Ubuntu

Change logs for “nova” source package in Oneiric

  • nova (2011.3+git20111117-0ubuntu1) oneiric-proposed; urgency=low
    
      * New upstream release, this is a stable updates release of Nova.
        This update fixes various issues with networking issues, OS API
        issues and EC2 API issues amongst others. Fixes include:
        + Make sure to recreate gateway for moved ip. (LP: #859587)
        + Put fully qualified domain name in local-hostname.
          (LP: #854614)
        + Fix the grantee group leading for source groups.
          (LP: #859679)
        + Call endheaders when auth_token is None. (LP: #856721)
        + Remove db_pool complexities from nova.db.sqlalchemy.session.
          (LP: #838581)
        + Raise InssufficentFreeMemory. (LP: #851374) (LP: #858679)
        + Don't leak exceptions out to users. (LP: #874472)
        + Make snapshots work for amis. (LP: #873156)
        + Make snapshots private by default. (LP: #850389)
        + Snapshots/bacups can no longer happen simultaneously.
          (LP: #727502)
        + Adding backing file copy operation on kvm block migration.
          (LP: #850602)
        + Check if host list is not empty before trying to weigh
          the hosts. (LP: #861310)
        + Enforce snapshot cleanup. (LP: #861582)
        + VDI is not resized to instance_type local_gb on
          initial boot. (LP: #845714)
        + Adds the tenant id to the create images response Location
          header (LP: #862672)
        + OS api consoles create() broken. (LP: #862633)
        + Deallocate IP if build fails. (LP: #837687)
        + Stop returning correct password on api calls.
          (LP: #868360)
        + Handle pidfile exception for dnsmasq. (LP: #865399)
        + Make sure unknown extensions return 404. (LP: #869153)
        + Ensure non-default FLAGS.logfile_mode is properly converted to
          an octet. (LP: #862969)
        + Explicit errors on confirm/revertResize failures. (LP: #856527)
        + Adds ext4 and reiserfs to _mount_filesystem(). (LP: #870495)
        + Improve access check on images. (LP: #863305)
        + Auto assigning floating IPs. (LP: #834633)
        + Fix typo in scheduler. (LP: #883233)
        + Fix deletion of instances without fixed ips.
        + Fix file injection of OSAPI rebuilds. (LP: #881649)
        + Fix adding bulk create fixed ips.
        + Retry failed SQL connections (LP: #876663)
        + Updated NoAuth to account for requests ending in /
          (LP:  #882742)
        + ajax_console_proxy_port needs to be an integer.
          (LP: #884527)
        + Newly created network has no uuid.
          (LP: #861160)
        + Fix KeyError when passed unknown format of time.
          (LP: #883253)
        + Add local storage of context for logging.
          (LP: #879582)
        + Fix nova logs everything to syslog twice.
          (LP: #884863)
        + Fix nova-ajax-console-proxy crashes on shutdown.
          (LP: #884534)
        + Fix exception.KeypairNotFound usage correction.
          (LP: #885462)
        + Undefine libvirt saved instances. (LP: #814561)
      * Dropped patches:
        + debian/patches/fqdn-in-local-hostname-of-ec2-metadata.patch:
          Applied upstream.
        + debian/patches/backport-recreate-gateway-using-dhcp.patch:
          Applied upstream.
        + debian/patches/block-migration-needs-copy-backingfile.patch:
          Applied usptream.
        + debian/patches/backport-snapshot-cleanup.patch:
          Applied upstream.
        + debian/patches/fix-lp863305-images-permission.patch:
          Applied upstream.
        + debian/patches/security-fix-lp868360.patch:
          Applied upstream.
     -- Chuck Short <email address hidden>   Thu, 17 Nov 2011 10:05:11 -0500
  • nova (2011.3-0ubuntu6.13) oneiric-security; urgency=low
    
      * SECURITY UPDATE: fix denial of service via fixed IPs when using extensions
        - debian/patches/CVE-2013-1838.patch: add explicit quota for fixed IP
        - CVE-2013-1838
        - LP: #1125468
     -- Jamie Strandboge <email address hidden>   Wed, 20 Mar 2013 09:48:07 -0500
  • nova (2011.3-0ubuntu6.12) oneiric-security; urgency=low
    
      * SECURITY UPDATE: fix denial of service
        - CVE-2013-1664.patch: Add a new utils.safe_minidom_parse_string function
          and update external API facing Nova modules to use it
        - CVE-2013-1664
     -- Jamie Strandboge <email address hidden>   Tue, 19 Feb 2013 13:28:11 -0600
  • nova (2011.3-0ubuntu6.11) oneiric-security; urgency=low
    
      * SECURITY UPDATE: fix lack of authentication on block device used for
        os-volume_boot
        - debian/patches/CVE-2013-0208.patch: adjust nova/compute/api.py to
          validate we can access the volumes
        - CVE-2013-0208
     -- Jamie Strandboge <email address hidden>   Wed, 23 Jan 2013 13:33:54 -0600
  • nova (2011.3-0ubuntu6.10) oneiric-security; urgency=low
    
      * SECURITY UPDATE: Prohibit file injection writing to host filesystem
        - debian/patches/CVE-2012-3447.patch: update to perform the file name
          canonicalization as the root user
        - CVE-2012-3447
     -- Jamie Strandboge <email address hidden>   Fri, 17 Aug 2012 13:55:33 -0500
  • nova (2011.3-0ubuntu6.9) oneiric-security; urgency=low
    
      * SECURITY UPDATE: arbitrary file injection/corruption
        - debian/patches/CVE-2012-3361.patch: ensure that files cannot
          be injected in arbitrary locations
        - CVE-2012-3361
     -- Steve Beattie <email address hidden>   Mon, 02 Jul 2012 12:26:31 -0700
  • nova (2011.3-0ubuntu6.8) oneiric-security; urgency=low
    
      * REGRESSION FIX: security group without protocol set failure (LP: #1010514)
        - debian/patches/CVE-2012-2654-regression.patch: only call .lower()
          when a protocol has been set.
     -- Steve Beattie <email address hidden>   Mon, 11 Jun 2012 16:20:19 -0700
  • nova (2011.3-0ubuntu6.7) oneiric-security; urgency=low
    
      * SECURITY UPDATE: set security groups correctly if IP protocol is
        specified in upper/mixed case
        - debian/patches/CVE-2012-2654.patch: ensure protocols are in
          lowercase for the controllers
     -- Steve Beattie <email address hidden>   Fri, 01 Jun 2012 12:21:51 -0700
  • nova (2011.3-0ubuntu6.6) oneiric-security; urgency=low
    
      * SECURITY UPDATE: Place limit on number of security groups a user may
        create
        - debian/patches/CVE-2012-2101.patch: add quotas for security groups and
          security groups rules
        - CVE-2012-2101
     -- Jamie Strandboge <email address hidden>   Thu, 03 May 2012 15:47:00 -0500
  • nova (2011.3-0ubuntu6.5) oneiric-security; urgency=low
    
      * SECURITY UPDATE: Denial of service via resource exhaustion in nova-api
        - debian/patches/validate_server_name_length.patch: Limit server names
          to a maximum of 255 characters to prevent nova-api log files from
          exhausting storage space. Based on upstream patch.
        - CVE-2012-1585
     -- Tyler Hicks <email address hidden>   Thu, 29 Mar 2012 01:13:25 -0500
  • nova (2011.3-0ubuntu6.4) oneiric-security; urgency=low
    
      * SECURITY UPDATE: fix tenant bypass by authenticated users via OpenStack
        API (LP: #904072)
        - CVE-2012-0030
     -- Jamie Strandboge <email address hidden>   Tue, 10 Jan 2012 10:26:57 +0100
  • nova (2011.3-0ubuntu6.3) oneiric-security; urgency=low
    
      * SECURITY UPDATE: fix directory traversal during image registration via
        EC2 API and S3/RegisterImage
        - fix-traversal-via-image-register.patch: adjust nova/image/s3.py to
          use basename instead of absolute path
        - CVE-2011-XXXX
     -- Jamie Strandboge <email address hidden>   Fri, 09 Dec 2011 06:45:31 -0600
  • nova (2011.3-0ubuntu6.2) oneiric-security; urgency=low
    
      * SECURITY UPDATE: fix information leak via invalid key
        debina/patches/security-fix-lp868360.patch: adjust nova/auth/manager.py
        to not return access, secret or admin fields for User error and
        project_manager_id, description and member_ids for Project
        - LP: #868360
        - CVE-2011-XXXX
     -- Jamie Strandboge <email address hidden>   Tue, 25 Oct 2011 08:57:02 -0500
  • nova (2011.3-0ubuntu6.1) oneiric-proposed; urgency=low
    
      [Scott Moser]
      * Removed db_pool complexities from nova.db.sqlalchemy.session (LP: #838581)
    
      [Chuck Short]
      * debian/patches/fix-iscsi-target-path.patch: Fix ISCSI target path patch.
        (LP: #871278)
      * debian/control: Either install xen-hypervisor-4.1-amd64 or
        xen-hypervisor-4.1-i386 for nova-compute-xen. (LP: #873243)
     -- Chuck Short <email address hidden>   Wed, 12 Oct 2011 14:33:25 -0400
  • nova (2011.3-0ubuntu6) oneiric; urgency=low
    
      * debian/patches/backport-libvirt-console-pipe.patch:
        - Patch updated to fix race on instance termination (LP: #868349)
     -- Robie Basak <email address hidden>   Wed, 05 Oct 2011 17:37:49 +0100
  • nova (2011.3-0ubuntu5) oneiric; urgency=low
    
      * debian/nova-common.postinst:
        - Set permissions recursively on /var/lib/nova to nova:nova for new
          installations (LP: #865169).
      * debian/patches/backport-libvirt-console-pipe.patch:
        - Patch updated to use correct patchset from upstream - incorrect version
          was uploaded in -0ubuntu4 (LP: #832507).
     -- James Page <email address hidden>   Tue, 04 Oct 2011 09:43:55 +0100
  • nova (2011.3-0ubuntu4) oneiric; urgency=low
    
      [James Page]
      * debian/nova-common.postinst:
        - Exclude mounted LXC rootfs filesystems within /var/lib/nova from
          user/group ownership changes (LP: #861260).
        - Ensure that primary group for 'nova' user is 'nova' so that files
          created by this user have the correct group ownership.
    
      [Adam Gandelman]
      * debian/nova-common.postinst: Restrict permissions of /var/log/nova
        (LP: #862816)
    
      [Ante Karamatic]
      * Add /usr/sbin/ietadm to sudoers (LP: #861547)
      * debian/control: Fix typo in Vcs-Bzr
    
      [Chuck Short]
      * debian/patches/backport-libvirt-console-pipe.patch:
        Move console.log to a ringbuffer so that the console.log
        keeps filling up. (LP: #832507)
      * debian/patches/backport-lxc-container-console-fix.patch:
        Make euca-get-console-output usable for LXC containers.
        (LP: #832159)
      * debian/patches/backport-snapshot-cleanup.patch:
        Enforce snapshot cleanup. (LP: #861582).
      * debian/patches/fix-lp863305-images-permission.patch:
        Fix image access control. (LP: #863305)
     -- Chuck Short <email address hidden>   Fri, 30 Sep 2011 15:21:56 -0400
  • nova (2011.3-0ubuntu3) oneiric; urgency=low
    
      [Adam Gandelman]
      * debian/nova-common.postinst: Create 'nova' group, add user to it
        (LP: #856530)
      * debian/nova.conf, debian/nova-compute.upstart.in: Move reference of
        nova-compute.conf from nova.conf to nova-compute's argv. (LP: #839796)
    
      [Chuck Short]
      * debian/patches/backport-recreate-gateway-using-dhcp.patch:
        Makes sure to recreate gateway for moved ip. (LP: #859587)
      * debian/control: Update Vcs info.
    
      [ Scott Moser ]
      * debian/patches/fqdn-in-local-hostname-of-ec2-metadata.patch
        Make the 'local-hostname' in the EC2 Metadata service contain
        the domainname also. (LP: #854614)
     -- Chuck Short <email address hidden>   Tue, 27 Sep 2011 14:56:59 -0400
  • nova (2011.3-0ubuntu2) oneiric; urgency=low
    
      [Chuck Short]
      * debian/rules, debian/control: Use dh_python2
      * debian/control, debian/series,
        debian/patches/backport-iscsitarget-choice.patch,
        debian/nova_sudoers:
        + Change the default from iscsitarget to tgt.
      * debian/control, debian/series,
        debian/patches/use-netcat-instead-of-socat.patch,
        debian/nova_sudoers:
         + Change from socat to netcat.
      * debian/patches/block-migration-needs-copy-backingfile.patch:
        Fix block migration by needing to copy backing_file.
    
      [Monty Taylor]
      * Install a new paste config to enable deprecated auth.,
     -- Chuck Short <email address hidden>   Fri, 23 Sep 2011 13:34:51 -0400
  • nova (2011.3-0ubuntu1) oneiric; urgency=low
    
      [Chuck Short]
      * New upstream release.
      * debian/control, debian/nova_sudoers:
        + Add iputils-arping and add /usr/bin/apring.
      * debian/nova_sudoers: Clean up missing binaries.
    
      [Monty Taylor]
      * debian/control:
        + Add vlan to nova-compute
     -- Chuck Short <email address hidden>   Thu, 22 Sep 2011 09:33:49 -0400
  • nova (2011.3~rc~20110920.r1192-0ubuntu2) oneiric; urgency=low
    
      * debian/nova_sudoers:
        + Fix typo in nova_sudoers.
        + Tabs vs Spaces.
      * debian/nova.conf:
        + Use force_dhcp_release.
     -- Chuck Short <email address hidden>   Tue, 20 Sep 2011 15:44:39 -0400
  • nova (2011.3~rc~20110916.r1173-0ubuntu1) oneiric; urgency=low
    
      * New uptream version.
      * debian/rules: Dont fail tests.
     -- Chuck Short <email address hidden>   Fri, 16 Sep 2011 10:29:09 -0400
  • nova (2011.3~rc~20110909.r1155-0ubuntu1) oneiric; urgency=low
    
      * New upstream version.
     -- Chuck Short <email address hidden>   Fri, 09 Sep 2011 15:09:02 -0400
  • nova (2011.3~rc~20110901.1523-0ubuntu1) oneiric; urgency=low
    
      [ Chuck Short ]
      * Really remove python-ipy.
      * New upstream release.
      * Use "--use_deprecated_auth" by default because we dont support
        kestone yet. (LP: #838768)
    
      [ James E. Blair ]
      * Add python-unittest2 as a build dep.
    
      [ Dave Walker (Daviey) ]
      * debian/control: Added python-kombu as a build and run depends.
        - LP: #798876
    
      [ Scott Moser ]
      * add dependency on qemu-kvm to nova-compute (LP: #833530)
     -- Chuck Short <email address hidden>   Fri, 02 Sep 2011 13:21:22 -0400
  • nova (2011.3~d4-0ubuntu1) oneiric; urgency=low
    
      [ Thierry Carrez (ttx) ]
      [Chuck Short]
      * New upstream release.
    
      [Thierry Carrez]
      * No longer run nova-objectstore as root (LP: #820968)
     -- Chuck Short <email address hidden>   Fri, 26 Aug 2011 13:31:14 -0400
  • nova (2011.3~d4~20110812.1417-0ubuntu1) oneiric; urgency=low
    
      [Chuck Short]
      * New upstream version
      * Dont respawn the upstart jobs if nova is failing.
      * Remove python-ipy.
    
      [ Dan Prince ]
      * Updated the ajaxterm patch to work with latest nova code (privsep)
      * Added python-lxml to python-nova build-deps.
    
      [ Thomas Goirand ]
      * Add copyright info for ipv6 class for boto.
    
      [ Soren Hansen ]
      * Add parted to sudoers file.
      * Add Depends: python-simplejson and Conflicts: python-cjson due to
        bug #800465 which caused the test suite to fail.
      * Remove nova-instancemonitor package (dropped upstream).
      * Remove twisted dependency (dropped upstream).
      * Create nova-compute-{kvm,lxc,uml,xen} packages that pull in the
        right packages and configures nova to use the hypervisor in
        question.
    
      [ Thierry Carrez (ttx) ]
      * Added python-xattr to build deps, apprently this is now needed
      * Removed python-xattr from build deps, now that python-glance properly
        depends on it
      * Added radvd to nova_sudoers file (LP: #758072)
      * Make nova.conf non-world-readable, as it may contain DB passwords
        (LP: #798878)
    
      [ Brian Waldon ]
      * Remove nova-instancemonitor man page stub.
      * Remove nova-instancemonitor from apport hook.
    
      [ Monty Taylor ]
      * Added python-lxml to build-deps.
    
      [ Scott Moser ]
      * use trailing '/' on all usages of chown to support the case where
        the directory is a symlink
     -- Chuck Short <email address hidden>   Fri, 12 Aug 2011 03:12:38 -0400
  • nova (2011.3~d4~20110805.1383-0ubuntu1) oneiric; urgency=low
    
      * New upstream release.
     -- Chuck Short <email address hidden>   Fri, 05 Aug 2011 13:27:11 -0400
  • nova (2011.3~d3-0ubuntu1) oneiric; urgency=low
    
      * New upstream release.
      * debian/*.upstart.in: Dont restart upstart jobs if nova
        is misconfigured.
      * debian/rules: Dont start upstart jobs when installing
        nova.
      * debian/copyright: Update copyright info. (LP: #8150051)
      * debian/control: Update VCS info.
      * debian/control, debian/nova_sudoers: Suggest openvswitch-swich
        and add ovs-vsctl to sudoers file. (LP: #816754)
     -- Chuck Short <email address hidden>   Fri, 29 Jul 2011 09:41:02 -0400
  • nova (2011.3~d3~20110715.1279-0ubuntu1) oneiric; urgency=low
    
      * New  upstream release.
     -- Chuck Short <email address hidden>   Fri, 15 Jul 2011 14:26:39 -0400
  • nova (2011.3~d3~20110708.1251-0ubuntu1) oneiric; urgency=low
    
      * debian/control:
        - Dropped python-ipy.
        - Dropped xen-linux-system.
        - Dropped python-support.
      * New upstream release.
     -- Chuck Short <email address hidden>   Fri, 08 Jul 2011 13:29:48 -0400
  • nova (2011.3~d2-0ubuntu1) oneiric; urgency=low
    
      * debian/control:
        - Dropped python-ipy.
        - Dropped xen-linux-system.
        - Dropped python-support.
      * New upstream release.
     -- Chuck Short <email address hidden>   Thu, 30 Jun 2011 17:02:20 +0100
  • nova (2011.3~d2~20110623.1209-0ubuntu1) oneiric; urgency=low
    
      * New upstream release.
      * debian/control: Dropped python-tempita.
     -- Chuck Short <email address hidden>   Fri, 24 Jun 2011 13:54:57 -0400
  • nova (2011.3~d2~20110617.1191-0ubuntu1) oneiric; urgency=low
    
      [Chuck Short]
      * New upstream version.
      * Build for python 2.7.
    
      [ Thomas Goirand ]
      * Add copyright info for ipv6 class for boto.
    
      [ Soren Hansen ]
      * Add parted to sudoers file.
     -- Chuck Short <email address hidden>   Fri, 17 Jun 2011 13:29:16 -0400
  • nova (2011.3~d1-0ubuntu3) oneiric; urgency=low
    
      * Build for python 2.7.  (LP: #792121)
     -- Chuck Short <email address hidden>   Tue, 07 Jun 2011 14:35:09 -0400
  • nova (2011.3~d1-0ubuntu2) oneiric; urgency=low
    
      * Don't bail on failing tests again.
     -- Chuck Short <email address hidden>   Thu, 02 Jun 2011 11:17:54 -0400
  • nova (2011.3~d1-0ubuntu1) oneiric; urgency=low
    
      [Chuck Short]
      * New upstream version.
    
      [Soren Hansen]
      * libvirt plugin was refactored. Adjust ajaxterm patch accordingly.
      * Add /sbin/brctl to sudoers (it moved from /usr/sbin to /sbin in
        Oneiric).
      * Add dependencies on dnsmasq-base and bridge-utils to nova-network.
        (LP: #790661)
     -- Chuck Short <email address hidden>   Thu, 02 Jun 2011 09:30:39 -0400
  • nova (2011.3~bzr1108-0ubuntu1) oneiric; urgency=low
    
      [ Thomas Goirand ]
      * Removes embedded jquery.js from nova-doc package.
      * Added some manpages stubs to make package lintian clean.
      * Adds a nova-volume.default where the admin can decide what VG to use.
      * debian/nova-objectstore.logrotate working in Debian.
      * Do not have debian/*.upstart files in Debian. Using debian/*.upstart.in
      and copying them as .upstart only if building in Ubuntu.
      * Nova init files reviewed so that they are working in Debian.
      * Initscripts of nova-compute now has a Should-Start: libvirt-bin
      * nova-compute.postinst working with libvirt group in Debian.
      * Reviewed the package descriptions.
      * Reviewed some dependencies in debian/control (added some adduser and
      lsb-base depends).
      * Added missing binary Depends: (nova-manage must depends on
      python-amqplib unless failing puiparts tests, nova-compute is pretty
      usless without qemu-utils)
      * Removes .gitignore files from binaries.
      * Don't package nova-manage.1 man page if we aren't building docs.
      * Packages correctly: nova-manage.1 and not novamanage.1 !!!
    
      [ Soren Hansen ]
      * Bump required version of libvirt-bin on Ubuntu to 0.8.8.
      * Drop the last of the AOE dependencies. iSCSI is the default
        nowadays.
      * Make the decision about the name of the libvirt group at build time
        rather than runtime. (LP: #781716)
    
      [ Vishvananda Ishaya ]
      * Add dd to the sudo cmd list.
      * Add a nova-vncproxy package.
     -- Soren Hansen <email address hidden>   Wed, 25 May 2011 15:57:03 +0200
  • nova (2011.2-0ubuntu1) natty; urgency=low
    
      * New upstream release.
     -- Chuck Short <email address hidden>   Fri, 15 Apr 2011 07:14:43 -0400