 2005; Martin Schlemmer <azarah@gentoo.org> getcwd.c:
81 Use generic getcwd() implementation from uclibc - should be more portable
82 and looks a bit cleaner.
83
84 09 June 2005; Martin Schlemmer <azarah@gentoo.org> getcwd.c, libsandbox.c:
85 Make sure our true_* pointers are initialized to NULL, and that we check for
86 all references that they are valid.
87
88 09 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
89 Be default we will fail if the path name we try to canonicalize is too long.
90 This however could cause issues with some things (bug #94630 and #21766), so
91 if fail_nametoolong == 0, canonicalize() will return a null length string and
92 do not fail.
93
94 08 June 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox_futils.c:
95 Do not abort if TMPDIR is not valid, but rather use '/tmp', bug #94360. Also
96 make sure we re-export the new TMPDIR environment variable.
97
98 08 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
99 Fix incorrect free of non-malloc'd array, bug #92313 and #94020. Fix noted
100 by Marcus D. Hanwell <cryos@gentoo.org>.
101
102 08 June 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
103 Add /dev/console to write list, bug #38588.
104
105* sandbox-1.2.8 (2005/05/13)
106
107 13 May 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c, sandbox.c,
108 sandbox.h, sandbox_futils.c:
109 General cleanups.
110
111 13 May 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c, sandbox.c,
112 sandbox.h:
113 Various LD_PRELOAD cleanups. Do not unset LD_PRELOAD for parent.
114
115 13 May 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c, sandbox.c,
116 sandbox.h, sandbox_futils.c:
117 Modify get_sandbox_pids_file(), get_sandbox_log() and get_sandbox_debug_log()
118 to use TMPDIR if present in environment.
119
120 13 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
121 Remove sandbox_log_file from main() as its no longer used.
122
123 13 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h,
124 sandbox_futils.c:
125 Add get_sandbox_debug_log(), and use it (add behaviour similar to SANDBOX_LOG
126 if already exported when sandbox started). Fix get_sandbox_log() and new
127 get_sandbox_debug_log() to not use already exported environment variables if
128 they have '/' in them. Use snprintf()'s instead of strncpy()'s. More
129 SB_PATH_MAX fixes.
130
131* sandbox-1.2.7 (2005/05/12)
132
133 12 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h,
134 sandbox_futils.c:
135 More path limit fixes. Declare SB_BUF_LEN global and use it where needed.
136
137 12 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox_futils.c:
138 Fix paths limited to 255 chars. Fix get_sandbox_dir() returning a string
139 with '(null)' in it if we did not call sandbox with absolute path.
140
141 12 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
142 Set SANDBOX_ON *before* doing the child's env stuff, else its not set
143 for the child.
144
145 12 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
146 Remove global preload_adaptable as it is no longer used.
147
148 12 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
149 Rewrite environment stuff to only be set when execve'ing the child process
150 to try and avoid issues like bug #91541 that causes sandbox to crash if
151 we set LD_PRELOAD sandbox side already.
152
153 11 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
154 Move print_sandbox_log() up to make things neater.
155
156 11 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
157 Remove load_preload_libs(), as its not used anymore.
158
159 11 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h:
160 Remove NO_FORK stuff, as its not used, and 'strace -f' works just fine.
161
162 11 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h:
163 Remove USE_SYSTEM_SHELL stuff, as it is not secure, and not in use.
164
165 11 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h:
166 Remove ld.so.preload crap - we are not going to use it again.
167
168 10 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox_futils.c:
169 Fix typo in code that checks if we got valid group information, causing a
170 segmentation fault, bug #91637.
171
172* sandbox-1.2.6 (2005/05/10)
173
174 10 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
175 Do not use LD_PRELOAD if it contains libtsocks.so, as it breaks sandbox
176 for some odd reason, bug #91541.
177
178 09 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
179 Fix typo (sizeof -> strlen).
180
181 08 May 2005; Brian Harring <ferringb@gentoo.org> libsandbox.c:
182 rewrote the sbcontext caching code so it accounts for env changes since lib
183 initialization.
184
185 05 May 2005; Martin Schlemmer <azarah@gentoo.org> configure.in, libctest.c:
186 We create libctest.c via configure, so no need to keep it around. Do some
187 cleanup related to libctest.c and libctest during configure.
188
189 04 May 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
190 Add rename support of symlinks pointing to protected files/directories.
191
192* sandbox-1.2.5 (2005/05/04)
193
194 04 May 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c, sandbox.c,
195 sandbox.bashrc:
196 Do not reset already set LD_PRELOAD when starting sandbox. If LD_PRELOAD is
197 already set, init of the env vars fails for some reason, so do this later on,
198 and do not warn (bug #91431).
199
200 03 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h,
201 sandbox.bashrc:
202 Fixup sandbox and sandbox.bashrc to call bash with the proper .bashrc.
203
204* sandbox-1.2.4 (2005/05/03)
205
206 03 May 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
207 Do not init the env entries with each call, as it creates too many calls to
208 lstat, etc. Should speedup things a bit, bug #91040.
209
210 03 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
211 Add /dev/pty to default write list. Noticed by Morfic.
212
213 02 May 2005; Mike Frysinger <vapier@gentoo.org> configure.in, localdecls.h,
214 sandbox.h:
215 uClibc doesn't support dlvsym() so add a configure check to make sure it doesn't
216 exist. Also update localdecls.h so BROKEN_RTLD_NEXT isn't defined in uClibc.
217
218* sandbox-1.2.3 (2005/04/29)
219
220 29 Apr 2005; Martin Schlemmer <azarah@gentoo.org> configure.in:
221 Do not check for (*&#$(* CXX or F77.
222
223 29 Apr 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
224 Do not append '/' to pathname in filter_path() if it already ends with it.
225
226 28 Apr 2005; Mike Frysinger <vapier@gentoo.org> Makefile.am, configure.in:
227 With az's help, clean up autotools to work with cross-compiling.
228
229* sandbox-1.2.2 (2005/04/28)
4 230
5 28 Apr 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c: 231 28 Apr 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
6 Only check for /dev/{null,zero} for unlink hack, else ricers using /dev/shm 232 Only check for /dev/{null,zero} for unlink hack, else ricers using /dev/shm
7 have issues; bug #90592. 233 have issues; bug #90592.
8 234
9* sandbox-1.2.1 235* sandbox-1.2.1 (2005/04/23)
10 236
11 23 Apr 2005; Martin Schlemmer <azarah@gentoo.org> Makefile.am, canonicalize.c, 237 23 Apr 2005; Martin Schlemmer <azarah@gentoo.org> Makefile.am, canonicalize.c,
12 getcwd.c, libsandbox.c, localdecls.h, sandbox.h, sandbox_futils.c: 238 getcwd.c, libsandbox.c, localdecls.h, sandbox.h, sandbox_futils.c:
13 Make sure all functions used in libsandbox.c is declared static. Define 239 Make sure all functions used in libsandbox.c is declared static. Define
14 SB_STATIC in localdecls.h for this. Include sandbox_futils.c rather than 240 SB_STATIC in localdecls.h for this. Include sandbox_futils.c rather than
15 linking with its object. Hopefully this will fix bug #90153. 241 linking with its object. Hopefully this will fix bug #90153.
16 242
17* sandbox-1.2 243* sandbox-1.2 (2005/04/23)
18 244
19 22 Mar 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c: 245 22 Mar 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
20 Allow lchown a symlink in write-allowed path pointing to write-denied 246 Allow lchown a symlink in write-allowed path pointing to write-denied
21 target. 247 target.
22 248

Legend:
Removed from v.47  
changed lines
  Added in v.147

  ViewVC Help
Powered by ViewVC 1.1.20