Version in base suite: 1.9.16p2-3+deb13u2 Base version: sudo_1.9.16p2-3+deb13u2 Target version: sudo_1.9.16p2-3+deb13u5 Base file: /srv/ftp-master.debian.org/ftp/pool/main/s/sudo/sudo_1.9.16p2-3+deb13u2.dsc Target file: /srv/ftp-master.debian.org/policy/pool/main/s/sudo/sudo_1.9.16p2-3+deb13u5.dsc changelog | 24 ++ patches/0006-exec_mailer-Set-group-as-well-as-uid-when-running-th.patch | 6 patches/0007-upstream-patch-for-CVE-2025-32463.patch | 2 patches/0011-sudo-ignore-user-specified-TZ-environment-variable.patch | 64 +++++++ patches/0012-Remove-TZ-from-sudo-s-working-environment-without-mo.patch | 73 ++++++++ patches/0013-Copy-envp-submit_envp-instead-of-replacing-the-envir.patch | 82 ++++++++++ patches/Whitelist-DPKG_COLORS-environment-variable.diff | 5 patches/X11R6.patch | 27 +++ patches/amd64-ibt.diff | 6 patches/paths-in-samples.diff | 16 + patches/series | 3 patches/spanish.patch | 47 +++-- patches/sudo-ldap-docs.patch | 16 + 13 files changed, 333 insertions(+), 38 deletions(-) dpkg-source: warning: cannot verify inline signature for /srv/release.debian.org/tmp/tmp21i37fgt/sudo_1.9.16p2-3+deb13u2.dsc: no acceptable signature found dpkg-source: warning: cannot verify inline signature for /srv/release.debian.org/tmp/tmp21i37fgt/sudo_1.9.16p2-3+deb13u5.dsc: no acceptable signature found diff -Nru sudo-1.9.16p2/debian/changelog sudo-1.9.16p2/debian/changelog --- sudo-1.9.16p2/debian/changelog 2026-04-11 12:21:02.000000000 +0000 +++ sudo-1.9.16p2/debian/changelog 2026-09-29 14:02:29.000000000 +0000 @@ -1,3 +1,27 @@ +sudo (1.9.16p2-3+deb13u5) trixie; urgency=medium + + * bump version number to allow git-debpush to work again + * This is the first version reaching the archive with + CVE-2026-96512 fixed. + Thanks to Salvatore Bonaccorso (Closes: #1148890) + + -- Marc Haber Tue, 29 Sep 2026 16:02:29 +0200 + +sudo (1.9.16p2-3+deb13u4) trixie; urgency=medium + + * bump version number to allow git-debpush to work again + * This is the first version reaching the archive with + CVE-2026-96512 fixed. + Thanks to Salvatore Bonaccorso (Closes: #1148890) + + -- Marc Haber Tue, 29 Sep 2026 15:24:34 +0200 + +sudo (1.9.16p2-3+deb13u3) trixie; urgency=medium + + * Apply upstream patches to address CVE-2026-96512. + + -- Marc Haber Mon, 28 Sep 2026 16:38:31 +0200 + sudo (1.9.16p2-3+deb13u2) trixie; urgency=medium * cherry-pick upstream exec_mailer-Set-group-as-well-as-uid. diff -Nru sudo-1.9.16p2/debian/patches/0006-exec_mailer-Set-group-as-well-as-uid-when-running-th.patch sudo-1.9.16p2/debian/patches/0006-exec_mailer-Set-group-as-well-as-uid-when-running-th.patch --- sudo-1.9.16p2/debian/patches/0006-exec_mailer-Set-group-as-well-as-uid-when-running-th.patch 2026-04-11 12:21:02.000000000 +0000 +++ sudo-1.9.16p2/debian/patches/0006-exec_mailer-Set-group-as-well-as-uid-when-running-th.patch 2026-09-29 14:02:29.000000000 +0000 @@ -115,10 +115,10 @@ void diff --git a/plugins/sudoers/logging.c b/plugins/sudoers/logging.c -index bd4de92..9535289 100644 +index 07a34d1..5b4dc54 100644 --- a/plugins/sudoers/logging.c +++ b/plugins/sudoers/logging.c -@@ -1157,7 +1157,7 @@ init_eventlog_config(void) +@@ -1155,7 +1155,7 @@ init_eventlog_config(void) eventlog_set_syslog_alertpri(def_syslog_badpri); eventlog_set_syslog_maxlen(def_syslog_maxlen); eventlog_set_file_maxlen(def_loglinelen); @@ -128,7 +128,7 @@ eventlog_set_logpath(def_logfile); eventlog_set_time_fmt(def_log_year ? "%h %e %T %Y" : "%h %e %T"); diff --git a/plugins/sudoers/policy.c b/plugins/sudoers/policy.c -index f3adfb0..27f6e58 100644 +index e3fe259..1440a71 100644 --- a/plugins/sudoers/policy.c +++ b/plugins/sudoers/policy.c @@ -639,7 +639,7 @@ sudoers_policy_deserialize_info(struct sudoers_context *ctx, void *v, diff -Nru sudo-1.9.16p2/debian/patches/0007-upstream-patch-for-CVE-2025-32463.patch sudo-1.9.16p2/debian/patches/0007-upstream-patch-for-CVE-2025-32463.patch --- sudo-1.9.16p2/debian/patches/0007-upstream-patch-for-CVE-2025-32463.patch 2026-04-11 12:21:02.000000000 +0000 +++ sudo-1.9.16p2/debian/patches/0007-upstream-patch-for-CVE-2025-32463.patch 2026-09-29 14:02:29.000000000 +0000 @@ -3218,7 +3218,7 @@ if (saved_user_cmnd != NULL) { if (info != NULL) { diff --git a/plugins/sudoers/match_digest.c b/plugins/sudoers/match_digest.c -index 09ea435..e361e4b 100644 +index 09ea435..2f6f82c 100644 --- a/plugins/sudoers/match_digest.c +++ b/plugins/sudoers/match_digest.c @@ -40,13 +40,14 @@ diff -Nru sudo-1.9.16p2/debian/patches/0011-sudo-ignore-user-specified-TZ-environment-variable.patch sudo-1.9.16p2/debian/patches/0011-sudo-ignore-user-specified-TZ-environment-variable.patch --- sudo-1.9.16p2/debian/patches/0011-sudo-ignore-user-specified-TZ-environment-variable.patch 1970-01-01 00:00:00.000000000 +0000 +++ sudo-1.9.16p2/debian/patches/0011-sudo-ignore-user-specified-TZ-environment-variable.patch 2026-09-29 14:02:29.000000000 +0000 @@ -0,0 +1,64 @@ +From: "Todd C. Miller" +Date: Sat, 14 Mar 2026 13:13:17 -0600 +Subject: sudo: ignore user-specified TZ environment variable + +This avoids potential issues caused by a user-specified timezone +when running sudo, such as the parsing of NOTBEFORE/NOTAFTER values +in sudoers. The TZ variable is still passed to the command being +run unless blocked by sudoers rules. + +Credit: +- XlabAI Team of Tencent Xuanwu Lab (xlabai@tencent.com) +- Atuin Automated Vulnerability Discovery Engine +- Guannan Wang, Zhanpeng Liu, Guancheng Li +--- + src/sudo.c | 22 +++++++++++++++++++++- + 1 file changed, 21 insertions(+), 1 deletion(-) + +diff --git a/src/sudo.c b/src/sudo.c +index 49f5bd2..d621d51 100644 +--- a/src/sudo.c ++++ b/src/sudo.c +@@ -99,6 +99,7 @@ static void sudo_check_suid(const char *path); + static char **get_user_info(struct user_details *); + static void command_info_to_details(char * const info[], + struct command_details *details); ++static void set_time_zone(void); + static void gc_init(void); + + /* Policy plugin convenience functions. */ +@@ -163,7 +164,8 @@ main(int argc, char *argv[], char *envp[]) + bindtextdomain(PACKAGE_NAME, LOCALEDIR); + textdomain(PACKAGE_NAME); + +- (void) tzset(); ++ /* Use system time zone, not user-specified. */ ++ set_time_zone(); + + /* Must be done before we do any password lookups */ + #if defined(HAVE_GETPRPWNAM) && defined(HAVE_SET_AUTH_PARAMETERS) +@@ -341,6 +343,24 @@ access_denied: + return EXIT_FAILURE; + } + ++/* ++ * Set the time zone using tzset(3), ignoring the user's TZ ++ * environment variable. The original value of TZ may still ++ * be present in the command's environment, depending on sudoers. ++ */ ++static void ++set_time_zone(void) ++{ ++ extern char **environ; ++ char **real_environ = environ; ++ char *empty[] = { NULL }; ++ ++ /* Use system time zone, not user-specified. */ ++ environ = empty; ++ (void) tzset(); ++ environ = real_environ; ++} ++ + int + os_init_common(int argc, char *argv[], char *envp[]) + { diff -Nru sudo-1.9.16p2/debian/patches/0012-Remove-TZ-from-sudo-s-working-environment-without-mo.patch sudo-1.9.16p2/debian/patches/0012-Remove-TZ-from-sudo-s-working-environment-without-mo.patch --- sudo-1.9.16p2/debian/patches/0012-Remove-TZ-from-sudo-s-working-environment-without-mo.patch 1970-01-01 00:00:00.000000000 +0000 +++ sudo-1.9.16p2/debian/patches/0012-Remove-TZ-from-sudo-s-working-environment-without-mo.patch 2026-09-29 14:02:29.000000000 +0000 @@ -0,0 +1,73 @@ +From: "Todd C. Miller" +Date: Fri, 28 Aug 2026 16:13:52 -0600 +Subject: Remove TZ from sudo's working environment without modifying envp. + +The earlier change to prevent NOTBEFORE/NOTAFTER in sudoers from +being affected by a user-specified timezone was not effective since +the mktime() function re-reads the TZ environment variable each +time it is called. + +Reported by Ermenson Junior +--- + src/sudo.c | 31 ++++++++++++++++++++++++------- + 1 file changed, 24 insertions(+), 7 deletions(-) + +diff --git a/src/sudo.c b/src/sudo.c +index d621d51..eba0529 100644 +--- a/src/sudo.c ++++ b/src/sudo.c +@@ -344,30 +344,47 @@ access_denied: + } + + /* +- * Set the time zone using tzset(3), ignoring the user's TZ ++ * Set the time zone using tzset(3), removing the user's TZ + * environment variable. The original value of TZ may still + * be present in the command's environment, depending on sudoers. + */ + static void + set_time_zone(void) + { +- extern char **environ; +- char **real_environ = environ; +- char *empty[] = { NULL }; +- + /* Use system time zone, not user-specified. */ +- environ = empty; ++ unsetenv("TZ"); + (void) tzset(); +- environ = real_environ; + } + + int + os_init_common(int argc, char *argv[], char *envp[]) + { ++ extern char **environ; ++ int envc; + #ifdef STATIC_SUDOERS_PLUGIN + preload_static_symbols(); + #endif + gc_init(); ++ ++ /* ++ * Make a copy of environ[] that is distinct from envp[]. ++ * This allows us to remove variables from sudo's environment ++ * while still providing the original envp to the plugins. ++ */ ++ for (envc = 0; envp[envc] != NULL; envc++) ++ continue; ++ if (envc != 0) { ++ char **new_env = reallocarray(NULL, sizeof(char *), envc + 1); ++ if (new_env == NULL || !gc_add(GC_PTR, new_env)) { ++ sudo_fatalx_nodebug(U_("%s: %s"), __func__, ++ U_("unable to allocate memory")); ++ } ++ for (envc = 0; envp[envc] != NULL; envc++) ++ new_env[envc] = envp[envc]; ++ new_env[envc] = NULL; ++ environ = new_env; ++ } ++ + return 0; + } + diff -Nru sudo-1.9.16p2/debian/patches/0013-Copy-envp-submit_envp-instead-of-replacing-the-envir.patch sudo-1.9.16p2/debian/patches/0013-Copy-envp-submit_envp-instead-of-replacing-the-envir.patch --- sudo-1.9.16p2/debian/patches/0013-Copy-envp-submit_envp-instead-of-replacing-the-envir.patch 1970-01-01 00:00:00.000000000 +0000 +++ sudo-1.9.16p2/debian/patches/0013-Copy-envp-submit_envp-instead-of-replacing-the-envir.patch 2026-09-29 14:02:29.000000000 +0000 @@ -0,0 +1,82 @@ +From: "Todd C. Miller" +Date: Sun, 30 Aug 2026 08:38:05 -0600 +Subject: Copy envp -> submit_envp instead of replacing the environ pointer. + +This has the same effect of passing the unmodified environment to +the plugin without needing to manually change the environ pointer. +--- + src/sudo.c | 26 +++++++++++++++----------- + 1 file changed, 15 insertions(+), 11 deletions(-) + +diff --git a/src/sudo.c b/src/sudo.c +index eba0529..de7e809 100644 +--- a/src/sudo.c ++++ b/src/sudo.c +@@ -133,8 +133,10 @@ static void approval_show_version(int verbose); + sudo_dso_public int main(int argc, char *argv[], char *envp[]); + + static struct sudo_settings *sudo_settings; +-static char * const *user_info, * const *submit_argv, * const *submit_envp; +-static int submit_optind; ++static char * const *user_info; ++static char * const *submit_argv; /* argv[] from main() */ ++static char **submit_envp; /* shallow copy of envp[] from main() */ ++static int submit_optind; /* optind from after getopt() */ + + int + main(int argc, char *argv[], char *envp[]) +@@ -205,9 +207,8 @@ main(int argc, char *argv[], char *envp[]) + if (sudo_conf_disable_coredump()) + disable_coredump(); + +- /* Parse command line arguments, preserving the original argv/envp. */ ++ /* Parse command line arguments, preserving the original argv. */ + submit_argv = argv; +- submit_envp = envp; + sudo_mode = parse_args(argc, argv, user_details.shell, &submit_optind, + &nargc, &nargv, &sudo_settings, &env_add, &list_user); + sudo_debug_printf(SUDO_DEBUG_DEBUG, "sudo_mode 0x%x", sudo_mode); +@@ -356,10 +357,14 @@ set_time_zone(void) + (void) tzset(); + } + ++/* ++ * Initialize garbage collection, load symbols for static sudoers, ++ * and make a shallow copy of envp[] for the plugins to use. ++ * Called via os_init(). ++ */ + int + os_init_common(int argc, char *argv[], char *envp[]) + { +- extern char **environ; + int envc; + #ifdef STATIC_SUDOERS_PLUGIN + preload_static_symbols(); +@@ -367,22 +372,21 @@ os_init_common(int argc, char *argv[], char *envp[]) + gc_init(); + + /* +- * Make a copy of environ[] that is distinct from envp[]. ++ * Make a shallow copy of envp[] and store in submit_envp[]. + * This allows us to remove variables from sudo's environment + * while still providing the original envp to the plugins. + */ + for (envc = 0; envp[envc] != NULL; envc++) + continue; + if (envc != 0) { +- char **new_env = reallocarray(NULL, sizeof(char *), envc + 1); +- if (new_env == NULL || !gc_add(GC_PTR, new_env)) { ++ submit_envp = reallocarray(NULL, sizeof(char *), envc + 1); ++ if (submit_envp == NULL || !gc_add(GC_PTR, submit_envp)) { + sudo_fatalx_nodebug(U_("%s: %s"), __func__, + U_("unable to allocate memory")); + } + for (envc = 0; envp[envc] != NULL; envc++) +- new_env[envc] = envp[envc]; +- new_env[envc] = NULL; +- environ = new_env; ++ submit_envp[envc] = envp[envc]; ++ submit_envp[envc] = NULL; + } + + return 0; diff -Nru sudo-1.9.16p2/debian/patches/Whitelist-DPKG_COLORS-environment-variable.diff sudo-1.9.16p2/debian/patches/Whitelist-DPKG_COLORS-environment-variable.diff --- sudo-1.9.16p2/debian/patches/Whitelist-DPKG_COLORS-environment-variable.diff 2026-04-11 12:21:02.000000000 +0000 +++ sudo-1.9.16p2/debian/patches/Whitelist-DPKG_COLORS-environment-variable.diff 2026-09-29 14:02:29.000000000 +0000 @@ -1,4 +1,3 @@ -From 18087bc16ec20ca2c8f0045a6b0408e94c53075c Mon Sep 17 00:00:00 2001 From: Guillem Jover Date: Wed, 4 May 2016 01:53:13 +0200 Subject: [PATCH] Whitelist DPKG_COLORS environment variable @@ -7,9 +6,11 @@ plugins/sudoers/env.c | 1 + 1 file changed, 1 insertion(+) +diff --git a/plugins/sudoers/env.c b/plugins/sudoers/env.c +index 95558e9..2fbceea 100644 --- a/plugins/sudoers/env.c +++ b/plugins/sudoers/env.c -@@ -216,6 +216,7 @@ static const char *initial_checkenv_tabl +@@ -216,6 +216,7 @@ static const char *initial_checkenv_table[] = { static const char *initial_keepenv_table[] = { "COLORS", "DISPLAY", diff -Nru sudo-1.9.16p2/debian/patches/X11R6.patch sudo-1.9.16p2/debian/patches/X11R6.patch --- sudo-1.9.16p2/debian/patches/X11R6.patch 2026-04-11 12:21:02.000000000 +0000 +++ sudo-1.9.16p2/debian/patches/X11R6.patch 2026-09-29 14:02:29.000000000 +0000 @@ -1,6 +1,19 @@ -Description: patch docs to correct path to ssh-askpass -Author: Marc Haber +From: Marc Haber +Date: Fri, 3 Apr 2026 06:58:39 +0200 +Subject: patch docs to correct path to ssh-askpass + Forwarded: not-needed +--- + docs/UPGRADE.md | 4 ++-- + docs/sudo.conf.man.in | 4 ++-- + docs/sudo.conf.mdoc.in | 4 ++-- + docs/sudo.man.in | 2 +- + docs/sudo.mdoc.in | 2 +- + examples/sudo.conf.in | 2 +- + 6 files changed, 9 insertions(+), 9 deletions(-) + +diff --git a/docs/UPGRADE.md b/docs/UPGRADE.md +index 81f7285..3252227 100644 --- a/docs/UPGRADE.md +++ b/docs/UPGRADE.md @@ -426,11 +426,11 @@ Notes on upgrading from an older release @@ -17,6 +30,8 @@ * Upgrading from a version prior to 1.7.5: +diff --git a/docs/sudo.conf.man.in b/docs/sudo.conf.man.in +index b1d80e7..4c102f9 100644 --- a/docs/sudo.conf.man.in +++ b/docs/sudo.conf.man.in @@ -238,7 +238,7 @@ For example: @@ -37,6 +52,8 @@ # # Use the Gnome OpenSSH askpass #Path askpass /usr/libexec/openssh/gnome-ssh-askpass +diff --git a/docs/sudo.conf.mdoc.in b/docs/sudo.conf.mdoc.in +index b7b40bd..0ec7026 100644 --- a/docs/sudo.conf.mdoc.in +++ b/docs/sudo.conf.mdoc.in @@ -218,7 +218,7 @@ For example: @@ -57,6 +74,8 @@ # # Use the Gnome OpenSSH askpass #Path askpass /usr/libexec/openssh/gnome-ssh-askpass +diff --git a/docs/sudo.man.in b/docs/sudo.man.in +index c451914..baddc87 100644 --- a/docs/sudo.man.in +++ b/docs/sudo.man.in @@ -205,7 +205,7 @@ For example: @@ -68,6 +87,8 @@ .RE .fi .RS 8n +diff --git a/docs/sudo.mdoc.in b/docs/sudo.mdoc.in +index 61f5eae..6461a3f 100644 --- a/docs/sudo.mdoc.in +++ b/docs/sudo.mdoc.in @@ -207,7 +207,7 @@ used. @@ -79,6 +100,8 @@ .Ed .Pp If no askpass program is available, +diff --git a/examples/sudo.conf.in b/examples/sudo.conf.in +index 2187457..862f139 100644 --- a/examples/sudo.conf.in +++ b/examples/sudo.conf.in @@ -24,7 +24,7 @@ diff -Nru sudo-1.9.16p2/debian/patches/amd64-ibt.diff sudo-1.9.16p2/debian/patches/amd64-ibt.diff --- sudo-1.9.16p2/debian/patches/amd64-ibt.diff 2026-04-11 12:21:02.000000000 +0000 +++ sudo-1.9.16p2/debian/patches/amd64-ibt.diff 2026-09-29 14:02:29.000000000 +0000 @@ -7,10 +7,10 @@ 1 file changed, 2 insertions(+) diff --git a/m4/hardening.m4 b/m4/hardening.m4 -index f7d2a8c..cc7ee01 100644 +index 45c501f..6c2caf2 100644 --- a/m4/hardening.m4 +++ b/m4/hardening.m4 -@@ -105,6 +105,7 @@ AC_DEFUN([SUDO_CHECK_HARDENING], [ +@@ -100,6 +100,7 @@ AC_DEFUN([SUDO_CHECK_HARDENING], [ ]) fi @@ -18,7 +18,7 @@ # Check for control-flow transfer instrumentation (Intel CET). AX_CHECK_COMPILE_FLAG([-fcf-protection], [ AX_CHECK_LINK_FLAG([-fcf-protection], [ -@@ -112,6 +113,7 @@ AC_DEFUN([SUDO_CHECK_HARDENING], [ +@@ -107,6 +108,7 @@ AC_DEFUN([SUDO_CHECK_HARDENING], [ AX_APPEND_FLAG([-Wc,-fcf-protection], [HARDENING_LDFLAGS]) ]) ]) diff -Nru sudo-1.9.16p2/debian/patches/paths-in-samples.diff sudo-1.9.16p2/debian/patches/paths-in-samples.diff --- sudo-1.9.16p2/debian/patches/paths-in-samples.diff 2026-04-11 12:21:02.000000000 +0000 +++ sudo-1.9.16p2/debian/patches/paths-in-samples.diff 2026-09-29 14:02:29.000000000 +0000 @@ -1,10 +1,18 @@ -Description: fix paths in sudoers example to match Debian's +From: Bdale Garbee +Date: Fri, 3 Apr 2026 06:58:39 +0200 +Subject: fix paths in sudoers example to match Debian's + Last-Update: 2021-12-13 -Author: Bdale Garbee Forwarded: not-needed +--- + examples/sudoers.in | 8 ++++---- + 1 file changed, 4 insertions(+), 4 deletions(-) + +diff --git a/examples/sudoers.in b/examples/sudoers.in +index 46953d6..1be6725 100644 --- a/examples/sudoers.in +++ b/examples/sudoers.in -@@ -44,7 +44,7 @@ Host_Alias CDROM = orion, perseus, hercu +@@ -44,7 +44,7 @@ Host_Alias CDROM = orion, perseus, hercules # Cmnd alias specification ## Cmnd_Alias DUMPS = /usr/sbin/dump, /usr/sbin/rdump, /usr/sbin/restore, \ @@ -13,7 +21,7 @@ sha224:0GomF8mNN3wlDt1HD9XldjJ3SNgpFdbjO1+NsQ== \ /home/operator/bin/start_backups Cmnd_Alias KILL = /usr/bin/kill, /usr/bin/top -@@ -85,7 +85,7 @@ operator ALL = DUMPS, KILL, SHUTDOWN, HA +@@ -85,7 +85,7 @@ operator ALL = DUMPS, KILL, SHUTDOWN, HALT, REBOOT, PRINTING,\ sudoedit /etc/printcap, /usr/oper/bin/ # joe may su only to operator diff -Nru sudo-1.9.16p2/debian/patches/series sudo-1.9.16p2/debian/patches/series --- sudo-1.9.16p2/debian/patches/series 2026-04-11 12:21:02.000000000 +0000 +++ sudo-1.9.16p2/debian/patches/series 2026-09-29 14:02:29.000000000 +0000 @@ -8,3 +8,6 @@ 0008-open_sudoers-Do-not-perform-path-expansion-on-files-.patch amd64-ibt.diff 0006-exec_mailer-Set-group-as-well-as-uid-when-running-th.patch +0011-sudo-ignore-user-specified-TZ-environment-variable.patch +0012-Remove-TZ-from-sudo-s-working-environment-without-mo.patch +0013-Copy-envp-submit_envp-instead-of-replacing-the-envir.patch diff -Nru sudo-1.9.16p2/debian/patches/spanish.patch sudo-1.9.16p2/debian/patches/spanish.patch --- sudo-1.9.16p2/debian/patches/spanish.patch 2026-04-11 12:21:02.000000000 +0000 +++ sudo-1.9.16p2/debian/patches/spanish.patch 2026-09-29 14:02:29.000000000 +0000 @@ -1,6 +1,15 @@ -Description: improve spanish program translation +From: Debian Sudo Maintainers +Date: Fri, 3 Apr 2026 06:58:39 +0200 +Subject: improve spanish program translation + Forwarded: https://bugzilla.sudo.ws/show_bug.cgi?id=1052 Origin: https://salsa.debian.org/sudo-team/sudo/-/commit/7f12ddebd18ea2021ace59741f773c9c7b476a27 +--- + po/es.po | 78 ++++++++++++++++++++++++++++++++-------------------------------- + 1 file changed, 39 insertions(+), 39 deletions(-) + +diff --git a/po/es.po b/po/es.po +index 5e238a1..97b0c9c 100644 --- a/po/es.po +++ b/po/es.po @@ -8,7 +8,7 @@ msgstr "" @@ -57,7 +66,7 @@ #: lib/util/sudo_conf.c:584 #, c-format -@@ -185,7 +185,7 @@ msgstr "no se puede cambiar de root a %s +@@ -185,7 +185,7 @@ msgstr "no se puede cambiar de root a %s" #: src/exec.c:215 src/exec.c:221 src/exec.c:228 #, c-format msgid "unable to change to runas uid (%u, %u)" @@ -66,7 +75,7 @@ #: src/exec.c:246 #, c-format -@@ -201,7 +201,7 @@ msgstr "no se puede establecer el maneja +@@ -201,7 +201,7 @@ msgstr "no se puede establecer el manejador para señal %d" #: src/exec_common.c:171 msgid "unable to remove PRIV_PROC_EXEC from PRIV_LIMIT" @@ -75,7 +84,7 @@ #: src/exec_monitor.c:364 msgid "error reading from socketpair" -@@ -259,11 +259,11 @@ msgstr "no se puede restaurar la etiquet +@@ -259,11 +259,11 @@ msgstr "no se puede restaurar la etiqueta tty " #: src/exec_nopty.c:358 src/exec_pty.c:1338 msgid "policy plugin failed session initialization" @@ -98,7 +107,7 @@ #: src/exec_pty.c:1531 msgid "unable to send message to monitor process" -@@ -303,7 +303,7 @@ msgstr "%s debe ser propiedad del uid %d +@@ -303,7 +303,7 @@ msgstr "%s debe ser propiedad del uid %d" #: src/load_plugins.c:136 #, c-format msgid "%s must be only be writable by owner" @@ -107,7 +116,7 @@ #: src/load_plugins.c:177 #, c-format -@@ -323,12 +323,12 @@ msgstr "tipo de política desconocido %d +@@ -323,12 +323,12 @@ msgstr "tipo de política desconocido %d encontrado en %s" #: src/load_plugins.c:198 #, c-format msgid "incompatible plugin major version %d (expected %d) found in %s" @@ -122,7 +131,7 @@ #: src/load_plugins.c:209 msgid "only a single policy plugin may be specified" -@@ -357,7 +357,7 @@ msgstr "error interno: desbordamiento de +@@ -357,7 +357,7 @@ msgstr "error interno: desbordamiento de %s" #: src/parse_args.c:224 #, c-format msgid "invalid environment variable name: %s" @@ -131,7 +140,7 @@ #: src/parse_args.c:320 msgid "the argument to -C must be a number greater than or equal to 3" -@@ -365,11 +365,11 @@ msgstr "el argumento -C debe ser un núm +@@ -365,11 +365,11 @@ msgstr "el argumento -C debe ser un número mayor o igual a 3" #: src/parse_args.c:505 msgid "you may not specify both the `-i' and `-s' options" @@ -145,7 +154,7 @@ #: src/parse_args.c:519 msgid "the `-E' option is not valid in edit mode" -@@ -377,7 +377,7 @@ msgstr "la opción '-E' no es válida en +@@ -377,7 +377,7 @@ msgstr "la opción '-E' no es válida en el modo edición" #: src/parse_args.c:521 msgid "you may not specify environment variables in edit mode" @@ -154,7 +163,7 @@ #: src/parse_args.c:529 msgid "the `-U' option may only be used with the `-l' option" -@@ -393,7 +393,7 @@ msgstr "sudoedit no está soportado en à +@@ -393,7 +393,7 @@ msgstr "sudoedit no está soportado en ésta plataforma" #: src/parse_args.c:682 msgid "Only one of the -e, -h, -i, -K, -l, -s, -v or -V options may be specified" @@ -172,7 +181,7 @@ #: src/parse_args.c:708 msgid "use specified BSD authentication type" -@@ -464,7 +464,7 @@ msgstr "asigna la variable HOME al direc +@@ -464,7 +464,7 @@ msgstr "asigna la variable HOME al directorio de inicio del usuario" #: src/parse_args.c:729 msgid "display help message and exit" @@ -181,7 +190,7 @@ #: src/parse_args.c:731 msgid "run command on host (if supported by plugin)" -@@ -472,23 +472,23 @@ msgstr "ejecuta comando en host (si està +@@ -472,23 +472,23 @@ msgstr "ejecuta comando en host (si está soportado por plugin)" #: src/parse_args.c:733 msgid "run login shell as the target user; a command may also be specified" @@ -210,7 +219,7 @@ #: src/parse_args.c:743 msgid "preserve group vector instead of setting to target's" -@@ -508,7 +508,7 @@ msgstr "lee la contraseña desde la entr +@@ -508,7 +508,7 @@ msgstr "lee la contraseña desde la entrada estandar" #: src/parse_args.c:753 msgid "run shell as the target user; a command may also be specified" @@ -219,7 +228,7 @@ #: src/parse_args.c:756 msgid "create SELinux security context with specified type" -@@ -516,15 +516,15 @@ msgstr "crea el contexto de seguridad SE +@@ -516,15 +516,15 @@ msgstr "crea el contexto de seguridad SELinux con el tipo especificado" #: src/parse_args.c:759 msgid "terminate command after the specified time limit" @@ -238,7 +247,7 @@ #: src/parse_args.c:765 msgid "display version information and exit" -@@ -532,7 +532,7 @@ msgstr "muestra la información de la ve +@@ -532,7 +532,7 @@ msgstr "muestra la información de la versión y sale" #: src/parse_args.c:767 msgid "update user's timestamp without running a command" @@ -247,7 +256,7 @@ #: src/parse_args.c:769 msgid "stop processing command line arguments" -@@ -564,16 +564,16 @@ msgstr "no se puede restaurar el context +@@ -564,16 +564,16 @@ msgstr "no se puede restaurar el contexto para %s" #: src/selinux.c:172 #, c-format msgid "unable to open %s, not relabeling tty" @@ -267,7 +276,7 @@ #: src/selinux.c:192 msgid "unknown security class \"chr_file\", not relabeling tty" -@@ -581,7 +581,7 @@ msgstr "clase de seguridad desconocida \ +@@ -581,7 +581,7 @@ msgstr "clase de seguridad desconocida \"chr_file\", tty no reetiquetada" #: src/selinux.c:197 msgid "unable to get new tty context, not relabeling tty" @@ -276,7 +285,7 @@ #: src/selinux.c:204 msgid "unable to set new tty context" -@@ -590,12 +590,12 @@ msgstr "no se puede establecer nuevo con +@@ -590,12 +590,12 @@ msgstr "no se puede establecer nuevo contexto tty" #: src/selinux.c:278 #, c-format msgid "you must specify a role for type %s" @@ -291,7 +300,7 @@ #: src/selinux.c:302 #, c-format -@@ -675,7 +675,7 @@ msgstr "no podría unirse al proyecto \" +@@ -675,7 +675,7 @@ msgstr "no podría unirse al proyecto \"%s\"" #: src/solaris.c:96 #, c-format msgid "no resource pool accepting default bindings exists for project \"%s\"" diff -Nru sudo-1.9.16p2/debian/patches/sudo-ldap-docs.patch sudo-1.9.16p2/debian/patches/sudo-ldap-docs.patch --- sudo-1.9.16p2/debian/patches/sudo-ldap-docs.patch 2026-04-11 12:21:02.000000000 +0000 +++ sudo-1.9.16p2/debian/patches/sudo-ldap-docs.patch 2026-09-29 14:02:29.000000000 +0000 @@ -1,6 +1,14 @@ -Description: Adapt README.LDAP to the actual state of the sudo-ldap package -Author: Marc Haber +From: Marc Haber +Date: Fri, 3 Apr 2026 06:58:39 +0200 +Subject: Adapt README.LDAP to the actual state of the sudo-ldap package + Forwarded: not-needed +--- + README.LDAP.md | 32 ++++++-------------------------- + 1 file changed, 6 insertions(+), 26 deletions(-) + +diff --git a/README.LDAP.md b/README.LDAP.md +index 7eb4da0..b69b470 100644 --- a/README.LDAP.md +++ b/README.LDAP.md @@ -35,22 +35,8 @@ They are one and the same. @@ -28,7 +36,7 @@ ## Schema Changes -@@ -186,13 +172,10 @@ I recommend using any of the following L +@@ -186,13 +172,10 @@ I recommend using any of the following LDAP browsers to administer your SUDOers. There are dozens of others, some Open Source, some free, some not. @@ -45,7 +53,7 @@ See the "Configuring ldap.conf" section in the sudoers.ldap manual for a list of supported ldap.conf parameters and an example ldap.conf -@@ -204,10 +187,7 @@ After configuring /etc/ldap.conf, you mu +@@ -204,10 +187,7 @@ After configuring /etc/ldap.conf, you must add a line in the /etc/nsswitch.conf file to tell sudo to look in LDAP for sudoers. See the "Configuring nsswitch.conf" section in the sudoers.ldap manual for details. Sudo will use /etc/nsswitch.conf even if the