Skip to content

Releases: shadow-maint/shadow

4.12.2 - ayibe+++

18 Aug 22:03
Compare
Choose a tag to compare

This includes the fix by Christian Göttsche for a TOCTTOU when copying directories.

4.12.1 - ayibe++

15 Aug 17:27
Compare
Choose a tag to compare

This should fix the broken uk manpages in 4.12.

4.12 - ayibe

11 Aug 16:15
Compare
Choose a tag to compare

This release includes the following changes:

    * Add absolute path hint to --root (Celeste Liu)
    * Various cleanups (Christian Göttsche)
    * Fix Ubuntu release used in CI tests (Jeremy Whiting)
    * add -F options to useradd (and tests) (Masatake YAMATO)
    * useradd manpage updates (Masatake YAMATO and Alexander Zhang))
    * Check for ownerid (not just username) in subid ranges (Iker Pedrosa)
    * Declare file local functions static (Christian Göttsche)
    * Use strict prototypes (Christian Göttsche)
    * Do not drop const qualifier for Basename (Christian Göttsche)
    * Constify various pointers (Christian Göttsche)
    * Don't return uninitialized memory (Christian Göttsche)
    * Don't let compiler optimize away memory cleaning (Christian Göttsche)
    * Remove many obsolete compatibility checks  and defines (Alejandro Colomar)
    * Modify ID range check in useradd (Iker Pedrosa)
    * Use "extern "C"" to make libsubid easier to use from C++ (Alois Wohlschlager)
    * French translation updates (bubu)
    * Fix s/with-pam/with-libpam/ (serge)
    * Spanish translation updates (Fernando)
    * French translation fixes (Balint Reczey)
    * Default max group name length to 32 (Jami Kettunen)
    * Fix PAM service files without-selinux (Ali Riza KESKIN)
    * Improve manpages (Markus Hiereth)
      - groupadd, useradd, usermod
      - groups and id
      - pwck
    * Add fedora to CI builds (Iker Pedrosa)
    * Fix condition under which pw_dir check happens (Ed Neville)
    * logoutd: switch to strncat (Steve Grubb)
    * AUTHORS: improve markdown output (Iker Pedrosa)
    * Handle ERANGE errors correctly (Niko)
    * Check for fopen NULL return (juyin)
    * Split get_salt() into its own fn juyin)
    * Get salt before chroot to ensure /dev/urandom. (juyin)
    * Chpasswd code cleanup (juyin)
    * Work around git safe.directory enforcement (serge)
    * Alphabetize order in usermod help (Matheus Marques)
    * Erase password copy on error branches (Christian Göttsche)
    * Suggest using --badname if needed (Iker Pedrosa)
    * Update translation files (Iker Pedrosa)
    * Correct badnames option to badname (Iker Pedrosa)
    * configure: replace obsolete autoconf macros (Christian Göttsche)
    * tests: replace egrep with grep -E (Sam James)
    * Update Ukrainian translations (Yuri Chornoivan)
    * Cleanups (Iker Pedrosa)
      - Remove redeclared variable
      - Remove commented out code and FIXMEs
      - Add header guards
      - Initialize local variables
    * CI updates (Iker Pedrosa)
      - Create github workflow to install dependencies
      - Enable CodeQL
      - Update actions version
    * libmisc: use /dev/urandom as fallback if other methods fail (Xi Ruoyao)

v4.11.1

03 Jan 03:18
v4.11.1
Compare
Choose a tag to compare

Changelog:
* build: include lib/shadowlog_internal.h in dist tarballs (Sam James)

v4.11

03 Jan 02:08
v4.11
Compare
Choose a tag to compare

Changelog:

* Handle possible TOCTTOU issues in usermod/userdel (edneville)
	* (CVE-2013-4235)
	* Use O_ when copying file
	* Kill all user tasks in userdel
* Fix useradd -D segfault (Xi Ruoyao)
* Clean up obsolete libc feature-check ifdefs (Alejandro Colomar)
* Fix -fno-common build breaks due to duplicate Prog declarations
	(Adam Sampson)
* Have single date_to_str definition (Alejandro Colomar)
* Fix libsubid SONAME version (Sam James)
* Clarify licensing info, use SPDX.

Release 4.10

19 Dec 20:25
Compare
Choose a tag to compare

Note: From this release forward, su from this package should be
considered deprecated. Please replace any users of it with su from
util-linux. Please open an issue if there is a problem with that.
We intend to remove it in an upcoming release.

This release features many fixes expecially to the building of
libsubid, some SELinux labeling issues, and a few signaling
issues.

Changelog:
* libsubid fixes (Xi Ruoyao, Serge Hallyn, Iker Pedrosa, Mike Gilbert,
GalaxyMaster, and Luís Ferreira)
* Rename the test program list_subid_ranges to getsubids, write
a manpage, so distros can ship it. (Iker Pedrosa)
* Add libeconf dep for new*idmap (Iker Pedrosa)
* Allow all group types with usermod -G (Iker Pedrosa)
* Avoid useradd generating empty subid range (Iker Pedrosa)
* Handle NULL pw_passwd (Jaroslav Jindrak)
* Fix default value SHA_get_salt_rounds (Mike Gilbert)
* Use https where possible in README (Paul Menzel)
* Update content and format of README (Iker Pedrosa)
* Translation updates (Balint Reczey, Frans Spiesschaert)
* Switch from xml2po to itstool in 'make dist' (Serge Hallyn)
* Fix double frees (Michael Vetter)
* Add LOG_INIT configurable to useradd (Andy Zaugg)
* Add CREATE_MAIL_SPOOL documentation (Andy Zaugg)
* Create a security.md
* Fix su never being SIGKILLd when trapping TERM (Ruihan li)
* Fix wrong SELinux labels in several possible cases (Iker Pedrosa)
* Fix missing chmod in chadowtb_move (GalaxyMaster)
* Handle malformed hushlogins entries (Tobias Stoeckmann)
* Fix groupdel segv when passwd does not exist (François Rigault)
* Fix covscan-found newgrp segfault (Iker Pedrosa)
* Remove trailing slash on hoedir (Ed Neville)
* Fix passwd -l message - it does not change expirey (Ed Neville)
* Fix SIGCHLD handling bugs in su and vipw (Tobias Stoeckmann)
* Remove special case for "" in usermod (Alejandro Colomar)
* Implement usermod -rG to remove a specific group
(Andy Zaugg)
* call pam_end() after fork in child path for su and login
(Björn Fischer)
* useradd: In absence of /etc/passwd, assume 0 == root
(Ludwig Nussel)
* lib: check NULL before freeing data (Iker Pedrosa)
* Fix pwck segfault (Iker Pedrosa)

Release 4.9

22 Jul 23:37
Compare
Choose a tag to compare

Changelog:

  • Updated translations (Björn Esser, Juergen Hoetzel)
  • Major salt updates (Björn Esser)
  • Various coverity and cleanup fixes (Iker Pedrosa)
  • Consistently use 0 to disable PASS_MIN_DAYS in man (tzccinct)
  • Implement NSS support for subids and a libsubid (Serge Hallyn)
  • setfcap: retain setfcap when mapping uid 0 (Christian Brauner)
  • login.defs: include HMAC_CRYPTO_ALGO key (Iker Pedrosa)
  • selinux fixes (Christian Göttsche)
  • Fix path prefix path handling (Lucas Servén Marín)
  • Manpage updates (tzccinct, Sevan Janiyan, Iker Pedrosa, Geert Ijewski,
    谭九鼎, Jamin W. Collins, towerpark, andydna, Frans Spiesschaert)
  • Treat an empty passwd field as invalid (Haelwenn Monnier)
  • newxidmap: allow running under alternative gid (Martijn de Gouw)
  • usermod: check that shell is executable (Geert Ijewski)
  • Add yescript support (Rodolphe Bréard)
  • useradd memleak fixes (whzhe)
  • useradd: use built-in settings by default (Ludwig Nussel)
  • getdefs: add foreign (non-shadow-utils) items (Karel Zak)
  • buffer overflow fixes (Tobias Stoeckmann)
  • Adding run-parts style for pre and post useradd/del ([email protected])

Release 4.8.1

23 Jan 21:23
Compare
Choose a tag to compare

This minor release was made mainly to revert the --sbindir/--bindir commit which broke some distributions.

Changelog:

    * selinux: incluee stdio (Michael Vetter)
    * man: don't suggest making groupmems user-writeable (Michael Weiser)
    * Makefile: bail out on error in for loops (Wolfgang Bumiller)
    * Adding logging of SSH_ORIGINAL_COMMAND to nologin. ([email protected])
    * add new HOME_MODE login.defs option (Duncan Overbruck)
    * Add tty logging to useradd ([email protected])
    * Useradd: make non-executable shell check only a warning (Tomas Mraz)
    * Update Dutch translation (Frans-Spiesschaert)
    * user_busy: Do not mistake a regular user process for a namespaced one (Tomas Mraz)
    * Revert "Honor --sbindir and --bindir for binary installation" Patrick McLean)

Release 4.8

01 Dec 17:54
Compare
Choose a tag to compare
    * Initial optional bcrypt support.
    * Make build/install of 'su' optional.
    * Fix for vipw not resuming correctly when suspended
    * Sync password field descriptions in manpages
    * Check for valid shell argument in useradd
    * Allow translation of new strings through POTFILES.in
    * Migrate to itstool for translations
    * Migrate to new SELinux api
    * Support --enable-vendordir
    * pwck: Only check homedir if set and not a system user
    * Support nonstandard usernames
    * sget{pw,gr}ent: check for data at EOL
    * Add YYY-MM-DD support in chage
    * Fix failing chmod calls for suidubins
    * Fix --sbindir and --bindir for binary installations
    * Fix LASTLOG_UID_MAX in login.defs
    * Fix configure error with dash

Releasing 4.7

13 Jun 19:32
Compare
Choose a tag to compare
Releasing 4.7 Pre-release
Pre-release

Changelog:

    * Spawn: don't loop forever on ECHILD
    * Do not fail locking if there is a stale lockfile Tomas Mraz)
    * Use lckpwdf if prefix not set (Tomas Mraz)
    * Build: check correct DocBook version (Jan Tojnar)
    * Usermod: Print 'no changes' to stdout, not stderr (Serge Hallyn)
    * Add support for btrfs subvolumes for home (Adam Majer)
    * Fix chpasswd long line handling (Nathan Ruiz)
    * Use secure_getenv for gettime (Chris Lamb)
    * Make sp_lstchg reproducible (Chris Lamb)
    * Do not crash commonio_close if db file is not open (Tomas Mraz)
    * Don't flush nscd and sssd cache in read-only mode (Charlie Vuillemez)
    * French manpage update (Alban VIDAL)
    * Fix manpage defaults for SUB_UID/GID_COUNT (Tomas Mraz)
    * Sync po files from shadow.pot (Alban VIDAL)
    * Usermod: guard against unsafe chown of homedir contents (Tomas Mraz)
    * Add LASTLOG_UID_MAX to login.defs (Tomas Mraz)
    * new[ug]idmap file capabilities support (Giuseppe Scrivano and Christian Brauner)
    * Fix segfault in useradd (Tomas Mraz)
    * Coverity issues (Tomas Mraz)
    * Flush sssd caches (Jakub Hrozek)
    * Log UID in nologin (Vladimir Ivanov)
    * run pam_getenvlist after setup_env in su.c (Michael Vogt)
    * Support systems with only utmpx (A. Wilcox)
    * Fix unguarded ENABLE_SUBIDS code (Jan Chren (rindeal))
    * Update po/zh_CN translation (Lion Yang)
    * Create parent dirs for useradd -m (Michael Vetter)
    * Prevent usermod segv
    * Fix usermod crash (fariouche)