[Pkg-samba-maint] r2582 - trunk/samba/debian

vorlon at alioth.debian.org vorlon at alioth.debian.org
Sun Feb 15 20:29:26 UTC 2009


tags 500129 pending
tags 509101 pending
tags 510450 pending
tags 508388 pending
tags 507620 pending
tags 459243 pending
tags 506109 pending
tags 483187 pending
tags 349049 pending
thanks

Author: vorlon
Date: 2009-02-15 20:29:25 +0000 (Sun, 15 Feb 2009)
New Revision: 2582

Modified:
   trunk/samba/debian/changelog
   trunk/samba/debian/smb.conf
Log:
* Re-add smb.conf fixes that were dropped in the 3.3.0 merge to unstable.
* Fix segfault whan accessign some NAS devices running old versions of Samba
  Closes: #500129
* Fix process crush when using gethostbyname_r in several threads
  Closes: #509101, #510450
* Security update
* Fix Potential access to "/" in setups with registry shares enabled
  This fixes CVE-2009-0022, backported from 3.2.7
* Fix links in HTML documentation index file.
  Closes: #508388
* Drop spurious docs-xml/smbdotconf/parameters.global.xml.new
  file in the diff. Thanks to the release managers for spotting it
* Fix typo in bug number in a comment for the default smb.conf file
  Closes: #507620
* Document the need to set appropriate permissions on the printer
  drivers directory, in the default smb.conf file. Also change
  the example group from ntadmin to lpadmin
  Closes: #459243
* Add missing rfc2307.so and sfu*.so links that prevent using the
  'winbind nss info' feature properly
  Thans to Martin Dag Nilsson for reporting and Jelmer Jaarsma for
  the patch. Closes: #506109
* New upstream version. Security-only release.
  This addresses CVE-2008-4314: potentially leaking
  arbitrary memory contents to malicious clients.
* Better document cases where using a "master" file for smb.conf
  is a bad idea. Closes: #483187
* Insert example "add machine script" and "add group script" scripts
  in the default smb.conf. Closes: #349049
* Move homepage URL to Homepage filed in debian/control
* Use alternatives for the smbstatus, nmblookup, net and 

Modified: trunk/samba/debian/changelog
===================================================================
--- trunk/samba/debian/changelog	2009-02-15 20:20:14 UTC (rev 2581)
+++ trunk/samba/debian/changelog	2009-02-15 20:29:25 UTC (rev 2582)
@@ -1,3 +1,9 @@
+samba (2:3.3.0-3) UNRELEASED; urgency=low
+
+  * Re-add smb.conf fixes that were dropped in the 3.3.0 merge to unstable.
+
+ -- Steve Langasek <vorlon at debian.org>  Sun, 15 Feb 2009 12:28:51 -0800
+
 samba (2:3.3.0-2) unstable; urgency=low
 
   * Upload to unstable
@@ -4,6 +10,55 @@
 
  -- Christian Perrier <bubulle at debian.org>  Sat, 14 Feb 2009 13:38:14 +0100
 
+samba (2:3.2.5-4) unstable; urgency=low
+
+  * Fix segfault whan accessign some NAS devices running old versions of Samba
+    Closes: #500129
+  * Fix process crush when using gethostbyname_r in several threads
+    Closes: #509101, #510450
+
+ -- Christian Perrier <bubulle at debian.org>  Thu, 08 Jan 2009 05:59:17 +0100
+
+samba (2:3.2.5-3) unstable; urgency=high
+
+  * Security update
+  * Fix Potential access to "/" in setups with registry shares enabled
+    This fixes CVE-2009-0022, backported from 3.2.7
+  * Fix links in HTML documentation index file.
+    Closes: #508388
+  * Drop spurious docs-xml/smbdotconf/parameters.global.xml.new
+    file in the diff. Thanks to the release managers for spotting it
+
+ -- Christian Perrier <bubulle at debian.org>  Sun, 21 Dec 2008 08:09:31 +0100
+
+samba (2:3.2.5-2) unstable; urgency=low
+
+  * Fix typo in bug number in a comment for the default smb.conf file
+    Closes: #507620
+  * Document the need to set appropriate permissions on the printer
+    drivers directory, in the default smb.conf file. Also change
+    the example group from ntadmin to lpadmin
+    Closes: #459243
+  * Add missing rfc2307.so and sfu*.so links that prevent using the
+    'winbind nss info' feature properly
+    Thans to Martin Dag Nilsson for reporting and Jelmer Jaarsma for
+    the patch. Closes: #506109
+
+ -- Christian Perrier <bubulle at debian.org>  Sat, 13 Dec 2008 13:56:07 +0100
+
+samba (2:3.2.5-1) unstable; urgency=high
+
+  * New upstream version. Security-only release.
+    This addresses CVE-2008-4314: potentially leaking
+    arbitrary memory contents to malicious clients.
+  * Better document cases where using a "master" file for smb.conf
+    is a bad idea. Closes: #483187
+  * Insert example "add machine script" and "add group script" scripts
+    in the default smb.conf. Closes: #349049
+  * Move homepage URL to Homepage filed in debian/control
+
+ -- Christian Perrier <bubulle at debian.org>  Thu, 27 Nov 2008 11:36:35 +0100
+
 samba (2:3.3.0-1) experimental; urgency=low
 
   * New upstream release. Fixes the following bugs:
@@ -17,7 +72,7 @@
     - fix swat status table layout. Closes: #511275
 
   [ Jelmer Vernooij ]
-  * Use alternatives for the smbtatus, nmblookup, net and 
+  * Use alternatives for the smbstatus, nmblookup, net and 
     testparm binaries and various data files in samba-common 
     to allow installation of Samba 3 together with Samba 4. 
   * Add myself to uploaders.
@@ -120,11 +175,6 @@
 
   * Provide idmap_adex and idmap_hash in winbind.
     Thanks to Jelmer Jaarsma for reporting and providing a patch
-  * Merged from unstable (needed for the above to work):
-    Add missing rfc2307.so and sfu*.so links that prevent using the
-    'winbind nss info' feature properly
-    Thans to Martin Dag Nilsson for reporting and Jelmer Jaarsma for
-    the patch. Closes: #506109
 
  -- Christian Perrier <bubulle at debian.org>  Thu, 04 Dec 2008 19:59:23 +0100
 

Modified: trunk/samba/debian/smb.conf
===================================================================
--- trunk/samba/debian/smb.conf	2009-02-15 20:20:14 UTC (rev 2581)
+++ trunk/samba/debian/smb.conf	2009-02-15 20:29:25 UTC (rev 2582)
@@ -23,6 +23,9 @@
 # testparm -s smb.conf.master >smb.conf
 # This minimizes the size of the really used smb.conf file
 # which, according to the Samba Team, impacts performance
+# However, use this with caution if your smb.conf file contains nested
+# "include" statements. See Debian bug #483187 for a case
+# where using a master file is not a good idea.
 #
 
 #======================= Global Settings =======================
@@ -159,6 +162,15 @@
 # password; please adapt to your needs
 ; add user script = /usr/sbin/adduser --quiet --disabled-password --gecos "" %u
 
+# This allows machine accounts to be created on the domain controller via the 
+# SAMR RPC pipe.  
+# The following assumes a "machines" group exists on the system
+; add machine script  = /usr/sbin/useradd -g machines -c "%u machine account" -d /var/lib/samba -s /bin/false %u
+
+# This allows Unix groups to be created on the domain controller via the SAMR
+# RPC pipe.  
+; add group script = /usr/sbin/addgroup --force-badname %g
+
 ########## Printing ##########
 
 # If you want to automatically load your printer list rather
@@ -284,9 +296,11 @@
    read only = yes
    guest ok = no
 # Uncomment to allow remote administration of Windows print drivers.
-# Replace 'ntadmin' with the name of the group your admin users are
-# members of.
-;   write list = root, @ntadmin
+# You may need to replace 'lpadmin' with the name of the group your
+# admin users are members of.
+# Please note that you also need to set appropriate Unix permissions
+# to the drivers directory for these users to have write rights in it
+;   write list = root, @lpadmin
 
 # A sample share for sharing your CD-ROM with others.
 ;[cdrom]




More information about the Pkg-samba-maint mailing list