[Pkg-freeipa-devel] [Git][freeipa-team/bind-dyndb-ldap][master] 23 commits: control: update standards version

Timo Aaltonen (@tjaalton) gitlab at salsa.debian.org
Mon Sep 28 15:19:39 BST 2026



Timo Aaltonen pushed to branch master at FreeIPA packaging / bind-dyndb-ldap


Commits:
971f750f by Jarl Gullberg at 2026-09-28T15:58:21+02:00
control: update standards version

- - - - -
b1861778 by Jarl Gullberg at 2026-09-28T15:58:22+02:00
control: update mininum bind version

- - - - -
d45982ff by Jarl Gullberg at 2026-09-28T15:58:23+02:00
control: add missing build dependency

- - - - -
42c33aee by Jarl Gullberg at 2026-09-28T15:58:24+02:00
control: clean up Depends

- - - - -
fee3a57c by Jarl Gullberg at 2026-09-28T15:59:04+02:00
rules: use git archive in gentarball

- - - - -
a53d1cc0 by Jarl Gullberg at 2026-09-28T15:59:17+02:00
rules: remove now-redundant targets

- - - - -
73d21152 by Jarl Gullberg at 2026-09-28T15:59:18+02:00
rules: explicitly specify Makefile build system

- - - - -
963cc864 by Jarl Gullberg at 2026-09-28T15:59:19+02:00
rules: export LIBDNS_VERSION

- - - - -
aca285b4 by Jarl Gullberg at 2026-09-28T15:59:20+02:00
rules: replace explicit CFLAGS with modern alternative

- - - - -
ec0a03a8 by Jarl Gullberg at 2026-09-28T15:59:21+02:00
rules: add architecture variables

- - - - -
5fb9cc04 by Jarl Gullberg at 2026-09-28T15:59:22+02:00
update install files

- - - - -
eca9284e by Jarl Gullberg at 2026-09-28T15:59:23+02:00
update postinst script

- - - - -
af459d42 by Jarl Gullberg at 2026-09-28T15:59:24+02:00
watch: modernize watch file

- - - - -
4540197d by Jarl Gullberg at 2026-09-28T16:00:26+02:00
patches: update fix-keytab-path.diff

- - - - -
83eb537a by Jarl Gullberg at 2026-09-28T16:00:29+02:00
patches: add patch to use LIBDNS_VERSION from debian/rules

- - - - -
62c66521 by Jarl Gullberg at 2026-09-28T16:00:30+02:00
patches: add patch to remove use of non-packaged config.h header

- - - - -
86348a77 by Jarl Gullberg at 2026-09-28T16:00:31+02:00
patches: add patch to fix missing includes

- - - - -
bdfa32ec by Jarl Gullberg at 2026-09-28T16:00:32+02:00
patches: add patch to fix overflow checks

- - - - -
2ff9486c by Jarl Gullberg at 2026-09-28T16:00:33+02:00
patches: add patch to actually use the flags set by debhelper

- - - - -
7a769fa3 by Jarl Gullberg at 2026-09-28T16:00:34+02:00
patches: add patch to support multiple BIND9 versions

- - - - -
31ae5724 by Jarl Gullberg at 2026-09-28T16:00:35+02:00
patches: add patch to fix discarded const qualifier

- - - - -
40529bc1 by Jarl Gullberg at 2026-09-28T16:00:36+02:00
patches: add patch to fix linking order

- - - - -
6d57882f by Jarl Gullberg at 2026-09-28T16:00:37+02:00
copyright: update copyright after full relicensing to MPL-2.0

- - - - -


17 changed files:

- + debian/bind9-dyndb-ldap.docs
- debian/bind9-dyndb-ldap.install
- debian/bind9-dyndb-ldap.postinst
- debian/control
- debian/copyright
- + debian/patches/bind-9-20-26-support.diff
- + debian/patches/fix-const-qualifier.diff
- debian/patches/fix-keytab-path.diff
- + debian/patches/fix-linking-order.diff
- + debian/patches/fix-missing-includes.diff
- + debian/patches/fix-overflow-checks.diff
- + debian/patches/remove-config-include.diff
- debian/patches/series
- + debian/patches/use-cflags-cppflags.diff
- + debian/patches/use-libdns-version-from-rules.diff
- debian/rules
- debian/watch


Changes:

=====================================
debian/bind9-dyndb-ldap.docs
=====================================
@@ -0,0 +1 @@
+docs/


=====================================
debian/bind9-dyndb-ldap.install
=====================================
@@ -1,2 +1,2 @@
-usr/lib/*/bind
-usr/share/doc/
+usr/lib64/bind/ldap.so /usr/lib/${DEB_HOST_MULTIARCH}/bind/
+


=====================================
debian/bind9-dyndb-ldap.postinst
=====================================
@@ -1,28 +1,15 @@
 #!/bin/bash
 set -e
 
-fix_named_conf() {
-    # The following sed script:
-    #   - scopes the named.conf changes to dyndb
-    #   - uses the new way the define path to the library
-
-    while read -r PATTERN
-    do
-        SEDSCRIPT+="$PATTERN"
-    done <<EOF
-/^\s*dyndb/,/};/ {
-  s/\/usr\/lib\/bind\///;
-}
-EOF
-    sed -i.bak -e "$SEDSCRIPT" /etc/bind/named.conf
-}
-
 if [ $1 = "configure" ]; then
-    chown root:bind /var/cache/bind/dynamic /var/cache/bind/dyndb-ldap
-    chmod 0770 /var/cache/bind/dynamic /var/cache/bind/dyndb-ldap
+    if [ -d /var/cache/bind/dyndb-ldap ]; then
+        chown root:bind /var/cache/bind/dyndb-ldap
+        chmod 0770 /var/cache/bind/dyndb-ldap
+    fi
 
-    if dpkg --compare-versions "$2" lt "11.10-1"; then
-        fix_named_conf
+    if [ -d /var/cache/bind/dynamic ]; then
+        chown root:bind /var/cache/bind/dynamic
+        chmod 0770 /var/cache/bind/dynamic
     fi
 fi
 


=====================================
debian/control
=====================================
@@ -5,21 +5,24 @@ Maintainer: Debian FreeIPA Team <pkg-freeipa-devel at alioth-lists.debian.net>
 Uploaders: Timo Aaltonen <tjaalton at debian.org>
 Build-Depends:
  debhelper-compat (= 13),
- bind9-dev (>= 1:9.18.13),
+ bind9-dev (>= 1:9.20.11),
  libkrb5-dev,
  libldap2-dev,
  libsasl2-dev,
+ liburcu-dev,
  uuid-dev,
-Standards-Version: 4.6.2
+Standards-Version: 4.7.2
 Homepage: https://pagure.io/bind-dyndb-ldap
 Vcs-Git: https://salsa.debian.org/freeipa-team/bind-dyndb-ldap.git
 Vcs-Browser: https://salsa.debian.org/freeipa-team/bind-dyndb-ldap
 
 Package: bind9-dyndb-ldap
 Architecture: any
-Depends: ${misc:Depends}, ${shlibs:Depends},
- bind9 (>= 9.11),
+Depends:
+ bind9 (>= 1:9.20.11),
  bind9-libs (= ${bind9-libs:Version}),
+ ${misc:Depends},
+ ${shlibs:Depends}
 Description: LDAP back-end plug-in for BIND
  This package provides an LDAP back-end plug-in for BIND. It features
  support for dynamic updates and internal caching, to lift the load


=====================================
debian/copyright
=====================================
@@ -4,25 +4,12 @@ Source: https://pagure.io/bind-dyndb-ldap
 
 Files: *
 Copyright: 2008-2014 Red Hat
-License: GPL-2+
-
-Files: src/acl.c
-Copyright: 2001-2008 Internet Systems Consortium, Inc. ("ISC")
-           2009 Red Hat
-License: GPL-2+ and ISC
-
-Files: src/krb5_helper.c
-Copyright: 2009 Simo Sorce <ssorce at redhat.com>
-License: GPL-2+
+License: MPL-2.0
 
 Files: debian/*
 Copyright: 2012 Timo Aaltonen <tjaalton at debian.org>
 License: GPL-2+
 
-Files: debian/patches/workaround-missing-headers.patch
-Copyright: 2000-2012 Internet Systems Consortium, Inc. ("ISC")
-License: ISC
-
 License: GPL-2+
  This package is free software; you can redistribute it and/or modify
  it under the terms of the GNU General Public License as published by
@@ -40,15 +27,18 @@ License: GPL-2+
  On Debian systems, the complete text of the GNU General
  Public License version 2 can be found in "/usr/share/common-licenses/GPL-2".
 
-License: ISC
- Permission to use, copy, modify, and/or distribute this software for any
- purpose with or without fee is hereby granted, provided that the above
- copyright notice and this permission notice appear in all copies.
+License: MPL-2.0
+ This Source Code Form is subject to the terms of the Mozilla Public
+ License, v. 2.0. If a copy of the MPL was not distributed with this
+ file, You can obtain one at http://mozilla.org/MPL/2.0/.
+ .
+ If it is not possible or desirable to put the notice in a particular
+ file, then You may include the notice in a location (such as a LICENSE
+ file in a relevant directory) where a recipient would be likely to look
+ for such a notice.
  .
- THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
- AND FITNESS.  IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
- PERFORMANCE OF THIS SOFTWARE.
+ You may add additional accurate notices of copyright ownership.
+ .
+ On Debian systems, the complete text of the Mozilla Public License version
+ 2 can be found in "/usr/share/common-licenses/MPL-2.0".
+


=====================================
debian/patches/bind-9-20-26-support.diff
=====================================
@@ -0,0 +1,103 @@
+Description: Use explicit worklane
+ Enqueueing work from an event loop requires the user to specify a work
+ lane in BIND >= 9.20.26.
+Author: Jarl Gullberg <jarl.gullberg at visar-systems.com>
+Forwarded: https://codeberg.org/freeipa/bind-dyndb-ldap/pulls/248
+Last-Update: 2026-09-25
+---
+This patch header follows DEP-3: http://dep.debian.net/deps/dep3/
+--- a/src/sync/sync_dyndb_ldap.c
++++ b/src/sync/sync_dyndb_ldap.c
+@@ -94,11 +94,20 @@
+     return;
+ }
+ 
++#if LIBDNS_VERSION > 92026
++isc_result_t
++bdl_sync_dyndb_ldap_work(void *arg);
++#else
+ static void
+ bdl_sync_dyndb_ldap_work(void *arg);
++#endif
+ 
+ static void
++#if LIBDNS_VERSION > 92024
++bdl_sync_dyndb_ldap_done(void *arg, isc_result_t result);
++#else
+ bdl_sync_dyndb_ldap_done(void *arg);
++#endif
+ 
+ /**
+  * Enqueue the work from the loop thread.
+@@ -109,8 +118,13 @@
+     bdl_sync_dyndb_ldap_event_ctx_t *ctx =
+         (bdl_sync_dyndb_ldap_event_ctx_t *)arg;
+ 
++#if LIBDNS_VERSION > 92024
++    isc_work_enqueue(ctx->instance->loop, ISC_WORKLANE_SLOW, bdl_sync_dyndb_ldap_work,
++                     bdl_sync_dyndb_ldap_done, ctx);
++#else
+     isc_work_enqueue(ctx->instance->loop, bdl_sync_dyndb_ldap_work,
+                      bdl_sync_dyndb_ldap_done, ctx);
++#endif
+ }
+ 
+ /**
+@@ -157,7 +171,11 @@
+  *
+  * Runs on its own thread from libuv thread pool. It is safe to block.
+  */
++#if LIBDNS_VERSION > 92026
++isc_result_t
++#else
+ static void
++#endif
+ bdl_sync_dyndb_ldap_work(void *arg)
+ {
+     bdl_sync_dyndb_ldap_event_ctx_t *ctx =
+@@ -168,6 +186,7 @@
+     dns_name_t *owner = data.owner;
+     dns_name_t *zone = data.zone;
+     dns_rdatalist_t *rdlist = data.rdlist;
++    isc_result_t result = ISC_R_SUCCESS;
+ 
+     char owner_buff[DNS_NAME_FORMATSIZE];
+     char zone_buff[DNS_NAME_FORMATSIZE];
+@@ -206,11 +225,11 @@
+          * LDAP_MOD_DELETE path because PTR sync needs the specific
+          * deleted record to remove the corresponding PTR.
+          */
+-        bdl_ldap_replace_from_rbtdb(owner, zone, instance,
++        result = bdl_ldap_replace_from_rbtdb(owner, zone, instance,
+                                     rdlist != NULL ? rdlist->type : data.type);
+         break;
+     case BDL_REMOVE_VALUES_FROM_LDAP:
+-        bdl_ldap_remove_values(owner, zone, instance, rdlist, data.delete_node);
++        result = bdl_ldap_remove_values(owner, zone, instance, rdlist, data.delete_node);
+         break;
+     default:
+         log_error("bdl_snc_dyndb_ldap_work: invalid action!");
+@@ -218,7 +237,11 @@
+     }
+     isc_mutex_unlock(&work_lock);
+ 
++#if LIBDNS_VERSION > 92026
++    return result;
++#else
+     return;
++#endif
+ }
+ 
+ /**
+@@ -228,7 +251,11 @@
+  * Runs on the main dyndb thread event loop.
+  */
+ static void
++#if LIBDNS_VERSION > 92024
++bdl_sync_dyndb_ldap_done(void *arg, isc_result_t result ISC_ATTR_UNUSED)
++#else
+ bdl_sync_dyndb_ldap_done(void *arg)
++#endif
+ {
+     bdl_sync_dyndb_ldap_event_ctx_t *ctx =
+         (bdl_sync_dyndb_ldap_event_ctx_t *)arg;


=====================================
debian/patches/fix-const-qualifier.diff
=====================================
@@ -0,0 +1,27 @@
+Description: Fix discarded const qualifier
+ Discarding const qualifiers is generally inadvisable.
+Author: Jarl Gullberg <jarl.gullberg at visar-systems.com>
+Forwarded: https://codeberg.org/freeipa/bind-dyndb-ldap/pulls/251
+Last-Update: 2026-09-25
+---
+This patch header follows DEP-3: http://dep.debian.net/deps/dep3/
+--- a/src/ldap/ldap.c
++++ b/src/ldap/ldap.c
+@@ -3386,7 +3386,7 @@
+     bool zone_sync_ptr;
+     char **vals = NULL;
+     dns_name_t zone_name;
+-    char *zone_dn = NULL;
++    const char *zone_dn = NULL;
+     bdl_settings_set_t *zone_settings = NULL;
+     int af; /* address family */
+     bool unknown_type = false;
+@@ -3403,7 +3403,7 @@
+     zone_dn = strstr(bdl_str_buf(owner_dn), ", ");
+ 
+     if (zone_dn == NULL) { /* SOA record; owner = zone => owner_dn = zone_dn */
+-        zone_dn = (char *)bdl_str_buf(owner_dn);
++        zone_dn = bdl_str_buf(owner_dn);
+     } else {
+         zone_dn += 1; /* skip whitespace */
+     }


=====================================
debian/patches/fix-keytab-path.diff
=====================================
@@ -1,3 +1,10 @@
+Description: Fix keytab path
+ Changes the default keytab path to the one used in Debian.
+Author: Jarl Gullberg <jarl.gullberg at visar-systems.com>
+Forwarded: not-needed
+Last-Update: 2026-09-25
+---
+This patch header follows DEP-3: http://dep.debian.net/deps/dep3/
 --- a/src/krb5.h
 +++ b/src/krb5.h
 @@ -12,7 +12,7 @@


=====================================
debian/patches/fix-linking-order.diff
=====================================
@@ -0,0 +1,19 @@
+--- a/src/Makefile
++++ b/src/Makefile
+@@ -27,13 +27,14 @@
+ 	acl.c \
+ 
+ CFLAGS += -Wall -Wextra -Werror -Wno-unused-parameter -ggdb3 -O2 -fPIC -I/usr/include/bind9.20 -I. -U_FORTIFY_SOURCE -D_FORTIFY_SOURCE=2  -DLIBDNS_VERSION=$(LIBDNS_VERSION) -I.
+-LDFLAGS += -Wl,-z,relro,-z,now,-z,noexecstack,-lldap,-luuid
++LDFLAGS += -Wl,-z,relro,-z,now,-z,noexecstack
++LIBRARIES = -lldap -luuid
+ PLUGIN = ldap.so
+ 
+ all: $(PLUGIN)
+ 
+ $(PLUGIN): $(SRCS:.c=.o)
+-	$(CC) $(LDFLAGS) -o $@ -shared $+
++	$(CC) $(LDFLAGS) -shared $+ $(LIBRARIES) -o $@
+ 
+ clean:
+ 	rm -f $(SRCS:.c=.o) $(PLUGIN)


=====================================
debian/patches/fix-missing-includes.diff
=====================================
@@ -0,0 +1,190 @@
+Description: Add missing includes
+ A number of includes aren't picked up in Debian's bind9 library packaging
+ that appear to be present on Fedora. This patch adds them as appropriate.
+Author: Jarl Gullberg <jarl.gullberg at visar-systems.com>
+Forwarded: not-needed
+Last-Update: 2026-09-25
+---
+This patch header follows DEP-3: http://dep.debian.net/deps/dep3/
+--- a/src/ldap/ldap.c
++++ b/src/ldap/ldap.c
+@@ -6,6 +6,8 @@
+  * file, You can obtain one at https://mozilla.org/MPL/2.0/.
+  */
+ 
++#include <urcu/call-rcu.h>
++
+ #include "ldap/ldap.h"
+ #include <ldap.h>
+ #include <regex.h>
+--- a/src/sync/sync_ldap_dyndb.c
++++ b/src/sync/sync_ldap_dyndb.c
+@@ -12,6 +12,8 @@
+ #include <string.h>
+ #include <unistd.h>
+ 
++#include <urcu/call-rcu.h>
++
+ #include <isc/async.h>
+ #include <isc/loop.h>
+ #include <isc/mem.h>
+--- a/src/ldap/ldap_driver.c
++++ b/src/ldap/ldap_driver.c
+@@ -8,6 +8,8 @@
+ 
+ #include <string.h> /* For memcpy */
+ 
++#include <urcu/call-rcu.h>
++
+ #include <isc/buffer.h>
+ #include <isc/commandline.h>
+ #include <isc/hash.h>
+--- a/src/ldap/metadb.c
++++ b/src/ldap/metadb.c
+@@ -6,6 +6,8 @@
+ 
+ #include "metadb.h"
+ 
++#include <urcu/call-rcu.h>
++
+ #include <isc/mutex.h>
+ #include <isc/util.h>
+ 
+--- a/src/ldap/mldap.c
++++ b/src/ldap/mldap.c
+@@ -15,6 +15,8 @@
+ #include <stddef.h>
+ #include <uuid/uuid.h>
+ 
++#include <urcu/call-rcu.h>
++
+ #include <isc/net.h>
+ #include <isc/refcount.h>
+ #include <isc/result.h>
+--- a/src/acl.c
++++ b/src/acl.c
+@@ -11,6 +11,8 @@
+ #include <string.h>
+ #include <strings.h>
+ 
++#include <urcu/call-rcu.h>
++
+ #include <isc/buffer.h>
+ #include <isc/log.h>
+ #include <isc/mem.h>
+--- a/src/driver.c
++++ b/src/driver.c
+@@ -10,6 +10,8 @@
+ #include <signal.h>
+ #include <unistd.h>
+ 
++#include <urcu/call-rcu.h>
++
+ #include <isc/loop.h>
+ 
+ #include <dns/ds.h>
+@@ -76,7 +78,7 @@
+          *
+          * We use SIGUSR1 to not to interfere with any signal
+          * used by BIND itself.
+-         * 
++         *
+          * This interrupts blocking LDAP calls (ldap_sync_poll) without
+          * killing the process, allowing clean thread termination.
+          */
+--- a/src/driver_config.c
++++ b/src/driver_config.c
+@@ -8,6 +8,8 @@
+ 
+ #include <unistd.h>
+ 
++#include <urcu/call-rcu.h>
++
+ #include <dns/view.h>
+ 
+ #include "driver_config.h"
+--- a/src/dyndb/dyndb.c
++++ b/src/dyndb/dyndb.c
+@@ -9,6 +9,8 @@
+ #include <inttypes.h>
+ #include <stdbool.h>
+ 
++#include <urcu/call-rcu.h>
++
+ #include <isc/string.h>
+ #include <isc/util.h>
+ 
+--- a/src/fwd.c
++++ b/src/fwd.c
+@@ -8,6 +8,8 @@
+ 
+ #include "fwd.h"
+ 
++#include <urcu/call-rcu.h>
++
+ #include <dns/qp.h>
+ #include <dns/view.h>
+ 
+--- a/src/sync/sync_dyndb_ldap.c
++++ b/src/sync/sync_dyndb_ldap.c
+@@ -6,6 +6,8 @@
+  * file, You can obtain one at https://mozilla.org/MPL/2.0/.
+  */
+ 
++#include <urcu/call-rcu.h>
++
+ #include <isc/async.h>
+ #include <isc/loop.h>
+ #include <isc/mutex.h>
+@@ -116,7 +118,7 @@
+  *
+  * This function may be called from any thread (main loop, LDAP syncrepl
+  * worker, or libuv thread-pool worker).  It first hops to instance->loop's
+- * thread via isc_async_run() (which is thread-safe), via bdl_sync_dyndb_ldap_enqueue, 
++ * thread via isc_async_run() (which is thread-safe), via bdl_sync_dyndb_ldap_enqueue,
+  * then from there isc_work_enqueue() dispatches the blocking LDAP write to the thread pool.
+  */
+ isc_result_t
+--- a/src/sync/syncptr.c
++++ b/src/sync/syncptr.c
+@@ -10,6 +10,8 @@
+ #include <ldap.h>
+ #include <sys/socket.h>
+ 
++#include <urcu/call-rcu.h>
++
+ #include <isc/netaddr.h>
+ #include <isc/types.h>
+ 
+--- a/src/zones/empty_zones.c
++++ b/src/zones/empty_zones.c
+@@ -1,5 +1,7 @@
+ #include <stdio.h>
+ 
++#include <urcu/call-rcu.h>
++
+ #include <isc/result.h>
+ #include <isc/types.h>
+ #include <isc/util.h>
+--- a/src/zones/zone.c
++++ b/src/zones/zone.c
+@@ -6,6 +6,8 @@
+  * file, You can obtain one at https://mozilla.org/MPL/2.0/.
+  */
+ 
++#include <urcu/call-rcu.h>
++
+ #include "zones/zone.h"
+ 
+ #include <isc/result.h>
+--- a/src/zones/zone_register.c
++++ b/src/zones/zone_register.c
+@@ -8,6 +8,8 @@
+ 
+ #include "zone_register.h"
+ 
++#include <urcu/call-rcu.h>
++
+ #include <isc/mem.h>
+ #include <isc/rwlock.h>
+ #include <isc/string.h>


=====================================
debian/patches/fix-overflow-checks.diff
=====================================
@@ -0,0 +1,52 @@
+Description: Fix overflow checks
+ The second argument to a few macros needs to be unsigned for overflow
+ checks to properly work, which surfaces when compiling on Debian.
+Author: Jarl Gullberg <jarl.gullberg at visar-systems.com>
+Forwarded: https://codeberg.org/freeipa/bind-dyndb-ldap/pulls/249
+Last-Update: 2026-09-25
+---
+This patch header follows DEP-3: http://dep.debian.net/deps/dep3/
+--- a/src/driver.c
++++ b/src/driver.c
+@@ -149,7 +149,7 @@
+ 
+     log_info("Creating new instance");
+ 
+-    instance = isc_mem_cget(mctx, 1, sizeof(*instance));
++    instance = isc_mem_cget(mctx, 1u, sizeof(*instance));
+     if (instance == NULL) {
+         return ISC_R_NOMEMORY;
+     }
+--- a/src/sync/sync_dyndb_ldap.c
++++ b/src/sync/sync_dyndb_ldap.c
+@@ -53,7 +53,7 @@
+ {
+     bdl_sync_dyndb_ldap_event_ctx_t *ctx;
+ 
+-    ctx = isc_mem_cget(mctx, 1, sizeof(*ctx));
++    ctx = isc_mem_cget(mctx, 1u, sizeof(*ctx));
+     if (ctx == NULL) {
+         return NULL;
+     }
+--- a/src/sync/sync_ldap_dyndb.c
++++ b/src/sync/sync_ldap_dyndb.c
+@@ -96,7 +96,7 @@
+ {
+     bdl_sync_ldap_dyndb_event_ctx_t *ctx;
+ 
+-    ctx = isc_mem_cget(mctx, 1, sizeof(*ctx));
++    ctx = isc_mem_cget(mctx, 1u, sizeof(*ctx));
+     if (ctx == NULL) {
+         return NULL;
+     }
+--- a/src/dyndb/dyndb.c
++++ b/src/dyndb/dyndb.c
+@@ -522,7 +522,7 @@
+ 
+     UNUSED(driverarg); /* no driver-specific configuration */
+ 
+-    bdl_dyndb = isc_mem_cget(mctx, 1, sizeof(*bdl_dyndb));
++    bdl_dyndb = isc_mem_cget(mctx, 1u, sizeof(*bdl_dyndb));
+     *bdl_dyndb = (bdl_dyndb_t){
+         .common.magic = DNS_DB_MAGIC,
+         .common.impmagic = LDAPDB_MAGIC,


=====================================
debian/patches/remove-config-include.diff
=====================================
@@ -0,0 +1,19 @@
+Description: Remove config.h include
+ Debian doesn't ship bind9's config.h, so we can't unconditionally include
+ it across the board.
+Author: Jarl Gullberg <jarl.gullberg at visar-systems.com>
+Forwarded: not-needed
+Last-Update: 2026-09-25
+---
+This patch header follows DEP-3: http://dep.debian.net/deps/dep3/
+--- a/src/Makefile
++++ b/src/Makefile
+@@ -26,7 +26,7 @@
+ 	rbt_helper.c \
+ 	acl.c \
+ 
+-CFLAGS = -Wall -Wextra -Werror -Wno-unused-parameter -ggdb3 -O2 -fPIC -I/usr/include/bind9.20 -I. -U_FORTIFY_SOURCE -D_FORTIFY_SOURCE=2  -DLIBDNS_VERSION=$(LIBDNS_VERSION) -I.  -include /usr/include/bind9.20/bind9/config.h
++CFLAGS = -Wall -Wextra -Werror -Wno-unused-parameter -ggdb3 -O2 -fPIC -I/usr/include/bind9.20 -I. -U_FORTIFY_SOURCE -D_FORTIFY_SOURCE=2  -DLIBDNS_VERSION=$(LIBDNS_VERSION) -I.
+ LDFLAGS = -Wl,-z,relro,-z,now,-z,noexecstack,-lldap,-luuid
+ PLUGIN = ldap.so
+ 


=====================================
debian/patches/series
=====================================
@@ -1 +1,9 @@
 fix-keytab-path.diff
+use-libdns-version-from-rules.diff
+remove-config-include.diff
+fix-missing-includes.diff
+fix-overflow-checks.diff
+use-cflags-cppflags.diff
+bind-9-20-26-support.diff
+fix-const-qualifier.diff
+fix-linking-order.diff


=====================================
debian/patches/use-cflags-cppflags.diff
=====================================
@@ -0,0 +1,22 @@
+Description: Ensure CFLAGS is appended to, not overridden
+ The makefile directly overrides CFLAGS, preventing hardening options from
+ Debian from making it into the build. This patch changes the assignment to
+ an append instead.
+Author: Jarl Gullberg <jarl.gullberg at visar-systems.com>
+Forwarded: https://codeberg.org/freeipa/bind-dyndb-ldap/pulls/250
+Last-Update: 2026-09-25
+---
+This patch header follows DEP-3: http://dep.debian.net/deps/dep3/
+--- a/src/Makefile
++++ b/src/Makefile
+@@ -26,8 +26,8 @@
+ 	rbt_helper.c \
+ 	acl.c \
+ 
+-CFLAGS = -Wall -Wextra -Werror -Wno-unused-parameter -ggdb3 -O2 -fPIC -I/usr/include/bind9.20 -I. -U_FORTIFY_SOURCE -D_FORTIFY_SOURCE=2  -DLIBDNS_VERSION=$(LIBDNS_VERSION) -I.
+-LDFLAGS = -Wl,-z,relro,-z,now,-z,noexecstack,-lldap,-luuid
++CFLAGS += -Wall -Wextra -Werror -Wno-unused-parameter -ggdb3 -O2 -fPIC -I/usr/include/bind9.20 -I. -U_FORTIFY_SOURCE -D_FORTIFY_SOURCE=2  -DLIBDNS_VERSION=$(LIBDNS_VERSION) -I.
++LDFLAGS += -Wl,-z,relro,-z,now,-z,noexecstack,-lldap,-luuid
+ PLUGIN = ldap.so
+ 
+ all: $(PLUGIN)


=====================================
debian/patches/use-libdns-version-from-rules.diff
=====================================
@@ -0,0 +1,19 @@
+Description: Use LIBDNS_VERSION from debian/rules
+ Debian doesn't ship bind9's config.h, so we pull LIBDNS_VERSION
+ from dpkg-query in debian/rules.
+Author: Jarl Gullberg <jarl.gullberg at visar-systems.com>
+Forwarded: not-needed
+Last-Update: 2026-09-25
+---
+This patch header follows DEP-3: http://dep.debian.net/deps/dep3/
+--- a/src/Makefile
++++ b/src/Makefile
+@@ -26,8 +26,6 @@
+ 	rbt_helper.c \
+ 	acl.c \
+ 
+-LIBDNS_VERSION = $(shell grep "BIND9_VERSION " /usr/include/bind9.20/bind9/config.h | cut -d\" -f2 | sed -e "s/\.//g")
+-
+ CFLAGS = -Wall -Wextra -Werror -Wno-unused-parameter -ggdb3 -O2 -fPIC -I/usr/include/bind9.20 -I. -U_FORTIFY_SOURCE -D_FORTIFY_SOURCE=2  -DLIBDNS_VERSION=$(LIBDNS_VERSION) -I.  -include /usr/include/bind9.20/bind9/config.h
+ LDFLAGS = -Wl,-z,relro,-z,now,-z,noexecstack,-lldap,-luuid
+ PLUGIN = ldap.so


=====================================
debian/rules
=====================================
@@ -1,12 +1,16 @@
 #!/usr/bin/make -f
 
+include /usr/share/dpkg/architecture.mk
 include /usr/share/dpkg/pkg-info.mk
 
-CFLAGS += -Wno-uninitialized
+export DEB_BUILD_MAINT_OPTIONS = hardening=+all
+export DEB_CFLAGS_MAINT_APPEND = -DZONEDB_DEFAULT='"qpzone"' -Wno-maybe-uninitialized -Wno-unused-but-set-variable
+
 BIND9_LIBS_VER = $(shell dpkg-query -f='$${Version}\n' -W bind9-libs)
+export LIBDNS_VERSION = $(shell dpkg-query -f='$${source:Upstream-Version}\n' -W bind9-libs | sed -e "s/\.//g")
 
 %:
-	dh $@ --builddirectory=build
+	dh $@ --buildsystem=makefile
 
 override_dh_auto_configure:
 	dh_auto_configure -- \
@@ -15,19 +19,11 @@ override_dh_auto_configure:
 override_dh_auto_install:
 	dh_auto_install --destdir=debian/tmp
 
-override_dh_install:
-	# purge .la files
-	find $(CURDIR)/debian/tmp -name "*.la" -type f -delete
-	dh_install
-
-override_dh_fixperms:
-	dh_fixperms -X var/cache/bind/dyndb-ldap
-
 override_dh_gencontrol:
 	dh_gencontrol -- \
 		-V'bind9-libs:Version=$(BIND9_LIBS_VER)'
 
 gentarball:
-	tar --transform 's,^.\/,$(DEB_SOURCE)-$(DEB_VERSION_UPSTREAM)/,' \
-		--exclude 'debian' --exclude '.git.*' --exclude-vcs \
-		-cJf ../$(DEB_SOURCE)_$(DEB_VERSION_UPSTREAM).orig.tar.xz .
+	git archive --format=tar upstream --prefix=$(DEB_SOURCE)-$(DEB_VERSION_UPSTREAM)/ ":(exclude)debian" | \
+		xz --best \
+		> ../$(DEB_SOURCE)_$(DEB_VERSION_UPSTREAM).orig.tar.xz


=====================================
debian/watch
=====================================
@@ -1,3 +1,9 @@
-#git=https://pagure.io/bind-dyndb-ldap.git
-version=3
-https://releases.pagure.org/bind-dyndb-ldap/bind-dyndb-ldap-(.*)\.tar\.bz2
+Version: 5
+
+Source: https://codeberg.org/api/v1/repos/freeipa/@PACKAGE@/releases
+Matching-Pattern: https://codeberg.org/freeipa/@PACKAGE@/archive/[^"-_v]*@ANY_VERSION@@ARCHIVE_EXT@
+Search-Mode: plain
+Pgp-Mode: auto
+Filename-Mangle: auto
+Uversion-Mangle: s/-/./g
+



View it on GitLab: https://salsa.debian.org/freeipa-team/bind-dyndb-ldap/-/compare/ec8c260dfd2bb32dd0ee327d8a67b166c2d3794e...6d57882ff58eebdc2a95e107b0fdc7a980c76074

-- 
View it on GitLab: https://salsa.debian.org/freeipa-team/bind-dyndb-ldap/-/compare/ec8c260dfd2bb32dd0ee327d8a67b166c2d3794e...6d57882ff58eebdc2a95e107b0fdc7a980c76074
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/pkg-freeipa-devel/attachments/20260928/db475738/attachment-0001.htm>


More information about the Pkg-freeipa-devel mailing list