From 60eed3195cadf001ef683e96a5e65be5c1a2dde5 Mon Sep 17 00:00:00 2001 From: Scott Garman Date: Tue, 28 Feb 2012 13:45:28 -0800 Subject: sudo: upgrade to 1.8.4 During the upgrade to 1.8.4, the UCB-licensed fnmatch.c was replaced with a non-recursive BSD-licensed version, hence the removal of UCB and addition of BSD in the LICENSE field. This led to checksum changes in the doc/LICENSE file, and we now additionally track the comment headers in redblack.c. These changes were confirmed on the sudo mailing list: http://www.sudo.ws/pipermail/sudo-workers/2012-February/000736.html This upgrade also fixes CVE-2012-0809. (From OE-Core rev: 7147a569758414467c9d022e4c11fbc303e050aa) Signed-off-by: Scott Garman Signed-off-by: Richard Purdie --- meta/recipes-extended/sudo/sudo.inc | 7 ++++--- meta/recipes-extended/sudo/sudo_1.8.3.bb | 29 ----------------------------- meta/recipes-extended/sudo/sudo_1.8.4.bb | 29 +++++++++++++++++++++++++++++ 3 files changed, 33 insertions(+), 32 deletions(-) delete mode 100644 meta/recipes-extended/sudo/sudo_1.8.3.bb create mode 100644 meta/recipes-extended/sudo/sudo_1.8.4.bb (limited to 'meta/recipes-extended/sudo') diff --git a/meta/recipes-extended/sudo/sudo.inc b/meta/recipes-extended/sudo/sudo.inc index 83dd209afa..2168690527 100644 --- a/meta/recipes-extended/sudo/sudo.inc +++ b/meta/recipes-extended/sudo/sudo.inc @@ -3,9 +3,10 @@ DESCRIPTION = "Sudo (superuser do) allows a system administrator to give certain HOMEPAGE = "http://www.sudo.ws" BUGTRACKER = "http://www.sudo.ws/bugs/" SECTION = "admin" -LICENSE = "ISC & UCB & Zlib" -LIC_FILES_CHKSUM = "file://doc/LICENSE;md5=54f1b46c2459ecec3d892618eab44302 \ - file://compat/fnmatch.c;beginline=6;endline=31;md5=5872733146b9eb0deb79e1f664815b85 \ +LICENSE = "ISC & BSD & Zlib" +LIC_FILES_CHKSUM = "file://doc/LICENSE;md5=19f95c610f585c26a836975654807669 \ + file://plugins/sudoers/redblack.c;beginline=1;endline=41;md5=fba1c1dca0951819964dfdc618e81724 \ + file://compat/fnmatch.c;beginline=3;endline=27;md5=67f83ee9bd456557397082f8f1be0efd \ file://compat/getcwd.c;beginline=5;endline=27;md5=449af4cc57fc7d46f42090608ba3e681 \ file://compat/glob.c;beginline=6;endline=31;md5=5872733146b9eb0deb79e1f664815b85 \ file://compat/snprintf.c;beginline=6;endline=31;md5=c98b24f02967c095d7a70ae2e4d4d4ea" diff --git a/meta/recipes-extended/sudo/sudo_1.8.3.bb b/meta/recipes-extended/sudo/sudo_1.8.3.bb deleted file mode 100644 index 99fe5b91e7..0000000000 --- a/meta/recipes-extended/sudo/sudo_1.8.3.bb +++ /dev/null @@ -1,29 +0,0 @@ -require sudo.inc - -PR = "r1" - -SRC_URI = "http://ftp.sudo.ws/sudo/dist/sudo-${PV}.tar.gz \ - file://libtool.patch \ - ${@base_contains('DISTRO_FEATURES', 'pam', '${PAM_SRC_URI}', '', d)}" - -PAM_SRC_URI = "file://sudo.pam" - -SRC_URI[md5sum] = "9e5517bbf3aee420b38c2d1d7a71bcad" -SRC_URI[sha256sum] = "ff1fcc410c5465063ee4912912e29936ea39f017d9a8a57ec76b0ded71b7c3c4" - -DEPENDS += " ${@base_contains('DISTRO_FEATURES', 'pam', 'libpam', '', d)}" -RDEPENDS_${PN} += " ${@base_contains('DISTRO_FEATURES', 'pam', 'pam-plugin-limits pam-plugin-keyinit', '', d)}" - -EXTRA_OECONF += " ${@base_contains('DISTRO_FEATURES', 'pam', '--with-pam', '--without-pam', d)}" - -do_install_append () { - for feature in ${DISTRO_FEATURES}; do - if [ "$feature" = "pam" ]; then - install -D -m 664 ${WORKDIR}/sudo.pam ${D}/${sysconfdir}/pam.d/sudo - break - fi - done - - chmod 4111 $D/usr/bin/sudo - chmod 0440 $D/etc/sudoers -} diff --git a/meta/recipes-extended/sudo/sudo_1.8.4.bb b/meta/recipes-extended/sudo/sudo_1.8.4.bb new file mode 100644 index 0000000000..dfa7291c55 --- /dev/null +++ b/meta/recipes-extended/sudo/sudo_1.8.4.bb @@ -0,0 +1,29 @@ +require sudo.inc + +PR = "r1" + +SRC_URI = "http://ftp.sudo.ws/sudo/dist/sudo-${PV}.tar.gz \ + file://libtool.patch \ + ${@base_contains('DISTRO_FEATURES', 'pam', '${PAM_SRC_URI}', '', d)}" + +PAM_SRC_URI = "file://sudo.pam" + +SRC_URI[md5sum] = "5a54dde137618bbc1dd46bb0ef725d7d" +SRC_URI[sha256sum] = "17a91da1857954aa73445197e6f73d5d50cc8c48719f6db457723bb8badc32a5" + +DEPENDS += " ${@base_contains('DISTRO_FEATURES', 'pam', 'libpam', '', d)}" +RDEPENDS_${PN} += " ${@base_contains('DISTRO_FEATURES', 'pam', 'pam-plugin-limits pam-plugin-keyinit', '', d)}" + +EXTRA_OECONF += " ${@base_contains('DISTRO_FEATURES', 'pam', '--with-pam', '--without-pam', d)}" + +do_install_append () { + for feature in ${DISTRO_FEATURES}; do + if [ "$feature" = "pam" ]; then + install -D -m 664 ${WORKDIR}/sudo.pam ${D}/${sysconfdir}/pam.d/sudo + break + fi + done + + chmod 4111 $D/usr/bin/sudo + chmod 0440 $D/etc/sudoers +} -- cgit v1.2.3-54-g00ecf