bzr branch
http://bzr.recompile.se/loggerhead/mandos/trunk
36
by Teddy Hogeborn
* TODO: Converted to org-mode style |
1 |
-*- org -*- |
2 |
||
640
by Teddy Hogeborn
Use architecture libdir. |
3 |
* GIT |
758
by Teddy Hogeborn
plugin-runner.xml (EXAMPLE): Use the /usr/lib/<arch> directory. |
4 |
** General: [[https://www.atlassian.com/git/workflows][Git Workflows]], [[http://gitimmersion.com/][Git Immersion]], [[https://news.ycombinator.com/item?id=7036628][Simple git workflow is simple]] [[https://news.ycombinator.com/item?id=9661349][On undoing, fixing, or removing commits in git]] |
651
by Teddy Hogeborn
Documentation change to clarify support of --connect option. |
5 |
** Intro: [[http://www.eyrie.org/~eagle/notes/debian/git.html#combine][Using Git for Debian Packaging]] |
640
by Teddy Hogeborn
Use architecture libdir. |
6 |
** Use: [[https://honk.sigxcpu.org/piki/projects/git-buildpackage/][git-buildpackage]] |
7 |
** Migration |
|
8 |
tailor? |
|
9 |
Using bzr-fastimport: [[http://www.fusonic.net/en/blog/2013/03/26/migrating-from-bazaar-to-git/][Migrating from Bazaar to Git]] |
|
10 |
** Unresolved: [[http://jameswestby.net/bzr/builddeb/user_manual/split.html][bzr builddeb split mode]] |
|
651
by Teddy Hogeborn
Documentation change to clarify support of --connect option. |
11 |
Maybe: [[http://honk.sigxcpu.org/projects/git-buildpackage/manual-html/gbp.import.html#GBP.IMPORT.UPSTREAM.GIT.NOTARBALL][git-buildpackage - No upstream tarballs]] |
12 |
[[http://www.python.org/dev/peps/pep-0374/][PEP 374 - Choosing a distributed VCS for the Python project]] |
|
13 |
[[http://www.emacswiki.org/emacs/GitForEmacsDevs][Git For Emacs Devs]] |
|
640
by Teddy Hogeborn
Use architecture libdir. |
14 |
|
501
by Teddy Hogeborn
* mandos-clients.conf.xml (OPTIONS/timeout): No longer used when |
15 |
* [[http://www.undeadly.org/cgi?action=article&sid=20110530221728][OpenBSD]] |
16 |
||
614
by Teddy Hogeborn
* mandos: Comment changes. |
17 |
* Testing |
18 |
** python-nemu |
|
19 |
||
462
by Teddy Hogeborn
* plugins.d/plymouth.c: Fixed comment to "Plymouth" instead of "Usplash". |
20 |
* mandos-applet |
21 |
||
171
by Teddy Hogeborn
Renamed "password-request" to "mandos-client". |
22 |
* mandos-client |
743
by Teddy Hogeborn
Automatically determine the number of DH bits in the TLS handshake. |
23 |
** TODO [#A] --dh-params=FILE |
365
by Teddy Hogeborn
* plugins.d/mandos-client.c (main): Bug fix: Check result of setgid(). |
24 |
** TODO [#B] Use capabilities instead of seteuid(). |
739
by Teddy Hogeborn
mandos (Client.config_parser): Move comment to correct place. |
25 |
https://forums.grsecurity.net/viewtopic.php?f=7&t=2522 |
484
by Teddy Hogeborn
* Makefile (plugins.d/mandos-client): Bug fix: Put $^ before all |
26 |
** TODO [#B] Use getaddrinfo(hints=AI_NUMERICHOST) instead of inet_pton() |
602
by Teddy Hogeborn
* plugins.d/mandos-client (mandos_context): Moved to inside "main()". |
27 |
** TODO [#C] Make start_mandos_communication() take "struct server". |
734
by Teddy Hogeborn
* mandos.service ([Unit]/Documentation): New. |
28 |
** TODO [#C] --interfaces=regex,eth*,noregex (bridge-utils-interfaces(5)) |
758
by Teddy Hogeborn
plugin-runner.xml (EXAMPLE): Use the /usr/lib/<arch> directory. |
29 |
** TODO [#C] Remove code for GNU libc < 2.15 |
355
by Teddy Hogeborn
* mandos: White-space fixes only. |
30 |
|
31 |
* splashy |
|
32 |
** TODO [#B] use scandir(3) instead of readdir(3) |
|
33 |
||
512
by Björn Påhlsson
usplash is deprecated |
34 |
* usplash (Deprecated) |
761
by Teddy Hogeborn
mandos.service: Use Type=dbus (implicitly). |
35 |
** TODO [#B] Make it work again |
355
by Teddy Hogeborn
* mandos: White-space fixes only. |
36 |
** TODO [#B] use scandir(3) instead of readdir(3) |
365
by Teddy Hogeborn
* plugins.d/mandos-client.c (main): Bug fix: Check result of setgid(). |
37 |
|
38 |
* askpass-fifo |
|
358
by Teddy Hogeborn
* plugins.d/mandos-client.c (start_mandos_communication): Check |
39 |
|
40 |
* password-prompt |
|
413
by Teddy Hogeborn
TODO file changes. |
41 |
** TODO [#B] lock stdin (with flock()?) |
484
by Teddy Hogeborn
* Makefile (plugins.d/mandos-client): Bug fix: Put $^ before all |
42 |
|
43 |
* plymouth |
|
355
by Teddy Hogeborn
* mandos: White-space fixes only. |
44 |
|
413
by Teddy Hogeborn
TODO file changes. |
45 |
* TODO [#B] passdev |
377
by Teddy Hogeborn
* plugins.d/password-prompt.c (main): Fix "-Wconversion" warning. |
46 |
|
240
by Teddy Hogeborn
Merge "mandos-list" from belorn. |
47 |
* plugin-runner |
24.1.174
by Björn Påhlsson
* Makefile (CFLAGS): Added "-lrt" to include real time library. |
48 |
** TODO handle printing for errors for plugins |
606
by Teddy Hogeborn
* mandos: New "--foreground" option. |
49 |
*** Hook up stderr of plugins, buffer them, and prepend "Mandos Plugin [plugin name]" |
344
by Teddy Hogeborn
* debian/control (Standards-Version): Changed to "3.8.1". |
50 |
** TODO [#C] use same file name rules as run-parts(8) |
24.1.145
by Björn Påhlsson
todo |
51 |
** kernel command line option for debug info |
758
by Teddy Hogeborn
plugin-runner.xml (EXAMPLE): Use the /usr/lib/<arch> directory. |
52 |
** TODO [#C] Remove code for GNU libc < 2.15 |
240
by Teddy Hogeborn
Merge "mandos-list" from belorn. |
53 |
|
87
by Teddy Hogeborn
* Makefile: Bug fix: fixed creation of man pages in "plugins.d". |
54 |
* mandos (server) |
747
by Teddy Hogeborn
mandos-keygen: Bug fix: Only use one SSH key from ssh-keyscan |
55 |
** TODO [#B] --notify-command |
56 |
This would allow the mandos.service to use |
|
57 |
--notify-command="systemd-notify --pid READY=1" |
|
413
by Teddy Hogeborn
TODO file changes. |
58 |
** TODO [#B] Log level :BUGS: |
59 |
*** TODO /etc/mandos/clients.d/*.conf |
|
60 |
Watch this directory and add/remove/update clients?
|
|
61 |
** TODO [#C] config for TXT record
|
|
505.2.11
by Björn Påhlsson
todo updates |
62 |
** TODO Log level dbus option
|
63 |
SetLogLevel D-Bus call
|
|
413
by Teddy Hogeborn
TODO file changes. |
64 |
** TODO [#C] DBusServiceObjectUsingSuper
|
65 |
** TODO [#B] Global enable/disable flag
|
|
505.2.11
by Björn Påhlsson
todo updates |
66 |
** TODO [#B] By-client countdown on number of secrets given
|
584
by Teddy Hogeborn
* mandos (Client.runtime_expansions): Add "expires" and (bug fix) |
67 |
** D-Bus Client method NeedsPassword(50) - Timeout, default disapprove
|
416.1.1
by Teddy Hogeborn
Initial design on approval system. |
68 |
+ SetPass(u"gazonk", True) -> Approval, persistent
|
418
by teddy at bsnet
* TODO: Clarifications. |
69 |
+ Approve(False) -> Close client connection immediately
|
416.1.2
by Teddy Hogeborn
* mandos (ClientHandler.handle): Set up the GnuTLS session object |
70 |
** TODO [#C] python-parsedatetime
|
24.1.149
by Björn Påhlsson
Changed ForkingMixIn in favor of multiprocessing |
71 |
** TODO Separate logging logic to own object
|
759
by Teddy Hogeborn
Merge change to add local route when network is "unreachable". |
72 |
** TODO [#B] Limit approval_delay to max gnutls/tls timeout value
|
24.1.164
by Björn Påhlsson
merge |
73 |
** TODO [#B] break the wait on approval_delay if connection dies
|
438
by Teddy Hogeborn
* mandos (Client.runtime_expansions): New attribute containing the |
74 |
** TODO Generate Client.runtime_expansions from client options + extra
|
75 |
** TODO Allow %%(checker)s as a runtime expansion
|
|
484
by Teddy Hogeborn
* Makefile (plugins.d/mandos-client): Bug fix: Put $^ before all |
76 |
** TODO Use python-tlslite?
|
505.3.16
by teddy at bsnet
* network-hooks.d/bridge: Use "/usr/sbin/brctl" explicitly. |
77 |
** TODO D-Bus AddClient() method on server object
|
611
by Teddy Hogeborn
* mandos (Client.start_checker): Add comment. Break long line. |
78 |
** TODO Use org.freedesktop.DBus.Method.NoReply annotation on async methods. :2:
|
79 |
** TODO Support [[http://dbus.freedesktop.org/doc/dbus-specification.html#standard-interfaces-objectmanager][org.freedesktop.DBus.ObjectManager]] interface on server object :2:
|
|
539
by teddy at recompile
Reorder TODO entries |
80 |
Deprecate methods GetAllClients(), GetAllClientsWithProperties()
|
81 |
and signals ClientAdded and ClientRemoved.
|
|
546
by Teddy Hogeborn
* debian/rules (binary-common): Exclude network-hooks.d from |
82 |
** TODO Save state periodically to recover better from hard shutdowns
|
556
by Teddy Hogeborn
* DBUS-API (se.recompile.Mandos.Client.LastCheckerStatus): New |
83 |
** TODO CheckerCompleted method, deprecate CheckedOK
|
563
by Teddy Hogeborn
* network-hooks.d/bridge: Move "start" and "stop" commands to separate |
84 |
** TODO Secret Service API?
|
85 |
http://standards.freedesktop.org/secret-service/
|
|
732
by Teddy Hogeborn
Emit D-Bus "org.freedesktop.DBus.Properties.PropertiesChanged" signal. |
86 |
** TODO Remove D-Bus interfaces with old domain name :2:
|
729
by Teddy Hogeborn
mandos: Stop using str() and remove unnecessary unicode() calls. |
87 |
** TODO Remove old string_to_delta format :2:
|
708
by Teddy Hogeborn
mandos-keygen: Generate "checker" option to use SSH fingerprints. |
88 |
** TODO http://0pointer.de/blog/projects/stateless.html
|
89 |
*** tmpfiles snippet to create /var/lib/mandos with right user+perms
|
|
90 |
*** File in /usr/lib/sysusers.d to create user+group "_mandos"
|
|
91 |
** TODO Error handling on error parsing config files
|
|
92 |
** TODO init.d script error handling
|
|
729
by Teddy Hogeborn
mandos: Stop using str() and remove unnecessary unicode() calls. |
93 |
** TODO D-Bus server properties; address, port, interface, etc. :2:
|
742
by Teddy Hogeborn
Add ":!RSA" to GnuTLS priority string, to disallow non-DHE kx. |
94 |
** TODO [#C] In Python 3.3, use shlex.quote() instead of re.escape()
|
36
by Teddy Hogeborn
* TODO: Converted to org-mode style |
95 |
|
243
by Teddy Hogeborn
* mandos (Client.timeout, Client.interval): Changed from being a |
96 |
* mandos.xml
|
24.1.143
by Björn Påhlsson
added documentation todo |
97 |
** Add mandos contact info in manual pages
|
243
by Teddy Hogeborn
* mandos (Client.timeout, Client.interval): Changed from being a |
98 |
|
308
by Teddy Hogeborn
* plugin-runner.c: Comment change. |
99 |
* mandos-ctl
|
243
by Teddy Hogeborn
* mandos (Client.timeout, Client.interval): Changed from being a |
100 |
*** Handle "no D-Bus server" and/or "no Mandos server found" better
|
240
by Teddy Hogeborn
Merge "mandos-list" from belorn. |
101 |
*** [#B] --dump option
|
729
by Teddy Hogeborn
mandos: Stop using str() and remove unnecessary unicode() calls. |
102 |
** TODO Remove old string_to_delta format :2:
|
36
by Teddy Hogeborn
* TODO: Converted to org-mode style |
103 |
|
377
by Teddy Hogeborn
* plugins.d/password-prompt.c (main): Fix "-Wconversion" warning. |
104 |
* TODO mandos-dispatch
|
105 |
Listens for specified D-Bus signals and spawns shell commands with
|
|
106 |
arguments.
|
|
107 |
||
375
by Teddy Hogeborn
* TODO: Updated. |
108 |
* mandos-monitor
|
24.1.174
by Björn Påhlsson
* Makefile (CFLAGS): Added "-lrt" to include real time library. |
109 |
** TODO help should be toggleable
|
386
by Teddy Hogeborn
* mandos (DBusObjectWithProperties.Introspect): Add the name |
110 |
** Urwid client data displayer
|
413
by Teddy Hogeborn
TODO file changes. |
111 |
Better view of client data in the listing
|
327
by Teddy Hogeborn
Merge from pipe IPC branch. |
112 |
*** Properties popup
|
537
by Björn Påhlsson
nicer stacktrace when mandos-monitor fail during startup |
113 |
** Print a nice "We are sorry" message, save stack trace to log.
|
618
by Teddy Hogeborn
* mandos: Bug fix: Make boolean options work from the config file |
114 |
** Rename module "gobject" to "GObject".
|
240
by Teddy Hogeborn
Merge "mandos-list" from belorn. |
115 |
|
228
by Teddy Hogeborn
* INSTALL: Add instructions on how to set the correct network |
116 |
* mandos-keygen
|
117 |
** TODO "--secfile" option
|
|
118 |
Using the "secfile" option instead of "secret"
|
|
119 |
** TODO [#B] "--test" option
|
|
120 |
For testing decryption before rebooting.
|
|
67
by Teddy Hogeborn
* mandos-keygen: New program to generate new client keys on |
121 |
|
275
by Teddy Hogeborn
* debian/mandos-client.postinst: Converted to Bourne shell. Also |
122 |
* Package
|
67
by Teddy Hogeborn
* mandos-keygen: New program to generate new client keys on |
123 |
** /usr/share/initramfs-tools/hooks/mandos
|
344
by Teddy Hogeborn
* debian/control (Standards-Version): Changed to "3.8.1". |
124 |
*** TODO [#C] use same file name rules as run-parts(8)
|
263
by Teddy Hogeborn
* README (The Plugin System): Removed redundant text about options and |
125 |
*** TODO [#C] Do not install in initrd.img if configured not to.
|
308
by Teddy Hogeborn
* plugin-runner.c: Comment change. |
126 |
Use "/etc/initramfs-tools/hooksconf.d/mandos"?
|
758
by Teddy Hogeborn
plugin-runner.xml (EXAMPLE): Use the /usr/lib/<arch> directory. |
127 |
** TODO [#C] $(pkg-config --variable=completionsdir bash-completion)
|
88
by Teddy Hogeborn
No code or documentation changes. |
128 |
From XML sources directly?
|
24.1.30
by Björn Påhlsson
Added more stuff to do |
129 |
|
24.1.149
by Björn Påhlsson
Changed ForkingMixIn in favor of multiprocessing |
130 |
* Side Stuff
|
505.1.8
by Teddy Hogeborn
* mandos-ctl: Update copyright year to 2011. |
131 |
** TODO Locate which package moves the other bin/sh when busybox is deactivated
|
132 |
** TODO contact owner of package, and ask them to have that shell static in position regardless of busybox
|
|
24.1.149
by Björn Påhlsson
Changed ForkingMixIn in favor of multiprocessing |
133 |
|
36
by Teddy Hogeborn
* TODO: Converted to org-mode style |
134 |
|
135 |
#+STARTUP: showall
|