=================================================================== RCS file: /cvsrepo/anoncvs/cvs/src/usr.bin/sudo/Attic/TODO,v retrieving revision 1.8 retrieving revision 1.9 diff -c -r1.8 -r1.9 *** src/usr.bin/sudo/Attic/TODO 2003/11/08 19:17:29 1.8 --- src/usr.bin/sudo/Attic/TODO 2004/09/28 15:10:50 1.9 *************** *** 33,39 **** 13) Should be able to mix Cmnd_Alias's and command args. Ie: pete ALL=PASSWD [A-z]*,!PASSWD root where PASSWD was defined to be /usr/bin/passwd. ! This requires the arg parsing to happen in the yacc grammar. At the very least, commands and args have to become separate tokens in the lexer. --- 33,39 ---- 13) Should be able to mix Cmnd_Alias's and command args. Ie: pete ALL=PASSWD [A-z]*,!PASSWD root where PASSWD was defined to be /usr/bin/passwd. ! This requires the arg parsing to happen in the yacc grammer. At the very least, commands and args have to become separate tokens in the lexer. *************** *** 41,126 **** 15) Add test for how to read ether interfaces in configure script ! 16) An option to make "sudo -s" use the target user's shell might be nice ! (and more like su). Overlaps with the upcoming -i option. ! ! 17) Add configure option to enable old behavior of visudo (O_EXCL)? --without-sudoers-lock? ! 18) Profile sudo again (is the yacc grammar optimal?) ! 19) Zero out encrypted passwords after use. Use an Exit function or some such (have to hook in to emalloc() and friends). Hard (impossible?) to be thorough w/ atexit/on_exit. ! 20) Make 'sudo -l user' if run as root do a "sudo -l" output for the specified user. ! 21) Use strtol() and strtoul(), not atoi() ! 23) Look into %e, %p, %k in parse.lex ! 23) Make syslog stuff work on vanilla ultrix ! 24) Implement date_format and log_format options. ! 25) Add support for: Default:user@host ! 26) Do login-style -sh hack for sudo -s? (new option or do it always?) ! 27) Make visudo rcs-aware ! ! 28) Add support for parsing multiple sudoers files. Basically make _PATH_SUDOERS be a colon-separated list of pathname like EDITOR. Requires _PATH_SUDOERS_TMP chages (perhaps "%s.tmp"). ! 29) Add -i (simulate initial login) option as per 946 +sudo ! (requires two-pass parser). Also add "default_path" Defaults option ! to go with it. (See MINUS_I.patch) ! ! 30) Some people want to be able to specify a special password in sudoers in addition or instead of the normal one. The best argument for this so far is to be able to use separate passwords for the target users that are not the passwd file ones. ! 31) Add support for trusted users. E.g. allow user to run a certain command regardless of what dir it is in if it is owned by the trusted user. ! 32) Add mechanism to choose logfile based on RunasUser ! ! 33) Split the parser into two stages. The first parse checks for syntax and sets the Defaults options and sets up the data structures to check a user. The second stage does the actual user check. ! 34) Add a flag similar to '-l' but that spits out sudo commands in a format suitable for cut & paste (requires parser overhaul first). ! 35) Someone wants a recursive version of the dir specifier. Ie: SOME_MODIFIER:/usr/local/ to allow anything under /usr/local to be run. ! 36) An option to set the shell to the target user would make sense. See other target user-related issues above. ! 37) Add an option (-D) to dump the defaults after the sudoers file has been parsed. Should only be available to root and should allow a -u user modifier. ! 38) For sudo 1.7 wipe out the environment by default. ! 39) Allow /etc/sudoers to be a symlink but require the parent dir to be root-owned and not writable by anything else. Should really traverse the tree to the root doing this. ! 40) Improve interfaces.c STREAMS code (see ntpd's ntp_io.c for hints) ! 41) Wildcard support for user and group names? (netgroup too?) ! 42) If root_sudo is off, still allow sudo -u to non-root users? ! 43) Add configure option to id user based on euid not ruid? ! 44) Split $EDITOR/$VISUAL in visudo into an argument vector based on whitespace ! 45) Use proper links in .pod files --- 41,143 ---- 15) Add test for how to read ether interfaces in configure script ! 16) Add configure option to enable old behavior of visudo (O_EXCL)? --without-sudoers-lock? ! 17) Profile sudo again (is the yacc grammar optimal?) ! 18) Zero out encrypted passwords after use. Use an Exit function or some such (have to hook in to emalloc() and friends). Hard (impossible?) to be thorough w/ atexit/on_exit. ! 19) Make 'sudo -l user' if run as root do a "sudo -l" output for the specified user. ! 20) Use strtol() and strtoul(), not atoi() ! 21) Look into %e, %p, %k in parse.lex ! 22) Make syslog stuff work on vanilla ultrix ! 23) Implement date_format and log_format options. ! 24) Add support for: Default:user@host ! 25) Make visudo rcs-aware ! 26) Add support for parsing multiple sudoers files. Basically make _PATH_SUDOERS be a colon-separated list of pathname like EDITOR. Requires _PATH_SUDOERS_TMP chages (perhaps "%s.tmp"). ! 27) Some people want to be able to specify a special password in sudoers in addition or instead of the normal one. The best argument for this so far is to be able to use separate passwords for the target users that are not the passwd file ones. ! 28) Add support for trusted users. E.g. allow user to run a certain command regardless of what dir it is in if it is owned by the trusted user. ! 28) Split the parser into two stages. The first parse checks for syntax and sets the Defaults options and sets up the data structures to check a user. The second stage does the actual user check. ! 30) Add a flag similar to '-l' but that spits out sudo commands in a format suitable for cut & paste (requires parser overhaul first). ! 31) Someone wants a recursive version of the dir specifier. Ie: SOME_MODIFIER:/usr/local/ to allow anything under /usr/local to be run. ! 31) An option to set the shell to the target user would make sense. See other target user-related issues above. ! 33) Add an option (-D) to dump the defaults after the sudoers file has been parsed. Should only be available to root and should allow a -u user modifier. ! 34) For sudo 1.7 wipe out the environment by default. ! 35) Allow /etc/sudoers to be a symlink but require the parent dir to be root-owned and not writable by anything else. Should really traverse the tree to the root doing this. ! 36) Improve interfaces.c STREAMS code (see ntpd's ntp_io.c for hints) ! 37) Wildcard support for user and group names? (netgroup too?) ! 38) If root_sudo is off, still allow sudo -u to non-root users? ! 39) Add configure option to id user based on euid not ruid? ! 40) Split $EDITOR/$VISUAL in visudo into an argument vector based on whitespace ! 41) Use proper links in .pod files ! ! 42) Parse gids like %#0 ! ! 43) Add support for systrace (requires that sudo fork and be persistent) ! ! 44) For AIX, call getuserattr() to get resource limits and set them ! as appropriate, see: ! http://nscp.upenn.edu/aix4.3html/libs/basetrf1/getuserattr.htm#A16691a89 ! ! 45) Add an insult_path variable that is intialized to "builtin" but that ! can point to other files containing an insult count as the first ! line and that have a constant record length (sparse files) for ! easy seeking. ! ! 46) Investigate using glob(3) instead of fnmatch(3) for path matching. That ! way we can stat each potential match like we normally would. Patterns ! ending in '/*' can be replaced with '/basename' as an optimization. ! ! 47) Some way of using a new pty for the program run via sudo would prevent ! access to the caller's /dev/tty (but probably makes job control tricky). ! ! 48) Maybe have a database of checksums that commands are verified against. ! Basically replace the st_ino/st_dev check with a checksum lookup. ! ! 49) Look into testing writability of a file via sudoedit *before* doing ! the edit; e.g., try opening with O_APPEND. ! ! 50) Add Makefile.in bits to autogenerate Solaris and HP-UX packages