[ubuntu/disco-proposed] samba 2:4.9.2+dfsg-2ubuntu1 (Accepted)
Andreas Hasenack
andreas at canonical.com
Thu Nov 29 17:15:15 UTC 2018
samba (2:4.9.2+dfsg-2ubuntu1) disco; urgency=medium
* Merge with Debian unstable. Remaining changes:
- debian/VERSION.patch: Update vendor string to "Ubuntu".
- debian/smb.conf;
+ Add "(Samba, Ubuntu)" to server string.
+ Comment out the default [homes] share, and add a comment about
"valid users = %s" to show users how to restrict access to
\\server\username to only username.
- debian/samba-common.config:
+ Do not change priority to high if dhclient3 is installed.
- Add apport hook:
+ Created debian/source_samba.py.
+ debian/rules, debian/samba-common-bin.install: install hook.
- d/control, d/rules: Disable glusterfs support because it's not in main.
MIR bug is https://launchpad.net/bugs/1274247
* Dropped:
- d/p/fix-rmdir.patch: Fix to make smbclient report directory-not-empty
errors (LP: 1795772)
[Fixed upstream]
samba (2:4.9.2+dfsg-2) unstable; urgency=high
* New upstream security release
- CVE-2018-14629 Unprivileged adding of CNAME record causing loop in AD
Internal DNS server
- CVE-2018-16841 Double-free in Samba AD DC KDC with PKINIT
- CVE-2018-16851 NULL pointer de-reference in Samba AD DC LDAP server
- CVE-2018-16852 NULL pointer de-reference in Samba AD DC DNS servers
- because of CVE-2018-16853 (Samba AD DC S4U2Self Crash in experimental
MIT Kerberos configuration (unsupported)), mark the MIT Kerberos build of
the Samba AD DC as experimental (not used in Debian package)
- CVE-2018-16857 Bad password count in AD DC not always effective
* Prepend 1.5.1+really to ldb version
samba (2:4.9.2+dfsg-1) unstable; urgency=medium
* New upstream release
- Bump build-dependencies to ldb 1.4.2
- Update debian/samba-libs.install
* d/gitlab-ci.yml:
- Update to use include
- allow_failure for reprotest until #912340 is fixed
* d/rules: Replace override_dh_perl by override_dh_perl-arch (Closes: #913143)
* debian/gitlab-ci.yml:
- Samba sometimes needs ldb from experimental
- Use ldb from experimental in piuparts
samba (2:4.9.1+dfsg-2) unstable; urgency=medium
[ Mathieu Parent ]
* Enable --accel-aes=intelaesni on DEB_HOST_ARCH_CPU=amd64 instead of
DEB_HOST_ARCH=amd64. This matches samba-libs.install and adds x32
* Allow one to change password via passwd in default config
- third_party: Update pam_wrapper to version 1.0.7
- third_party: Add pam_set_items.so from pam_wrapper
- nsswitch: Add try_authtok option to pam_winbind
- tests: Check pam_winbind pw change with different options
- Patch for previous 4 commits
- debian/winbind.pam-config: Use the new try_authtok option allowing
password change while preserving current behavior with password strength
modules (Closes: #858923, LP: #570944)
* README.source: use gbp pull --track-missing
* Override library-not-linked-against-libc false positives (See #896012)
* Fix wrong-path-for-interpreter for pidl and findsmb
* ctdb.postrm: Fix to disable_legacy (found by piuparts) (Closes: #911530)
[ James Clarke ]
* Fix systemd-related build failures on non-Linux
[ Mathieu Parent ]
* Add Gitlab CI:
- Subscribe to salsa-ci-team/pipeline (See salsa-ci-team/pipeline!27 and
samba-team/samba!10)
- Copy /etc/apt/{sources.list.d,preferences.d} in the dockerbuilder
container (salsa-ci-team/images!9)
- Allow daemons to start during autopkgtest (salsa-ci-team/images!10)
- debian/gitlab-ci.yml: all jobs: Use ldb from experimental
- debian/gitlab-ci.yml: piuparts job: Add --scriptsdir, --allow-database
and --warn-on-leftovers-after-purge options
- debian/gitlab-ci.yml: piuparts job: Copy apt config to allow enabling
extra repositories
- debian/gitlab-ci.yml: piuparts job: Use image with the following changes:
+ Add pre_install_copy_configs and post_install_remove_configs to copy,
resp. remove config files from /etc-target to /etc
+ patch pre_remove_50_find_bad_permissions to workaround findutils bug
#912180. Also proposed another workaround in piuparts as bug #911334
which is merged but not yet released
* Upload to unstable
samba (2:4.9.1+dfsg-1) experimental; urgency=medium
* New upstream release
samba (2:4.9.0+dfsg-1) experimental; urgency=medium
* Upload to experimental
* New upstream release
- Update d/gbp.conf, d/watch and d/README.source for 4.9
- Remove Fix-pidl-manpage-sections.patch, Fix-spelling.patch and
Improve-vfs_linux_xfs_sgid-manpage.patch, merged upstream
- Bump build-depends talloc >= 2.1.14, tdb >= 1.3.16, tevent >= 0.9.37 and
ldb >= 2:1.4.2'
- Update paths
- Update libsmbclient.symbols
- ctdb.lintian-override: Remove script-not-executable override
- Add ctdb.NEWS: "Configuration has been completely overhauled"
- ctdb: Enable/disable legacy script in postinst/presinst
samba (2:4.8.5+dfsg-1) unstable; urgency=medium
* New upstream release
- Bump ldb Build-depends to 2:1.4.0+really1.3.6
- Fixes FTBFS on kFreeBSD (Closes: #883972)
- d/rules: winbind_krb5_locator is now in the correct path
- winbind_krb5_locator manpage has moved from section 7 to 8
* Standards-Version: 4.2.1
Date: Wed, 28 Nov 2018 20:06:47 -0200
Changed-By: Andreas Hasenack <andreas at canonical.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/samba/2:4.9.2+dfsg-2ubuntu1
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Wed, 28 Nov 2018 20:06:47 -0200
Source: samba
Binary: samba samba-libs samba-common samba-common-bin smbclient samba-testsuite registry-tools libparse-pidl-perl samba-dev python-samba samba-dsdb-modules samba-vfs-modules libsmbclient libsmbclient-dev winbind libpam-winbind libnss-winbind libwbclient0 libwbclient-dev ctdb
Architecture: source
Version: 2:4.9.2+dfsg-2ubuntu1
Distribution: disco
Urgency: high
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Andreas Hasenack <andreas at canonical.com>
Description:
ctdb - clustered database to store temporary data
libnss-winbind - Samba nameservice integration plugins
libpam-winbind - Windows domain authentication integration plugin
libparse-pidl-perl - IDL compiler written in Perl
libsmbclient - shared library for communication with SMB/CIFS servers
libsmbclient-dev - development files for libsmbclient
libwbclient-dev - Samba winbind client library - development files
libwbclient0 - Samba winbind client library
python-samba - Python bindings for Samba
registry-tools - tools for viewing and manipulating the Windows registry
samba - SMB/CIFS file, print, and login server for Unix
samba-common - common files used by both the Samba server and client
samba-common-bin - Samba common files used by both the server and the client
samba-dev - tools for extending Samba
samba-dsdb-modules - Samba Directory Services Database
samba-libs - Samba core libraries
samba-testsuite - test suite from Samba
samba-vfs-modules - Samba Virtual FileSystem plugins
smbclient - command-line SMB/CIFS clients for Unix
winbind - service to resolve user and group information from Windows NT ser
Closes: 858923 883972 911530 913143
Launchpad-Bugs-Fixed: 570944
Changes:
samba (2:4.9.2+dfsg-2ubuntu1) disco; urgency=medium
.
* Merge with Debian unstable. Remaining changes:
- debian/VERSION.patch: Update vendor string to "Ubuntu".
- debian/smb.conf;
+ Add "(Samba, Ubuntu)" to server string.
+ Comment out the default [homes] share, and add a comment about
"valid users = %s" to show users how to restrict access to
\\server\username to only username.
- debian/samba-common.config:
+ Do not change priority to high if dhclient3 is installed.
- Add apport hook:
+ Created debian/source_samba.py.
+ debian/rules, debian/samba-common-bin.install: install hook.
- d/control, d/rules: Disable glusterfs support because it's not in main.
MIR bug is https://launchpad.net/bugs/1274247
* Dropped:
- d/p/fix-rmdir.patch: Fix to make smbclient report directory-not-empty
errors (LP: 1795772)
[Fixed upstream]
.
samba (2:4.9.2+dfsg-2) unstable; urgency=high
.
* New upstream security release
- CVE-2018-14629 Unprivileged adding of CNAME record causing loop in AD
Internal DNS server
- CVE-2018-16841 Double-free in Samba AD DC KDC with PKINIT
- CVE-2018-16851 NULL pointer de-reference in Samba AD DC LDAP server
- CVE-2018-16852 NULL pointer de-reference in Samba AD DC DNS servers
- because of CVE-2018-16853 (Samba AD DC S4U2Self Crash in experimental
MIT Kerberos configuration (unsupported)), mark the MIT Kerberos build of
the Samba AD DC as experimental (not used in Debian package)
- CVE-2018-16857 Bad password count in AD DC not always effective
* Prepend 1.5.1+really to ldb version
.
samba (2:4.9.2+dfsg-1) unstable; urgency=medium
.
* New upstream release
- Bump build-dependencies to ldb 1.4.2
- Update debian/samba-libs.install
* d/gitlab-ci.yml:
- Update to use include
- allow_failure for reprotest until #912340 is fixed
* d/rules: Replace override_dh_perl by override_dh_perl-arch (Closes: #913143)
* debian/gitlab-ci.yml:
- Samba sometimes needs ldb from experimental
- Use ldb from experimental in piuparts
.
samba (2:4.9.1+dfsg-2) unstable; urgency=medium
.
[ Mathieu Parent ]
* Enable --accel-aes=intelaesni on DEB_HOST_ARCH_CPU=amd64 instead of
DEB_HOST_ARCH=amd64. This matches samba-libs.install and adds x32
* Allow one to change password via passwd in default config
- third_party: Update pam_wrapper to version 1.0.7
- third_party: Add pam_set_items.so from pam_wrapper
- nsswitch: Add try_authtok option to pam_winbind
- tests: Check pam_winbind pw change with different options
- Patch for previous 4 commits
- debian/winbind.pam-config: Use the new try_authtok option allowing
password change while preserving current behavior with password strength
modules (Closes: #858923, LP: #570944)
* README.source: use gbp pull --track-missing
* Override library-not-linked-against-libc false positives (See #896012)
* Fix wrong-path-for-interpreter for pidl and findsmb
* ctdb.postrm: Fix to disable_legacy (found by piuparts) (Closes: #911530)
.
[ James Clarke ]
* Fix systemd-related build failures on non-Linux
.
[ Mathieu Parent ]
* Add Gitlab CI:
- Subscribe to salsa-ci-team/pipeline (See salsa-ci-team/pipeline!27 and
samba-team/samba!10)
- Copy /etc/apt/{sources.list.d,preferences.d} in the dockerbuilder
container (salsa-ci-team/images!9)
- Allow daemons to start during autopkgtest (salsa-ci-team/images!10)
- debian/gitlab-ci.yml: all jobs: Use ldb from experimental
- debian/gitlab-ci.yml: piuparts job: Add --scriptsdir, --allow-database
and --warn-on-leftovers-after-purge options
- debian/gitlab-ci.yml: piuparts job: Copy apt config to allow enabling
extra repositories
- debian/gitlab-ci.yml: piuparts job: Use image with the following changes:
+ Add pre_install_copy_configs and post_install_remove_configs to copy,
resp. remove config files from /etc-target to /etc
+ patch pre_remove_50_find_bad_permissions to workaround findutils bug
#912180. Also proposed another workaround in piuparts as bug #911334
which is merged but not yet released
* Upload to unstable
.
samba (2:4.9.1+dfsg-1) experimental; urgency=medium
.
* New upstream release
.
samba (2:4.9.0+dfsg-1) experimental; urgency=medium
.
* Upload to experimental
* New upstream release
- Update d/gbp.conf, d/watch and d/README.source for 4.9
- Remove Fix-pidl-manpage-sections.patch, Fix-spelling.patch and
Improve-vfs_linux_xfs_sgid-manpage.patch, merged upstream
- Bump build-depends talloc >= 2.1.14, tdb >= 1.3.16, tevent >= 0.9.37 and
ldb >= 2:1.4.2'
- Update paths
- Update libsmbclient.symbols
- ctdb.lintian-override: Remove script-not-executable override
- Add ctdb.NEWS: "Configuration has been completely overhauled"
- ctdb: Enable/disable legacy script in postinst/presinst
.
samba (2:4.8.5+dfsg-1) unstable; urgency=medium
.
* New upstream release
- Bump ldb Build-depends to 2:1.4.0+really1.3.6
- Fixes FTBFS on kFreeBSD (Closes: #883972)
- d/rules: winbind_krb5_locator is now in the correct path
- winbind_krb5_locator manpage has moved from section 7 to 8
* Standards-Version: 4.2.1
Checksums-Sha1:
a8d976f28e4403913214d1f58147ccbf8889510b 4240 samba_4.9.2+dfsg-2ubuntu1.dsc
ce61822c165232ef9711dcb510cdae6c10c33349 11417264 samba_4.9.2+dfsg.orig.tar.xz
9baa8d332d1722903b0162ae9660e7136bd58e39 253764 samba_4.9.2+dfsg-2ubuntu1.debian.tar.xz
4547c8850dc53997e541a5f31c2629aec5346a63 11252 samba_4.9.2+dfsg-2ubuntu1_source.buildinfo
Checksums-Sha256:
356ef14db01efd1dbdb24f6826166894d47e5049ab3c705e967d752441e91da3 4240 samba_4.9.2+dfsg-2ubuntu1.dsc
8e36d199e27fc9764c4d0e6aad51fe659b9836e2048ba955251eb8a03fba5b8a 11417264 samba_4.9.2+dfsg.orig.tar.xz
d201e71145bfaedbf92987f05def99bb0627e1c3cb075d6c18f113214e9be7b6 253764 samba_4.9.2+dfsg-2ubuntu1.debian.tar.xz
61327159da78d62ea461c493e4054a42a9f1a8ed774a591f59cd2809f3ddd67e 11252 samba_4.9.2+dfsg-2ubuntu1_source.buildinfo
Files:
0314a3990cf7207ec88134c2f764f710 4240 net optional samba_4.9.2+dfsg-2ubuntu1.dsc
f497e701444bcc280f200384d9344a6c 11417264 net optional samba_4.9.2+dfsg.orig.tar.xz
f1db557694db80ea96e03976807bbb49 253764 net optional samba_4.9.2+dfsg-2ubuntu1.debian.tar.xz
fdccaf769b58cbb92eaf7f5662838870 11252 net optional samba_4.9.2+dfsg-2ubuntu1_source.buildinfo
Original-Maintainer: Debian Samba Maintainers <pkg-samba-maint at lists.alioth.debian.org>
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEiGZB1jWM2kalbBxyrJg+tb9ry6kFAlwAHkkACgkQrJg+tb9r
y6lDbw//erQjUcRsHiIFr5WubneIpcHfSau1+JciOiyDQdp5/v8wd5rudWYkBSv1
4yeKIBfM7ITFyxhjG9OrCFJI1UYkbEemlEs1G3d3iAumDMGXAYhuGgVaTuPZqQAT
bMIcc0mbPH70R+0sEWQnZXa1iWPG5oMvP/+jbCIQ+YYf5xeXfYInklq4hw7LYVsS
i3gBmsQUceBEq3ENkQRNLdH82qK/ij+/HQO+k1AwosoXGd2KpiJUeYUsqooWoiL7
LhFhd61PulOgG+vTdX7nU2jXhWd3dM0+YQZuHNJrnH6dy50AeS29q+/lTP6sqC0t
aCe21zlT+jpDKAgBGcstX6huAdEauLkmiRTwBzdb+NM7MZUIvAuGqiJ2M3N4aqJv
iQdEK5rXU8ylpIAKnWJL5mZ9F1GTy5w8JhneIJ54CWNYg4K7HzmQztKCEKotpmEl
zY/4yU0dAOgiK55/zR499ChO0/7GiIZ9Irng2XLNHf77ttL4DiE2Eik/GJxPvDbJ
j/1CvI8aAdlug2gVP/+CB/XUhETdFxdG+NUMNa9Lwm9+7kh16b31iaC2QLR9LjIO
orTxohfILLnqY1AwdNBDj2HdRMhAlpOUtNVWyCF5HvdcrRS5BR/ouLl0jbImhl1H
VRUCc9oGw6rrtoCkxovwmFwNT0jyESDXVWAKFIob/bGA+83gTQs=
=l4xP
-----END PGP SIGNATURE-----
More information about the Disco-changes
mailing list