Change log for samba package in Ubuntu

175 of 628 results
Published in noble-proposed
samba (2:4.19.5+dfsg-1ubuntu1) noble; urgency=medium

  * Merge with Debian unstable (LP: #2054592). Remaining changes:
    - debian/control: Ubuntu i386 binary compatibility:
      + enable the liburing vfs module, except on i386 where liburing is
        not available
    - d/t/control, d/t/util,d/t/samba-ad-dc-provisioning-internal-dns:
      samba AD DC provisioning and domain join tests with internal DNS
      (LP #1977746, LP #2011745)
    - d/control: adjust breaks/replaces for file move that Debian did in
      4.16.6+dfsg-5, and Ubuntu only did in 4.17.7+dfsg-1ubuntu1, to avoid
      file conflict in a dist-upgrade from earlier Ubuntu releases, like
      Kinetic (LP #2024663)
    - d/control: python3-samba has a runtime dep on python3-markdown
    - glusterfs is no longer in main, create new binary package in
      universe to ship the samba glusterfs vfs modules and manpages
      (LP #2045063):
      + d/control: new samba-vfs-modules-glusterfs package
      + d/rules: glusterfs vfs modules and manpages are now in the
        samba-vfs-modules-extra package
      + d/samba-vfs-modules-extra.install: add glusterfs vfs modules and
        manpage
    - d/t/util: handle breakage introduced by lxd-installer. If on
      Ubuntu, assume lxd comes from a snap and install it if needed
    - d/t/util: ignore cloud-init's warning exit status, which is
      happening because of LP #2048129 (also see LP #2048522)

 -- Andreas Hasenack <email address hidden>  Sun, 25 Feb 2024 14:45:54 -0300
Published in jammy-proposed
samba (2:4.15.13+dfsg-0ubuntu1.6) jammy; urgency=medium

  * d/p/lp2046994-spotlight-doesnt-work-with-latest-macos-ventura.patch: fix
    spotlight search function on macos ventura (LP: #2046994).

 -- Mitchell Dzurick <email address hidden>  Fri, 05 Jan 2024 14:23:01 -0700
Published in focal-proposed
samba (2:4.15.13+dfsg-0ubuntu0.20.04.8) focal; urgency=medium

  * d/p/lp2046994-spotlight-doesnt-work-with-latest-macos-ventura.patch: fix
    spotlight search function on macos ventura (LP: #2046994).

 -- Mitchell Dzurick <email address hidden>  Thu, 01 Feb 2024 11:24:27 -0700
Published in noble-release
Deleted in noble-proposed (Reason: Moved to noble)
samba (2:4.19.4+dfsg-3ubuntu1) noble; urgency=medium

  * Merge with Debian unstable (LP: #2051717). Remaining changes:
    - debian/control: Ubuntu i386 binary compatibility:
      + enable the liburing vfs module, except on i386 where liburing is
        not available
    - d/t/control, d/t/util,d/t/samba-ad-dc-provisioning-internal-dns:
      samba AD DC provisioning and domain join tests with internal DNS
      (LP #1977746, LP #2011745)
    - d/control: adjust breaks/replaces for file move that Debian did in
      4.16.6+dfsg-5, and Ubuntu only did in 4.17.7+dfsg-1ubuntu1, to avoid
      file conflict in a dist-upgrade from earlier Ubuntu releases, like
      Kinetic (LP #2024663)
    - d/control: python3-samba has a runtime dep on python3-markdown
    - glusterfs is no longer in main, create new binary package in
      universe to ship the samba glusterfs vfs modules and manpages
      (LP #2045063):
      + d/control: new samba-vfs-modules-glusterfs package
      + d/rules: glusterfs vfs modules and manpages are now in the
        samba-vfs-modules-extra package
      + d/samba-vfs-modules-extra.install: add glusterfs vfs modules and
        manpage
  * Added:
    - d/t/util: handle breakage introduced by lxd-installer. If on
      Ubuntu, assume lxd comes from a snap and install it if needed
    - d/t/util: ignore cloud-init's warning exit status, which is
      happening because of LP #2048129 (also see LP #2048522)

 -- Andreas Hasenack <email address hidden>  Sat, 03 Feb 2024 10:14:42 -0300
Superseded in noble-proposed
samba (2:4.19.4+dfsg-2ubuntu2) noble; urgency=medium

  * No-change rebuild with Python 3.12 as default

 -- Graham Inggs <email address hidden>  Sat, 20 Jan 2024 19:20:19 +0000
Superseded in noble-proposed
samba (2:4.19.4+dfsg-2ubuntu1) noble; urgency=medium

  * Merge with Debian unstable (LP: #2040363). Remaining changes:
    - debian/control: Ubuntu i386 binary compatibility:
      + enable the liburing vfs module, except on i386 where liburing is
        not available
    - d/t/control, d/t/util,d/t/samba-ad-dc-provisioning-internal-dns:
      samba AD DC provisioning and domain join tests with internal DNS
      (LP #1977746, LP #2011745)
    - d/control: adjust breaks/replaces for file move that Debian did in
      4.16.6+dfsg-5, and Ubuntu only did in 4.17.7+dfsg-1ubuntu1, to avoid
      file conflict in a dist-upgrade from earlier Ubuntu releases, like
      Kinetic (LP #2024663)
  * Dropped:
    - d/rules: ceph is not available in Ubuntu i386, disable it
      [In 2:4.19.1+dfsg-1]
    - debian/control: Ubuntu i386 binary compatibility:
      + drop ceph support
      [In 2:4.19.1+dfsg-1]
  * Added:
    - d/control: python3-samba has a runtime dep on python3-markdown
    - glusterfs is no longer in main, create new binary package in
      universe to ship the samba glusterfs vfs modules and manpages
      (LP: #2045063):
      + d/control: new samba-vfs-modules-glusterfs package
      + d/rules: glusterfs vfs modules and manpages are now in the
        samba-vfs-modules-extra package
      + d/samba-vfs-modules-extra.install: add glusterfs vfs modules and
        manpage

 -- Andreas Hasenack <email address hidden>  Mon, 15 Jan 2024 12:21:28 -0300
Superseded in noble-release
Deleted in noble-proposed (Reason: Moved to noble)
samba (2:4.18.6+dfsg-1ubuntu2.2) noble; urgency=medium

  * No-change rebuild for ICU soname change.

 -- Matthias Klose <email address hidden>  Tue, 19 Dec 2023 18:41:25 +0100
Published in focal-updates
Published in focal-security
samba (2:4.15.13+dfsg-0ubuntu0.20.04.7) focal-security; urgency=medium

  * No-change rebuild to fix build issue resulting in regressions.
    (LP: #2039031)

 -- Marc Deslauriers <email address hidden>  Wed, 11 Oct 2023 13:30:13 -0400
Superseded in noble-release
Deleted in noble-proposed (Reason: Moved to noble)
Superseded in noble-proposed
Published in mantic-updates
Published in mantic-security
samba (2:4.18.6+dfsg-1ubuntu2.1) mantic-security; urgency=medium

  * SECURITY UPDATE: SMB clients can truncate files with read-only
    permissions
    - debian/patches/CVE-2023-4091-*.patch
    - CVE-2023-4091
  * SECURITY UPDATE: Samba AD DC password exposure to privileged users and
    RODCs
    - debian/patches/CVE-2023-4154-*.patch
    - CVE-2023-4154
  * SECURITY UPDATE: rpcecho development server allows Denial of Service
    via sleep() call on AD DC
    - debian/patches/CVE-2023-42669-*.patch
    - CVE-2023-42669
  * SECURITY UPDATE: Samba AD DC Busy RPC multiple listener DoS
    - debian/patches/CVE-2023-42670-*.patch
    - CVE-2023-42670

 -- Marc Deslauriers <email address hidden>  Tue, 10 Oct 2023 12:25:20 -0400
Superseded in focal-updates
Superseded in focal-security
samba (2:4.15.13+dfsg-0ubuntu0.20.04.6) focal-security; urgency=medium

  * SECURITY UPDATE: SMB clients can truncate files with read-only
    permissions
    - debian/patches/CVE-2023-4091-*.patch
    - CVE-2023-4091
  * SECURITY UPDATE: Samba AD DC password exposure to privileged users and
    RODCs
    - debian/patches/CVE-2023-4154-*.patch
    - CVE-2023-4154
  * SECURITY UPDATE: rpcecho development server allows Denial of Service
    via sleep() call on AD DC
    - debian/patches/CVE-2023-42669.patch
    - CVE-2023-42669

 -- Marc Deslauriers <email address hidden>  Wed, 04 Oct 2023 09:02:06 -0400
Published in jammy-updates
Published in jammy-security
samba (2:4.15.13+dfsg-0ubuntu1.5) jammy-security; urgency=medium

  * SECURITY UPDATE: SMB clients can truncate files with read-only
    permissions
    - debian/patches/CVE-2023-4091-*.patch
    - CVE-2023-4091
  * SECURITY UPDATE: Samba AD DC password exposure to privileged users and
    RODCs
    - debian/patches/CVE-2023-4154-*.patch
    - CVE-2023-4154
  * SECURITY UPDATE: rpcecho development server allows Denial of Service
    via sleep() call on AD DC
    - debian/patches/CVE-2023-42669.patch
    - CVE-2023-42669

 -- Marc Deslauriers <email address hidden>  Wed, 04 Oct 2023 08:38:27 -0400
Published in lunar-updates
Published in lunar-security
samba (2:4.17.7+dfsg-1ubuntu2.3) lunar-security; urgency=medium

  * SECURITY UPDATE: SMB clients can truncate files with read-only
    permissions
    - debian/patches/CVE-2023-4091-*.patch
    - CVE-2023-4091
  * SECURITY UPDATE: Samba AD DC password exposure to privileged users and
    RODCs
    - debian/patches/CVE-2023-4154-*.patch
    - CVE-2023-4154
  * SECURITY UPDATE: rpcecho development server allows Denial of Service
    via sleep() call on AD DC
    - debian/patches/CVE-2023-42669-*.patch
    - CVE-2023-42669
  * SECURITY UPDATE: Samba AD DC Busy RPC multiple listener DoS
    - debian/patches/CVE-2023-42670-*.patch
    - CVE-2023-42670

 -- Marc Deslauriers <email address hidden>  Wed, 04 Oct 2023 08:18:32 -0400
Superseded in noble-release
Published in mantic-release
Deleted in mantic-proposed (Reason: Moved to mantic)
samba (2:4.18.6+dfsg-1ubuntu2) mantic; urgency=medium

  * No-change rebuild with glusterfs 10.3 (LP: #2035127)

 -- Andreas Hasenack <email address hidden>  Wed, 13 Sep 2023 09:57:01 -0300
Superseded in lunar-updates
Deleted in lunar-proposed (Reason: moved to -updates)
samba (2:4.17.7+dfsg-1ubuntu2.2) lunar; urgency=medium

  * d/p/issue-when-updating-old-passwd-containing-regex-metachars.patch:
    Add changes to fix uncaught exception when updating old password
    containing regex metacharacters by simplifying samba-tool password
    redaction (LP: #2002949).

Superseded in jammy-updates
Deleted in jammy-proposed (Reason: moved to -updates)
samba (2:4.15.13+dfsg-0ubuntu1.4) jammy; urgency=medium

  * d/p/issue-when-updating-old-passwd-containing-regex-metachars.patch:
    Add changes to fix uncaught exception when updating old password
    containing regex metacharacters by simplifying samba-tool password
    redaction (LP: #2002949).

 -- Michal Maloszewski <email address hidden>  Fri, 18 Aug 2023 15:53:14 +0200
Superseded in focal-updates
Deleted in focal-proposed (Reason: moved to -updates)
samba (2:4.15.13+dfsg-0ubuntu0.20.04.5) focal; urgency=medium

  * d/p/issue-when-updating-old-passwd-containing-regex-metachars.patch:
    Add changes to fix uncaught exception when updating old password
    containing regex metacharacters by simplifying samba-tool password
    redaction (LP: #2002949).

 -- Michal Maloszewski <email address hidden>  Fri, 18 Aug 2023 22:56:58 +0200
Superseded in lunar-proposed
samba (2:4.17.7+dfsg-1ubuntu2.1) lunar; urgency=medium

  * d/control: adjust breaks/replaces for file move that Debian did in
    4.16.6+dfsg-5, and Ubuntu only did in 4.17.7+dfsg-1ubuntu1, to avoid
    file conflict in a dist-upgrade from earlier Ubuntu releases, like
    Kinetic (LP: #2024663)

 -- Andreas Hasenack <email address hidden>  Tue, 01 Aug 2023 18:30:42 -0300
Superseded in mantic-release
Deleted in mantic-proposed (Reason: Moved to mantic)
samba (2:4.18.6+dfsg-1ubuntu1) mantic; urgency=medium

  * Merge with Debian unstable (LP: #2031655, LP: #2031619). Remaining changes:
    - debian/control: Ubuntu i386 binary compatibility:
      + drop ceph support
      + enable the liburing vfs module, except on i386 where liburing is
        not available
    - d/t/control, d/t/util,d/t/samba-ad-dc-provisioning-internal-dns:
      samba AD DC provisioning and domain join tests with internal DNS
      (LP #1977746, LP #2011745)
  * Dropped:
    - build-depend on libglusterfs-dev only on !i386 arches
      [In 2:4.18.5+dfsg-2]
    - Add changes to fix uncaught exception when updating old password
      containing regex metacharacters by simplifying samba-tool password
      redaction (LP #2002949).
      + d/p/lib-cmdline-Return-if-the-commandline-was-redacted-i.patch
      + d/p/lib-cmdline-Also-redact-newpassword-in-samba_cmdline.patch
      + d/p/lib-cmdline-Also-burn-the-password2-parameter-if-giv.patch
      + d/p/samba-tool-Use-samba.glue.get_burnt_cmdline-rather-t.patch
      + d/p/python-Add-glue.burn_commandline-method.patch
      + d/p/python-Move-PyList_AsStringList-to-common-code-so-we.patch
      + d/p/python-Remove-const-from-PyList_AsStringList.patch
        [Fixed upstream in 4.18.6]
  * Added:
    - d/control: adjust breaks/replaces for file move that Debian did in
      4.16.6+dfsg-5, and Ubuntu only did in 4.17.7+dfsg-1ubuntu1, to avoid
      file conflict in a dist-upgrade from earlier Ubuntu releases, like
      Kinetic (LP: #2024663)
    - d/rules: ceph is not available in Ubuntu i386, disable it

 -- Andreas Hasenack <email address hidden>  Thu, 17 Aug 2023 09:52:00 -0300
Superseded in mantic-release
Deleted in mantic-proposed (Reason: Moved to mantic)
samba (2:4.18.5+dfsg-1ubuntu2) mantic; urgency=medium

  * Add changes to fix uncaught exception when updating old password
    containing regex metacharacters by simplifying samba-tool password
    redaction (LP: #2002949).
    - d/p/lib-cmdline-Return-if-the-commandline-was-redacted-i.patch
    - d/p/lib-cmdline-Also-redact-newpassword-in-samba_cmdline.patch
    - d/p/lib-cmdline-Also-burn-the-password2-parameter-if-giv.patch
    - d/p/samba-tool-Use-samba.glue.get_burnt_cmdline-rather-t.patch
    - d/p/python-Add-glue.burn_commandline-method.patch
    - d/p/python-Move-PyList_AsStringList-to-common-code-so-we.patch
    - d/p/python-Remove-const-from-PyList_AsStringList.patch

 -- Michal Maloszewski <email address hidden>  Fri, 28 Jul 2023 00:55:03 +0200
Superseded in focal-updates
Deleted in focal-proposed (Reason: moved to -updates)
samba (2:4.15.13+dfsg-0ubuntu0.20.04.4) focal; urgency=medium

  * d/p/secure-channel-faulty-kb5028166.patch: fix domain membership
    after Windows KB5028166 update (LP: #2027716)
  * Cherry pick samba AD DC provisioning DEP8 test from later Ubuntu
    releases (LP: #1977746, LP: #2011745):
    - d/t/control, d/t/util,d/t/samba-ad-dc-provisioning-internal-dns:
      samba AD DC provisioning and domain join tests with internal DNS
      + d/t/control: adjust package dependencies
      + d/t/samba-ad-dc-provisioning-internal-dns: handle the case where
        libnss-winbind does not automatically add winbind to
        /etc/nsswitch.conf (that is done only in Lunar and later)
      + d/t/samba-ad-dc-provisioning-internal-dns: use case insensitive
        match when inspecting kerberos tickets, as the hostname may be
        capitalized
      + d/t/samba-ad-dc-provisioning-internal-dns: Adjust regexp for
        slightly different resolvectl output
      + d/t/util: several lxc command output parsing changes, needed for
        this older version of the lxd snap
      + d/t/samba-ad-dc-provisioning-internal-dns: more dependencies for
        the winbind and sssd domain join tests, which don't get
        installed automatically for us by this version of realmd
      + d/t/util: increase the RLIMIT_MEMLOCK limit for lxd containers,
        as the default of 64kb is too low for at least ppc64el on focal

 -- Andreas Hasenack <email address hidden>  Sun, 23 Jul 2023 17:19:48 -0300
Superseded in jammy-updates
Deleted in jammy-proposed (Reason: moved to -updates)
samba (2:4.15.13+dfsg-0ubuntu1.3) jammy; urgency=medium

  * d/p/secure-channel-faulty-kb5028166.patch: fix domain membership
    after Windows KB5028166 update (LP: #2027716)
  * Cherry pick samba AD DC provisioning DEP8 test from later Ubuntu
    releases (LP: #1977746, LP: #2011745):
    - d/t/control, d/t/util, d/t/samba-ad-dc-provisioning-internal-dns:
      samba AD DC provisioning and domain join tests with internal DNS
      + d/t/control: adjust package dependencies
      + d/t/samba-ad-dc-provisioning-internal-dns: handle the case where
        libnss-winbind does not automatically add winbind to
        /etc/nsswitch.conf (that is done only in Lunar and later)
      + d/t/samba-ad-dc-provisioning-internal-dns: use case insensitive
        match when inspecting kerberos tickets, as the hostname may be
        capitalized

 -- Andreas Hasenack <email address hidden>  Sun, 23 Jul 2023 17:09:59 -0300
Superseded in lunar-updates
Deleted in lunar-proposed (Reason: moved to -updates)
samba (2:4.17.7+dfsg-1ubuntu2) lunar; urgency=medium

  * d/p/secure-channel-faulty-kb5028166.patch: fix domain membership
    after Windows KB5028166 update (LP: #2027716)

 -- Andreas Hasenack <email address hidden>  Thu, 20 Jul 2023 10:26:31 -0300
Superseded in mantic-release
Deleted in mantic-proposed (Reason: Moved to mantic)
samba (2:4.18.5+dfsg-1ubuntu1) mantic; urgency=medium

  * Merge with Debian unstable (LP: #2028265, LP: #2027716). Remaining
    changes:
    - debian/control: Ubuntu i386 binary compatibility:
      + drop ceph support
      + enable the liburing vfs module, except on i386 where liburing is
        not available
      + build-depend on libglusterfs-dev only on !i386 arches
    - d/t/control, d/t/util,d/t/samba-ad-dc-provisioning-internal-dns:
      samba AD DC provisioning and domain join tests with internal DNS
      (LP #1977746, LP #2011745)
    - d/t/util: reload instead of restarting samba, as it's quicker and
      has the same effect we want in this test

 -- Andreas Hasenack <email address hidden>  Thu, 20 Jul 2023 10:15:22 -0300
Superseded in jammy-updates
Superseded in jammy-security
samba (2:4.15.13+dfsg-0ubuntu1.2) jammy-security; urgency=medium

  * SECURITY UPDATE: Out-Of-Bounds read in winbind AUTH_CRAP
    - debian/patches/CVE-2022-2127-*.patch
    - CVE-2022-2127
  * SECURITY UPDATE: Spotlight mdssvc RPC Request Infinite Loop DoS
    - debian/patches/CVE-2023-34966-*.patch
    - CVE-2023-34966
  * SECURITY UPDATE: Spotlight mdssvc RPC Request Type Confusion DoS
    - debian/patches/CVE-2023-34967-*.patch
    - CVE-2023-34967
  * SECURITY UPDATE: Spotlight server-side Share Path Disclosure
    - debian/patches/CVE-2023-34968-*.patch
    - CVE-2023-34968

 -- Marc Deslauriers <email address hidden>  Tue, 11 Jul 2023 08:44:35 -0400
Superseded in focal-updates
Superseded in focal-security
samba (2:4.15.13+dfsg-0ubuntu0.20.04.3) focal-security; urgency=medium

  * SECURITY UPDATE: Out-Of-Bounds read in winbind AUTH_CRAP
    - debian/patches/CVE-2022-2127-*.patch
    - CVE-2022-2127
  * SECURITY UPDATE: Spotlight mdssvc RPC Request Infinite Loop DoS
    - debian/patches/CVE-2023-34966-*.patch
    - CVE-2023-34966
  * SECURITY UPDATE: Spotlight mdssvc RPC Request Type Confusion DoS
    - debian/patches/CVE-2023-34967-*.patch
    - CVE-2023-34967
  * SECURITY UPDATE: Spotlight server-side Share Path Disclosure
    - debian/patches/CVE-2023-34968-*.patch
    - CVE-2023-34968

 -- Marc Deslauriers <email address hidden>  Tue, 11 Jul 2023 08:45:47 -0400
Obsolete in kinetic-updates
Obsolete in kinetic-security
samba (2:4.16.8+dfsg-0ubuntu1.2) kinetic-security; urgency=medium

  * SECURITY UPDATE: Out-Of-Bounds read in winbind AUTH_CRAP
    - debian/patches/CVE-2022-2127-*.patch
    - CVE-2022-2127
  * SECURITY UPDATE: Spotlight mdssvc RPC Request Infinite Loop DoS
    - debian/patches/CVE-2023-34966-*.patch
    - CVE-2023-34966
  * SECURITY UPDATE: Spotlight mdssvc RPC Request Type Confusion DoS
    - debian/patches/CVE-2023-34967-*.patch
    - CVE-2023-34967
  * SECURITY UPDATE: Spotlight server-side Share Path Disclosure
    - debian/patches/CVE-2023-34968-*.patch
    - CVE-2023-34968

 -- Marc Deslauriers <email address hidden>  Tue, 11 Jul 2023 08:00:26 -0400
Superseded in lunar-updates
Superseded in lunar-security
samba (2:4.17.7+dfsg-1ubuntu1.1) lunar-security; urgency=medium

  * SECURITY UPDATE: Out-Of-Bounds read in winbind AUTH_CRAP
    - debian/patches/CVE-2022-2127-*.patch
    - CVE-2022-2127
  * SECURITY UPDATE: SMB2 packet signing not enforced
    - debian/patches/CVE-2023-3347-*.patch
    - CVE-2023-3347
  * SECURITY UPDATE: Spotlight mdssvc RPC Request Infinite Loop DoS
    - debian/patches/CVE-2023-34966-*.patch
    - CVE-2023-34966
  * SECURITY UPDATE: Spotlight mdssvc RPC Request Type Confusion DoS
    - debian/patches/CVE-2023-34967-*.patch
    - CVE-2023-34967
  * SECURITY UPDATE: Spotlight server-side Share Path Disclosure
    - debian/patches/CVE-2023-34968-*.patch
    - CVE-2023-34968

 -- Marc Deslauriers <email address hidden>  Tue, 11 Jul 2023 07:54:30 -0400
Superseded in mantic-release
Deleted in mantic-proposed (Reason: Moved to mantic)
samba (2:4.18.3+dfsg-3ubuntu1) mantic; urgency=medium

  * Merge with Debian unstable (LP: #2018054). Remaining changes:
    - debian/control: Ubuntu i386 binary compatibility:
      + drop ceph support
      + enable the liburing vfs module, except on i386 where liburing is
        not available
      + build-depend on libglusterfs-dev only on !i386 arches
    - d/t/control, d/t/util,d/t/samba-ad-dc-provisioning-internal-dns:
      samba AD DC provisioning and domain join tests with internal DNS
      (LP #1977746, LP #2011745)
  * Added changes:
    - d/t/util: reload instead of restarting samba, as it's quicker and
      has the same effect we want in this test

 -- Andreas Hasenack <email address hidden>  Thu, 22 Jun 2023 11:59:19 -0300
Superseded in mantic-release
Published in lunar-release
Deleted in lunar-proposed (Reason: Moved to lunar)
samba (2:4.17.7+dfsg-1ubuntu1) lunar; urgency=medium

  * Merge with Debian unstable (LP: #2014052). Remaining changes:
    - debian/control: Ubuntu i386 binary compatibility:
      + drop ceph support
      + enable the liburing vfs module, except on i386 where liburing is
        not available
      + build-depend on libglusterfs-dev only on !i386 arches
    - d/t/control, d/t/util,d/t/samba-ad-dc-provisioning-internal-dns:
      samba AD DC provisioning and domain join tests with internal DNS
      (LP #1977746, LP #2011745)

 -- Andreas Hasenack <email address hidden>  Fri, 31 Mar 2023 15:26:11 -0300
Superseded in focal-updates
Superseded in focal-security
samba (2:4.15.13+dfsg-0ubuntu0.20.04.2) focal-security; urgency=medium

  * SECURITY UPDATE: Access controlled AD LDAP attributes can be discovered
    - debian/patches/CVE-2023-0614-*.patch: upstream patches to fix the
      issue (some of these aren't directly used in this package as they
      apply to the ldb library which is updated separately).
    - debian/control: bump ldb Build-Depends to security update version.
    - CVE-2023-0614
  * SECURITY UPDATE: admin tool samba-tool sends passwords in cleartext
    - debian/patches/CVE-2023-0922.patch: set default ldap client sasl
      wrapping to seal.
    - CVE-2023-0922

 -- Marc Deslauriers <email address hidden>  Thu, 30 Mar 2023 09:25:19 -0400
Superseded in jammy-updates
Superseded in jammy-security
samba (2:4.15.13+dfsg-0ubuntu1.1) jammy-security; urgency=medium

  * SECURITY UPDATE: Access controlled AD LDAP attributes can be discovered
    - debian/patches/CVE-2023-0614-*.patch: upstream patches to fix the
      issue (some of these aren't directly used in this package as they
      apply to the ldb library which is updated separately).
    - debian/control: bump ldb Build-Depends to security update version.
    - CVE-2023-0614
  * SECURITY UPDATE: admin tool samba-tool sends passwords in cleartext
    - debian/patches/CVE-2023-0922.patch: set default ldap client sasl
      wrapping to seal.
    - CVE-2023-0922

 -- Marc Deslauriers <email address hidden>  Thu, 30 Mar 2023 09:25:19 -0400
Superseded in kinetic-updates
Superseded in kinetic-security
samba (2:4.16.8+dfsg-0ubuntu1.1) kinetic-security; urgency=medium

  * SECURITY UPDATE: Access controlled AD LDAP attributes can be discovered
    - debian/patches/CVE-2023-0614-*.patch: upstream patches to fix the
      issue.
    - debian/libldb2.symbols: added new symbols.
    - debian/python3-ldb.symbols.in: added new symbols.
    - CVE-2023-0614
  * SECURITY UPDATE: admin tool samba-tool sends passwords in cleartext
    - debian/patches/CVE-2023-0922.patch: set default ldap client sasl
      wrapping to seal.
    - CVE-2023-0922

 -- Marc Deslauriers <email address hidden>  Thu, 30 Mar 2023 07:55:26 -0400
Superseded in lunar-release
Deleted in lunar-proposed (Reason: Moved to lunar)
samba (2:4.17.5+dfsg-2ubuntu3) lunar; urgency=medium

  * Add domain join tests (LP: #2011745):
    - d/t/control: update dependencies for samba AD provisioning test,
      which now also includes a member server join test
    - d/t/util, d/t/samba-ad-dc-*: add member server join tests

 -- Andreas Hasenack <email address hidden>  Wed, 15 Mar 2023 20:49:56 -0300
Superseded in lunar-release
Deleted in lunar-proposed (Reason: Moved to lunar)
samba (2:4.17.5+dfsg-2ubuntu2) lunar; urgency=medium

  * d/t/samba-ad-dc-provisioning-internal-dns: test improvements
    (LP: #2009485):
    - increase kinit timeout, as it also does DNS lookups
    - add a trap on exit to show logs in the case of some failure

 -- Andreas Hasenack <email address hidden>  Mon, 06 Mar 2023 11:49:34 -0300
Superseded in focal-updates
Superseded in focal-security
samba (2:4.15.13+dfsg-0ubuntu0.20.04.1) focal-security; urgency=medium

  * Update to 4.15.13 as a security update
    - Removed patches included in new version:
      + CVE-*.patch
      + win-22H2-fix*.patch
      + Rename-mdfind-to-mdsearch.patch
      + lp-1951490-fix-printing-KB5006743.patch
    - d/rules: remove --with-dnsupdate, it was merged with --with-ads.
    - debian/control: bump libldb-dev Build-Depends to 2.4.4, bump
      libtalloc to 2.3.3, libtdb to 1.4.4, and libtevent to 0.11.0.
    - debian/control: added python3-markdown to Build-Depends.
    - debian/{gpb.conf,watch,README.source}: updated for 4.15.
    - debian/{*.install,*.symbols,*.lintian-overrides}: updated for 4.15.
    - debian/rules: drop fixing of findsmb shebang.
    - debian/rules: drop removal of ctdb tests, they are no longer
      installed.
    - CVE-2022-3437, CVE-2022-37966, CVE-2022-37967, CVE-2022-38023,
      CVE-2022-42898, CVE-2022-45141

 -- Marc Deslauriers <email address hidden>  Fri, 24 Feb 2023 07:31:43 -0500
Superseded in lunar-release
Deleted in lunar-proposed (Reason: Moved to lunar)
samba (2:4.17.5+dfsg-2ubuntu1) lunar; urgency=medium

  * Merge with Debian unstable (LP: #2002181). Remaining changes:
    - debian/control: Ubuntu i386 binary compatibility:
      + drop ceph support
      + enable the liburing vfs module, except on i386 where liburing is
        not available
      + build-depend on libglusterfs-dev only on !i386 arches
  * Added:
    - d/t/control, d/t/samba-ad-dc-provisioning-internal-dns: samba AD
      DC provisioning test with internal DNS (LP: #1977746)

 -- Andreas Hasenack <email address hidden>  Sun, 05 Feb 2023 13:47:57 -0300
Superseded in lunar-proposed
samba (2:4.17.3+dfsg-3ubuntu3) lunar; urgency=medium

  * Rebuild against latest icu

 -- Jeremy Bicha <email address hidden>  Mon, 06 Feb 2023 07:57:36 -0500
Superseded in focal-updates
Superseded in focal-security
samba (2:4.13.17~dfsg-0ubuntu1.20.04.5) focal-security; urgency=medium

  * SECURITY UPDATE: Multiple regressions (LP: #2003867) (LP: #2003891)
    - debian/patches/series: disable all security fixes from the previous
      update pending further investigation. This reverts the following
      CVEs: CVE-2022-3437, CVE-2022-42898, CVE-2022-45141, CVE-2022-38023,
      CVE-2022-37966, CVE-2022-37967.

 -- Marc Deslauriers <email address hidden>  Thu, 26 Jan 2023 09:03:40 -0500
Superseded in focal-updates
Superseded in focal-security
samba (2:4.13.17~dfsg-0ubuntu1.20.04.4) focal-security; urgency=medium

  * SECURITY UPDATE: Buffer overflow in Heimdal unwrap_des3()
    - debian/patches/CVE-2022-3437-*.patch
    - CVE-2022-3437
  * SECURITY UPDATE: Buffer overflow vulnerabilities on 32-bit systems
    - debian/patches/CVE-2022-42898-*.patch
    - CVE-2022-42898
  * SECURITY UPDATE: Samba AD DC can be forced to issue rc4-hmac encrypted
    Kerberos tickets
    - debian/patches/CVE-2022-45141-*.patch
    - CVE-2022-45141
  * SECURITY UPDATE: RC4/HMAC-MD5 NetLogon Secure Channel is weak and
    should be avoided
    - debian/patches/CVE-2022-38023-*.patch
    - CVE-2022-38023
  * SECURITY UPDATE: rc4-hmac Kerberos session keys issued to modern servers
    - debian/patches/CVE-2022-3796x-*.patch
    - CVE-2022-37966
  * SECURITY UPDATE: Kerberos constrained delegation ticket forgery
    possible against Samba AD DC
    - debian/patches/CVE-2022-3796x-*.patch
    - CVE-2022-37967
  * debian/patches/win-22H2-fix.patch: split git-style patch into three
    individual patches so that it can be manipulated properly with quilt.
  * debian/patches/CVE-2022-44640-*.patch: Heimdal issue that did not
    affect Samba, but patches included for completeness.

 -- Marc Deslauriers <email address hidden>  Wed, 11 Jan 2023 11:12:16 -0500
Superseded in jammy-updates
Superseded in jammy-security
samba (2:4.15.13+dfsg-0ubuntu1) jammy-security; urgency=medium

  * Updated to upstream 4.15.13 to fix multiple security issues.
    - debian/patches/win-22H2-fix.patch: removed, included in new version.
    - CVE-2022-3437
    - CVE-2022-37966
    - CVE-2022-37967
    - CVE-2022-38023
    - CVE-2022-42898
    - CVE-2022-45141

 -- Marc Deslauriers <email address hidden>  Tue, 10 Jan 2023 10:04:53 -0500
Superseded in kinetic-updates
Superseded in kinetic-security
samba (2:4.16.8+dfsg-0ubuntu1) kinetic-security; urgency=medium

  * Updated to upstream 4.16.8 to fix multiple security issues.
    - debian/patches/fix-samba-tool-domain-join-segfault.patch: removed,
      included in new version.
    - CVE-2021-20251
    - CVE-2022-3437
    - CVE-2022-37966
    - CVE-2022-37967
    - CVE-2022-38023
    - CVE-2022-42898

 -- Marc Deslauriers <email address hidden>  Tue, 10 Jan 2023 09:07:59 -0500
Superseded in lunar-release
Deleted in lunar-proposed (Reason: Moved to lunar)
samba (2:4.17.3+dfsg-3ubuntu2) lunar; urgency=medium

  * No-change rebuild with Python 3.11 as default

 -- Graham Inggs <email address hidden>  Mon, 26 Dec 2022 18:01:11 +0000
Superseded in lunar-release
Deleted in lunar-proposed (Reason: Moved to lunar)
samba (2:4.17.3+dfsg-3ubuntu1) lunar; urgency=medium

  * Merge with Debian unstable (LP: #1993380). Remaining changes:
    - debian/control: Ubuntu i386 binary compatibility:
      + drop ceph support
    - d/control: enable the liburing vfs module, except on i386 where
      liburing is not available
    - d/control: build-depend on libglusterfs-dev only on !i386 arches
  * Dropped:
    - debian/smb.conf;
      + Add "(Samba, Ubuntu)" to server string.
        [In 2:4.16.6+dfsg-1]
      + Comment out the default [homes] share, and add a comment about
        "valid users = %s" to show users how to restrict access to
        \\server\username to only username.
        [In 2:4.16.6+dfsg-1]
    - d/t/{cifs-share-access-uring,smbclient-share-access-uring}:
      Skip running the tests if on i386 platform, because the uring
      package is not available there.
      [In 2:4.16.6+dfsg-1, improved]
    - d/t/util: fix setting the password of the smb test user
      (LP #1955851)
      [In 2:4.16.5+dfsg-2]
    - d/p/VERSION.patch: Update vendor string to "Ubuntu".
      [Implemented dynamically in d/rules in 2:4.16.6+dfsg-6]
    - d/rules: in Ubuntu, glusterfs is not built for i386, so don't
      enable the samba glusterfs vfs mofule in that case
      [In 2:4.16.6+dfsg-1]

 -- Andreas Hasenack <email address hidden>  Tue, 13 Dec 2022 18:36:23 -0300
Superseded in lunar-proposed
samba (2:4.16.4+dfsg-2ubuntu2) lunar; urgency=medium

  * No-change rebuild against libldap-2

 -- Steve Langasek <email address hidden>  Thu, 15 Dec 2022 19:55:02 +0000
Published in bionic-updates
Deleted in bionic-proposed (Reason: moved to -updates)
samba (2:4.7.6+dfsg~ubuntu-0ubuntu2.29) bionic; urgency=medium

  * d/p/win-22H2-fix.patch: fix interoperability with Windows 22H2
    clients (LP: #1993934)

 -- Andreas Hasenack <email address hidden>  Wed, 09 Nov 2022 11:42:14 -0300
Superseded in focal-updates
Deleted in focal-proposed (Reason: moved to -updates)
samba (2:4.13.17~dfsg-0ubuntu1.20.04.2) focal; urgency=medium

  * d/p/win-22H2-fix.patch: fix interoperability with Windows 22H2
    clients (LP: #1993934)

 -- Andreas Hasenack <email address hidden>  Tue, 08 Nov 2022 11:35:28 -0300
Superseded in jammy-updates
Deleted in jammy-proposed (Reason: moved to -updates)
samba (2:4.15.9+dfsg-0ubuntu0.3) jammy; urgency=medium

  * d/p/win-22H2-fix.patch: fix interoperability with Windows 22H2
    clients (LP: #1993934)

 -- Andreas Hasenack <email address hidden>  Tue, 08 Nov 2022 10:59:27 -0300
Superseded in lunar-release
Obsolete in kinetic-release
Deleted in kinetic-proposed (Reason: Moved to kinetic)
samba (2:4.16.4+dfsg-2ubuntu1) kinetic; urgency=medium

  * Merge with Debian unstable. Remaining changes:
    - d/p/VERSION.patch: Update vendor string to "Ubuntu".
    - debian/smb.conf;
      + Add "(Samba, Ubuntu)" to server string.
      + Comment out the default [homes] share, and add a comment about
        "valid users = %s" to show users how to restrict access to
        \\server\username to only username.
    - debian/control: Ubuntu i386 binary compatibility:
      + drop ceph support
    - d/control: enable the liburing vfs module, except on i386 where
      liburing is not available
    - d/t/{cifs-share-access-uring,smbclient-share-access-uring}:
      Skip running the tests if on i386 platform, because the uring
      package is not available there.
    - d/t/util: fix setting the password of the smb test user
      (LP #1955851)
    - d/rules: in Ubuntu, glusterfs is not built for i386, so don't
      enable the samba glusterfs vfs mofule in that case
    - d/control: build-depend on libglusterfs-dev only on !i386 arches

 -- Andreas Hasenack <email address hidden>  Tue, 02 Aug 2022 09:30:05 -0300
Superseded in kinetic-release
Deleted in kinetic-proposed (Reason: Moved to kinetic)
samba (2:4.16.3+dfsg-1ubuntu1) kinetic; urgency=medium

  * Merge with Debian unstable (LP: #1982116). Remaining changes:
    - d/p/VERSION.patch: Update vendor string to "Ubuntu".
    - debian/smb.conf;
      + Add "(Samba, Ubuntu)" to server string.
      + Comment out the default [homes] share, and add a comment about
        "valid users = %s" to show users how to restrict access to
        \\server\username to only username.
    - debian/control: Ubuntu i386 binary compatibility:
      + drop ceph support
    - d/control: enable the liburing vfs module, except on i386 where
      liburing is not available
    - d/t/{cifs-share-access-uring,smbclient-share-access-uring}:
      Skip running the tests if on i386 platform, because the uring
      package is not available there.
    - d/t/util: fix setting the password of the smb test user
      (LP #1955851)
    - d/rules: in Ubuntu, glusterfs is not built for i386, so don't
      enable the samba glusterfs vfs mofule in that case
    - d/control: build-depend on libglusterfs-dev only on !i386 arches
  * Dropped:
    - Update nfs scripts for new nfs.conf config (LP: #1961840):
      + d/p/fix-nfs-service-name-to-nfs-kernel-server.patch: updated to use
        nfsconf(8) if it's available, instead of parsing the old config
        files in /etc/default/nfs-*
        [In 2:4.16.3+dfsg-1]
      + d/ctdb.example/nfs-kernel-server/nfs.conf: /etc/nfs.conf to be
        used by the example enable-nfs.sh example script
        [In 2:4.16.3+dfsg-1]
      + d/ctdb.example/nfs-kernel-server/quota: quota config file to be
        used by the example enable-nfs.sh script
        [In 2:4.16.3+dfsg-1]
      + d/ctdb.example/nfs-kernel-server/nfs-{common,kernel-server}:
        obsolete, replaced by nfs.conf
        [In 2:4.16.3+dfsg-1]
      + d/ctdb.example/nfs-kernel-server/enable-nfs.sh: handle new
        nfs.conf and other changes in the new nfs server packages
        [In 2:4.16.3+dfsg-1]
    - Fix abort when deleting a file and "fruit:resource = stream" is
      used.  (LP #1977491)
      + d/p/lp1977491-dont-crash-on-vfs_fruit-resource-stream-01.patch:
        Add test that shows smbd crashing when deleting a file while using
        vfs_fruit with "fruit:resource = stream".
      + d/p/lp1977491-dont-crash-on-vfs_fruit-resource-stream-02.patch:
        Handle file deleting when "fruit:resource = stream" is used.
        [Fixed upstream]
    - Build dlz module for bind 9.18.x (LP #1964032)
      + d/p/add-support-for-bind-918.patch: build a dlz module for
        bind 9.18.x
      + d/p/add-support-for-bind-918-2.patch: also update the
        provisioning tool and template config file
        [Fixed upstream]

 -- Andreas Hasenack <email address hidden>  Fri, 29 Jul 2022 17:09:27 -0300
Superseded in jammy-updates
Superseded in jammy-security
samba (2:4.15.9+dfsg-0ubuntu0.2) jammy-security; urgency=medium

  * Updated to 2.15.9 to fix multiple security issues.
    - debian/control: require ldb 2.4.4.
    - debian/*install: install libsmbconf.so*.
    - debian/libwbclient0.symbols: updated symbols for new version.
    - CVE-2022-2031, CVE-2022-32742, CVE-2022-32744, CVE-2022-32745,
      CVE-2022-32746
  * Removed patches included in new version:
    - lp-1951490-fix-printing-KB5006743.patch
    - add-support-for-bind-918.patch
    - add-support-for-bind-918-2.patch
    - lp1977491-dont-crash-on-vfs_fruit-resource-stream-01.patch
    - lp1977491-dont-crash-on-vfs_fruit-resource-stream-02.patch

 -- Marc Deslauriers <email address hidden>  Thu, 28 Jul 2022 08:07:32 -0400
Superseded in focal-updates
Superseded in focal-security
samba (2:4.13.17~dfsg-0ubuntu1.20.04.1) focal-security; urgency=medium

  * SECURITY UPDATE: MaxQueryDuration not honoured in Samba AD DC LDAP
    - debian/patches/CVE-2021-3670-*.patch
    - CVE-2021-3670
  * SECURITY UPDATE: Samba AD users can bypass certain restrictions
    associated with changing passwords
    - debian/patches/CVE-2022-2031-*.patch
    - CVE-2022-2031
  * SECURITY UPDATE: Server memory information leak via SMB1
    - debian/patches/CVE-2022-32742-*.patch
    - CVE-2022-32742
  * SECURITY UPDATE: Samba AD users can forge password change requests for
    any user
    - debian/patches/CVE-2022-2031-*.patch
    - CVE-2022-32744
  * SECURITY UPDATE: Samba AD users can crash the server process with an
    LDAP add or modify request
    - debian/patches/CVE-2022-32745_6-*.patch
    - CVE-2022-32745
  * SECURITY UPDATE: Samba AD users can induce a use-after-free in the
    server process with an LDAP add or modify request
    - debian/patches/CVE-2022-32745_6-*.patch
    - CVE-2022-32746
  * debian/control: Build-Depends on ldb security update.
  * Fix version string to match focal.

 -- Marc Deslauriers <email address hidden>  Mon, 18 Jul 2022 08:52:26 -0400
Superseded in kinetic-release
Deleted in kinetic-proposed (Reason: Moved to kinetic)
samba (2:4.16.2+dfsg-1ubuntu1) kinetic; urgency=medium

  * Merge with Debian unstable. Remaining changes:
    - d/p/VERSION.patch: Update vendor string to "Ubuntu".
    - debian/smb.conf;
      + Add "(Samba, Ubuntu)" to server string.
      + Comment out the default [homes] share, and add a comment about
        "valid users = %s" to show users how to restrict access to
        \\server\username to only username.
    - debian/control: Ubuntu i386 binary compatibility:
      + drop ceph support
    - d/control: enable the liburing vfs module, except on i386 where
      liburing is not available
    - d/t/{cifs-share-access-uring,smbclient-share-access-uring}:
      Skip running the tests if on i386 platform, because the uring
      package is not available there.
    - d/t/util: fix setting the password of the smb test user
      (LP #1955851)
    - Update nfs scripts for new nfs.conf config (LP #1961840):
      + d/p/fix-nfs-service-name-to-nfs-kernel-server.patch: updated to use
        nfsconf(8) if it's available, instead of parsing the old config
        files in /etc/default/nfs-*
      + d/ctdb.example/nfs-kernel-server/nfs.conf: /etc/nfs.conf to be
        used by the example enable-nfs.sh example script
      + d/ctdb.example/nfs-kernel-server/quota: quota config file to be
        used by the example enable-nfs.sh script
      + d/ctdb.example/nfs-kernel-server/nfs-{common,kernel-server}:
        obsolete, replaced by nfs.conf
      + d/ctdb.example/nfs-kernel-server/enable-nfs.sh: handle new
        nfs.conf and other changes in the new nfs server packages
    - Build dlz module for bind 9.18.x (LP #1964032)
      + d/p/add-support-for-bind-918.patch: build a dlz module for
        bind 9.18.x
      + d/p/add-support-for-bind-918-2.patch: also update the
        provisioning tool and template config file
    - d/rules: in Ubuntu, glusterfs is not built for i386, so don't
      enable the samba glusterfs vfs mofule in that case
    - d/control: build-depend on libglusterfs-dev only on !i386 arches
    - Fix abort when deleting a file and "fruit:resource = stream" is
      used.  (LP #1977491)
      + d/p/lp1977491-dont-crash-on-vfs_fruit-resource-stream-01.patch:
        Add test that shows smbd crashing when deleting a file while using
        vfs_fruit with "fruit:resource = stream".
      + d/p/lp1977491-dont-crash-on-vfs_fruit-resource-stream-02.patch:
        Handle file deleting when "fruit:resource = stream" is used.

 -- Andreas Hasenack <email address hidden>  Mon, 27 Jun 2022 18:32:00 -0300
Superseded in jammy-updates
Deleted in jammy-proposed (Reason: moved to -updates)
samba (2:4.15.5~dfsg-0ubuntu5.1) jammy; urgency=medium

  * Fix abort when deleting a file and "fruit:resource = stream" is
    used.  (LP: #1977491)
    - d/p/lp1977491-dont-crash-on-vfs_fruit-resource-stream-01.patch:
      Add test that shows smbd crashing when deleting a file while using
      vfs_fruit with "fruit:resource = stream".
    - d/p/lp1977491-dont-crash-on-vfs_fruit-resource-stream-02.patch:
      Handle file deleting when "fruit:resource = stream" is used.

 -- Sergio Durigan Junior <email address hidden>  Tue, 21 Jun 2022 16:31:40 -0400
Superseded in kinetic-release
Deleted in kinetic-proposed (Reason: Moved to kinetic)
samba (2:4.16.1+dfsg-8ubuntu2) kinetic; urgency=medium

  * Fix abort when deleting a file and "fruit:resource = stream" is
    used.  (LP: #1977491)
    - d/p/lp1977491-dont-crash-on-vfs_fruit-resource-stream-01.patch:
      Add test that shows smbd crashing when deleting a file while using
      vfs_fruit with "fruit:resource = stream".
    - d/p/lp1977491-dont-crash-on-vfs_fruit-resource-stream-02.patch:
      Handle file deleting when "fruit:resource = stream" is used.

 -- Sergio Durigan Junior <email address hidden>  Mon, 20 Jun 2022 19:09:25 -0400
Superseded in kinetic-release
Deleted in kinetic-proposed (Reason: Moved to kinetic)
samba (2:4.16.1+dfsg-8ubuntu1) kinetic; urgency=medium

  * Merge with Debian unstable (LP: #1971256, LP: #1846947). Remaining
    changes:
    - d/p/VERSION.patch: Update vendor string to "Ubuntu".
    - debian/smb.conf;
      + Add "(Samba, Ubuntu)" to server string.
      + Comment out the default [homes] share, and add a comment about
        "valid users = %s" to show users how to restrict access to
        \\server\username to only username.
    - debian/control: Ubuntu i386 binary compatibility:
      + drop ceph support
    - d/control: enable the liburing vfs module, except on i386 where
      liburing is not available
    - d/t/{cifs-share-access-uring,smbclient-share-access-uring}:
      Skip running the tests if on i386 platform, because the uring
      package is not available there.
    - d/t/util: fix setting the password of the smb test user
      (LP #1955851)
    - Update nfs scripts for new nfs.conf config (LP #1961840):
      + d/p/fix-nfs-service-name-to-nfs-kernel-server.patch: updated to use
        nfsconf(8) if it's available, instead of parsing the old config
        files in /etc/default/nfs-*
      + d/ctdb.example/nfs-kernel-server/nfs.conf: /etc/nfs.conf to be
        used by the example enable-nfs.sh example script
      + d/ctdb.example/nfs-kernel-server/ctdb.example.quota: quota
        config file to be used by the example enable-nfs.sh script
      + d/ctdb.example/nfs-kernel-server/nfs-{common,kernel-server}:
        obsolete, replaced by nfs.conf
      + d/ctdb.example/nfs-kernel-server/enable-nfs.sh: handle new
        nfs.conf and other changes in the new nfs server packages
    - Build dlz module for bind 9.18.x (LP #1964032)
      + d/p/add-support-for-bind-918.patch: build a dlz module for
        bind 9.18.x
      + d/p/add-support-for-bind-918-2.patch: also update the
        provisioning tool and template config file
    - d/rules: in Ubuntu, glusterfs is not built for i386, so don't
      enable the samba glusterfs vfs mofule in that case
    - d/control: build-depend on libglusterfs-dev only on !i386 arches
  * Dropped:
    - d/control: add a versioned libgnutls28-dev build-depends to reduce
      the amount of in-tree crypto code that is built
      [superfluous, the version in the archive is recent enough]
    - d/samba.postinst: do not populate sambashare from the Ubuntu admin group (LP 1942195)
      [Included in 2:4.13.13+dfsg-1]
    - d/control: bump required build-depends
      [Included in Debian]
    - d/samba-libs.install: update list of installed libraries and
      modules/plugins
      [Done in Debian]
    - debian/patches/CVE-2021-20254.patch: removed, applied upstream
      [Applied upstream, Debian didn't have this patch]
    - d/p/Rename-mdfind-to-mdsearch.patch: removed, applied usptream
      [Applied usptream, Debian did not have it]
    - d/{gpb.conf,watch,README.source}: update for 4.15
      [Debian updated it for 4.16]
    - d/rules: remove --with-dnsupdate, it was merged with
      --with-ads in samba 4.15.0
      [Included in 2:4.16.0+dfsg-1]
    - d/rules: drop removal of ctdb tests, they are no longer installed
      [Included in 2:4.16.0+dfsg-1]
    - Remove findsmb, no longer installed:
      + d/smbclient.install: remove findsmb
      + d/rules: drop fixing of findsmb shebang
      [Included in 2:4.16.0+dfsg-1]
    - d/ctdb.install: remove ctdb_local_daemons, part of ctdb tests,
      no longer installed
      [Included in 2:4.16.0+dfsg-1]
    - d/ctdb.install: add tdb_mutex_check
      [Included in 2:4.16.0+dfsg-1]
    - d/winbind.install: add async_dns_krb5_locator
      [Included in 2:4.16.0+dfsg-1]
    - d/samba.install: install samba-bgqd and its manpage
      [Included in 2:4.16.0+dfsg-1]
    - d/{libsmbclient,libwbclient0}.symbols: symbols updates
      [Obsolete, these were for 4.15.5]
    - d/rules: drop dh_perl override, unneeded
      [Included in 2:4.16.0+dfsg-1]
    - d/p/lp-1951490-fix-printing-KB5006743.patch: Fix printing after
      Windows 2021-10 Monthly Rollup patch (LP #1951490)
      [Included upstream in 4.16.0rc2]
    - d/rules: install the new/changed ctdb example nfs files
      [Installed via ctdb.examples]
  * Added:
    - rename ctdb example files nfs.conf and quota, to match what the
      enable-nfs.sh script expects
    - enable-nfs.sh ctdb example: use debian's filename for the
      static port sysctl configuration
    - enable-nfs.sh: in ctdb 4.16, the "recovery lock" config option was
      renamed to "cluster lock"

 -- Andreas Hasenack <email address hidden>  Wed, 08 Jun 2022 11:02:29 -0300
Superseded in kinetic-release
Deleted in kinetic-proposed (Reason: Moved to kinetic)
samba (2:4.15.5~dfsg-0ubuntu6) kinetic; urgency=medium

  * No-change rebuild against libicu71

 -- Steve Langasek <email address hidden>  Sat, 30 Apr 2022 02:14:39 +0000
Superseded in kinetic-release
Published in jammy-release
Deleted in jammy-proposed (Reason: Moved to jammy)
samba (2:4.15.5~dfsg-0ubuntu5) jammy; urgency=medium

  * Enable glusterfs support (LP: #1894618):
    - d/control: revert disabling of glusterfs, since it's in main now
    - d/rules: in Ubuntu, glusterfs is not built for i386, so don't
      enable the samba glusterfs vfs mofule in that case
    - d/control: build-depend on libglusterfs-dev only on !i386 arches

 -- Andreas Hasenack <email address hidden>  Wed, 09 Mar 2022 17:31:25 -0300
Superseded in jammy-release
Deleted in jammy-proposed (Reason: Moved to jammy)
samba (2:4.15.5~dfsg-0ubuntu4) jammy; urgency=medium

  * Build dlz module for bind 9.18.x (LP: #1964032)
    - d/p/add-support-for-bind-918.patch: build a dlz module for
      bind 9.18.x
    - d/samba-libs.install: remove fixme comment
    - d/p/add-support-for-bind-918-2.patch: also update the provisioning
      tool and template config file

 -- Andreas Hasenack <email address hidden>  Fri, 25 Mar 2022 14:53:19 -0300
Superseded in jammy-proposed
samba (2:4.15.5~dfsg-0ubuntu3) jammy; urgency=medium

  * Update nfs scripts for new nfs.conf config (LP: #1961840):
    - d/p/fix-nfs-service-name-to-nfs-kernel-server.patch: updated to use
      nfsconf(8) if it's available, instead of parsing the old config
      files in /etc/default/nfs-*
    - d/ctdb.example.nfs.conf: /etc/nfs.conf to be used by the example
      enable-nfs.sh example script
    - d/ctdb.example.quota: quota config file to be used by the example
      enable-nfs.sh script
    - d/ctdb.example.nfs-{common,kernel-server}: obsolete, replaced by
      nfs.conf
    - d/ctdb.example.enable.nfs.sh: handle new nfs.conf and other
      changes in the new nfs server packages
    - d/rules: install the new/changed ctdb example nfs files

 -- Andreas Hasenack <email address hidden>  Mon, 21 Mar 2022 11:55:54 -0300
Superseded in focal-updates
Deleted in focal-proposed (Reason: moved to -updates)
samba (2:4.13.17~dfsg-0ubuntu0.21.04.2) focal; urgency=medium

  * d/p/lp-1951490-fix-printing-KB5006743.patch: Fix printing after
    Windows 2021-10 Monthly Rollup patch (LP: #1951490)

 -- Andreas Hasenack <email address hidden>  Thu, 10 Mar 2022 10:48:01 -0300
Deleted in impish-proposed (Reason: The package was removed due to its SRU bug(s) not being v...)
samba (2:4.13.17~dfsg-0ubuntu0.21.10.2) impish; urgency=medium

  * d/p/lp-1951490-fix-printing-KB5006743.patch: Fix printing after
    Windows 2021-10 Monthly Rollup patch (LP: #1951490)

 -- Andreas Hasenack <email address hidden>  Thu, 10 Mar 2022 10:52:15 -0300
Superseded in jammy-release
Deleted in jammy-proposed (Reason: Moved to jammy)
samba (2:4.15.5~dfsg-0ubuntu2) jammy; urgency=medium

  * d/p/lp-1951490-fix-printing-KB5006743.patch: Fix printing after
    Windows 2021-10 Monthly Rollup patch (LP: #1951490)

 -- Andreas Hasenack <email address hidden>  Thu, 10 Mar 2022 10:32:59 -0300
Superseded in jammy-release
Deleted in jammy-proposed (Reason: Moved to jammy)
samba (2:4.15.5~dfsg-0ubuntu1) jammy; urgency=medium

  * d/{gpb.conf,watch,README.source}: update for 4.15
  * New upstream release: 4.15.5 (LP: #1946839)
  * d/p/Rename-mdfind-to-mdsearch.patch: removed, applied usptream
  * d/rules: remove --with-dnsupdate, it was merged with
    --with-ads in samba 4.15.0
  * d/control: bump required build-depends
  * d/rules: drop removal of ctdb tests, they are no longer installed
  * Remove findsmb, no longer installed:
    - d/smbclient.install: remove findsmb
    - d/rules: drop fixing of findsmb shebang
  * d/ctdb.install: remove ctdb_local_daemons, part of ctdb tests,
    no longer installed
  * d/samba-libs.install: update list of installed libraries and
    modules/plugins
  * d/ctdb.install: add tdb_mutex_check
  * d/winbind.install: add async_dns_krb5_locator
  * d/samba.install: install samba-bgqd and its manpage
  * d/{libsmbclient,libwbclient0}.symbols: symbols updates
  * d/control: add python3-markdown to build-depends
  * d/watch: updated to handle ~dfsg versioning, thanks to
    Sergio Durigan Junior <email address hidden>

 -- Andreas Hasenack <email address hidden>  Tue, 22 Feb 2022 17:59:22 -0300
Superseded in jammy-proposed
samba (2:4.13.17~dfsg-0ubuntu2) jammy; urgency=medium

  * No-change rebuild to update maintainer scripts, see LP: 1959054

 -- Dave Jones <email address hidden>  Wed, 16 Feb 2022 17:31:06 +0000
Superseded in jammy-proposed
samba (2:4.13.17~dfsg-0ubuntu1) jammy; urgency=medium

  * Update to 4.13.17 as a security update
    - CVE-2021-43566, CVE-2021-44142, CVE-2022-0336
  * Removed patches included in new version:
    - debian/patches/trusted_domain_regression_fix.patch
    - debian/patches/bug14901-*.patch
    - debian/patches/bug14922.patch

 -- Marc Deslauriers <email address hidden>  Mon, 14 Feb 2022 10:19:08 -0500
Superseded in jammy-proposed
samba (2:4.13.14+dfsg-0ubuntu5) jammy; urgency=medium

  * No-change rebuild for icu soname change

 -- William 'jawn-smith' Wilson <email address hidden>  Fri, 11 Feb 2022 11:36:14 -0600
Superseded in focal-updates
Superseded in focal-security
samba (2:4.13.17~dfsg-0ubuntu0.21.04.1) focal-security; urgency=medium

  * Update to 4.13.17 as a security update
    - CVE-2021-43566, CVE-2021-44142, CVE-2022-0336
  * Removed patches included in new version:
    - debian/patches/trusted_domain_regression_fix.patch
    - debian/patches/bug14901-*.patch
    - debian/patches/bug14922.patch

 -- Marc Deslauriers <email address hidden>  Mon, 31 Jan 2022 08:11:13 -0500
Obsolete in impish-updates
Obsolete in impish-security
samba (2:4.13.17~dfsg-0ubuntu0.21.10.1) impish-security; urgency=medium

  * Update to 4.13.17 as a security update
    - CVE-2021-43566, CVE-2021-44142, CVE-2022-0336
  * Removed patches included in new version:
    - debian/patches/trusted_domain_regression_fix.patch
    - debian/patches/bug14901-*.patch
    - debian/patches/bug14922.patch

 -- Marc Deslauriers <email address hidden>  Mon, 31 Jan 2022 08:11:13 -0500
Superseded in bionic-updates
Published in bionic-security
samba (2:4.7.6+dfsg~ubuntu-0ubuntu2.28) bionic-security; urgency=medium

  * SECURITY UPDATE: code exec via out-of-bounds read/write in vfs_fruit
    - debian/patches/CVE-2021-44142-1.patch: add defines for icon lengths
      in source3/modules/vfs_fruit.c.
    - debian/patches/CVE-2021-44142-2.patch: add Netatalk xattr used by
      vfs_fruit to the list of private Samba xattrs in
      source3/smbd/trans2.c.
    - debian/patches/CVE-2021-44142-3.patch: harden ad_unpack_xattrs() in
      source3/modules/vfs_fruit.c.
    - debian/patches/CVE-2021-44142-4.patch: tweak buffer size check in
      source3/modules/vfs_fruit.c.
    - debian/patches/CVE-2021-44142-5.patch: add basic cmocka tests in
      selftest/knownfail.d/samba.unittests.adouble, selftest/tests.py,
      source3/lib/test_adouble.c, source3/wscript_build.
    - debian/patches/CVE-2021-44142-6.patch: harden parsing code in
      source3/modules/vfs_fruit.c.
    - CVE-2021-44142

 -- Marc Deslauriers <email address hidden>  Tue, 25 Jan 2022 10:20:03 -0500
Superseded in jammy-proposed
samba (2:4.13.14+dfsg-0ubuntu4) jammy; urgency=medium

  * d/t/util: fix setting the password of the smb test user
    (LP: #1955851)

 -- Andreas Hasenack <email address hidden>  Thu, 20 Jan 2022 17:06:13 -0300
Superseded in jammy-proposed
samba (2:4.13.14+dfsg-0ubuntu3) jammy; urgency=medium

  * No-change rebuild with Python 3.10 as default version

 -- Graham Inggs <email address hidden>  Sun, 16 Jan 2022 07:01:34 +0000
Superseded in bionic-updates
Superseded in bionic-security
samba (2:4.7.6+dfsg~ubuntu-0ubuntu2.27) bionic-security; urgency=medium

  * SECURITY REGRESSION: Kerberos authentication on standalone server in
    MIT realm broken
    - debian/patches/bug14922.patch: fix MIT Realm regression in
      source3/auth/user_krb5.c.

 -- Marc Deslauriers <email address hidden>  Mon, 13 Dec 2021 07:12:56 -0500
Superseded in focal-updates
Superseded in focal-security
samba (2:4.13.14+dfsg-0ubuntu0.20.04.4) focal-security; urgency=medium

  * SECURITY REGRESSION: Kerberos authentication on standalone server in
    MIT realm broken
    - debian/patches/bug14922.patch: fix MIT Realm regression in
      source3/auth/user_krb5.c.

 -- Marc Deslauriers <email address hidden>  Mon, 13 Dec 2021 07:12:25 -0500
Obsolete in hirsute-updates
Obsolete in hirsute-security
samba (2:4.13.14+dfsg-0ubuntu0.21.04.4) hirsute-security; urgency=medium

  * SECURITY REGRESSION: Kerberos authentication on standalone server in
    MIT realm broken
    - debian/patches/bug14922.patch: fix MIT Realm regression in
      source3/auth/user_krb5.c.

 -- Marc Deslauriers <email address hidden>  Mon, 13 Dec 2021 07:11:56 -0500
Superseded in impish-updates
Superseded in impish-security
samba (2:4.13.14+dfsg-0ubuntu0.21.10.4) impish-security; urgency=medium

  * SECURITY REGRESSION: Kerberos authentication on standalone server in
    MIT realm broken
    - debian/patches/bug14922.patch: fix MIT Realm regression in
      source3/auth/user_krb5.c.

 -- Marc Deslauriers <email address hidden>  Mon, 13 Dec 2021 07:11:23 -0500
175 of 628 results