Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

permissions-20200127-lp153.24.3.1 RPM for x86_64

From OpenSuSE Leap 15.3 updates for x86_64

Name: permissions Distribution: openSUSE Leap 15.3
Version: 20200127 Vendor: openSUSE
Release: lp153.24.3.1 Build date: Mon Nov 29 12:38:47 2021
Group: Productivity/Security Build host: lamb77
Size: 1302919 Source RPM: permissions-20200127-lp153.24.3.1.src.rpm
Packager: http://bugs.opensuse.org
Url: http://github.com/openSUSE/permissions
Summary: SUSE Linux Default Permissions
Permission settings of files and directories depending on the local
security settings. The local security setting (easy, secure, or paranoid)
can be configured in /etc/sysconfig/security.

Provides

Requires

License

GPL-2.0+

Changelog

* Wed Nov 17 2021 matthias.gerstner@suse.com
  - Update to version 20200127:
    * Makefile: Leap 15.3 still uses /etc, so adjust the installation setup
* Tue Nov 16 2021 matthias.gerstner@suse.com
  - Update to version 20181225:
    * mgetty: faxq-helper now finally reside in /usr/libexec
    * libksysguard5: Updated path for ksgrd_network_helper
    * kdesu: Updated path for kdesud
    * sbin_dirs cleanup: these binaries have already been moved to /usr/sbin
    * mariadb: revert auth_pam_tool to /usr/lib{,64} again
    * cleanup: revert virtualbox back to plain /usr/lib
    * cleanup: remove deprecated /etc/ssh/sshd_config
    * hawk_invoke is not part of newer hawk2 packages anymore
    * cleanup: texlive-filesystem: public now resides in libexec
    * cleanup: authbind: helper now resides in libexec
    * cleanup: polkit: the agent now also resides in libexec
    * libexec cleanup: 'inn' news binaries now reside in libexec
    * whitelist please (bsc#1183669)
    * Fix enlightenment paths
    * usbauth: drop compatibility variable for libexec
    * usbauth: Updated path for usbauth-npriv
    * profiles: finish usage of variable for polkit-agent-helper-1
    * Makefile: fix custom flags support when using make command line variables
    * added information about know limitations of this approach
    * Makefile: compile with LFO support to fix 32-bit emulation on 64-bit hosts (bsc#1178476)
    * Makefile: support CXXFLAGS and LDFLAGS override / extension via make/env variables (bsc#1178475)
    * profiles: prepare /usr/sbin versions of profile entries (bsc#1029961)
    * profiles: use new variables feature to remove redundant entries
    * profiles: remove now superfluous squid pinger paths (bsc#1171569)
    * tests: implement basic tests for new the new variable feature
    * tests: avoid redundant specification of test names by using class names
    * regtests: split up base types and actual test implementation
    * man pages: add documentation about variables, update copyrights
    * chkstat: implement support for variables in profile paths
    * chkstat: prepare reuse of config file locations
    * chkstat: fix some typos and whitespace
    * etc/permissions: remove unnecessary, duplicate, outdated entries
    * etc/permissions: remove trailing whitespace
    * ksgrd_network_helper: remove obviously wrong path
    * adjust squid pinger path (bsc#1171569)
    * mgetty: remove long dead (or never existing) locks directory (bsc#1171882)
    * squid: remove basic_pam_auth which doesn't need special perms (bsc#1171569)
    * cleanup now useless /usr/lib entries after move to /usr/libexec (bsc#1171164)
    * drop (f)ping capabilities in favor of ICMP_PROTO sockets (bsc#1174504)
    * whitelist Xorg setuid-root wrapper (bsc#1175867)
    * screen: remove /run/uscreens covered by systemd-tmpfiles (bsc#1171879)
    * Add /usr/libexec for cockpit-session as new path
    * physlock: whitelist with tight restrictions (bsc#1175720)
    * mtr-packet: stop requiring dialout group
    * etc/permissions: fix mtr permission
    * list_permissions: improve output format
    * list_permissions: support globbing in --path argument
    * list_permissions: implement simplifications suggested in PR#92
    * list_permissions: new tool for better path configuration overview
    * regtest: support new getcap output format in libcap-2.42
    * regtest: print individual test case errors to stderr
    * etc/permissions: remove static /var/spool/* dirs
    * etc/permissions: remove outdated entries
    * etc/permissions: remove unnecessary static dirs and devices
    * screen: remove now unused /var/run/uscreens
    * Revert "etc/permissions: remove entries for bind-chrootenv"
    * rework permissions.local text (boo#1173221)
    * dbus-1: adjust to new libexec dir location (bsc#1171164)
    * permission profiles: reinstate kdesud for kde5
    * etc/permissions: remove entries for bind-chrootenv
    * etc/permissions: remove traceroute entry
    * VirtualBox: remove outdated entry which is only a symlink any more
    * /bin/su: remove path refering to symlink
    * etc/permissions: remove legacy RPM directory entries
    * /etc/permissions: remove outdated sudo directories
    * singularity: remove outdated setuid-binary entries
    * chromium: remove now unneeded chrome_sandbox entry (bsc#1163588)
    * dbus-1: remove deprecated alternative paths
    * PolicyKit: remove outdated entries last used in SLE-11
    * pcp: remove no longer needed / conflicting entries
    * gnats: remove entries for package removed from Factory
    * kdelibs4: remove entries for package removed from Factory
    * v4l-base: remove entries for package removed from Factory
    * mailman: remove entries for package deleted from Factory
    * gnome-pty-helper: remove dead entry no longer part of the vte package
    * gnokii: remove entries for package no longer in Factory
    * xawtv (v4l-conf): correct group ownership in easy profile
    * systemd-journal: remove unnecessary profile entries
    * thttp: make makeweb entry usable in the secure profile (bsc#1171580)
    * profiles: add entries for enlightenment (bsc#1171686)
    * permissions fixed profile: utempter: reinstate libexec compatibility entry
    * chkstat: fix sign conversion warnings on non 32-bit architectures
    * chkstat: allow simultaneous use of `--set` and `--system`
    * regtest: adjust TestUnkownOwnership test to new warning output behaviour
    * whitelist texlive public binary (bsc#1171686)
    * fixed permissions: adjust to new libexec dir location (bsc#1171164)
    * chkstat: don't print warning about unknown user/group by default
    * Makefile: link with --as-needed, move libs to the end of the command line
    * setuid bit for cockpit (bsc#1169614)
    * Fix paranoid mode for newgidmap and newuidmap (boo#1171173)
    * chkstat: collectProfilePaths(): use directory_iterator to simplify code
    * chkstat: collectProfilePaths(): prefer /usr over /etc
    * regtest: add relative symlink corner case to TestSymlinkBehaviour
    * Chkstat::parseProfile(): avoid use of raw pointer
    * parseSysconfig(): only emmit warning if value is non-empty
    * incorporate a bunch of PR #56 review comments
    * regtest: add test for correct ownership change
    * chkstat: final pass over refactored code
    * chkstat: finish refactoring of safeOpen()
    * chkstat: improve/fix output of mismatches
    * chkstat: support numerical owner/group specification in profiles
    * chkstat: safeOpen: simplify path handling by using a std::string
    * chkstat regtest: support debug build
    * chkstat: start refactoring of safe_open() -> safeOpen()
    * chkstat: processEntries: pull out change logic into applyChanges()
    * chkstat: processEntries: pull out safety check logic
    * chkstat: processEntries: separate printing code and simplify ownership flags
    * chkstat: processEntries: also add file_status and *_ok flags to EntryContext
    * chkstat: processEntries: also add caps to EntryContext
    * chkstat: also move fd_path into EntryContext
    * chkstat: processEntries(): introduce EntryContext data structure
    * chkstat: introduce class type to deal with capabilities
    * chkstat: overhaul of the main entry processing loop
    * chkstat: smaller cleanup of Chkstat::run()
    * chkstat: remove last global variables `root` and `rootl`
    * chkstat: refactor parsing of permission profiles
    * chkstat: replace global `permlist` by STL map
    * chkstat: remove now obsolete usage() function
    * chkstat: refactor collection of permission files
    * regtest: support --after-test-enter-shell
    * chkstat: change global euid variable into const class member
    * chkstat: replace global level, nlevel by a vector data structure
    * chkstat: refactor check_fscaps_enabled()
    * chkstat: refactor parse_sysconfig as a member function Chkstat::parseSysconfig
    * chkstat: introduce separate processArguments() and refactor --files logic
    * chkstat: replace C style chkecklist by std::set
    * chkstat: refactor command line parsing
    * allow /usr/libexec in addition to /usr/lib (bsc#1171164)
    * whitelist s390-tools setgid bit on log directory (bsc#1167163)
    * whitelist WMP (bsc#1161335)
    * regtest: improve readability of path variables by using literals
    * regtest: adjust test suite to new path locations in /usr/share/permissions
    * regtest: only catch explicit FileNotFoundError
    * regtest: provide valid home directory in /root
    * regtest: mount permissions src repository in /usr/src/permissions
    * regtest: move initialialization of TestBase paths into the prepare() function
    * chkstat: suppport new --config-root command line option
    * fix spelling of icingacmd group
    * chkstat: fix readline() on platforms with unsigned char
    * remove capability whitelisting for radosgw
    * whitelist ceph log directory (bsc#1150366)
    * adjust testsuite to post CVE-2020-8013 link handling
    * testsuite: add option to not mount /proc
    * do not follow symlinks that are the final path element: CVE-2020-8013
    * add a test for symlinked directories
    * fix relative symlink handling
    * include cpp compat headers, not C headers
    * Move permissions and permissions.* except .local to /usr/share/permissions
    * regtest: fix the static PATH list which was missing /usr/bin
    * regtest: also unshare the PID namespace to support /proc mounting
    * regtest: bindMount(): explicitly reject read-only recursive mounts
    * Makefile: force remove upon clean target to prevent bogus errors
    * regtest: by default automatically (re)build chkstat before testing
    * regtest: add test for symlink targets
    * regtest: make capability setting tests optional
    * regtest: fix capability assertion helper logic
    * regtests: add another test case that catches set*id or caps in world-writable sub-trees
    * regtest: add another test that catches when privilege bits are set for special files
    * regtest: add test case for user owned symlinks
    * regtest: employ subuid and subgid feature in user namespace
    * regtest: add another test case that covers unknown user/group config
    * regtest: add another test that checks rejection of insecure mixed-owner paths
    * regtest: add test that checks for rejection of world-writable paths
    * regtest: add test for detection of unexpected parent directory ownership
    * regtest: add further helper functions, allow access to main instance
    * regtest: introduce some basic coloring support to improve readability
    * regtest: sort imports, another piece of rationale
    * regtest: add capability test case
    * regtest: improve error flagging of test cases and introduce warnings
    * regtest: support caps
    * regtest: add a couple of command line parameter test cases
    * regtest: add another test that checks whether the default profile works
    * regtests: add tests for correct application of local profiles
    * regtest: add further test cases that test correct profile application
    * regtest: simplify test implementation and readability
    * regtest: add helpers for permissions.d per package profiles
    * regtest: support read-only bind mounts, also bind-mount permissions repo
    * tests: introduce a regression test suite for chkstat
    * Makefile: allow to build test version programmatically
    * README.md: add basic readme file that explains the repository's purpose
    * chkstat: change and harmonize coding style
    * chkstat: switch to C++ compilation unit
    * remove obsolete/broken entries for rcp/rsh/rlogin
    * chkstat: handle symlinks in final path elements correctly
    * Revert "Revert "mariadb: settings for new auth_pam_tool (bsc#1160285)""
    * Revert "mariadb: settings for new auth_pam_tool (bsc#1160285)"
    * mariadb: settings for new auth_pam_tool (bsc#1160285)
    * add read-only fallback when /proc is not mounted (bsc#1160764)
    * capability handling fixes (bsc#1161779)
    * better error message when refusing to fix dir perms (#32)
    * fix paths of ksysguard whitelisting
    * fix zero-termination of error message for overly long paths
    * fix misleading indendation
    * fix changing of capabilities
    * fix warning text for unlisted files
    * fix error message with insecure sym links
    * remove useless if around realloc()
    * fix invalid free() when permfiles points to argv
    * use path-based operations with /proc/self/fd/X to avoid errors due to O_PATH
    * add .gitignore for chkstat binary
    * add/fix compiler warnings, free memory at exit
    * only open regular files/directories without O_PATH, fix stat buffer initialization
    * update
    * rewrite while protecting against symlinks and races
    * fix whitespace
    * faxq-helper: correct "secure" permission for trusted group (bsc#1157498)
    * whitelist ksysguard network helper (bsc#1151190)
    * fix syntax of paranoid profile
    * fix squid permissions (bsc#1093414, CVE-2019-3688)
    * setgid bit for nagios directory (bsc#1028975, bsc#1150345)
    * global: removal of unneeded SuSEconfig file and directory
    * global: restructure repository layout
    * dumpcap: remove 'other' executable bit because of capabilities (boo#1148788, CVE-2019-3687)
    * add one more missing slash for icinga2
    * fix more missing slashes for directories
    * cron directory permissions: add slashes
    * iputils: Add capability permissions for clockdiff
    * iputils/ping: Drop effective capability
    * iputils/ping6: Remove definitions
    * singluarity: Add starter-suid for version 3.2.0
    * removed entry for /var/cache/man. Conflicts with packaging and man:man is the better setting anyway (bsc#1133678)
    * fixed error in description of permissions.paranoid. Make it clear that this is not a usable profile, but intended as a base for own developments
    * Misleading comment fix
    * removed old entry for wodim
    * removed old entry for netatalk
    * removed old entry for suidperl
    * removed old entriy for utempter
    * removed old entriy for hostname
    * removed old directory entries
    * removed old entry for qemu-bridge-helper
    * removed old entries for pccardctl
    * removed old entries for isdnctrl
    * removed old entries for unix(2)_chkpwd
    * removed old entries for mount.nfs
    * removed old entries for (u)mount
    * removed old entry for fileshareset
    * removed old entries for KDE
    * removed old entry for heartbeat
    * removed old entry for gnome-control-center
    * removed old entry for pcp
    * removed old entry for lpdfilter
    * removed old entry for scotty
    * removed old entry for ia32el
    * removed old entry for squid
    * removed old qpopper whitelist
    * removed pt_chown entries. Not needed anymore and a bad idea anyway
    * removed old majordomo entry
    * removed stale entries for old ncpfs tools
    * removed old entry for rmtab
    * Fixed type in icinga2 whitelist entry
    * New whitelisting for /usr/lib/virtualbox/VirtualBoxVM and removed stale entries for VirtualBox
    * Removed whitelist for /usr/bin/su.core. According to comment a temporary hack introduced 2012 to help moving su from coretuils to util-linux. I couldn't find it anywhere, so we don't need it anymore
    * Remove entry for /usr/bin/yaps. We don't ship it anymore and the group that is used doesn't exists anymore starting with Leap 15, so it will not work there anyway. Users using this (old) package can do this individually
    * removed entry for /etc/ftpaccess. We currently don't have it anywhere (and judging from my search this has been the case for quite a while)
    * Ensure consistency of entries, otherwise switching between settings becomes problematic
    * Fix spelling of SUSE
    * adjust settings for amanda to current binary layout
* Fri Apr 30 2021 matthias.gerstner@suse.com
  - Update to version 20181225:
    * etc/permissions: remove unnecessary entries (bsc#1182899)
* Thu Jan 21 2021 matthias.gerstner@suse.com
  - Update to version 20181224:
    * pcp: remove no longer needed / conflicting entries
      (bsc#1171883, CVE-2020-8025)
* Tue Jun 02 2020 matthias.gerstner@suse.com
  - Update to version 20181224:
    * profiles: add entries for enlightenment (bsc#1171686)
* Thu May 28 2020 malte.kraus@suse.com
  - whitelist texlive public binary (bsc#1171686)
* Mon May 11 2020 jsegitz@suse.com
  - Remove setuid bit for newgidmap and newuidmap in paranoid profile
    (bsc#1171173)
* Thu Apr 02 2020 jsegitz@suse.com
  - correct spelling of icinga group (icingagmd -> icingacmd, bsc#1168364)
* Tue Mar 24 2020 jsegitz@suse.com
  - whitelist s390-tools setgid bit on log directory (bsc#1167163)
* Mon Mar 02 2020 malte.kraus@suse.com
  - run testsuite during package build
  - Update to version 20181224:
    * testsuite: adapt expected behavior to legacy branches
    * adjust testsuite to post CVE-2020-8013 link handling
    * testsuite: add option to not mount /proc
    * do not follow symlinks that are the final path element: CVE-2020-8013, bsc#1163922
    * add a test for symlinked directories
    * fix relative symlink handling
    * regtest: fix the static PATH list which was missing /usr/bin
    * regtest: also unshare the PID namespace to support /proc mounting
    * Makefile: force remove upon clean target to prevent bogus errors
    * regtest: by default automatically (re)build chkstat before testing
    * regtest: add test for symlink targets
    * regtest: make capability setting tests optional
    * regtest: fix capability assertion helper logic
    * regtests: add another test case that catches set*id or caps in world-writable sub-trees
    * regtest: add another test that catches when privilege bits are set for special files
    * regtest: add test case for user owned symlinks
    * regtest: employ subuid and subgid feature in user namespace
    * regtest: add another test case that covers unknown user/group config
    * regtest: add another test that checks rejection of insecure mixed-owner paths
    * regtest: add test that checks for rejection of world-writable paths
    * regtest: add test for detection of unexpected parent directory ownership
    * regtest: add further helper functions, allow access to main instance
    * regtest: introduce some basic coloring support to improve readability
    * regtest: sort imports, another piece of rationale
    * regtest: add capability test case
    * regtest: improve error flagging of test cases and introduce warnings
    * regtest: support caps
    * regtest: add a couple of command line parameter test cases
    * regtest: add another test that checks whether the default profile works
    * regtests: add tests for correct application of local profiles
    * regtest: add further test cases that test correct profile application
    * regtest: simplify test implementation and readability
    * regtest: add helpers for permissions.d per package profiles
    * regtest: support read-only bind mounts, also bind-mount permissions repo
    * tests: introduce a regression test suite for chkstat
* Fri Feb 28 2020 malte.kraus@suse.com
  - Update to version 20181224:
    * whitelist WMP (bsc#1161335)
    * Makefile: allow to build test version programmatically
    * chkstat: handle symlinks in final path elements correctly
    * add .gitignore for chkstat binary
    * faxq-helper: correct "secure" permission for trusted group (bsc#1157498)
    * fix syntax of paranoid profile
* Thu Feb 06 2020 matthias.gerstner@suse.com
  - Update to version 20181224:
    * mariadb: settings for new auth_pam_tool (bsc#1160285)
    * chkstat: capability handling fixes (bsc#1161779)
    * chkstat: fix regression where chkstat breaks without /proc available (bsc#1160764, bsc#1160594)
    * dumpcap: remove 'other' executable bit because of capabilities (boo#1148788, CVE-2019-3687)
* Wed Feb 05 2020 matthias.gerstner@suse.com
  Sync upstream SLE-15-SP1 branch with our SLE-15-SP1:Update package. Therefore
    remove all of the following patches which are now included in the tarball:
  - 0001-whitelisting-update-virtualbox.patch
  - 0002-consistency-between-profiles.patch 0003-var-run-postgresql.patch
  - 0004-var-cache-man.patch
  - 0005-singularity-starter-suid.patch
  - 0006-bsc1110797_amanda.patch
  - 0007-chkstat-fix-privesc-CVE-2019-3690.patch
  - 0008-squid-pinger-owner-fix-CVE-2019-3688.patch
  - 0009-chkstat-handle-missing-proc.patch
  - 0010-chkstat-capabilities-implicit-changes.patch
    Because of inconsistencies between the upstream branch and the package state
    the following previously missing changes are introduced by this update:
  - Update to version 20181117:
    * removed old entry for rmtab
    * Fixed typo in icinga2 whitelist entry
* Fri Jan 31 2020 Malte Kraus <malte.kraus@suse.com>
  - fix regression where chkstat breaks without /proc available
    (bsc#1160764, bsc#1160594, 0009-chkstat-handle-missing-proc.patch)
  - fix capability handling when doing multiple permission changes
    at once (bsc#1161779,
    0010-chkstat-capabilities-implicit-changes.patch)
* Tue Nov 19 2019 Malte Kraus <malte.kraus@suse.com>
  - fix invalid free() when permfiles points to argv (bsc#1157198,
    changed 0007-chkstat-fix-privesc-CVE-2019-3690.patch)
* Mon Oct 28 2019 Malte Kraus <malte.kraus@suse.com>
  - fix /usr/sbin/pinger ownership to root:squid (bsc#1093414,
    CVE-2019-3688, 0008-squid-pinger-owner-fix-CVE-2019-3688.patch)
* Mon Oct 28 2019 Malte Kraus <malte.kraus@suse.com>
  - fix privilege escalation through untrusted symlinks (bsc#1150734,
    CVE-2019-3690, 0007-chkstat-fix-privesc-CVE-2019-3690.patch)
* Thu Sep 26 2019 Johannes Segitz <jsegitz@suse.com>
  - Updated permissons for amanda, added 0006-bsc1110797_amanda.patch
    (bsc#1110797)
* Thu Jun 13 2019 Malte Kraus <malte.kraus@suse.com>
  - Added ./0005-singularity-starter-suid.patch (bsc#1128598)
    New whitelisting for /usr/lib/singularity/bin/starter-suid
* Tue Apr 30 2019 jsegitz@suse.com
  - Added 0004-var-cache-man.patch. Removed entry for /var/cache/man.
    Conflicts with packaging and man:man is the better setting anyway
    (bsc#1133678)
* Tue Feb 12 2019 jsegitz@suse.com
  - Added 0001-whitelisting-update-virtualbox.patch (bsc#1120650)
    New whitelisting for /usr/lib/virtualbox/VirtualBoxVM and removed
    stale entries for VirtualBox
  - Added 0002-consistency-between-profiles.patch
    Ensure consistency of entries, otherwise switching between settings
    becomes problematic
  - Added 0003-var-run-postgresql.patch (bsc#1123886)
    Whitelist for postgresql. Currently the checker doesn't complain
    because the directories aren't packaged, but that might change
    and/or our checkers might improve
* Wed Nov 28 2018 opensuse-packaging@opensuse.org
  - Update to version 20181116:
    * zypper-plugin: new plugin to fix bsc#1114383
    * singularity: remove dropped -suid binaries (bsc#1028304)
    * capability whitelisting: allow cap_net_bind_service for ns-slapd from 389-ds
    * setuid whitelisting: add fusermount3 (bsc#1111230)
    * setuid whitelisting: add authbind binary (bsc#1111251)
    * setuid whitelisting: add firejail binary (bsc#1059013)
    * setuid whitelisting: add lxc-user-nic (bsc#988348)
    * whitelisting: add smc-tools LD_PRELOAD library (bsc#1102956)
    * whitelisting: add spice-gtk usb helper setuid binary (bnc#1101420)
    * Fix wrong file path in help string
    * Capabilities for usage of Wireshark for non-root
  - remove 0001-whitelisting-add-spice-gtk-usb-helper-setuid-binary-.patch:
    is now contained in tarball.
* Mon Aug 20 2018 matthias.gerstner@suse.com
  - 0001-whitelisting-add-spice-gtk-usb-helper-setuid-binary-.patch: add
    whitelisting for the spice-gtk setuid binary (bsc#1101420) for improved
    usability.
* Thu Jan 25 2018 meissner@suse.com
  - Update to version 20180125:
    * the eror should be reported for permfiles[i], not argv[i], as these are not the same files. (bsc#1047247)
    * make btmp root:utmp (bsc#1050467)
* Mon Jan 15 2018 krahmer@suse.com
  - Update to version 20180115:
    * - polkit-default-privs: usbauth (bsc#1066877)
* Mon Dec 04 2017 kukuk@suse.com
  - fillup is required for post, not pre installation
* Thu Nov 30 2017 mpluskal@suse.com
  - Cleanup spec file with spec-cleaner
  - Drop conditions/definitions related to old distros
* Wed Nov 29 2017 astieger@suse.com
  - Update to version 20171129:
    * permissions: adding gvfs (bsc#1065864)
    * Allow setgid incingacmd on directory /run/icinga2/cmd bsc#1069410
    * Allow fping cap_net_raw (bsc#1047921)
* Thu Nov 23 2017 rbrown@suse.com
  - Replace references to /var/adm/fillup-templates with new
    %_fillupdir macro (boo#1069468)
* Tue Nov 21 2017 krahmer@suse.com
  - Update to version 20171121:
    * - permissions: adding kwayland (bsc#1062182)
* Mon Nov 06 2017 eeich@suse.com
  - Update to version 20171106:
    * Allow setuid root for singularity (group only) bsc#1028304
* Wed Oct 25 2017 jsegitz@suse.com
  - Update to version 20171025:
    * Stricter permissions on cron directories (paranoid) and stricter permissions on sshd_config (secure/paranoid)
* Thu Sep 28 2017 astieger@suse.com
  - Update to version 20170928:
    * Fix invalid syntax bsc#1048645 bsc#1060738
* Wed Sep 27 2017 pgajdos@suse.com
  - Update to version 20170927:
    * fix typos in manpages
* Fri Sep 22 2017 astieger@suse.com
  - Update to version 20170922:
    * Allow setuid root for singularity (group only) bsc#1028304
* Wed Sep 13 2017 astieger@suse.com
  - Update to version 20170913:
    * Allow setuid for shadow newuidmap, newgidmap bsc#979282, bsc#1048645)
* Wed Sep 06 2017 opensuse-packaging@opensuse.org
  - Update to version 20170906:
    * permissions - copy dbus-daemon-launch-helper from / to /usr - bsc#1056764
    * permissions: Adding suid bit for VBoxNetNAT (bsc#1033425)
* Wed Jun 07 2017 dimstar@opensuse.org
  - BuildIgnore group(trusted): we don't really care for this group
    in the buildroot and do not want to get system-users into the
    bootstrap cycle as we can avoid it.
* Sat Jun 03 2017 meissner@suse.com
  - Require: group(trusted), as we are handing it out to some unsuspecting
    binaries and it is no longer default. (bsc#1041159 for fuse, also cronie, etc)
* Fri Jun 02 2017 meissner@suse.com
  - Update to version 20170602:
    * make /etc/ppp owned by root:root. The group dialout usage is no longer used
* Sun Aug 07 2016 meissner@suse.com
  - Update to version 20160807:
    * suexec2 is a symlink, no need for permissions handling
* Tue Aug 02 2016 meissner@suse.com
  - Update to version 20160802:
    * list the newuidmap and newgidmap, currently 0755 until review is done (bsc#979282)
    * root:shadow 0755 for newuidmap/newgidmap
* Tue Aug 02 2016 krahmer@suse.com
  - adding qemu-bridge-helper mode 04750 (bsc#988279)
* Mon May 23 2016 dimstar@opensuse.org
  - Introduce _service to easier update the package. For simplicity,
    change the version from yyyy.mm.dd to yyyymmdd (which is eactly
    %cd in the _service defintion). Upgrading is no problem.
* Mon May 23 2016 meissner@suse.com
  - chage only needs read rights to /etc/shadow, so setgid shadow is sufficient (bsc#975352)
* Wed Mar 30 2016 meissner@suse.com
  - permissions: adding gstreamer ptp file caps (bsc#960173)
* Fri Jan 15 2016 meissner@suse.com
  - the apache folks renamed suexec2 to suexec with symlink. adjust both (bsc#962060)
* Tue Jan 12 2016 meissner@suse.com
  - pinger needs to be squid:root, not root:squid (there is no squid group) bsc#961363
* Thu Oct 29 2015 meissner@suse.com
  - add suexec with 0755 to all standard profiles. this can and should be overridden in permissions.local if you need it setuid root. bsc#951765 bsc#263789
  - added missing / to the squid specific directories (bsc#950557)
* Mon Sep 28 2015 meissner@suse.com
  - adjusted radosgw to root:www mode 0750 (bsc#943471)
* Mon Sep 28 2015 meissner@suse.com
  - radosgw can get capability cap_bind_net_service (bsc#943471)
* Mon Jun 08 2015 meissner@suse.com
  - remove /usr/bin/get_printing_ticket; (bnc#906336)
* Wed Dec 03 2014 krahmer@suse.com
  - Added iouyap capabilities (bnc#904060)
* Wed Nov 05 2014 meissner@suse.com
  - %{_bindir}/get_printing_ticket turned to mode 700, setuid root no longer needed (bnc#685093)
  - permissions: incorporating squid changes from bnc#891268
  - hint that chkstat --system --set needs to be run after editing bnc#895647

Files

/etc/permissions
/etc/permissions.easy
/etc/permissions.local
/etc/permissions.paranoid
/etc/permissions.secure
/usr/bin/chkstat
/usr/share/fillup-templates/sysconfig.security
/usr/share/man/man5/permissions.5.gz
/usr/share/man/man8/chkstat.8.gz
/usr/share/permissions
/usr/share/permissions/variables.conf


Generated by rpm2html 1.8.1

Fabrice Bellet, Tue Aug 9 18:44:14 2022