FFE: Please update to 1.16.1 for bionic

Bug #1754746 reported by Jim Campbell
12
This bug affects 1 person
Affects Status Importance Assigned to Milestone
sssd (Ubuntu)
Fix Released
Low
Timo Aaltonen

Bug Description

SSSD 1.16.1 was tagged for release:

https://pagure.io/SSSD/sssd/releases
https://github.com/SSSD/sssd/releases/tag/sssd-1_16_1

. . . I'm hopeful that, although we're past the Debian sync freeze, that it will be possible to get this point release into Ubuntu before the final 18.04 initial release.

Thanks for your help.

### FFE Rationale:

Upstream release notes:
https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html
- 53 tickets fixed

Has been in Debian testing for over three weeks without any new bugs filed.

tags: added: upgrade-software-version
Revision history for this message
Simon Quigley (tsimonq2) wrote :

Directly subscribed Andreas Hasenack, he uploaded the last merge from Debian.

Revision history for this message
Andreas Hasenack (ahasenack) wrote :
Download full text (6.5 KiB)

I saw some memleak fixes in 1.16.1, but also new features and new behavior. This bug was filed past the ubuntu feature freeze, so it would need a feature freeze exception (https://wiki.ubuntu.com/FreezeExceptionProcess).

Here is the list of changes from upstream. I'm not sure we would be able to get a FFe for this:

New Features
^^^^^^^^^^^^
  * A new option ``auto_private_groups`` was added. If this option is
    enabled, SSSD will automatically create user private groups based on
    user's UID number. The GID number is ignored in this case. Please
    see https://docs.pagure.org/SSSD.sssd/design_pages/auto_private_groups.html
    for more details on the feature.

  * The SSSD smart card integration now supports a special type of PAM
    conversation implemented by GDM which allows the user to select the
    appropriate smrt card certificate in GDM. Please refer to
    https://docs.pagure.org/SSSD.sssd/design_pages/smartcard_multiple_certificates.html
    for more details about this feature.

  * A new API for accessing user and group information was added. This API
    is similar to the tradiional Name Service Switch API, but allows
    the consumer to talk to SSSD directly as well as to fine-tune
    the query with e.g. how cache should be evaluated. Please see
    https://docs.pagure.org/SSSD.sssd/design_pages/enhanced_nss_api.html
    for more information on the new API.

  * The ``sssctl`` command line tool gained a new command ``access-report``,
    which can generate who can access the client machine. Currently only generating
    the report on an IPA client based on HBAC rules is supported. Please see
    https://docs.pagure.org/SSSD.sssd/design_pages/attestation_report.html
    for more information about this new feature.

  * The ``hostid`` provider was moved from the IPA specific code to the generic
    LDAP code. This allows SSH host keys to be access by the generic LDAP provider
    as well. See the ``ldap_host_*`` options in the ``sssd-ldap`` manual page
    for more details.

  * Setting the ``memcache_timeout`` option to 0 disabled creating the
    memory cache files altogether. This can be useful in cases there is a
    bug in the memory cache that needs working around.

Performance enhancements
^^^^^^^^^^^^^^^^^^^^^^^^
  * Several internal changes to how objects are stored in the cache improve
    SSSD performance in environments with large number of objects of the same
    type (e.g. many users, many groups). In particular, several useless indexes
    were removed and the most common object types no longer use the indexed
    ``objectClass`` attribute, but use unindexed ``objectCategory`` instead
    (#3503)

  * In setups with ``id_provider=ad`` that use POSIX attributes which
    are replicated to the Global Catalog, SSSD uses the Global Catalog to
    determine which domain should be contacted for a by-ID lookup instead
    of iterating over all domains. More details about this feature can
    be found at
    https://docs.pagure.org/SSSD.sssd/design_pages/uid_negative_global_catalog.html

Notable bug fixes
^^^^^^^^^^^^^^^^^
 * A crash in ``sssd_nss`` that might have happened if a list of domains
   was refreshed whi...

Read more...

Changed in sssd (Ubuntu):
status: New → Triaged
importance: Undecided → Low
Revision history for this message
Timo Aaltonen (tjaalton) wrote :

just do it, sssd has a standing MRE too, btw

Revision history for this message
Andreas Hasenack (ahasenack) wrote :

Hm, https://wiki.ubuntu.com/StableReleaseUpdates#New_upstream_microreleases has some criteria, and I'm not sure the above changelog meets it. I also don't see an explicit exception for sssd in https://wiki.ubuntu.com/StableReleaseUpdates#Documentation_for_Special_Cases.

Do you have upload rights for this, Timo?

Revision history for this message
Timo Aaltonen (tjaalton) wrote :

I'm a core-dev, so yes

Revision history for this message
Timo Aaltonen (tjaalton) wrote :

I've uploaded 1.16.1-1u1 for bionic, the list of bugfixes makes it worth it

In general, the first point-release to sssd usually have some new features too, but the focus is still on bugfixes.

Changed in sssd (Ubuntu):
assignee: nobody → Timo Aaltonen (tjaalton)
Revision history for this message
Jim Campbell (jwcampbell) wrote :

Thank you Timo, Andreas and Simon. This is a big help to us.

Timo Aaltonen (tjaalton)
summary: - Please update to 1.16.1 for bionic
+ FFE: Please update to 1.16.1 for bionic
Timo Aaltonen (tjaalton)
description: updated
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package sssd - 1.16.1-1ubuntu1

---------------
sssd (1.16.1-1ubuntu1) bionic; urgency=medium

  * Merge from Debian. (LP: #1754746)
  * d/p/restart_providers_on_timeshift.patch: Dropped, upstream.

sssd (1.16.1-1) unstable; urgency=medium

  * New upstream release.
  * common.dirs, common.postinst: Add dir for secrets with correct
    permissions. (Closes: #892315)
  * common: Add support for Fleet Commander, create deskprofile dir with
    correct permissions.
  * control: Add libgdm-dev to build-depends to support multiple
    certificates.
  * control, rules, common.install: Add support for systemtap.
  * control: Bump policy to 4.1.3, no changes.

 -- Timo Aaltonen <email address hidden> Mon, 09 Apr 2018 13:45:29 +0300

Changed in sssd (Ubuntu):
status: Triaged → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.