/[path-sandbox]/trunk/ChangeLog.0
Gentoo

Diff of /trunk/ChangeLog.0

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

Revision 47 Revision 165
1# ChangeLog for Path Sandbox 1# ChangeLog for Path Sandbox
2# Copyright 1999-2004 Gentoo Foundation; Distributed under the GPL v2 2# Copyright 1999-2005 Gentoo Foundation; Distributed under the GPL v2
3# $Header$ 3# $Header$
4
5 12 Sep 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
6
7 Do not handle adding working directory to SANDBOX_WRITE, as portage does it
8 itself.
9
10 04 Sep 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
11
12 Also allow symlink() system call to operate on a symlink in a writable path
13 that points to non-writable path, bug #104711.
14
15* sandbox-1.2.12 (2005/08/05)
16
17 05 Aug 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c, sandbox.c,
18 sandbox.h:
19
20 Do not give an access violation if the access() system call do not have
21 write/read access - it does not actually modify, so we only need to return
22 not being able to write/read. Noted by Andres Loeh <kosmikus@gentoo.org>,
23 bug #101433.
24
25 If we are called from the command line, do not care about PORTAGE_TMPDIR,
26 and make the current directory the work directory. Also rename the variable
27 portage_tmp_dir to work_dir.
28
29 Remove the tmp_dir variable - we do not need it.
30
31 Improve error handling for get_sandbox_*_envvar() functions.
32
33 01 Aug 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
34
35 Still do normal log if debugging is requested.
36
37 Add support for SANDBOX_VERBOSE (enabled by default). Adjust SANDBOX_DEBUG
38 to only enable if equal to "1" or "yes".
39
40 Add /dev/tts to write permit, bug #42809.
41
42 27 July 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h,
43 sandbox_futils.c:
44
45 Do not resolve symlinks in PORTAGE_TMPDIR in sandbox .. we will handle that
46 in libsandbox .. bug #100309.
47
48 22 July 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.h:
49
50 Print all logging to stderr, bug #90343, comment #15, by Zac Medico.
51
52* sandbox-1.2.11 (2005/07/14)
53
54 14 July 2005; Martin Schlemmer <azarah@gentoo.org> getcwd.c:
55 Fix getcwd, bug #98419.
56
57 08 July 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox_futils.c,
58 libsandbox.c:
59 - Try to cleanup and make error handling/printing consistent.
60 - Remove old logs if present and conflicting with current.
61 - Fix compile error with previous change, and return rather then exit().
62
63 07 July 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c, sandbox.c,
64 sandbox.h, sandbox_futils.c:
65 - Fix possible segfault in env init code.
66 - Major cleanup of sandbox_futils.c. Removed most of the functions as we now
67 write to /var/log/sandbox/, so in theory do not need all that.
68 - Redo the interface of the get_* functions so that we do not leak memory.
69 - Remove sandbox_dir and co - we are not using it anymore.
70 - Remove unused includes and variables.
71 - Only declare functions in sandbox_futils.c that are used in libsandbox.c when
72 OUTSIDE_LIBSANDBOX is not defined.
73 - Cleanup access/log printing. Make access printing honour NOCOLOR. Fix log
74 printing's last line not honouring NOCOLOR.
75
76 06 July 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.h, sandbox_futils.c,
77 libsandbox.c:
78 - Change log dir to /var/log/sandbox/. Make sure the sandboxed process cannot
79 write to it.
80 - Clean up logging in libsandbox.c, and hopefully make it more consistant.
81 - Add check_prefixes() with major cleanup on check_access().
82 - Cleanup init_env_entries() and check_prefixes().
83
84 05 July 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h,
85 sandbox_futils.c, libsandbox.c:
86 Remove unused 'pids file' code.
87
88* sandbox-1.2.10 (2005/07/03)
89
90 03 July 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
91 Add PREDICT items for nss-db, bug #92079. Patch from Robin Johnson.
92
93 17 June 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
94 General cleanups:
95 - Remove fooling around with exit codes - we error out on presence of a log
96 anyhow.
97 - Move get_sandbox_*_envvar() to sandbox_setup_environ(), as its more
98 appropriate there.
99
100 12 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
101 Cleanup the fail_nametoolong stuff a bit more.
102
103 11 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
104 Remove hopefully the last ld.so.preload bits we do not use anymore.
105
106 11 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
107 Remove the unneeded canonicalize() calls in the wrappers - we do it anyhow
108 in check_syscall(). Should speed things up a bit (at least for the getcwd()
109 and long path name test it goes down to under a second, and not 10+ seconds
110 like before). Also warn if we skip checking due to the canonicalized path
111 being too long.
112
113 11 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
114 More comment/readability cleanups.
115
116 10 June 2005; Martin Schlemmer <azarah@gentoo.org> canonicalize.c, getcwd.c,
117 sandbox_futils.c, libsandbox.c:
118 Some strncpy/strncat and other cleanups.
119
120* sandbox-1.2.9 (2005/06/09)
121
122 09 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
123 Move symlink hack down a bit to try and minimize on the amount of lstat()
124 calls we do.
125
126 09 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c, sandbox.c:
127 Add hack to allow writing to /proc/self/fd (or /dev/fd), bug #91516.
128
129 09 June 2005; Martin Schlemmer <azarah@gentoo.org> symbols.in, libsandbox.c:
130 Add wrapper for access() function, bug #85413.
131
132 09 June 2005; Martin Schlemmer <azarah@gentoo.org> getcwd.c:
133 Use generic getcwd() implementation from uclibc - should be more portable
134 and looks a bit cleaner.
135
136 09 June 2005; Martin Schlemmer <azarah@gentoo.org> getcwd.c, libsandbox.c:
137 Make sure our true_* pointers are initialized to NULL, and that we check for
138 all references that they are valid.
139
140 09 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
141 Be default we will fail if the path name we try to canonicalize is too long.
142 This however could cause issues with some things (bug #94630 and #21766), so
143 if fail_nametoolong == 0, canonicalize() will return a null length string and
144 do not fail.
145
146 08 June 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox_futils.c:
147 Do not abort if TMPDIR is not valid, but rather use '/tmp', bug #94360. Also
148 make sure we re-export the new TMPDIR environment variable.
149
150 08 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
151 Fix incorrect free of non-malloc'd array, bug #92313 and #94020. Fix noted
152 by Marcus D. Hanwell <cryos@gentoo.org>.
153
154 08 June 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
155 Add /dev/console to write list, bug #38588.
156
157* sandbox-1.2.8 (2005/05/13)
158
159 13 May 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c, sandbox.c,
160 sandbox.h, sandbox_futils.c:
161 General cleanups.
162
163 13 May 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c, sandbox.c,
164 sandbox.h:
165 Various LD_PRELOAD cleanups. Do not unset LD_PRELOAD for parent.
166
167 13 May 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c, sandbox.c,
168 sandbox.h, sandbox_futils.c:
169 Modify get_sandbox_pids_file(), get_sandbox_log() and get_sandbox_debug_log()
170 to use TMPDIR if present in environment.
171
172 13 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
173 Remove sandbox_log_file from main() as its no longer used.
174
175 13 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h,
176 sandbox_futils.c:
177 Add get_sandbox_debug_log(), and use it (add behaviour similar to SANDBOX_LOG
178 if already exported when sandbox started). Fix get_sandbox_log() and new
179 get_sandbox_debug_log() to not use already exported environment variables if
180 they have '/' in them. Use snprintf()'s instead of strncpy()'s. More
181 SB_PATH_MAX fixes.
182
183* sandbox-1.2.7 (2005/05/12)
184
185 12 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h,
186 sandbox_futils.c:
187 More path limit fixes. Declare SB_BUF_LEN global and use it where needed.
188
189 12 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox_futils.c:
190 Fix paths limited to 255 chars. Fix get_sandbox_dir() returning a string
191 with '(null)' in it if we did not call sandbox with absolute path.
192
193 12 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
194 Set SANDBOX_ON *before* doing the child's env stuff, else its not set
195 for the child.
196
197 12 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
198 Remove global preload_adaptable as it is no longer used.
199
200 12 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
201 Rewrite environment stuff to only be set when execve'ing the child process
202 to try and avoid issues like bug #91541 that causes sandbox to crash if
203 we set LD_PRELOAD sandbox side already.
204
205 11 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
206 Move print_sandbox_log() up to make things neater.
207
208 11 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
209 Remove load_preload_libs(), as its not used anymore.
210
211 11 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h:
212 Remove NO_FORK stuff, as its not used, and 'strace -f' works just fine.
213
214 11 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h:
215 Remove USE_SYSTEM_SHELL stuff, as it is not secure, and not in use.
216
217 11 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h:
218 Remove ld.so.preload crap - we are not going to use it again.
219
220 10 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox_futils.c:
221 Fix typo in code that checks if we got valid group information, causing a
222 segmentation fault, bug #91637.
223
224* sandbox-1.2.6 (2005/05/10)
225
226 10 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
227 Do not use LD_PRELOAD if it contains libtsocks.so, as it breaks sandbox
228 for some odd reason, bug #91541.
229
230 09 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
231 Fix typo (sizeof -> strlen).
232
233 08 May 2005; Brian Harring <ferringb@gentoo.org> libsandbox.c:
234 rewrote the sbcontext caching code so it accounts for env changes since lib
235 initialization.
236
237 05 May 2005; Martin Schlemmer <azarah@gentoo.org> configure.in, libctest.c:
238 We create libctest.c via configure, so no need to keep it around. Do some
239 cleanup related to libctest.c and libctest during configure.
240
241 04 May 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
242 Add rename support of symlinks pointing to protected files/directories.
243
244* sandbox-1.2.5 (2005/05/04)
245
246 04 May 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c, sandbox.c,
247 sandbox.bashrc:
248 Do not reset already set LD_PRELOAD when starting sandbox. If LD_PRELOAD is
249 already set, init of the env vars fails for some reason, so do this later on,
250 and do not warn (bug #91431).
251
252 03 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h,
253 sandbox.bashrc:
254 Fixup sandbox and sandbox.bashrc to call bash with the proper .bashrc.
255
256* sandbox-1.2.4 (2005/05/03)
257
258 03 May 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
259 Do not init the env entries with each call, as it creates too many calls to
260 lstat, etc. Should speedup things a bit, bug #91040.
261
262 03 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c:
263 Add /dev/pty to default write list. Noticed by Morfic.
264
265 02 May 2005; Mike Frysinger <vapier@gentoo.org> configure.in, localdecls.h,
266 sandbox.h:
267 uClibc doesn't support dlvsym() so add a configure check to make sure it doesn't
268 exist. Also update localdecls.h so BROKEN_RTLD_NEXT isn't defined in uClibc.
269
270* sandbox-1.2.3 (2005/04/29)
271
272 29 Apr 2005; Martin Schlemmer <azarah@gentoo.org> configure.in:
273 Do not check for (*&#$(* CXX or F77.
274
275 29 Apr 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
276 Do not append '/' to pathname in filter_path() if it already ends with it.
277
278 28 Apr 2005; Mike Frysinger <vapier@gentoo.org> Makefile.am, configure.in:
279 With az's help, clean up autotools to work with cross-compiling.
280
281* sandbox-1.2.2 (2005/04/28)
4 282
5 28 Apr 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c: 283 28 Apr 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
6 Only check for /dev/{null,zero} for unlink hack, else ricers using /dev/shm 284 Only check for /dev/{null,zero} for unlink hack, else ricers using /dev/shm
7 have issues; bug #90592. 285 have issues; bug #90592.
8 286
9* sandbox-1.2.1 287* sandbox-1.2.1 (2005/04/23)
10 288
11 23 Apr 2005; Martin Schlemmer <azarah@gentoo.org> Makefile.am, canonicalize.c, 289 23 Apr 2005; Martin Schlemmer <azarah@gentoo.org> Makefile.am, canonicalize.c,
12 getcwd.c, libsandbox.c, localdecls.h, sandbox.h, sandbox_futils.c: 290 getcwd.c, libsandbox.c, localdecls.h, sandbox.h, sandbox_futils.c:
13 Make sure all functions used in libsandbox.c is declared static. Define 291 Make sure all functions used in libsandbox.c is declared static. Define
14 SB_STATIC in localdecls.h for this. Include sandbox_futils.c rather than 292 SB_STATIC in localdecls.h for this. Include sandbox_futils.c rather than
15 linking with its object. Hopefully this will fix bug #90153. 293 linking with its object. Hopefully this will fix bug #90153.
16 294
17* sandbox-1.2 295* sandbox-1.2 (2005/04/23)
18 296
19 22 Mar 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c: 297 22 Mar 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c:
20 Allow lchown a symlink in write-allowed path pointing to write-denied 298 Allow lchown a symlink in write-allowed path pointing to write-denied
21 target. 299 target.
22 300

Legend:
Removed from v.47  
changed lines
  Added in v.165

  ViewVC Help
Powered by ViewVC 1.1.20