Format: 1.7
Date: Tue,  6 Feb 2007 13:22:06 +0000
Source: cupsys
Binary: libcupsys2-dev cupsys libcupsys2 libcupsimage2 cupsys-common cupsys-client cupsys-bsd libcupsimage2-dev
Architecture: source
Version: 1.2.7-4ubuntu1
Distribution: feisty
Urgency: high
Maintainer: Debian CUPS Maintainers <pkg-cups-devel at>
Changed-By: Till Kamppeter <till.kamppeter at>
 cupsys     - Common UNIX Printing System(tm) - server
 cupsys-bsd - Common UNIX Printing System(tm) - BSD commands
 cupsys-client - Common UNIX Printing System(tm) - client programs (SysV)
 cupsys-common - Common UNIX Printing System(tm) - common files
 libcupsimage2 - Common UNIX Printing System(tm) - image libs
 libcupsimage2-dev - Common UNIX Printing System(tm) - image development files
 libcupsys2 - Common UNIX Printing System(tm) - libs
 libcupsys2-dev - Common UNIX Printing System(tm) - development files
Closes: 403703 406253 408154 408332 409335
 cupsys (1.2.7-4ubuntu1) feisty; urgency=low
   * Merge from debian unstable, remaining changes:
     - Snakeoil SSL cert support:
       + debian/control: Add ssl-cert dependency.
       + debian/cupsys.postinst: Symlink snakeoil SSL certificate if present.
     - TearDown (fast shutdown):
       + debian/control: Add sysv-rc (>= 2.86.ds1-14.1ubuntu2) dependency.
       + debian/cupsys.postinst: Remove obsolete rc.d links.
       + debian/rules: Use 'multiuser' update-rc.d mode.
     - debian/control: Drop libcupsys2-gnutls10 and cupsys-dbg packages.
     - Run cupsd as system user 'cupsd' instead of root to confine impact of
       security vulnerabilities:
       + cupsys{,-client}.postinst: Set up cupsys user and put it into the
         appropriate groups.
       + debian/cupsys.init.d: Set up proper permissions of log files.
       + debian/cupsys.init.d: Disable 'reload', force-reload does restart,
         since cupsd cannot reload as non-root.
       + debian/cupsys.logrotate: Own the log files to cupsys:lpadmin.
       + Add debian/patches/ubuntu-external-pam-helper.dpatch: Helper program
         cups-check-pam-auth which performs PAM authentication and returns the
         status as exit code.
       + debian/cupsys.files: Install cups-check-pam-auth.
       + debian/cupsys.postinst: Set permissions of cups-check-pam-auth to
         cupsys:shadow 2754.
       + debian/rules: Configure with --enable-privilege-dropping.
       + debian/rules: Install lpd backend suid root so that it can bind to a
         privileged port.
     - Support user-installed PPDs:
       - debian/cupsys.dirs: Add usr/share/ppd/custom.
       - debian/cupsys.init.d: Set up this dir as root:lpadmin 03775.
     - debian/patches/14_dont_force_ssl.dpatch: Do not require SSL for the web
       frontend since gnome-cups-manager does not cope with that.
     - debian/patches/58_cupsd.conf-AllowLocal.dpatch: Allow access to local
       ethernet by default. This just affects the ACL, for actually enabling
       access cupsd needs to be switched to not only listen on localhost. (So
       this does not need to be configured in two different places).
     - debian/patches/ubuntu-default-error-policy-retry-job.dpatch: Retry a
       failed job instead of stopping the print queue.
     - debian/patches/ubuntu-disable-browsing.dpatch: Disable browsing by
     - Changed dependency in cupsys-bsd for netbase into update-inetd.
     - Removed obsolete emacs config settings at the end of changelog.
   * debian/cupsys.init.d: Fixed parallel port module loading in the
     init script, the "ppdev" module got only loaded when the "lp"
     module was not loaded yet (closes LP#29050).
   * debian/cupsys.init.d: Set permissions of log files again after
     starting the CUPS daemon, as the daemon sets them to a bad state
     so that it cannot log after dropping privileges (closes LP#54277).
 cupsys (1.2.7-4) unstable; urgency=high
   [ Kenshi Muto ]
   * Use dh_usrlocal to install files in /usr/local in the
     maintainer scripts, instead of shipping them in the deb.
     This was policy violation (closes: #409335)
 cupsys (1.2.7-3) unstable; urgency=high
   [ Kenshi Muto ]
   * removed STR2137 patch. This patch corruted some
     Postscript files. (closes: #403703) This was a release
     critical bug.
   * Provides /usr/local/share/ppd and /opt/share/ppd
     to satisfy LSB 3.2. (closes: #408154)
   * Applied upstream patch:
     - STR2198: The scheduler still loaded the remote printer cache,
       even when browsing was disabled
   * Debconf translation
     - Portuguese (closes: #408332)
     - Norwegian (closes: #406253)
