samba.git
7 weeks agoMerge version 2:4.22.10+dfsg-0+deb13u1+rpi1 and 2:4.22.10+dfsg-0+deb13u2 to produce... archive/raspbian/2%4.22.10+dfsg-0+deb13u2+rpi1 raspbian/2%4.22.10+dfsg-0+deb13u2+rpi1
Raspbian automatic forward porter [Wed, 29 Jul 2026 11:17:39 +0000 (12:17 +0100)]
Merge version 2:4.22.10+dfsg-0+deb13u1+rpi1 and 2:4.22.10+dfsg-0+deb13u2 to produce 2:4.22.10+dfsg-0+deb13u2+rpi1

7 weeks agoMerge samba (2:4.22.10+dfsg-0+deb13u2) import into refs/heads/workingbranch
Michael Tokarev [Fri, 24 Jul 2026 13:14:13 +0000 (16:14 +0300)]
Merge samba (2:4.22.10+dfsg-0+deb13u2) import into refs/heads/workingbranch

7 weeks agoJuly 2026 samba security fixes for v4.22
Björn Jacke [Wed, 15 Jul 2026 18:42:00 +0000 (18:42 +0000)]
July 2026 samba security fixes for v4.22

Origin: upstream, https://bugzilla.samba.org/show_bug.cgi?id=16039
Forwarded: not-needed

From ea7530366da502e0a116467e4565304603eba5b1 Mon Sep 17 00:00:00 2001
From: Stefan Metzmacher <metze@samba.org>
Date: Fri, 29 May 2026 12:43:13 +0200
Subject: [PATCH 01/23] CVE-2026-6949: ndr_dns: let ndr_pull_dns_res_rec()
 remember the start offset

In order to verify TSIG signatures we need a reliable way to
truncate the original dns_name_packet buffer before the
last additional dns_res_rec.

BUG: https://bugzilla.samba.org/show_bug.cgi?id=16083

Signed-off-by: Stefan Metzmacher <metze@samba.org>
Reviewed-by: Douglas Bagnall <dbagnall@samba.org>
Gbp-Pq: Name 2026-jul-sec-update-bug-16039-v4-22-combined.patch

7 weeks agoreplace: use __xpg_strerror_r if available
Michael Tokarev [Fri, 7 Feb 2025 07:04:37 +0000 (10:04 +0300)]
replace: use __xpg_strerror_r if available

Forwarded: no

In order to avoid linking libreplace, use __xpg_strerror_r
instead of rep_strerror_r

Gbp-Pq: Name replace-xpg-strerror.patch

7 weeks agoctdb: use /run/ctdb instead of /var/run/ctdb
Michael Tokarev [Fri, 2 Dec 2022 08:45:01 +0000 (11:45 +0300)]
ctdb: use /run/ctdb instead of /var/run/ctdb

Forwarded: not-needed

Whole upstream path assignment needs a review.

Gbp-Pq: Name ctdb-use-run-instead-of-var-run.patch

7 weeks agoprint meaningful error message if python3-markdown is not installed
Michael Tokarev [Fri, 2 Dec 2022 08:08:27 +0000 (11:08 +0300)]
print meaningful error message if python3-markdown is not installed

Updated: Mon, 08 Apr 2024 14:14:38 +0300
Debian-Specific: yes
Forwarded: not-needed

Gbp-Pq: Name meaningful-error-if-no-python3-markdown.patch

7 weeks agoprint meaningful error message if samba-ad-provision is not installed
Michael Tokarev [Fri, 2 Dec 2022 07:54:31 +0000 (10:54 +0300)]
print meaningful error message if samba-ad-provision is not installed

Updated: Thu, 03 Aug 2023 17:06:24 +0300
Debian-Specific: yes
Forwarded: not-needed

Gbp-Pq: Name meaningful-error-if-no-samba-ad-provision.patch

7 weeks agomove msg.sock from /var/lib/samba to /run/samba
Michael Tokarev [Tue, 26 Apr 2022 13:11:48 +0000 (16:11 +0300)]
move msg.sock from /var/lib/samba to /run/samba

Move socket directory from /var/lib/samba to /run/samba,
exactly like msg.lock.  This directory is only used by various
samba components to communicate with each other (smbcontrol),
there's no place for it in /var/lib.

Also remove msg.sock subdir in various tests.

It'd be nice to also move ntp socket and similar somewhere to
/run/samba too, but this is a bit more difficult since it is
used in other software.

https://lists.samba.org/archive/samba-technical/2022-April/137322.html

Signed-off-by: Michael Tokarev <mjt@tls.msk.ru>
Gbp-Pq: Name move-msg.sock-from-var-lib-samba-to-run-samba.patch

7 weeks agodisable setuid configure checks
Michael Tokarev [Fri, 8 Apr 2022 08:50:21 +0000 (11:50 +0300)]
disable setuid configure checks

Forwarded: not-needed

For some strange reason, when running reprotest test on salsa-ci,
which apparently is running as root, - on the *second* build only
the configure fails (after successfully built package the first
time). The configure test tries to change gid and verifies it
actually changed (not that the syscall exist), - and that fails.
Since it is extremely uncommon to configure the build process as
root, salsa-ci test environment details are quite deep down the line,
and we know the syscall actually works, just disable the probe,
pretending we are not root.

For upstream, this probably should be done by removing a *lot* of
configure-time checks which are useless these days.

Gbp-Pq: Name disable-setuid-confchecks.patch

7 weeks agosilence uselib_local warning produced by waf
Michael Tokarev [Sun, 3 Apr 2022 04:57:38 +0000 (07:57 +0300)]
silence uselib_local warning produced by waf

During config/build process in verbose mode, waf produces
about 2k repetitions of this warning:

  compat: "uselib_local" is deprecated, replace by "use"

which clutters the build log.

Comment this warning out for now until it will be
fixed properly.

Gbp-Pq: Name silence-waf-uselib_local.diff

7 weeks agocreate ctdb pid directory
Michael Tokarev [Fri, 9 Sep 2022 09:49:55 +0000 (12:49 +0300)]
create ctdb pid directory

(which is /run/ctdb/). Create it in the systemd service
file (using RuntimeDirectory directive) and in the sysv-init
script.

Gbp-Pq: Name ctdb-create-piddir.patch

7 weeks agofix pathname for ctdb_etcd_lock
Michael Tokarev [Sat, 2 Apr 2022 14:49:38 +0000 (17:49 +0300)]
fix pathname for ctdb_etcd_lock

Forwarded: not-needed

Specify the actual installation path for this helper script.

This is a quick hack, this issue should be addressed
upstream in a more generic way.

Gbp-Pq: Name ctdb_etcd_lock-path.patch

7 weeks agouse bzero() instead of memset_s()
Debian Samba Maintainers [Fri, 24 Jul 2026 13:14:13 +0000 (16:14 +0300)]
use bzero() instead of memset_s()

lib/replace/replace.h header defines ZERO_STRUCT macro
which uses memset_s() function (which is similar to
memset() but can not be optimized out by the compiler).
Glibc has bzero() with similar property, while memset_s()
have is implemented in lib/replace/replace.c, - this way,
some binaries needlessly link with libreplace-samba4 just
to get rep_memset_s() symbol. By using bzero() instead,
this endless linkage is eliminated, so we can package,
for example, libldb (which uses ZERO_STRUCT) without it
linking to libreplace-samba4.

Note: actually using explicit_bzero() so it is not optimized
out by the compiler - this is the original goal of using
memset_s().

Gbp-Pq: Name use-bzero-instead-of-memset_s.diff

7 weeks agoctdb-config: enable syslog by default
Rafael David Tinoco [Fri, 24 Jul 2026 13:14:13 +0000 (16:14 +0300)]
ctdb-config: enable syslog by default

Bug-Debian: https://bugs.debian.org/929931
Bug-Ubuntu: https://bugs.launchpad.net/bugs/722201
Last-Update: 2022-03-24
Forwarded: not-needed

CTDB uses /var/log/ctdb/ directory for the default log files. With
syslog disabled, systemd journal is not able to correctly inform
errors happening during service initialization.

Upstream community creates generic config files to be used by different
distributions, so this change makes no big difference to be accepted by
upstream.

With this patch the end user will be able to identify initialization
errors by executing:

  systemctl status ctdb.service

or to follow ctdb logs by executing:

  journalctl -f -u ctdb

Signed-off-by: Rafael David Tinoco <rafaeldtinoco@ubuntu.com>
Gbp-Pq: Name ctdb-config-enable-syslog-by-default.patch

7 weeks agofix nfs related service names
Rafael David Tinoco [Fri, 24 Jul 2026 13:14:13 +0000 (16:14 +0300)]
fix nfs related service names

Upstream defines nfs related service names based on the Linux
distribution. This patch fixes the names for Debian and derivatives.

Update by Andreas Hasenack <andreas@canonical.com> (LP: #1961840):
Use nfsconf(8) if it's available, instead of parsing the old config
files in /etc/default/nfs-*

Bug-Debian: https://bugs.debian.org/929931
Bug-Ubuntu: https://bugs.launchpad.net/bugs/722201
Last-Update: 2024-07-30

Gbp-Pq: Name fix-nfs-service-name-to-nfs-kernel-server.patch

7 weeks agodrop "replace" dependency from libldb
Michael Tokarev [Wed, 27 Nov 2024 18:51:50 +0000 (21:51 +0300)]
drop "replace" dependency from libldb

Forwarded: not-needed

When building as a sub-library within samba, where
libreplace is a private library, libldb.so will
have rpath pointing to the private samba dir.  Since
ldb actually does not use anything from libreplace,
just remove the dependency.

Gbp-Pq: Name ldb-no-replace.diff

7 weeks agoAdd so version number to private libraries for dpkg-shlibdeps
Jeroen Dekkers [Fri, 24 Jul 2026 13:14:13 +0000 (16:14 +0300)]
Add so version number to private libraries for dpkg-shlibdeps

We also want dpkg-shlibdeps to generate correct dependency information
for the private libraries in our binary packages, but dpkg-shlibdeps
only works when the library has a version number.

Origin: vendor
Forwarded: not-needed

Gbp-Pq: Name add-so-version-to-private-libraries

7 weeks agoPatch in symbol table from rfc3454, for Heimdal scripts
Brian May [Fri, 24 Jul 2026 13:14:13 +0000 (16:14 +0300)]
Patch in symbol table from rfc3454, for Heimdal scripts

Forwarded: not-needed

Status: cherry-picked from heimdal package

Gbp-Pq: Name heimdal-rfc3454.txt

7 weeks agoEnable net usershares by default at build time
mathiaz@ubuntu.com [Fri, 24 Jul 2026 13:14:13 +0000 (16:14 +0300)]
Enable net usershares by default at build time

Enable net usershares by default at build time, with a limit of 100, and update
the corresponding documentation.

Bug-Debian: http://bugs.debian.org/443230
Bug-Ubuntu: https://bugs.launchpad.net/ubuntu/+source/samba/+bug/128548
Forwarded: not-needed

Gbp-Pq: Name usershare.patch

7 weeks agoUse the pager alternative as pager is PAGER is undefined
Steve Langasek [Fri, 24 Jul 2026 13:14:13 +0000 (16:14 +0300)]
Use the pager alternative as pager is PAGER is undefined

Bug-Debian: http://bugs.debian.org/135603
Forwarded: not-needed

Gbp-Pq: Name smbclient-pager.patch

7 weeks agoMention smbldap-tools package in examples/LDAP/README
Christian Perrier [Fri, 24 Jul 2026 13:14:13 +0000 (16:14 +0300)]
Mention smbldap-tools package in examples/LDAP/README

Bug-Debian: http://bugs.debian.org/341934
Forwarded: not-needed

Gbp-Pq: Name README_nosmbldap-tools.patch

7 weeks agohurd compatibility changes
Michael Tokarev [Thu, 3 Nov 2022 17:49:33 +0000 (20:49 +0300)]
hurd compatibility changes

Hurd does not define PIPE_BUF, so lib/tevent/testsuite.c fails to compile
(yes, this file is used as part of *samba* testsuite, not tevent testsuite).
Define it to a safe minimal value like 512 bytes.

Hurd does not provide SA_NOCLDWAIT define, so lib/util/tests/tfork.c does
not compile. This is only needed during testing to omit zombie process
generation, which has only cosmetic effect.  Define it to be 0.

Based on prior work and ideas by Samuel Thibault.

Gbp-Pq: Name hurd-compat.patch

7 weeks agoProvide public symbol tdb_logging_function removed upstream without major version...
Jelmer Vernooij [Fri, 24 Jul 2026 13:14:13 +0000 (16:14 +0300)]
Provide public symbol tdb_logging_function removed upstream without major version change. (bug #511011)

Status: Not forwarded upstream

Gbp-Pq: Name tdb_logging_func.diff

7 weeks agoforce tdb to be standalone
Michael Tokarev [Tue, 26 Nov 2024 14:28:51 +0000 (17:28 +0300)]
force tdb to be standalone

Forwarded: not-needed

Upstream ships contents of lib/tdb/ as a separate
source of tdb.  Since we build samba anyway, there's
no need to have separate tdb source package, it's
enough to build it during samba build.

Always build tdb as stand-alone library
(instead of being samba-private if in a subdir).

When building as a sub-library within samba,
where libreplace is a private library, libtdb.so
will have rpath pointing to the private samba
dir.  Since tdb actually does not use anything
from libreplace, just remove the dependency.

Gbp-Pq: Name tdb-standalone.diff

7 weeks agoforce tevent to be standalone
Michael Tokarev [Tue, 26 Nov 2024 14:28:51 +0000 (17:28 +0300)]
force tevent to be standalone

Forwarded: not-needed

Upstream ships contents of lib/tevent/ as a separate
source of tevent.  Since we build samba anyway, there's
no need to have separate tevent source package, it's
enough to build it during samba build.

Always build tevent as stand-alone library
(instead of being samba-private if in a subdir).

When building as a sub-library within samba, where
libreplace is a private library, libtevent.so will
have rpath pointing to the private samba dir.  Since
tevent actually does not use anything from libreplace,
just remove the dependency.

Gbp-Pq: Name tevent-standalone.diff

7 weeks agoforce talloc to be standalone
Michael Tokarev [Tue, 26 Nov 2024 14:28:51 +0000 (17:28 +0300)]
force talloc to be standalone

Forwarded: not-needed

Upstream ships contents of lib/talloc/ as a separate
source of talloc.  Since we build samba anyway, there's
no need to have separate talloc source package, it's
enough to build it during samba build.

Always build talloc as stand-alone library
(instead of being samba-private if in a subdir).

When building as a sub-library within samba, where
libreplace is a private library, libtalloc.so will
have rpath pointing to the private samba dir.  Since
talloc actually does not use anything from libreplace,
just remove the dependency.

Gbp-Pq: Name talloc-standalone.diff

7 weeks agoensure libsmbclient.h is being used with LFS enabled
Michael Tokarev [Sat, 2 Apr 2022 16:01:55 +0000 (19:01 +0300)]
ensure libsmbclient.h is being used with LFS enabled

Bug-Debian: https://bugs.debian.org/221618
Forwarded: not-needed

We build samba with LFS (Large File Support) even on 32bits.
This means some types like off_t are 64-bit wide, again,
even on a 32bit host.  libsmbclient.h uses off_t in function
prototypes, and thes prototypes muct match those which were
used at samba compile time - if some other source includes
libsmbclient.h without LFS, it'll get wrong prototypes and
the resulting binary will most likely crash when using
libsmbclient functions.

Detect and error-out this at compile time.

We can not do anything with this in the public header since
it is alredy too late to redefine things, since we can't
guarantee we're the first header a program #includes, and
at the time this libsmbclient.h is included, off_t can
already be defined so our (re)define of _FILE_OFFSET_BITS
does nothing already.

Patching libsmbclient.h to use off64_t means client program
should change their off_t to off64_t too when storing
file offsets returning from libsmbclient, so this is not
an option too.

With this change, we will error out even if the user source
does not use any off_t-related functions. Namely, it was ok
to #include <libsmbclient.h> and use smbc_open/smbc_read/
smbc_write/smbc_close without _F_O_B=64, - neither of these
functions uses off_t. smbc_lseek and others doesn't work,
but if a program does not use them anyway, whole thing will
just work even without enabling LFS.  Ideally we can probably
check each individual function which is being affected, by
replacing it with #error if sizeof(off_t) < 8.  But this
requires quite some hackery...

Gbp-Pq: Name libsmbclient-ensure-lfs-221618.patch

7 weeks agosamba (2:4.22.10+dfsg-0+deb13u2) trixie-security; urgency=medium
Michael Tokarev [Fri, 24 Jul 2026 13:14:13 +0000 (16:14 +0300)]
samba (2:4.22.10+dfsg-0+deb13u2) trixie-security; urgency=medium

  * 2026-jul-sec-update-bug-16039-v4-22-combined.patch:
    Jul-2026 samba security update addresses the following defects:

    CVE-2026-6949: https://bugzilla.samba.org/show_bug.cgi?id=16083
      TSIG packet with crafted name compression can crash internal DNS server

    CVE-2026-58224: https://bugzilla.samba.org/show_bug.cgi?id=16085
      CTDB: heap OOB read via unchecked packet length fields

    CVE-2026-58216: https://bugzilla.samba.org/show_bug.cgi?id=16087
      kpasswd service: 6-byte heap OOB read in packet parser

    CVE-2026-58218: https://bugzilla.samba.org/show_bug.cgi?id=16115
      DNS TKEY negotiation stores unauthenticated GSS contexts
      in a fixed FIFO before authentication completes

    CVE-2026-58221: https://bugzilla.samba.org/show_bug.cgi?id=16147
      authenticated LDAP access to internal LDB special DNs
      permits domain takeover

    CVE-2026-58222: https://bugzilla.samba.org/show_bug.cgi?id=16148
      LDAP Compare filter injection and trusted-request
      confusion disclose protected attributes

[dgit import unpatched samba 2:4.22.10+dfsg-0+deb13u2]

7 weeks agoImport samba_4.22.10+dfsg-0+deb13u2.debian.tar.xz
Michael Tokarev [Fri, 24 Jul 2026 13:14:13 +0000 (16:14 +0300)]
Import samba_4.22.10+dfsg-0+deb13u2.debian.tar.xz

[dgit import tarball samba 2:4.22.10+dfsg-0+deb13u2 samba_4.22.10+dfsg-0+deb13u2.debian.tar.xz]

8 weeks agoMerge version 2:4.22.8+dfsg-0+deb13u2+rpi1 and 2:4.22.10+dfsg-0+deb13u1 to produce... archive/raspbian/2%4.22.10+dfsg-0+deb13u1+rpi1 raspbian/2%4.22.10+dfsg-0+deb13u1+rpi1
Raspbian automatic forward porter [Tue, 21 Jul 2026 10:36:54 +0000 (11:36 +0100)]
Merge version 2:4.22.8+dfsg-0+deb13u2+rpi1 and 2:4.22.10+dfsg-0+deb13u1 to produce 2:4.22.10+dfsg-0+deb13u1+rpi1

3 months agoMerge version 2:4.22.8+dfsg-0+deb13u1+rpi1 and 2:4.22.8+dfsg-0+deb13u2 to produce... archive/raspbian/2%4.22.8+dfsg-0+deb13u2+rpi1 raspbian/2%4.22.8+dfsg-0+deb13u2+rpi1
Raspbian automatic forward porter [Thu, 28 May 2026 19:06:43 +0000 (20:06 +0100)]
Merge version 2:4.22.8+dfsg-0+deb13u1+rpi1 and 2:4.22.8+dfsg-0+deb13u2 to produce 2:4.22.8+dfsg-0+deb13u2+rpi1

3 months agoMerge samba (2:4.22.10+dfsg-0+deb13u1) import into refs/heads/workingbranch
Michael Tokarev [Tue, 26 May 2026 12:46:55 +0000 (15:46 +0300)]
Merge samba (2:4.22.10+dfsg-0+deb13u1) import into refs/heads/workingbranch

3 months agoImport samba_4.22.10+dfsg.orig.tar.xz
Michael Tokarev [Tue, 26 May 2026 12:46:55 +0000 (15:46 +0300)]
Import samba_4.22.10+dfsg.orig.tar.xz

[dgit import orig samba_4.22.10+dfsg.orig.tar.xz]

3 months agoreplace: use __xpg_strerror_r if available
Michael Tokarev [Fri, 7 Feb 2025 07:04:37 +0000 (10:04 +0300)]
replace: use __xpg_strerror_r if available

Forwarded: no

In order to avoid linking libreplace, use __xpg_strerror_r
instead of rep_strerror_r

Gbp-Pq: Name replace-xpg-strerror.patch

3 months agoctdb: use /run/ctdb instead of /var/run/ctdb
Michael Tokarev [Fri, 2 Dec 2022 08:45:01 +0000 (11:45 +0300)]
ctdb: use /run/ctdb instead of /var/run/ctdb

Forwarded: not-needed

Whole upstream path assignment needs a review.

Gbp-Pq: Name ctdb-use-run-instead-of-var-run.patch

3 months agoprint meaningful error message if python3-markdown is not installed
Michael Tokarev [Fri, 2 Dec 2022 08:08:27 +0000 (11:08 +0300)]
print meaningful error message if python3-markdown is not installed

Updated: Mon, 08 Apr 2024 14:14:38 +0300
Debian-Specific: yes
Forwarded: not-needed

Gbp-Pq: Name meaningful-error-if-no-python3-markdown.patch

3 months agoprint meaningful error message if samba-ad-provision is not installed
Michael Tokarev [Fri, 2 Dec 2022 07:54:31 +0000 (10:54 +0300)]
print meaningful error message if samba-ad-provision is not installed

Updated: Thu, 03 Aug 2023 17:06:24 +0300
Debian-Specific: yes
Forwarded: not-needed

Gbp-Pq: Name meaningful-error-if-no-samba-ad-provision.patch

3 months agomove msg.sock from /var/lib/samba to /run/samba
Michael Tokarev [Tue, 26 Apr 2022 13:11:48 +0000 (16:11 +0300)]
move msg.sock from /var/lib/samba to /run/samba

Move socket directory from /var/lib/samba to /run/samba,
exactly like msg.lock.  This directory is only used by various
samba components to communicate with each other (smbcontrol),
there's no place for it in /var/lib.

Also remove msg.sock subdir in various tests.

It'd be nice to also move ntp socket and similar somewhere to
/run/samba too, but this is a bit more difficult since it is
used in other software.

https://lists.samba.org/archive/samba-technical/2022-April/137322.html

Signed-off-by: Michael Tokarev <mjt@tls.msk.ru>
Gbp-Pq: Name move-msg.sock-from-var-lib-samba-to-run-samba.patch

3 months agodisable setuid configure checks
Michael Tokarev [Fri, 8 Apr 2022 08:50:21 +0000 (11:50 +0300)]
disable setuid configure checks

Forwarded: not-needed

For some strange reason, when running reprotest test on salsa-ci,
which apparently is running as root, - on the *second* build only
the configure fails (after successfully built package the first
time). The configure test tries to change gid and verifies it
actually changed (not that the syscall exist), - and that fails.
Since it is extremely uncommon to configure the build process as
root, salsa-ci test environment details are quite deep down the line,
and we know the syscall actually works, just disable the probe,
pretending we are not root.

For upstream, this probably should be done by removing a *lot* of
configure-time checks which are useless these days.

Gbp-Pq: Name disable-setuid-confchecks.patch

3 months agosilence uselib_local warning produced by waf
Michael Tokarev [Sun, 3 Apr 2022 04:57:38 +0000 (07:57 +0300)]
silence uselib_local warning produced by waf

During config/build process in verbose mode, waf produces
about 2k repetitions of this warning:

  compat: "uselib_local" is deprecated, replace by "use"

which clutters the build log.

Comment this warning out for now until it will be
fixed properly.

Gbp-Pq: Name silence-waf-uselib_local.diff

3 months agocreate ctdb pid directory
Michael Tokarev [Fri, 9 Sep 2022 09:49:55 +0000 (12:49 +0300)]
create ctdb pid directory

(which is /run/ctdb/). Create it in the systemd service
file (using RuntimeDirectory directive) and in the sysv-init
script.

Gbp-Pq: Name ctdb-create-piddir.patch

3 months agofix pathname for ctdb_etcd_lock
Michael Tokarev [Sat, 2 Apr 2022 14:49:38 +0000 (17:49 +0300)]
fix pathname for ctdb_etcd_lock

Forwarded: not-needed

Specify the actual installation path for this helper script.

This is a quick hack, this issue should be addressed
upstream in a more generic way.

Gbp-Pq: Name ctdb_etcd_lock-path.patch

3 months agouse bzero() instead of memset_s()
Debian Samba Maintainers [Tue, 26 May 2026 12:46:55 +0000 (15:46 +0300)]
use bzero() instead of memset_s()

lib/replace/replace.h header defines ZERO_STRUCT macro
which uses memset_s() function (which is similar to
memset() but can not be optimized out by the compiler).
Glibc has bzero() with similar property, while memset_s()
have is implemented in lib/replace/replace.c, - this way,
some binaries needlessly link with libreplace-samba4 just
to get rep_memset_s() symbol. By using bzero() instead,
this endless linkage is eliminated, so we can package,
for example, libldb (which uses ZERO_STRUCT) without it
linking to libreplace-samba4.

Note: actually using explicit_bzero() so it is not optimized
out by the compiler - this is the original goal of using
memset_s().

Gbp-Pq: Name use-bzero-instead-of-memset_s.diff

3 months agoctdb-config: enable syslog by default
Rafael David Tinoco [Tue, 26 May 2026 12:46:55 +0000 (15:46 +0300)]
ctdb-config: enable syslog by default

Bug-Debian: https://bugs.debian.org/929931
Bug-Ubuntu: https://bugs.launchpad.net/bugs/722201
Last-Update: 2022-03-24
Forwarded: not-needed

CTDB uses /var/log/ctdb/ directory for the default log files. With
syslog disabled, systemd journal is not able to correctly inform
errors happening during service initialization.

Upstream community creates generic config files to be used by different
distributions, so this change makes no big difference to be accepted by
upstream.

With this patch the end user will be able to identify initialization
errors by executing:

  systemctl status ctdb.service

or to follow ctdb logs by executing:

  journalctl -f -u ctdb

Signed-off-by: Rafael David Tinoco <rafaeldtinoco@ubuntu.com>
Gbp-Pq: Name ctdb-config-enable-syslog-by-default.patch

3 months agofix nfs related service names
Rafael David Tinoco [Tue, 26 May 2026 12:46:55 +0000 (15:46 +0300)]
fix nfs related service names

Upstream defines nfs related service names based on the Linux
distribution. This patch fixes the names for Debian and derivatives.

Update by Andreas Hasenack <andreas@canonical.com> (LP: #1961840):
Use nfsconf(8) if it's available, instead of parsing the old config
files in /etc/default/nfs-*

Bug-Debian: https://bugs.debian.org/929931
Bug-Ubuntu: https://bugs.launchpad.net/bugs/722201
Last-Update: 2024-07-30

Gbp-Pq: Name fix-nfs-service-name-to-nfs-kernel-server.patch

3 months agodrop "replace" dependency from libldb
Michael Tokarev [Wed, 27 Nov 2024 18:51:50 +0000 (21:51 +0300)]
drop "replace" dependency from libldb

Forwarded: not-needed

When building as a sub-library within samba, where
libreplace is a private library, libldb.so will
have rpath pointing to the private samba dir.  Since
ldb actually does not use anything from libreplace,
just remove the dependency.

Gbp-Pq: Name ldb-no-replace.diff

3 months agoAdd so version number to private libraries for dpkg-shlibdeps
Jeroen Dekkers [Tue, 26 May 2026 12:46:55 +0000 (15:46 +0300)]
Add so version number to private libraries for dpkg-shlibdeps

We also want dpkg-shlibdeps to generate correct dependency information
for the private libraries in our binary packages, but dpkg-shlibdeps
only works when the library has a version number.

Origin: vendor
Forwarded: not-needed

Gbp-Pq: Name add-so-version-to-private-libraries

3 months agoPatch in symbol table from rfc3454, for Heimdal scripts
Brian May [Tue, 26 May 2026 12:46:55 +0000 (15:46 +0300)]
Patch in symbol table from rfc3454, for Heimdal scripts

Forwarded: not-needed

Status: cherry-picked from heimdal package

Gbp-Pq: Name heimdal-rfc3454.txt

3 months agoEnable net usershares by default at build time
mathiaz@ubuntu.com [Tue, 26 May 2026 12:46:55 +0000 (15:46 +0300)]
Enable net usershares by default at build time

Enable net usershares by default at build time, with a limit of 100, and update
the corresponding documentation.

Bug-Debian: http://bugs.debian.org/443230
Bug-Ubuntu: https://bugs.launchpad.net/ubuntu/+source/samba/+bug/128548
Forwarded: not-needed

Gbp-Pq: Name usershare.patch

3 months agoUse the pager alternative as pager is PAGER is undefined
Steve Langasek [Tue, 26 May 2026 12:46:55 +0000 (15:46 +0300)]
Use the pager alternative as pager is PAGER is undefined

Bug-Debian: http://bugs.debian.org/135603
Forwarded: not-needed

Gbp-Pq: Name smbclient-pager.patch

3 months agoMention smbldap-tools package in examples/LDAP/README
Christian Perrier [Tue, 26 May 2026 12:46:55 +0000 (15:46 +0300)]
Mention smbldap-tools package in examples/LDAP/README

Bug-Debian: http://bugs.debian.org/341934
Forwarded: not-needed

Gbp-Pq: Name README_nosmbldap-tools.patch

3 months agohurd compatibility changes
Michael Tokarev [Thu, 3 Nov 2022 17:49:33 +0000 (20:49 +0300)]
hurd compatibility changes

Hurd does not define PIPE_BUF, so lib/tevent/testsuite.c fails to compile
(yes, this file is used as part of *samba* testsuite, not tevent testsuite).
Define it to a safe minimal value like 512 bytes.

Hurd does not provide SA_NOCLDWAIT define, so lib/util/tests/tfork.c does
not compile. This is only needed during testing to omit zombie process
generation, which has only cosmetic effect.  Define it to be 0.

Based on prior work and ideas by Samuel Thibault.

Gbp-Pq: Name hurd-compat.patch

3 months agoProvide public symbol tdb_logging_function removed upstream without major version...
Jelmer Vernooij [Tue, 26 May 2026 12:46:55 +0000 (15:46 +0300)]
Provide public symbol tdb_logging_function removed upstream without major version change. (bug #511011)

Status: Not forwarded upstream

Gbp-Pq: Name tdb_logging_func.diff

3 months agoforce tdb to be standalone
Michael Tokarev [Tue, 26 Nov 2024 14:28:51 +0000 (17:28 +0300)]
force tdb to be standalone

Forwarded: not-needed

Upstream ships contents of lib/tdb/ as a separate
source of tdb.  Since we build samba anyway, there's
no need to have separate tdb source package, it's
enough to build it during samba build.

Always build tdb as stand-alone library
(instead of being samba-private if in a subdir).

When building as a sub-library within samba,
where libreplace is a private library, libtdb.so
will have rpath pointing to the private samba
dir.  Since tdb actually does not use anything
from libreplace, just remove the dependency.

Gbp-Pq: Name tdb-standalone.diff

3 months agoforce tevent to be standalone
Michael Tokarev [Tue, 26 Nov 2024 14:28:51 +0000 (17:28 +0300)]
force tevent to be standalone

Forwarded: not-needed

Upstream ships contents of lib/tevent/ as a separate
source of tevent.  Since we build samba anyway, there's
no need to have separate tevent source package, it's
enough to build it during samba build.

Always build tevent as stand-alone library
(instead of being samba-private if in a subdir).

When building as a sub-library within samba, where
libreplace is a private library, libtevent.so will
have rpath pointing to the private samba dir.  Since
tevent actually does not use anything from libreplace,
just remove the dependency.

Gbp-Pq: Name tevent-standalone.diff

3 months agoforce talloc to be standalone
Michael Tokarev [Tue, 26 Nov 2024 14:28:51 +0000 (17:28 +0300)]
force talloc to be standalone

Forwarded: not-needed

Upstream ships contents of lib/talloc/ as a separate
source of talloc.  Since we build samba anyway, there's
no need to have separate talloc source package, it's
enough to build it during samba build.

Always build talloc as stand-alone library
(instead of being samba-private if in a subdir).

When building as a sub-library within samba, where
libreplace is a private library, libtalloc.so will
have rpath pointing to the private samba dir.  Since
talloc actually does not use anything from libreplace,
just remove the dependency.

Gbp-Pq: Name talloc-standalone.diff

3 months agoensure libsmbclient.h is being used with LFS enabled
Michael Tokarev [Sat, 2 Apr 2022 16:01:55 +0000 (19:01 +0300)]
ensure libsmbclient.h is being used with LFS enabled

Bug-Debian: https://bugs.debian.org/221618
Forwarded: not-needed

We build samba with LFS (Large File Support) even on 32bits.
This means some types like off_t are 64-bit wide, again,
even on a 32bit host.  libsmbclient.h uses off_t in function
prototypes, and thes prototypes muct match those which were
used at samba compile time - if some other source includes
libsmbclient.h without LFS, it'll get wrong prototypes and
the resulting binary will most likely crash when using
libsmbclient functions.

Detect and error-out this at compile time.

We can not do anything with this in the public header since
it is alredy too late to redefine things, since we can't
guarantee we're the first header a program #includes, and
at the time this libsmbclient.h is included, off_t can
already be defined so our (re)define of _FILE_OFFSET_BITS
does nothing already.

Patching libsmbclient.h to use off64_t means client program
should change their off_t to off64_t too when storing
file offsets returning from libsmbclient, so this is not
an option too.

With this change, we will error out even if the user source
does not use any off_t-related functions. Namely, it was ok
to #include <libsmbclient.h> and use smbc_open/smbc_read/
smbc_write/smbc_close without _F_O_B=64, - neither of these
functions uses off_t. smbc_lseek and others doesn't work,
but if a program does not use them anyway, whole thing will
just work even without enabling LFS.  Ideally we can probably
check each individual function which is being affected, by
replacing it with #error if sizeof(off_t) < 8.  But this
requires quite some hackery...

Gbp-Pq: Name libsmbclient-ensure-lfs-221618.patch

3 months agosamba (2:4.22.10+dfsg-0+deb13u1) trixie; urgency=medium
Michael Tokarev [Tue, 26 May 2026 12:46:55 +0000 (15:46 +0300)]
samba (2:4.22.10+dfsg-0+deb13u1) trixie; urgency=medium

  * switch to actual upstream release for the May-2026 security fixes:

  * This is a security release in order to address the following defects:

    CVE-2026-1933: Missing access checks on reparse point operations
      On a share marked "read only = yes" and on file handles opened R/O users
      can set or delete the reparse point xattrs on files that the user has
      write-access in the file system for.
      https://www.samba.org/samba/security/CVE-2026-1933.html

    CVE-2026-2340: WORM vfs module does not block overwrites
      The WORM (Write-Once, Read Many) vfs module is supposed to lock write
      access to shared files, so they cannot be altered after initial writes.
      It was allowing files to be overwritten by renaming a newly created file
      over a protected file.
      https://www.samba.org/samba/security/CVE-2026-2340.html

    CVE-2026-3012: auto-enrolment GPO installing CA certificate over http
      without verification
      To bootstrap a certificate chain a domain member must fetch a certificate
      without TLS. It was trusting HTTP for this when a more secure encrypted
      LDAP channel was also available.
      https://www.samba.org/samba/security/CVE-2026-3012.html

    CVE-2026-3238: Denial of service against AD DC WINS server
      The WINS server component of the Active Directory Domain controller code
      in Samba is vulnerable to a NULL pointer dereference and crash caused by
      an unauthenticated UDP packet.
      https://www.samba.org/samba/security/CVE-2026-3238.html

    CVE-2026-4408: Unauthenticated Remote Code Execution in Samba DCE/RPC
      SAMR server
      Samba file servers and classic (non-AD) domain controllers with
      samba-dcerpcd started as a system service and with a "check password
      script" that has the %u substitution character are vulnerable to a
      remote code execution.
      https://www.samba.org/samba/security/CVE-2026-4408.html

    CVE-2026-4480: Unauthenticated Remote Code Execution in Samba
      printing subsystem
      Samba print servers with a "print command" that has the %J substitution
      character are vulnerable to a Remote Code Execution.
      https://www.samba.org/samba/security/CVE-2026-4480.html

[dgit import unpatched samba 2:4.22.10+dfsg-0+deb13u1]

3 months agoImport samba_4.22.10+dfsg-0+deb13u1.debian.tar.xz
Michael Tokarev [Tue, 26 May 2026 12:46:55 +0000 (15:46 +0300)]
Import samba_4.22.10+dfsg-0+deb13u1.debian.tar.xz

[dgit import tarball samba 2:4.22.10+dfsg-0+deb13u1 samba_4.22.10+dfsg-0+deb13u1.debian.tar.xz]

4 months agoMerge samba (2:4.22.8+dfsg-0+deb13u2) import into refs/heads/workingbranch
Michael Tokarev [Fri, 15 May 2026 03:38:23 +0000 (06:38 +0300)]
Merge samba (2:4.22.8+dfsg-0+deb13u2) import into refs/heads/workingbranch

4 months agosamba May-2026 security fixes
Debian Samba Maintainers [Fri, 15 May 2026 03:38:23 +0000 (06:38 +0300)]
samba May-2026 security fixes

Origin: upstream, https://bugzilla.samba.org/show_bug.cgi?id=16018
Forwarded: not-needed

This is bug-16018-v4-22-06.patch, with addition+deletion of
selftest/knownfail.d/vfs-worm commented-out (as dpkg does not
handle this situation well).

From f428950037af7a8e96b625b3bfc6e33fb7162aa3 Mon Sep 17 00:00:00 2001
From: Volker Lendecke <vl@samba.org>
Date: Thu, 5 Feb 2026 20:24:12 +0100
Subject: [PATCH 01/31] CVE-2026-1933 tests: Fix permissions used for creating
 reparse points

SEC_STD_ALL does not lead to fsp->access_mask to include the required
bits.

Bug: https://bugzilla.samba.org/show_bug.cgi?id=15992
Signed-off-by: Volker Lendecke <vl@samba.org>
Reviewed-by: Stefan Metzmacher <metze@samba.org>
Gbp-Pq: Name bug-16018-v4-22-06.patch

4 months agoreplace: use __xpg_strerror_r if available
Michael Tokarev [Fri, 7 Feb 2025 07:04:37 +0000 (10:04 +0300)]
replace: use __xpg_strerror_r if available

Forwarded: no

In order to avoid linking libreplace, use __xpg_strerror_r
instead of rep_strerror_r

Gbp-Pq: Name replace-xpg-strerror.patch

4 months agoctdb: use /run/ctdb instead of /var/run/ctdb
Michael Tokarev [Fri, 2 Dec 2022 08:45:01 +0000 (11:45 +0300)]
ctdb: use /run/ctdb instead of /var/run/ctdb

Forwarded: not-needed

Whole upstream path assignment needs a review.

Gbp-Pq: Name ctdb-use-run-instead-of-var-run.patch

4 months agoprint meaningful error message if python3-markdown is not installed
Michael Tokarev [Fri, 2 Dec 2022 08:08:27 +0000 (11:08 +0300)]
print meaningful error message if python3-markdown is not installed

Updated: Mon, 08 Apr 2024 14:14:38 +0300
Debian-Specific: yes
Forwarded: not-needed

Gbp-Pq: Name meaningful-error-if-no-python3-markdown.patch

4 months agoprint meaningful error message if samba-ad-provision is not installed
Michael Tokarev [Fri, 2 Dec 2022 07:54:31 +0000 (10:54 +0300)]
print meaningful error message if samba-ad-provision is not installed

Updated: Thu, 03 Aug 2023 17:06:24 +0300
Debian-Specific: yes
Forwarded: not-needed

Gbp-Pq: Name meaningful-error-if-no-samba-ad-provision.patch

4 months agomove msg.sock from /var/lib/samba to /run/samba
Michael Tokarev [Tue, 26 Apr 2022 13:11:48 +0000 (16:11 +0300)]
move msg.sock from /var/lib/samba to /run/samba

Move socket directory from /var/lib/samba to /run/samba,
exactly like msg.lock.  This directory is only used by various
samba components to communicate with each other (smbcontrol),
there's no place for it in /var/lib.

Also remove msg.sock subdir in various tests.

It'd be nice to also move ntp socket and similar somewhere to
/run/samba too, but this is a bit more difficult since it is
used in other software.

https://lists.samba.org/archive/samba-technical/2022-April/137322.html

Signed-off-by: Michael Tokarev <mjt@tls.msk.ru>
Gbp-Pq: Name move-msg.sock-from-var-lib-samba-to-run-samba.patch

4 months agodisable setuid configure checks
Michael Tokarev [Fri, 8 Apr 2022 08:50:21 +0000 (11:50 +0300)]
disable setuid configure checks

Forwarded: not-needed

For some strange reason, when running reprotest test on salsa-ci,
which apparently is running as root, - on the *second* build only
the configure fails (after successfully built package the first
time). The configure test tries to change gid and verifies it
actually changed (not that the syscall exist), - and that fails.
Since it is extremely uncommon to configure the build process as
root, salsa-ci test environment details are quite deep down the line,
and we know the syscall actually works, just disable the probe,
pretending we are not root.

For upstream, this probably should be done by removing a *lot* of
configure-time checks which are useless these days.

Gbp-Pq: Name disable-setuid-confchecks.patch

4 months agosilence uselib_local warning produced by waf
Michael Tokarev [Sun, 3 Apr 2022 04:57:38 +0000 (07:57 +0300)]
silence uselib_local warning produced by waf

During config/build process in verbose mode, waf produces
about 2k repetitions of this warning:

  compat: "uselib_local" is deprecated, replace by "use"

which clutters the build log.

Comment this warning out for now until it will be
fixed properly.

Gbp-Pq: Name silence-waf-uselib_local.diff

4 months agocreate ctdb pid directory
Michael Tokarev [Fri, 9 Sep 2022 09:49:55 +0000 (12:49 +0300)]
create ctdb pid directory

(which is /run/ctdb/). Create it in the systemd service
file (using RuntimeDirectory directive) and in the sysv-init
script.

Gbp-Pq: Name ctdb-create-piddir.patch

4 months agofix pathname for ctdb_etcd_lock
Michael Tokarev [Sat, 2 Apr 2022 14:49:38 +0000 (17:49 +0300)]
fix pathname for ctdb_etcd_lock

Forwarded: not-needed

Specify the actual installation path for this helper script.

This is a quick hack, this issue should be addressed
upstream in a more generic way.

Gbp-Pq: Name ctdb_etcd_lock-path.patch

4 months agouse bzero() instead of memset_s()
Debian Samba Maintainers [Fri, 15 May 2026 03:38:23 +0000 (06:38 +0300)]
use bzero() instead of memset_s()

lib/replace/replace.h header defines ZERO_STRUCT macro
which uses memset_s() function (which is similar to
memset() but can not be optimized out by the compiler).
Glibc has bzero() with similar property, while memset_s()
have is implemented in lib/replace/replace.c, - this way,
some binaries needlessly link with libreplace-samba4 just
to get rep_memset_s() symbol. By using bzero() instead,
this endless linkage is eliminated, so we can package,
for example, libldb (which uses ZERO_STRUCT) without it
linking to libreplace-samba4.

Note: actually using explicit_bzero() so it is not optimized
out by the compiler - this is the original goal of using
memset_s().

Gbp-Pq: Name use-bzero-instead-of-memset_s.diff

4 months agoctdb-config: enable syslog by default
Rafael David Tinoco [Fri, 15 May 2026 03:38:23 +0000 (06:38 +0300)]
ctdb-config: enable syslog by default

Bug-Debian: https://bugs.debian.org/929931
Bug-Ubuntu: https://bugs.launchpad.net/bugs/722201
Last-Update: 2022-03-24
Forwarded: not-needed

CTDB uses /var/log/ctdb/ directory for the default log files. With
syslog disabled, systemd journal is not able to correctly inform
errors happening during service initialization.

Upstream community creates generic config files to be used by different
distributions, so this change makes no big difference to be accepted by
upstream.

With this patch the end user will be able to identify initialization
errors by executing:

  systemctl status ctdb.service

or to follow ctdb logs by executing:

  journalctl -f -u ctdb

Signed-off-by: Rafael David Tinoco <rafaeldtinoco@ubuntu.com>
Gbp-Pq: Name ctdb-config-enable-syslog-by-default.patch

4 months agofix nfs related service names
Rafael David Tinoco [Fri, 15 May 2026 03:38:23 +0000 (06:38 +0300)]
fix nfs related service names

Upstream defines nfs related service names based on the Linux
distribution. This patch fixes the names for Debian and derivatives.

Update by Andreas Hasenack <andreas@canonical.com> (LP: #1961840):
Use nfsconf(8) if it's available, instead of parsing the old config
files in /etc/default/nfs-*

Bug-Debian: https://bugs.debian.org/929931
Bug-Ubuntu: https://bugs.launchpad.net/bugs/722201
Last-Update: 2024-07-30

Gbp-Pq: Name fix-nfs-service-name-to-nfs-kernel-server.patch

4 months agodrop "replace" dependency from libldb
Michael Tokarev [Wed, 27 Nov 2024 18:51:50 +0000 (21:51 +0300)]
drop "replace" dependency from libldb

Forwarded: not-needed

When building as a sub-library within samba, where
libreplace is a private library, libldb.so will
have rpath pointing to the private samba dir.  Since
ldb actually does not use anything from libreplace,
just remove the dependency.

Gbp-Pq: Name ldb-no-replace.diff

4 months agoAdd so version number to private libraries for dpkg-shlibdeps
Jeroen Dekkers [Fri, 15 May 2026 03:38:23 +0000 (06:38 +0300)]
Add so version number to private libraries for dpkg-shlibdeps

We also want dpkg-shlibdeps to generate correct dependency information
for the private libraries in our binary packages, but dpkg-shlibdeps
only works when the library has a version number.

Origin: vendor
Forwarded: not-needed

Gbp-Pq: Name add-so-version-to-private-libraries

4 months agoPatch in symbol table from rfc3454, for Heimdal scripts
Brian May [Fri, 15 May 2026 03:38:23 +0000 (06:38 +0300)]
Patch in symbol table from rfc3454, for Heimdal scripts

Forwarded: not-needed

Status: cherry-picked from heimdal package

Gbp-Pq: Name heimdal-rfc3454.txt

4 months agoEnable net usershares by default at build time
mathiaz@ubuntu.com [Fri, 15 May 2026 03:38:23 +0000 (06:38 +0300)]
Enable net usershares by default at build time

Enable net usershares by default at build time, with a limit of 100, and update
the corresponding documentation.

Bug-Debian: http://bugs.debian.org/443230
Bug-Ubuntu: https://bugs.launchpad.net/ubuntu/+source/samba/+bug/128548
Forwarded: not-needed

Gbp-Pq: Name usershare.patch

4 months agoUse the pager alternative as pager is PAGER is undefined
Steve Langasek [Fri, 15 May 2026 03:38:23 +0000 (06:38 +0300)]
Use the pager alternative as pager is PAGER is undefined

Bug-Debian: http://bugs.debian.org/135603
Forwarded: not-needed

Gbp-Pq: Name smbclient-pager.patch

4 months agoMention smbldap-tools package in examples/LDAP/README
Christian Perrier [Fri, 15 May 2026 03:38:23 +0000 (06:38 +0300)]
Mention smbldap-tools package in examples/LDAP/README

Bug-Debian: http://bugs.debian.org/341934
Forwarded: not-needed

Gbp-Pq: Name README_nosmbldap-tools.patch

4 months agohurd compatibility changes
Michael Tokarev [Thu, 3 Nov 2022 17:49:33 +0000 (20:49 +0300)]
hurd compatibility changes

Hurd does not define PIPE_BUF, so lib/tevent/testsuite.c fails to compile
(yes, this file is used as part of *samba* testsuite, not tevent testsuite).
Define it to a safe minimal value like 512 bytes.

Hurd does not provide SA_NOCLDWAIT define, so lib/util/tests/tfork.c does
not compile. This is only needed during testing to omit zombie process
generation, which has only cosmetic effect.  Define it to be 0.

Based on prior work and ideas by Samuel Thibault.

Gbp-Pq: Name hurd-compat.patch

4 months agoProvide public symbol tdb_logging_function removed upstream without major version...
Jelmer Vernooij [Fri, 15 May 2026 03:38:23 +0000 (06:38 +0300)]
Provide public symbol tdb_logging_function removed upstream without major version change. (bug #511011)

Status: Not forwarded upstream

Gbp-Pq: Name tdb_logging_func.diff

4 months agoforce tdb to be standalone
Michael Tokarev [Tue, 26 Nov 2024 14:28:51 +0000 (17:28 +0300)]
force tdb to be standalone

Forwarded: not-needed

Upstream ships contents of lib/tdb/ as a separate
source of tdb.  Since we build samba anyway, there's
no need to have separate tdb source package, it's
enough to build it during samba build.

Always build tdb as stand-alone library
(instead of being samba-private if in a subdir).

When building as a sub-library within samba,
where libreplace is a private library, libtdb.so
will have rpath pointing to the private samba
dir.  Since tdb actually does not use anything
from libreplace, just remove the dependency.

Gbp-Pq: Name tdb-standalone.diff

4 months agoforce tevent to be standalone
Michael Tokarev [Tue, 26 Nov 2024 14:28:51 +0000 (17:28 +0300)]
force tevent to be standalone

Forwarded: not-needed

Upstream ships contents of lib/tevent/ as a separate
source of tevent.  Since we build samba anyway, there's
no need to have separate tevent source package, it's
enough to build it during samba build.

Always build tevent as stand-alone library
(instead of being samba-private if in a subdir).

When building as a sub-library within samba, where
libreplace is a private library, libtevent.so will
have rpath pointing to the private samba dir.  Since
tevent actually does not use anything from libreplace,
just remove the dependency.

Gbp-Pq: Name tevent-standalone.diff

4 months agoforce talloc to be standalone
Michael Tokarev [Tue, 26 Nov 2024 14:28:51 +0000 (17:28 +0300)]
force talloc to be standalone

Forwarded: not-needed

Upstream ships contents of lib/talloc/ as a separate
source of talloc.  Since we build samba anyway, there's
no need to have separate talloc source package, it's
enough to build it during samba build.

Always build talloc as stand-alone library
(instead of being samba-private if in a subdir).

When building as a sub-library within samba, where
libreplace is a private library, libtalloc.so will
have rpath pointing to the private samba dir.  Since
talloc actually does not use anything from libreplace,
just remove the dependency.

Gbp-Pq: Name talloc-standalone.diff

4 months agoensure libsmbclient.h is being used with LFS enabled
Michael Tokarev [Sat, 2 Apr 2022 16:01:55 +0000 (19:01 +0300)]
ensure libsmbclient.h is being used with LFS enabled

Bug-Debian: https://bugs.debian.org/221618
Forwarded: not-needed

We build samba with LFS (Large File Support) even on 32bits.
This means some types like off_t are 64-bit wide, again,
even on a 32bit host.  libsmbclient.h uses off_t in function
prototypes, and thes prototypes muct match those which were
used at samba compile time - if some other source includes
libsmbclient.h without LFS, it'll get wrong prototypes and
the resulting binary will most likely crash when using
libsmbclient functions.

Detect and error-out this at compile time.

We can not do anything with this in the public header since
it is alredy too late to redefine things, since we can't
guarantee we're the first header a program #includes, and
at the time this libsmbclient.h is included, off_t can
already be defined so our (re)define of _FILE_OFFSET_BITS
does nothing already.

Patching libsmbclient.h to use off64_t means client program
should change their off_t to off64_t too when storing
file offsets returning from libsmbclient, so this is not
an option too.

With this change, we will error out even if the user source
does not use any off_t-related functions. Namely, it was ok
to #include <libsmbclient.h> and use smbc_open/smbc_read/
smbc_write/smbc_close without _F_O_B=64, - neither of these
functions uses off_t. smbc_lseek and others doesn't work,
but if a program does not use them anyway, whole thing will
just work even without enabling LFS.  Ideally we can probably
check each individual function which is being affected, by
replacing it with #error if sizeof(off_t) < 8.  But this
requires quite some hackery...

Gbp-Pq: Name libsmbclient-ensure-lfs-221618.patch

4 months agosamba (2:4.22.8+dfsg-0+deb13u2) trixie-security; urgency=medium
Michael Tokarev [Fri, 15 May 2026 03:38:23 +0000 (06:38 +0300)]
samba (2:4.22.8+dfsg-0+deb13u2) trixie-security; urgency=medium

  * https://bugzilla.samba.org/show_bug.cgi?id=16018
    May-2026 samba security update fixing the following issues:
    CVE-2026-1933: Missing access check on reparse point operations
      https://bugzilla.samba.org/show_bug.cgi?id=15992
    CVE-2026-2340: vfs_worm does not block directory modification
      https://bugzilla.samba.org/show_bug.cgi?id=15997
    CVE-2026-3012: group policy certificate enrollment uses http://
      without validation
      https://bugzilla.samba.org/show_bug.cgi?id=16003
    CVE-2026-3238: unauthenticated udp packet crashes AD DC nbt server
      https://bugzilla.samba.org/show_bug.cgi?id=16012
    CVE-2026-4480: Unauthenticated Remote Code Execution using print command
      https://bugzilla.samba.org/show_bug.cgi?id=16033
    CVE-2026-4408: Remote Code Execution in SAMR when check password script
      contains %u substitution placeholder
      https://bugzilla.samba.org/show_bug.cgi?id=16034

[dgit import unpatched samba 2:4.22.8+dfsg-0+deb13u2]

4 months agoImport samba_4.22.8+dfsg-0+deb13u2.debian.tar.xz
Michael Tokarev [Fri, 15 May 2026 03:38:23 +0000 (06:38 +0300)]
Import samba_4.22.8+dfsg-0+deb13u2.debian.tar.xz

[dgit import tarball samba 2:4.22.8+dfsg-0+deb13u2 samba_4.22.8+dfsg-0+deb13u2.debian.tar.xz]

5 months agoMerge version 2:4.22.6+dfsg-0+deb13u1+rpi1 and 2:4.22.8+dfsg-0+deb13u1 to produce... archive/raspbian/2%4.22.8+dfsg-0+deb13u1+rpi1 raspbian/2%4.22.8+dfsg-0+deb13u1+rpi1
Raspbian automatic forward porter [Wed, 18 Mar 2026 03:55:31 +0000 (03:55 +0000)]
Merge version 2:4.22.6+dfsg-0+deb13u1+rpi1 and 2:4.22.8+dfsg-0+deb13u1 to produce 2:4.22.8+dfsg-0+deb13u1+rpi1

6 months agoMerge samba (2:4.22.8+dfsg-0+deb13u1) import into refs/heads/workingbranch
Michael Tokarev [Thu, 19 Feb 2026 12:17:34 +0000 (15:17 +0300)]
Merge samba (2:4.22.8+dfsg-0+deb13u1) import into refs/heads/workingbranch

6 months agoImport samba_4.22.8+dfsg.orig.tar.xz
Michael Tokarev [Thu, 19 Feb 2026 12:17:34 +0000 (15:17 +0300)]
Import samba_4.22.8+dfsg.orig.tar.xz

[dgit import orig samba_4.22.8+dfsg.orig.tar.xz]

6 months agoreplace: use __xpg_strerror_r if available
Michael Tokarev [Fri, 7 Feb 2025 07:04:37 +0000 (10:04 +0300)]
replace: use __xpg_strerror_r if available

Forwarded: no

In order to avoid linking libreplace, use __xpg_strerror_r
instead of rep_strerror_r

Gbp-Pq: Name replace-xpg-strerror.patch

6 months agoctdb: use /run/ctdb instead of /var/run/ctdb
Michael Tokarev [Fri, 2 Dec 2022 08:45:01 +0000 (11:45 +0300)]
ctdb: use /run/ctdb instead of /var/run/ctdb

Forwarded: not-needed

Whole upstream path assignment needs a review.

Gbp-Pq: Name ctdb-use-run-instead-of-var-run.patch

6 months agoprint meaningful error message if python3-markdown is not installed
Michael Tokarev [Fri, 2 Dec 2022 08:08:27 +0000 (11:08 +0300)]
print meaningful error message if python3-markdown is not installed

Updated: Mon, 08 Apr 2024 14:14:38 +0300
Debian-Specific: yes
Forwarded: not-needed

Gbp-Pq: Name meaningful-error-if-no-python3-markdown.patch

6 months agoprint meaningful error message if samba-ad-provision is not installed
Michael Tokarev [Fri, 2 Dec 2022 07:54:31 +0000 (10:54 +0300)]
print meaningful error message if samba-ad-provision is not installed

Updated: Thu, 03 Aug 2023 17:06:24 +0300
Debian-Specific: yes
Forwarded: not-needed

Gbp-Pq: Name meaningful-error-if-no-samba-ad-provision.patch

6 months agomove msg.sock from /var/lib/samba to /run/samba
Michael Tokarev [Tue, 26 Apr 2022 13:11:48 +0000 (16:11 +0300)]
move msg.sock from /var/lib/samba to /run/samba

Move socket directory from /var/lib/samba to /run/samba,
exactly like msg.lock.  This directory is only used by various
samba components to communicate with each other (smbcontrol),
there's no place for it in /var/lib.

Also remove msg.sock subdir in various tests.

It'd be nice to also move ntp socket and similar somewhere to
/run/samba too, but this is a bit more difficult since it is
used in other software.

https://lists.samba.org/archive/samba-technical/2022-April/137322.html

Signed-off-by: Michael Tokarev <mjt@tls.msk.ru>
Gbp-Pq: Name move-msg.sock-from-var-lib-samba-to-run-samba.patch

6 months agodisable setuid configure checks
Michael Tokarev [Fri, 8 Apr 2022 08:50:21 +0000 (11:50 +0300)]
disable setuid configure checks

Forwarded: not-needed

For some strange reason, when running reprotest test on salsa-ci,
which apparently is running as root, - on the *second* build only
the configure fails (after successfully built package the first
time). The configure test tries to change gid and verifies it
actually changed (not that the syscall exist), - and that fails.
Since it is extremely uncommon to configure the build process as
root, salsa-ci test environment details are quite deep down the line,
and we know the syscall actually works, just disable the probe,
pretending we are not root.

For upstream, this probably should be done by removing a *lot* of
configure-time checks which are useless these days.

Gbp-Pq: Name disable-setuid-confchecks.patch

6 months agosilence uselib_local warning produced by waf
Michael Tokarev [Sun, 3 Apr 2022 04:57:38 +0000 (07:57 +0300)]
silence uselib_local warning produced by waf

During config/build process in verbose mode, waf produces
about 2k repetitions of this warning:

  compat: "uselib_local" is deprecated, replace by "use"

which clutters the build log.

Comment this warning out for now until it will be
fixed properly.

Gbp-Pq: Name silence-waf-uselib_local.diff

6 months agocreate ctdb pid directory
Michael Tokarev [Fri, 9 Sep 2022 09:49:55 +0000 (12:49 +0300)]
create ctdb pid directory

(which is /run/ctdb/). Create it in the systemd service
file (using RuntimeDirectory directive) and in the sysv-init
script.

Gbp-Pq: Name ctdb-create-piddir.patch

6 months agofix pathname for ctdb_etcd_lock
Michael Tokarev [Sat, 2 Apr 2022 14:49:38 +0000 (17:49 +0300)]
fix pathname for ctdb_etcd_lock

Forwarded: not-needed

Specify the actual installation path for this helper script.

This is a quick hack, this issue should be addressed
upstream in a more generic way.

Gbp-Pq: Name ctdb_etcd_lock-path.patch

6 months agouse bzero() instead of memset_s()
Debian Samba Maintainers [Thu, 19 Feb 2026 12:17:34 +0000 (15:17 +0300)]
use bzero() instead of memset_s()

lib/replace/replace.h header defines ZERO_STRUCT macro
which uses memset_s() function (which is similar to
memset() but can not be optimized out by the compiler).
Glibc has bzero() with similar property, while memset_s()
have is implemented in lib/replace/replace.c, - this way,
some binaries needlessly link with libreplace-samba4 just
to get rep_memset_s() symbol. By using bzero() instead,
this endless linkage is eliminated, so we can package,
for example, libldb (which uses ZERO_STRUCT) without it
linking to libreplace-samba4.

Note: actually using explicit_bzero() so it is not optimized
out by the compiler - this is the original goal of using
memset_s().

Gbp-Pq: Name use-bzero-instead-of-memset_s.diff