[Pkg-shadow-devel] Ubuntu (new upstream) shadow 1:4.1.1-5ubuntu1

Ubuntu Merge-o-Matic mom at ubuntu.com
Wed Nov 5 10:45:16 UTC 2008


This e-mail has been sent due to an upload to Ubuntu of a new upstream
version which still contains Ubuntu changes.  It contains the difference
between the Ubuntu version and the equivalent base version in Debian, note
that this difference may include the upstream changes.
-------------- next part --------------
Format: 1.7
Date: Wed, 05 Nov 2008 07:26:43 +0000
Source: shadow
Binary: login passwd
Architecture: source
Version: 1:4.1.1-5ubuntu1
Distribution: jaunty
Urgency: low
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Scott James Remnant <scott at ubuntu.com>
Description: 
 login      - system login tools
 passwd     - change and administer password and group data
Closes: 412234 443322 443322 475795 482352 482823 488515 491460 491907 492307 492410 493181 493230 493230 495831
Changes: 
 shadow (1:4.1.1-5ubuntu1) jaunty; urgency=low
 .
   * Merge from debian unstable, remaining changes:
     - debian/login.pam: Enable SELinux support in login.pam.
 .
 shadow (1:4.1.1-5) unstable; urgency=low
 .
   * The "Bergues" release.
   * debian/login.pam: restore the Etch behavior of pam_securetty.so in case of
     unknown user. Closes: #443322, #495831
 .
 shadow (1:4.1.1-4) unstable; urgency=low
 .
   * The "Rocamadour" release.
   * debian/patches/302_remove_non_translated_polish_manpages,
     debian/patches/series: Remove the (untranslated) su.1 and login.1 polish
     translation.  Closes: #491460
   * debian/patches/506_relaxed_usernames: Document that the naming policy is
     also used for the group names policy. Differentiate the Debian
     constraints in a separate paragraph. Added documentation of the username
     length restriction. Closes: #493230
   * debian/patches/507_32char_grnames.dpatch: Update the documentation of the
     group length restriction. Closes: #493230
   * debian/login.pam: Replace the "multiple" option of pam_selinux by
     "select_context". This requires PAM 1.0.1, but is commented.
     Closes: #493181
   * debian/patches/494_passwd_lock-no_account_lock: Fix typo (missing
     parenthesis). Thanks to Moray Allan.
 .
 shadow (1:4.1.1-3) unstable; urgency=low
 .
   * The "Morbier" release.
   * debian/patches/302_vim_selinux_support: Add SE Linux support to vipw/vigr.
     Thanks to Russell Coker. Closes: #491907
   * debian/patches/494_passwd_lock-no_account_lock: Restore the previous
     behavior of passwd -l (which changed in #389183): only lock the user's
     password, not the user's account. Also explicitly document the
     differences. This restores a behavior common with the previous versions of
     passwd and with other implementations. Closes: #492307
   * debian/patches/494_passwd_lock-no_account_lock: Add a reference to
     usermod(8) in passwd(1). Closes: #412234
   * debian/login.pam: Enforce a fail delay to avoid login brute-force.
     Closes: #443322
   * debian/login.pam: Indicate why the pam_securetty module is used as a
     requisite module and mentions the possible drawbacks. Closes: #482352
   * debian/login.defs: Do not mention the libpam-umask package (the module is
     now provided by libpam-modules). Closes: #492410
   * debian/patches/200_Czech_binary_translation: Updated Czech translation.
     Thanks to Miroslav Kure. Closes: #482823
   * debian/securetty.linux: Add the PA-RISC mux ports (ttyB0, ttyB1).
     Closes: #488515
 .
 shadow (1:4.1.1-2) unstable; urgency=low
 .
   * The "Brie de Meaux" and "Brie de Melun" double cheese release.
   * Backported patches from upstream
     - debian/patches/300_SHA_crypt_method:
       This fixes bugs in the SHA encryption method that force the salt to have
       8 bytes (instead of a random length between 8 and 16 bytes), and force
       the number of SHA rounds to be equal to the lowest limit (at least 1000
       SHA rounds).
     - debian/patches/301_manpages_missing_options:
       This add the missing documentation of options in useradd, groupadd, and
       newusers.
   * Tag patches already applied upstream
     - debian/patches/487_passwd_chauthtok_failed_message
     - debian/patches/406_vipw_resume_properly
     - debian/patches/008_su_get_PAM_username
     - debian/patches/491_configure.in_friendly_selinux_detection
     - debian/patches/434_login_stop_checking_args_after--
     - debian/patches/414_remove-unwise-advices
   * Added description of new variables in /etc/login.defs:
     - SYS_UID_MIN, SYS_UID_MAX, SYS_GID_MIN, SYS_GID_MAX
     - ENCRYPT_METHOD
     - SHA_CRYPT_MIN_ROUNDS, SHA_CRYPT_MAX_ROUNDS
   * New Debian Policy:
     - debian/control: Bump Standards-Version to 3.8.0 (no changes needed).
     - debian/README.source: Document how to patch the upstream source, how to
       use quilt, how to package a new upstream and how to use the testsuite.
   * debian/patches/505_useradd_recommend_adduser: Fix typo: userdel is used to
     remove an user, not to add one. Closes: #475795
Files: 
 5fa8ce9629dd89d763a1ed5f98155a50 1654 admin required shadow_4.1.1-5ubuntu1.dsc
 bcfe65af5e0fb120b67e7045e8b5424f 91420 admin required shadow_4.1.1-5ubuntu1.diff.gz
Original-Maintainer: Shadow package maintainers <pkg-shadow-devel at lists.alioth.debian.org>
-------------- next part --------------
diff -pruN 1:4.1.1-5/debian/changelog 1:4.1.1-5ubuntu1/debian/changelog
--- 1:4.1.1-5/debian/changelog	2008-11-05 10:28:22.000000000 +0000
+++ 1:4.1.1-5ubuntu1/debian/changelog	2008-11-05 10:24:24.000000000 +0000
@@ -1,3 +1,10 @@
+shadow (1:4.1.1-5ubuntu1) jaunty; urgency=low
+
+  * Merge from debian unstable, remaining changes:
+    - debian/login.pam: Enable SELinux support in login.pam.
+
+ -- Scott James Remnant <scott at ubuntu.com>  Wed, 05 Nov 2008 07:26:43 +0000
+
 shadow (1:4.1.1-5) unstable; urgency=low
 
   * The "Bergues" release.
@@ -83,6 +90,13 @@ shadow (1:4.1.1-2) unstable; urgency=low
 
  -- Nicolas FRANCOIS (Nekral) <nicolas.francois at centraliens.net>  Fri, 13 Jun 2008 01:27:16 +0200
 
+shadow (1:4.1.1-1ubuntu1) intrepid; urgency=low
+
+  * Merge from debian unstable, remaining changes:
+    - debian/login.pam: Enable SELinux support in login.pam.
+
+ -- Kees Cook <kees at ubuntu.com>  Mon, 09 Jun 2008 10:08:38 -0700
+
 shadow (1:4.1.1-1) unstable; urgency=low
 
   * New upstream release. This closes the following bugs:
@@ -208,6 +222,20 @@ shadow (1:4.1.0-1) unstable; urgency=low
 
  -- Christian Perrier <bubulle at debian.org>  Sat, 12 Jan 2008 20:40:02 +0100
 
+shadow (1:4.0.18.2-1ubuntu2) hardy; urgency=low
+
+  * Add 498_make_useradd_faster_with_ldap: make useradd faster when
+    nsswitch uses LDAP or some other remote names database (LP: #120015),
+    thanks to Vince Busam.
+
+ -- Matt T. Proud <mtp at google.com>  Fri, 08 Feb 2008 18:30:51 -0800
+
+shadow (1:4.0.18.2-1ubuntu1) hardy; urgency=low
+
+  * debian/login.pam: Enable SELinux support in login.pam (LP: #191326).
+
+ -- Caleb Case <ccase at tresys.com>  Fri, 08 Feb 2008 02:20:06 -0500
+
 shadow (1:4.0.18.2-1) unstable; urgency=low
 
   * The "Vacherin" release.
@@ -1150,7 +1178,7 @@ shadow (1:4.0.12-5) unstable; urgency=lo
   * Really add /etc/pam.d/su. Closes: #330291
   
  -- Christian Perrier <bubulle at debian.org>  Wed, 28 Sep 2005 19:59:31 +0200
-   
+
 shadow (1:4.0.12-4) unstable; urgency=low
 
   * The "Epoisses" release
@@ -2482,7 +2510,7 @@ shadow (20000902-6.1) unstable; urgency=
   * Upgrade to latest config.sub and config.guess.  Closes: #88547
  
  -- Gerhard Tonn <gt at debian.org>  Fri,  1 Jun 2001 20:38:43 +0200
-                                                              
+
 shadow (20000902-6) unstable; urgency=medium
 
   * actually set root's password when appropriate
diff -pruN 1:4.1.1-5/debian/control 1:4.1.1-5ubuntu1/debian/control
--- 1:4.1.1-5/debian/control	2008-11-05 10:28:22.000000000 +0000
+++ 1:4.1.1-5ubuntu1/debian/control	2008-11-05 10:24:24.000000000 +0000
@@ -1,7 +1,8 @@
 Source: shadow
 Section: admin
 Priority: required
-Maintainer: Shadow package maintainers <pkg-shadow-devel at lists.alioth.debian.org>
+Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss at lists.ubuntu.com>
+XSBC-Original-Maintainer: Shadow package maintainers <pkg-shadow-devel at lists.alioth.debian.org>
 Standards-Version: 3.8.0
 Uploaders: Christian Perrier <bubulle at debian.org>, Martin Quinson <mquinson at debian.org>, Nicolas FRANCOIS (Nekral) <nicolas.francois at centraliens.net>
 Build-Depends: autoconf, automake1.9, libtool, gettext, libpam0g-dev, debhelper (>= 5.0.0), quilt, dpkg-dev (>= 1.13.5), xsltproc, docbook-xsl, docbook-xml, libxml2-utils, cdbs, libselinux1-dev [!hurd-i386 !kfreebsd-i386 !kfreebsd-amd64], gnome-doc-utils (>= 0.4.3-1)
diff -pruN 1:4.1.1-5/debian/login.pam 1:4.1.1-5ubuntu1/debian/login.pam
--- 1:4.1.1-5/debian/login.pam	2008-11-05 10:28:22.000000000 +0000
+++ 1:4.1.1-5ubuntu1/debian/login.pam	2008-11-05 10:24:24.000000000 +0000
@@ -20,6 +20,12 @@ auth       [success=ok ignore=ignore use
 # (Replaces the `NOLOGINS_FILE' option from login.defs)
 auth       requisite  pam_nologin.so
 
+# SELinux needs to be the first session rule. This ensures that any 
+# lingering context has been cleared. Without out this it is possible 
+# that a module could execute code in the wrong domain.  (When SELinux
+# is disabled, this returns success.)
+session    required   pam_selinux.so close
+
 # This module parses environment configuration file(s)
 # and also allows you to use an extended config
 # file /etc/security/pam_env.conf.
@@ -72,12 +78,13 @@ session    optional   pam_motd.so
 # See comments in /etc/login.defs
 session    optional   pam_mail.so standard
 
-# SELinux needs to intervene at login time to ensure that the process
-# starts in the proper default security context.
-# Uncomment the following line to enable SELinux
-# session required pam_selinux.so select_context
-
 # Standard Un*x account and session
 @include common-account
 @include common-session
 @include common-password
+
+# SELinux needs to intervene at login time to ensure that the process
+# starts in the proper default security context. Only sessions which are
+# intended to run in the user's context should be run after this.  (When
+# SELinux is disabled, this returns success.)
+session required pam_selinux.so open


More information about the Pkg-shadow-devel mailing list