<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<html lang="en" style='--code-editor-font: var(--default-mono-font, "GitLab Mono"), JetBrains Mono, Menlo, DejaVu Sans Mono, Liberation Mono, Consolas, Ubuntu Mono, Courier New, andale mono, lucida console, monospace;'>
<head>
<meta content="text/html; charset=utf-8" http-equiv="Content-Type">
<title>
GitLab
</title>
<style data-premailer="ignore" type="text/css">
a { color: #1068bf; }
</style>
<style>img {
max-width: 100%; height: auto;
}
body {
font-size: .875rem;
}
body {
-webkit-text-shadow: hsla(0,0%,100%,.01) 0 0 1px;
}
body {
font-family: "GitLab Sans",-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,"Noto Sans",Ubuntu,Cantarell,"Helvetica Neue",sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol","Noto Color Emoji"; font-size: inherit;
}
</style>
</head>
<body style='font-size: inherit; -webkit-text-shadow: hsla(0,0%,100%,.01) 0 0 1px; font-family: "GitLab Sans",-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,"Noto Sans",Ubuntu,Cantarell,"Helvetica Neue",sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol","Noto Color Emoji";'>
<div class="content">
<h3 style="margin-top: 20px; margin-bottom: 10px;">
Timo Aaltonen pushed to branch upstream at <a href="https://salsa.debian.org/sssd-team/sssd">Debian SSSD packaging / sssd</a>
</h3>
<h4 style="margin-top: 10px; margin-bottom: 10px;">
Commits:
</h4>
<ul>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/ab7a7f438bebdce156a68890a3367250514f4ae6">ab7a7f43</a></strong>
<div>
<span> by Dan Lavu </span> <i> at 2026-01-15T12:02:38-06:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>removing netgroup intg test
Reviewed-by: Scott Poore <spoore@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/6afffacf298222d0f5857f1733f5671f611b57d2">6afffacf</a></strong>
<div>
<span> by Pavel Březina </span> <i> at 2026-01-16T10:00:24+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update version in version.m4 to track the next release
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/8b0071c64eb736c231f2ab53b0cd106912cd17bc">8b0071c6</a></strong>
<div>
<span> by aborah-sudo </span> <i> at 2026-01-16T14:03:50+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Tests: Handle SELinux in proxy provider tests
Tests using nslcd fail under SELinux enforcing due to missing
policies for test-only nss-pam-ldapd configuration. Add context
manager to temporarily set permissive mode for affected tests.
Reviewed-by: Jakub Vávra <jvavra@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/e73250b1e6652d36e18fbc06cf3d8f4f93a1ccef">e73250b1</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-01-19T12:17:58+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>SPEC: since Fedora 44 Samba provides dedicated 'samba-ndr-libs' package
with libraries needed by 'sssd-ipa'.
Note that 'sssd-ad' still needs 'samba-client-libs'
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/ee081e11fa0017fea4d6097125ec69ac9afdbfb7">ee081e11</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-01-19T15:51:48+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>SBUS: increase SBUS_MESSAGE_TIMEOUT to 5 mins
Handling BE_REQ_INITGROUPS for LDAP user with 10k groups takes longer
than 2 mins.
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/7762901c3e94cf8adfbc058d2e3e540188cbc76c">7762901c</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-01-19T15:51:48+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>RESPONDER: fixed an issue with 'client_idle_timer'
As it was implemented previously, effective period was 1.5*client_idle_timeout
instead of `client_idle_timeout` as documented.
Log with default value - 60 - before a fix:
```
(:49:12): [nss] [setup_client_idle_timer] (0x4000): Idle timer re-set for client [0x557af16f31b0][22]
(:49:42): [nss] [setup_client_idle_timer] (0x4000): Idle timer re-set for client [0x557af16f31b0][22]
(:50:12): [nss] [setup_client_idle_timer] (0x4000): Idle timer re-set for client [0x557af16f31b0][22]
(:50:42): [nss] [client_idle_handler] (0x2000): Terminating idle client [0x557af16f31b0][22]
```
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/96829a000cb91ea18fb30f118c62d5554c431475">96829a00</a></strong>
<div>
<span> by Justin Stephenson </span> <i> at 2026-01-19T10:15:23-06:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>tests: python black 26.1.0 style changes
Adapt to changes from https://github.com/psf/black/releases/tag/26.1.0
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Scott Poore <spoore@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/f8c281cfe1aa7c449c0e389b422a7904b1a929af">f8c281cf</a></strong>
<div>
<span> by Scott Poore </span> <i> at 2026-01-19T11:03:15-06:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Tests: Add GDM Smartcard tests
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/d78e326783beb58a81b6ca29269cec720f858f0f">d78e3267</a></strong>
<div>
<span> by Scott Poore </span> <i> at 2026-01-19T11:03:15-06:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Tests: gdm passkey fixes for timing issues in c10s
Also removing unused GenericProvider references and update some
docstrings.
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/7f78c93f152d8bbddc66b495f69bb981e3901bc3">7f78c93f</a></strong>
<div>
<span> by Scott Poore </span> <i> at 2026-01-19T11:03:15-06:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Tests: rename and update test_gdm to xidp
Renaming test_gdm.py to test_gdm_xidp.py to align with the other
test_gdm_* test modules.
Also adding authselect for with-switchable-auth which is needed to
configure the system for GDM to use the new switchable authentication
mechanisms.
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/35e32b77db0beb20e5620dbc860cd18a08f2169d">35e32b77</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-01-20T11:01:44+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>UTILS: comment fixed
'child_common.c' was renamed to 'child_handlers.c' in 8bddb6a510c3c1a88e31d43c6b1c66709be53193
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/743b8d33f92877578debf8b23f9d77066de17750">743b8d33</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-01-20T11:01:44+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Makefile: 'libsss_child' doesn't need to be part of 'libsss_util'
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/704f36333244518ae6a4e6cb97aabfbcf107e0d9">704f3633</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-01-20T11:01:44+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Makefile: don't link against 'KEYUTILS_LIBS'
where it's not needed
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/25dcf242d9bede6d717084e7da5ce74ef56a33be">25dcf242</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-01-20T11:01:44+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>UTILS: get rid of 'selinux.c'
It's not used since 15a22136e19f192c03758c21fa8e48697fa16857
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/2112b6eb05b2b538fc508d94f3f9ead197958415">2112b6eb</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-01-20T11:01:44+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Makefile: removed some duplicates
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/8d376e8cf6e0bf733f6e9f010ccec7589118959f">8d376e8c</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-01-20T11:01:44+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Makefile: `libsss_crypt` doesn't need `libdhash`
`SSS_CRYPT_*` vars also do not make much sense.
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/f2a4ce27dd8c5bca7fe5d80d2b58ceb8286569d0">f2a4ce27</a></strong>
<div>
<span> by Gleb Popov </span> <i> at 2026-01-20T17:54:11+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>FreeBSD CI: Switch to FreeBSD 15
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/46fb30abda6914a2eaccced4c5d76956f4bc99df">46fb30ab</a></strong>
<div>
<span> by Gleb Popov </span> <i> at 2026-01-20T17:54:11+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>FreeBSD CI: Enable testing and run the build with -j
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/165f5112943ffb13969a38c820e0722287ddd867">165f5112</a></strong>
<div>
<span> by Gleb Popov </span> <i> at 2026-01-20T17:54:11+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>FreeBSD CI: Remove the timezone patch for FreeBSD 14 and add another one
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/af8ef967a81c7d7254a0a9557b79ac67d2ed47c8">af8ef967</a></strong>
<div>
<span> by Gleb Popov </span> <i> at 2026-01-20T17:54:11+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Use portable shebangs in tests scripts
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/308bacbd22f2f5a483cb2cef098082b5f9625b8d">308bacbd</a></strong>
<div>
<span> by Gleb Popov </span> <i> at 2026-01-20T17:54:11+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Skip whitespace and double semicolon tests on FreeBSD
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/26350606aad694dce5c0651f47d1973efa7a3a43">26350606</a></strong>
<div>
<span> by Gleb Popov </span> <i> at 2026-01-20T17:54:11+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>FreeBSD CI: Add some more deps and make configure flags match what our port does
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/d78f89cde44f449e5d8b4090231d8d92ea1e6821">d78f89cd</a></strong>
<div>
<span> by Gleb Popov </span> <i> at 2026-01-20T17:54:11+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>test_responder_common.c: Use correct value to check against
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/e4eb8bdc006e800fe2f875de9f447bc8a8478bb1">e4eb8bdc</a></strong>
<div>
<span> by Gleb Popov </span> <i> at 2026-01-20T17:54:11+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>test_pam_srv: Use more random UIDs/GIDs for the test
On FreeBSD the UID 123 corresponds to the built-in ntpd user and the machine
that runs this test may be running the ntpd daemon.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/7d8e3c333fb167e8723047e963a70806fb9cb8f8">7d8e3c33</a></strong>
<div>
<span> by Pavel Březina </span> <i> at 2026-01-21T14:44:52+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>scripts: fetch branch before checkout in release script
actions/checkout does a sparse clone by default so the branch may not
be yet available.
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/0fc52802f762a38d96c9e572d9a024b3ea9d0fe1">0fc52802</a></strong>
<div>
<span> by Timo Eisenmann </span> <i> at 2026-01-22T10:56:59+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Add OAuth2 prompting config
:config: New options to customize the OAuth2 prompting behavior:
`interactive` and `interactive_prompt`.
Reviewed-by: Iker Pedrosa <ipedrosa@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/870619c42f9852e9299a4ebbce24217b1ae009f2">870619c4</a></strong>
<div>
<span> by Timo Eisenmann </span> <i> at 2026-01-22T10:56:59+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>sss_client: deduplicate string copying in pc_list_from_response
Reviewed-by: Iker Pedrosa <ipedrosa@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/a50a9529d97cd6aa52afd387261cf4032ccf341c">a50a9529</a></strong>
<div>
<span> by Timo Eisenmann </span> <i> at 2026-01-22T10:56:59+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Add test for OAuth2 prompting config
Reviewed-by: Iker Pedrosa <ipedrosa@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/dd3cd958d5b06e2429921ae46feeddfe137a1f7e">dd3cd958</a></strong>
<div>
<span> by Iker Pedrosa </span> <i> at 2026-01-24T10:39:59+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>krb5_child: fix enterprise principal parsing in keep-alive sessions
When keep-alive sessions transition between command types (e.g., from
SSS_PAM_PREAUTH to SSS_PAM_AUTHENTICATE), enterprise principal settings
were not being updated, causing parsing inconsistencies in complex AD
environments.
This change ensures that when the backend sends updated enterprise
principal settings for different command types, the principals are
correctly re-parsed with the appropriate flags, fixing UPN handling in
multi-domain AD environments.
Signed-off-by: Iker Pedrosa <ipedrosa@redhat.com>
Reviewed-by: Alejandro López <allopez@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/f95f64f52614edc682de911a0f3a6cecea330c64">f95f64f5</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-01-27T16:08:16+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>CONFIG: allow 'ldap_subuid_*' attrs
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/4ca8bb655a5cfa717fe0ba512326c2f542dde7d5">4ca8bb65</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-01-29T15:27:38+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>pam_sss: change PAM message type for PIN locked
To make sure GDM can display this message together with an
authentication failed error message the PAM message type has to be the
same.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Iker Pedrosa <ipedrosa@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/bc3ad168e1b5ef07c11488cd745446d799ff8fd2">bc3ad168</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-01-29T15:27:38+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>krb5: check for PIN locked in error message
Currently the PIN locked message is only displays if the Smartcard
authentication is done locally, e.g. if the system is offline. During
pkinit libkrb5 does not send a dedicated error code but the error
message generated by the library contains a hint.
This patch checks the libkrb5 error message in case the authentication
fails with the pre-authentication failed error code. This is a bit
tricky because 'krb5_get_error_message()' currently only returns a
defined result at the first call after a failed library call.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Iker Pedrosa <ipedrosa@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/498974b843ee3cce3b9d5681419643243c0e0402">498974b8</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-01-30T09:30:09+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>RESPONDER: fix `responder_set_fd_limit()`
to not even try setting hard limit as SSSD never has CAP_SYS_RESOURCE
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/308af8f215eea347a32d068e658d99bb1bfb2ba9">308af8f2</a></strong>
<div>
<span> by Gleb Popov </span> <i> at 2026-01-31T10:02:03+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>platform.m4: Fix case when we have to source /etc/os-release
When sourcing this file it may overwrite the VERSION shell variable, which
in turn end up being used for @VERSION@ substitutions in various .in files.
While here, make sure we always set $osname to something sensible too.
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/a7fb84376fe0baad8156fd97fecc5fc98912d034">a7fb8437</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-02-03T11:12:52+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>PO: remove stray </arg> from translation
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/af5fbd52e2745b83b6c7c58047b313e1b492492f">af5fbd52</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-02-03T11:12:52+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>PO: add missing <placeholder ...> tag
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/29a8731d23d67b2e9641ff4e97fa9be15f4a8fe3">29a8731d</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-02-03T12:34:38+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix libini_config related includes.
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/ee42c35db951619aed7545020f6d7c0e0b8c0b8a">ee42c35d</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-02-03T12:34:38+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>INI: get rid of useless macros
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/ade61ef1bac6aa2f6d91a25b39417a93375ed3ed">ade61ef1</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-02-03T12:34:38+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>INI: use proper deallocators
This also allows to avoid inclusion of 'ini_config.h'
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/4e89caeb9f3b9dee86ccbe25cd601848eb5256c4">4e89caeb</a></strong>
<div>
<span> by Pavel Březina </span> <i> at 2026-02-03T18:33:38+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>errors: add ERR_SERVER_FAILURE
To indicate server communication error.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/cc42932ac4c58c681d4d928b53f2803bbb9ad277">cc42932a</a></strong>
<div>
<span> by Pavel Březina </span> <i> at 2026-02-03T18:33:38+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>sdap: remove be context from sdap_cli_connect code
This is a steps towards new implementation of new failover mechanism.
The new code will reuse sdap_cli_connect to connect to the LDAP server
but it will not use any be resolver stuff. This patch moves be resolver
usage one level up so the connection code can be easily reused.
It also moves kinit before connecting to LDAP into a separate,
standalone step (previously it was connect -> kinit -> sasl bind,
now it is kinit -> connect -> sasl bind).
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/07401d6263332fc75a75577ebdde6ce55afb0cc3">07401d62</a></strong>
<div>
<span> by Jakub Vávra </span> <i> at 2026-02-05T20:51:50+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Test: Update misc ipa tests to work correctly on stig
The custom ssh library previously used in the tests does not work
correctly on stig as the test are testing sudo, replacing ssh
with su to switch user.
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/003c591a351792a2a7eaaa32ddcc7325e7672b94">003c591a</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-02-06T08:36:50+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>CHILD HELPERS: use less severe debug level
if `child_sig_handler()` is called for unknown pid.
If there are N handlers registered and 1 child process exists,
all N handlers will be invoked, and N-1 of them will get
`waitpid() == 0`.
It would be possible to have a single handler registed that would
manage a list (or hash table) of `sss_child_ctx`, but it still
would have to perform N `waitpid()` calls (`waitpid(-1)` can't
be used to avoid handling "foreign" process) so complexity overhead
doesn't worth it.
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/bcd9998f02c83b548788f205317cda81b5a5400a">bcd9998f</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-02-06T11:56:18+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>man: add details about 'an2ln'
With a recent security fix the 'an2ln' module was disabled in SSSD's
configuration snippet for the localauth configuration of libkrb5. With
this patch the related man page is update accordingly.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/0458e655673e5ad9ea7478582b79559ea1a3bbc7">0458e655</a></strong>
<div>
<span> by Dan Lavu </span> <i> at 2026-02-06T14:19:43+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>updating subid test case to test provider_ldap config
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Jakub Vávra <jvavra@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/ad173e057969289b645659281f415e8368786f6b">ad173e05</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-02-17T08:46:21+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>sdap: do not require GID for non-POSIX group
In 85b632d130d126861bda7472f7a7ae301e70c098 the attribute for the GID
was removed from non-POSIX groups. Currently sdap_save_group() still
requires the attribute and this patch removes this.
sdap_save_group() is currently only used in the code path handling
nested groups. To verify the change a test was added were indirect
group-members are coming from a nested non-POSIX group.
Resolves: https://github.com/SSSD/sssd/issues/8441
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/09e283e22c7ea23b520538e948e3bcb1178dd617">09e283e2</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-02-17T15:56:17+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>SDAP: use `DEBUG_CONDITIONAL` in hot path
Both `perf` and manual measurement confirms ~6..8% perf gain
in the test case:
- INITGROUPS lookup for a user that is a member of 5k groups,
no groups were cached;
- debug_level = 3
- debug_microseconds = true
Note `debug_microseconds = true` - without this setting impact isn't
that dramatic.
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/9a2cf21228b126016f3118c53dc7b47d94a1664d">9a2cf212</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-02-17T15:56:17+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>UTIL: `sss_tc_utf8_str_tolower()` optimization
In vast majority of cases strings are ascii and lowercase.
In other cases overhead added should be negligible.
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/a5b77e42916bcaebb898d01932c9247ca129bbbf">a5b77e42</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-02-17T15:56:17+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>UTIL: `sss_create_internal_fqname()` optimization (caching)
This helper is heavily used, including in hot paths.
Since number of domains used is very limited, hash table used for caching
should be very small and lookup much more efficient as compared with
`sss_tc_utf8_str_tolower()`
Assisted-by: Claude Code (Opus 4.6)
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/157194618adcbb103c827998cb82a087838a1800">15719461</a></strong>
<div>
<span> by aborah-sudo </span> <i> at 2026-02-18T08:32:22+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>tests: reorganize infopipe tests by interface
Group the infopipe tests into logical sections based on the D-Bus
interface they exercise:
- Infopipe (root object)
- Domains
- Users
- Groups
- Mixed/Combined interfaces
This is a pure reorganization with no logic changes to improve test
maintainability and readability.
Reviewed-by: Jakub Vávra <jvavra@redhat.com>
Reviewed-by: Shridhar Gadekar <sgadekar@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/b4336056dc65029c61e86a2c146da2d7735efc28">b4336056</a></strong>
<div>
<span> by squiddim </span> <i> at 2026-02-19T14:42:08+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>systemd: relaunch sssd after unclean exit
Resolves: #6219
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Alejandro López <allopez@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/d87b96f117f45b2cd70527d623f9da47720b8b04">d87b96f1</a></strong>
<div>
<span> by Justin Stephenson </span> <i> at 2026-02-19T14:53:11+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>ci: Skip GPG checks when installing rawhide sssd rpms
At this time, workaround rawhide dnf issue causing failed install
Total size of inbound packages is 11 MiB. Need to download 0 B.
After this operation, 30 MiB extra will be used (install 40 MiB, remove 10 MiB).
Running transaction
Transaction failed: Rpm transaction failed.
Warning: skipped OpenPGP checks for 60 packages from repository: @commandline
- package sssd-2.13.0-0.fc45.x86_64 does not verify: no signature
- package sssd-common-2.13.0-0.fc45.x86_64 does not verify: no signature
...
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/2de37515b52ae571b19689ac0c9d7f6720ef9fe5">2de37515</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-02-23T15:19:50+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>UTIL: fix discarded-qualifiers warning in domain_to_basedn()
Use a separate `const char *dot` variable for the strchr() result
on the const input string, keeping the mutable `char *p` for the
later iteration over the output buffer.
Implementation-By: Claude Code (Opus 4.6)
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/5548493c7b4d6196c20bcf235e1040ab405b4175">5548493c</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-02-23T15:19:50+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>SDAP: fix discarded-qualifiers warning in are_sids_from_same_dom()
Make rid1 and rid2 `const char *` since they only hold strrchr()
results from const input strings and are used for pointer arithmetic.
Implementation-By: Claude Code (Opus 4.6)
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/ef104b784da9050ac244170c1fb9f038043ed65b">ef104b78</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-02-23T15:19:50+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>SDAP: fix discarded-qualifiers warnings in sdap_parse_range()
Make endptr and end_range `const char *` since they only hold
strchr()/strrchr() results from const input strings. Introduce a
separate `numendptr` variable for the strtouint32() output parameter.
Implementation-By: Claude Code (Opus 4.6)
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/086a52e5d1c0ec9454ca377438faef6d318d4a6a">086a52e5</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-02-23T15:19:50+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>SDAP: fix discarded-qualifiers warning in split_extra_attr()
Make sep `const char *` since it only holds a strchr() result
from a const input string and is used for pointer arithmetic.
Implementation-By: Claude Code (Opus 4.6)
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/0f21660dabb472753d004f7061b80a00f0af0d71">0f21660d</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-02-23T15:19:50+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>AD: fix discarded-qualifiers warnings in ad_access filter parsing
Make specdelim and kwdelim `const char *` in parse_sub_filter() and
parse_filter() since they only hold strchr() results from const
input strings and are used for pointer arithmetic.
Implementation-By: Claude Code (Opus 4.6)
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/24de2bc0aeba7909e1164c854384e543940cd81d">24de2bc0</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-02-23T15:19:50+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>CERTMAP: fix discarded-qualifiers warnings in sss_certmap.c
Make delim in get_type_prefix() and sep in expand_sid() `const char *`
since they only hold strchr()/strrchr() results from const input
strings and are used for pointer arithmetic and reading.
Implementation-By: Claude Code (Opus 4.6)
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/68edad94bafc3bf1cf272181fa4f8245acc5fd20">68edad94</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-02-23T15:19:50+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>KRB5: fix discarded-qualifiers warning in compare_principal_realm()
Make at_sign `const char *` since it only holds a strchr() result
from a const input string and is used for reading.
Implementation-By: Claude Code (Opus 4.6)
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/9e517f84bf4f377bb2e78e706124997fbd5a8176">9e517f84</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-02-23T15:19:50+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Makefile: add missing 'CMOCKA_CFLAGS'
Assisted-By: Claude Code (Opus 4.6)
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/39db12dc3c47a61fbd130193ae5b261ceeefd03e">39db12dc</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-02-23T15:19:50+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>BUILD: supress 'deprecated-declarations' error for cmocka tests
Older Fedora versions still have cmocka < 2.0.0 making it
inconvinient to support two interfaces.
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/54c634033817205c33073fc5187fabffa0aee051">54c63403</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-02-23T15:19:50+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>BUILD: fix _POSIX_C_SOURCE redefinition with Python 3.14 and glibc 2.41+
Python 3.14's pyconfig-64.h defines _POSIX_C_SOURCE=200809L and
_XOPEN_SOURCE=700, but glibc 2.41+ headers (pulled in earlier via
sss_nss_idmap.h) already define them to higher values (202405L and
800). This causes -Werror redefinition errors when building the Python
extension modules.
Assisted-By: Claude Code (Sonnet 4.6)
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/f91c7bbc38e41eeb31f2132acc7263bd4ac9d47c">f91c7bbc</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-02-24T10:21:16+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>sdap: eliminate O(N^2) loop in `sdap_add_incomplete_groups()`
`sdap_add_incomplete_groups()` had two separate steps: first it
iterated the group name list checking each against sysdb to build
a 'missing' list, then for each missing group it scanned the entire
'ldap_groups' array calling to find matching LDAP attributes.
This resulted in O(N^2) behavior when all groups were missing (i.e.
empty cache).
Replace this with a single O(N) loop that iterates 'ldap_groups'
directly: check sysdb, and if missing create the incomplete entry
immediately.
The 'sysdb_groupnames' parameter is removed as it is not used
anymore.
This patch also has an interesting side effect: it also makes
`sysdb_update_members()` executed in the `sdap_initgr_common_store()`
after `sdap_add_incomplete_groups()` faster. Most probably this
is because previosuly O(N^2) allocations of `groupname` (by
`sdap_get_group_primary_name()`) trashed memory, purging ldb/tdb
data from the cache.
Implementation assisted-by: Claude Code (Opus 4.6)
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/2cdaaa47aa5eddcff9af784e227d981b40681120">2cdaaa47</a></strong>
<div>
<span> by Madhuri Upadhye </span> <i> at 2026-02-24T12:30:53+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix test_sudo__case_sensitive_false: use /bin/ls and /bin/cat instead of less/more
test_sudo__case_sensitive_false runs sudo via su -c (no TTY). less and more exit
non-zero without a terminal, so the test failed. Switched to /bin/ls and /bin/cat
so the run is non-interactive; the test still checks case-insensitive sudo rule
merging for user-1 and USER-1.
Assisted-by: Cursor (Composer-1.5)
Signed-off-by: Madhuri Upadhye <mupadhye@redhat.com>
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Shridhar Gadekar <sgadekar@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/c6dc4d7af4d61ad6c50d0bfcb3d01c6d185f73c9">c6dc4d7a</a></strong>
<div>
<span> by Gleb Popov </span> <i> at 2026-02-24T18:21:52+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>FreeBSD CI: Pass correct paths to adcli and realm programs
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/404d166a6a56630933e05b29254de7558b17c79c">404d166a</a></strong>
<div>
<span> by Gleb Popov </span> <i> at 2026-02-26T10:16:26+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>sdap_select_principal_from_keytab_sync: waitpid() synchronously
Without this change the ldap_child process started by this function ends up
in the <defunct> state. kernel trace hints that the process isn't fully
finished by the time waitpid is called:
13126 sssd_be CALL wait4(13127,0,0x1<WNOHANG>,0)
13126 sssd_be RET wait4 0
waitpid(ldap_child) failed, process might be leaking
According to man waitpid(3), the function returns 0 when passed WNOHANG and
there is no child process that can be reported as exited. Omitting WNOHANG
fixes the issue.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Iker Pedrosa <ipedrosa@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/b970e7facc96ea7a632977ef3ee547f7c763c361">b970e7fa</a></strong>
<div>
<span> by Gleb Popov </span> <i> at 2026-02-27T09:11:58+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Print a bit more information in the debugging output of resolv_is_address() and get_client_cred()
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Iker Pedrosa <ipedrosa@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/64ee91fa560a22807869347ccbf3b17cd315c2a7">64ee91fa</a></strong>
<div>
<span> by Gleb Popov </span> <i> at 2026-02-27T09:11:58+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>getsockopt: Pass correct option level value on FreeBSD
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Iker Pedrosa <ipedrosa@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/8c1e20b23ce0412a7cf7e452b20db6896492a0a7">8c1e20b2</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-03-02T10:34:50+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>LDAP: free tmp var within the loop
inside `sdap_add_incomplete_groups()` to avoid memory pressure
/ cache trashing if handling large groups set.
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/b4e88e833bc27ac2059c4203ea90d5f2b62808d8">b4e88e83</a></strong>
<div>
<span> by Dan Lavu </span> <i> at 2026-03-04T09:10:51-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>adding sss_ssh_knownhosts test case
Reviewed-by: Anuj Borah <aborah@redhat.com>
Reviewed-by: Alejandro López <allopez@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/03b7441039c03a72237c6f268001bc0276c74027">03b74410</a></strong>
<div>
<span> by Iker Pedrosa </span> <i> at 2026-03-06T09:16:36+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>ci: install and load kernel module for passkey testing
virtual-fido requires `vhci-hcd` kernel module to be loaded to work
Signed-off-by: Iker Pedrosa <ipedrosa@redhat.com>
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
Reviewed-by: Scott Poore <spoore@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/dc6970c2ae554399430ba26791f98047de2f4a9f">dc6970c2</a></strong>
<div>
<span> by Christopher Byrne </span> <i> at 2026-03-06T12:40:31+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>src/sss_client/common.c: Use getpwnam_r to avoid clobbering struct passwd
If something else uses PAM (like openrc, see
https://github.com/OpenRC/openrc/pull/984) and getpwnam, and calls
something like pam_open_session, sssd's call to getpwnam in
init_sssd_ids clobbers the cached value by the other program.
Signed-off-by: Christopher Byrne <salah.coronya@gmail.com>
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/7328fbdb8ff67608bb528e1926692f64b608db00">7328fbdb</a></strong>
<div>
<span> by dependabot[bot] </span> <i> at 2026-03-06T16:56:38+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>ci: bump actions/upload-artifact from 6 to 7
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 6 to 7.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](https://github.com/actions/upload-artifact/compare/v6...v7)
---
updated-dependencies:
- dependency-name: actions/upload-artifact
dependency-version: '7'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Reviewed-by: Iker Pedrosa <ipedrosa@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/c1eced627e3d6edb33133f3d52557d257605870b">c1eced62</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-03-09T19:00:52+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>memberOf plugin: redundant comparison removed
'msg->dn' (== 'addop->entry_dn') is already filtered out from 'parents->dns[i]'
at the beginning of `mbof_add_operation()`
Reviewed-by: Iker Pedrosa <ipedrosa@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/7a7480e841ebcbf054d8c8a23c2bf3b9faf30b47">7a7480e8</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-03-09T19:00:52+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>memberOf plugin: swap instead of a shift
when removing a duplicate. DNs order doesn't matter.
Reviewed-by: Iker Pedrosa <ipedrosa@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/704c31dbcb86266a9ad5cb02c96fc73ca6a2fb95">704c31db</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-03-09T19:00:52+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>memberOf plugin: avoid `ldb_dn_compare()` in `mbof_add_operation()`
`ldb_dn_compare()` here is heavy because when DNs are not equal (vast majority of cases),
it performs `ldb_dn_casefold_internal()` to return -1 or 1, but it's not important in
this context.
Note that in general using `str*cmp()` instead of `ldb_dn_get_linearized()` might yield
incorrect results due to different DN representations.
But since all 'memberof' DNs originate from sysdb cache / memberof plugin itself, it
should be safe replacement in this context.
Reviewed-by: Iker Pedrosa <ipedrosa@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/5df3bfff92ffe57e3d856e246ca8ffec5250b6fc">5df3bfff</a></strong>
<div>
<span> by Neal Gompa </span> <i> at 2026-03-10T11:05:31+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Add support for Plasma Login Manager as a supported PAM service
Plasma Login Manager is the new recommended login manager for KDE Plasma,
and is used as the login manager for Fedora Linux 44 and higher for KDE
Plasma.
Reference: https://fedoraproject.org/wiki/Changes/PlasmaLoginManager
Resolves: https://github.com/SSSD/sssd/issues/8490
Signed-off-by: Neal Gompa <ngompa@velocitylimitless.com>
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/77fc6ff1d83f1d8e20f519df7194a95d0abf7491">77fc6ff1</a></strong>
<div>
<span> by Dan Lavu </span> <i> at 2026-03-13T10:23:38+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>updated kcm flaky test
Reviewed-by: Scott Poore <spoore@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/f9697d4ff3fc1e1df5a9ed9c069c8ca045244a14">f9697d4f</a></strong>
<div>
<span> by Nikola Forró </span> <i> at 2026-03-16T10:20:07+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Use macro rather than shell expansion for string processing in spec file
Signed-off-by: Nikola Forró <nforro@redhat.com>
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/caa0ec2280c64d6f36db414761b74e8b4b7674d0">caa0ec22</a></strong>
<div>
<span> by Nikola Forró </span> <i> at 2026-03-16T10:20:07+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Add a default for %samba_package_version
Signed-off-by: Nikola Forró <nforro@redhat.com>
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/3766e5188da355ff1461ee2c27931cd68edefa26">3766e518</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-03-17T13:10:05+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>sdap: add sdap_get_and_multi_parse_generic_send()
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/d77096434197fee928f04c82c152321f21b77b9e">d7709643</a></strong>
<div>
<span> by Ondrej Valousek </span> <i> at 2026-03-17T13:10:05+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Simplify direct nested group processing
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/b3a9b8198c42c4346f76bd9753ad22d631f50e99">b3a9b819</a></strong>
<div>
<span> by Ondrej Valousek </span> <i> at 2026-03-17T13:10:05+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Parser update, cleanup
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/f13a88ca5faf9144066398d6e1a9836406153d69">f13a88ca</a></strong>
<div>
<span> by Ondrej Valousek </span> <i> at 2026-03-17T13:10:05+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Tests fix: mock users/groups with objectclasses and expected RFC2307 attrs
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/461722a398ae76c82b790b68b4ef90e435e0dcb9">461722a3</a></strong>
<div>
<span> by Ondrej Valousek </span> <i> at 2026-03-17T13:10:05+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Bugfix (handle unreadable references) that intg check discovered
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/d028661e1bc404985e755a9cf4b66c0cff65271b">d028661e</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-03-17T13:10:05+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>sdap: use sdap_get_and_multi_parse_generic_send
When processing nested group-memberships the
sdap_get_and_multi_parse_generic request is used to better handle the
different types of members, especially in Active Directory.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/c6f941d62d61b06bdfa962a4c0db49c6aec417e9">c6f941d6</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-03-17T13:10:05+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>sdap: remove extra parsing
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/e27b791b52453801f073b18f1a9500f47a26ec4f">e27b791b</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-03-17T13:10:05+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>ad: add basic foreign security principal sdap map
Add objectclass and other basic attributes to identify a foreign
security principal.
:relnote: Active Directory's Foreign Security Principals (FSP) are now
properly detected and ignored when reading nested group members. The
'ldap_ignore_unreadable_references' option is not needed anymore to
ignore FSPs only in cases where members objects are really not
accessible.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/b97dbe536c75df0546e868010d3b542463cd2aef">b97dbe53</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-03-17T13:10:05+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>sdap: avoid second parsing of objectclasses
To make it easy for the caller of the sdap_get_and_multi_parse_generic
request to identify the type of the objects returned a new integer array
will be returned with a type identifier which can be set by the caller
together with the attribute maps.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/d8b53a88d4689e131202f8bea94f67e5e979c2d3">d8b53a88</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-03-17T13:10:05+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>tests: add a test with a FSP group member
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/92ffd72c17989242a1f5cb47ddb142ea4153c4f4">92ffd72c</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-03-17T13:10:05+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>sdap: new type SDAP_NESTED_GROUP_DN_IGNORE
The new type SDAP_NESTED_GROUP_DN_IGNORE will be used for nested group
members which have an expected type but a required attribute, e.g. the
name, is missing.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/ccfc33a9a49d1ad10da7322aad4c10c996017d96">ccfc33a9</a></strong>
<div>
<span> by Ondrej Valousek </span> <i> at 2026-03-17T13:10:05+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>sdap: restrict list of requested attributes
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/251aca94353da316eb2d97c08f7b9c7cf12eb9cd">251aca94</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-03-17T13:10:05+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>sdap: add struct sdap_reply_with_type
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/59bc5d6288b264e2a7020e634ead0fdee61b8f76">59bc5d62</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-03-17T13:10:05+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>sdap: add struct sdap_attr_map_info_ex
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/6e87db116cd9bb5ffea4e07613c30e50de3a6ae2">6e87db11</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-03-17T13:10:05+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>sdap: re-add IPA shortcut for nested members
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/3a33ae01e31995370dcaf42d33aba3aba51af5fc">3a33ae01</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-03-17T13:10:05+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>sdap: initialize attribute list only once
To avoid that the list of requested attributes is initialize for each
nested member lookup it is initialized at the first use and saved on the
nested group context.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/527d67072475a45e48de425ff2c6a70a469e7483">527d6707</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-03-17T13:10:05+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>sdap: initialize base filter only once
To avoid that the base filter is initialize for each nested member
lookup it is initialized at the first use and saved on the nested group
context.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/fc779c4d9e86725216d17a658693a2586c733c8c">fc779c4d</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-03-17T13:10:05+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>sdap: change increment style for reply array
Instead of increasing the reply array with a constant number of new
entries the array size is now doubled.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/639814e6b05fc3f196d90f7a045f484d3e56eb72">639814e6</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-03-17T13:10:05+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>tests: remove wrong and misleading assigment
In nested_group_external_member_test() the assignment
test_ctx->sdap_opts->group_map[SDAP_AT_GROUP_MEMBER].name = \
discard_const(TEST_EXT_MEMBER);
is wrong and not needed.
Since the external groups are a concept for the IPA provider the LDAP
provider does not use SDAP_AT_GROUP_EXT_MEMBER. The original purpose of
the assignment above was most probably to set the 'name' member for
SDAP_AT_GROUP_EXT_MEMBER since it is NULL by default and
SDAP_AT_GROUP_MEMBER is just a typo. Nevertheless the 'name' member is
only used when sending searches to the LDAP server or evaluate replies
from the server. But during this test there is no interaction with the
LDAP server not even a mocked one. So this option does not have any
effect on the test.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/a6d0f0cf484aeeead535b7138d1334b309c61a4e">a6d0f0cf</a></strong>
<div>
<span> by aborah-sudo </span> <i> at 2026-03-17T14:24:39+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Tests: Fix ipa multihost test_authentication_indicators
Provide sleep time to test
Reviewed-by: Jakub Vávra <jvavra@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/74e7bc65855a7510358eff8fde8400449bc415dd">74e7bc65</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-03-19T16:50:47-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>KRB5: fix mem leak in `authenticate_stored_users()`
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/5b85b647e4a7bdb376f7016a2e306de3dc2ee695">5b85b647</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-03-19T16:50:47-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>UTIL: fix mem leak if `get_active_uid()` fails
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/feca02838a8889ceded54fb794e63d7257e0625f">feca0283</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-03-25T10:41:38+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>SDAP: reduce logger load in the hot path
This patch reduced number of *sprintf() keeping the same level
of details in the resulting log.
Besides, list of attrs being requested was excluded from the backtrace.
Reviewed-by: Iker Pedrosa <ipedrosa@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/87c7bce1552aec2da064b506aec391c40f365705">87c7bce1</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-03-25T10:41:38+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>SDAP: use DEBUG_CONDITIONAL in the hot paths
Reviewed-by: Iker Pedrosa <ipedrosa@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/8631c02e0c73fb89b11b110ac53f30c905962c54">8631c02e</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-03-25T14:40:33+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>KRB5: log level adjusted
Resolves: https://github.com/SSSD/sssd/issues/8531
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/17390fd25d237ccab70ce2d486dc3c893094b5d1">17390fd2</a></strong>
<div>
<span> by Scott Poore </span> <i> at 2026-03-25T16:19:46-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Test: combine gdm tests into one file
Combining all the GDM tests into a single test module to simplify
management of these specific tests.
Refactoring setup helper functions and adding xidp one.
Marking critical tests as well.
Removing some unnecessary comments and adding blank lines to make setup
steps match code.
Renaming some test cases to make purpose more clear.
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/96d38232f95dadf0b68229f5ffde29b15b0ecf26">96d38232</a></strong>
<div>
<span> by Ondrej Valousek </span> <i> at 2026-03-26T18:34:55+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Honor ldap filters
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/3d27526791cb50eb7a5c0ca22fea6379c4092a1b">3d275267</a></strong>
<div>
<span> by Paymon MARANDI </span> <i> at 2026-03-27T15:44:58+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>krb5: improve reporting failure on reading keytab
also, s/has not entries/has no entries/ when keytab_file has actually
no entries.
Signed-off-by: Paymon MARANDI <paymon@encs.concordia.ca>
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/b89f9b6263f0aef43e30d6663d8ec5583ab2e09b">b89f9b62</a></strong>
<div>
<span> by Alejandro López </span> <i> at 2026-03-27T19:51:38+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>SYSDB: Remove unused function
Function sysdb_enumpwent() is not used.
It was replaced by sysdb_enumpwent_filter().
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/5b5d1ffd64da0e233bc769d47f8d9ca8b7691b76">5b5d1ffd</a></strong>
<div>
<span> by Alejandro López </span> <i> at 2026-03-27T19:51:38+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>NSS: Reduce a possibly extremely long log message
When there are too many users (17,000+) this message can be too long.
Limit it to the first 50 characters.
Resolves: https://github.com/SSSD/sssd/issues/6951
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/e91c10a643f6dbc1e21a88a5d2cd4c332ebbd8d5">e91c10a6</a></strong>
<div>
<span> by Alejandro López </span> <i> at 2026-03-27T19:51:38+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>NSS: Fix wrong condition invalidating an optimization
We must look into the TS cache only when a name is provided.
Using the TS cache on an unfiltered enumeration is useless.
Resolves: https://github.com/SSSD/sssd/issues/6951
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/70e78f105809fb1c6c1c5227f078f7608d39c7ad">70e78f10</a></strong>
<div>
<span> by Alejandro López </span> <i> at 2026-03-27T19:51:38+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>TESTS: Improve test_sysdb_enumpwent_filter
Added a case that was not checked before. It is the case
when `attr`, `attr_name` and `addtl_filter` are all `NULL`.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/5284ea6c321ba501c7aa76df9d0e4c4905f9e888">5284ea6c</a></strong>
<div>
<span> by Alejandro López </span> <i> at 2026-03-27T19:51:38+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>NSS: Some optimizations.
Create the filter to retrieve only the requested entries.
Do not create a new filter and search for matches if there is
no results from the previous search. The called functions
handle this case correctly but why wasting time calling them?
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/670db53b151f3da8ab7ada8889f5eacb6bc9691c">670db53b</a></strong>
<div>
<span> by Alejandro López </span> <i> at 2026-03-27T19:51:38+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>NSS: Be coherent when using a lastUpdate filter
Function cache_req_user_by_filter_lookup() will set or not the recent
filter depending on whether data->name.attr is set or not. As mentioned
in the comment, it should be done base on whether the refernced
attribute is name or not.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/55e3a308e3f4e383830fa409e2b9953585d7dcbf">55e3a308</a></strong>
<div>
<span> by Alejandro López </span> <i> at 2026-03-27T19:51:38+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>NSS: Fix the logged function name
The message said that sysdb_enumpwent() had failed, but it was
actually sysdb_enumpwent_filter() which failed.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/11a15c25002033d6b5426a4b45f3cb2918b9fd90">11a15c25</a></strong>
<div>
<span> by Alejandro López </span> <i> at 2026-03-27T19:51:38+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>NSS: Fix sysdb_enumpwent_filter()
The "name" attribute was not being added to the TS cache, even though
that it is part of the DN (ldb doesn't enforce it). Adding this
attribute requires that the DB version is incremented for the TS cache
to be regenerated with the missing attribute.
This made the if-block in sysdb_enumpwent_filter() rather useless.
In addition, once this if-block is executed, the fuction leaves without
further processing.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/0a739f855b344413d45b92cd7fb4750d28f9e0de">0a739f85</a></strong>
<div>
<span> by Alejandro López </span> <i> at 2026-03-27T19:51:38+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>NSS: Better handle ERR_NO_TS in sysdb_enumpwent_filter()
Although ts_res.count is set to 0 when sysdb_search_ts_users()
return ERR_NO_TS, before using it we make an extra check to verify
that the returned code is EOK.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/2dcdca2f9b2682816ba8fd5e99c8fafe54ce1abc">2dcdca2f</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-03-27T20:51:12+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>memberOf plugin: avoid `ldb_dn_compare()` in `mbof_append_addop()`
Justification is the same as in 704c31dbcb86266a9ad5cb02c96fc73ca6a2fb95
In certain scenarios this function is a hot path and using heavy
`ldb_dn_compare()` adds unnecessary overhead.
Reviewed-by: Alejandro López <allopez@redhat.com>
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/05706145e4c5ebab7ef523739ab6706271d16a32">05706145</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-03-30T09:52:42+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>memberOf plugin: avoid `ldb_dn_compare()` in `mbof_append_muop`
Justification is the same as in 704c31dbcb86266a9ad5cb02c96fc73ca6a2fb95
In certain scenarios this function is a hot path and using heavy
`ldb_dn_compare()` adds unnecessary overhead.
Reviewed-by: Alejandro López <allopez@redhat.com>
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/06692d50a9fc2df70287f3b82bffb289f113a94e">06692d50</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-03-30T09:52:42+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>memberOf plugin: use hash table for value dedup in `mbof_append_muop()`
Replace O(N) linear `strcmp` scan over `op->el->values[]` with O(1)
hash table lookup for duplicate name detection.
Implementation assisted-by: Claude Code (Opus 4.6)
Reviewed-by: Alejandro López <allopez@redhat.com>
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/abee6e7cafcb784e178cf21d098a9146bad474ad">abee6e7c</a></strong>
<div>
<span> by aborah-sudo </span> <i> at 2026-03-30T16:12:37+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Tests: Add integration tests validating SSSD socket
Add integration tests validating SSSD socket activation behavior
for individual responders and mixed socket/traditional configurations.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Jakub Vávra <jvavra@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/3bd74d9b31735401bcdfa0c94fa5ff9aadc29aa7">3bd74d9b</a></strong>
<div>
<span> by Ezri Zhu </span> <i> at 2026-04-02T16:16:44+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>oidc_child: parameterize entra_idp url
Creates a function to extract the idp url from idp_type instead of using
hardcoded entra url due to GCC High Entra instances using a different
url.
Resolves: https://github.com/SSSD/sssd/issues/8446
idp_type
:feature: `idp_type` option allows entra_idp url to be specified if user is using a
different microsoft entra endpoint.
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/23a23cd2947ae2f0a9944f98e1ee97826000d233">23a23cd2</a></strong>
<div>
<span> by dependabot[bot] </span> <i> at 2026-04-06T08:32:57-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>ci: bump crazy-max/ghaction-import-gpg from 6.3.0 to 7.0.0
Bumps [crazy-max/ghaction-import-gpg](https://github.com/crazy-max/ghaction-import-gpg) from 6.3.0 to 7.0.0.
- [Release notes](https://github.com/crazy-max/ghaction-import-gpg/releases)
- [Commits](https://github.com/crazy-max/ghaction-import-gpg/compare/e89d40939c28e39f97cf32126055eeae86ba74ec...2dc316deee8e90f13e1a351ab510b4d5bc0c82cd)
---
updated-dependencies:
- dependency-name: crazy-max/ghaction-import-gpg
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/0c956d95cf05b585dbe8913f9aea53c6b8fffce8">0c956d95</a></strong>
<div>
<span> by Jakub Vávra </span> <i> at 2026-04-07T11:28:00-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Tests: Housekeeping and Clean Sweep of Sevice/Logging suite
Merged tests for sssd offline message in logs and syslog.
Split backend offline(unreachable) and dns resolution error scenario.
Check that user login does not generate logs on default debug level
extended to all providers. Added link to debug level documentation.
Dropped references to (now-irrelevant) bugzillas in rewritten tests.
Skipping test_logging__user_logins_are_not_written_to_logs
as updating log level of the messages is low priority.
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/428e6130442e855a3ba386c377fe29b52d99f6bc">428e6130</a></strong>
<div>
<span> by Dan Lavu </span> <i> at 2026-04-08T08:37:44-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Reworked memcache tests
* parametrized test cases
* added colliding hash test case
* remove poor test scenarios
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/7d9bdd508cd2bf5c482361f323008dedca3166c3">7d9bdd50</a></strong>
<div>
<span> by Dan Lavu </span> <i> at 2026-04-08T08:37:44-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>removing intg memcache tests
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/58cc4d2263adfbe64214b79aa9c5ae8b8a577fc7">58cc4d22</a></strong>
<div>
<span> by Striker Leggette </span> <i> at 2026-04-10T11:51:40-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix spelling in AD provider code comments
Reviewed-by: Dan Lavu <dlavu@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/3b7dc8c739f2821ea389fa36daf75c9b0ec62c50">3b7dc8c7</a></strong>
<div>
<span> by Pavel Březina </span> <i> at 2026-04-13T12:07:25+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>contrib: removed unused test-suite
This was used by sssd-test-suite virtual machines based CI that we no
longer use.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Iker Pedrosa <ipedrosa@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/f260623f95497cd7f629b4a3915ec2724889602c">f260623f</a></strong>
<div>
<span> by Pavel Březina </span> <i> at 2026-04-13T12:07:25+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>dist: clean up and fix ditribution tarball
The tarball contained malformed src/tests/tests folder due to including
full src/tests in noinst_DATA (because $distdir/src/tests was already
created by check unit tests).
It also clean up the tarball to avoid various build time artifacts and
including missing files.
Resolves: https://github.com/SSSD/sssd/issues/8514
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Iker Pedrosa <ipedrosa@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/0100b1c3536688c12f1db2a65164f03765727f81">0100b1c3</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-04-13T12:08:37+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>KCM: fix use-after-free in `kcm_read_options()`
The `renew_intv` string was allocated under tmp_ctx but not re-linked
to mem_ctx before tmp_ctx was freed.
Assisted-By: Claude Code (Opus 4.6)
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/95d8476702386bd8567e3aad463fbd48c4508fd6">95d84767</a></strong>
<div>
<span> by Paymon MARANDI </span> <i> at 2026-04-13T12:51:33+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>krb5: make sure keytab is a FILE before checking for access
KCM: and API: are other cases besides MEMORY:
Resolves: https://github.com/SSSD/sssd/issues/8555
Signed-off-by: Paymon MARANDI <paymon@encs.concordia.ca>
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/10d509a84ba0c2f045b8d3ab843851e44b3ca7ce">10d509a8</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-04-13T14:29:51+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>conf: add avoid_by_id_lookups domain option
If this new option is set to 'true' SSSD will try to avoid sending
lookups by ID to the backend and will switch to a lookup by name if a
cached object with a matching ID can be found. This option can e.g. be
used in cases where searches by ID are expensive on the server side
because of missing indexes or are not even possible.
:config: New option 'avoid_by_id_lookups' to tell the SSSD responders to
use a lookup by name instead of by id where possible
Resolves: https://github.com/SSSD/sssd/issues/7668
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/c767b8ea06bbc538ddb40b32111c1d71323595c8">c767b8ea</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-04-13T14:29:51+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>cache_req: switch from ID to name lookup
If 'avoid_by_id_lookups' is set to 'True' switch to a lookup by name if
a user or a group is searched by ID.
Resolves: https://github.com/SSSD/sssd/issues/7668
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/a3b2b4f1517b250bde36f9278b18aa54f88645ef">a3b2b4f1</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-04-13T14:29:51+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>idp: do not update cache timeout if member is added
If only a single member is added to a group, e.g. during an initgroups
request, do not increment the cache timeout because it is not clear if
the list of members is complete or not.
Resolves: https://github.com/SSSD/sssd/issues/8330
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/cb1ef376a31262ea1f1b11b560de61986dc86c60">cb1ef376</a></strong>
<div>
<span> by Pavel Březina </span> <i> at 2026-04-14T12:43:43+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>scripts: add fixed-issues.sh script
Add a bash script to extract and list resolved GitHub issues from git commit
history. The script searches for "Resolves:" references in commit messages
between two git refs and outputs a formatted list of closed issues.
Features:
- Accepts --from <ref> (required) and --to <ref> (defaults to HEAD)
- Supports multiple output formats via --format: plain, rst, md
- Uses gh CLI to fetch issue details (number, title, state)
- Filters to only include closed issues
- Outputs formatted list with issue number, URL, and title
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
Reviewed-by: Alejandro López <allopez@redhat.com>
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/27aac3a294cf10a501d1565aa8d427bff24dd512">27aac3a2</a></strong>
<div>
<span> by Pavel Březina </span> <i> at 2026-04-14T12:43:43+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>scripts: add generate-release-notes.py script
Generate release notes from commit messages:
./scripts/generate-release-notes.py --from FROM --to TO --version VERSION --format md|rst
Co-Authored-By: Claude <noreply@anthropic.com>
Reviewed-by: Alejandro López <allopez@redhat.com>
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/033a81befb6d57e34776e938e24813b93ecf7b06">033a81be</a></strong>
<div>
<span> by Pavel Březina </span> <i> at 2026-04-14T12:43:43+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>scripts: add generate-full-release-notes.sh script
This scripts prepares a release notes for sssd.io.
Reviewed-by: Alejandro López <allopez@redhat.com>
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/c8257a3ef5085e87f58eb910bcb1bfb4b25c609a">c8257a3e</a></strong>
<div>
<span> by Pavel Březina </span> <i> at 2026-04-14T12:43:43+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>ci: automatically generate release notes
The release workflow is extended to automatically generate release
notes and open a draft pull request against sssd.io.
Reviewed-by: Alejandro López <allopez@redhat.com>
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/35019632b6fc199f60b11000413c9e793ecee594">35019632</a></strong>
<div>
<span> by Striker Leggette </span> <i> at 2026-04-14T09:17:25-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>More trivial spelling/grammatical fixes. No functional code was harmed in the changing of these files.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/1233fc7d63e96d667e716c806549688977da5d5a">1233fc7d</a></strong>
<div>
<span> by Timo Eisenmann </span> <i> at 2026-04-14T21:33:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>config: add missing rules for idp options
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/6a3295280b338f6686680629448594425aba7e9f">6a329528</a></strong>
<div>
<span> by Timo Eisenmann </span> <i> at 2026-04-14T21:33:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>oidc_child: get refresh_token for later
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/371148d7c7644cc55a621edede30c2308a77ffb6">371148d7</a></strong>
<div>
<span> by Timo Eisenmann </span> <i> at 2026-04-14T21:33:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>oidc_child: store tokens in cache
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/ede49c2c25445a32edfea466345c1ed50d0f4d35">ede49c2c</a></strong>
<div>
<span> by Timo Eisenmann </span> <i> at 2026-04-14T21:33:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>oidc_child: add --refresh-access-token flag
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/9525cccb460115ef93f21a09dd5d0bd758128437">9525cccb</a></strong>
<div>
<span> by Timo Eisenmann </span> <i> at 2026-04-14T21:33:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>idp: automatically refresh tokens
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/2e887f12c94fadbdae1421885e125676305962e7">2e887f12</a></strong>
<div>
<span> by Timo Eisenmann </span> <i> at 2026-04-14T21:33:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>idp: add option to automatically refresh tokens
:feature: Tokens acquired from the IdP are now stored in the domain
cache, and are automatically refreshed if the new option
`idp_auto_refresh` is enabled.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/1f57c2b118542f0590683686baf1ed1eef27cfae">1f57c2b1</a></strong>
<div>
<span> by Timo Eisenmann </span> <i> at 2026-04-14T21:33:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>idp: delete non-replaced tokens from cache
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/aadae62db208c34062fdf35ce15a4338046ad601">aadae62d</a></strong>
<div>
<span> by Timo Eisenmann </span> <i> at 2026-04-14T21:33:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>idp: construct pam_data with timer
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/a3c506dd9cf55b5b757aade127239c7f4cf33f08">a3c506dd</a></strong>
<div>
<span> by Timo Eisenmann </span> <i> at 2026-04-14T21:33:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>oidc_child: url-encode post data items
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/0f08795fd02464526ac2de548cc21079a3fb3ad1">0f08795f</a></strong>
<div>
<span> by Timo Eisenmann </span> <i> at 2026-04-14T21:33:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>oidc_child: free json objects properly
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/c9ca1900eb2b576de925f33a179ea3e26455c3c9">c9ca1900</a></strong>
<div>
<span> by Timo Eisenmann </span> <i> at 2026-04-14T21:33:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>oidc_child: add macros for token names
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/fe5d548d7e1e2654d1d1f0c09bb032347dd32475">fe5d548d</a></strong>
<div>
<span> by Timo Eisenmann </span> <i> at 2026-04-14T21:33:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>idp: pass sss_domain_info to create_refresh_token_timer
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/c3f6388f8208a9a4ef85e06db9f7e623383f1945">c3f6388f</a></strong>
<div>
<span> by Timo Eisenmann </span> <i> at 2026-04-14T21:33:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>idp: fix idp_id_scope Entra example
Because scope is URL-encoded by oidc_child, the `idp_id_scope` option
must not be encoded already.
This also checks for and automatically corrects the old example value.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/3f65f58b2039d0bab55c8ec092eb7d630f59457f">3f65f58b</a></strong>
<div>
<span> by Timo Eisenmann </span> <i> at 2026-04-14T21:33:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>oidc_child: initialize curl only once
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/f9ee090e7ded1b0a4f202f53464410d8f7b300e2">f9ee090e</a></strong>
<div>
<span> by Timo Eisenmann </span> <i> at 2026-04-14T21:33:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>fix typos
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/ec440c04c2923475040bb2fc5d981471388f69e2">ec440c04</a></strong>
<div>
<span> by Timo Eisenmann </span> <i> at 2026-04-14T21:33:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>fix gcc warning
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/a32aab401ecc097bceff5313dd19d61abb2b50b0">a32aab40</a></strong>
<div>
<span> by Timo Eisenmann </span> <i> at 2026-04-14T21:33:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>add config option to enable logging sensitive data
Sensitive data is logged by the new macro `DEBUG_SENSITIVE`, which is an
alias to `DEBUG` if configured with `--enable-sensitive-logs`.
Otherwise, it is simply a no-op.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/a809b9236250e6f20e9a9ff1452708cd288b705f">a809b923</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-04-15T10:34:22+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Add missing include
Original patch f3af8c89af656767333410b0e94da9288dd8ade8 didn't include
"config.h" that provides `HAVE_PTHREAD_EXT`
It works in some branches accidentally because of transitive include
via "sss_cli.h" but that's fragile (and in some branches "sss_cli.h"
doesn't include "config.h")
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/80e64825795222fb6c21db116d7a5ae9fb76e407">80e64825</a></strong>
<div>
<span> by Madhuri Upadhye </span> <i> at 2026-04-15T12:30:10+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>tests: port LDAP+Kerberos tests to pytest
- Port three downstream krb_misc_bugzilla bash tests to upstream pytest
- BZ 773660: Clock skew errors logged to syslog
- BZ 869150: ldap_child handles missing keytab without segfault
- BZ 805281: Correct principal selected from multi-realm keytab
Signed-off-by: Madhuri Upadhye <mupadhye@redhat.com>
Reviewed-by: Dan Lavu <dlavu@redhat.com>
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/3f9c415abcf5a9c051a287602c00a9279c3d50b6">3f9c415a</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-04-20T13:06:11+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>ad: move ad_get_sids_from_pac() to ad_pac_common.c
To make ad_get_sids_from_pac() better reusable it is moved with its
dependencies into ad_pac_common.c
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/22de4fd2d7679d9c00de277e5cd9076d032c6812">22de4fd2</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-04-20T13:06:11+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>pam: add pam_gssapi_indicators_apply option
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/1f680edad023c8c57343447b156f6b34696e8221">1f680eda</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-04-20T13:06:11+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>pam: apply SIDs from PAC to authentication indicators
This patch reads the PAC of a Kerberos ticket while evaluating the
authentication indicators of the Kerberos ticket during a pam_sss_gss
request. Based on the value of the pam_gssapi_indicators_apply option
the found SIDs might add additional authentication indicators to the
evaluation.
The primary use case is to handle SIDs added by Active Directory's
Authentication Mechanism Assurance (AMA).
:relnote: During the processing of the pam_sss_gss request SSSD will
read the SID from the PAC of the Kerberos ticket and might add
authentication indicators based on the value of the new option
pam_gssapi_indicators_apply. The primary use case is to handle SIDs
added by Active Directory's Authentication Mechanism Assurance (AMA).
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/550b08cabe4dd5508c7ea74f634869374204d63f">550b08ca</a></strong>
<div>
<span> by Xu Raoqing </span> <i> at 2026-04-21T21:15:01+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>pam: fix out-of-bounds read in pam_passkey_child_read_data
The pam_passkey_child_read_data() function failed to properly handle
raw bytes received from a pipe. The data was treated as a NUL-terminated
C string without explicit termination, resulting in an out-of-bounds read
when processed by snprintf() with %s format.
Fix by using memcpy instead of snprintf and explicitly NUL-terminating
the buffer. Add checks for buf_len == 0 or buf == NULL to avoid undefined
behavior. Check the return value of sss_authtok_set_passkey_reply and
propagate errors properly.
Fixes: CVE-2026-6245
:relnote: Security fix for CVE-2026-6245: out-of-bounds read in PAM passkey responder
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Iker Pedrosa <ipedrosa@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/6726f5a8a4a42c68246c3f2e5e093dfd5341e199">6726f5a8</a></strong>
<div>
<span> by Dan Lavu </span> <i> at 2026-04-22T00:19:12-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>removing unstable topologies from memecache tests
Reviewed-by: Scott Poore <spoore@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/9926e7ef9f05bda8dbda07644ee02d5ebb48d625">9926e7ef</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-04-22T09:33:23+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>oidc_child: add new option return-tokens
oidc_child should only return access and refresh tokens during
authentication if the new option '--return-tokens' is given.
Resolves: https://github.com/SSSD/sssd/issues/8616
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/ba4353fddc95d23131a73598e93b0e3cdec7a13c">ba4353fd</a></strong>
<div>
<span> by Gleb Popov </span> <i> at 2026-04-22T10:43:22+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>dp_target_id.c: Fix typo "lenght" -> "length"
Resolves #8590
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/d0beceaa17b94fa07a2ee7af8165392b90e83d94">d0beceaa</a></strong>
<div>
<span> by Paul Adelsbach </span> <i> at 2026-04-22T11:25:21+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>pam: gate PAC indicator code on BUILD_SAMBA
Commit 1f680edad023c8c57343447b156f6b34696e8221 added ad_pac_common.c and
$(NDR_KRB5PAC_LIBS) to sssd_pam unconditionally. So when building --without-samba, sssd_pam fails to link with undefined references to ndr_pull_init_blob and ndr_pull_PAC_DATA.
This change qualifies those additions with `BUILD_SAMBA` so the PAC
indicator feature is compiled in only when samba support is enabled.
Reviewed-by: Sumit Bose <sbose@redhat.com>
Reviewed-by: Tomáš Halman <thalman@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/3b0b16e96728b3d2f8ddd8c0ee67b92ec210d44f">3b0b16e9</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-04-22T16:40:43+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>PAM/PASSKEY: avoid unnecessary memcpy
`sss_authtok_set_passkey_reply()` -> `sss_authtok_set_string()` handles
non NULL-terminated buffer correctly.
Reviewed-by: Iker Pedrosa <ipedrosa@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/9c836671ce51ee39c31baf7b4db48e985b3befb8">9c836671</a></strong>
<div>
<span> by Hosted Weblate </span> <i> at 2026-04-23T12:49:49+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>po: update translations
(Italian) currently translated at 100.0% (2838 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/
po: update translations
(Italian) currently translated at 99.9% (2836 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/
po: update translations
(Italian) currently translated at 99.9% (2836 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/
po: update translations
(Italian) currently translated at 99.9% (2836 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/
po: update translations
(Italian) currently translated at 79.5% (2257 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/
po: update translations
(Italian) currently translated at 79.5% (2257 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/
po: update translations
(Italian) currently translated at 69.1% (1962 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/
po: update translations
(Italian) currently translated at 69.1% (1962 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/
po: update translations
(Italian) currently translated at 69.1% (1962 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/
po: update translations
(Italian) currently translated at 55.8% (1584 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/
po: update translations
(Italian) currently translated at 55.8% (1584 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/
po: update translations
(Italian) currently translated at 35.2% (1001 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/
po: update translations
(Italian) currently translated at 35.2% (1001 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/
po: update translations
(Italian) currently translated at 22.7% (646 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/
po: update translations
(Italian) currently translated at 22.7% (646 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/
po: update translations
(Italian) currently translated at 22.7% (646 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/
po: update translations
(Italian) currently translated at 22.7% (646 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/
po: update translations
(Italian) currently translated at 22.7% (646 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/
po: update translations
(Italian) currently translated at 22.7% (646 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/
po: update translations
(Italian) currently translated at 6.7% (192 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/
po: update translations
(Italian) currently translated at 6.7% (192 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/
po: update translations
(Italian) currently translated at 6.7% (192 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/
po: update translations
(Italian) currently translated at 6.7% (192 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/
po: update translations
(Italian) currently translated at 6.7% (192 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/
po: update translations
(Italian) currently translated at 100.0% (735 of 735 strings)
Translation: SSSD/sssd
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/it/
po: update translations
(Italian) currently translated at 100.0% (735 of 735 strings)
Translation: SSSD/sssd
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/it/
po: update translations
(Italian) currently translated at 100.0% (735 of 735 strings)
Translation: SSSD/sssd
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/it/
po: update translations
(Polish) currently translated at 100.0% (735 of 735 strings)
Translation: SSSD/sssd
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/pl/
po: update translations
(Italian) currently translated at 100.0% (735 of 735 strings)
Translation: SSSD/sssd
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/it/
po: update translations
(Portuguese) currently translated at 100.0% (2838 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/pt/
po: update translations
(Finnish) currently translated at 10.4% (77 of 735 strings)
Translation: SSSD/sssd
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/fi/
po: update translations
(Swedish) currently translated at 100.0% (2838 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/sv/
po: update translations
(Korean) currently translated at 68.1% (1681 of 2465 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ko/
po: update translations
(Korean) currently translated at 68.1% (1681 of 2465 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ko/
po: update translations
(Korean) currently translated at 68.1% (1681 of 2465 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ko/
po: update translations
(Korean) currently translated at 68.1% (1681 of 2465 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ko/
po: update translations
(Korean) currently translated at 68.1% (1681 of 2465 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ko/
po: update translations
(Korean) currently translated at 68.1% (1681 of 2465 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ko/
po: update translations
(Czech) currently translated at 100.0% (735 of 735 strings)
Translation: SSSD/sssd
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/cs/
po: update translations
(Czech) currently translated at 100.0% (735 of 735 strings)
Translation: SSSD/sssd
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/cs/
po: update translations
(Czech) currently translated at 100.0% (735 of 735 strings)
Translation: SSSD/sssd
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/cs/
po: update translations
(Czech) currently translated at 100.0% (735 of 735 strings)
Translation: SSSD/sssd
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/cs/
po: update translations
(Czech) currently translated at 100.0% (735 of 735 strings)
Translation: SSSD/sssd
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/cs/
po: update translations
(Czech) currently translated at 100.0% (735 of 735 strings)
Translation: SSSD/sssd
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/cs/
po: update translations
(Czech) currently translated at 100.0% (735 of 735 strings)
Translation: SSSD/sssd
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/cs/
po: update translations
(Czech) currently translated at 100.0% (735 of 735 strings)
Translation: SSSD/sssd
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/cs/
po: update translations
(Turkish) currently translated at 100.0% (735 of 735 strings)
Translation: SSSD/sssd
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/tr/
po: update translations
(Korean) currently translated at 100.0% (735 of 735 strings)
Translation: SSSD/sssd
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/ko/
po: update translations
(Spanish) currently translated at 100.0% (735 of 735 strings)
Translation: SSSD/sssd
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/es/
po: update translations
(Spanish) currently translated at 100.0% (2838 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/es/
po: update translations
(Russian) currently translated at 100.0% (735 of 735 strings)
Translation: SSSD/sssd
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/ru/
po: update translations
(French) currently translated at 100.0% (735 of 735 strings)
Translation: SSSD/sssd
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/fr/
po: update translations
(Russian) currently translated at 100.0% (2838 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ru/
po: update translations
(Korean) currently translated at 100.0% (735 of 735 strings)
Translation: SSSD/sssd
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/ko/
po: update translations
(Korean) currently translated at 67.8% (1672 of 2465 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ko/
po: update translations
(Korean) currently translated at 67.8% (1672 of 2465 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ko/
po: update translations
(Swedish) currently translated at 100.0% (735 of 735 strings)
Translation: SSSD/sssd
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/sv/
po: update translations
(Portuguese) currently translated at 100.0% (735 of 735 strings)
Translation: SSSD/sssd
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/pt/
po: update translations
(Portuguese) currently translated at 100.0% (2838 of 2838 strings)
Translation: SSSD/sssd-manpage
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/pt/
Update translation files
Updated by "Update LINGUAS file" hook in Weblate.
Translation: SSSD/sssd
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/
Added translation using Weblate (Turkish)
Added translation using Weblate (Norwegian Bokmål)
Added translation using Weblate (Italian)
Added translation using Weblate (Indonesian)
Added translation using Weblate (Hungarian)
Added translation using Weblate (Bulgarian)
Added translation using Weblate (Latvian)
Update translation files
Updated by "Update PO files to match POT (msgmerge)" hook in Weblate.
Translation: SSSD/sssd
Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/
Added translation using Weblate (Breton)
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/9faae339dee2bd4ab6f0eb0fa3eadcbdca822832">9faae339</a></strong>
<div>
<span> by sssd-bot </span> <i> at 2026-04-24T11:52:44+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>pot: update pot files
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/d1329f90294f1a59756886abd8a61296427f8d72">d1329f90</a></strong>
<div>
<span> by sssd-bot </span> <i> at 2026-04-24T11:52:44+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Release sssd-2.13.0
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/d77df8e584b43e5be14663513e3edefd025de545">d77df8e5</a></strong>
<div>
<span> by Madhuri Upadhye </span> <i> at 2026-04-28T15:21:15+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>tests: poll for KCM TGT renewal instead of fixed sleep
test_kcm__tgt_renewal_updates_ticket_as_configured
no longer uses a fixed sleep(5) and flaky retries.
The test now polls klist every 0.5s and asserts renewal
by checking that TGT start or end time advances,
with a detailed failure message that prints both
initial and last timestamps.
To match KCM renewal behavior (renewal only starts
after roughly half the ticket lifetime),
the test uses a short renewable ticket (-r 5s -l 5s) and
a bounded polling window (9s) so it stays fast while still
waiting long enough for renewal to be attempted.
Also removed the temporary CI comment and the flaky marker from this test.
Assited by: Cursor(Claude Opus 4.6)
Signed-off-by: Madhuri Upadhye <mupadhye@redhat.com>
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Scott Poore <spoore@redhat.com>
(cherry picked from commit 233db39fc84dc2a0b3bfb86000080b66d5d46713)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/feef76172ce2259a8e73028561f78da408ad31db">feef7617</a></strong>
<div>
<span> by krishnavema </span> <i> at 2026-05-06T15:15:22-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>tests: implement multi-token support for smart card authentication
Reviewed-by: Scott Poore <spoore@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
(cherry picked from commit e5b65979f11e10ffafa398fe38e4d1cf63cd99bf)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/87b819c73abe5e6e79655f05331ce5ec35e1feca">87b819c7</a></strong>
<div>
<span> by dependabot[bot] </span> <i> at 2026-05-07T09:24:16-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>ci: bump cross-platform-actions/action from 0.32.0 to 1.0.0
Bumps [cross-platform-actions/action](https://github.com/cross-platform-actions/action) from 0.32.0 to 1.0.0.
- [Release notes](https://github.com/cross-platform-actions/action/releases)
- [Changelog](https://github.com/cross-platform-actions/action/blob/master/changelog.md)
- [Commits](https://github.com/cross-platform-actions/action/compare/v0.32.0...v1.0.0)
---
updated-dependencies:
- dependency-name: cross-platform-actions/action
dependency-version: 1.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
(cherry picked from commit fa413a9694a5dfbb17171e4b26cfce4d75881a5c)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/d19f6860e6064399c51dec9b5ba99ff9ab4f1478">d19f6860</a></strong>
<div>
<span> by Dan Lavu </span> <i> at 2026-05-08T20:12:09+05:30 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>refactoring ipa tests for hostname framework changes.
Reviewed-by: Jakub Vávra <jvavra@redhat.com>
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
Reviewed-by: Madhuri Upadhye <mupadhye@redhat.com>
(cherry picked from commit 8f170d08a0ca0a9573fc173ae5e7e6a1cd8ffc26)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/6e2b87aa43e15f18c10d859bbed59dab314ffed1">6e2b87aa</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-05-11T10:29:03+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>KRB5: read keytab copy in offline mode too
The process can transition from offline pre-auth to online auth within
the same invocation.
Reviewed-by: Iker Pedrosa <ipedrosa@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
(cherry picked from commit b070171e8371ce9be20c0554617b35d13a2ef17c)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/9826dca055e4f8f42eec24cde682a30806ab9e55">9826dca0</a></strong>
<div>
<span> by Samuel Cabrero </span> <i> at 2026-05-11T22:05:16+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>sdap: Reduce log level when get_naming_context() fails
Signed-off-by: Samuel Cabrero <scabrero@suse.com>
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
(cherry picked from commit edf4a0f9b683a96526a205ab8cd2148012da63b9)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/67444c41fc8d21fdeae8d6c68128dfe67a36a47a">67444c41</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-05-11T22:09:48+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>p11_child: ignore failure of C_GetTokenInfo
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
(cherry picked from commit d6483bb5c5639e3045092170cd5ee5cdcd5b5867)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/cd184920572cb5949fafe6413cc8c4d9216e2381">cd184920</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-05-11T22:09:48+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>pam: handle protected authentication path
If a Smartcard reader has a built-in keypad or keyboard the flag
CKF_PROTECTED_AUTHENTICATION_PATH is set in the token info data. To
properly tell the user that the pin must be given at the reader directly
and not at the computer this information must be propagated to the
pam_sss module.
Resolves: https://github.com/SSSD/sssd/issues/5371
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
(cherry picked from commit 016bc7a2a389900907579631c0016986e5eb0678)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/89accfc155a216ff5688cade7786208e2ec5efd1">89accfc1</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-05-11T22:09:48+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>authtok: remove sss_authtok_set_sc_keypad()
sss_authtok_set_sc_keypad() does not set which token and certificate
should be used for authentication, just using sss_authtok_set_sc() with
SSS_AUTHTOK_TYPE_SC_KEYPAD as type is sufficient.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
(cherry picked from commit f3aea6728f2ccfc52fc2f8211828094dd5edf609)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/072f8ec11aa280ec6213e1466fae989cc2282b54">072f8ec1</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-05-11T22:09:48+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>pam_sss: fix potential memory leak
In case the conversation callback allocates memory for a reply we have
to free it.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
(cherry picked from commit 084268fc284b35514ac7e4cd9e9410d344817d37)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/8c59fa3e6d069863f9f66985415597b1d79b75da">8c59fa3e</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-05-11T22:09:48+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>pam: refactor pack_cert_data
Use safealign_memcpy() instead of plain memcpy() and add a consistency
check.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
(cherry picked from commit 50a38380e2cb19f17dd2e0abf523091ddc45476b)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/a4bbfb40be39bde05af2366366a6145e211427bd">a4bbfb40</a></strong>
<div>
<span> by Jakub Vávra </span> <i> at 2026-05-12T11:11:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Tests: Fix test_refresh_contain_timestamp
Reviewed-by: Madhuri Upadhye <mupadhye@redhat.com>
(cherry picked from commit 1b802f4cbcf04ddd4cb43942701311a4e3a661c0)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/22ee18410301def2c9979b2c2bdde20e7151d04b">22ee1841</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-05-12T18:09:23+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>krb5: restart krb5_child for Smartcard authentication
In contrast to other authentication methods for PKINIT some information
about the used Smartcard and certificate are already needed for the
pre-authentication step to trigger the MIT Kerberos PKINIT module to get
back the information if PKINIT is possible or not and if the Smartcard
can be used for authentication. If krb5_child is kept running between
the pre-authentication and the authentication step the information given
during pre-authentication is used if Smartcard authentication was
selected.
As long as only a single certificate is available there is no issue. But
if there are multiple certificates which all apply to the given mapping
and matching rules for the user trying to log in and the user can choose
a certificate for authentication the authentication might fail if the
certificate use during pre-authentication and the one selected by the
user differ. Before the change to keep krb5_child running for all
authentication methods this was not an issue since the fresh instance
started during the authentication step was using the certificate
selected by the user.
With this patch krb5_child is restart during the authentication step is
Smartcard authentication was selected.
Reviewed-by: Iker Pedrosa <ipedrosa@redhat.com>
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
(cherry picked from commit f3a36bec2a6c9fe11076c8f4673775a0d4221ad1)
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/c3acaa3a5104ee32efdb536b311a343276afb5d0">c3acaa3a</a></strong>
<div>
<span> by Pavel Březina </span> <i> at 2026-05-13T12:34:56+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>sdap: let callers mark SSSD as offline if kinit fails
The callers expected that ret == EIO and can_retry == false to bring
SSSD to an offline state.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
(cherry picked from commit c5b631ee6df531b506d2b2ba7f2d9f0b9de02746)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/e12ff3c62d2b72fe5ded4242a3f4651ab3f396e6">e12ff3c6</a></strong>
<div>
<span> by Simo Sorce </span> <i> at 2026-05-19T19:32:11+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Correct x400Address type check in crypto.m4
Update the compilation check for the x400Address field in the GENERAL_NAME
struct. By comparing the address of the field against an ASN1_STRING double
pointer, it ensures the compiler strictly and safely verifies the exact type
during autoconf checks without causing invalid pointer arithmetic errors.
Co-authored-by: Gemini <gemini@google.com>
Signed-off-by: Simo Sorce <simo@redhat.com>
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
(cherry picked from commit ab6713f781ba02c4ff881f276a9289b4b3ff1133)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/e30bd32e9e278518108a47ad617f1d7888ef987c">e30bd32e</a></strong>
<div>
<span> by Simo Sorce </span> <i> at 2026-05-19T19:32:11+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update certmap for OpenSSL 4.0 compatibility
Replace direct struct field accesses with OpenSSL accessor functions like
ASN1_STRING_get0_data and ASN1_STRING_length. Add const qualifiers to
ensure compatibilitty with OpenSSL 4.0.
Signed-off-by: Simo Sorce <simo@redhat.com>
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
(cherry picked from commit b197d9d3f566f8b840663e31105b338e1a4f962e)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/52547f7f9efa5dc7c122f20467a31dbbbbcdc475">52547f7f</a></strong>
<div>
<span> by Simo Sorce </span> <i> at 2026-05-19T19:32:11+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Add const qualifier to X509_NAME pointers
The issuer_name and subject_name variables in get_issuer_subject_str have been
updated to use the const qualifier. This improves const-correctness and
prevents accidental modification of the certificate data.
Signed-off-by: Simo Sorce <simo@redhat.com>
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
(cherry picked from commit 770ae6cb020fd60e64507747bfddbb948cb52984)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/eecbb52ab06905f2080318c13756b39422c3835d">eecbb52a</a></strong>
<div>
<span> by Justin Stephenson </span> <i> at 2026-05-26T10:20:39-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>tests: Clarify approx match filter
Reviewed-by: Tomáš Halman <thalman@redhat.com>
(cherry picked from commit 21674dd9689742b292f84c5e7f98278f6d99ab30)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/1b6efb03fa5fdb0f555d1a36dabd67fc176b1ee7">1b6efb03</a></strong>
<div>
<span> by Iker Pedrosa </span> <i> at 2026-05-26T10:36:14-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>tests: add TMT plan for passkey testing
Add comprehensive TMT plan for testing SSSD passkey functionality across
IPA, LDAP, and Samba identity providers using containerized environments.
Signed-off-by: Iker Pedrosa <ipedrosa@redhat.com>
Co-authored-by: Claude Sonnet 4 <noreply@anthropic.com>
Reviewed-by: Jakub Vávra <jvavra@redhat.com>
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
(cherry picked from commit d54cf526c92143653108b455fa4e477c24b6263f)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/f21a1432fd3abb9d8805e19c73092dc0bb85b116">f21a1432</a></strong>
<div>
<span> by Iker Pedrosa </span> <i> at 2026-05-26T10:36:14-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>ci: add TMT passkey tests to packit workflow
Enable automated passkey testing on pull requests after COPR builds
complete. Tests run on fedora-all and centos-stream-10 targets using
the TMT plan.
Signed-off-by: Iker Pedrosa <ipedrosa@redhat.com>
Co-Authored-By: Claude Sonnet 4 <noreply@anthropic.com>
Reviewed-by: Jakub Vávra <jvavra@redhat.com>
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
(cherry picked from commit 210f50f507c8443d1522fd7504b001e95af29950)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/b292c6ddbcc163cf76f158cf310e304535d333c2">b292c6dd</a></strong>
<div>
<span> by Akshay Sakure </span> <i> at 2026-05-26T11:08:48-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Component: sssd-tools
Explanation: This patch will make sure to print correct command on
running 'sssctl analyze --help' command avoiding confusion.
Resolves: https://github.com/SSSD/sssd/issues/8718
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
(cherry picked from commit 30a4940f51736a9b2303a0573b5ca11c9f83ab73)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/1c764c59bfb58be29ca5574a3b1c2b7ea36089df">1c764c59</a></strong>
<div>
<span> by aborah-sudo </span> <i> at 2026-05-27T08:42:33-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Tests: fix the tests to check the new pattern
I got confirmation that this is simply a log change issue. We can fix the tests to check the new pattern.
https://github.com/SSSD/sssd/pull/8540
Reviewed-by: Scott Poore <spoore@redhat.com>
(cherry picked from commit 04d593755659b1afb2139c99c8c31ecc4a6c0436)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/0ab98c7b3984fcf4128486c0efdb07c5e25dd75f">0ab98c7b</a></strong>
<div>
<span> by Pavel Březina </span> <i> at 2026-05-27T17:49:06+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>sdap: handle missing rootDSE gracefully
If `ldap_read_rootdse = never` then srv_opts is NULL which is unexpected.
It can also happen on other path in the connection code, because
sdap_cli_use_rootdse() is called only when the rootDSE is successfully
fetch. This patch makes sure that srv_opts are always set.
:fixes: SSSD no longer crashes if `ldap_read_rootdse = never` and
`enumerate = true`
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Tomáš Halman <thalman@redhat.com>
(cherry picked from commit 2cc7dfa18830336bd75ee8fa7e8a5db40bc253fb)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/fa138120caaf6cda85d0f87de0518988afc18d34">fa138120</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-05-29T13:31:42+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>sdap: defer libldap global options setup to first connection
During initialization LDAP/AD/IPA backends unconditionally call
`setup_tls_config()` and `setup_ldap_debug()` that call
`ldap_set_option()`. This triggers `ldap_int_initialize()` ->
`getaddrinfo(local_hostname)`. If DNS is unresponsive, this blocks
and the backend doesn't complete initialization in time, so that
'monitor' terminates the entire SSSD.
Move these calls out of the module init path into a new
`sdap_setup_libldap_global_options()` wrapper guarded by a static bool.
Call it from `sdap_connect_send()` just before `sss_ldap_init_send()`,
which is the single entry point for all LDAP connections.
:fixes:Fixed an issue where SSSD fails to start when DNS is unresponsive.
Assisted-By: Claude Code (Opus 4.6)
Reviewed-by: Dan Lavu <dlavu@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
Reviewed-by: Tomáš Halman <thalman@redhat.com>
(cherry picked from commit b84e7fa856317cd629a212ddf05e5d5e2e20374d)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/7682b02e3b4e4c8885c9bb3bd1683fa35e0c188b">7682b02e</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-06-01T17:30:15+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Makefile: krb5 plugins: don't export internal symbols
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
(cherry picked from commit 9adeb27348decab9c47307d04e15b379d6bc7d92)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/7b9e0059a04cc440faae633448b9022f6242270c">7b9e0059</a></strong>
<div>
<span> by Akshay Sakure </span> <i> at 2026-06-01T13:40:13-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>sssd man-page: Improve man-page for override_gid
This commit improves the man-page statement for override_gid
option by adding clear description & "Default" value.
Resolves: https://github.com/SSSD/sssd/issues/7341
Signed-off-by: Akshay Sakure <asakure@redhat.com>
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
(cherry picked from commit 5b6c11d507ec9dcd4daef27b683e42af364d8dc7)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/12d538c42e13ef1c66caeab165499455f8e2fb82">12d538c4</a></strong>
<div>
<span> by aborah-sudo </span> <i> at 2026-06-04T07:32:17+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Tests: Disable test_authentication_indicators
Test is avilable as: https://github.com/SSSD/sssd/blob/master/src/tests/system/tests/test_ipa.py#L339
Reviewed-by: Jakub Vávra <jvavra@redhat.com>
(cherry picked from commit c20c27003a45e82d3ea34a8fa151a270483657bd)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/004a8be12056104df74bd53fad8ddaedaf83dbaf">004a8be1</a></strong>
<div>
<span> by dependabot[bot] </span> <i> at 2026-06-04T16:30:34+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>ci: bump cross-platform-actions/action from 1.0.0 to 1.2.0
Bumps [cross-platform-actions/action](https://github.com/cross-platform-actions/action) from 1.0.0 to 1.2.0.
- [Release notes](https://github.com/cross-platform-actions/action/releases)
- [Changelog](https://github.com/cross-platform-actions/action/blob/master/changelog.md)
- [Commits](https://github.com/cross-platform-actions/action/compare/v1.0.0...v1.2.0)
---
updated-dependencies:
- dependency-name: cross-platform-actions/action
dependency-version: 1.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
(cherry picked from commit 9dfd78c7c2fb0b0eb76d0a00d770e8a02de0e908)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/9a3938fc5a0d7d1355454ba2175795dfa13c05b6">9a3938fc</a></strong>
<div>
<span> by Alexey Tikhonov </span> <i> at 2026-06-04T19:59:42+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>RESOLV: handle empty addr list properly
The address list can be NULL or empty when '/etc/hosts' has
an IPv6 only entry and IPv4 was requested or vice versa. It
was treated as an indicator that the name component contains
the path to an LDAPI socket, leading to a crash.
Reviewed-by: Iker Pedrosa <ipedrosa@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
(cherry picked from commit b6e7f0518990cbf786d35d387589dfa690bfa6d8)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/b388d22dbe2142b001f2b8bf96f2bf74b92ca928">b388d22d</a></strong>
<div>
<span> by Akshay Sakure </span> <i> at 2026-06-04T15:02:48-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>sssd man-page: Fix man-page for offline_timeout*
Currently, all the offline_timeout* options are in the wrong section
due to which 'sssctl config-check' gives a WARNING. Ideally, they should
be in DOMAIN SECTIONS.
This PR will move all offline_timeout* options into DOMAIN SECTIONS
and also fix a typo along with a couple of grammatical corrections.
Resolves: https://github.com/SSSD/sssd/issues/7289
Signed-off-by: Akshay Sakure <asakure@redhat.com>
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
(cherry picked from commit c183ecbd2558b61a41e46913482ea64759584baf)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/adf76523c1db58424592a5c662ce7a8489370c08">adf76523</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-06-08T15:36:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>crypto: add get_jwk_from_pkcs12()
To allow signing web tokens with the help of libjose the new function
get_jwk_from_pkcs12() can generate a JSON Web Key (JWK) from a given
PKCS#12 file.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
(cherry picked from commit 8100381136a015ac72452c1d3ff6d71e71232232)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/d50a069694efe430bc2be50f25c6e2713932b3e7">d50a0696</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-06-08T15:36:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>oidc_child: add pkcs12-client-creds option
With the new option pkcs12-client-creds a PKCS#12 file with certificate
and private key can be specified for client authentication. The client
credential will be used as a password to unlock the key in the PKCS#12
file. The PKCS#12 file is used in a way to make mutual TLS (mTLS) work
with an IdP.
:relnote: new oidc_child option --pkcs12-client-creds to specify the
path to a PKCS#12 file with certificate and private key for certificate
based authentication. Password to unlock the private key can be given
with --client-secret or --client-secret-stdin options.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
(cherry picked from commit ec078ea0e99d5b7038b2a77d7c0d1a46eb17eeac)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/7b51a9ba6b5824e77c99d3229765c1271b294cd5">7b51a9ba</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-06-08T15:36:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>oidc_child: add JWT authentication
With the new option --client-auth-method oidc_child can select between
authentication with a client secret, mutual-TLS/mTLS (RFC-8705) and JWT
client assertion (RFC-7523). The latter two require a PKCS#12 file with
the client credentials (certificate and private key) and the password to
unlock the private key must be provided with the --client-secret or
--client-secret-stdin option.
:relnote: new oidc_child option --client-auth-method to select between
authentication with client secret, mutual-TLS/mTLS (RFC-8705) and JWT
client assertion (RFC-7523). For mTLS all key types supported by libcurl
can be used. For JWT RS256, ES256, ES384 and ES512 with matching key
types are supported.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
(cherry picked from commit 6577434c7429c3a176c1ba0dfead0d71f3c3c7e3)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/d217bba4613e381d75a8198305f063487eefe59f">d217bba4</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-06-08T15:36:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>test: add tests for oidc_child 'get-device-code'
This new test call oidc_child with the '--get-device-code' option with
different client authentication methods.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
(cherry picked from commit 9a3487d757d9678b4474f53f76d9bf1832aa0083)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/04f661d6e7ee1ce0e8323f72d6b3a7adfcb290b3">04f661d6</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-06-08T15:36:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>oidc_child: remove potential double-free in JSON code
The reference is always stolen if the 'o' format specifier is used even
in the case of errors.
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
(cherry picked from commit f72a7a69dbc972adecf41544c9c5c4e73ecdd240)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/28ca8cc2851f694fa9ea1b47cbb3d6caf3cb73ae">28ca8cc2</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-06-08T15:36:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>oisc_child: add missing NULL checks
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
(cherry picked from commit 44cd06ba7b58cc92466cd496715042986e19cd7a)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/cd3809bd1e1f117ba036f923bfedbbe6aa100e23">cd3809bd</a></strong>
<div>
<span> by Sumit Bose </span> <i> at 2026-06-08T15:36:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>oidc_child: clarify why a value isn't copied
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
(cherry picked from commit c2f9fff0c8811d62108479be749ef1b90c74980d)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/92172fc3a782a66f01390e9fe9c7291c5ad7028f">92172fc3</a></strong>
<div>
<span> by sssd-bot </span> <i> at 2026-06-08T16:27:41+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>pot: update pot files
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/57209f99cb2b285abe1b20b21bf6b628e9f02eb6">57209f99</a></strong>
<div>
<span> by sssd-bot </span> <i> at 2026-06-08T16:27:41+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Release sssd-2.13.1
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/e08f1bd13cba0a576e086751c071014dfae3a82a">e08f1bd1</a></strong>
<div>
<span> by Jakub Vávra </span> <i> at 2026-06-08T17:33:06-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Tests: Update LdapOperations to fail on bind immediately
Co-authored-by: Cursor <cursoragent@cursor.com>
Reviewed-by: Scott Poore <spoore@redhat.com>
(cherry picked from commit 9df13ca250dcbc0dd37d3d91a13271787111bc8f)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/cb1bdedaad0aa156b82c1f36534d8443f6cc0e67">cb1bdeda</a></strong>
<div>
<span> by kkz </span> <i> at 2026-06-09T13:41:07+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>resolv: Fix incorrect variable used in ares_parse_txt_reply() error check
Reviewed-by: Alexey Tikhonov <atikhono@redhat.com>
Reviewed-by: Alejandro López <allopez@redhat.com>
(cherry picked from commit 4a800e56a52c1eddc4b9e2a379d2e9731be0ef6f)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/b9154c27bd6e5dbac59503c32ef06b8de0f25988">b9154c27</a></strong>
<div>
<span> by sssd-bot </span> <i> at 2026-06-09T12:32:20+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>pot: update pot files
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/sssd-team/sssd/-/commit/7116806484d141b0f6cb051883041b059b6ab29c">71168064</a></strong>
<div>
<span> by sssd-bot </span> <i> at 2026-06-09T12:32:21+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Release sssd-2.13.1
</pre>
</li>
</ul>
<h4 style="margin-top: 10px; margin-bottom: 10px;">
269 changed files:
</h4>
<ul>
<li class="file-stats">
<a href="#60e3091cdc3ed045878712dee12825cf278b767f">
<span class="new-file">
+
.fmf/version
</span>
</a>
</li>
<li class="file-stats">
<a href="#fe77d5d1439f26e353a42bbd38dece2467ff6558">
.github/workflows/build.yml
</a>
</li>
<li class="file-stats">
<a href="#899ce9c202bf7bb5480e72836c3edc773c9c4244">
.github/workflows/ci.yml
</a>
</li>
<li class="file-stats">
<a href="#16911b9809e0d05b7b124ba8453fa5303d74924c">
.github/workflows/release.yml
</a>
</li>
<li class="file-stats">
<a href="#4d938f6c1c694e539e55e88076490273a04798ba">
.github/workflows/static-code-analysis.yml
</a>
</li>
<li class="file-stats">
<a href="#8eef649c6f3efda90b9e4f57ec6593b23880057e">
.packit.yaml
</a>
</li>
<li class="file-stats">
<a href="#d5b4de16d947214ec306bd57bed1bd23a939b5f9">
Makefile.am
</a>
</li>
<li class="file-stats">
<a href="#87db583be5c13c1f7b3c958b10e03d67b6a2ca06">
configure.ac
</a>
</li>
<li class="file-stats">
<a href="#b8d57aa4a09effcbac8deeffe8aea9131499424f">
contrib/sssd.spec.in
</a>
</li>
<li class="file-stats">
<a href="#3d2f764ef24a4af4d2f718f6385375e433c0eeb7">
<span class="deleted-file">
−
contrib/test-suite/README.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#944f00a9afc281fcd148fc61fdc2cf888f624877">
<span class="deleted-file">
−
contrib/test-suite/test-suite.yml
</span>
</a>
</li>
<li class="file-stats">
<a href="#38f794257a78c650a4d3fa3a8732098b1449e34f">
<span class="new-file">
+
plans/passkey.fmf
</span>
</a>
</li>
<li class="file-stats">
<a href="#54d6c31c823e250ebb67120d8dd489a69a02213c">
po/LINGUAS
</a>
</li>
<li class="file-stats">
<a href="#4e573a66c66b45b45a1e180cad791738ed22cdd2">
po/bg.po
</a>
</li>
<li class="file-stats">
<a href="#a7557f237f70a13fa924a18d9d54f6481c9963fd">
<span class="new-file">
+
po/br.po
</span>
</a>
</li>
<li class="file-stats">
<a href="#b91599a7e7dcdfc93152518865a9d894acfe41c9">
po/ca.po
</a>
</li>
<li class="file-stats">
<a href="#fccf081b8d2f9631b6347df4a24d22fac5a73474">
po/cs.po
</a>
</li>
<li class="file-stats">
<a href="#8133f48bcd872819f4d7310d09b4ef30a26831b0">
po/de.po
</a>
</li>
<li class="file-stats">
<a href="#bf0ecd6fd82096852700283e68fd723ccfe57871">
po/es.po
</a>
</li>
<li class="file-stats">
<a href="#804f8c75d12ae05ad9351001530d8575e03a169d">
po/eu.po
</a>
</li>
<li class="file-stats">
<a href="#4a909f28ec13a23ac75c362bf9a9e15669d47d6d">
po/fi.po
</a>
</li>
<li class="file-stats">
<a href="#09aa9a4cf22de79302d7cefe7d280b7235f787c7">
po/fr.po
</a>
</li>
<li class="file-stats">
<a href="#1ea4eac30921a4a13fc7be0b323144e189daec70">
po/hu.po
</a>
</li>
<li class="file-stats">
<a href="#cbd0a16c6ab85833ae5892982bc57d68cc315864">
po/id.po
</a>
</li>
<li class="file-stats">
<a href="#327aa0bc550fa884acca79a3295e722b622f7559">
po/it.po
</a>
</li>
<li class="file-stats">
<a href="#5c873de36a1b57f9c8b16c7fb9cd64292a431fb2">
po/ja.po
</a>
</li>
<li class="file-stats">
<a href="#b4483a69a17ce84171905a68001440348a030887">
po/ka.po
</a>
</li>
<li class="file-stats">
<a href="#462de2f88a6167ce90705f7096ce3afdcfa1d264">
po/ko.po
</a>
</li>
<li class="file-stats">
<a href="#a0adcdda490179b406b32704f47949b4fae75aa9">
<span class="new-file">
+
po/lv.po
</span>
</a>
</li>
<li class="file-stats">
<a href="#088da71e4e8eddb438a4704013c74671ac837fe3">
po/nb.po
</a>
</li>
<li class="file-stats">
<a href="#c54e8255699d35fd83cf0c4800a6cf1fe45533d9">
po/nl.po
</a>
</li>
<li class="file-stats">
<a href="#74adca948cd9fddf7f9644856d4988126ffe9601">
po/pl.po
</a>
</li>
<li class="file-stats">
<a href="#7a488413e07158a724225892439d611e4ba28ba0">
po/pt.po
</a>
</li>
<li class="file-stats">
<a href="#160f60c3dd59b978e505eccda1925dc3923a1d71">
po/pt_BR.po
</a>
</li>
<li class="file-stats">
<a href="#2316433971b53f8a58c69a9c3ce650787e35b3c0">
po/ru.po
</a>
</li>
<li class="file-stats">
<a href="#0d4e896bfdd3ddb2a1208357455cc9d994cf5a94">
po/sssd.pot
</a>
</li>
<li class="file-stats">
<a href="#4a5c1cf4e30bce97baf810ad306a537239e2c52e">
po/sv.po
</a>
</li>
<li class="file-stats">
<a href="#172b5ede9463bce50719ca3fba867887ecdaa56c">
po/tg.po
</a>
</li>
<li class="file-stats">
<a href="#cf4f0b0dadc52f5cd0dfbc7af6bc3ca27ba42355">
po/tr.po
</a>
</li>
<li class="file-stats">
<a href="#b51f8cbe35a8772efe6f023fc1673b635dca1f80">
po/uk.po
</a>
</li>
<li class="file-stats">
<a href="#649f57c2c27e08866163cb3bc5d7709242509a33">
po/zh_CN.po
</a>
</li>
<li class="file-stats">
<a href="#9073c7a6a45185a5d8109b9db2583c3a6ebb6fc0">
po/zh_TW.po
</a>
</li>
<li class="file-stats">
<a href="#22b5f169fa5bd7cfc6c4702a39103021c5f762ba">
<span class="new-file">
+
scripts/fixed-issues.sh
</span>
</a>
</li>
<li class="file-stats">
<a href="#434d06ec78a9b2950366518f9588cb0507800bb6">
<span class="new-file">
+
scripts/generate-full-release-notes.sh
</span>
</a>
</li>
<li class="file-stats">
<a href="#34b8f85ec76d1ba5286fbb01ed53bb5454ac11c8">
<span class="new-file">
+
scripts/generate-release-notes.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#34aeb3b6accb0b44278d3b85aa5697729ce1d38a">
<span class="new-file">
+
scripts/release-notes.sh
</span>
</a>
</li>
<li class="file-stats">
<a href="#683862a8af0d029716fb19dda489378cc3eab5cc">
scripts/release.sh
</a>
</li>
<li class="file-stats">
<a href="#e126e29c556fb5b57b454ff0fe568ab8d23ec4ff">
src/conf_macros.m4
</a>
</li>
<li class="file-stats">
<a href="#8130d92ab2dbb731fb207301f85bd6212a4925e1">
src/confdb/confdb.c
</a>
</li>
<li class="file-stats">
<a href="#87f797812a6c8103120c84edd047870e3d4238fc">
src/confdb/confdb.h
</a>
</li>
<li class="file-stats">
<a href="#1498d4d2f787823f79492cf4f0bac6ca11eb0bf8">
src/config/SSSDConfig/ipachangeconf.py
</a>
</li>
<li class="file-stats">
<a href="#3a143ef9ccd76ba9850988da39e18c709ba194f2">
src/config/SSSDConfig/sssdoptions.py
</a>
</li>
<li class="file-stats">
<a href="#1d29c13360f2093ae9138bc2560306b5f889780e">
src/config/SSSDConfigTest.py
</a>
</li>
<li class="file-stats">
<a href="#e88f08bc547274216ac6b8b404de90b01e62a715">
src/config/cfg_rules.ini
</a>
</li>
<li class="file-stats">
<a href="#0bb5ac26196a4eea2483a67a54e2901eb1654636">
src/config/etc/sssd.api.conf
</a>
</li>
<li class="file-stats">
<a href="#62474e063be5780c2c61f9b6aa3613919abb17ea">
src/db/sysdb.h
</a>
</li>
<li class="file-stats">
<a href="#1ea6ba812516e713c51d55c753e83152ef8d3ce1">
src/db/sysdb_init.c
</a>
</li>
<li class="file-stats">
<a href="#abeebb898a84e42faa346439dce7acf5863620e3">
src/db/sysdb_ops.c
</a>
</li>
<li class="file-stats">
<a href="#1dd9cebb46e3c30e605ff57276e9dbb391477ba4">
src/db/sysdb_private.h
</a>
</li>
<li class="file-stats">
<a href="#0d23baa45350ac5307eec6b21a8fc0554cd5ad5e">
src/db/sysdb_search.c
</a>
</li>
<li class="file-stats">
<a href="#43f78164d84c68f68eaa0a02400af17f255c19a0">
src/db/sysdb_subdomains.c
</a>
</li>
<li class="file-stats">
<a href="#8f544b4fd9b85877e668a95259d67522f81addac">
src/db/sysdb_sudo.h
</a>
</li>
<li class="file-stats">
<a href="#0d391f4ff5f17702e3752f69ba8eb6a97b419933">
src/db/sysdb_upgrade.c
</a>
</li>
<li class="file-stats">
<a href="#36b6e461fd3643c0547766f376de511cd75ef187">
src/db/sysdb_views.c
</a>
</li>
<li class="file-stats">
<a href="#83417efe6814c6c33480bb336ac7c8c4aee511f4">
src/doxy.config.in
</a>
</li>
<li class="file-stats">
<a href="#e531e9af44afa78ae024144b5dbb28622ec4431b">
src/external/cifsidmap.m4
</a>
</li>
<li class="file-stats">
<a href="#a86518a6c3e73e5ee74250d55d25d174685062ec">
src/external/crypto.m4
</a>
</li>
<li class="file-stats">
<a href="#044af449fb178d5ed76ca761a1b8a18fb69f8654">
src/external/libcmocka.m4
</a>
</li>
<li class="file-stats">
<a href="#f2410a866f455eb5c3971f18cc5f1bb1944039e6">
src/external/libnfsidmap.m4
</a>
</li>
<li class="file-stats">
<a href="#be457717636aed981d743600acd0da03d027c1dc">
src/external/platform.m4
</a>
</li>
<li class="file-stats">
<a href="#758e10225ce03051cadddc52e2b8735afdc65734">
src/external/test_ca.m4
</a>
</li>
<li class="file-stats">
<a href="#568e5f296eacd317e50066befcbfb0b49182c0dc">
src/ldb_modules/memberof.c
</a>
</li>
<li class="file-stats">
<a href="#3aa96b43c5e95d75de293f843cf9cd5381c0b4e8">
src/lib/certmap/sss_cert_content_crypto.c
</a>
</li>
<li class="file-stats">
<a href="#6e77cf7d4d9bc0edb1c7a8d691a09304df60d5b7">
src/lib/certmap/sss_certmap.c
</a>
</li>
<li class="file-stats">
<a href="#0da8c90bb708d439f69e3d2d5808cff5a0b62d0c">
src/lib/certmap/sss_certmap.h
</a>
</li>
<li class="file-stats">
<a href="#7f95ad430e6e971a3947bece1b987cf19404dae1">
src/lib/certmap/sss_certmap_int.h
</a>
</li>
<li class="file-stats">
<a href="#5b9c96988a655f2faf1f904b585263765d0841ec">
src/lib/idmap/sss_idmap.h
</a>
</li>
<li class="file-stats">
<a href="#6e1ebca399d2e51448a7e1e675936b198aeecc4c">
src/lib/ipa_hbac/ipa_hbac.doxy.in
</a>
</li>
<li class="file-stats">
<a href="#378d022775f860275fb91aa34dbaf01c1efcfbbd">
src/lib/winbind_idmap_sss/winbind_idmap_sss.c
</a>
</li>
<li class="file-stats">
<a href="#ea8ae28ff50b5ec3d4bb4589644460604ca13b96">
src/lib/winbind_idmap_sss/winbind_idmap_sss.h
</a>
</li>
<li class="file-stats">
<a href="#e18f93a0c17ea91445d7fed901e611619d18af9c">
src/man/Makefile.am
</a>
</li>
<li class="file-stats">
<a href="#1a14ea8a5b18a9fbef9dacadc62f41f230680b65">
<span class="new-file">
+
src/man/po/bg.po
</span>
</a>
</li>
<li class="file-stats">
<a href="#57f6acb472af7084a87335932ea41992bb30a35d">
src/man/po/br.po
</a>
</li>
<li class="file-stats">
<a href="#dbfa196c52236ac697f5c119cf3f3802197e5a49">
src/man/po/ca.po
</a>
</li>
<li class="file-stats">
<a href="#8226d5e4ce16f6cd0b6ae2c43243684f17d6e40e">
src/man/po/cs.po
</a>
</li>
<li class="file-stats">
<a href="#587621c0831f8ec13ffe600166e06205a199f554">
src/man/po/de.po
</a>
</li>
<li class="file-stats">
<a href="#a7861c52f3b1006d4e23c46d7663efe04f921c7d">
src/man/po/es.po
</a>
</li>
<li class="file-stats">
<a href="#35f0f810b0e5ae3cbc43a48543d79019213497d2">
src/man/po/eu.po
</a>
</li>
<li class="file-stats">
<a href="#34df2355e4ceaf43b259198016c3a20490cfee60">
src/man/po/fi.po
</a>
</li>
<li class="file-stats">
<a href="#6d4ef8b31fd19b2c25cd7921c670444f27b16f9b">
src/man/po/fr.po
</a>
</li>
<li class="file-stats">
<a href="#eaf89bbf9773f4743e1fbb8aa93ace9563e5b32a">
<span class="new-file">
+
src/man/po/hu.po
</span>
</a>
</li>
<li class="file-stats">
<a href="#d08f88c0c972cbfa83515963953872b2e0d62b0c">
<span class="new-file">
+
src/man/po/id.po
</span>
</a>
</li>
<li class="file-stats">
<a href="#078eaa11aafc74576c291a947642fc33153f2fef">
<span class="new-file">
+
src/man/po/it.po
</span>
</a>
</li>
<li class="file-stats">
<a href="#04d8b4e374b1f0212c6bc04201c100c75b25bd4e">
src/man/po/ja.po
</a>
</li>
<li class="file-stats">
<a href="#731dbb5f2b43f5d596f388421d95b493a3f8221c">
src/man/po/ko.po
</a>
</li>
<li class="file-stats">
<a href="#2ffeb6e778f4398348d9172f8a863195d3fa45ad">
src/man/po/lv.po
</a>
</li>
<li class="file-stats">
<a href="#bf8950fdfb813f8c1bbbd3cc76c078a318bf79d7">
<span class="new-file">
+
src/man/po/nb_NO.po
</span>
</a>
</li>
<li class="file-stats">
<a href="#0e7fc554b6d1752b42d6a4bcc3cdfc3c0b624c8c">
src/man/po/nl.po
</a>
</li>
<li class="file-stats">
<a href="#34f36500467b30b0fa1f54d1029b8e4578a5decb">
src/man/po/pt.po
</a>
</li>
<li class="file-stats">
<a href="#25665ba0820f06ec80ccb9fc2d793095221dbc66">
src/man/po/pt_BR.po
</a>
</li>
<li class="file-stats">
<a href="#1574269bb5b331ca21ad843da9cc0eefdde27d80">
src/man/po/ru.po
</a>
</li>
<li class="file-stats">
<a href="#4b723b8389be78693507a4fd8565d5ea64ad01ae">
src/man/po/sssd-docs.pot
</a>
</li>
<li class="file-stats">
<a href="#bbac6a79a3c8139e03a39fdada355f01d3f9dfec">
src/man/po/sv.po
</a>
</li>
<li class="file-stats">
<a href="#b5bb1b007d2520b49ccd10acef65bde92d63114e">
src/man/po/tg.po
</a>
</li>
<li class="file-stats">
<a href="#4250bb264e4f8c2963c10a87a328c4d33e2f8454">
<span class="new-file">
+
src/man/po/tr.po
</span>
</a>
</li>
<li class="file-stats">
<a href="#ea51d4c8341a5c277996b86eaf6ec79414e067a6">
src/man/po/uk.po
</a>
</li>
<li class="file-stats">
<a href="#f071078a9da76bc6ab756e2c2ce9c65575a26f1a">
src/man/po/zh_CN.po
</a>
</li>
<li class="file-stats">
<a href="#cf3f93e29f743acaf3a01ab22fbb3857ad0f6469">
src/man/sss_ssh_knownhosts.1.xml
</a>
</li>
<li class="file-stats">
<a href="#b254640277cb6fb002bebc29ef8542b13b30d17d">
src/man/sssd-ad.5.xml
</a>
</li>
<li class="file-stats">
<a href="#2adc864b4dd4752d81a247135f57a9071deb4046">
src/man/sssd-idp.5.xml
</a>
</li>
<li class="file-stats">
<a href="#626322c16d5b424d9999f3fa7a267744cb65d4a5">
src/man/sssd.conf.5.xml
</a>
</li>
<li class="file-stats">
<a href="#5913ebac1444467e157818457b4dea69e4d3990e">
src/man/sssd_krb5_localauth_plugin.8.xml
</a>
</li>
<li class="file-stats">
<a href="#1397c97561904cbc9e5bcca697e9ce3cef1ed2bf">
src/monitor/monitor.c
</a>
</li>
<li class="file-stats">
<a href="#98c26479dc748026b703f505df7792519ab8cbcb">
<span class="new-file">
+
src/oidc_child/libcrypto/oidc_child_get_jwk.c
</span>
</a>
</li>
<li class="file-stats">
<a href="#6ab20b02df813e328ed7b95629460efc5d4dbe0b">
src/oidc_child/oidc_child.c
</a>
</li>
<li class="file-stats">
<a href="#4991418753e1ee50e03dfe7f8d5f52bcdef2e4aa">
src/oidc_child/oidc_child_curl.c
</a>
</li>
<li class="file-stats">
<a href="#183c77d882e10449fd1c5d1f24244ae27228541c">
src/oidc_child/oidc_child_id.c
</a>
</li>
<li class="file-stats">
<a href="#099a7b44a095ab78a9fdc1c324adacde9f4d7894">
src/oidc_child/oidc_child_json.c
</a>
</li>
<li class="file-stats">
<a href="#ef5a602d38640d383528a5936a26e57b01ab0bf1">
src/oidc_child/oidc_child_util.h
</a>
</li>
<li class="file-stats">
<a href="#18fbf36328b2b02c1049457bc9f48620252bdfc4">
src/p11_child/p11_child.h
</a>
</li>
<li class="file-stats">
<a href="#528db958897fe0a80822662fde8df19331c57d26">
src/p11_child/p11_child_common.c
</a>
</li>
<li class="file-stats">
<a href="#7837fdcaa82984cacf93933714336ebef6623096">
src/p11_child/p11_child_common_utils.c
</a>
</li>
<li class="file-stats">
<a href="#dd3bd903b743c7cf118465a4b7373b06f652690c">
src/p11_child/p11_child_openssl.c
</a>
</li>
<li class="file-stats">
<a href="#5eb81c88743789d04b87e6665e387f7e487e185a">
src/passkey_child/passkey_child.c
</a>
</li>
<li class="file-stats">
<a href="#0f94b06fc8aa2589ccca1d52981260f54eb527d5">
src/passkey_child/passkey_child.h
</a>
</li>
<li class="file-stats">
<a href="#51f493875cc31f5ace607b241f3470dd340caec1">
src/passkey_child/passkey_child_assert.c
</a>
</li>
<li class="file-stats">
<a href="#9e4f7254f8fad9d2bbc5760e33a3a5ee6b76f9fa">
src/passkey_child/passkey_child_credentials.c
</a>
</li>
<li class="file-stats">
<a href="#c98756a385b67d79b3d62cdf231d9b815395c997">
src/passkey_child/passkey_child_devices.c
</a>
</li>
<li class="file-stats">
<a href="#d15015343f63217e9e17ba58c426efce33cb7032">
src/providers/ad/ad_access.c
</a>
</li>
<li class="file-stats">
<a href="#c77e1b74ff214c15682f3a3c79525c5c708e29b5">
src/providers/ad/ad_common.c
</a>
</li>
<li class="file-stats">
<a href="#0443b792d6a313cef630a4edef240cfe2f86a091">
src/providers/ad/ad_common.h
</a>
</li>
<li class="file-stats">
<a href="#44bb941c322c62d06544f7896cd9dd62481039aa">
src/providers/ad/ad_gpo.c
</a>
</li>
<li class="file-stats">
<a href="#731b1b746b539fdd171ef2b8a8820210fe522d2b">
src/providers/ad/ad_gpo_child.c
</a>
</li>
<li class="file-stats">
<a href="#0fadf0fd5297098f8497c38cf0f23cd89af9586b">
src/providers/ad/ad_gpo_child_utils.c
</a>
</li>
<li class="file-stats">
<a href="#355133f160040a075ceb42e271a56fc20d7a87dd">
src/providers/ad/ad_id.c
</a>
</li>
<li class="file-stats">
<a href="#eb2138dad7b7bd32bd459f80437e8d5037e2501d">
src/providers/ad/ad_init.c
</a>
</li>
<li class="file-stats">
<a href="#980671763f2ac5f9c3efa481530e86082a2d995b">
src/providers/ad/ad_opts.c
</a>
</li>
<li class="file-stats">
<a href="#2473d5978a8d65afb7258a6a59f2cf26e2be4266">
src/providers/ad/ad_opts.h
</a>
</li>
<li class="file-stats">
<a href="#ca329c595b45e031dda80c84b284657a5ff3259c">
src/providers/ad/ad_pac.c
</a>
</li>
<li class="file-stats">
<a href="#06ed918fb6fb127f81b5a23167130adad18d7e58">
src/providers/ad/ad_pac_common.c
</a>
</li>
<li class="file-stats">
<a href="#b776212f5dad9690254fbd6710fc976e2f97fe3a">
src/providers/ad/ad_subdomains.c
</a>
</li>
<li class="file-stats">
<a href="#447b78c5d3803eb98437f4c550d733c71195eaa6">
src/providers/be_dyndns.c
</a>
</li>
<li class="file-stats">
<a href="#502225b7e61da744e139fb97655904951e79be14">
src/providers/be_ptask.h
</a>
</li>
<li class="file-stats">
<a href="#5d2ebf5d53b859dddbbbee669cb50d5faa03d6d5">
src/providers/be_refresh.c
</a>
</li>
<li class="file-stats">
<a href="#a3874461e57eb0745a14aa02a63abea70894af9c">
src/providers/data_provider/dp_request.h
</a>
</li>
<li class="file-stats">
<a href="#fd2ba5ae820394db98bb5800a2dc5cfa0199a02e">
src/providers/data_provider/dp_target_id.c
</a>
</li>
<li class="file-stats">
<a href="#d9a483d0ffdfbdf6547d66b7f771b58ca8ff4b54">
src/providers/fail_over.c
</a>
</li>
<li class="file-stats">
<a href="#7723a6ffa9d81b60cc7cb3b14be3b1b0319b6384">
src/providers/fail_over.h
</a>
</li>
<li class="file-stats">
<a href="#1df4422a5dc3cbe8e4e210688b710a84d92b5cfa">
src/providers/idp/idp_auth.c
</a>
</li>
<li class="file-stats">
<a href="#6e2e485d5469ab6e22af212b800440073455b298">
src/providers/idp/idp_auth.h
</a>
</li>
<li class="file-stats">
<a href="#738e9d1d4aae8a447f90024433b84364c22b6b9a">
src/providers/idp/idp_auth_eval.c
</a>
</li>
<li class="file-stats">
<a href="#56a1883bb33c070bb914bcfaffadc454a48e94ef">
src/providers/idp/idp_common.h
</a>
</li>
<li class="file-stats">
<a href="#56bcdeb4ef06422684cf1039317592441e55d096">
src/providers/idp/idp_id_eval.c
</a>
</li>
<li class="file-stats">
<a href="#5b5fe501bb22867c14acb0c56e60112abef3ad9d">
src/providers/idp/idp_init.c
</a>
</li>
<li class="file-stats">
<a href="#e48af9954838df68fcc4c92f52874c9b30824fcc">
src/providers/idp/idp_opts.c
</a>
</li>
<li class="file-stats">
<a href="#c44779db0d3565fae9cca443c92a74a917bab370">
src/providers/ipa/ipa_access.c
</a>
</li>
<li class="file-stats">
<a href="#f0dfc4e8edb3c48b1634d30c72f0e706e21cbd98">
src/providers/ipa/ipa_auth.c
</a>
</li>
<li class="file-stats">
<a href="#b0bd846f4f6cdf5cd4e8291c307a6d23a1232f56">
src/providers/ipa/ipa_common.c
</a>
</li>
<li class="file-stats">
<a href="#e06e2bde6e09ec5590e1b4fa84054c1b61eeedd5">
src/providers/ipa/ipa_hbac_services.c
</a>
</li>
<li class="file-stats">
<a href="#bf1e9708ed6620d6545c51f85170b70ef672d967">
src/providers/ipa/ipa_id.c
</a>
</li>
<li class="file-stats">
<a href="#3df14dea467e2d73553329242c3e91678e620836">
src/providers/ipa/ipa_init.c
</a>
</li>
<li class="file-stats">
<a href="#8b131ba0d1451cd1a5e3c7511c96f777092226e6">
src/providers/ipa/ipa_opts.c
</a>
</li>
<li class="file-stats">
<a href="#877462785ba3a1495e5913e085e1d37e703c42ab">
src/providers/ipa/ipa_s2n_exop.c
</a>
</li>
<li class="file-stats">
<a href="#c85ae2a4e061a15f171c9f5c8f1c86cd4e8ad5ab">
src/providers/ipa/ipa_subdomains_id.c
</a>
</li>
<li class="file-stats">
<a href="#22b707ea44a5a6fceea501064f4f24ae956ec67b">
src/providers/krb5/krb5_auth.c
</a>
</li>
<li class="file-stats">
<a href="#430c660511b41fd57eb9449306b57a6cdb16f7ec">
src/providers/krb5/krb5_child.c
</a>
</li>
<li class="file-stats">
<a href="#4dc91a642119ab30cef10c739427d1e1bb11e18a">
src/providers/krb5/krb5_common.c
</a>
</li>
<li class="file-stats">
<a href="#ad2589cd23cc049d3daa7fcc13f39301d2df9907">
src/providers/krb5/krb5_delayed_online_authentication.c
</a>
</li>
<li class="file-stats">
<a href="#c831712cb27a9f0dd3ccb3124a5770ca5e2b10fe">
src/providers/krb5/krb5_init.c
</a>
</li>
<li class="file-stats">
<a href="#197041da5372d4ca204093ba02047ab07f0096ba">
src/providers/krb5/krb5_keytab.c
</a>
</li>
<li class="file-stats">
<a href="#adf410ab7fa21f1dd9b5c5add7fc9dc3e8934a79">
src/providers/ldap/ldap_auth.c
</a>
</li>
<li class="file-stats">
<a href="#a2dd5c43ec7a02d3ccc754edf19f107d54c37a26">
src/providers/ldap/ldap_init.c
</a>
</li>
<li class="file-stats">
<a href="#a4eaa60a643bf66ea1508a712bc9bfba04575ebf">
src/providers/ldap/sdap.c
</a>
</li>
<li class="file-stats">
<a href="#a515b227fd0b9b56cb96257898c923760995c8d2">
src/providers/ldap/sdap.h
</a>
</li>
<li class="file-stats">
<a href="#3dca029957804f388b5586ecd15e2befa972dab0">
src/providers/ldap/sdap_async.c
</a>
</li>
<li class="file-stats">
<a href="#515b731eb0cbc9863f0535dae137b43fe31eeec5">
src/providers/ldap/sdap_async.h
</a>
</li>
<li class="file-stats">
<a href="#952f0470b16e09e7729688ffad77df5b2185a710">
src/providers/ldap/sdap_async_connection.c
</a>
</li>
<li class="file-stats">
<a href="#66848bc4e05a3a7c2cb4b96f4074287bda4044e9">
src/providers/ldap/sdap_async_groups.c
</a>
</li>
<li class="file-stats">
<a href="#9a6a2d1f5f892682b839a7a77e509962a5e6fe41">
src/providers/ldap/sdap_async_initgroups.c
</a>
</li>
<li class="file-stats">
<a href="#dc16f7e93d1f63a04fe54c6eab43aaec956cdcc6">
src/providers/ldap/sdap_async_nested_groups.c
</a>
</li>
<li class="file-stats">
<a href="#5802675df0737ba1f3bbfcc06e0dc43aeb8801dc">
src/providers/ldap/sdap_async_private.h
</a>
</li>
<li class="file-stats">
<a href="#39c6b60ae1541a5541f774044eda95e634aa13e7">
src/providers/ldap/sdap_child_helpers.c
</a>
</li>
<li class="file-stats">
<a href="#58b7f2ff0517287684641a587eabbd4f46c2be08">
src/providers/ldap/sdap_id_op.c
</a>
</li>
<li class="file-stats">
<a href="#cfc5e987cb3a2ce309a7ec43dcb7898deb5e4570">
src/providers/ldap/sdap_online_check.c
</a>
</li>
<li class="file-stats">
<a href="#57d580e27b70c56082152954840d32b28a7acd7a">
src/providers/ldap/sdap_range.c
</a>
</li>
<li class="file-stats">
<a href="#d831c0fd4563e1fe83adb0b2cd9020068c5ce7c8">
src/python/sss_python.h
</a>
</li>
<li class="file-stats">
<a href="#d09bcdcb6efe36b1904b4448d7397ab8d5489405">
src/resolv/async_resolv.c
</a>
</li>
<li class="file-stats">
<a href="#71caf581941f69201c2a094427add2115b0cfcbe">
src/responder/common/cache_req/cache_req.c
</a>
</li>
<li class="file-stats">
<a href="#bafe11eaecd7a2e91d7df8b2bdaa9ea8c0d60a13">
src/responder/common/cache_req/cache_req_private.h
</a>
</li>
<li class="file-stats">
<a href="#7bfaa921c3fe7cce88126a8248c71eb5d0368c0f">
src/responder/common/cache_req/cache_req_search.c
</a>
</li>
<li class="file-stats">
<a href="#ab4ecb0b0abd1a85cc7460664602b6bd2064b483">
src/responder/common/cache_req/plugins/cache_req_user_by_filter.c
</a>
</li>
<li class="file-stats">
<a href="#7819b0770a45e7a8fff9af3a04937e8d61726aa5">
src/responder/common/responder_common.c
</a>
</li>
<li class="file-stats">
<a href="#10c071cc9149f6e7cb82d7239cf0c35b52430845">
src/responder/kcm/kcm_renew.c
</a>
</li>
<li class="file-stats">
<a href="#5ccff53e0f74b403e2f1603a6f23bae124c67e44">
src/responder/pam/pam_prompting_config.c
</a>
</li>
<li class="file-stats">
<a href="#996adc41dcca06b96179e99ed69a43f05db26a20">
src/responder/pam/pamsrv.c
</a>
</li>
<li class="file-stats">
<a href="#eff5c8ffef23773d338cb9bd31da680e849f1179">
src/responder/pam/pamsrv.h
</a>
</li>
<li class="file-stats">
<a href="#518b9ae773ac3e405c9bfc68e949c33aff4d144d">
src/responder/pam/pamsrv_cmd.c
</a>
</li>
<li class="file-stats">
<a href="#be92edb1dfc85b71ea7118d6a7107055e384dd2a">
src/responder/pam/pamsrv_gssapi.c
</a>
</li>
<li class="file-stats">
<a href="#60c2b528a40320dfcb9a774c8fff7cf9aa1a49fc">
src/responder/pam/pamsrv_json.c
</a>
</li>
<li class="file-stats">
<a href="#43f517ac5eb4791e2adba7a58eee9c13e79ab681">
src/responder/pam/pamsrv_p11.c
</a>
</li>
<li class="file-stats">
<a href="#a1110a0c741e2dde98cae14e3cc43c0833adda37">
src/responder/pam/pamsrv_passkey.c
</a>
</li>
<li class="file-stats">
<a href="#2095b7c986b6f7bae4d017bdb5931fbbbf37e107">
src/sbus/sbus_message.h
</a>
</li>
<li class="file-stats">
<a href="#febf2da3acb9f67c49c910a357cd41ef8b57d674">
src/shared/cred.h
</a>
</li>
<li class="file-stats">
<a href="#ab5794642a9fc112c83653fcfb2dd59c497770c6">
src/sss_client/autofs/sss_autofs.c
</a>
</li>
<li class="file-stats">
<a href="#d7a290b5f41a40c4b030749d1676fca72422d817">
src/sss_client/common.c
</a>
</li>
<li class="file-stats">
<a href="#ad720a2283eca311d50c26afe882737dccd4d255">
src/sss_client/pam_sss.c
</a>
</li>
<li class="file-stats">
<a href="#723e0bd732da14f51b8695a46d10c51b8aa465a2">
src/sss_client/pam_sss_prompt_config.c
</a>
</li>
<li class="file-stats">
<a href="#d1e6a840bac6311e68c734760827990eabeb8a33">
src/sss_client/sss_cli.h
</a>
</li>
<li class="file-stats">
<a href="#68f4c9f0a3af28dc801c360a4fcd49ea5b320f64">
src/sysv/systemd/sssd.service.in
</a>
</li>
<li class="file-stats">
<a href="#cce301cc4f9329d2f0b95cfc671985dbdcd342ef">
src/tests/cmocka/common_mock_sdap.c
</a>
</li>
<li class="file-stats">
<a href="#805b2b06965de497d9c846fc77d2f4235660ee6e">
src/tests/cmocka/common_mock_sysdb_objects.c
</a>
</li>
<li class="file-stats">
<a href="#cec4b45da498c28297adea940f962446c440e4ff">
src/tests/cmocka/test_authtok.c
</a>
</li>
<li class="file-stats">
<a href="#e8d3bce456a7a93e1966874462a293106bb9f62e">
src/tests/cmocka/test_cert_utils.c
</a>
</li>
<li class="file-stats">
<a href="#d4f3b042365e3bb99254c1da1815d2834711db9d">
src/tests/cmocka/test_nested_groups.c
</a>
</li>
<li class="file-stats">
<a href="#a02873f4a40141f3cb8ce104d5275c115e6da6b3">
src/tests/cmocka/test_pam_srv.c
</a>
</li>
<li class="file-stats">
<a href="#5fbf858a55dba2b4c28c6038e71a363dc6bc2767">
src/tests/cmocka/test_prompt_config.c
</a>
</li>
<li class="file-stats">
<a href="#52b29c0098d38ea4b939f89ffea54b4ba4702097">
src/tests/cmocka/test_sysdb_views.c
</a>
</li>
<li class="file-stats">
<a href="#9f868a953cb748f46e7af9157a6845442d800e1a">
src/tests/cwrap/cwrap_test_setup.sh
</a>
</li>
<li class="file-stats">
<a href="#9a271074c8644a1177d7d62914ac7d361042e347">
src/tests/cwrap/test_responder_common.c
</a>
</li>
<li class="file-stats">
<a href="#e0fac9afa989ed9479dab970905c8de290eb5c27">
src/tests/double_semicolon_test
</a>
</li>
<li class="file-stats">
<a href="#c86699bc4e1931938b7c3e8f79a746d166b77ed3">
src/tests/intg/Makefile.am
</a>
</li>
<li class="file-stats">
<a href="#a8cdd72d12f9049cb47253ce6d3b9973e2ca0c07">
<span class="deleted-file">
−
src/tests/intg/test_memory_cache.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#c48749e0c136e7c8e0b64d6181a8c6fbb34c8813">
<span class="deleted-file">
−
src/tests/intg/test_netgroup.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#8f2259748f327b46c0082ef020953e664d202b52">
src/tests/multihost/alltests/test_kcm.py
</a>
</li>
<li class="file-stats">
<a href="#f5c1792041b6983236f48a9d8fc61bb8c7354b8e">
src/tests/multihost/ipa/test_misc.py
</a>
</li>
<li class="file-stats">
<a href="#3a14a712e9b4d3dc6fdeee7e7dd6e06c48143081">
src/tests/multihost/sssd/testlib/common/utils.py
</a>
</li>
<li class="file-stats">
<a href="#8bff5a4151cbdeb61119d4471d6b3f44e105e265">
src/tests/sysdb-tests.c
</a>
</li>
<li class="file-stats">
<a href="#70f93eed386bab59272257d2085e0f6e0dcb24a9">
src/tests/system/tests/test_access_control_ldap_filter.py
</a>
</li>
<li class="file-stats">
<a href="#4055e41fe83cdc55b35b70c0b04c7b79200b9f22">
src/tests/system/tests/test_ad.py
</a>
</li>
<li class="file-stats">
<a href="#5e41c10984d4f396af5296c3e31f2a0d9d34e65b">
src/tests/system/tests/test_failover.py
</a>
</li>
<li class="file-stats">
<a href="#4754e114f9d4e26a734d3693b2576544c93b07b1">
src/tests/system/tests/test_gdm.py
</a>
</li>
<li class="file-stats">
<a href="#8618442f80ca1aa7571af007f4d4dd5d8b415c31">
<span class="deleted-file">
−
src/tests/system/tests/test_gdm_passkey.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#eda4765bb5962cbaf071820e20b6162ca897597e">
src/tests/system/tests/test_gpo.py
</a>
</li>
<li class="file-stats">
<a href="#94a37238321a42ba9218173d11841c16c4124978">
src/tests/system/tests/test_identity.py
</a>
</li>
<li class="file-stats">
<a href="#de039fb47c3fe72466e62ecdf72b3698a970e13a">
src/tests/system/tests/test_idp.py
</a>
</li>
<li class="file-stats">
<a href="#6e5906a9641eab20a308bd1215c1fe4e7998f954">
src/tests/system/tests/test_infopipe.py
</a>
</li>
<li class="file-stats">
<a href="#12870276c1e39d1b07d1c70799d3455c98b542d0">
src/tests/system/tests/test_ipa.py
</a>
</li>
<li class="file-stats">
<a href="#6c58d7f661f40f2017026b7c2bdaa8acf5027f5c">
src/tests/system/tests/test_kcm.py
</a>
</li>
<li class="file-stats">
<a href="#ffae9856107e48a229a37faee75174efc804f027">
<span class="new-file">
+
src/tests/system/tests/test_ldap_krb5.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#07b8153b71be43b61c947a3fa65275c5c25121c0">
src/tests/system/tests/test_logging.py
</a>
</li>
<li class="file-stats">
<a href="#815db17ac5bd955586ec749adad3924b6b74eee8">
src/tests/system/tests/test_memcache.py
</a>
</li>
<li class="file-stats">
<a href="#0d04098618d152925cfbbee1b4891a20db4e7e3a">
src/tests/system/tests/test_oidc_child.py
</a>
</li>
<li class="file-stats">
<a href="#6e96edd4fb188de824b188c6c9cd3e29be3cef29">
src/tests/system/tests/test_proxy.py
</a>
</li>
<li class="file-stats">
<a href="#e03a6c3e44fbd313ed813716f834c46fb8433a44">
src/tests/system/tests/test_pysss_nss_idmap.py
</a>
</li>
<li class="file-stats">
<a href="#aa04a56609bbb593015d4615b2f12847de64eb52">
src/tests/system/tests/test_smartcard.py
</a>
</li>
<li class="file-stats">
<a href="#3cb1a645e833ba00c0b3bf4b44809e5a49e0f6f5">
<span class="new-file">
+
src/tests/system/tests/test_socket.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#4724e6ae97b236b6fa1176e1f05bcb9203474cb6">
src/tests/system/tests/test_sudo.py
</a>
</li>
<li class="file-stats">
<a href="#42cade825a52d152223758d3b26b21a1aa5acf52">
src/tests/system/tests/test_tools.py
</a>
</li>
<li class="file-stats">
<a href="#884c75b3f0fce12d8dd7becfc657169857b05529">
src/tests/test_CA/Makefile.am
</a>
</li>
<li class="file-stats">
<a href="#6222794e1e0cbf1e8fe6fa9d772e7654e9f3115c">
src/tests/test_ECC_CA/Makefile.am
</a>
</li>
<li class="file-stats">
<a href="#4bfc3c9b44c7fdfec9a6f2394d821990a3bb485f">
src/tests/whitespace_test
</a>
</li>
<li class="file-stats">
<a href="#ac158a1d55a1f9d813adfb5a959b5792a746b8a9">
src/tools/analyzer/sss_analyze.py
</a>
</li>
<li class="file-stats">
<a href="#333b5f1526b3f973892fbe85c386947e2c059131">
src/tools/sssctl/sssctl_config.c
</a>
</li>
<li class="file-stats">
<a href="#da7d2ebfdd58c4f578f0da624ff3fc4a9083b2da">
src/util/authtok.c
</a>
</li>
<li class="file-stats">
<a href="#0fbd2dc1e505374ba766c44a82d4dfae24422000">
src/util/authtok.h
</a>
</li>
<li class="file-stats">
<a href="#3b46ae779b0a9bd9fc2420c7fbeca25a585fb9f3">
src/util/child_common.h
</a>
</li>
<li class="file-stats">
<a href="#1b56bfce72420d4d5f200464dd3cf4ac1584da4d">
src/util/child_handlers.c
</a>
</li>
<li class="file-stats">
<a href="#e47cafa0eba1d8e82561d1d6a8f80edf30c2a16e">
src/util/debug.h
</a>
</li>
<li class="file-stats">
<a href="#c2f9ace2969d5030820c40b16af9da127c0ef113">
src/util/find_uid.c
</a>
</li>
<li class="file-stats">
<a href="#9fb0246a64f1577e4a9e6708aac83dc74b1a4462">
<span class="deleted-file">
−
src/util/selinux.c
</span>
</a>
</li>
<li class="file-stats">
<a href="#925a989ade318787c331c43ab34625d66268fc9f">
src/util/sss_ini.c
</a>
</li>
<li class="file-stats">
<a href="#993f76db2ec4677be80052af21fea9bf767b7c7d">
src/util/sss_ini.h
</a>
</li>
<li class="file-stats">
<a href="#08c1d63019f39d5f787332b9d12eecb7c4d74dce">
src/util/sss_tc_utf8.c
</a>
</li>
<li class="file-stats">
<a href="#be6cfd8bad0abb4112f475118c434d54ce45f5fd">
src/util/usertools.c
</a>
</li>
<li class="file-stats">
<a href="#641a45ff5a6b25264c45c963f2ca9d7e9d5c5b55">
src/util/util.c
</a>
</li>
<li class="file-stats">
<a href="#dfaa328ba65cbcfe079945a9d0fcbf665047e568">
src/util/util.h
</a>
</li>
<li class="file-stats">
<a href="#457c4a3ba22f5b9e4bcc0cced82e90f6bec37b42">
src/util/util_errors.c
</a>
</li>
<li class="file-stats">
<a href="#fb14cf8ce632e04f35bcacb480a8a5659b41a27b">
src/util/util_errors.h
</a>
</li>
<li class="file-stats">
<a href="#836d4fe4ee2163d2f04919c9dd927c460d8d4ef6">
version.m4
</a>
</li>
</ul>
<h5 style="margin-top: 10px; margin-bottom: 10px; font-size: .875rem;">
The diff was not included because it is too large.
</h5>
</div>
<div class="footer" style="margin-top: 10px;">
<p style="font-size: small; color: #626168;">
—
<br>
<a href="https://salsa.debian.org/sssd-team/sssd/-/compare/1a1cf163b78ff4768cc8bfc1e631171bc021e2fe...7116806484d141b0f6cb051883041b059b6ab29c">View it on GitLab</a>.
<br>
You're receiving this email because of your account on <a target="_blank" rel="noopener noreferrer" href="https://salsa.debian.org">salsa.debian.org</a>. <a href="https://salsa.debian.org/-/profile/notifications" target="_blank" rel="noopener noreferrer" class="mng-notif-link">Manage all notifications</a> · <a href="https://salsa.debian.org/help" target="_blank" rel="noopener noreferrer" class="help-link">Help</a>
<span style="color: transparent; font-size: 0; display: none; overflow: hidden; opacity: 0; width: 0; height: 0; max-width: 0; max-height: 0;">
Notification message regarding https://salsa.debian.org/sssd-team/sssd/-/compare/1a1cf163b78ff4768cc8bfc1e631171bc021e2fe...7116806484d141b0f6cb051883041b059b6ab29c at 1785740988
</span>
</p>
</div>
</body>
</html>