Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 883408 - Make it clear that ldap_sudo_include_regexp can only handle wildcards
Make it clear that ldap_sudo_include_regexp can only handle wildcards
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: sssd (Show other bugs)
6.4
Unspecified Unspecified
unspecified Severity unspecified
: rc
: ---
Assigned To: Jakub Hrozek
Kaushik Banerjee
:
Depends On:
Blocks: 888457
  Show dependency treegraph
 
Reported: 2012-12-04 09:12 EST by Nikolai Kondrashov
Modified: 2013-02-21 04:41 EST (History)
5 users (show)

See Also:
Fixed In Version: sssd-1.9.2-41.el6
Doc Type: Bug Fix
Doc Text:
No documentation needed.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2013-02-21 04:41:57 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2013:0508 normal SHIPPED_LIVE Low: sssd security, bug fix and enhancement update 2013-02-20 16:30:10 EST

  None (edit)
Description Nikolai Kondrashov 2012-12-04 09:12:21 EST
Description of problem:
The "ldap_sudo_include_regexp" option is named incorrectly, because sudo doesn't actually support regular expressions (as in, e.g. perl-compatible regular expressions) for configuration, but instead shell-like wildcards. In particular, sudoers(5) states about wildcards: "Note that these are not regular expressions."

This results in confusion.

The option would better be named "ldap_sudo_include_wildcards" or "ldap_sudo_include_glob" and documentation should be updated accordingly. Namely:

1. sssd-sudo(5) - change "regular expression" to "wildcards" or "glob characters".
2. sssd-ldap(5) - the description of the option in question.

Version-Release number of selected component (if applicable):
sssd-1.9.2-30.el6.x86_64
libsss_sudo-1.9.2-30.el6.x86_64
sudo-1.8.6p3-6.el6.x86_64
sssd-client-1.9.2-30.el6.x86_64
libsss_idmap-1.9.2-30.el6.x86_64
Comment 2 Pavel Březina 2012-12-04 09:36:57 EST
Upstream ticket:
https://fedorahosted.org/sssd/ticket/1690
Comment 4 Nikolai Kondrashov 2012-12-14 08:25:50 EST
Verified *unfixed* with the following packages:

sssd-client-1.9.2-41.el6.x86_64
libsss_idmap-1.9.2-41.el6.x86_64
libsss_sudo-1.9.2-41.el6.x86_64
sudo-1.8.6p3-6.el6.x86_64
sssd-1.9.2-41.el6.x86_64

The option is *not* renamed and sssd-ldap(5) still shows the old name.
Comment 5 Jakub Hrozek 2012-12-14 09:24:02 EST
That was not the point of the patch. Sorry, I should have been more clear. 

We can't rename the option just like that. There may be people using the option already. For 6.4, the only thing we could do was be clear in the man page that the option only supports wildcards, not regexes. For a later release, we will provide a new option ldap_sudo_include_wildcard that would be the preferred one and anybody who will use ldap_sudo_include_regexp will get a warning.

For 6.4, the verification only amounts to checking that the manpage says wildcard, not regexp.
Comment 6 Nikolai Kondrashov 2012-12-14 09:38:05 EST
I can confirm that documentation was updated to use "wildcards" instead of "regular expressions".

Otherwise this bug cannot be closed as fixed yet.
Comment 7 Jakub Hrozek 2012-12-14 09:58:49 EST
We won't be doing anything else except the docs fix in 6.4. Tracking that is the purpose of this bugzilla.

The rest of the work is being tracked in the upstream ticket https://fedorahosted.org/sssd/ticket/1707 and will be cloned as appropriate.
Comment 8 Nikolai Kondrashov 2012-12-14 10:01:27 EST
OK. What will be tracking renaming of the option, then? Shall we make another bug for renaming, or maybe another bug for documentation fix?
Comment 9 Dmitri Pal 2012-12-14 10:02:37 EST
Yes this should be closed as verified. The real fix will be done some time later when we address the ticket above.
Please flip it back to ON_QE.
Comment 10 Nikolai Kondrashov 2012-12-14 10:05:00 EST
Verified fixed with the following packages:

sssd-client-1.9.2-41.el6.x86_64
libsss_idmap-1.9.2-41.el6.x86_64
libsss_sudo-1.9.2-41.el6.x86_64
sudo-1.8.6p3-6.el6.x86_64
sssd-1.9.2-41.el6.x86_64
Comment 11 errata-xmlrpc 2013-02-21 04:41:57 EST
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHSA-2013-0508.html

Note You need to log in before you can comment on or make changes to this bug.