Recent commits

198f5a7... by Marc Deslauriers on 2017-10-26

Import patches-unapplied version 232-21ubuntu7.1 to ubuntu/zesty-security

Imported using git-ubuntu import.

Changelog parent: f204e1420367baa79b675deed96bf666bf4e536e

New changelog entries:
  * SECURITY UPDATE: remote DoS in resolve (LP: #1725351)
    - debian/patches/CVE-2017-15908.patch: fix loop on packets with pseudo
      dns types in src/resolve/resolved-dns-packet.c.
    - CVE-2017-15908

f204e14... by Dimitri John Ledkov on 2017-10-04

Import patches-unapplied version 232-21ubuntu7 to ubuntu/zesty-proposed

Imported using git-ubuntu import.

Changelog parent: 9e5398e2f441583f3f0ec62b7a00b2b789fdfffe

New changelog entries:
  * networkd: accept `:' in ifnames in systemd/networkd. (LP: #1714933)
  * networkd: add support for ActiveSlave and PrimarySlave netdev options.
    (LP: #1709135)
  * Cherrypick upstream fix for a race between .mount and .automount units,
    which currently may result in automounts hanging. (LP: #1709649)
  * systemd.postinst: Fix-up version number check in the previous sru.
    The version check in the postinst was too tight, thus the SRU fix failed
    validation. (LP: #1710410)

9e5398e... by Dimitri John Ledkov on 2017-08-31

Import patches-unapplied version 232-21ubuntu6 to ubuntu/zesty-proposed

Imported using git-ubuntu import.

Changelog parent: afc143932c5f549d0296f80b06ca8f5f2d15c407

New changelog entries:
  * link: Fix offload features initialization.
    This fixes a regression introduced in v232 which caused TCP
    segmentation offloads being disabled by default, resulting in
    significant performance issues under certain conditions. (Closes: #864073)
    (LP: #1703393)
  * loginctl: Fix loginctl ignoring user given session IDs at command-line
    (LP: #1682154)
  * Disable fallback DNS servers.
    This causes resolved to call-home to google, attempt to access network when
    none is available, and spams logs. (LP: #1449001)
  * initramfs-tools: trigger udevadm add actions with subsystems first.
    This updates the initramfs-tools init-top udev script to trigger udevadm
    actions with type specified. This mimicks the
    systemd-udev-trigger.service. Without type specified only devices are
    triggered, but triggering subsystems may also be required and should happen
    before triggering the devices. This is the case for example on s390x with zdev
    generated udev rules. (LP: #1713536)
  * Enable systemd-resolved by default. (LP: #1710410)
  * core: fix systemd failing to serialize tasks correctly on daemon-reload.
    (LP: #1702823)

afc1439... by Chris Coulson on 2017-06-21

Import patches-unapplied version 232-21ubuntu5 to ubuntu/zesty-security

Imported using git-ubuntu import.

Changelog parent: b40f923b22ce6ef82af6b90352e89e3d97ed7c01

New changelog entries:
  * SECURITY UPDATE: Out-of-bounds write in systemd-resolved (LP: #1695546)
    - debian/patches/test-resolved-packet-add-a-simple-test-for-our-alloc.patch:
      Add a simple allocation test
    - debian/patches/resolved-simplify-alloc-size-calculation.patch: Simply
      allocation size calculation
    - CVE-2017-9445

b40f923... by Dimitri John Ledkov on 2017-05-24

Import patches-unapplied version 232-21ubuntu4 to ubuntu/zesty-proposed

Imported using git-ubuntu import.

Changelog parent: c33207394ee4e4a8e5af055aa16294950e4e2c68

New changelog entries:
  * Cherrypick upstream commit to enable system use kernel maximum limit for
    RLIMIT_NOFILE isntead of hard-coded (low) limit of 65536. (LP: #1686361)
  * debian/tests/root-unittests: disable execute and seccomp tests on arm
    test-seccomp and test-execute fail on arm64 kernels. Marking both tests as
    expected failures. An upstream bug report is filed to resolve these.
    (LP: #1672499)
  * Cherrypick upstream patch for platform predictable interface names.
    (LP: #1686784)
  * resolved: fix null pointer dereference crash (LP: #1621396)
  * Cherrypick core/timer downgrade message about random time addition
    (LP: #1692136)

c332073... by Dimitri John Ledkov on 2017-04-13

Import patches-unapplied version 232-21ubuntu3 to ubuntu/zesty-proposed

Imported using git-ubuntu import.

Changelog parent: 68b915580ddcb2788b5cbc3f4316f6fbd06fb3eb

New changelog entries:
  [ Martin Pitt ]
  * resolved: Disable DNSSEC by default on stretch and zesty.
    Both Debian stretch and Ubuntu zesty are close to releasing, switch to
    DNSSEC=off by default for those. Users can still turn it back on with
    DNSSEC=allow-downgrade (or even "yes"). (LP: #1682499)
  [ Michael Biebl ]
  * journal: fix up syslog facility when forwarding native messages.
    Native journal messages (_TRANSPORT=journal) typically don't have a
    syslog facility attached to it. As a result when forwarding the
    messages to syslog they ended up with facility 0 (LOG_KERN).
    Apply syslog_fixup_facility() so we use LOG_USER instead. (Closes: #837893)
    (LP: #1682484)
  [ Dimitri John Ledkov ]
  * networkd: cherry-pick support for setting bridge port's priority.
    This is a useful feature/bugfix to improve feature parity of networkd with
    ifupdown. This matches netplan's expectations to be able to set bridge port's
    priorities via networked. This featue is to be used by netplan/MAAS/OpenStack.
    (LP: #1668347)
  * TEST-12: cherry-pick upstream fix for compat with new netcat-openbsd.
    (LP: #1672542)
  * udev.postinst: preserve virtio interfaces names on upgrades, on s390x.
    New udev generates stable interface names on s390x kvm instances, however, upon
    upgrades existing ethX names should be preserved to prevent breaking networking
    and software configurations. (Closes: #860246) (LP: #1682437)

68b9155... by Dimitri John Ledkov on 2017-03-28

Import patches-unapplied version 232-21ubuntu2 to ubuntu/zesty-proposed

Imported using git-ubuntu import.

Changelog parent: e70bc544ba9b570ff382494c6125ad7077580615

New changelog entries:
  * pkgconfig: Cherrypick upstream fix to libdir locations in .pc files
    (LP: #1674201)

e70bc54... by Gianfranco Costamagna on 2017-03-23

Import patches-unapplied version 232-21ubuntu1 to ubuntu/zesty-proposed

Imported using git-ubuntu import.

Changelog parent: b52be83d85f3450aea44d1608b9353a129e8f22f

New changelog entries:
  * Merge from Debian unstable, remaining changes:
  * debian/extra/units/systemd-resolved.service.d/resolvconf.conf: if
    resolved is going to be started, make sure this blocks
    network-online.target. LP: #1673860.

b52be83... by Michael Biebl on 2017-03-21

Import patches-unapplied version 232-21 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 2260180a3dd97f05b97a4de332d9ab807d48a3e4

New changelog entries:
  * resolved: Downgrade "processing query..." message to debug.
    It doesn't really add much value in normal operation and just spams the
    log. (Closes: #858197)
  * Do not throw a warning in emergency and rescue mode if plymouth is not
    Ideally, plymouth should only be referenced via dependencies, not
    ExecStartPre. This at least avoids the confusing error message on
    minimal installations that do not carry plymouth.
  * rules: Allow SPARC vdisk devices when identifying CD drives
    (Closes: #858014)

2260180... by Michael Biebl on 2017-03-16

Import patches-unapplied version 232-20 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 87093a4f22885d25221d3c264c838f08e6e05b14

New changelog entries:
  [ Martin Pitt ]
  * debian/gbp.conf: Switch to "stretch" branch
  * udev: Fix /dev/disk/by-path aliases for virtio disks. (Closes: #856558)
  * udev: Create persistent net names for virtio CCW devices.
    This only affects s390x as only this has CCW devices. This provides
    stable network interface names for those and avoids changing the names
    on updating Stretch to Buster. (Closes: #856559)
  * Move systemd.link(5) to udev package.
    .link files are being handled by udev, so it should ship the
    corresponding manpage. Bump Breaks/Replaces accordingly. (Closes: #857270)
  [ Michael Biebl ]
  * Avoid strict DM API versioning.
    Compiling against the dm-ioctl.h header as provided by the Linux kernel
    will embed the DM interface version number. Running an older kernel can
    lead to errors on shutdown when trying to detach DM devices.
    As a workaround, build against a local copy of dm-ioctl.h based on 3.13,
    which is the minimum required version to support DM_DEFERRED_REMOVE.
    (Closes: #856337)
  * cryptsetup-generator: Run cryptsetup service before swap unit.
    Otherwise if the cryptsetup service unit and swap unit for a swap
    device are not strictly ordered, it might happen that the swap unit
    activates/mounts the swap device before its cryptsetup service unit has
    a chance to run the 'mkswap' command. (Closes: #787028)
  * Override package-name-doesnt-match-sonames lintian warning for libnss-*
  * networkd: Fix size of MTUBytes so that it does not overwrite ARP
  [ Felipe Sateler ]
  * git-cherry-pick: Actually use cherry-pick for picking.
    Use git cherry-pick for picking instead of rebase.
    This allows using -x flag and thus record the upstream commit that is
    being picked.