systemd (242-7) unstable; urgency=medium
authorMichael Biebl <biebl@debian.org>
Wed, 4 Sep 2019 17:34:17 +0000 (18:34 +0100)
committerMichael Biebl <biebl@debian.org>
Wed, 4 Sep 2019 17:34:17 +0000 (18:34 +0100)
commit5f29b41d078593e3f8b8ae8f492f53acd72fd61f
tree1127922ea780261bbc4c04df8f8bd8b78ca50204
parenta4c7c30211c7697aaf227bf7104c626186e6721d
parent015be5628121f5dedca7041cf8d4f5446aa5fb07
systemd (242-7) unstable; urgency=medium

  * sleep: properly pass verb to sleep script
  * core: factor root_directory application out of apply_working_directory.
    Fixes RootDirectory not working when used in combination with User.
    (Closes: #939408)
  * shared/bus-util: drop trusted annotation from
    bus_open_system_watch_bind_with_description().
    This ensures that access controls on systemd-resolved's D-Bus interface
    are enforced properly.
    (CVE-2019-15718, Closes: #939353)

[dgit import unpatched systemd 242-7]
171 files changed:
debian/README.Debian
debian/README.source
debian/changelog
debian/compat
debian/control
debian/copyright
debian/extra/checkout-upstream
debian/extra/dhclient-exit-hooks.d/timesyncd
debian/extra/fbdev-blacklist.conf
debian/extra/init-functions.d/40-systemd
debian/extra/initramfs-tools/hooks/udev
debian/extra/initramfs-tools/scripts/init-bottom/udev
debian/extra/initramfs-tools/scripts/init-top/udev
debian/extra/kernel-install.d/85-initrd.install
debian/extra/make-fbdev-blacklist
debian/extra/make-sysusers-basic
debian/extra/pam-configs/systemd
debian/extra/pam.d/systemd-user
debian/extra/rules-ubuntu/40-vm-hotadd.rules
debian/extra/rules-ubuntu/61-persistent-storage-android.rules
debian/extra/rules-ubuntu/71-power-switch-proliant.rules
debian/extra/rules-ubuntu/78-graphics-card.rules
debian/extra/rules/50-firmware.rules
debian/extra/rules/73-special-net-names.rules
debian/extra/rules/73-usb-net-by-mac.rules
debian/extra/rules/80-debian-compat.rules
debian/extra/set-cpufreq
debian/extra/start-udev
debian/extra/systemd-sysv-install
debian/extra/systemd.py
debian/extra/tmpfiles.d/debian.conf
debian/extra/udev.py
debian/extra/units-ubuntu/ondemand.service
debian/extra/units-ubuntu/user@.service.d/timeout.conf
debian/extra/units/getty-static.service
debian/extra/units/rc-local.service.d/debian.conf
debian/extra/units/systemd-resolved.service.d/resolvconf.conf
debian/extra/units/systemd-timesyncd.service.d/disable-with-time-daemon.conf
debian/gbp.conf
debian/git-cherry-pick
debian/libnss-myhostname.install
debian/libnss-myhostname.lintian-overrides
debian/libnss-myhostname.postinst
debian/libnss-myhostname.postrm
debian/libnss-mymachines.install
debian/libnss-mymachines.lintian-overrides
debian/libnss-mymachines.postinst
debian/libnss-mymachines.postrm
debian/libnss-resolve.install
debian/libnss-resolve.lintian-overrides
debian/libnss-resolve.postinst
debian/libnss-resolve.postrm
debian/libnss-systemd.install
debian/libnss-systemd.lintian-overrides
debian/libnss-systemd.postinst
debian/libnss-systemd.postrm
debian/libpam-systemd.install
debian/libpam-systemd.postinst
debian/libpam-systemd.prerm
debian/libsystemd-dev.install
debian/libsystemd0.install
debian/libsystemd0.symbols
debian/libudev-dev.install
debian/libudev1-udeb.install
debian/libudev1.install
debian/libudev1.symbols
debian/patches/Drop-dbus-activation-stub-service.patch
debian/patches/Drop-support-for-usr-sbin-halt.local.patch
debian/patches/Revert-core-check-start-limit-on-condition-checks-too.patch
debian/patches/ask-password-prevent-buffer-overflow-when-reading-from-ke.patch
debian/patches/bash-completion-don-t-sort-syslog-priorities.patch
debian/patches/core-factor-root_directory-application-out-of-apply_worki.patch
debian/patches/core-never-propagate-reload-failure-to-service-result.patch
debian/patches/core-unset-HOME-that-the-kernel-gives-us.patch
debian/patches/debian/Add-env-variable-for-machine-ID-path.patch
debian/patches/debian/Add-support-for-TuxOnIce-hibernation.patch
debian/patches/debian/Bring-tmpfiles.d-tmp.conf-in-line-with-Debian-defaul.patch
debian/patches/debian/Don-t-enable-audit-by-default.patch
debian/patches/debian/Drop-seccomp-system-call-filter-for-udev.patch
debian/patches/debian/Let-graphical-session-pre.target-be-manually-started.patch
debian/patches/debian/Make-run-lock-tmpfs-an-API-fs.patch
debian/patches/debian/Only-start-logind-if-dbus-is-installed.patch
debian/patches/debian/Re-enable-journal-forwarding-to-syslog.patch
debian/patches/debian/Revert-core-enable-TasksMax-for-all-services-by-default-a.patch
debian/patches/debian/Revert-core-one-step-back-again-for-nspawn-we-actual.patch
debian/patches/debian/Revert-core-set-RLIMIT_CORE-to-unlimited-by-default.patch
debian/patches/debian/Skip-filesystem-check-if-already-done-by-the-initram.patch
debian/patches/debian/Use-Debian-specific-config-files.patch
debian/patches/debian/fsckd-daemon-for-inter-fsckd-communication.patch
debian/patches/man-add-note-that-h-u-U-are-mostly-useless.patch
debian/patches/meson-make-nologin-path-build-time-configurable.patch
debian/patches/meson-stop-creating-.wants-directories-for-multi-user-get.patch
debian/patches/network-do-not-send-ipv6-token-to-kernel.patch
debian/patches/network-fix-ListenPort-in-WireGuard-section.patch
debian/patches/network-ignore-requested-ipv6-addresses-when-ipv6-is-disa.patch
debian/patches/network-ignore-requested-ipv6-route-when-ipv6-is-disabled.patch
debian/patches/network-ignore-requested-ipv6-routing-policy-rule-when-ip.patch
debian/patches/network-read-link-specific-sysctl-value.patch
debian/patches/networkd-fix-link_up-12505.patch
debian/patches/random-util-eat-up-bad-RDRAND-values-seen-on-AMD-CPUs.patch
debian/patches/series
debian/patches/shared-bus-util-drop-trusted-annotation-from-bus_open_sys.patch
debian/patches/shared-seccomp-add-sync_file_range2.patch
debian/patches/sleep-properly-pass-verb-to-sleep-script.patch
debian/patches/socket-util-make-sure-flush_accept-doesn-t-hang-on-unexpe.patch
debian/patches/test-add-test-for-flush_accept.patch
debian/patches/test-bpf-skip-test-when-run-inside-containers.patch
debian/patches/tests-skip-test-bpf-only-when-we-re-100-sure-it-s-run-in-.patch
debian/rules
debian/shlibs.local.in
debian/source/format
debian/systemd-container.install
debian/systemd-container.maintscript
debian/systemd-container.postinst
debian/systemd-container.postrm
debian/systemd-coredump.install
debian/systemd-coredump.postinst
debian/systemd-coredump.prerm
debian/systemd-journal-remote.install
debian/systemd-journal-remote.postinst
debian/systemd-sysv.install
debian/systemd-sysv.postinst
debian/systemd-tests.install
debian/systemd-tests.lintian-overrides
debian/systemd.NEWS
debian/systemd.bug-control
debian/systemd.bug-script
debian/systemd.dirs
debian/systemd.install
debian/systemd.links
debian/systemd.lintian-overrides
debian/systemd.maintscript
debian/systemd.postinst
debian/systemd.postrm
debian/systemd.prerm
debian/systemd.triggers
debian/tests/assert.sh
debian/tests/boot-and-services
debian/tests/boot-smoke
debian/tests/build-login
debian/tests/control
debian/tests/fsck
debian/tests/hostnamed
debian/tests/lidswitch.evemu
debian/tests/localed-locale
debian/tests/localed-x11-keymap
debian/tests/logind
debian/tests/process-killer
debian/tests/root-unittests
debian/tests/storage
debian/tests/systemd-fsckd
debian/tests/timedated
debian/tests/udev
debian/tests/unit-config
debian/tests/upstream
debian/udev-udeb.dirs
debian/udev-udeb.install
debian/udev.NEWS
debian/udev.README.Debian
debian/udev.bug-control
debian/udev.bug-script
debian/udev.init
debian/udev.install
debian/udev.links
debian/udev.maintscript
debian/udev.postinst
debian/udev.postrm
debian/udev.preinst
debian/udev.prerm
debian/udev.triggers
debian/watch