Age | Commit message (Collapse) | Author | Files | Lines | |
---|---|---|---|---|---|
2012-11-14 | sudo: do not send domain name with username | Pavel Březina | 3 | -6/+5 | |
This caused troubles with subdomain users and it is not really necessary. This patch does not change the protocol itself, that should be done on the earliest possible occasion. Part of https://fedorahosted.org/sssd/ticket/1616 | |||||
2012-11-14 | sudo: support users from subdomains | Pavel Březina | 4 | -60/+214 | |
https://fedorahosted.org/sssd/ticket/1616 | |||||
2012-11-14 | use tmp_ctx in sudosrv_get_sudorules_from_cache() | Pavel Březina | 1 | -8/+20 | |
2012-11-14 | sudo: fix missing parameter in two debug messages | Pavel Březina | 1 | -3/+3 | |
2012-10-30 | sudo: do not hardcode protocol version | Pavel Březina | 1 | -1/+2 | |
2012-10-29 | Include talloc log in our debug facility | Michal Zidek | 1 | -1/+1 | |
https://fedorahosted.org/sssd/ticket/1495 | |||||
2012-10-01 | Add new option default_domain_suffix | Sumit Bose | 1 | -1/+2 | |
2012-08-07 | Remove SYSDB_SUDO_CACHE_OC from attribute lists | Pavel Březina | 1 | -1/+0 | |
It is not an attribute. | |||||
2012-08-07 | Rename SYSDB_SUDO_CACHE_AT_OC to SYSDB_SUDO_CACHE_OC | Pavel Březina | 1 | -1/+1 | |
It does not contain name of the object class attribute but the value itself. I renamed it to avoid confusion. | |||||
2012-07-18 | Fix uninitialized values | Nick Guay | 1 | -1/+1 | |
https://fedorahosted.org/sssd/ticket/1379 | |||||
2012-07-09 | Fix potential NULL-dereference | Stephen Gallagher | 1 | -1/+2 | |
Coverity #12800 | |||||
2012-07-09 | Fix potential NULL-dereference | Stephen Gallagher | 1 | -1/+3 | |
Coverity #12801 | |||||
2012-06-29 | sudo responder: schedule OOB full refresh when expired rule is deleted | Pavel Březina | 2 | -4/+40 | |
2012-06-29 | sudo responder: refresh expired rules | Pavel Březina | 1 | -31/+106 | |
2012-06-29 | sudo responder: update dp interface | Pavel Březina | 3 | -34/+72 | |
2012-06-29 | sudo responder: allow fetching only expired rules in ↵ | Pavel Březina | 1 | -25/+22 | |
sudosrv_get_sudorules_query_cache() | |||||
2012-06-29 | sudo sysdb: add expiration time to the filter | Pavel Březina | 1 | -1/+1 | |
2012-06-29 | sudo responder: new request enum type | Pavel Březina | 3 | -13/+19 | |
sss_sudo_type represents query type that comes to the responder sss_dp_sudo_type represents query type to DP that is issued by the responder I'm leaving current values of sss_dp_sudo_type untouched so the compilation is not broken. Hovewer, they will be changed to new DP types once the DP interface is updated. | |||||
2012-06-29 | sudo responder: discard in-memory cache | Pavel Březina | 3 | -375/+0 | |
2012-06-29 | sudo responder: change protocol version to 1 | Pavel Březina | 1 | -0/+9 | |
2012-06-29 | sudo api: send uid, username and domainname | Pavel Březina | 4 | -109/+102 | |
https://fedorahosted.org/sssd/ticket/1239 Test client was changed accordingly. The new usage is: sss_sudo_cli username [uid] If uid is not set, getpwnam(username) is called. It will retrieve both default options and rules. | |||||
2012-06-29 | sudo responder: get rid of dctx where possible | Pavel Březina | 3 | -93/+102 | |
2012-06-29 | sudo responder: remove code duplication in commands | Pavel Březina | 4 | -277/+283 | |
2012-06-12 | Make re_expression and full_name_format per domain options | Stef Walter | 1 | -2/+2 | |
* Allows different user/domain qualified names for different domains. For example Domain\User or user@domain. * The global re_expression and full_name_format options remain as defaults for the domains. * Subdomains get the re_expression and full_name_format of their parent domain. https://bugzilla.redhat.com/show_bug.cgi?id=811663 | |||||
2012-04-24 | Modified responder_get_domain() | Jan Zeleny | 1 | -1/+1 | |
Now it checks for subdomains as well as for the domain itself | |||||
2012-03-09 | Potential NULL-dereference in sudosrv_cmd_get_sudorules | Pavel Březina | 1 | -14/+12 | |
https://fedorahosted.org/sssd/ticket/1236 | |||||
2012-03-09 | Use of unininitialized value in sudosrv_cache_set_entry and ↵ | Pavel Březina | 1 | -0/+2 | |
sudosrv_cache_lookup_internal https://fedorahosted.org/sssd/ticket/1232 | |||||
2012-03-08 | Use the correct hash table for pending requests | Simo Sorce | 1 | -1/+1 | |
The function that handled pending requests on reconnect was checking an orphaned global variable that was never used, redenring the whole function uselsess. This fixes a very nasty bug that was causing requests for which we never received an answer for (for example because the backend failed and was restarted) to be never removed and therefore causing a black hole effect for any other request of the same type. Fixes: https://fedorahosted.org/sssd/ticket/1229 | |||||
2012-02-29 | Remove sysdb_get_ctx_from_list() | Sumit Bose | 1 | -7/+4 | |
2012-02-23 | Move sudo_dom_ctx.user to local variable | Pavel Březina | 2 | -8/+8 | |
2012-02-23 | Honor case_sensitive option in sudo responder | Pavel Březina | 4 | -21/+100 | |
https://fedorahosted.org/sssd/ticket/1205 | |||||
2012-02-21 | Don't give memory context in confdb where not needed | Jan Zeleny | 1 | -3/+3 | |
2012-02-10 | SUDO responder: check if the input is a UTF-8 string | Pavel Březina | 1 | -0/+7 | |
https://fedorahosted.org/sssd/ticket/1171 | |||||
2012-02-06 | SUDO Integration - fix offline behaviour | Pavel Březina | 1 | -2/+2 | |
2012-02-04 | SUDO Integration - responder 'sudo_timed' option | Pavel Březina | 3 | -1/+32 | |
https://fedorahosted.org/sssd/ticket/1116 | |||||
2012-02-04 | SUDO Integration - in-memory cache in responder | Pavel Březina | 5 | -9/+415 | |
New sudo responder option: cache_timeout https://fedorahosted.org/sssd/ticket/1111 | |||||
2012-01-30 | Fix sudo compilation on RHEL5 | Jakub Hrozek | 1 | -0/+2 | |
2012-01-27 | SUDO Integration - responder command for cn=defaults | Pavel Březina | 4 | -18/+93 | |
https://fedorahosted.org/sssd/ticket/1143 | |||||
2012-01-27 | SUDO Integration - prepare data provider for new responder commands | Pavel Březina | 1 | -1/+1 | |
https://fedorahosted.org/sssd/ticket/1143 | |||||
2012-01-27 | SUDO Integration - make sysdb_get_sudo_filter() more configurable | Pavel Březina | 1 | -2/+5 | |
https://fedorahosted.org/sssd/ticket/1143 | |||||
2012-01-27 | Rename sss_dp_type to sss_dp_sudo_type | Stephen Gallagher | 2 | -4/+4 | |
I pushed an older version of this patch that had the incorrect name. This is the interdiff. | |||||
2012-01-27 | Use the new SUDO request in DP and sudo responder | Jakub Hrozek | 3 | -216/+67 | |
Also remove the old request implementation https://fedorahosted.org/sssd/ticket/1115 | |||||
2012-01-27 | SUDO: Provide a sudo DP request based on the internal_req | Jakub Hrozek | 2 | -0/+144 | |
2012-01-23 | DP: Fix bugs in sss_dp_get_account_int | Stephen Gallagher | 1 | -0/+1 | |
The conversion to the tevent_req style introduced numerous bugs related to memory management of the various client requests. In some circumstances, this could cause memory corruption and segmentation faults in the NSS responder. This patch makes the following changes: 1) Rename the internal lookup from subreq to sidereq, to indicate that it is not a sub-request of the current lookup (and therefore is not cancelled if the current request is). 2) Change the handling of the callback loops since they call tevent_req_[done|error], which results in them being freed (and therefore removed from the cb_list. This was the source of the memory corruption that would occasionally result in dereferencing an unreadable request. 3) Remove the unnecessary sss_dp_get_account_int_recv() function and change sss_dp_get_account_done() so that it only frees the sidereq. All of the waiting processes have already been signaled with the final results from sss_dp_get_account_int_done() | |||||
2012-01-21 | RESPONDER: Extend sss_dp_account_send() to include extra data | Stephen Gallagher | 1 | -1/+1 | |
Some NSS maps such as 'services' require more values to be passed to the data provider than just the name or ID. In these cases, we will amend an optional component to filter value to pass to the data provider backend. | |||||
2012-01-17 | SUDO Integration review issues | Pavel Březina | 2 | -1/+4 | |
2011-12-16 | SUDO Integration - responder - get sudo rules logic | Jakub Hrozek | 1 | -2/+444 | |
2011-12-16 | SUDO Integration - responder | Pavel Březina | 6 | -0/+1041 | |