bzr branch
http://bzr.recompile.se/loggerhead/mandos/release
36
by Teddy Hogeborn
* TODO: Converted to org-mode style |
1 |
-*- org -*- |
2 |
||
237.5.2
by Teddy Hogeborn
* mandos (ClientHandler.handle): Set up the GnuTLS session object |
3 |
* _attribute_((nonnull)) |
24.1.155
by Björn Påhlsson
mandos server: Added debuglevel that adjust at what level information |
4 |
|
5 |
* Release critical |
|
6 |
** TODO Change make-run-server to not include --no-dbus |
|
237.5.2
by Teddy Hogeborn
* mandos (ClientHandler.handle): Set up the GnuTLS session object |
7 |
|
171
by Teddy Hogeborn
Renamed "password-request" to "mandos-client". |
8 |
* mandos-client |
237.2.118
by Teddy Hogeborn
* mandos: White-space fixes only. |
9 |
** TODO [#B] use scandir(3) instead of readdir(3) |
237.2.152
by Teddy Hogeborn
* plugins.d/splashy.c: Use exit codes from <sysexits.h>. |
10 |
** TODO [#B] Prefix all debug output with "Mandos plugin " + program_invocation_short_name |
237.2.128
by Teddy Hogeborn
* plugins.d/mandos-client.c (main): Bug fix: Check result of setgid(). |
11 |
** TODO [#B] Retry a server which has a non-definite reply: |
237.2.126
by Teddy Hogeborn
* plugin-runner.c: Minor stylistic changes. |
12 |
*** A closed connection during the TLS handshake |
13 |
*** A TCP timeout |
|
237.2.128
by Teddy Hogeborn
* plugins.d/mandos-client.c (main): Bug fix: Check result of setgid(). |
14 |
** TODO [#B] Use capabilities instead of seteuid(). |
237.2.176
by Teddy Hogeborn
TODO file changes. |
15 |
** TODO [#A] Retry --connect forever |
237.2.118
by Teddy Hogeborn
* mandos: White-space fixes only. |
16 |
|
17 |
* splashy |
|
18 |
** TODO [#B] use scandir(3) instead of readdir(3) |
|
237.2.152
by Teddy Hogeborn
* plugins.d/splashy.c: Use exit codes from <sysexits.h>. |
19 |
** TODO [#B] Prefix all debug output with "Mandos plugin " + program_invocation_short_name |
237.2.118
by Teddy Hogeborn
* mandos: White-space fixes only. |
20 |
|
21 |
* usplash |
|
237.2.177
by Teddy Hogeborn
Bug fix: mandos-client needs GnuPG but lacked a dependency on it. The |
22 |
** TODO [#A] Make it work again |
237.2.118
by Teddy Hogeborn
* mandos: White-space fixes only. |
23 |
** TODO [#B] use scandir(3) instead of readdir(3) |
237.2.152
by Teddy Hogeborn
* plugins.d/splashy.c: Use exit codes from <sysexits.h>. |
24 |
** TODO [#B] Prefix all debug output with "Mandos plugin " + program_invocation_short_name |
24.1.155
by Björn Påhlsson
mandos server: Added debuglevel that adjust at what level information |
25 |
** TODO Use [[info:libc:Argz%20Functions][argz_extract]] |
237.2.128
by Teddy Hogeborn
* plugins.d/mandos-client.c (main): Bug fix: Check result of setgid(). |
26 |
|
27 |
* askpass-fifo |
|
237.2.152
by Teddy Hogeborn
* plugins.d/splashy.c: Use exit codes from <sysexits.h>. |
28 |
** TODO [#B] Prefix all debug output with "Mandos plugin " + program_invocation_short_name |
237.2.128
by Teddy Hogeborn
* plugins.d/mandos-client.c (main): Bug fix: Check result of setgid(). |
29 |
** TODO [#B] Drop privileges after opening FIFO. |
237.2.121
by Teddy Hogeborn
* plugins.d/mandos-client.c (start_mandos_communication): Check |
30 |
|
31 |
* password-prompt |
|
237.2.152
by Teddy Hogeborn
* plugins.d/splashy.c: Use exit codes from <sysexits.h>. |
32 |
** TODO [#B] Prefix all debug output with "Mandos plugin " + program_invocation_short_name |
237.2.176
by Teddy Hogeborn
TODO file changes. |
33 |
** TODO [#B] lock stdin (with flock()?) |
237.2.118
by Teddy Hogeborn
* mandos: White-space fixes only. |
34 |
|
24.1.155
by Björn Påhlsson
mandos server: Added debuglevel that adjust at what level information |
35 |
* plymouth |
36 |
** TODO Use [[info:libc:Argz%20Functions][argz_extract]] |
|
37 |
||
237.2.176
by Teddy Hogeborn
TODO file changes. |
38 |
* TODO [#B] passdev |
237.2.140
by Teddy Hogeborn
* plugins.d/password-prompt.c (main): Fix "-Wconversion" warning. |
39 |
|
237.2.3
by Teddy Hogeborn
Merge "mandos-list" from belorn. |
40 |
* plugin-runner |
41 |
** TODO [#B] use scandir(3) instead of readdir(3) |
|
237.2.107
by Teddy Hogeborn
* debian/control (Standards-Version): Changed to "3.8.1". |
42 |
** TODO [#C] use same file name rules as run-parts(8) |
24.1.145
by Björn Påhlsson
todo |
43 |
** kernel command line option for debug info |
237.5.2
by Teddy Hogeborn
* mandos (ClientHandler.handle): Set up the GnuTLS session object |
44 |
** TODO [$B] Use openat() and readdir64() |
45 |
http://udrepper.livejournal.com/19395.html |
|
237.2.3
by Teddy Hogeborn
Merge "mandos-list" from belorn. |
46 |
|
87
by Teddy Hogeborn
* Makefile: Bug fix: fixed creation of man pages in "plugins.d". |
47 |
* mandos (server) |
237.2.176
by Teddy Hogeborn
TODO file changes. |
48 |
** TODO [#B] Log level :BUGS: |
49 |
** TODO Persistent state :BUGS: |
|
50 |
/var/lib/mandos/* |
|
51 |
*** TODO /etc/mandos/clients.d/*.conf
|
|
52 |
Watch this directory and add/remove/update clients?
|
|
53 |
** TODO [#C] config for TXT record
|
|
54 |
** TODO Log level option
|
|
55 |
syslogger.setLevel(logging.WARNING)
|
|
56 |
+ SetLogLevel D-Bus call
|
|
57 |
** TODO Implement --foreground :BUGS:
|
|
182
by Teddy Hogeborn
* Makefile (install): Use "install-client-nokey". |
58 |
[[info:standards:Option%20Table][Table of Long Options]]
|
59 |
** TODO Implement --socket
|
|
60 |
[[info:standards:Option%20Table][Table of Long Options]]
|
|
237.2.176
by Teddy Hogeborn
TODO file changes. |
61 |
** TODO Date+time on console log messages :BUGS:
|
64
by Teddy Hogeborn
* mandos-client.c (print_out_password): Strip trailing '\n'. |
62 |
Is this the default?
|
237.2.176
by Teddy Hogeborn
TODO file changes. |
63 |
** TODO [#C] DBusServiceObjectUsingSuper
|
64 |
** TODO [#B] Global enable/disable flag
|
|
65 |
** TODO [#B] By-client countdown on secrets given
|
|
66 |
** TODO [#B] Fix problem with fsck taking a really long time
|
|
237.2.130
by Teddy Hogeborn
* init.d-mandos: Bug fix: Correct the LSB header. |
67 |
Whenever a client successfully gets a secret it could get a
|
68 |
one-time timeout boost to allow for an fsck-incurred delay
|
|
237.2.176
by Teddy Hogeborn
TODO file changes. |
69 |
** TODO [#A] Delay before client receives key
|
237.2.140
by Teddy Hogeborn
* plugins.d/password-prompt.c (main): Fix "-Wconversion" warning. |
70 |
This would give an operator opportunity to cancel the request if
|
71 |
desired.
|
|
237.2.176
by Teddy Hogeborn
TODO file changes. |
72 |
** TODO [#A] Client manual approval mode
|
237.2.140
by Teddy Hogeborn
* plugins.d/password-prompt.c (main): Fix "-Wconversion" warning. |
73 |
A client needs manual approval on the server before it gets the
|
74 |
secret
|
|
237.2.176
by Teddy Hogeborn
TODO file changes. |
75 |
** TODO [#B] Support RFC 3339 time duration syntax
|
237.5.1
by Teddy Hogeborn
Initial design on approval system. |
76 |
** More D-Bus methods
|
77 |
*** NeedsApproval(50, True) -> timeout, default approve
|
|
78 |
Default approval is configurable, but True by default
|
|
79 |
+ Approval(True) -> approve sending saved
|
|
80 |
+ Approval(False) -> Close client connection immediately
|
|
81 |
*** NeedsPassword(50) - Timeout, default disapprove
|
|
82 |
+ SetPass(u"gazonk", True) -> Approval, persistent
|
|
83 |
+ Approval(False) -> Close client connection immediately
|
|
237.5.2
by Teddy Hogeborn
* mandos (ClientHandler.handle): Set up the GnuTLS session object |
84 |
** TODO [#C] python-parsedatetime
|
85 |
** TODO [#C] systemd/launchd
|
|
86 |
http://0pointer.de/blog/projects/systemd.html
|
|
24.1.149
by Björn Påhlsson
Changed ForkingMixIn in favor of multiprocessing |
87 |
** TODO Separate logging logic to own object
|
88 |
** TODO make clients to a dict!
|
|
24.1.161
by Björn Påhlsson
minor debug info for plugin-runner. |
89 |
** TODO [#A] Limit approved_delay to max gnutls/tls timeout value
|
36
by Teddy Hogeborn
* TODO: Converted to org-mode style |
90 |
|
237.2.6
by Teddy Hogeborn
* mandos (Client.timeout, Client.interval): Changed from being a |
91 |
* mandos.xml
|
92 |
** [[file:mandos.xml::XXX][Document D-Bus interface]]
|
|
237.2.176
by Teddy Hogeborn
TODO file changes. |
93 |
Remove mention of lack of such interface in BUGS section
|
24.1.143
by Björn Påhlsson
added documentation todo |
94 |
** Add mandos contact info in manual pages
|
237.2.6
by Teddy Hogeborn
* mandos (Client.timeout, Client.interval): Changed from being a |
95 |
|
237.2.176
by Teddy Hogeborn
TODO file changes. |
96 |
* TODO [#A] Provide and install /etc/dbus-1/system.d/mandos.conf
|
237.2.6
by Teddy Hogeborn
* mandos (Client.timeout, Client.interval): Changed from being a |
97 |
|
237.2.71
by Teddy Hogeborn
* plugin-runner.c: Comment change. |
98 |
* mandos-ctl
|
237.2.6
by Teddy Hogeborn
* mandos (Client.timeout, Client.interval): Changed from being a |
99 |
*** Handle "no D-Bus server" and/or "no Mandos server found" better
|
237.2.3
by Teddy Hogeborn
Merge "mandos-list" from belorn. |
100 |
*** [#B] --dump option
|
237.2.174
by Teddy Hogeborn
More consistent terminology: Clients are no longer "invalid" - they |
101 |
** TODO Support RFC 3339 time duration syntax
|
36
by Teddy Hogeborn
* TODO: Converted to org-mode style |
102 |
|
237.2.140
by Teddy Hogeborn
* plugins.d/password-prompt.c (main): Fix "-Wconversion" warning. |
103 |
* TODO mandos-dispatch
|
104 |
Listens for specified D-Bus signals and spawns shell commands with
|
|
105 |
arguments.
|
|
106 |
||
237.2.138
by Teddy Hogeborn
* TODO: Updated. |
107 |
* mandos-monitor
|
24.1.155
by Björn Påhlsson
mandos server: Added debuglevel that adjust at what level information |
108 |
** TODO help should be toggable
|
237.2.149
by Teddy Hogeborn
* mandos (DBusObjectWithProperties.Introspect): Add the name |
109 |
** Urwid client data displayer
|
237.2.176
by Teddy Hogeborn
TODO file changes. |
110 |
Better view of client data in the listing
|
237.2.90
by Teddy Hogeborn
Merge from pipe IPC branch. |
111 |
*** Properties popup
|
24.1.154
by Björn Påhlsson
merge |
112 |
** Nicer crashes. Stack traces Messes up shell.
|
113 |
*** Print a nice "We are sorry" message, save stack trace to log.
|
|
237.2.3
by Teddy Hogeborn
Merge "mandos-list" from belorn. |
114 |
|
228
by Teddy Hogeborn
* INSTALL: Add instructions on how to set the correct network |
115 |
* mandos-keygen
|
24.1.126
by Björn Påhlsson
small stuff |
116 |
** TODO Loop until passwords match when run interactively
|
228
by Teddy Hogeborn
* INSTALL: Add instructions on how to set the correct network |
117 |
** TODO "--secfile" option
|
118 |
Using the "secfile" option instead of "secret"
|
|
119 |
** TODO [#B] "--test" option
|
|
120 |
For testing decryption before rebooting.
|
|
67
by Teddy Hogeborn
* mandos-keygen: New program to generate new client keys on |
121 |
|
237.2.133
by Teddy Hogeborn
* debian/control (Standards-Version): Updated to "2.8.3". |
122 |
* Makefile
|
237.5.2
by Teddy Hogeborn
* mandos (ClientHandler.handle): Set up the GnuTLS session object |
123 |
** TODO Add "--Xlinker --as-needed"
|
124 |
http://udrepper.livejournal.com/19395.html
|
|
237.2.176
by Teddy Hogeborn
TODO file changes. |
125 |
** TODO [#C] Implement DEB_BUILD_OPTIONS
|
237.2.133
by Teddy Hogeborn
* debian/control (Standards-Version): Updated to "2.8.3". |
126 |
http://www.debian.org/doc/debian-policy/ch-source.html#s-debianrules-options
|
127 |
||
237.2.38
by Teddy Hogeborn
* debian/mandos-client.postinst: Converted to Bourne shell. Also |
128 |
* Package
|
67
by Teddy Hogeborn
* mandos-keygen: New program to generate new client keys on |
129 |
** /usr/share/initramfs-tools/hooks/mandos
|
237.2.107
by Teddy Hogeborn
* debian/control (Standards-Version): Changed to "3.8.1". |
130 |
*** TODO [#C] use same file name rules as run-parts(8)
|
237.2.26
by Teddy Hogeborn
* README (The Plugin System): Removed redundant text about options and |
131 |
*** TODO [#C] Do not install in initrd.img if configured not to.
|
237.2.71
by Teddy Hogeborn
* plugin-runner.c: Comment change. |
132 |
Use "/etc/initramfs-tools/hooksconf.d/mandos"?
|
237.2.26
by Teddy Hogeborn
* README (The Plugin System): Removed redundant text about options and |
133 |
** TODO [#C] /etc/bash_completion.d/mandos
|
88
by Teddy Hogeborn
No code or documentation changes. |
134 |
From XML sources directly?
|
24.1.30
by Björn Påhlsson
Added more stuff to do |
135 |
|
24.1.149
by Björn Påhlsson
Changed ForkingMixIn in favor of multiprocessing |
136 |
* Side Stuff
|
137 |
** TODO Locate which packet move the other bin/sh when busy box is deactivated
|
|
138 |
** TODO contact owner of packet, and ask them to have that shell static in position regardless of busybox
|
|
139 |
||
36
by Teddy Hogeborn
* TODO: Converted to org-mode style |
140 |
|
141 |
#+STARTUP: showall
|