** Description changed:

- (Tracking bug from upstream:
- https://github.com/trifectatechfoundation/sudo-rs/issues/1602)
+ [ Impact ]
+ 
+ sudo-rs's visudo will not parse UID/GIDs containing 10 digits correctly
+ in its sudoers file, giving:
+ 
+   syntax error: token exceeds maximum length
+ 
+ for a value like 1999999999. The reason for this is that the number of digits
+ is capped at 9, which makes the str::parse method always succeed.
+ On modern systems however, UID and GID are unsigned 32-bit integers and can
+ assume values of up to 4,294,967,295.
+ 
+ The consequence is that sudo-rs becomes unable to accept rules for these users
+ or groups based on the UID or GID. It is considered justified for backport as
+ these values are valid and are observed to occur in the real world.
+ 
+ This upload fixes the issue by relaxing the number of digits to 10, parsing
+ them explicitly as 32-bit unsigned integers, and catching the error where the
+ value exceeds what can be represented by 32-bits.
+ 
+ [ Test Plan ]
+ 
+ * Detailed instructions on how to reproduce the bug.
+ 
+ * These should allow someone who is not familiar with the affected
+   package to reproduce the bug and verify that the updated package
+   fixes the problem.
+ 
+ * If other testing is appropriate to perform before landing this
+   update, this should also be described here.
+ 
+ Reproduce the bug
+ -----------------
+ 
+ * Verify that sudo-rs is the sudo provider:
+ 
+ sudo --version
+ 
+ # Output:
+ # sudo-rs 0.2.13-0ubuntu1
+ # ~~~~~~~
+ 
+ * Create a sudoers file containing a valid 10-digit id:
+ 
+ echo "%#1234567890 ALL=(ALL:ALL) NOPASSWD:ALL" > test_sudoers
+ 
+ * Check the file with visudo:
+ 
+ visudo -c -f test_sudoers
+ 
+ * Verify the error:
+ 
+ test_sudoers:1:13: syntax error: token exceeds maximum length
+ %#1999999999 ALL=(ALL:ALL) NOPASSWD:ALL
+             ^
+ visudo: invalid sudoers file
+ 
+ Testing proposed
+ ----------------
+ 
+ * Install the fixed version:
+ 
+ sudo apt install -t resolute-proposed rust-sudo-rs
+ 
+ * Check the file with visudo:
+ 
+ visudo -c -f test_sudoers
+ 
+ * Verify no errors:
+ 
+ test_sudoers: parsed OK
+ 
+ [ Where problems could occur ]
+ 
+ * The upload introduces a behavioral change to the visudo check. If a rule
+   contains a value above the size of an unsigned 32-bit integer, it will now
+   be treated as a comment rather rather than a rule. This is a
+   security-relevant semantic change, considering that an external client
+   *may* have been reliant on such IDs being parsed.
+ 
+ * The fix is internal to sudo-rs with no other package depending on its
+   tokenizer, which means that problems will likely be internal.
+ 
+ 
+ [ Other Info ]
+ 
+ * This SRU is part of a larger merge proposal for 26.04.1
+ 
+ * The fix is also natively part of the 0.2.14-1 upload to Stonking, currently
+   in proposed-migration
+ 
+ [ Original Description ]
+ (Tracking bug from upstream: 
https://github.com/trifectatechfoundation/sudo-rs/issues/1602)
  
  root@host:/etc/sudoers.d# visudo -c linux-users
-   linux-users:2:13: syntax error: token exceeds maximum length
-   %#9999999999 ALL=(ALL:ALL) NOPASSWD:ALL
-               ^
-   visudo: invalid sudoers file
+   linux-users:2:13: syntax error: token exceeds maximum length
+   %#9999999999 ALL=(ALL:ALL) NOPASSWD:ALL
+               ^
+   visudo: invalid sudoers file
  
  But with an actual user id such as 1999999999.
  
  In the CLI, these are accepted, but the token limitations in the parser
  are simply a bit too strict.
  
  Reported by @Flo2388
  
  **Additional context**
  
  POSIX allows such user id's; and they have been observed to occur in the
  real world.

** Summary changed:

- Large group id's / user id's (larger than 10 digits but < 32bits) are not 
parsed correctly
+ [SRU] Large group id's / user id's (larger than 10 digits but < 32bits) are 
not parsed correctly

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2160214

Title:
  [SRU] Large group id's / user id's (larger than 10 digits but <
  32bits) are not parsed correctly

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/rust-sudo-rs/+bug/2160214/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to