Merge samba from Debian unstable for kinetic
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
samba (Ubuntu) |
Fix Released
|
Undecided
|
Andreas Hasenack |
Bug Description
Upstream: 4.15.7
Debian: 2:4.16.1+dfsg-3
Ubuntu: 2:4.15.
Debian does new releases regularly, so it's likely there will be newer versions available before FF that we can pick up if this merge is done later in the cycle.
### New Debian Changes ###
samba (2:4.16.1+dfsg-3) unstable; urgency=medium
* fix ldb package version generation in d/make_shlibs
which was wrong in 2 previous uploads.
Will I *ever* make it actually work someday?
-- Michael Tokarev <email address hidden> Mon, 02 May 2022 18:32:24 +0300
samba (2:4.16.1+dfsg-2) unstable; urgency=medium
* rethink ldb version *again*, to be 2.5.0+smb4.16.1-2
or else 2.5.0+smb-1 from samba-4.16.1-2 sorts before
2.5.0+smb-7 from samba-4.16.0-7.
-- Michael Tokarev <email address hidden> Mon, 02 May 2022 17:02:16 +0300
samba (2:4.16.1+dfsg-1) unstable; urgency=medium
* new upstream minor release 4.16.1
* move-msg.
move /var/lib/
This is a (private) socket directory for IPC, it should not be in /var.
* Remove /var/lib/
* testparm-
testparm deliberately fails if /run/samba does not exist,
while testparam itself does not use it and daemons will
create it on demand. Just make it a warning instead of a
fatal error, and we'll not need to pre-create this dir
in a random place using hackish ways
* ctdb-create-
and ctdb.init before invoking ctdbd (as the latter does not
create its pid directory on demand).
* stop (ab)using tmpfiles.d to pre-create /run/samba/ and /run/ctdb/
and stop creating /run/samba/ in samba-common-
make testparam happy.
* d/rules: minor tweaks
-- Michael Tokarev <email address hidden> Mon, 02 May 2022 13:16:12 +0300
samba (2:4.16.0+dfsg-7) unstable; urgency=medium
* another bunch of small tweaks to d/rules:
- set SHELL to /bin/sh -e
- rework the clean target
- provide fast replacement of architecture.mk
- better expression for DEB_REVISION
- rearrange configure options
* do not disable glusterfs on ubuntu-i386 (glusterfs is now in main)
* mention closing of #1001053 by the 4.16 upload
* change the ldb version string again, removing te '+samba*' suffix
to allow bin-NMUs +b1 (Closes: #1010100)
-- Michael Tokarev <email address hidden> Sun, 24 Apr 2022 16:56:34 +0300
samba (2:4.16.0+dfsg-6) unstable; urgency=medium
* another attempt to fix/work around #221618. Re-enable
libsmbclien
an extra type array int[sizeof(
become a compile error. It is an ugly way to do it, but it should
actually work, unlike various static_
language (C/C++) and standard-dependent. Closes: #221618.
-- Michael Tokarev <email address hidden> Sat, 09 Apr 2022 17:27:09 +0300
samba (2:4.16.0+dfsg-5) unstable; urgency=medium
* disable libsmbclient-
It throws errors in one or another configuration no matter what.
Repoens: #221618
* d/salsa-ci.yml: re-allow blhc salsa-ci test to fail again
due to different bug in blhc
-- Michael Tokarev <email address hidden> Sat, 09 Apr 2022 16:33:57 +0300
samba (2:4.16.0+dfsg-4) unstable; urgency=medium
* libsmbclient-
static_assert (and include <assert.h> to make C++ happy too
(Closes: #1009211)
* disable-
samba tries to verify setuid/setgid etc calls are actually
*working*, not just exists. This is only possible when the
configure is running as root. But it turns out in some salsa-ci
configuration (namely in the reprotest), the second build is
actually running as root, and in that environment, actual
setegid call is failing somehow. Just disable the config-time
check for correctly working setgid and assume it 'just works'
if present, exactly like non-root build will do.
* d/salsa-ci.yml: do not expect failure in blhc test (the original
prob has been fixed long ago), and stop requiring experimental
* mention closing of #999876 by 4.16
-- Michael Tokarev <email address hidden> Sat, 09 Apr 2022 00:42:38 +0300
samba (2:4.16.0+dfsg-3) unstable; urgency=medium
* d/control: comment out the selftest-mode build deps for now
* d/control: forgotten python3-
not just samba-libs, when moving dckeytab python lib (Closes: #1009175)
### Old Ubuntu Delta ###
samba (2:4.15.
* Enable glusterfs support (LP: #1894618):
- d/control: revert disabling of glusterfs, since it's in main now
- d/rules: in Ubuntu, glusterfs is not built for i386, so don't
enable the samba glusterfs vfs mofule in that case
- d/control: build-depend on libglusterfs-dev only on !i386 arches
-- Andreas Hasenack <email address hidden> Wed, 09 Mar 2022 17:31:25 -0300
samba (2:4.15.
* Build dlz module for bind 9.18.x (LP: #1964032)
- d/p/add-
bind 9.18.x
- d/samba-
- d/p/add-
tool and template config file
-- Andreas Hasenack <email address hidden> Fri, 25 Mar 2022 14:53:19 -0300
samba (2:4.15.
* Update nfs scripts for new nfs.conf config (LP: #1961840):
- d/p/fix-
nfsconf(8) if it's available, instead of parsing the old config
files in /etc/default/nfs-*
- d/ctdb.
enable-nfs.sh example script
- d/ctdb.
enable-nfs.sh script
- d/ctdb.
nfs.conf
- d/ctdb.
changes in the new nfs server packages
- d/rules: install the new/changed ctdb example nfs files
-- Andreas Hasenack <email address hidden> Mon, 21 Mar 2022 11:55:54 -0300
samba (2:4.15.
* d/p/lp-
Windows 2021-10 Monthly Rollup patch (LP: #1951490)
-- Andreas Hasenack <email address hidden> Thu, 10 Mar 2022 10:32:59 -0300
samba (2:4.15.
* d/{gpb.
* New upstream release: 4.15.5 (LP: #1946839)
* d/p/Rename-
* d/rules: remove --with-dnsupdate, it was merged with
--with-ads in samba 4.15.0
* d/control: bump required build-depends
* d/rules: drop removal of ctdb tests, they are no longer installed
* Remove findsmb, no longer installed:
- d/smbclient.
- d/rules: drop fixing of findsmb shebang
* d/ctdb.install: remove ctdb_local_daemons, part of ctdb tests,
no longer installed
* d/samba-
modules/plugins
* d/ctdb.install: add tdb_mutex_check
* d/winbind.install: add async_dns_
* d/samba.install: install samba-bgqd and its manpage
* d/{libsmbclient
* d/control: add python3-markdown to build-depends
* d/watch: updated to handle ~dfsg versioning, thanks to
Sergio Durigan Junior <email address hidden>
-- Andreas Hasenack <email address hidden> Tue, 22 Feb 2022 17:59:22 -0300
samba (2:4.13.
* Update to 4.13.17 as a security update
- CVE-2021-43566, CVE-2021-44142, CVE-2022-0336
* Removed patches included in new version:
- debian/
- debian/patches/bug14901-*.patch
- debian/patches/bug14922.patch
-- Marc Deslauriers <email address hidden> Mon, 14 Feb 2022 10:19:08 -0500
samba (2:4.13.
* No-change rebuild for icu soname change
-- William 'jawn-smith' Wilson <email address hidden> Fri, 11 Feb 2022 11:36:14 -0600
samba (2:4.13.
* d/t/util: fix setting the password of the smb test user
(LP: #1955851)
-- Andreas Hasenack <email address hidden> Thu, 20 Jan 2022 17:06:13 -0300
samba (2:4.13.
* No-change rebuild with Python 3.10 as default version
-- Graham Inggs <email address hidden> Sun, 16 Jan 2022 07:01:34 +0000
samba (2:4.13.
* SECURITY REGRESSION: Kerberos authentication on standalone server in
MIT realm broken
- debian/patches/bug14922.patch: fix MIT Realm regression in
source3/
-- Marc Deslauriers <email address hidden> Mon, 13 Dec 2021 07:09:36 -0500
samba (2:4.13.
* Update to 4.13.14 as a security update (LP: #1950363)
- debian/
version.
- debian/control: bump ldb Build-Depends to 2.2.3.
- debian/
- debian/
introduced in 4.13.14.
- debian/patches/bug14901-*.patch: upstream patches to fix some
mapping issues.
- debian/patches/bug14918-*.patch: upstream patches to properly handle
dangling symlinks.
- CVE-2016-2124, CVE-2020-25717, CVE-2020-25718, CVE-2020-25719,
CVE-
-- Marc Deslauriers <email address hidden> Tue, 09 Nov 2021 14:52:07 -0500
samba (2:4.13.
* No-change rebuild against liburing2
-- Paride Legovini <email address hidden> Mon, 22 Nov 2021 18:08:34 +0100
samba (2:4.13.
* d/samba.postinst: do not populate sambashare from the admin group
(Debian packaging cherry-pick. LP: #1942195)
-- Paride Legovini <email address hidden> Wed, 06 Oct 2021 10:31:14 +0200
samba (2:4.13.
* No-change rebuild due to OpenLDAP soname bump.
-- Sergio Durigan Junior <email address hidden> Mon, 21 Jun 2021 18:08:36 -0400
samba (2:4.13.
* Merge with Debian unstable. Remaining changes:
- d/p/VERSION.patch: Update vendor string to 'Ubuntu'.
- debian/smb.conf;
+ Add '(Samba, Ubuntu)' to server string.
+ Comment out the default [homes] share, and add a comment about
'valid users = %s' to show users how to restrict access to
- d/control: Disable glusterfs support because it's not in main.
MIR bug is https:/
- debian/control: Ubuntu i386 binary compatibility:
+ drop ceph support
- d/control: add a versioned libgnutls28-dev build-depends to reduce
the amount of in-tree crypto code that is built
- d/control: enable the liburing vfs module, except on i386 where
liburing is not available
- d/t/{cifs-
Skip running the tests if on i386 platform, because the uring
package is not available there.
* Dropped changes:
- debian/
+ Do not change priority to high if dhclient3 is installed.
[Included in 2:4.13.4+dfsg-1]
- d/p/fix-
change nfs service name from nfs to nfs-kernel-server
(LP #722201)
[Included in 2:4.13.4+dfsg-1]
- d/p/ctdb-
enable syslog and systemd journal by default
[Included in 2:4.13.4+dfsg-1]
- debian/rules: Ubuntu i386 binary compatibility:
+ drop ceph support
+ disable the following binary packages:
- ctdb
- libnss-winbind
- libpam-winbind
- python3-samba
- samba
- samba-common-bin
- samba-testsuite
- winbind
[Included in 2:4.13.4+dfsg-1]
- debian/rules: Ubuntu i386 binary compatibility:
+ re-enable the following binary packages:
- libnss-winbind
- samba-common-bin
- python3-samba
- winbind
[Included in 2:4.13.4+dfsg-1]
- SECURITY UPDATE: wrong group entries via negative idmap cache entries
+ debian/
+ CVE-2021-20254
[Included in 2:4.13.5+dfsg-2]
-- Athos Ribeiro <email address hidden> Mon, 17 May 2021 11:51:54 -0300
CVE References
Changed in samba (Ubuntu): | |
milestone: | none → ubuntu-22.07 |
Changed in samba (Ubuntu): | |
assignee: | nobody → Andreas Hasenack (ahasenack) |
milestone: | ubuntu-22.07 → ubuntu-22.06 |
milestone: | ubuntu-22.06 → ubuntu-22.05 |
Changed in samba (Ubuntu): | |
milestone: | ubuntu-22.05 → ubuntu-22.06 |
Changed in samba (Ubuntu): | |
status: | New → In Progress |
This bug was fixed in the package samba - 2:4.16. 1+dfsg- 8ubuntu1
--------------- 1+dfsg- 8ubuntu1) kinetic; urgency=medium
samba (2:4.16.
* Merge with Debian unstable (LP: #1971256, LP: #1846947). Remaining
\\server\ username to only username. share-access- uring,smbclient -share- access- uring}: nfs-service- name-to- nfs-kernel- server. patch: updated to use example/ nfs-kernel- server/ nfs.conf: /etc/nfs.conf to be example/ nfs-kernel- server/ ctdb.example. quota: quota example/ nfs-kernel- server/ nfs-{common, kernel- server} : example/ nfs-kernel- server/ enable- nfs.sh: handle new support- for-bind- 918.patch: build a dlz module for support- for-bind- 918-2.patch: also update the
provisioning tool and template config file libs.install: update list of installed libraries and plugins patches/ CVE-2021- 20254.patch: removed, applied upstream mdfind- to-mdsearch. patch: removed, applied usptream conf,watch, README. source} : update for 4.15
changes:
- d/p/VERSION.patch: Update vendor string to "Ubuntu".
- debian/smb.conf;
+ Add "(Samba, Ubuntu)" to server string.
+ Comment out the default [homes] share, and add a comment about
"valid users = %s" to show users how to restrict access to
- debian/control: Ubuntu i386 binary compatibility:
+ drop ceph support
- d/control: enable the liburing vfs module, except on i386 where
liburing is not available
- d/t/{cifs-
Skip running the tests if on i386 platform, because the uring
package is not available there.
- d/t/util: fix setting the password of the smb test user
(LP #1955851)
- Update nfs scripts for new nfs.conf config (LP #1961840):
+ d/p/fix-
nfsconf(8) if it's available, instead of parsing the old config
files in /etc/default/nfs-*
+ d/ctdb.
used by the example enable-nfs.sh example script
+ d/ctdb.
config file to be used by the example enable-nfs.sh script
+ d/ctdb.
obsolete, replaced by nfs.conf
+ d/ctdb.
nfs.conf and other changes in the new nfs server packages
- Build dlz module for bind 9.18.x (LP #1964032)
+ d/p/add-
bind 9.18.x
+ d/p/add-
- d/rules: in Ubuntu, glusterfs is not built for i386, so don't
enable the samba glusterfs vfs mofule in that case
- d/control: build-depend on libglusterfs-dev only on !i386 arches
* Dropped:
- d/control: add a versioned libgnutls28-dev build-depends to reduce
the amount of in-tree crypto code that is built
[superfluous, the version in the archive is recent enough]
- d/samba.postinst: do not populate sambashare from the Ubuntu admin group (LP 1942195)
[Included in 2:4.13.13+dfsg-1]
- d/control: bump required build-depends
[Included in Debian]
- d/samba-
modules/
[Done in Debian]
- debian/
[Applied upstream, Debian didn't have this patch]
- d/p/Rename-
[Applied usptream, Debian did not have it]
- d/{gpb.
[Debian updated it for 4.16]
- d/rules: remove --with-dnsupdate, it was merged with
--with-ads in samba 4.15.0
[Included in 2:4.16.0+dfsg-1]
- d/rules: drop removal of ctdb tests, they ...