~nacc/ubuntu/+source/bind9:debian/experimental

Last commit made on 2016-03-23
Get this branch:
git clone -b debian/experimental https://git.launchpad.net/~nacc/ubuntu/+source/bind9
Only Nish Aravamudan can upload to this branch. If you are Nish Aravamudan please log in for upload directions.

Branch merges

Branch information

Name:
debian/experimental
Repository:
lp:~nacc/ubuntu/+source/bind9

Recent commits

6116e61... by LaMont Jones

Import patches-unapplied version 1:9.10.3.dfsg.P4-5 to debian/experimental

Imported using usd-importer.

Publish parent: ab25a2bde01516ba0f1ebc7bbc7fbc025f941c70

New changelog entries:
  * Drop dead code in bind9.preinst.
  * move from /var/run to /run for policy.
  * use multiarch path in udebs
  * Updated root cache file. Closes: #806954
  * Fix vcs links
  * build in debian/tmp, use bind9.install
  * updated precise_time patch
  * add RT#s to some patches
  * Merge ubuntu changes
  * Fix debian/rules to properly remove files from bind9 that are delivered
    elsewhere. LP: #1559090
  * Bump debhelper to v9 to use dh-exec.
  * libbind-export-dev: Fix the libbind.so symlink.
  * Move static libs to the multiarch libdir again.
  * Fix udeb dependencies.
  [ ISC ]
  * New upstream: 9.10.3-P3
    - Specific APL data could trigger a INSIST. (CVE-2015-8704) [RT #41396]
    - render_ecs errors were mishandled when printing out a OPT record
      resulting in a assertion failure. (CVE-2015-8705) [RT #41397]
    - Fixed a regression in resolver.c:possibly_mark() which caused
      known-bogus servers to be queried anyway. [RT #41321]
  * New upstream: 9.10.3-P4
    - Malformed control messages can trigger assertions in named and rndc.
      (CVE-2016-1285) [RT #41666]
    - Fix resolver assertion failure due to improper DNAME handling when
      parsing fetch reply messages. (CVE-2016-1286) [RT #41753]
    - Duplicate EDNS COOKIE options in a response could trigger an
      assertion failure. (CVE-2016-2088) [RT #41809]
  [LaMont Jones]
  * Do not build -export libs for libbind90 and liblwres. Relates in part
    to, and is the last fix to LP: #1551351
  * update patches for 9.10.3.dfsg.P4. Drop 50_CVE_2015-8704.diff
  [ Stefan Bader ]
  * Do not modify signal handlers for external apps. LP: #1556175
  * Fix my bad merge of autoreconf workaround.
  * Re-implement -export libraries. LP: #1556175
  * Deliver libisccc-export library.

ab25a2b... by LaMont Jones

Import patches-unapplied version 1:9.10.3.dfsg.P2-5 to debian/experimental

Imported using usd-importer.

Publish parent: 4e9f2a577a35589840ff4b906ba67de43f9f11ca

New changelog entries:
  [Timo Aaltonen]
  * Sync 30_dynamic_db.diff from Fedora.
  * rules: Backup some files which dh_autoreconf_clean would remove, restore
    on clean.
  [Jamie Strandboge]
  * apparmor: use @{PROC} instead of /proc, allow read on
    sys.net.ipv4.ip_local_port_range. LP: #1552441
  [LaMont Jones]
  * Return nanosecond-precise time for files, so that we more-correctly know
    when we can skip loading a zonefile. (Bug introduced 9.9.3b2)

4e9f2a5... by LaMont Jones

Import patches-unapplied version 1:9.10.3.dfsg.P2-4 to debian/experimental

Imported using usd-importer.

Publish parent: 5da11e103c0d8a8641a5801ff5efd735027e30bd

New changelog entries:
  [Matthias Klose]
  * Fix .so symlinks.
  * libbind-dev: Depend on libirs141.
  * For the udeb's, use a separate build with a reduced feature set, drop the
    name difference, and do both builds in a separate directory.
  [Filip Pytloun]
  * Add apparmor rules needed by freeipa-server. Closes: #814314
  [LaMont Jones]
  * Do not deliver libraries (left in /lib) as part of bind9. LP: #1547052
  * clean up library path for libirs.
  * For the udeb's, use a separate build with a reduced feature set.
  * Don't call the reduced build "export"; it was used by isc-dhcp as well.
  * Do both builds in a separate builddir.
  * libbind-dev: Depend on libirs141.
  * Ship libirs.{a,so} in libbind-dev.
  * Remove obsolete debian/*.dirs files.
  * Fix .so symlinks.

5da11e1... by LaMont Jones

Import patches-unapplied version 1:9.10.3.dfsg.P2-3 to debian/experimental

Imported using usd-importer.

Publish parent: a080437bfe45e3f90472345bd0e1aaf2302fd0c2
Changelog parent: 9d94cc56f009b5e110a6e5807c74ffeadc9ef703

New changelog entries:
  [Marc Deslauriers]
  * SECURITY UPDATE: denial of service via string formatting operations.
    CVE-2015-8704
  [Matthias Klose]
  * Add multiarch support. Closes: #802584
  * Standars cleanup.
  [LaMont Jones]
  * Properly finish converting to 3.0 (quilt) format.
  * Drop geoip_acl patch temporarily while we evaluate the upstream geoip
    changes.
  * Prechroot init appears to have been taken upstream.
  * New upstream, no need for export packages with 9.10
  * Fix sonames
  * Update how we do hardening.
  * Add Robie Basak as an uploader
  * Migrate quilt patches from 9.9.5 branch, and incorporate Michael Gilbert's
    changes.

9d94cc5... by Michael Gilbert <email address hidden>

Import patches-unapplied version 1:9.9.5.dfsg-12 to debian/sid

Imported using usd-importer.

Publish parent: 7704153e03b7b3da152633423d2506d8b3b38f92

New changelog entries:
  * Fix CVE-2015-5722: maliciously crafted DNSSEC key can cause named to crash.

7704153... by Michael Gilbert <email address hidden>

Import patches-unapplied version 1:9.9.5.dfsg-11 to debian/sid

Imported using usd-importer.

Publish parent: 68c454bebf1d0229c94058a2eec74de749f33ac2

New changelog entries:
  * Fix CVE-2015-5477: maliciously crafted TKEY query can cause named to exit
    (closes: #793903).

68c454b... by Michael Gilbert <email address hidden>

Import patches-unapplied version 1:9.9.5.dfsg-10 to debian/sid

Imported using usd-importer.

Publish parent: fd649d95fb0a99052c524e8250b0379e4bb25335

New changelog entries:
  * Fix CVE-2015-4620: DNSSEC validation of a malicously crafted zone can
    cause the resolver to crash (closes: #791715).

fd649d9... by Michael Gilbert <email address hidden>

Import patches-unapplied version 1:9.9.5.dfsg-9 to debian/sid

Imported using usd-importer.

Publish parent: d5e474c77898aa41ffa3cec35f149a72309fa631

New changelog entries:
  * Fix CVE-2015-1349: named crash due to managed key rollover, primarily only
    affecting setups using DNSSEC (closes: #778733).

d5e474c... by Michael Gilbert <email address hidden>

Import patches-unapplied version 1:9.9.5.dfsg-8 to debian/sid

Imported using usd-importer.

Publish parent: 7c5d82a1dce90d1b9d4ada85c2ac24e465bf2cd3

New changelog entries:
  * Launch rndc command in the background in networking scripts to avoid a
    hang in named from bringing down the entire network (closes: #760555).

7c5d82a... by Michael Gilbert <email address hidden>

Import patches-unapplied version 1:9.9.5.dfsg-7 to debian/sid

Imported using usd-importer.

Publish parent: ac73dd8c395a6f21f464bbd5213faee8447542a0

New changelog entries:
  * Fix CVE-2014-8500: limit recursion in order to avoid memory consuption
    issues that can lead to denial-of-service (closes: #772610).