Created by Scott Moser and last modified

This is a branch tracking precise-updates, because it seems that lp:ubuntu/precise-updates/isc-dhcp is not functioning correctly.

I've used 'bzr import-dsc' to keep it updated.

I'm using this branch to merge with the branch at lp:~smoser/ubuntu/precise/isc-dhcp/nouid

Get this branch:
bzr branch lp:~smoser/ubuntu/precise/isc-dhcp/precise-updates.dist
Only Scott Moser can upload to this branch. If you are Scott Moser please log in for upload directions.

Branch merges

Related bugs

Related blueprints

Branch information

Scott Moser

Recent revisions

54. By Philipp Kern

debian/dhclient-script.linux: Allow stateless DHCPv6 to complete
configuration. (LP: #1214385)

53. By Stéphane Graber

[ Dave Chiluk ]
* Allow dhcpd to read /etc/ldap/ldap.conf for isc-dhcp-server-ldap.
  (LP: #1057358). Backported from Stéphane Graber's quantal patch.

[ Stéphane Graber ]
* Include patch from RedHat/Fedora to deal with hardware/xen/virtio offload
  of UDP checksums. (LP: #930962)
* Update apparmor profile to add required the "network packet raw" rule
  for the checksum change.

52. By chiluk <email address hidden>

Allow dhcpd to read /etc/ldap/ldap.conf for isc-dhcp-server-ldap.
(LP: #1057358). Backported from Stéphane Graber's quantal patch.

51. By Stéphane Graber

[ Scott Moser ]
* debian/apparmor-profile.dhcpd: use include directory to enable
  other packages to re-use isc-dhcp-server. (LP: #1049177)

[ Stéphane Graber ]
* Update onetry_retry_after_initial_success to disable the onetry variable
  early enough to actually prevent dhclient from exiting. (LP: #974284)
* Update droppriv patch to also call initgroups() (LP: #727837)

50. By Marc Deslauriers

[ Jamie Strandboge ]
* debian/dhclient-script.linux: Explicitly set the PATH to that of
  ENV_SUPATH in /etc/login.defs and unset various other variables. We need
  to do this so /sbin/dhclient cannot abuse the environment to escape
  AppArmor confinement via this script. Don't worry about
  debian/dhclient-script.linux.udeb or debian/dhclient-script.kfreebsd*
  since AppArmor isn't used in these environments.
  - LP: #1045986

[ Marc Deslauriers ]
* SECURITY UPDATE: denial of service via ipv6 lease expiration time
  - debian/patches/CVE-2012-3955.patch: properly handle time reduction in
    server/dhcpv6.c, server/mdb6.c.
  - CVE-2012-3955

49. By Stéphane Graber

Move onetry_retry_after_initial_success to the proper spot in the patch
stack so that it actually gets applied. (LP: #974284)

48. By Stéphane Graber

* Set -pf option for both isc-dhcp-server and isc-dhcp-server6 so they
  create their pid files in a path that's actually writable. (LP: #985417)
* Also allow read access to the pid file in the apparmor profile,
  otherwise only the initial start succeeds. (LP: #1005062)
* On upgrade from dhcp3-server, move /etc/default/dhcp3-server to
  /etc/default/isc-dhcp-server. (LP: #1003971)
* On upgrade from dhcp3-relay, remove /etc/default/dhcp3-relay.
  (LP: #1005547)
* Try to preseed isc-dhcp-relay with the values from
  /etc/default/dhcp3-relay. (LP: #1005547)

47. By Stéphane Graber

releasing version 4.1.ESV-R4-0ubuntu5

46. By Stéphane Graber

Exit onetry mode after we get our initial lease in -1 mode.

45. By Jamie Strandboge

* debian/apparmor-profile.dhcpd:
  - allow writes to the compiled in default pid file (LP: #974054)
  - allow reads to /var/lib/wicd/* (LP: #588635)

Branch metadata

Branch format:
Branch format 7
Repository format:
Bazaar repository format 2a (needs bzr 1.16 or later)
Stacked on:
This branch contains Public information 
Everyone can see this information.