Merge newer dovecot for Cosmic

Bug #1771816 reported by Christian Ehrhardt 
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
dovecot (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

For reasons outlined in bug 1771524 we won't merge 2.3.x just yet.
So reconsider merging the latest 2.2.x to have the work on mail-stack-delivery done.

This will simplify the 2.3.x move later on to be focused on just that.

Related branches

Revision history for this message
Christian Ehrhardt  (paelzer) wrote :

CVEs are all in.
Also all other assumptions of bug 1771524 still hold true in regard to mail-stack-delivery.

The only thing not needed here is for the config changes and pam login issue sin 2.3.1

Changed in dovecot (Ubuntu):
status: New → In Progress
Revision history for this message
Christian Ehrhardt  (paelzer) wrote :

Need to re-eval Lucene issues with 2.2.35-2

Revision history for this message
Christian Ehrhardt  (paelzer) wrote :
Revision history for this message
Christian Ehrhardt  (paelzer) wrote :
Revision history for this message
Christian Ehrhardt  (paelzer) wrote :

FYI: In Cosmic-Proposed now

Revision history for this message
Launchpad Janitor (janitor) wrote :
Download full text (4.9 KiB)

This bug was fixed in the package dovecot - 1:2.2.35-2ubuntu1

---------------
dovecot (1:2.2.35-2ubuntu1) cosmic; urgency=medium

  * Merge with Debian unstable (LP: #1771816). Remaining changes:
    - Add updated autopkgtest to debian/tests/* (these tests got simplified
      and streamlined to use the packages default configuration which solves
      LP: #1638865)
  * Dropped Changes (now upstream)
    - SECURITY UPDATE: rfc822_parse_domain Information Leak Vulnerability
    - SECURITY UPDATE: TLS SNI config lookups DoS
    - SECURITY UPDATE: Memory leak that can cause crash due to memory exhaustion
  * Dropped Changes (no more needed after 18.04)
    - handle conffile removal of /etc/init/dovecot.conf (due to dropping
      upstart).
  * Dropped Changes (no more needed)
    - Drop build dependency on libstemmer-dev (universe) - this is now in main
    - Disable dovecot-lucene plugin as it had various issues and is deprecated
      in favor of solr anyway (LP 1524526) - no more failing in Cosmic.
  * Dropped Changes (mail-stack-delivery)
    It was decided to no more carry mail-stack-delivery as a package in favor
    to out-of-package solutions. It became less useful due to one of the
    biggest benefit (auto-ssl setup) being part of the base setup now.
    - Add mail-stack-delivery
      - add package in d/rules, d/control
      - add d/*mail-stack-delivery* maintainer scripts and default conf
      - d/mail-stack-delivery.preinst: Move previously installed backups and
        config files to a new package namespace.
      - d/mail-stack-delivery.README.Debian clarified use of configuration files
    - d/mail-stack-delivery.postinst: Use ssl key/cert paths now set up by
      dovecot-core; transition for such configs formerly set up by
      mail-stack-delivery to use the new default ssl config (if user had no
      conffile change or choses new defaults).
    - d/mail-stack-delivery.postinst: if moving dovecot to the new defaults on
      upgrade, also move the related postfix key/cert entries.
    - debian/99-mail-stack-delivery.conf: do not explicitly enable protocols
      as all installed are auto-included from the base config now.
    - adapt autopkgtests to match new version.
    - d/control: for the ssl transition to work we need to ensure dovecot-core
      is complete before upgrading mail-stack-delivery, so add a Pre-Depends.
    - d/mail-stack-delivery.postinst: add SSL_CERT/SSL_KEY detection to
      postconf section (was formerly initialized at the now dropped key setup)
    - d/mail-stack-delivery.postinst: fix SSL_CERT/SSL_KEY detection to only
      read non-comments from the right keywords and to strip common bad-chars
    - d/mail-stack-delivery.postinst: stop modifying mandatory tls config,
      recent upstream has sane defaults now
    - debian/99-mail-stack-delivery.conf: drop explicit ssl_cipher_list,
      recent upstream has sane defaults now
  * Added Changes:
    - carry mail-stack-delivery as empty transitional package
      (can be dropped >20.04)

dovecot (1:2.2.35-2) unstable; urgency=medium

  * [7665652] Use git-subtree to generate pigeonhole patch from git; add
    single-debian-patch to d/source/local...

Read more...

Changed in dovecot (Ubuntu):
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.