summary |
shortlog | log |
commit |
commitdiff |
tree
first ⋅ prev ⋅ next
Otto Kekäläinen [Wed, 8 Apr 2026 15:32:51 +0000 (23:32 +0800)]
Add AppArmor notice for Debian/Ubuntu users during server startup
When MariaDB fails to start due to permission errors, users on
Debian/Ubuntu might not be able to guess that AppArmor might be the
cause, and they should check for AppArmor denials in the kernel audit
log.
Add an informational message during startup that:
- Only prints when the 'mariadbd' profile is actually loaded
- Includes exact commands from the Debian packaging NEWS
- Provides actionable paths for local overrides
- Mentions both complain and enforce modes for troubleshooting
The message is printed once during normal server startup (not in help or
bootstrap modes) through the existing logging infrastructure, ensuring
it appears in both syslog and the error log where users will see it when
troubleshooting startup failures.
Forwarded: https://github.com/MariaDB/server/pull/5003
Gbp-Pq: Name Add-AppArmor-notice-for-Debian-Ubuntu-users-during-server.patch
Lena Voytek [Tue, 28 Apr 2026 14:39:51 +0000 (22:39 +0800)]
Update default datadir config to /var/lib/mariadb.
Last-Update: 2026-03-24
Use /var/lib/mariadb as the default datadir for Debian/Ubuntu to improve
co-installability between MySQL and MariaDB servers.
Last-Update: 2026-03-24
Forwarded: https://github.com/MariaDB/server/pull/5059
Gbp-Pq: Name set-default-datadir-to-var-lib-mariadb.patch
Aquila Macedo [Fri, 9 Jan 2026 00:34:26 +0000 (21:34 -0300)]
sysusers.d: lock mysql user and keep Debian home/shell
Use u! and set HOME=/nonexistent and shell=/bin/false for the mysql
user.
This patch should be submitted upstream once proven stable in Debian.
Forwarded: https://github.com/MariaDB/server/pull/5012
Gbp-Pq: Name sysusers-lock-mysql-account.patch
Otto Kekäläinen [Thu, 27 Nov 2025 00:49:24 +0000 (16:49 -0800)]
Make the new merge_alter test indifferent to extra version info
Modify the test regex to accept any extra version info, just like it
accepts any server version info. The test is supposed to fail on actual
differences in behaviour and server info strings are intentionally
normalized and not regarded.
Without this modification, the test introduced in
9e8e215e would fail
in post-build MTR on "from Debian-log" and in autopkgtest on "from Debian":
main.merge_alter w4 [ fail ]
Test ended at 2025-11-26 22:41:38
CURRENT_TEST: main.merge_alter
/usr/share/mariadb/mariadb-test/main/merge_alter.result 2025-11-13 11:45:29.
000000000 +0300
/tmp/tmp.3vGjZWHA79/var/4/log/merge_alter.reject 2025-11-27 01:41:38.
523996124 +0300
@@ -10,7 +10,7 @@
/*!50003 SET @OLD_COMPLETION_TYPE=@@COMPLETION_TYPE,COMPLETION_TYPE=0*/;
DELIMITER /*!*/;
# at #
-#010909 4:46:40 server id # end_log_pos # CRC32 XXX Start: binlog v 4, server v #.##.## created 010909 4:46:40 at startup
+#010909 4:46:40 server id # end_log_pos # CRC32 XXX Start: binlog v 4, server v #.##.## from Debian created 010909 4:46:40 at startup
ROLLBACK/*!*/;
# at #
#010909 4:46:40 server id # end_log_pos # CRC32 XXX Gtid list []
Result length mismatch
Forwarded: not-needed
Gbp-Pq: Name include-debian-in-test-merge-alter-result.patch
Otto Kekäläinen [Fri, 8 Aug 2025 04:30:51 +0000 (21:30 -0700)]
Suppress native AIO warning introduced in 10.8.3
Upstream
a87bb96 introduced a new warning, visible at least on all ppc64el and
s390x builds which makes the post-build mariadb-test-test fail:
[Warning] InnoDB: native AIO failed: falling back to
innodb_use_native_aio=OFF
The case of this is the ci environment only where there is insufficent
fs.aio-max-nr configured. A such we are adding a suppression to the
mtr only. The warning is valuable for users. Upstream MDEV-37411 has
added a io_setup as a warning, which will fail in the CI environment,
so we're pre-emptively suppressing this warning too.
Unlike upstream MariaDB, in Debian we removed libaio in for Linux on
MariaDB 10.6+ in
612630c6 and completely in
1d648d6f. This was re-added
by upstream added a system variable innodb_linux_aio to control, and
also provided automated fallback. As such we're readding it back too.
With liburing still seccomp filterer in container environments having
a libaio fallback is more valuable than the threads implementation of
last resort.
Edited & Updated: Daniel Black <daniel@mariabdb.org>
Upstream rejected this with the conclusion, is that it will start working in
Debian/Salsa/Ubuntu/Launchpad once the Linux kernel is new enough to handle the
I/O calls and fallbacks properly, or once the CI system increases the value of
/proc/sys/fs/aio-max-nr to 1 million or so, to allow multiple parallel MariaDB
servers (as started by mariadb-test-run) each have enough quota for native AIO
to work.
Forwarded: https://jira.mariadb.org/browse/MDEV-37411 (rejected)
Gbp-Pq: Name MDEV-37411-suppress-new-warning-about-native-aio.patch
Otto Kekäläinen [Wed, 4 Jun 2025 11:46:31 +0000 (14:46 +0300)]
Improve output from mariadb-secure-installation to be more honest
The script is not useful in Debian, and likely misleading to users.
Improve the output to be more clear about what it is doing or is not
doing.
Merged on 'main' in
https://github.com/MariaDB/server/commit/
3a08a8e3d2212f3f60937b3fd97207c3ea7b933a
and thus included in MariaDB 12.3 onward.
Forwarded: https://github.com/MariaDB/server/pull/4457
Gbp-Pq: Name Improve-output-from-mariadb-secure-installation-to-be-mor.patch
Otto Kekalainen [Sun, 10 Mar 2024 16:56:13 +0000 (16:56 +0000)]
Fix misc spelling in MariaDB Server repository
Note! Do not update this patch with new typos, but put them in a new
patch that can be submitted upstream and tracked separately.
* Fix misc typos in MariaDB Server
* Fix spelling of 'allows one to'
Fix the following Lintian nags introduced in commit
c8d040938a7ebe10e62506a726702c5990ef4dda:
X: libmariadbd19t64: spelling-error-in-binary choosen chosen [usr/lib/x86_64-linux-gnu/libmariadbd.so.19]
X: mariadb-backup: spelling-error-in-binary "allows to" "allows one to" [usr/bin/mariadb-backup]
X: mariadb-backup: spelling-error-in-binary choosen chosen [usr/bin/mariadb-backup]
X: mariadb-server-core: spelling-error-in-binary "allows to" "allows one to" [usr/sbin/mariadbd]
X: mariadb-server-core: spelling-error-in-binary choosen chosen [usr/sbin/mariadbd]
X: mariadb-test: spelling-error-in-binary "allows to" "allows one to" [usr/bin/mariadb-client-test-embedded]
X: mariadb-test: spelling-error-in-binary "allows to" "allows one to" [usr/bin/mariadb-test-embedded]
X: mariadb-test: spelling-error-in-binary "allows to" "allows one to" [usr/bin/test-connect-t]
X: mariadb-test: spelling-error-in-binary choosen chosen [usr/bin/mariadb-client-test-embedded]
X: mariadb-test: spelling-error-in-binary choosen chosen [usr/bin/mariadb-test-embedded]
X: mariadb-test: spelling-error-in-binary choosen chosen [usr/bin/test-connect-t]
Merged in https://github.com/MariaDB/server/commit/
5879c85f505d3a11d4b8f479f2437416d8a1d724
and thus included in MariaDB 12.3 onward.
Forwarded: https://github.com/MariaDB/server/pull/4458
Gbp-Pq: Name Fix-misc-spelling-in-MariaDB-Server-repository.patch
Otto Kekalainen [Sun, 30 Jun 2024 15:18:06 +0000 (15:18 +0000)]
Disable the 'mysql*' command deprecation warning
Many command-line tools expect the commands they run to return without
any output in stderr or having error codes. The fact that now in MariaDB
11.4 all 'mysql*' commands emit a deprecation warning causes a lot of
scripts to fail, such as the /etc/init.d/mariadb itself and many dependent
programs as witnessed via Debian autopkgtests. See examples below.
https://ci.debian.net/packages/m/mariadb-connector-odbc/testing/amd64/
48373500/
https://ci.debian.net/packages/p/pam-mysql/testing/amd64/
48373511/
https://ci.debian.net/packages/r/roundcube/testing/amd64/
48373518/
Forwarded: not-needed
Gbp-Pq: Name hide-mysql-command-deprecation-warnings.patch
Otto Kekalainen [Sun, 10 Mar 2024 16:56:13 +0000 (16:56 +0000)]
Show banner in server and client startup to drive community engagement
Suggest to users that they can support MariaDB development by simply giving a
star on GitHub. This patch experiments with how well such a banner works, and
may later change the contents to drive some other kind of engagement.
Client output:
Welcome to the MariaDB monitor. Commands end with ; or \g.
Your MariaDB connection id is 17
Server version: 11.8.1-MariaDB-5 from Debian -- Please help get to 10k stars at https://github.com/MariaDB/Server
Copyright (c) 2000, 2018, Oracle, MariaDB Corporation Ab and others.
Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.
MariaDB [(none)]>
Server output:
[Note] Please help get to 10k stars at https://github.com/MariaDB/Server
Server output if built in git directory:
[Note] Starting MariaDB 11.8.1-MariaDB-5 from Debian source revision
1a9c3debfd6b1b16af4e501d3530b866b85c38a8 server_uid eNAjF8/wvUNM09/mSmh+k3a5o5w= as process 1359
Logs will also show as server output:
mysqld: Version: '11.8.1-MariaDB-5 from Debian' socket: '/run/mysqld/mysqld.sock' port: 3306 -- Please help get to 10k stars at https://github.com/MariaDB/Server
This patch can be dropped if Debian updates to ship
Something similar was merged in https://github.com/MariaDB/server/commit/
346c7afe9b7071ce9c47892a83d69944b608b3da
and thus included in MariaDB 12.3 onward.
Forwarded: not-needed
Gbp-Pq: Name startup-message.patch
Michael Biebl [Mon, 22 Jan 2024 21:52:25 +0000 (22:52 +0100)]
Install PAM modules and systemd units into /usr
Since Debian trixie all files need to be installed into their canonical
location under /usr.
Merged in https://github.com/MariaDB/server/commit/
34aac090f2acc1a4b5850810fe41370c19659d55
and thus included in MariaDB 12.3.2 and onward.
Origin: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=
1061348
Forwarded: https://github.com/MariaDB/server/pull/4065
Gbp-Pq: Name install-files-into-usr.patch
Sutou Kouhei [Sat, 5 Feb 2022 02:05:39 +0000 (11:05 +0900)]
cmake: add support for reproducible buildS
We should use relative path not absolute path. We can use target without
breaking reproducibility.
This patch can be removed once MariaDB ships with Mroonga v12.00+ that has
https://github.com/mroonga/mroonga/commit/
27caeb9b8ce7fa432b1251eca475b517c6902a6c
Origin: https://github.com/mroonga/mroonga/issues/298#issuecomment-
1030815927
Bug: https://github.com/mroonga/mroonga/issues/298
Forwarded: not-needed
Gbp-Pq: Name mroonga-mrn-lib-dirs-path-reproducible-build.patch
Otto Kekalainen [Sun, 20 Dec 2020 18:58:42 +0000 (20:58 +0200)]
Fix perl path in scripts
Fix Lintian issue https://lintian.debian.org/tags/incorrect-path-for-interpreter.html
Upstream will never accept this patch,
see https://github.com/MariaDB/server/pull/1718
Origin: https://patch-diff.githubusercontent.com/raw/MariaDB/server/pull/1718.patch
Forwarded: https://github.com/MariaDB/server/pull/1718 (rejected, will never be merged)
Gbp-Pq: Name env-perl-usr-bin-perl.patch
Otto Kekäläinen [Tue, 2 Jun 2026 00:02:02 +0000 (00:02 +0000)]
mariadb (1:11.8.8-1) unstable; urgency=medium
[ Otto Kekäläinen ]
* New upstream version 11.8.8 with critical fix for regression in 11.8.7 as
noted at https://mariadb.com/docs/release-notes/community-server/11.8/11.8.8
and for the following security issues:
- CVE-2026-48165
- CVE-2026-48163
* Previous upstream version 11.8.7 included fixes for several defects as noted
at https://mariadb.com/docs/release-notes/community-server/11.8/11.8.7 as
well the following security issues:
- CVE-2026-44173
- CVE-2026-44172
- CVE-2026-44171
- CVE-2026-44170
- CVE-2026-44169
- CVE-2026-44168
* Also cherry-pick the following upstream debian/ changes:
- MDEV-38587 slow_query_log missing from debian conf
- MDEV-39031 remove Docs/README-wsrep
- MDEV-34902 debian-start erroneously reports issues
- MDEV-32745 Add a simple MySQL to MariaDB upgrade helper (Debian part)
* Update configuration traces to match changes in system variables
- new variable 'innodb-buffer-pool-in-core-dump' (default: FALSE)
- new default value 0->
8796093022208 in 'innodb-buffer-pool-size-max'
* New upstream version included fixes for these Debian tracked issues:
- MDEV-38698 Upgrade did not fix charset and collation for mysql.user,
leading to "Illegal mix of collations" errors on upgrades or when trying
to restore backups (Closes: #
1104533, #
1126850, #
1137221)
- MDEV-39479 Mroonga hangs on invalid index flag (Closes: #
1110683)
* Drop patches included upstream and refresh metadata for easier tracking
* Use upstream patch from MariaDB 13.0 to use the invoking Unix user's login
name instead of 'root' when running mytop (Closes: #
1109404)
* Re-add patch to fix build failures on x32
* Add patch to update TLS test regexes for OpenSSL 4.0
* Add upstream patch to fix "invalid iv length" with OpenSSL 4.0
(Closes: #
1138309, LP: #
2154856)
* Remove override for deprecated Lintian tag 'exit-in-shared-library'
* Salsa CI: Disable new uscan test that is not suitable for MariaDB
* Include new upstream test file pam_mariadb_mtr.so
* Clean away obsolete Lintian overrides
* Extend spelling patch to fix new typos introduced in 11.8.7/8
* Bump Debian Policy version to 4.7.4
[ Luca Boccassi ]
* Use dh-sequence-installsysusers instead of manual dependency
* d/mariadb-server.postinst: sd-sysusers is idempotent
[dgit import unpatched mariadb 1:11.8.8-1]
Otto Kekäläinen [Tue, 2 Jun 2026 00:02:02 +0000 (00:02 +0000)]
Import mariadb_11.8.8.orig.tar.gz
[dgit import orig mariadb_11.8.8.orig.tar.gz]
Otto Kekäläinen [Tue, 2 Jun 2026 00:02:02 +0000 (00:02 +0000)]
Import mariadb_11.8.8-1.debian.tar.xz
[dgit import tarball mariadb 1:11.8.8-1 mariadb_11.8.8-1.debian.tar.xz]