Bug#963971: samba-libs: libndr.so.0 gone from latest version, breaks sssd-ad-common dependency

2020-06-29 Thread Andrew Bartlett
aking sssd- > ad-common. We can't put a version number in samba-libs as there are multiple public libraries in there. (Upstream) Samba doesn't promise not to keep doing this - the underlying change has happened before, but this time we were honest and bumped the .so - so sssd may need to have a depende

Bug#955474: [Pkg-samba-maint] Bug#955474: FTBFS: fatal error: stropts.h: No such file or directory

2020-04-01 Thread Andrew Bartlett
a python bug, it should not be setting HAVE_STROPTS_H. See bug 954582 -- Andrew Bartlett https://samba.org/~abartlet/ Authentication Developer, Samba Team https://samba.org Samba Developer, Catalyst IT https://catalyst.net.nz/services/samba

Bug#954582: samba: FTBFS glibc/stropts/python issue.

2020-03-30 Thread Andrew Bartlett
Python. The correct fix is for Python not to leak these defines. Andrew Bartlett -- Andrew Bartlett https://samba.org/~abartlet/ Authentication Developer, Samba Team https://samba.org Samba Developer, Catalyst IT https://catalyst.net.nz/services/samba

Bug#902883: [Pkg-samba-maint] Bug#902883: FTBFS on arch != amd64 because different libpytalloc-util.*.so name

2018-07-02 Thread Andrew Bartlett
bols doesn't match > completely debian/python3-talloc.symbols See also https://github.com/samba-team/samba/pull/110 for BaT trying to fix this kind of thing on FreeBSD. Andrew Bartlett -- Andrew Bartlett https://samba.org/~abartlet/ Authentication Developer, Samba Team https://samba.o

Bug#868209: CVE-2017-11103: MitM attack, impersonation of the Kerberos client, known as Orpheus Lyre

2017-07-13 Thread Andrew Bartlett
On Thu, 2017-07-13 at 18:05 +1200, Andrew Bartlett wrote: > On Thu, 2017-07-13 at 07:14 +0200, Raphael Hertzog wrote: > > Source: samba > > Severity: grave > > Tags: security patch > > Version: 2:4.1.11+dfsg-1 > > > > Hi, > > > > the followin

Bug#868209: CVE-2017-11103: MitM attack, impersonation of the Kerberos client, known as Orpheus Lyre

2017-07-13 Thread Andrew Bartlett
. Proposed updates are in jessie and stretch branches at: git://git.samba.org/abartlet/samba-debian.git I've only built them, not tested them.  Then again, the upstream patches were not manually tested either (we relied on autobuild), such was the rush... I can upload the buil

Bug#821811: [Pkg-samba-maint] Bug#821811: samba: badlock patch breaks trust relationship

2016-06-09 Thread Andrew Bartlett
On Thu, 2016-05-26 at 11:40 +0200, Santiago Ruano Rincón wrote: > El 23/05/16 a las 22:28, Andrew Bartlett escribió: > > > > On Wed, 2016-05-18 at 15:47 -0400, Antoine Beaupré wrote: > > > > > > On 2016-04-29 08:55:43, Santiago Ruano Rincón wrote: > &

Bug#821811: [Pkg-samba-maint] Bug#821811: samba: badlock patch breaks trust relationship

2016-05-23 Thread Andrew Bartlett
is point. I'm happy to review things, just not had the time to switch back on to debian matters. Andrew Bartlett -- Andrew Bartlett http://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Catalyst IT http://catalyst.net.nz/services/samba

Bug#820965: [regression]: net usersidlist: Could not malloc sid array Could not get the user/sid list

2016-04-14 Thread Andrew Bartlett
e. 'net cache flush' or similar may have helped. That is, I think wbcListUsers() returned 0 entries, which causes other code to think a realloc of length 0 'failed'. wbinfo -u would probably have failed in a similar way, but with a more useful error message. Andrew Bartlett -- Andrew Bartlett

Bug#808769: ldb: FTBFS on s390x

2016-01-06 Thread Andrew Bartlett
php?pkg=ldb=2%3A1.1.24-1 > https://buildd.debian.org/status/fetch.php?pkg=ldb=ppc64=2%3 > A1.1.24-1=1450397581 > https://buildd.debian.org/status/fetch.php?pkg=ldb=ppc64=2%3 > A1.1.24-1=1450616129 > > Regards > > Mathieu Parent > -- Andrew Bartlett http://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Catalyst IT http://catalyst.net.nz/services/samba

Bug#808769: [Pkg-samba-maint] Bug#808769: LDB build failure isn't a regression

2016-01-02 Thread Andrew Bartlett
On Sat, 2016-01-02 at 21:51 +, Jelmer Vernooij wrote: > On Sun, Jan 03, 2016 at 10:38:12AM +1300, Andrew Bartlett wrote: > > On Thu, 2015-12-31 at 18:53 +1300, Andrew Bartlett wrote: > > > Just a quick note to say that the LDB build failure isn't a > > > regression

Bug#808769: LDB build failure isn't a regression

2016-01-02 Thread Andrew Bartlett
On Thu, 2015-12-31 at 18:53 +1300, Andrew Bartlett wrote: > Just a quick note to say that the LDB build failure isn't a > regression > - whatever is going on here has always been going on, it just wasn't > tested before ldb 1.1.23. > That said, fixing this is going to requir

Bug#808769: [Pkg-samba-maint] Bug#808769: Bug#808769: LDB build failure isn't a regression

2016-01-02 Thread Andrew Bartlett
On Sat, 2016-01-02 at 22:22 +, Jelmer Vernooij wrote: > On Sun, Jan 03, 2016 at 11:00:44AM +1300, Andrew Bartlett wrote: > > On Sat, 2016-01-02 at 21:51 +, Jelmer Vernooij wrote: > > > On Sun, Jan 03, 2016 at 10:38:12AM +1300, Andrew Bartlett wrote: > > > > On

Bug#808769: LDB build failure isn't a regression

2015-12-30 Thread Andrew Bartlett
gative test for Dn.__contains__ Add a helper function to register a dummy DN extension for testing. Signed-off-by: Petr Viktorin <pvikt...@redhat.com> Reviewed-by: Andrew Bartlett <abart...@samba.org> Reviewed-by: Stefan Metzmacher <me...@samba.org> That sa

Bug#790777: [Pkg-samba-maint] Bug#790777: Bug#790777: Building with sbuild?

2015-09-01 Thread Andrew Bartlett
le for > all users? We can reproduce this at will on i686 Ubuntu images on the Catalyst cloud. Douglas chased it as far as the kernel page layout! It seems to come down to differences in opinion on how deep a nested stack should be able to go. Thanks, Andrew Bartlett -- Andrew Bartlett

Bug#762789: proposed fix for ppp CVE-2014-3158

2014-10-15 Thread Andrew Bartlett
also need a fix). This is my first fix for squeeze-lts, so I'm using this lower-impact issue to learn the ropes, so feedback most welcome. I'm also not yet a Debian Maintainer, but will apply for that soon so I can also do the announcement next time. Thanks! Andrew Bartlett -- Andrew Bartlett

Bug#762789: proposed fix for ppp CVE-2014-3158

2014-10-15 Thread Andrew Bartlett
On Thu, 2014-10-16 at 01:36 +0200, Marco d'Itri wrote: On Oct 16, Andrew Bartlett abartlet+deb...@catalyst.net.nz wrote: I've prepared a a fix for CVE-2014-3158, an integer overflow potentially permitting a user in the dip group to abuse the privileges of the setuid root pppd binary

Bug#762789: proposed fix for ppp CVE-2014-3158

2014-10-15 Thread Andrew Bartlett
On Thu, 2014-10-16 at 02:30 +0200, Marco d'Itri wrote: On Oct 16, Andrew Bartlett abartlet+deb...@catalyst.net.nz wrote: Thanks. How do you wish to proceed? I suggest that you just upload the package. Just to be clear, I'm not (yet) a Debian Maintainer, so I don't have upload rights

Bug#732342: Samba Stack Trace due to hdb interface change in Heimdal

2014-01-20 Thread Andrew Bartlett
On Sun, 2014-01-19 at 11:30 +1100, Brian May wrote: On 16 January 2014 14:03, Andrew Bartlett abart...@samba.org wrote: Can we get this patch into the Heimdal package, so we can fix that side of bug #732342? Once I know the version number

Bug#732342: Samba Stack Trace due to hdb interface change in Heimdal

2014-01-15 Thread Andrew Bartlett
On Wed, 2014-01-15 at 02:32 +1300, Andrew Bartlett wrote: On Thu, 2014-01-09 at 18:04 -0600, Jeff Clark wrote: No problem. Will send it over in a few hours. With all the false starts on this, I've sat on the patches until I can test it with the developer at Catalyst IT who also reproduced

Bug#732342: Stack Trace

2014-01-15 Thread Andrew Bartlett
On Tue, 2014-01-07 at 16:58 -0800, Steve Langasek wrote: On Wed, Jan 08, 2014 at 01:54:32PM +1300, Andrew Bartlett wrote: Reading symbols from /usr/lib/x86_64-linux-gnu/libhdb.so.9...Reading symbols from /usr/lib/debug/usr/lib/x86_64-linux-gnu/libhdb.so.9.2.0...done. done

Bug#732342: Samba Stack Trace due to hdb interface change in Heimdal

2014-01-14 Thread Andrew Bartlett
, and get the matching Heimdal patch in. Brian, This bug needs a patch to Heimdal as well as to Samba. I'll post you the patch once I've tested it, and then I guess we need to work on a stricter version dep here to make sure this all keeps in sync. Andrew Bartlett -- Andrew Bartlett

Bug#732342: Stack Trace

2014-01-09 Thread Andrew Bartlett
if anyone is interested. Thanks for looking into this. I was coming to exactly the same conclusion. For upstream, I'll patch Samba, can you submit the patch to Heimdal (feel free to CC me)? Thanks, Andrew Bartlett -- Andrew Bartlett http://samba.org/~abartlet/ Authentication Developer, Samba

Bug#732342: Stack Trace

2014-01-09 Thread Andrew Bartlett
On Fri, 2014-01-10 at 12:12 +1300, Andrew Bartlett wrote: On Thu, 2014-01-09 at 16:04 -0600, Jeff Clark wrote: Samba needs the hdb plugin updated to support hdb version 8. Heimdal needs the hdb callback function patched because even when the plugin is registered properly

Bug#732342: Stack Trace

2014-01-07 Thread Andrew Bartlett
corruption errors at runtime /before/ they clobber the stack. I strongly suspect in this and in 734355 that Heimdal and Samba have got out of sync. We use libhdb (and other parts) from Heimdal in a quite intimate manner. Andrew Bartlett -- Andrew Bartlett http://samba.org/~abartlet/ Authentication

Bug#732342: Stack Trace

2014-01-07 Thread Andrew Bartlett
On Tue, 2014-01-07 at 16:58 -0800, Steve Langasek wrote: On Wed, Jan 08, 2014 at 01:54:32PM +1300, Andrew Bartlett wrote: Reading symbols from /usr/lib/x86_64-linux-gnu/libhdb.so.9...Reading symbols from /usr/lib/debug/usr/lib/x86_64-linux-gnu/libhdb.so.9.2.0...done. done

Bug#732342: [Pkg-samba-maint] Bug#732342: Stack Trace

2014-01-07 Thread Andrew Bartlett
On Wed, 2014-01-08 at 14:29 +1300, Andrew Bartlett wrote: On Tue, 2014-01-07 at 16:58 -0800, Steve Langasek wrote: On Wed, Jan 08, 2014 at 01:54:32PM +1300, Andrew Bartlett wrote: Reading symbols from /usr/lib/x86_64-linux-gnu/libhdb.so.9...Reading symbols from /usr/lib/debug

Bug#726472: [Pkg-samba-maint] Bug#726472: share passwords not working after upgrade from samba3

2013-11-02 Thread Andrew Bartlett
should be fixed by the earlier changes. Thank you so much for you diligent attention to this difficult problem. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To UNSUBSCRIBE

Bug#726472: [Pkg-samba-maint] Bug#726472: share passwords not working after upgrade from samba3

2013-10-30 Thread Andrew Bartlett
On Wed, 2013-10-30 at 10:22 +0100, Ivo De Decker wrote: Hi Andrew, On Wed, Oct 30, 2013 at 11:34:25AM +1300, Andrew Bartlett wrote: That'll also cause some confusion though, as those files will be in sysstatedir on debian but in privatedir on other systems... I'm not sure

Bug#726472: [Pkg-samba-maint] Bug#726472: share passwords not working after upgrade from samba3

2013-10-29 Thread Andrew Bartlett
On Tue, 2013-10-29 at 00:35 +0100, Jelmer Vernooij wrote: On Mon, Oct 28, 2013 at 10:00:12PM +0100, Ivo De Decker wrote: Hi, On Mon, Oct 21, 2013 at 10:37:49PM +1300, Andrew Bartlett wrote: Ok. I think we need to undo this /var/lib/samba/private nonsense. It is a pointless

Bug#726472: share passwords not working after upgrade from samba3

2013-10-28 Thread Andrew Bartlett
On Mon, 2013-10-28 at 22:00 +0100, Ivo De Decker wrote: Hi, On Mon, Oct 21, 2013 at 10:37:49PM +1300, Andrew Bartlett wrote: Ok. I think we need to undo this /var/lib/samba/private nonsense. It is a pointless and imperfect migration (as shown by this bug report), and the only

Bug#726472: share passwords not working after upgrade from samba3

2013-10-21 Thread Andrew Bartlett
not change it again, having once more Debian packages special and different. Or in the alternate, propose such changes upstream. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org

Bug#726726: [Pkg-samba-maint] Bug#726726: Bug#726726: Bug#726726: Bug#726726: samba: Unable to share printer using cups

2013-10-21 Thread Andrew Bartlett
on a affected system? Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact

Bug#726726: [Pkg-samba-maint] Bug#726726: Bug#726726: Bug#726726: Bug#726726: samba: Unable to share printer using cups

2013-10-21 Thread Andrew Bartlett
On Mon, 2013-10-21 at 12:20 +0200, Ivo De Decker wrote: Hi Andrew, On Mon, Oct 21, 2013 at 10:45:22PM +1300, Andrew Bartlett wrote: Almost certainly this is due to the output of cups-config. We have had similar issues before, including a patch posted to the list just last week. Can

Bug#726726: [Pkg-samba-maint] Bug#726726: Bug#726726: Bug#726726: Bug#726726: samba: Unable to share printer using cups

2013-10-21 Thread Andrew Bartlett
On Mon, 2013-10-21 at 12:44 +0200, Ivo De Decker wrote: Andrew, On Mon, Oct 21, 2013 at 11:32:14PM +1300, Andrew Bartlett wrote: cups-config --libs: -lcups -Wl,-z,relro -lgssapi_krb5 -lkrb5 -lk5crypto -lcom_err -lgnutls -lgcrypt -lz -lpthread -lm -lcrypt -lz cups-config

Bug#726472: share passwords not working after upgrade from samba3

2013-10-18 Thread Andrew Bartlett
that this was the case? Samba should print it's version in the logs when starting up. We changed the default passdb backend long before 3.6. Is there as passdb.tdb anywhere else on your system? Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication

Bug#726472: share passwords not working after upgrade from samba3

2013-10-17 Thread Andrew Bartlett
to one using tdbsam by default, but I can't find any evidence in the packaging source tree for that. Steve, how was this handled at the time? Thanks, Andrew Bartlett -- Andrew Bartlett http://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer

Bug#716932: samba: Source package fails to unpack (fuzz is now allowed when applying patches)

2013-07-15 Thread Andrew Bartlett
: pbuilder: Failed extracting the source All because we carry a patch to add a source copy of a build system we don't use and which upstream removes essential files from (so won't work anyway). (In versions where we use waf in Debian, the waf code has been included as source). Andrew Bartlett

Bug#713097: [Pkg-samba-maint] Bug#713097: Bug#713097: samba4: FTBFS: ValueError: command execution failed: /usr/bin/python2.7 /usr/bin/python2.7-config --includes - ''

2013-06-23 Thread Andrew Bartlett
version of Samba including the fix upstream. That said, I don't propose we do anything other than migrate samba4 in from experimental to fix this. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http

Bug#705908: [Pkg-samba-maint] Bug#705908: libsamba-credentials.so.0.0.1 links libdbwrap.so but libsamba-credentials0 missing dep on python-samba

2013-06-21 Thread Andrew Bartlett
samba_4.0, so that is where the effort needs to be made. Thanks, Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org

Bug#705908: [Pkg-samba-maint] Bug#705908: Bug#705908: libsamba-credentials.so.0.0.1 links libdbwrap.so but libsamba-credentials0 missing dep on python-samba

2013-06-21 Thread Andrew Bartlett
On Fri, 2013-06-21 at 10:33 +0200, Raphael Hertzog wrote: On Fri, 21 Jun 2013, Andrew Bartlett wrote: dbwrap*.so is now in samba-common-bin. The issue is that this almost certainly depends on the credentials library, so we may need yet another library package, or to re-consider

Bug#519570: [Pkg-samba-maint] Bug#519570: Bug#519570: Kerberos working on samba 3.2.5 PDC, but failing when joining the domain

2009-03-15 Thread Andrew Bartlett
documentations. That is because aside from interesting hacks with Linux clients, the only Samba Kerberised DC is Samba4. (and yes, running Heimdal as the KDC and Samba for windows works, but it isn't a kerberised DC). Andrew Bartlett -- Andrew Bartlett http://samba.org/~abartlet/ Authentication

Bug#383592: samba processes crash due to incorrect access of tdbsam

2006-08-18 Thread Andrew Bartlett
syntax changes. Our list code allows these separators. If you can point me to some resource that said to use the comma, then I'll happily implement that check. I'm pretty sure it has been standard smb.conf syntax for a very long while. Andrew Bartlett -- Andrew Bartlett

Bug#382429: samba: problem detecting network interfaces

2006-08-15 Thread Andrew Bartlett
. That said, a system that can't even report that the loopback device exists is a pretty poor system... Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Red Hat Inc

Bug#312513: [ANDREW] Re: Bug#312513: winbind 3.0.14a-4 (sarge) breaks samba ADS member server

2005-06-23 Thread Andrew Bartlett
of this. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Samba Developer, SuSE Labs, Novell Inc.http://suse.de Authentication Developer, Samba Team http://samba.org Student Network Administrator, Hawker College http://hawkerc.net

Bug#310982: smbmount does not honor uid and gid options with 2.4 kernel

2005-05-29 Thread Andrew Bartlett
-0700, Steve Langasek wrote: On Sat, May 28, 2005 at 05:17:39AM +1000, Andrew Bartlett wrote: Yeah, on second look I see that it can be done in smbmount, and this would be a far more expedient fix. You mean something like the patch below ? (Not tested yet, want to be sure

Bug#310982: smbmount does not honor uid and gid options with 2.4 kernel

2005-05-28 Thread Andrew Bartlett
On Sat, 2005-05-28 at 18:39 +0200, Bill Allombert wrote: On Fri, May 27, 2005 at 12:20:49PM -0700, Steve Langasek wrote: On Sat, May 28, 2005 at 05:17:39AM +1000, Andrew Bartlett wrote: Yeah, on second look I see that it can be done in smbmount, and this would be a far more expedient fix

Bug#310982: smbmount does not honor uid and gid options with 2.4 kernel

2005-05-27 Thread Andrew Bartlett
/gid options have been passed to mount. This is also a very sensible way to handle it, and is the only 'secure' way, given that smbmount is unprivileged. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team

Bug#302771: my konqueror, smbc, smbclient versions

2005-05-08 Thread Andrew Bartlett
the client and server code. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Student Network Administrator, Hawker College http://hawkerc.net signature.asc Description: This is a digitally

Bug#302378: samba: smbd exits with SIGABRT

2005-04-07 Thread Andrew Bartlett
will end up in the normal Samba logfiles (we redirect stderr). Thanks, Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Student Network Administrator, Hawker College http://hawkerc.net

Bug#302378: bug confirmed

2005-04-04 Thread Andrew Bartlett
trace of the deamon crashing, to find where the double-free is. Andrew Bartlett -- Andrew Bartletthttp://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Student Network Administrator, Hawker College http://hawkerc.net