systemd (239-11) unstable; urgency=high
authorMichael Biebl <biebl@debian.org>
Sun, 28 Oct 2018 12:02:18 +0000 (12:02 +0000)
committerMichael Biebl <biebl@debian.org>
Sun, 28 Oct 2018 12:02:18 +0000 (12:02 +0000)
commit00d09d23b1bfd78f862ffadf72b67fcbf4e98670
treea547e7ffee92649ff0981970e0d6b13eb93a6917
parente0c00f64bd2072bf47264d8dc5f5e6054b0d068c
parent6da0e670d8716c04165a40af1a4609c996149a9d
systemd (239-11) unstable; urgency=high

  [ Michael Biebl ]
  * debian/tests/upstream: Clean up after each test run.
    Otherwise the loopback images used by qemu are not properly released and
    we might run out of disk space.
  * dhcp6: Make sure we have enough space for the DHCP6 option header.
    Fixes out-of-bounds heap write in systemd-networkd dhcpv6 option
    handling.
    (CVE-2018-15688, LP: #1795921, Closes: #912008)
  * chown-recursive: Rework the recursive logic to use O_PATH.
    Fixes a race condition in chown_one() which allows an attacker to cause
    systemd to set arbitrary permissions on arbitrary files.
    (CVE-2018-15687, LP: #1796692, Closes: #912007)

  [ Martin Pitt ]
  * debian/tests/boot-and-services: Use gdm instead of lightdm.
    This seems to work more reliably, on Ubuntu CI's i386 instances lightdm
    fails.

  [ Manuel A. Fernandez Montecelo ]
  * Run "meson test" instead of "ninja test"
    Upstream developers of meson recommend to run it in this way, because
    "ninja test" just calls "meson test", and by using meson directly and
    using extra command line arguments it is possible to control aspects of
    how the tests are run.
  * Increase timeout for test in riscv64.
    The buildds for the riscv64 arch used at the moment are slow, so increase
    the timeouts for this arch by a factor of 10, for good measure.
    (Closes: #906429)

[dgit import unpatched systemd 239-11]
175 files changed:
debian/README.Debian
debian/README.source
debian/changelog
debian/compat
debian/control
debian/copyright
debian/extra/checkout-upstream
debian/extra/dhclient-exit-hooks.d/timesyncd
debian/extra/fbdev-blacklist.conf
debian/extra/init-functions.d/40-systemd
debian/extra/initramfs-tools/hooks/udev
debian/extra/initramfs-tools/scripts/init-bottom/udev
debian/extra/initramfs-tools/scripts/init-top/udev
debian/extra/kernel-install.d/85-initrd.install
debian/extra/make-fbdev-blacklist
debian/extra/make-sysusers-basic
debian/extra/pam-configs/systemd
debian/extra/pam.d/systemd-user
debian/extra/rules-ubuntu/40-vm-hotadd.rules
debian/extra/rules-ubuntu/61-persistent-storage-android.rules
debian/extra/rules-ubuntu/71-power-switch-proliant.rules
debian/extra/rules-ubuntu/78-graphics-card.rules
debian/extra/rules/50-firmware.rules
debian/extra/rules/73-special-net-names.rules
debian/extra/rules/73-usb-net-by-mac.rules
debian/extra/rules/80-debian-compat.rules
debian/extra/set-cpufreq
debian/extra/start-udev
debian/extra/systemd-sysv-install
debian/extra/systemd.py
debian/extra/tmpfiles.d/debian.conf
debian/extra/udev.py
debian/extra/units-ubuntu/ondemand.service
debian/extra/units-ubuntu/user@.service.d/timeout.conf
debian/extra/units/getty-static.service
debian/extra/units/rc-local.service.d/debian.conf
debian/extra/units/systemd-resolved.service.d/resolvconf.conf
debian/gbp.conf
debian/git-cherry-pick
debian/libnss-myhostname.install
debian/libnss-myhostname.lintian-overrides
debian/libnss-myhostname.postinst
debian/libnss-myhostname.postrm
debian/libnss-mymachines.install
debian/libnss-mymachines.lintian-overrides
debian/libnss-mymachines.postinst
debian/libnss-mymachines.postrm
debian/libnss-resolve.install
debian/libnss-resolve.lintian-overrides
debian/libnss-resolve.postinst
debian/libnss-resolve.postrm
debian/libnss-systemd.install
debian/libnss-systemd.lintian-overrides
debian/libnss-systemd.postinst
debian/libnss-systemd.postrm
debian/libpam-systemd.install
debian/libpam-systemd.postinst
debian/libpam-systemd.prerm
debian/libsystemd-dev.install
debian/libsystemd0.install
debian/libsystemd0.symbols
debian/libudev-dev.install
debian/libudev-dev.maintscript
debian/libudev1-udeb.install
debian/libudev1.install
debian/libudev1.symbols
debian/patches/Do-not-apply-uaccess-tag-for-dev-kvm-if-mode-is-0666.patch
debian/patches/Re-add-uaccess-tag-for-dev-kvm.patch
debian/patches/basic-add-missing-comma-in-raw_clone-assembly-for-sparc.patch
debian/patches/bus-util-make-log-level-lower-in-request_name_destroy_cal.patch
debian/patches/chown-recursive-TAKE_FD-is-your-friend.patch
debian/patches/chown-recursive-also-drop-ACLs-when-recursively-chown-ing.patch
debian/patches/chown-recursive-let-s-rework-the-recursive-logic-to-use-O.patch
debian/patches/core-fix-gid-when-DynamicUser-yes-with-static-User.patch
debian/patches/debian/Add-env-variable-for-machine-ID-path.patch
debian/patches/debian/Add-support-for-TuxOnIce-hibernation.patch
debian/patches/debian/Bring-tmpfiles.d-tmp.conf-in-line-with-Debian-defaul.patch
debian/patches/debian/Don-t-enable-audit-by-default.patch
debian/patches/debian/Drop-seccomp-system-call-filter-for-udev.patch
debian/patches/debian/Let-graphical-session-pre.target-be-manually-started.patch
debian/patches/debian/Make-run-lock-tmpfs-an-API-fs.patch
debian/patches/debian/Only-start-logind-if-dbus-is-installed.patch
debian/patches/debian/Re-enable-journal-forwarding-to-syslog.patch
debian/patches/debian/Revert-core-enable-TasksMax-for-all-services-by-default-a.patch
debian/patches/debian/Revert-core-one-step-back-again-for-nspawn-we-actual.patch
debian/patches/debian/Revert-core-set-RLIMIT_CORE-to-unlimited-by-default.patch
debian/patches/debian/Revert-systemctl-when-removing-enablement-or-mask-symlink.patch
debian/patches/debian/Revert-udev-network-device-renaming-immediately-give.patch
debian/patches/debian/Revert-udev-rules-Permission-changes-for-dev-dri-renderD.patch
debian/patches/debian/Skip-filesystem-check-if-already-done-by-the-initram.patch
debian/patches/debian/Use-Debian-specific-config-files.patch
debian/patches/debian/cgroup-don-t-trim-cgroup-trees-created-by-someone-el.patch
debian/patches/debian/fsckd-daemon-for-inter-fsckd-communication.patch
debian/patches/dhcp6-make-sure-we-have-enough-space-for-the-DHCP6-option.patch
debian/patches/meson-rename-Ddebug-to-Ddebug-extra.patch
debian/patches/network-link-Fix-logic-error-in-matching-devices-by-MAC.patch
debian/patches/series
debian/patches/sleep-fix-one-more-printf-format-of-a-fiemap-field.patch
debian/patches/sleep-fix-printf-format-of-fiemap-fields.patch
debian/patches/sysusers-tmpfiles-re-create-systemd-network-systemd-resol.patch
debian/patches/test-Drop-SKIP_INITRD-for-QEMU-based-tests.patch
debian/patches/test-fix-networkd-test.py-rate-limiting-and-dynamic-user.patch
debian/patches/test-introduce-test_is_running_from_builddir.patch
debian/patches/test-make-test-catalog-relocatable.patch
debian/patches/test-remove-support-for-suffix-in-get_testdata_dir.patch
debian/patches/test-use-builddir-systemd-runtest.env-for-SYSTEMD_CATALOG.patch
debian/patches/test-use-builddir-systemd-runtest.env-to-set-SYSTEMD_TEST.patch
debian/patches/timedate-defer-the-property-changed-signal-until-job-of-s.patch
debian/patches/timedate-increment-reference-count-of-sd_bus_message.patch
debian/patches/timesync-changes-type-of-drift_freq-to-int64_t.patch
debian/patches/tmpfiles-specify-access-mode-for-run-systemd-netif.patch
debian/patches/user-runtime-dir-fix-selinux-regression.patch
debian/rules
debian/shlibs.local.in
debian/source/format
debian/systemd-container.install
debian/systemd-container.maintscript
debian/systemd-container.postinst
debian/systemd-container.postrm
debian/systemd-coredump.install
debian/systemd-coredump.postinst
debian/systemd-coredump.prerm
debian/systemd-journal-remote.install
debian/systemd-journal-remote.postinst
debian/systemd-sysv.install
debian/systemd-sysv.postinst
debian/systemd-tests.install
debian/systemd-tests.lintian-overrides
debian/systemd.NEWS
debian/systemd.bug-control
debian/systemd.bug-script
debian/systemd.dirs
debian/systemd.install
debian/systemd.links
debian/systemd.lintian-overrides
debian/systemd.maintscript
debian/systemd.postinst
debian/systemd.postrm
debian/systemd.prerm
debian/systemd.triggers
debian/tests/assert.sh
debian/tests/boot-and-services
debian/tests/boot-smoke
debian/tests/build-login
debian/tests/control
debian/tests/fsck
debian/tests/hostnamed
debian/tests/lidswitch.evemu
debian/tests/localed-locale
debian/tests/localed-x11-keymap
debian/tests/logind
debian/tests/process-killer
debian/tests/root-unittests
debian/tests/storage
debian/tests/systemd-fsckd
debian/tests/timedated
debian/tests/udev
debian/tests/unit-config
debian/tests/upstream
debian/udev-udeb.dirs
debian/udev-udeb.install
debian/udev.NEWS
debian/udev.README.Debian
debian/udev.bug-control
debian/udev.bug-script
debian/udev.init
debian/udev.install
debian/udev.links
debian/udev.maintscript
debian/udev.postinst
debian/udev.postrm
debian/udev.preinst
debian/udev.prerm
debian/udev.triggers
debian/watch