diff --git a/debian/changelog b/debian/changelog index 43c8bc9..c92976b 100644 --- a/debian/changelog +++ b/debian/changelog @@ -1,16 +1,21 @@ -sudo (1.9.16p2-3deepin2) unstable; urgency=medium +sudo (1.9.16p2-3+deb13u2) trixie; urgency=medium - * Fix CVE-2026-35535: exec_mailer: Set group as well as uid when - running the mailer. + * cherry-pick upstream exec_mailer-Set-group-as-well-as-uid. + This is upstream and fixes CVE-2026-35535: + https://github.com/sudo-project/sudo/commit/3e474c2 (Closes: #1130593) - -- deepin-ci-robot Mon, 13 Apr 2026 21:24:10 +0800 + -- Marc Haber Sat, 11 Apr 2026 14:21:02 +0200 -sudo (1.9.16p2-3deepin1) unstable; urgency=medium +sudo (1.9.16p2-3+deb13u1) trixie; urgency=medium - [ zhouzilong ] - * add develper mode verify message. + [ Marc Haber ] + * add upstream patch: Do not perform path expansion + Thanks to Adam D. Barratt" (Closes: #1126085) + * Enable Intel CET on amd64 only. + Thanks to Marcos Del Sol Vives (Closes: #1124339) + * Pull more robust test suite from unstable - -- Tianyu Chen Mon, 30 Jun 2025 23:01:07 +0800 + -- Marc Haber Wed, 11 Feb 2026 20:22:01 +0100 sudo (1.9.16p2-3) unstable; urgency=high diff --git a/debian/patches/cve_2026_35535.patch b/debian/patches/0006-exec_mailer-Set-group-as-well-as-uid-when-running-th.patch similarity index 67% rename from debian/patches/cve_2026_35535.patch rename to debian/patches/0006-exec_mailer-Set-group-as-well-as-uid-when-running-th.patch index 565d20b..7022a44 100644 --- a/debian/patches/cve_2026_35535.patch +++ b/debian/patches/0006-exec_mailer-Set-group-as-well-as-uid-when-running-th.patch @@ -1,10 +1,10 @@ -Description: exec_mailer: Set group as well as uid when running the mailer. - Also make a setuid(), setgid() or setgroups() failure fatal. -Author: Todd C. Miller -Origin: upstream -Bug: https://security-tracker.debian.org/tracker/CVE-2026-35535 -Forwarded: not-needed -Last-Update: 2026-04-13 +From: "Todd C. Miller" +Date: Sat, 8 Nov 2025 15:34:02 -0700 +Subject: exec_mailer: Set group as well as uid when running the mailer + +Also make a setuid(), setgid() or setgroups() failure fatal. + +Found by the ZeroPath AI Security Engineer --- include/sudo_eventlog.h | 3 ++- lib/eventlog/eventlog.c | 21 +++++++++++++++++---- @@ -12,10 +12,11 @@ Last-Update: 2026-04-13 plugins/sudoers/logging.c | 2 +- plugins/sudoers/policy.c | 2 +- 5 files changed, 24 insertions(+), 8 deletions(-) -Index: github-sudo-CVE-2026-35535/include/sudo_eventlog.h -=================================================================== ---- github-sudo-CVE-2026-35535.orig/include/sudo_eventlog.h -+++ github-sudo-CVE-2026-35535/include/sudo_eventlog.h + +diff --git a/include/sudo_eventlog.h b/include/sudo_eventlog.h +index eb9f4f4..485d259 100644 +--- a/include/sudo_eventlog.h ++++ b/include/sudo_eventlog.h @@ -80,6 +80,7 @@ struct eventlog_config { int syslog_rejectpri; int syslog_alertpri; @@ -24,7 +25,7 @@ Index: github-sudo-CVE-2026-35535/include/sudo_eventlog.h bool omit_hostname; const char *logpath; const char *time_fmt; -@@ -151,7 +152,7 @@ void eventlog_set_syslog_rejectpri(int p +@@ -151,7 +152,7 @@ void eventlog_set_syslog_rejectpri(int pri); void eventlog_set_syslog_alertpri(int pri); void eventlog_set_syslog_maxlen(size_t len); void eventlog_set_file_maxlen(size_t len); @@ -33,10 +34,10 @@ Index: github-sudo-CVE-2026-35535/include/sudo_eventlog.h void eventlog_set_omit_hostname(bool omit_hostname); void eventlog_set_logpath(const char *path); void eventlog_set_time_fmt(const char *fmt); -Index: github-sudo-CVE-2026-35535/lib/eventlog/eventlog.c -=================================================================== ---- github-sudo-CVE-2026-35535.orig/lib/eventlog/eventlog.c -+++ github-sudo-CVE-2026-35535/lib/eventlog/eventlog.c +diff --git a/lib/eventlog/eventlog.c b/lib/eventlog/eventlog.c +index 5a32824..d56c4e4 100644 +--- a/lib/eventlog/eventlog.c ++++ b/lib/eventlog/eventlog.c @@ -304,15 +304,13 @@ exec_mailer(int pipein) syslog(LOG_ERR, _("unable to dup stdin: %m")); // -V618 sudo_debug_printf(SUDO_DEBUG_ERROR, @@ -89,11 +90,11 @@ Index: github-sudo-CVE-2026-35535/lib/eventlog/eventlog.c } /* Send a message to the mailto user */ -Index: github-sudo-CVE-2026-35535/lib/eventlog/eventlog_conf.c -=================================================================== ---- github-sudo-CVE-2026-35535.orig/lib/eventlog/eventlog_conf.c -+++ github-sudo-CVE-2026-35535/lib/eventlog/eventlog_conf.c -@@ -70,6 +70,7 @@ static struct eventlog_config evl_conf = +diff --git a/lib/eventlog/eventlog_conf.c b/lib/eventlog/eventlog_conf.c +index 0663a38..ec3b569 100644 +--- a/lib/eventlog/eventlog_conf.c ++++ b/lib/eventlog/eventlog_conf.c +@@ -70,6 +70,7 @@ static struct eventlog_config evl_conf = { MAXSYSLOGLEN, /* syslog_maxlen */ 0, /* file_maxlen */ ROOT_UID, /* mailuid */ @@ -113,11 +114,11 @@ Index: github-sudo-CVE-2026-35535/lib/eventlog/eventlog_conf.c } void -Index: github-sudo-CVE-2026-35535/plugins/sudoers/logging.c -=================================================================== ---- github-sudo-CVE-2026-35535.orig/plugins/sudoers/logging.c -+++ github-sudo-CVE-2026-35535/plugins/sudoers/logging.c -@@ -1155,7 +1155,7 @@ init_eventlog_config(void) +diff --git a/plugins/sudoers/logging.c b/plugins/sudoers/logging.c +index bd4de92..9535289 100644 +--- a/plugins/sudoers/logging.c ++++ b/plugins/sudoers/logging.c +@@ -1157,7 +1157,7 @@ init_eventlog_config(void) eventlog_set_syslog_alertpri(def_syslog_badpri); eventlog_set_syslog_maxlen(def_syslog_maxlen); eventlog_set_file_maxlen(def_loglinelen); @@ -126,11 +127,11 @@ Index: github-sudo-CVE-2026-35535/plugins/sudoers/logging.c eventlog_set_omit_hostname(!def_log_host); eventlog_set_logpath(def_logfile); eventlog_set_time_fmt(def_log_year ? "%h %e %T %Y" : "%h %e %T"); -Index: github-sudo-CVE-2026-35535/plugins/sudoers/policy.c -=================================================================== ---- github-sudo-CVE-2026-35535.orig/plugins/sudoers/policy.c -+++ github-sudo-CVE-2026-35535/plugins/sudoers/policy.c -@@ -639,7 +639,7 @@ sudoers_policy_deserialize_info(struct s +diff --git a/plugins/sudoers/policy.c b/plugins/sudoers/policy.c +index f3adfb0..27f6e58 100644 +--- a/plugins/sudoers/policy.c ++++ b/plugins/sudoers/policy.c +@@ -639,7 +639,7 @@ sudoers_policy_deserialize_info(struct sudoers_context *ctx, void *v, } #ifdef NO_ROOT_MAILER diff --git a/debian/patches/0008-open_sudoers-Do-not-perform-path-expansion-on-files-.patch b/debian/patches/0008-open_sudoers-Do-not-perform-path-expansion-on-files-.patch new file mode 100644 index 0000000..0afe744 --- /dev/null +++ b/debian/patches/0008-open_sudoers-Do-not-perform-path-expansion-on-files-.patch @@ -0,0 +1,34 @@ +From: "Todd C. Miller" +Date: Sat, 24 Jan 2026 11:30:06 -0700 +Subject: open_sudoers: Do not perform path expansion on files in an + includedir + +A file in an includedir containing one or more colons (':') in the +name we was being expanded as a colon-separated path instead of +being opened as-is. This fixes a regression introduced in +sudo 1.9.14. Bug #1085 +--- + plugins/sudoers/sudoers.c | 10 +++++++++- + 1 file changed, 9 insertions(+), 1 deletion(-) + +diff --git a/plugins/sudoers/sudoers.c b/plugins/sudoers/sudoers.c +index 0f75c96..fecd279 100644 +--- a/plugins/sudoers/sudoers.c ++++ b/plugins/sudoers/sudoers.c +@@ -1286,7 +1286,15 @@ open_sudoers(const char *path, char **outfile, bool doedit, bool *keepopen) + int error, fd; + debug_decl(open_sudoers, SUDOERS_DEBUG_PLUGIN); + +- fd = sudo_open_conf_path(path, fname, sizeof(fname), open_file); ++ if (outfile == NULL) { ++ /* Single file, do not treat as a path. */ ++ fd = open_file(path, O_RDONLY|O_NONBLOCK); ++ if (fd != -1) ++ (void)fcntl(fd, F_SETFL, fcntl(fd, F_GETFL, 0) & ~O_NONBLOCK); ++ } else { ++ /* Could be a colon-separated path of file names. */ ++ fd = sudo_open_conf_path(path, fname, sizeof(fname), open_file); ++ } + if (sudoers_ctx.parser_conf.ignore_perms) { + /* Skip sudoers security checks when ignore_perms is set. */ + if (fd == -1 || fstat(fd, &sb) == -1) diff --git a/debian/patches/amd64-ibt.diff b/debian/patches/amd64-ibt.diff new file mode 100644 index 0000000..0ad20fd --- /dev/null +++ b/debian/patches/amd64-ibt.diff @@ -0,0 +1,28 @@ +From: Marcos Del Sol Vives +Date: Tue, 2 Sep 2025 00:00:35 +0200 +Subject: Enable Intel CET on amd64 only + +--- + m4/hardening.m4 | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/m4/hardening.m4 b/m4/hardening.m4 +index f7d2a8c..cc7ee01 100644 +--- a/m4/hardening.m4 ++++ b/m4/hardening.m4 +@@ -105,6 +105,7 @@ AC_DEFUN([SUDO_CHECK_HARDENING], [ + ]) + fi + ++ if test "$host_cpu" = "x86_64"; then + # Check for control-flow transfer instrumentation (Intel CET). + AX_CHECK_COMPILE_FLAG([-fcf-protection], [ + AX_CHECK_LINK_FLAG([-fcf-protection], [ +@@ -112,6 +113,7 @@ AC_DEFUN([SUDO_CHECK_HARDENING], [ + AX_APPEND_FLAG([-Wc,-fcf-protection], [HARDENING_LDFLAGS]) + ]) + ]) ++ fi + fi + + # Linker-specific hardening flags. diff --git a/debian/patches/developer-mode-verify.patch b/debian/patches/developer-mode-verify.patch deleted file mode 100644 index 8499d78..0000000 --- a/debian/patches/developer-mode-verify.patch +++ /dev/null @@ -1,87 +0,0 @@ -From 69ef2673766f4ea918a5b8290eb30db5db409a3a Mon Sep 17 00:00:00 2001 -From: zhouzilong -Date: Wed, 23 Apr 2025 15:45:55 +0800 -Subject: [PATCH] developer mode verify - ---- - plugins/sudoers/auth/pam.c | 7 +++++++ - plugins/sudoers/po/zh_CN.po | 11 ++++++----- - 2 files changed, 13 insertions(+), 5 deletions(-) - -diff --git a/plugins/sudoers/auth/pam.c b/plugins/sudoers/auth/pam.c -index 973d67b..d0cabc8 100644 ---- a/plugins/sudoers/auth/pam.c -+++ b/plugins/sudoers/auth/pam.c -@@ -298,6 +298,7 @@ sudo_pam_verify(const struct sudoers_context *ctx, struct passwd *pw, - const char *prompt, sudo_auth *auth, struct sudo_conv_callback *callback) - { - const char *envccname, *pam_user; -+ const char *pam_item; - int rc, *pam_status = (int *)auth->data; - debug_decl(sudo_pam_verify, SUDOERS_DEBUG_AUTH); - -@@ -355,6 +356,12 @@ sudo_pam_verify(const struct sudoers_context *ctx, struct passwd *pw, - sudo_debug_printf(SUDO_DEBUG_WARN|SUDO_DEBUG_LINENO, - "pam_authenticate: %d", *pam_status); - debug_return_int(AUTH_FAILURE); -+ case PAM_ABORT: -+ rc = pam_get_item(pamh, PAM_SERVICE, &pam_item); -+ if((rc == PAM_SUCCESS)&&(!strcmp(pam_item, "security-verify"))){ -+ log_warningx(ctx, 0, N_("No root privileges. Please request root access in developer mode in Control Center.")); -+ debug_return_int(AUTH_ERROR); -+ } - default: - log_warningx(ctx, 0, N_("PAM authentication error: %s"), - sudo_pam_strerror(pamh, *pam_status)); -diff --git a/plugins/sudoers/po/zh_CN.po b/plugins/sudoers/po/zh_CN.po -index 00b5214..1194283 100644 ---- a/plugins/sudoers/po/zh_CN.po -+++ b/plugins/sudoers/po/zh_CN.po -@@ -8,7 +8,7 @@ msgstr "" - "Project-Id-Version: sudoers 1.9.16b1\n" - "Report-Msgid-Bugs-To: https://bugzilla.sudo.ws\n" - "POT-Creation-Date: 2024-06-08 09:06-0600\n" --"PO-Revision-Date: 2024-06-17 14:52-0400\n" -+"PO-Revision-Date: 2025-04-23 15:36+0800\n" - "Last-Translator: Boyuan Yang <073plan@gmail.com>\n" - "Language-Team: Chinese (simplified) \n" - "Language: zh_CN\n" -@@ -17,7 +17,7 @@ msgstr "" - "Content-Transfer-Encoding: 8bit\n" - "Plural-Forms: nplurals=1; plural=0;\n" - "X-Bugs: Report translation errors to the Language-Team address.\n" --"X-Generator: Poedit 3.4.4\n" -+"X-Generator: Poedit 2.2.1\n" - - #: confstr.sh:1 gram.y:1240 plugins/sudoers/logging.c:919 - msgid "syntax error" -@@ -1530,6 +1530,10 @@ msgstr "无法初始化 PAM:%s" - msgid "PAM authentication error: %s" - msgstr "PAM 认证出错:%s" - -+#: plugins/sudoers/auth/pam.c:362 -+msgid "No root privileges. Please request root access in developer mode in Control Center." -+msgstr "无root权限,如想获得root权限可以在控制中心选择进入开发者模式" -+ - #: plugins/sudoers/auth/pam.c:369 - msgid "account validation failure, is your account locked?" - msgstr "账户验证失败,您的账户是不是上锁了?" -@@ -3891,15 +3895,12 @@ msgstr "将忽略包含“.”字符的文件名" - msgid "too many levels of includes" - msgstr "include 嵌套层数过多" - --#, c-format - #~ msgid "%s must be owned by uid %d" - #~ msgstr "%s 必须属于用户 ID %d" - --#, c-format - #~ msgid "%s must only be writable by owner" - #~ msgstr "%s 必须只对所有者可写" - --#, c-format - #~ msgid "timestamp owner (%s): No such user" - #~ msgstr "时间戳所有者(%s):无此用户" - --- -2.20.1 - diff --git a/debian/patches/series b/debian/patches/series index f9a9455..21e0e90 100644 --- a/debian/patches/series +++ b/debian/patches/series @@ -5,5 +5,6 @@ sudo-ldap-docs.patch X11R6.patch 0007-upstream-patch-for-CVE-2025-32463.patch 0008-upstream-patch-for-CVE-2025-32462.patch -developer-mode-verify.patch -cve_2026_35535.patch +0008-open_sudoers-Do-not-perform-path-expansion-on-files-.patch +amd64-ibt.diff +0006-exec_mailer-Set-group-as-well-as-uid-when-running-th.patch diff --git a/debian/tests/01-getroot b/debian/tests/01-getroot index 4edef3e..bae4096 100755 --- a/debian/tests/01-getroot +++ b/debian/tests/01-getroot @@ -9,7 +9,7 @@ passwd1=$(echo "$passwd" |cut -c1) # Note: we do need the 'xfoo' syntax here, since POSIX special-cases # the $passwd value '!' as negation. if [ "x$passwd" = "x*" ] || [ "x$passwd1" = "x!" ]; then - echo "root:rootpassword" | chpasswd + echo "root:riegh@oh4ahR" | chpasswd fi TESTNR="01" @@ -19,7 +19,7 @@ DIR="${BASEDIR}/${TESTNR}" PATH="/bin:/usr/bin:/sbin:/usr/sbin" ACCTA="test${TESTNR}a" ACCTB="test${TESTNR}b" -PASSWD="test${TESTNR}23456" +PASSWD="test${TESTNR}Terah9ien7e" HOMEDIRA="/home/${ACCTA}" HOMEDIRB="/home/${ACCTB}" LDIFDIR="${DIR}/ldif" diff --git a/debian/tests/02-1003969-audit-no-resolve b/debian/tests/02-1003969-audit-no-resolve index 3fc32aa..11d2aaf 100755 --- a/debian/tests/02-1003969-audit-no-resolve +++ b/debian/tests/02-1003969-audit-no-resolve @@ -7,21 +7,29 @@ BASEDIR="$(pwd)/debian/tests" COMMONDIR="${BASEDIR}/common" DIR="${BASEDIR}/${TESTNR}" PATH="/bin:/usr/bin:/sbin:/usr/sbin" -ACCTA="test${TESTNR}a" -ACCTB="test${TESTNR}b" -PASSWD="test${TESTNR}23456" HOMEDIRA="/root" -LDIFDIR="${DIR}/ldif" trap ' printf "\ntrap handler\n" - mv /etc/resolv.conf.disabled /etc/resolv.conf || true - mv /etc/hosts.disabled /etc/hosts || true + if [ -e /etc/resolv.conf.disabled ]; then + cp /etc/resolv.conf.disabled /etc/resolv.conf || true + rm -f /etc/resolv.conf.disabled || true + fi + if [ -e /etc/hosts.disabled ]; then + cp /etc/hosts.disabled /etc/hosts || true + rm -f /etc/hosts.disabled || true + fi ' 0 INT QUIT ABRT PIPE TERM printf "========= test %s\.1: sudo to nobody\n" "${TESTNR}" -mv /etc/resolv.conf /etc/resolv.conf.disabled -mv /etc/hosts /etc/hosts.disabled +if [ -e /etc/resolv.conf ]; then + cp /etc/resolv.conf /etc/resolv.conf.disabled + : >/etc/resolv.conf +fi +if [ -e /etc/hosts ]; then + cp /etc/hosts /etc/hosts.disabled + : >/etc/hosts +fi RET=0 printf "trying sudo to nobody\n" cd "${HOMEDIRA}" @@ -35,7 +43,7 @@ if [ "${STDERRLENGTH}" != "0" ]; then printf >&2 "stderr:\n" cat >&2 ${HOMEDIRA}/stderr printf >&2 "exit code %s\n" "${RET}" - printf >&2 "exit 1\n" "${RET}" + printf >&2 "exit 1\n" exit 1 fi diff --git a/debian/tests/03-1126085-sudoersd b/debian/tests/03-1126085-sudoersd new file mode 100755 index 0000000..119157a --- /dev/null +++ b/debian/tests/03-1126085-sudoersd @@ -0,0 +1,32 @@ +#!/bin/sh + +set -e + +TESTNR="03" +BASEDIR="$(pwd)/debian/tests" +COMMONDIR="${BASEDIR}/common" +DIR="${BASEDIR}/${TESTNR}" +PATH="/bin:/usr/bin:/sbin:/usr/sbin" +FILES="$(find $DIR/sudoersd/ -type f)" +echo $FILES +DSTFILES="$(echo $FILES | sed "s|${DIR}/sudoersd|/etc/sudoers.d|g")" +echo $DSTFILES + +trap ' + true +' 0 INT QUIT ABRT PIPE TERM + +printf "copy files to sudoers ... " +cp $FILES /etc/sudoers.d/ +printf "collect sudo -l output ... " +OUTPUT="$(sudo -l | grep -- ----marker----)" +EXPECTED=" (ALL : ALL) /usr/bin/----marker----/this-is-the-sudoersd-10_dsa\:\:util\:\:sudo[dfsg-team-role]-file + (ALL : ALL) /usr/bin/----marker----/this-is-the-sudoersd-root-file" +if [ "$OUTPUT" != "$EXPECTED" ]; then + printf "sudo -l output not as expected, Test failed\n" + exit 1 +fi + +printf "test series sucessful, exit 0\n" +exit 0 + diff --git a/debian/tests/03/10_dsa::util::sudo[dfsg-team-role] b/debian/tests/03/10_dsa::util::sudo[dfsg-team-role] new file mode 100644 index 0000000..0a77cf3 --- /dev/null +++ b/debian/tests/03/10_dsa::util::sudo[dfsg-team-role] @@ -0,0 +1 @@ +root ALL=(ALL:ALL) /usr/bin/----marker----/this-is-the-sudoersd-10_dsa\:\:util\:\:sudo[dfsg-team-role]-file diff --git a/debian/tests/03/root b/debian/tests/03/root new file mode 100644 index 0000000..12a03fd --- /dev/null +++ b/debian/tests/03/root @@ -0,0 +1 @@ +root ALL=(ALL:ALL) /usr/bin/----marker----/this-is-the-sudoersd-root-file diff --git a/debian/tests/03/sudoersd/10_dsa::util::sudo[dfsg-team-role] b/debian/tests/03/sudoersd/10_dsa::util::sudo[dfsg-team-role] new file mode 100644 index 0000000..0a77cf3 --- /dev/null +++ b/debian/tests/03/sudoersd/10_dsa::util::sudo[dfsg-team-role] @@ -0,0 +1 @@ +root ALL=(ALL:ALL) /usr/bin/----marker----/this-is-the-sudoersd-10_dsa\:\:util\:\:sudo[dfsg-team-role]-file diff --git a/debian/tests/03/sudoersd/root b/debian/tests/03/sudoersd/root new file mode 100644 index 0000000..12a03fd --- /dev/null +++ b/debian/tests/03/sudoersd/root @@ -0,0 +1 @@ +root ALL=(ALL:ALL) /usr/bin/----marker----/this-is-the-sudoersd-root-file diff --git a/debian/tests/04-getroot-sssd b/debian/tests/04-getroot-sssd index bcafaf8..5b08018 100755 --- a/debian/tests/04-getroot-sssd +++ b/debian/tests/04-getroot-sssd @@ -17,58 +17,89 @@ HOMEDIRA="/home/${ACCTA}" HOMEDIRB="/home/${ACCTB}" LDIFDIR="${DIR}/ldif" SSSDCONF="/etc/sssd/sssd.conf" +RUNDIR="/run/slapd" +VARRUNDIR="/var/run/slapd" trap ' kill $(pidof slapd) 2>/dev/null || true kill $(pidof sssd) 2>/dev/null || true + kill $(pidof socat) 2>/dev/null || true + rm -f /dev/log || true ' 0 INT QUIT ABRT PIPE TERM # openssl req -x509 -days 365 -nodes -newkey rsa:4096 -keyout server_key.pem -out server_cert.pem --subj "/C=DE/CN=emptysid86.zugschlus.de" +printf "make and chown dirs ... " +mkdir -p "${RUNDIR}" "${VARRUNDIR}" +chown openldap "${VARRUNDIR}" < ${LDIFDIR}/debconf debconf-set-selections + printf "clean up ldap database ... " rm -rf /var/lib/ldap/*.mdb + printf "move configuration in place ... " mkdir -p /etc/ldap /etc/sssd cp ${LDIFDIR}/server_*.pem /etc/ldap/ cp ${LDIFDIR}/ldap.conf /etc/ldap/ chown openldap:openldap /etc/ldap/server_*.pem chmod 600 /etc/ldap/server_key.pem +# slapd.conf is only needed for OpenLDAP 2.4 on bullseye +# but since it's already there now, use it for OpenLDAP 2.5+ as well +# this is a testsuite. If you want /etc/ldap/slapd.d to be used (again), +# please submit a patch that will also work on bullseye. +cp ${LDIFDIR}/slapd.conf /etc/ldap/ cp ${LDIFDIR}/sssd.conf /etc/sssd chown root:root /etc/sssd/sssd.conf chmod 600 /etc/sssd/sssd.conf cp ${LDIFDIR}/slapd-default /etc/default/slapd echo "slapd: [::1]" >> /etc/hosts.allow + printf "reconfigure slapd ... " DEBIAN_FRONTEND=noninteractive dpkg-reconfigure -pcritical slapd 2>/dev/null kill $(pidof slapd) 2>/dev/null || true sleep 1 + +if ! [ -S /dev/log ]; then + echo "starting fake syslog socket on /dev/log" + + # remove stale file if present + [ -e /dev/log ] && rm -f /dev/log + + socat -u UNIX-RECV:/dev/log,mode=666 STDOUT >/dev/null 2>/dev/null & +fi + printf "start slapd ... " -slapd -h "ldaps:/// ldapi:///" -g openldap -u openldap -F /etc/ldap/slapd.d +slapd -f /etc/ldap/slapd.conf -h "ldaps://:1636/ ldapi:///" -g openldap -u openldap + +printf "check slapd running .... " +pgrep -a slapd # ldapsearch -x -LLL -s base -b "" namingContexts should work here -printf "set LDAP passwords" -ldapmodify -Y external -H ldapi:/// -f ${LDIFDIR}/tls.ldif 2>/dev/null -ldapmodify -Y external -H ldapi:/// -f ${LDIFDIR}/adminpw.ldif 2>/dev/null -ldapmodify -Y external -H ldapi:/// -f ${LDIFDIR}/adminpw-example-com.ldif 2>/dev/null -printf "add users and groups OUs ..." -ldapadd -x -D "cn=admin,dc=example,dc=com" -w ldappw -f ${LDIFDIR}/sss-ous.ldif 2>/dev/null -printf "add users ..." + +printf "add users and groups OUs ...\n" +ldapadd -x -c -D "cn=admin,dc=example,dc=com" -w ldappw -f ${LDIFDIR}/sss-ous.ldif 2>/dev/null || true printf "sssd.conf ...\n" cp ${LDIFDIR}/sssd.conf "${SSSDCONF}" -printf "sudoers file ...\n"A +printf "sudoers file ...\n" mkdir -p /etc/sudoers.d/ -mv ${LDIFDIR}/ldapsudoers /etc/sudoers.d/ +cp ${LDIFDIR}/ldapsudoers /etc/sudoers.d/ chown root:root "${SSSDCONF}" /etc/sudoers.d/ /etc/sudoers.d/* chmod 755 /etc/sudoers.d/ chmod 600 "${SSSDCONF}" /etc/sudoers.d/* + +printf "start sssd ..." kill $(pidof sssd) 2>/dev/null || true sleep 1 sssd --logger=files -D +printf "check sssd running .... " +pgrep -a sssd + +printf "add users ..." for user in testuser1 testuser2; do ldapadd -x -D "cn=admin,dc=example,dc=com" -w ldappw -f ${LDIFDIR}/${user}.ldif 2>/dev/null + getent passwd ${user} mkdir -p /home/${user} chown ${user}:nogroup /home/${user} done diff --git a/debian/tests/04/ldif/ldap.conf b/debian/tests/04/ldif/ldap.conf index 3f3000a..b3b3022 100644 --- a/debian/tests/04/ldif/ldap.conf +++ b/debian/tests/04/ldif/ldap.conf @@ -1,5 +1,5 @@ BASE dc=example,dc=com -URI ldaps://[::1]:636/ +URI ldaps://[::1]:1636/ TLS_CACERT /etc/ldap/server_cert.pem TLS_REQCERT allow SASL_NOCANON on diff --git a/debian/tests/04/ldif/slapd.conf b/debian/tests/04/ldif/slapd.conf new file mode 100644 index 0000000..9fe0727 --- /dev/null +++ b/debian/tests/04/ldif/slapd.conf @@ -0,0 +1,22 @@ +# OpenLDAP 2.4 (bullseye) only +modulepath /usr/lib/ldap +moduleload back_mdb +include /etc/ldap/schema/core.schema +include /etc/ldap/schema/cosine.schema +include /etc/ldap/schema/nis.schema +include /etc/ldap/schema/inetorgperson.schema + +database mdb +maxsize 1073741824 +directory /var/lib/ldap + +# Suffix and root DN must come in this order +suffix "dc=example,dc=com" +rootdn "cn=admin,dc=example,dc=com" +rootpw ldappw + +# TLS optional +TLSCertificateFile /etc/ldap/server_cert.pem +TLSCertificateKeyFile /etc/ldap/server_key.pem +TLSCACertificateFile /etc/ldap/server_cert.pem + diff --git a/debian/tests/04/ldif/sss-ous.ldif b/debian/tests/04/ldif/sss-ous.ldif index 5ba018c..144b2fa 100644 --- a/debian/tests/04/ldif/sss-ous.ldif +++ b/debian/tests/04/ldif/sss-ous.ldif @@ -1,3 +1,10 @@ +dn: dc=example,dc=com +objectClass: top +objectClass: dcObject +objectClass: organization +o: Example Organization +dc: example + dn: ou=users,dc=example,dc=com objectClass: top objectClass: organizationalUnit diff --git a/debian/tests/04/ldif/sssd.conf b/debian/tests/04/ldif/sssd.conf index ee06ef5..b0b4796 100755 --- a/debian/tests/04/ldif/sssd.conf +++ b/debian/tests/04/ldif/sssd.conf @@ -7,7 +7,7 @@ debug_level = 0x01ff id_provider = ldap auth_provider = ldap -ldap_uri = ldaps://[::1]:636/ +ldap_uri = ldaps://[::1]:1636/ ldap_search_base = dc=example,dc=com ldap_tls_cacert = /etc/ldap/server_cert.pem diff --git a/debian/tests/04/ldif/tls.ldif b/debian/tests/04/ldif/tls.ldif index 012adf2..a84b4c1 100644 --- a/debian/tests/04/ldif/tls.ldif +++ b/debian/tests/04/ldif/tls.ldif @@ -1,10 +1,32 @@ +dn: cn=config +changetype: modify +delete: olcTLSCACertificateFile +- + +dn: cn=config +changetype: modify +delete: olcTLSCertificateFile +- + +dn: cn=config +changetype: modify +delete: olcTLSCertificateKeyFile +- + dn: cn=config changetype: modify add: olcTLSCACertificateFile olcTLSCACertificateFile: /etc/ldap/server_cert.pem - + +dn: cn=config +changetype: modify +add: olcTLSCertificateFile +olcTLSCertificateFile: /etc/ldap/server_cert.pem +- + +dn: cn=config +changetype: modify add: olcTLSCertificateKeyFile olcTLSCertificateKeyFile: /etc/ldap/server_key.pem - -add: olcTLSCertificateFile -olcTLSCertificateFile: /etc/ldap/server_cert.pem diff --git a/debian/tests/control b/debian/tests/control index abea94c..dcb8429 100644 --- a/debian/tests/control +++ b/debian/tests/control @@ -1,16 +1,11 @@ Tests: 01-getroot -Depends: sudo, adduser +Depends: adduser, sudo, cracklib-runtime Restrictions: needs-root Tests: 02-1003969-audit-no-resolve Depends: sudo Restrictions: needs-root -Tests: 03-getroot-ldap -Depends: sudo-ldap, adduser, slapd, ldap-utils, cron -Restrictions: needs-root - Tests: 04-getroot-sssd -Depends: sudo, adduser, slapd, ldap-utils, sssd-common, sssd-ldap, cron +Depends: adduser, cron, ldap-utils, procps, slapd, sssd-common, sssd-ldap, sudo, socat, libnss-sss, libpam-sss Restrictions: needs-root - diff --git a/plugins/sudoers/po/zh_CN.mo b/plugins/sudoers/po/zh_CN.mo index de42b0f..ee28ea3 100644 Binary files a/plugins/sudoers/po/zh_CN.mo and b/plugins/sudoers/po/zh_CN.mo differ