Revisions of permissions
Dominique Leuenberger (dimstar_suse)
accepted
request 730732
from
Johannes Segitz (jsegitz)
(revision 126)
Dominique Leuenberger (dimstar_suse)
accepted
request 727267
from
Malte Kraus (mkraus)
(revision 125)
- Update to version 20190830: * dumpcap: remove 'other' executable bit because of capabilities (boo#1148788, CVE-2019-3687) - Update to version 20190829: * add one more missing slash for icinga2 * fix more missing slashes for directories - Update to version 20190820: * cron directory permissions: add slashes
Dominique Leuenberger (dimstar_suse)
accepted
request 714806
from
Johannes Segitz (jsegitz)
(revision 124)
- Update to version 20190711: * iputils: Add capability permissions for clockdiff (bsc#1140994) - Update to version 20190710: * iputils/ping: Drop effective capability * iputils/ping6: Remove definitions
Dominique Leuenberger (dimstar_suse)
accepted
request 709714
from
Marcus Meissner (msmeissn)
(revision 123)
- Update to version 20190521: * singluarity: Add starter-suid for version 3.2.0 * adjust settings for amanda to current binary layout - Move BuildRequires: back to main package - Moved requires to subpackages (bsc#1137257)
Dominique Leuenberger (dimstar_suse)
accepted
request 700154
from
Marcus Meissner (msmeissn)
(revision 122)
- Fixed versions. Removed set_version from _service file, doesn't work with the new packaging. Call fix_version.sh to set current date as version instead - Fixed requires for -config and -zypp-plugin - Update to version 20190429: * removed entry for /var/cache/man. Conflicts with packaging and man:man is the better setting anyway (bsc#1133678) * fixed error in description of permissions.paranoid. Make it clear that this is not a usable profile, but intended as a base for own developments - Fix RPM group, fix hard requirement on documentation. Update description typography. - Created new subpackages -config, -doc and standalone package chkstat where we can start a better versioning scheme and require it from the original package
Dominique Leuenberger (dimstar_suse)
accepted
request 649630
from
Matthias Gerstner (mgerstner)
(revision 120)
- Update to version 20181116: * zypper-plugin: new plugin to fix bsc#1114383 - Update to version 20181112: * singularity: remove -suid binaries that have been dropped since version 2.4 (bsc#1028304)
Dominique Leuenberger (dimstar_suse)
accepted
request 645523
from
Matthias Gerstner (mgerstner)
(revision 119)
- Update to version 20181030: * capability whitelisting: allow cap_net_bind_service for ns-slapd from 389-ds - Update to version 20181029: * setuid whitelisting: add fusermount3 (bsc#1111230) - Update to version 20181025: * setuid whitelisting: add authbind binary (bsc#1111251)
Dominique Leuenberger (dimstar_suse)
accepted
request 631726
from
Matthias Gerstner (mgerstner)
(revision 118)
- Update to version 20180827: * setuid whitelisting: add firejail binary (bsc#1059013) - Update to version 20180810: * setuid whitelisting: add lxc-user-nic (bsc#988348)
Dominique Leuenberger (dimstar_suse)
accepted
request 627117
from
Matthias Gerstner (mgerstner)
(revision 117)
- Update to version 20180802: * whitelisting: added smc-tools LD_PRELOAD library (bsc#1102956)
Dominique Leuenberger (dimstar_suse)
accepted
request 625020
from
Andreas Stieger (AndreasStieger)
(revision 116)
- Update to version 20180724: * Fix wrong file path in help string * whitelisting: add spice-gtk usb helper setuid binary (bnc#1101420) (forwarded request 624972 from mgerstner)
Dominique Leuenberger (dimstar_suse)
accepted
request 605257
from
Marcus Meissner (msmeissn)
(revision 115)
- Update to version 20180508: * Capabilities for usage of Wireshark for non-root (bsc#957624)
Dominique Leuenberger (dimstar_suse)
accepted
request 569510
from
Marcus Meissner (msmeissn)
(revision 114)
- Update to version 20180125: * the eror should be reported for permfiles[i], not argv[i], as these are not the same files. (bsc#1047247) * make btmp root:utmp (bsc#1050467) - Update to version 20180115: * - polkit-default-privs: usbauth (bsc#1066877)
Dominique Leuenberger (dimstar_suse)
accepted
request 548532
from
Marcus Meissner (msmeissn)
(revision 113)
- fillup is required for post, not pre installation (forwarded request 548215 from kukuk)
Dominique Leuenberger (dimstar_suse)
accepted
request 539346
from
Marcus Meissner (msmeissn)
(revision 112)
- Update to version 20171106: * Allow setuid root for singularity (group only) bsc#1028304
Dominique Leuenberger (dimstar_suse)
accepted
request 536588
from
Marcus Meissner (msmeissn)
(revision 111)
- Update to version 20171025: * Stricter permissions on cron directories (paranoid) and stricter permissions on sshd_config (secure/paranoid)
Dominique Leuenberger (dimstar_suse)
accepted
request 529130
from
Marcus Meissner (msmeissn)
(revision 110)
- Update to version 20170928: * Fix invalid syntax bsc#1048645 bsc#1060738 - Update to version 20170927: * fix typos in manpages
Dominique Leuenberger (dimstar_suse)
accepted
request 528303
from
Marcus Meissner (msmeissn)
(revision 109)
- Update to version 20170922: * Allow setuid root for singularity (group only) bsc#1028304
Dominique Leuenberger (dimstar_suse)
accepted
request 526050
from
Marcus Meissner (msmeissn)
(revision 108)
- Update to version 20170913: * Allow setuid for shadow newuidmap, newgidmap bsc#979282, bsc#1048645) - Update to version 20170906: * permissions - copy dbus-daemon-launch-helper from / to /usr - bsc#1056764 * permissions: Adding suid bit for VBoxNetNAT (bsc#1033425)
Dominique Leuenberger (dimstar_suse)
accepted
request 501683
from
Marcus Meissner (msmeissn)
(revision 107)
- BuildIgnore group(trusted): we don't really care for this group in the buildroot and do not want to get system-users into the bootstrap cycle as we can avoid it. (forwarded request 501680 from dimstar)
Displaying revisions 41 - 60 of 166