* Mon May 04 2026 adrian.glaubitz@suse.com
- Update to version 20260430.00
* URLEncode request parameters sent to the metadata server. (#182)
* Tue Apr 28 2026 rjschwei@suse.com
- Add /var/google-sudoers.d to tmpfile config
+ The /var/google-users.d directory is pre-created in the Makefile but
the google-sudoers.d is not. But the code wil not behave as expected
if the directory is not there. Because of the pre-creation missing in
Makefile this was missed initially.
* Tue Apr 07 2026 rjschwei@suse.com
- Update to version 20260227.00 (bsc#1257010)
+ Fix broken cache_refresh behavior when groups are disabled. (#181)
* Implement a binary cache for OS Login passwd entries.
This change introduces a new binary cache format for storing OS Login
passwd information. It includes:
- `OsLoginPasswdCacheWriter`: A C++ class to build and write the cache
file. It buffers user entries, sorts them, and writes them to a
temporary file before atomically renaming it.
- `oslogin_passwd_cache_reader`: A C implementation for reading from
the cache file using mmap. It provides functions compatible with
NSS modules for looking up entries by UID, name, and iterating
through all entries.
- `eytzinger_layout.h`: A template function to convert a sorted vector
into an Eytzinger layout, used for the name index to improve cache
locality during lookups.
- `oslogin_index_structs.h`: Defines the structures used for the UID
and Name indices.
- New unit tests (`eytzinger_layout_test.cc`,
`oslogin_passwd_cache_reader_test.cc`, `round_trip_test.cc`) to
validate the cache functionality, including concurrent read access.
- The `Makefile` is updated to build and run the new tests. The `main`
function is removed from `oslogin_utils_test.cc` as `gtest_main.cc`
is now linked.
* Fix incorrect cache_refresh return value.
+ Add google-guest-oslogin.conf and ggosl-no-var-content.patch (jsc#PED-14688)
* Wed Nov 19 2025 zkubala@suse.com
- Update SELinux module dir as macro to allow root path move from
/var/lib/selinux to /etc/selinux (bsc#1221342)
* Fri Nov 07 2025 adrian.glaubitz@suse.com
- Update to version 20251022.00
* Log the response body when an auth failure occurs;
it usually has helpful info in it. (#167)
* Tue Sep 02 2025 adrian.glaubitz@suse.com
- Update to version 20250821.00
* Check policy uses adminLogin for cloud run (#165)
- from version 20250807.00
* Extract the principal from certs when cloud_run enabled (#164)
* Fri Jul 11 2025 adrian.glaubitz@suse.com
- Update to version 20250710.00
* Add the cloudrun support (#162)
* Wed Jun 25 2025 adrian.glaubitz@suse.com
- Update to version 20250624.00
* Pass c-strings to logging functions (#140)
- from version 20241216.00
* Send the correct type to SysLogErr; the clang sanitizer
dislikes the type mismatch. (#158)
* Add Eric to the owners file. (#157)
* Revert "new client component and tests" (#155)
- from version 20241214.00
* Remove pat from owners (#156)
- from version 20241206.00
* Fix json include (#154)
* build: remove oslogin_sshca from binaries list (#153)
* Fix bad struct initialization pattern `= { 0 }` (#150)
* Apply "include what you use," fixing missing include
statements broadly. (#152)
* Fix base64.h's missing includes and BSD types (#151)
* Fix a bug where very large GIDs would cause integer
overflow errors (#149)
- from version 20241127.00
* Rename openbsd.h to base64.h and move it into the src/ folder (#148)
- from version 20241126.01
* Follow the Google style guide by using the "local include style"
to include files from this project. (#147)
- from version 20241126.00
* Delete oslogin_sshca binary, add it to the ignore list (#146)
- from version 20241120.00
* OS Login agent searches for full fingerprint extension instead
of equals (#144)
- from version 20241116.00
* Log an error when user has no challenges configured (#135)
* Thu Feb 27 2025 adrian.glaubitz@suse.com
- Rework SELinux support (bsc#1232553)
* Add pkgconfig(systemd) to BuildRequires for SELinux builds
* Add policycoreutils to BuildRequires
* Build and install SELinux module on older distributions as well
to allow users to use the module with their own SELinux policies
* Make checkpolicy build dependency unconditional
* Move oslogin.pp SELinux module into %{selinuxtype} subdirectory
* Own %{_datadir}/selinux{,/packages} on older distributions
* Split SELinux support into separate -selinux package
* Use SELinux RPM macros to install and uninstall SELinux module
* Use RPM conditional builds to enable SELinux on newer distributions
* Wed Feb 12 2025 adrian.glaubitz@suse.com
- Build and install SELinux module (bsc#1232553)
Version: 20231116.00-160000.2.2
* Thu Jan 04 2024 adrian.glaubitz@suse.com
- Update to version 20231116.00
* build: Fix DESTDIR concatenation (#124)
- from version 20231113.00
* build: Fix clang build (#122)
- from version 20231103.00
* Update owners (#121)
* Thu Nov 02 2023 adrian.glaubitz@suse.com
- Update to version 20231101.00 (bsc#1216548, bsc#1216750)
* Fix HTTP calls retry logic (#117)
* Thu Oct 19 2023 adrian.glaubitz@suse.com
- Update to version 20231004
* packaging: Make the dependency explicit (#120)
* Sun Oct 01 2023 dmueller@suse.com
- update to 20230926.00:
* fix suse build
* selinux: fix selinux build (#114)
* test: align CXX Flags
* sshca: Make the implementation more C++ like
* sshca: Add a SysLog wrapper
* oslogin_utils: introduce AuthorizeUser() API
* sshca: move it out of pam dir
* pam: start disabling the use of oslogin_sshca
* sshca: consider sshca API to assume a cert only
* authorized principals: introduce the new command
* authorize keys: update to use new APIs
* pam modules: remove pam_*_admin and update pam_*_login
* cache_refresh: should be catching by reference.
* Thu Aug 31 2023 adrian.glaubitz@suse.com
- Update to version 20230823.00
* selinux: Add sshd_key_t type enforcement to trusted user ca (#113)
- from version 20230822.00
* sshca: Add tests with fingerprint and multiple extensions (#111)
- from version 20230821.01
* sshca: Support method token and handle multi line (#109)
- from version 20230821.00
* Update owners (#110)
* Tue Aug 15 2023 adrian.glaubitz@suse.com
- Update to version 20230808.00
* byoid: extract and apply the ca fingerprint to policy call (#106)
* Tue May 09 2023 adrian.glaubitz@suse.com
- Update to version 20230502.00
* Improve the URL in 2fa prompt (#104)
- from version 20230406.02
* Check open files (#101)
- from version 20230406.01
* Initialize variables (#100)
* Fix formatting (#102)
- from version 20230406.00
* PAM cleanup: remove duplicates (#97)
- from version 20230405.00
* NSS cleanup (#98)
- from version 20230403.01
* Cleanup Makefiles (#95)
- from version 20230403.00
* Add anandadalton to the owners list (#96)
* Tue Feb 28 2023 adrian.glaubitz@suse.com
- Update to version 20230217.00
* Update OWNERS (#91)
- from version 20230202.00
* Update owners file (#89)
* Wed Aug 03 2022 adrian.glaubitz@suse.com
- Update to version 20220721.00 (bsc#1202100, bsc#1202101)
* prune outdated info from readme (#86)
- from version 20220714.00
* strip json-c version symbol (#84)
- from version 20220622.00
* pam login: split conditions for logging (#83)
* Wed May 04 2022 rjschwei@suse.com
- use pam_moduledir (boo#1191036)
* Support UsrMerge project