[ubuntu/disco-proposed] samba 2:4.9.2+dfsg-2ubuntu1 (Accepted)

Andreas Hasenack andreas at canonical.com
Thu Nov 29 17:15:15 UTC 2018


samba (2:4.9.2+dfsg-2ubuntu1) disco; urgency=medium

  * Merge with Debian unstable. Remaining changes:
    - debian/VERSION.patch: Update vendor string to "Ubuntu".
    - debian/smb.conf;
      + Add "(Samba, Ubuntu)" to server string.
      + Comment out the default [homes] share, and add a comment about
        "valid users = %s" to show users how to restrict access to
        \\server\username to only username.
    - debian/samba-common.config:
      + Do not change priority to high if dhclient3 is installed.
    - Add apport hook:
      + Created debian/source_samba.py.
      + debian/rules, debian/samba-common-bin.install: install hook.
    - d/control, d/rules: Disable glusterfs support because it's not in main.
      MIR bug is https://launchpad.net/bugs/1274247
  * Dropped:
    - d/p/fix-rmdir.patch: Fix to make smbclient report directory-not-empty
      errors (LP: 1795772)
      [Fixed upstream]

samba (2:4.9.2+dfsg-2) unstable; urgency=high

  * New upstream security release
    - CVE-2018-14629 Unprivileged adding of CNAME record causing loop in AD
      Internal DNS server
    - CVE-2018-16841 Double-free in Samba AD DC KDC with PKINIT
    - CVE-2018-16851 NULL pointer de-reference in Samba AD DC LDAP server
    - CVE-2018-16852 NULL pointer de-reference in Samba AD DC DNS servers
    - because of CVE-2018-16853 (Samba AD DC S4U2Self Crash in experimental
      MIT Kerberos configuration (unsupported)), mark the MIT Kerberos build of
      the Samba AD DC as experimental (not used in Debian package)
    - CVE-2018-16857 Bad password count in AD DC not always effective
  * Prepend 1.5.1+really to ldb version

samba (2:4.9.2+dfsg-1) unstable; urgency=medium

  * New upstream release
    - Bump build-dependencies to ldb 1.4.2
    - Update debian/samba-libs.install
  * d/gitlab-ci.yml:
    - Update to use include
    - allow_failure for reprotest until #912340 is fixed
  * d/rules: Replace override_dh_perl by override_dh_perl-arch (Closes: #913143)
  * debian/gitlab-ci.yml:
    - Samba sometimes needs ldb from experimental
    - Use ldb from experimental in piuparts

samba (2:4.9.1+dfsg-2) unstable; urgency=medium

  [ Mathieu Parent ]
  * Enable --accel-aes=intelaesni on DEB_HOST_ARCH_CPU=amd64 instead of
    DEB_HOST_ARCH=amd64. This matches samba-libs.install and adds x32
  * Allow one to change password via passwd in default config
    - third_party: Update pam_wrapper to version 1.0.7
    - third_party: Add pam_set_items.so from pam_wrapper
    - nsswitch: Add try_authtok option to pam_winbind
    - tests: Check pam_winbind pw change with different options
    - Patch for previous 4 commits
    - debian/winbind.pam-config: Use the new try_authtok option allowing
      password change while preserving current behavior with password strength
      modules (Closes: #858923, LP: #570944)
  * README.source: use gbp pull --track-missing
  * Override library-not-linked-against-libc false positives (See #896012)
  * Fix wrong-path-for-interpreter for pidl and findsmb
  * ctdb.postrm: Fix to disable_legacy (found by piuparts) (Closes: #911530)

  [ James Clarke ]
  * Fix systemd-related build failures on non-Linux

  [ Mathieu Parent ]
  * Add Gitlab CI:
    - Subscribe to salsa-ci-team/pipeline (See salsa-ci-team/pipeline!27 and
      samba-team/samba!10)
    - Copy /etc/apt/{sources.list.d,preferences.d} in the dockerbuilder
      container (salsa-ci-team/images!9)
    - Allow daemons to start during autopkgtest (salsa-ci-team/images!10)
    - debian/gitlab-ci.yml: all jobs: Use ldb from experimental
    - debian/gitlab-ci.yml: piuparts job: Add --scriptsdir, --allow-database
      and --warn-on-leftovers-after-purge options
    - debian/gitlab-ci.yml: piuparts job: Copy apt config to allow enabling
      extra repositories
    - debian/gitlab-ci.yml: piuparts job: Use image with the following changes:
      + Add pre_install_copy_configs and post_install_remove_configs to copy,
        resp. remove config files from /etc-target to /etc
      + patch pre_remove_50_find_bad_permissions to workaround findutils bug
        #912180. Also proposed another workaround in piuparts as bug #911334
        which is merged but not yet released
  * Upload to unstable

samba (2:4.9.1+dfsg-1) experimental; urgency=medium

  * New upstream release

samba (2:4.9.0+dfsg-1) experimental; urgency=medium

  * Upload to experimental
  * New upstream release
    - Update d/gbp.conf, d/watch and d/README.source for 4.9
    - Remove Fix-pidl-manpage-sections.patch, Fix-spelling.patch and
      Improve-vfs_linux_xfs_sgid-manpage.patch, merged upstream
    - Bump build-depends talloc >= 2.1.14, tdb >= 1.3.16, tevent >= 0.9.37 and
      ldb >= 2:1.4.2'
    - Update paths
    - Update libsmbclient.symbols
    - ctdb.lintian-override: Remove script-not-executable override
    - Add ctdb.NEWS: "Configuration has been completely overhauled"
    - ctdb: Enable/disable legacy script in postinst/presinst

samba (2:4.8.5+dfsg-1) unstable; urgency=medium

  * New upstream release
    - Bump ldb Build-depends to 2:1.4.0+really1.3.6
    - Fixes FTBFS on kFreeBSD (Closes: #883972)
    - d/rules: winbind_krb5_locator is now in the correct path
    - winbind_krb5_locator manpage has moved from section 7 to 8
  * Standards-Version: 4.2.1

Date: Wed, 28 Nov 2018 20:06:47 -0200
Changed-By: Andreas Hasenack <andreas at canonical.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/samba/2:4.9.2+dfsg-2ubuntu1
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 28 Nov 2018 20:06:47 -0200
Source: samba
Binary: samba samba-libs samba-common samba-common-bin smbclient samba-testsuite registry-tools libparse-pidl-perl samba-dev python-samba samba-dsdb-modules samba-vfs-modules libsmbclient libsmbclient-dev winbind libpam-winbind libnss-winbind libwbclient0 libwbclient-dev ctdb
Architecture: source
Version: 2:4.9.2+dfsg-2ubuntu1
Distribution: disco
Urgency: high
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Andreas Hasenack <andreas at canonical.com>
Description:
 ctdb       - clustered database to store temporary data
 libnss-winbind - Samba nameservice integration plugins
 libpam-winbind - Windows domain authentication integration plugin
 libparse-pidl-perl - IDL compiler written in Perl
 libsmbclient - shared library for communication with SMB/CIFS servers
 libsmbclient-dev - development files for libsmbclient
 libwbclient-dev - Samba winbind client library - development files
 libwbclient0 - Samba winbind client library
 python-samba - Python bindings for Samba
 registry-tools - tools for viewing and manipulating the Windows registry
 samba      - SMB/CIFS file, print, and login server for Unix
 samba-common - common files used by both the Samba server and client
 samba-common-bin - Samba common files used by both the server and the client
 samba-dev  - tools for extending Samba
 samba-dsdb-modules - Samba Directory Services Database
 samba-libs - Samba core libraries
 samba-testsuite - test suite from Samba
 samba-vfs-modules - Samba Virtual FileSystem plugins
 smbclient  - command-line SMB/CIFS clients for Unix
 winbind    - service to resolve user and group information from Windows NT ser
Closes: 858923 883972 911530 913143
Launchpad-Bugs-Fixed: 570944
Changes:
 samba (2:4.9.2+dfsg-2ubuntu1) disco; urgency=medium
 .
   * Merge with Debian unstable. Remaining changes:
     - debian/VERSION.patch: Update vendor string to "Ubuntu".
     - debian/smb.conf;
       + Add "(Samba, Ubuntu)" to server string.
       + Comment out the default [homes] share, and add a comment about
         "valid users = %s" to show users how to restrict access to
         \\server\username to only username.
     - debian/samba-common.config:
       + Do not change priority to high if dhclient3 is installed.
     - Add apport hook:
       + Created debian/source_samba.py.
       + debian/rules, debian/samba-common-bin.install: install hook.
     - d/control, d/rules: Disable glusterfs support because it's not in main.
       MIR bug is https://launchpad.net/bugs/1274247
   * Dropped:
     - d/p/fix-rmdir.patch: Fix to make smbclient report directory-not-empty
       errors (LP: 1795772)
       [Fixed upstream]
 .
 samba (2:4.9.2+dfsg-2) unstable; urgency=high
 .
   * New upstream security release
     - CVE-2018-14629 Unprivileged adding of CNAME record causing loop in AD
       Internal DNS server
     - CVE-2018-16841 Double-free in Samba AD DC KDC with PKINIT
     - CVE-2018-16851 NULL pointer de-reference in Samba AD DC LDAP server
     - CVE-2018-16852 NULL pointer de-reference in Samba AD DC DNS servers
     - because of CVE-2018-16853 (Samba AD DC S4U2Self Crash in experimental
       MIT Kerberos configuration (unsupported)), mark the MIT Kerberos build of
       the Samba AD DC as experimental (not used in Debian package)
     - CVE-2018-16857 Bad password count in AD DC not always effective
   * Prepend 1.5.1+really to ldb version
 .
 samba (2:4.9.2+dfsg-1) unstable; urgency=medium
 .
   * New upstream release
     - Bump build-dependencies to ldb 1.4.2
     - Update debian/samba-libs.install
   * d/gitlab-ci.yml:
     - Update to use include
     - allow_failure for reprotest until #912340 is fixed
   * d/rules: Replace override_dh_perl by override_dh_perl-arch (Closes: #913143)
   * debian/gitlab-ci.yml:
     - Samba sometimes needs ldb from experimental
     - Use ldb from experimental in piuparts
 .
 samba (2:4.9.1+dfsg-2) unstable; urgency=medium
 .
   [ Mathieu Parent ]
   * Enable --accel-aes=intelaesni on DEB_HOST_ARCH_CPU=amd64 instead of
     DEB_HOST_ARCH=amd64. This matches samba-libs.install and adds x32
   * Allow one to change password via passwd in default config
     - third_party: Update pam_wrapper to version 1.0.7
     - third_party: Add pam_set_items.so from pam_wrapper
     - nsswitch: Add try_authtok option to pam_winbind
     - tests: Check pam_winbind pw change with different options
     - Patch for previous 4 commits
     - debian/winbind.pam-config: Use the new try_authtok option allowing
       password change while preserving current behavior with password strength
       modules (Closes: #858923, LP: #570944)
   * README.source: use gbp pull --track-missing
   * Override library-not-linked-against-libc false positives (See #896012)
   * Fix wrong-path-for-interpreter for pidl and findsmb
   * ctdb.postrm: Fix to disable_legacy (found by piuparts) (Closes: #911530)
 .
   [ James Clarke ]
   * Fix systemd-related build failures on non-Linux
 .
   [ Mathieu Parent ]
   * Add Gitlab CI:
     - Subscribe to salsa-ci-team/pipeline (See salsa-ci-team/pipeline!27 and
       samba-team/samba!10)
     - Copy /etc/apt/{sources.list.d,preferences.d} in the dockerbuilder
       container (salsa-ci-team/images!9)
     - Allow daemons to start during autopkgtest (salsa-ci-team/images!10)
     - debian/gitlab-ci.yml: all jobs: Use ldb from experimental
     - debian/gitlab-ci.yml: piuparts job: Add --scriptsdir, --allow-database
       and --warn-on-leftovers-after-purge options
     - debian/gitlab-ci.yml: piuparts job: Copy apt config to allow enabling
       extra repositories
     - debian/gitlab-ci.yml: piuparts job: Use image with the following changes:
       + Add pre_install_copy_configs and post_install_remove_configs to copy,
         resp. remove config files from /etc-target to /etc
       + patch pre_remove_50_find_bad_permissions to workaround findutils bug
         #912180. Also proposed another workaround in piuparts as bug #911334
         which is merged but not yet released
   * Upload to unstable
 .
 samba (2:4.9.1+dfsg-1) experimental; urgency=medium
 .
   * New upstream release
 .
 samba (2:4.9.0+dfsg-1) experimental; urgency=medium
 .
   * Upload to experimental
   * New upstream release
     - Update d/gbp.conf, d/watch and d/README.source for 4.9
     - Remove Fix-pidl-manpage-sections.patch, Fix-spelling.patch and
       Improve-vfs_linux_xfs_sgid-manpage.patch, merged upstream
     - Bump build-depends talloc >= 2.1.14, tdb >= 1.3.16, tevent >= 0.9.37 and
       ldb >= 2:1.4.2'
     - Update paths
     - Update libsmbclient.symbols
     - ctdb.lintian-override: Remove script-not-executable override
     - Add ctdb.NEWS: "Configuration has been completely overhauled"
     - ctdb: Enable/disable legacy script in postinst/presinst
 .
 samba (2:4.8.5+dfsg-1) unstable; urgency=medium
 .
   * New upstream release
     - Bump ldb Build-depends to 2:1.4.0+really1.3.6
     - Fixes FTBFS on kFreeBSD (Closes: #883972)
     - d/rules: winbind_krb5_locator is now in the correct path
     - winbind_krb5_locator manpage has moved from section 7 to 8
   * Standards-Version: 4.2.1
Checksums-Sha1:
 a8d976f28e4403913214d1f58147ccbf8889510b 4240 samba_4.9.2+dfsg-2ubuntu1.dsc
 ce61822c165232ef9711dcb510cdae6c10c33349 11417264 samba_4.9.2+dfsg.orig.tar.xz
 9baa8d332d1722903b0162ae9660e7136bd58e39 253764 samba_4.9.2+dfsg-2ubuntu1.debian.tar.xz
 4547c8850dc53997e541a5f31c2629aec5346a63 11252 samba_4.9.2+dfsg-2ubuntu1_source.buildinfo
Checksums-Sha256:
 356ef14db01efd1dbdb24f6826166894d47e5049ab3c705e967d752441e91da3 4240 samba_4.9.2+dfsg-2ubuntu1.dsc
 8e36d199e27fc9764c4d0e6aad51fe659b9836e2048ba955251eb8a03fba5b8a 11417264 samba_4.9.2+dfsg.orig.tar.xz
 d201e71145bfaedbf92987f05def99bb0627e1c3cb075d6c18f113214e9be7b6 253764 samba_4.9.2+dfsg-2ubuntu1.debian.tar.xz
 61327159da78d62ea461c493e4054a42a9f1a8ed774a591f59cd2809f3ddd67e 11252 samba_4.9.2+dfsg-2ubuntu1_source.buildinfo
Files:
 0314a3990cf7207ec88134c2f764f710 4240 net optional samba_4.9.2+dfsg-2ubuntu1.dsc
 f497e701444bcc280f200384d9344a6c 11417264 net optional samba_4.9.2+dfsg.orig.tar.xz
 f1db557694db80ea96e03976807bbb49 253764 net optional samba_4.9.2+dfsg-2ubuntu1.debian.tar.xz
 fdccaf769b58cbb92eaf7f5662838870 11252 net optional samba_4.9.2+dfsg-2ubuntu1_source.buildinfo
Original-Maintainer: Debian Samba Maintainers <pkg-samba-maint at lists.alioth.debian.org>

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEiGZB1jWM2kalbBxyrJg+tb9ry6kFAlwAHkkACgkQrJg+tb9r
y6lDbw//erQjUcRsHiIFr5WubneIpcHfSau1+JciOiyDQdp5/v8wd5rudWYkBSv1
4yeKIBfM7ITFyxhjG9OrCFJI1UYkbEemlEs1G3d3iAumDMGXAYhuGgVaTuPZqQAT
bMIcc0mbPH70R+0sEWQnZXa1iWPG5oMvP/+jbCIQ+YYf5xeXfYInklq4hw7LYVsS
i3gBmsQUceBEq3ENkQRNLdH82qK/ij+/HQO+k1AwosoXGd2KpiJUeYUsqooWoiL7
LhFhd61PulOgG+vTdX7nU2jXhWd3dM0+YQZuHNJrnH6dy50AeS29q+/lTP6sqC0t
aCe21zlT+jpDKAgBGcstX6huAdEauLkmiRTwBzdb+NM7MZUIvAuGqiJ2M3N4aqJv
iQdEK5rXU8ylpIAKnWJL5mZ9F1GTy5w8JhneIJ54CWNYg4K7HzmQztKCEKotpmEl
zY/4yU0dAOgiK55/zR499ChO0/7GiIZ9Irng2XLNHf77ttL4DiE2Eik/GJxPvDbJ
j/1CvI8aAdlug2gVP/+CB/XUhETdFxdG+NUMNa9Lwm9+7kh16b31iaC2QLR9LjIO
orTxohfILLnqY1AwdNBDj2HdRMhAlpOUtNVWyCF5HvdcrRS5BR/ouLl0jbImhl1H
VRUCc9oGw6rrtoCkxovwmFwNT0jyESDXVWAKFIob/bGA+83gTQs=
=l4xP
-----END PGP SIGNATURE-----


More information about the Disco-changes mailing list