lp:ubuntu/intrepid-security/procps

Created by James Westby and last modified
Get this branch:
bzr branch lp:ubuntu/intrepid-security/procps
Members of Ubuntu branches can upload to this branch. Log in for directions.

Branch merges

Related bugs

Related blueprints

Branch information

Owner:
Ubuntu branches
Review team:
Ubuntu Development Team
Status:
Development

Recent revisions

26. By Colin Watson

Drop debian/sysctl.d/10-tcp-timestamps-workaround.conf again now that we
have a fixed kernel, and make sure it gets removed on upgrade to this
version (LP: #264019).

25. By Colin Watson

Add debian/sysctl.d/10-tcp-timestamps-workaround.conf to disable TCP
timestamping, since its implementation in the 2.6.27 kernel in Ubuntu
8.10 causes problems with certain routers (LP: #264019).

24. By Kees Cook

* Merge from debian unstable, remaining changes:
  - debian/{postinst,rules}: init script to priority 17, remove on upgrade.
  - debian/patches/60_top_nohz: fix idle report when running NOHZ (debian
    bug #495882).
  - debian/init: respect $VERBOSE setting (debian bug #495885).
  - debian/sysctl.conf: recommend against tcp_syncookies since it blocks
    tcp window scaling (debian bug #495884).
  - debian/control: Maintainer field update.
* debian/sysctl.d: move all Ubuntu-specific sysctl settings:
  - 10-console-messages.conf: stop low-level kernel messages on console.
  - 10-network-security.conf: enable "rp_filter" by default.
  - 10-process-security.conf:
    - block lower 64k allocations to protect kernel from NULL deref attacks.
    - enable /proc/$pid/maps protection.
  - 10-keyboard.conf.powerpc: Mouse button emulation.
  - 30-inotify-limits.conf: moved to "tracker" package for increasing
    inotify watches to 524,388 for tracker.
* debian/rules:
  - install sysctl files from new sysctl.d directory.
  - append debian/sysctl.d/*.conf.$DEB_HOST_ARCH to 10-arch-specific.conf
* debian/sysctl.conf: add comment drawing attention to sysctl.d directory
  (debian bug #495884).

23. By Adam Conrad

Remove rcS.d/S17procps.sh on upgrade, eliminating Ubuntu cruft.

22. By to be removed

* Merge from debian unstable, remaining changes (LP: #242976):
  - debian/{postinst,rules}: Place init script at priority 17.
  - debian/patches/60_top_nohz: fix idle report when running NOHZ.
  - debian/sysctl.conf: enable /proc/$pid/maps protection.
  - debian/rules: allow for arch-specific sysctl.conf settings.
    (append debian/sysctl.conf.$DEB_HOST_ARCH, if it exists, to sysctl.conf)
  - debian/sysctl.conf.powerpc: Mouse button emulation.
  - debian/init: respect $VERBOSE setting.
  - debian/control: Maintainer field update.
  - debian/sysctl.conf: stop low-level kernel messages to console
    (this was formerly not documented in the changelog)
  - debian/sysctl.conf: increase inotify watches to 524,388 for tracker.
  - debian/sysctl.conf: enable "rp_filter" by default.
  - debian/sysctl.conf: comment added about tcp_syncookies setting disabling
    TCP Window Scaling
  - debian/sysctl.conf: enable lower 64k protection to stop NULL deref
    attacks.

21. By Kees Cook

* debian/sysctl.conf:
  - enable "rp_filter" by default (LP: #201952).
  - clean up duplicated entries, adjust documentation about syn cookies.

20. By Kees Cook

* Merge from debian unstable, remaining changes:
  - debian/{postinst,rules}: Place init script at priority 17.
  - debian/patches/60_top_nohz: fix idle report when running NOHZ.
  - debian/sysctl.conf: enable /proc/$pid/maps protection.
  - debian/rules: allow for arch-specific sysctl.conf settings.
  - debian/sysctl.conf.powerpc: Mouse button emulation.
  - debian/init: respect $VERBOSE setting.
  - debian/control: Maintainer field update.
  - debian/sysctl.conf: increase inotify watches to 524,388 for tracker.
* debian/sysctl.conf: enable lower 64k protection to stop NULL deref attacks.

19. By Scott James Remnant (Canonical)

No particular need for the maximum inotify instances to be that high,
leave them at the default -otherwise you'll exhaust file descriptors
first.

18. By Scott James Remnant (Canonical)

Increase maximum inotify instances to 1,024 and watches to 524,388 -
since tracker is in our default install, we need a lot more.

17. By Adam Conrad

Test for DEB_HOST_ARCH_OS=linux instead of DEB_HOST_GNU_SYSTEM=linux-gnu
as the lpia DEB_HOST_GNU_SYSTEM is linux-gnulp instead, which breaks.

Branch metadata

Branch format:
Branch format 7
Repository format:
Bazaar repository format 2a (needs bzr 1.16 or later)
Stacked on:
lp:ubuntu/karmic/procps
This branch contains Public information 
Everyone can see this information.

Subscribers