diff --git a/.fmf/version b/.fmf/version new file mode 100644 index 0000000..d00491f --- /dev/null +++ b/.fmf/version @@ -0,0 +1 @@ +1 diff --git a/.gitignore b/.gitignore index 0f69f79..47652a9 100644 --- a/.gitignore +++ b/.gitignore @@ -1,253 +1,4 @@ -samba-3.5.4.tar.gz -samba-3.6.0pre1.tar.gz -/samba-3.6.0pre2.tar.gz -/samba-3.6.0pre3.tar.gz -/samba-3.6.0rc1.tar.gz -/samba-3.6.0rc2.tar.gz -/samba-3.6.0rc3.tar.gz -/samba-3.6.0.tar.gz -/samba-3.6.1.tar.gz -/samba-3.6.3.tar.gz -/samba-3.6.4.tar.gz -/samba-3.6.5.tar.gz -/samba-3.6.6.tar.gz -/samba-3.6.7.tar.gz -/samba-4.0.0rc1.tar.bz2 -/samba-4.0.0rc2.tar.bz2 -/samba-4.0.0rc3.tar.bz2 -/samba-4.0.0rc4.tar.bz2 -/samba-4.0.0rc5.tar.bz2 -/samba-4.0.0rc6.tar.bz2 -/samba-4.0.0.tar.bz2 -/samba-4.0.1.tar.bz2 -/samba-4.0.2.tar.bz2 -/samba-4.0.3.tar.bz2 -/samba-4.0.4.tar.bz2 -/samba-4.0.5.tar.bz2 -/samba-4.0.6.tar.bz2 -/samba-4.0.7.tar.xz -/samba-4.1.0rc1.tar.xz -/samba-4.1.0rc2.tar.xz -/samba-4.1.0rc3.tar.xz -/samba-4.1.0rc4.tar.xz -/samba-4.1.0.tar.xz -/samba-4.1.1.tar.xz -/samba-4.1.2.tar.xz -/samba-4.1.3.tar.xz -/samba-4.1.4.tar.xz -/samba-4.1.5.tar.xz -/samba-4.1.6.tar.xz -/samba-4.1.8.tar.xz -/samba-4.1.9.tar.xz -/samba-4.1.11.tar.gz -/samba-4.1.11.tar.xz -/samba-4.1.12.tar.xz -/samba-4.2.0rc2.tar.xz -/samba-4.2.0rc3.tar.xz -/samba-4.2.0rc4.tar.xz -/samba-4.2.0rc5.tar.xz -/samba-4.2.0.tar.xz -/samba-4.2.1.tar.xz -/samba-4.2.2.tar.xz -/samba-4.2.3.tar.xz -/samba-4.3.0rc3.tar.xz -/samba-4.3.0rc4.tar.xz -/samba-4.3.0.tar.xz -/samba-4.3.1.tar.xz -/samba-4.3.2.tar.xz -/samba-4.3.3.tar.xz -/samba-4.3.4.tar.xz -/samba-4.4.0rc1.tar.xz -/samba-4.4.0rc2.tar.xz -/samba-4.4.0rc3.tar.xz -/samba-4.4.0rc4.tar.xz -/samba-4.4.0rc5.tar.xz -/samba-4.4.0.tar.xz -/samba-4.4.2.tar.xz -/samba-4.4.3.tar.xz -/samba-4.4.4.tar.xz -/samba-4.4.5.tar.xz -/samba-4.5.0rc1.tar.xz -/samba-4.5.0rc2.tar.xz -/samba-4.5.0rc3.tar.xz -/samba-4.5.0.tar.xz -/samba-4.5.1.tar.xz -/samba-4.5.2.tar.xz -/samba-4.5.3.tar.xz -/samba-4.6.0rc1.tar.xz -/samba-4.6.0rc2.tar.xz -/samba-4.6.0rc2.tar.asc -/samba-4.6.0rc3.tar.asc -/samba-4.6.0rc3.tar.xz -/samba-4.6.0rc4.tar.xz -/samba-4.6.0rc4.tar.asc -/samba-4.6.0.tar.asc -/samba-4.6.0.tar.xz -/samba-4.6.1.tar.xz -/samba-4.6.1.tar.asc -/samba-4.6.2.tar.xz -/samba-4.6.2.tar.asc -/samba-4.6.3.tar.xz -/samba-4.6.3.tar.asc -/samba-4.6.4.tar.xz -/samba-4.6.4.tar.asc -/samba-4.6.5.tar.xz -/samba-4.6.5.tar.asc -/samba-4.7.0rc1.tar.xz -/samba-4.7.0rc1.tar.asc -/samba-4.7.0rc3.tar.xz -/samba-4.7.0rc3.tar.asc -/samba-4.7.0rc5.tar.xz -/samba-4.7.0rc5.tar.asc -/samba-4.7.0rc6.tar.xz -/samba-4.7.0rc6.tar.asc -/samba-4.7.0.tar.xz -/samba-4.7.0.tar.asc -/samba-4.7.1.tar.xz -/samba-4.7.1.tar.asc -/samba-4.7.2.tar.xz -/samba-4.7.2.tar.asc -/samba-4.7.3.tar.xz -/samba-4.7.3.tar.asc -/samba-4.7.4.tar.xz -/samba-4.7.4.tar.asc -/samba-4.8.0rc1.tar.xz -/samba-4.8.0rc1.tar.asc -/samba-4.8.0rc2.tar.xz -/samba-4.8.0rc2.tar.asc -/samba-4.8.0rc3.tar.xz -/samba-4.8.0rc3.tar.asc -/samba-4.8.0rc4.tar.xz -/samba-4.8.0rc4.tar.asc -/samba-4.8.0.tar.xz -/samba-4.8.0.tar.asc -/samba-4.8.1.tar.xz -/samba-4.8.1.tar.asc -/samba-4.8.2.tar.xz -/samba-4.8.2.tar.asc -/samba-4.8.3.tar.asc -/samba-4.8.3.tar.xz -/samba-4.9.0rc1.tar.xz -/samba-4.9.0rc1.tar.asc -/samba-4.9.0rc2.tar.xz -/samba-4.9.0rc2.tar.asc -/samba-4.9.0rc3.tar.xz -/samba-4.9.0rc3.tar.asc -/samba-4.9.0rc4.tar.xz -/samba-4.9.0rc4.tar.asc -/samba-4.9.0rc5.tar.asc -/samba-4.9.0rc5.tar.xz -/samba-4.9.0.tar.xz -/samba-4.9.0.tar.asc -/samba-4.9.1.tar.asc -/samba-4.9.1.tar.xz -/samba-4.9.2.tar.xz -/samba-4.9.2.tar.asc -/samba-4.9.3.tar.xz -/samba-4.9.3.tar.asc -/samba-4.9.4.tar.xz -/samba-4.9.4.tar.asc -/samba-4.10.0rc1.tar.xz -/samba-4.10.0rc1.tar.asc -/samba-4.10.0rc2.tar.xz -/samba-4.10.0rc2.tar.asc -/samba-4.10.0rc3.tar.xz -/samba-4.10.0rc3.tar.asc -/samba-4.10.0rc4.tar.xz -/samba-4.10.0rc4.tar.asc -/samba-4.10.0.tar.xz -/samba-4.10.0.tar.asc -/samba-4.10.1.tar.xz -/samba-4.10.1.tar.asc -/samba-4.10.2.tar.xz -/samba-4.10.2.tar.asc -/samba-4.10.3.tar.xz -/samba-4.10.3.tar.asc -/samba-4.10.4.tar.xz -/samba-4.10.4.tar.asc -/samba-4.10.5.tar.xz -/samba-4.10.5.tar.asc -/samba-4.10.6.tar.xz -/samba-4.10.6.tar.asc -/samba-4.11.0rc1.tar.xz -/samba-4.11.0rc1.tar.asc -/samba-4.11.0rc2.tar.xz -/samba-4.11.0rc2.tar.asc -/samba-4.11.0rc3.tar.xz -/samba-4.11.0rc3.tar.asc -/samba-4.11.0rc4.tar.xz -/samba-4.11.0rc4.tar.asc -/samba-4.11.0.tar.xz -/samba-4.11.0.tar.asc -/samba-4.11.1.tar.xz -/samba-4.11.1.tar.asc -/samba-4.11.2.tar.xz -/samba-4.11.2.tar.asc -/samba-4.11.3.tar.xz -/samba-4.11.3.tar.asc -/samba-4.11.4.tar.xz -/samba-4.11.4.tar.asc -/samba-4.11.5.tar.xz -/samba-4.11.5.tar.asc -/samba-4.12.0rc1.tar.xz -/samba-4.12.0rc1.tar.asc -/samba-4.12.0rc2.tar.xz -/samba-4.12.0rc2.tar.asc -/samba-4.12.0rc3.tar.xz -/samba-4.12.0rc3.tar.asc -/samba-4.12.0rc4.tar.xz -/samba-4.12.0rc4.tar.asc -/samba-4.12.0.tar.xz -/samba-4.12.0.tar.asc -/samba-4.12.1.tar.xz -/samba-4.12.1.tar.asc -/samba-4.12.2.tar.xz -/samba-4.12.2.tar.asc -/samba-4.12.3.tar.xz -/samba-4.12.3.tar.asc -/samba-4.12.4.tar.xz -/samba-4.12.4.tar.asc -/samba-4.12.5.tar.xz -/samba-4.12.5.tar.asc -/samba-4.13.0rc1.tar.xz -/samba-4.13.0rc1.tar.asc -/samba-4.13.0rc2.tar.xz -/samba-4.13.0rc2.tar.asc -/samba-4.13.0rc3.tar.xz -/samba-4.13.0rc3.tar.asc -/samba-4.13.0rc4.tar.xz -/samba-4.13.0rc4.tar.asc -/samba-4.13.0rc5.tar.xz -/samba-4.13.0rc5.tar.asc -/samba-4.13.0rc6.tar.xz -/samba-4.13.0rc6.tar.asc -/samba-4.13.0.tar.xz -/samba-4.13.0.tar.asc -/samba-4.13.1.tar.xz -/samba-4.13.1.tar.asc -/samba-4.13.2.tar.xz -/samba-4.13.2.tar.asc -/samba-4.13.3.tar.xz -/samba-4.13.3.tar.asc -/samba-4.13.4.tar.xz -/samba-4.13.4.tar.asc -/samba-4.13.5.tar.xz -/samba-4.13.5.tar.asc -/samba-4.13.6.tar.xz -/samba-4.13.6.tar.asc -/samba-4.13.7.tar.xz -/samba-4.13.7.tar.asc -/samba-4.13.8.tar.xz -/samba-4.13.8.tar.asc -/samba-4.13.9.tar.xz -/samba-4.13.9.tar.asc -/samba-4.13.10.tar.xz -/samba-4.13.10.tar.asc -/samba-4.13.11.tar.xz -/samba-4.13.11.tar.asc -/samba-4.13.12.tar.xz -/samba-4.13.12.tar.asc -/samba-4.13.13.tar.xz -/samba-4.13.13.tar.asc -/samba-4.13.14.tar.xz -/samba-4.13.14.tar.asc +/samba-*.tar.xz +/samba-*.tar.asc +/*.rpm +/results_samba diff --git a/changelog b/changelog new file mode 100644 index 0000000..680c54c --- /dev/null +++ b/changelog @@ -0,0 +1,3039 @@ +* Wed May 08 2024 Guenther Deschner - 4.20.1-1 +- resolves: #2279780 - Update to version 4.20.1 + +* Wed Mar 27 2024 Guenther Deschner - 4.20.0-7 +- resolves: #2271916 - Update to version 4.20.0 + +* Tue Mar 12 2024 Richard W.M. Jones - 2:4.20.0-0.6.rc4 +- Bump and rebuild package (for riscv64) + +* Mon Mar 11 2024 Guenther Deschner - 4.20.0rc4-5 +- resolves: #2269037 - Update to version 4.20.0rc4 + +* Mon Feb 26 2024 Guenther Deschner - 4.20.0rc3-4 +- resolves: #2266039 - Update to version 4.20.0rc3 + +* Mon Feb 12 2024 Guenther Deschner - 4.20.0rc2-3 +- resolves: #2263874 - Update to version 4.20.0rc2 + +* Thu Feb 01 2024 Pete Walter - 2:4.20.0-0.2.rc1 +- Rebuild for ICU 74 + +* Mon Jan 29 2024 Guenther Deschner - 4.20.0rc1-1 +- resolves: #2260895 - Update to version 4.20.0rc1 + +* Sat Jan 27 2024 Fedora Release Engineering - 2:4.19.4-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Tue Jan 16 2024 Andreas Schneider - 4.29.4-3 +- Fix samba-gpupdate on Fedora/RHEL + +* Tue Jan 09 2024 Andreas Schneider - 4.19.4-2 +- resolves: rhbz#2256326 - Create all groups using systemd + +* Mon Jan 08 2024 Guenther Deschner - 4.19.4-1 +- resolves: #2257287 - Update to version 4.19.4 + +* Tue Nov 28 2023 Guenther Deschner - 4.19.3-2 +- Disable performance co-pilot support for i686 + +* Mon Nov 27 2023 Guenther Deschner - 4.19.3-1 +- resolves: #2251766 - Update to version 4.19.3 + +* Wed Nov 15 2023 Andreas Schneider - 4.19.2-2 +- Package samba-gpupdate also for RHEL9 + +* Mon Oct 16 2023 Guenther Deschner - 4.19.2-1 +- resolves: #2244496 - Update to version 4.19.2 + +* Tue Oct 10 2023 Guenther Deschner - 4.19.1-1 +- resolves: #2243073 - Update to version 4.19.1 +- resolves: #2241881, #2243228: Security fix for CVE-2023-3961 +- resolves: #2241882, #2243231: Security fix for CVE-2023-4091 +- resolves: #2241883, #2243230: Security fix for CVE-2023-4154 +- resolves: #2241884, #2243229: Security fix for CVE-2023-42669 +- resolves: #2241885, #2243232: Security fix for CVE-2023-42670 + +* Mon Sep 04 2023 Guenther Deschner - 4.19.0-1 +- resolves: #2237259 - Update to version 4.19.0 + +* Mon Aug 28 2023 Guenther Deschner - 4.19.0-0.5.rc4 +- resolves: #2232744 - Update to version 4.19.0rc4 + +* Fri Aug 18 2023 Guenther Deschner - 4.19.0-0.4.rc3 +- resolves: #2232744 - Update to version 4.19.0rc3 + +* Wed Aug 16 2023 Yaakov Selkowitz - 2:4.19.0-0.3.rc2 +- Move ad-claims and authn-policy-util to dc-libs + +* Tue Aug 15 2023 Adam Williamson - 4.19.0-0.2.rc2 +- python3-samba-dc requires python3-markdown now + +* Tue Aug 08 2023 Guenther Deschner - 4.19.0-0.1.rc2 +- resolves: #2227246 - Update to version 4.19.0rc2 + +* Mon Aug 07 2023 Guenther Deschner - 4.19.0-0.0.rc1 +- resolves: #2227246 - Update to version 4.19.0rc1 + +* Thu Jul 20 2023 Guenther Deschner - 4.18.5-0 +- resolves: #2224040 - Update to version 4.18.5 +- resolves: #2222791, #2224254 - Security fix for CVE-2022-2127 +- resolves: #2222792, #2224255 - Security fix for CVE-2023-3347 +- resolves: #2222793, #2224253 - Security fix for CVE-2023-34966 +- resolves: #2222794, #2224252 - Security fix for CVE-2023-34967 +- resolves: #2222795, #2224250 - Security fix for CVE-2023-34968 + +* Sat Jul 15 2023 Guenther Deschner - 4.18.4-3 +- resolves: #2223091 - Fix netlogon LogonGetCapabilities level 2 error handling + +* Tue Jul 11 2023 František Zatloukal - 2:4.18.4-2 +- Rebuilt for ICU 73.2 + +* Wed Jul 05 2023 Python Maint - 2:4.18.4-1 +- Rebuilt for Python 3.12 + +* Wed Jul 05 2023 Guenther Deschner - 4.18.4-0 +- resolves: #2219799 - Update to version 4.18.4 + +* Mon Jun 26 2023 Python Maint - 2:4.18.3-5 +- Rebuilt for Python 3.12 + +* Mon Jun 26 2023 Adam Williamson - 4.18.3-4 +- Only run libwbclient %pre on upgrade, not fresh install + +* Fri Jun 23 2023 Andreas Schneider - 4.18.3-3 +- resolves: rhbz#2211577 - Fix libwbclient package upgrades + +* Thu Jun 15 2023 Python Maint - 2:4.18.3-2 +- Rebuilt for Python 3.12 + +* Thu Jun 15 2023 Andreas Schneider - 4.18.3-1 +- resolves: #2203539 - Also cover mit_kdc.log by logrotate + +* Thu Jun 01 2023 Guenther Deschner - 4.18.3-0 +- resolves: #2211453 - Update to version 4.18.3 + +* Wed Apr 19 2023 Guenther Deschner - 4.18.2-0 +- resolves: #2187991 - Update to version 4.18.2 + +* Wed Mar 29 2023 Guenther Deschner - 4.18.1-0 +- resolves: #2182787 - Update to version 4.18.1 +- resolves: #2182772, #2182773 - Security fixes for CVE-2023-0225 +- resolves: #2182774, #2182775 - Security fixes for CVE-2023-0922 +- resolves: #2182776, #2182777 - Security fixes for CVE-2023-0614 + +* Tue Mar 21 2023 Andreas Schneider - 4.18.0-12 +- Fix ctdb file lists when built with test suite enabled + +* Fri Mar 17 2023 Kalev Lember - 4.18.0-10 +- Move libstable-sort-samba4.so to samba-client-libs subpackage + +* Wed Mar 08 2023 Guenther Deschner - 4.18.0-9 +- resolves: #2176469 - Update to version 4.18.0 + +* Wed Mar 01 2023 Guenther Deschner - 4.18.0rc4-8 +- resolves: #2174415 - Update to version 4.18.0rc4 + +* Tue Feb 28 2023 Andreas Schneider - 4.18.0-0.7.rc3 +- resolves: #2173619 - Add missing Requires for glibc-gconv-extra + +* Thu Feb 23 2023 Pavel Filipenský - 4.18.0-0.6.rc3 +- SPDX migration + +* Wed Feb 15 2023 Guenther Deschner - 4.18.0rc3-6 +- resolves: #2166416 - Update to version 4.18.0rc3 + +* Mon Feb 13 2023 Pavel Filipenský - 4.18.0rc2-5 +- Create package samba-tools, move there samba-tool binary + +* Thu Feb 02 2023 Guenther Deschner - 4.18.0rc2-3 +- resolves: #2166416 - Update to version 4.18.0rc2 + +* Sat Jan 21 2023 Fedora Release Engineering - 2:4.18.0-0.2.rc1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild + +* Thu Jan 19 2023 Guenther Deschner - 4.18.0rc1-0 +- resolves: #2162097 - Update to version 4.18.0rc1 + +* Sat Dec 31 2022 Pete Walter - 2:4.17.4-4 +- Rebuild for ICU 72 + +* Thu Dec 22 2022 Pavel Filipenský - 4.17.4-3 +- Create package dc-libs also for 'non-dc build' + +* Tue Dec 20 2022 Pavel Filipenský - 4.17.4-2 +- Fix '--without dc' build: delete libauth4-samba4.so + +* Mon Dec 19 2022 Pavel Filipenský - 4.17.4-1 +- Create a samba-dcerpc sub-package +- Fix package installation without samba and samba-dc package + +* Fri Dec 16 2022 Guenther Deschner - 4.17.4-0 +- resolves: #2153906 - Update to version 4.17.4 +- resolves: #2154362, #2154363 - Security fixes for CVE-2022-38023 +- resolves: #2154303, #2154304 - Security fixes for CVE-2022-37966 +- resolves: #2154320, #2154322 - Security fixes for CVE-2022-37967 + +* Thu Dec 1 2022 Alexander Bokovoy - 2:4.17.3-2 +- Rebuild against krb5 1.20.1, new KDB interface + +* Mon Nov 21 2022 Florian Weimer - 2:4.17.3-1 +- Remove C89-specific language constructs from configure checks +- Fix feature detection for major/minor macros + +* Tue Nov 15 2022 Guenther Deschner - 4.17.3-0 +- resolves: #2142959 - Update to version 4.17.3 +- resolves: #2140960, #2143117 - Security fixes for CVE-2022-42898 + +* Wed Nov 02 2022 Pavel Filipenský - 4.17.2-1 +- Always add epoch to samba_depver to fix osci.brew-build.rpmdeplint.functional + +* Tue Oct 25 2022 Andreas Schneider - 4.17.2-1 +- Update to version 4.17.2 +- Fix CVE-2022-3592: A malicious client can use a symlink to escape the + exported + +* Mon Oct 24 2022 Andreas Schneider - 4.17.1-2 +- Add missing dependency for wbinfo used by ctdb scripts + +* Wed Oct 19 2022 Pavel Filipenský - 4.17.1-1 +- Update to version 4.17.1 +- resolves: rhbz#2127301 - Permission denied calling SMBC_getatr when file not exists +- resolves: rhbz#2133818 - rpcclient 4.17.0 unable to resolve server hostname + +* Wed Oct 05 2022 Andreas Schneider - 4.17.0-2 +- Move group creation logic to sysusers.d fragment + +* Tue Sep 13 2022 Andreas Schneider - 4.17.0-1 +- resolves: rhbz#2118818 - Update to version 4.17.0 +- resolves: rhbz#2121138 - Fix CVE-2022-32743 +- resolves: rhbz#2122650 - Fix CVE-2022-1615 + +* Tue Sep 13 2022 Andreas Schneider - 4.17.0-0.11.rc5 +- resolves: rhbz#2093656 - Split out libnetapi(-devel) sub-packages +- resolves: rhbz#2096405 - Add samba-usershare package + +* Tue Sep 06 2022 Guenther Deschner - 4.17.0-0.10.rc5 +- resolves: #2118818 - Update to version 4.17.0rc5 + +* Wed Aug 31 2022 Guenther Deschner - 4.17.0-0.9.rc4 +- resolves: #2118818 - Update to version 4.17.0rc4 + +* Thu Aug 25 2022 Adam Williamson - 4.17.0-0.8.rc3 +- Rebuild with no changes to fix F37 update grouping + +* Thu Aug 25 2022 Andreas Schneider - 4.17.0-0.7.rc3 +- python3-samba package should not require the samba package + +* Tue Aug 23 2022 Pavel Filipenský - 4.17.0-0.6.rc3 +- resolves: #2118818 - Update to version 4.17.0rc3 + +* Fri Aug 19 2022 Andreas Schneider - 4.17.0-0.5.rc2 +- Create a samba-gpupdate sub-package for GPO client support + +* Fri Aug 19 2022 Andreas Schneider - 4.17.0-0.4.rc2 +- Split out a samba-ldb-ldap-modules subpackage + +* Thu Aug 18 2022 Kalev Lember - 2:4.17.0-0.3.rc2 +- Avoid requiring systemd as per updated packaging guidelines + +* Wed Aug 17 2022 Guenther Deschner - 4.17.0rc2-2 +- resolves: #2118818 - Update to version 4.17.0rc2 + +* Wed Aug 10 2022 Andreas Schneider - 4.17.0rc1-1 +- Make sure we detect if SO version numbers of public libraries change. + +* Mon Aug 08 2022 Guenther Deschner - 4.17.0rc1-0 +- resolves: #2116503 - Update to version 4.17.0rc1 + +* Mon Aug 01 2022 Frantisek Zatloukal - 2:4.16.4-1 +- Rebuilt for ICU 71.1 + +* Wed Jul 27 2022 Guenther Deschner - 4.16.4-0 +- resolves: #2111490 - Update to version 4.16.4 +- resolves: #2108196, #2111729 - Security fixes for CVE-2022-32742 +- resolves: #2108205, #2111731 - Security fixes for CVE-2022-32744 +- resolves: #2108211, #2111732 - Security fixes for CVE-2022-32745 +- resolves: #2108215, #2111734 - Security fixes for CVE-2022-32746 + +* Sat Jul 23 2022 Fedora Release Engineering - 2:4.16.3-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild + +* Mon Jul 18 2022 Andreas Schneider - 4.16.3-1 +- Update to version 4.16.3 + +* Wed Jun 15 2022 Python Maint - 2:4.16.2-1 +- Rebuilt for Python 3.11 + +* Mon Jun 13 2022 Guenther Deschner - 4.16.2-0 +- Update to Samba 4.16.2 +- resolves: #2096167 + +* Wed Jun 08 2022 Andreas Schneider - 4.16.1-7 +- resolves: rhbz#2093833 - Remove weak dependency for logrotate for CentOS/RHEL + +* Tue May 31 2022 Jitka Plesnikova - 2:4.16.1-6 +- Perl 5.36 rebuild + +* Fri May 13 2022 Pavel Filipenský - 4.16.1-5 +- Fix rpminspect abidiff + +* Fri May 06 2022 Pavel Filipenský - 4.16.1-2 +- Update requires for packages + +* Thu May 05 2022 Tomas Popela - 4.16.1-1 +- Don't require full systemd for tmp files handling in samba-common + +* Mon May 02 2022 Pavel Filipenský - 4.16.1-0 +- Update to Samba 4.16.1 +- resolves: #2080915 + +* Fri Mar 25 2022 Sandro Mani - 2:4.16.0-7 +- Rebuild with mingw-gcc-12 + +* Tue Mar 22 2022 Guenther Deschner - 4.16.0-6 +- Update to Samba 4.16.0 +- resolves: #2066290 + +* Wed Mar 09 2022 Guenther Deschner - 4.16.0-0.5.rc5 +- Update to Samba 4.16.0rc5 +- resolves: #2042518 + +* Tue Mar 01 2022 Pavel Filipenský - 4.16.0-0.4.rc4 +- Update to Samba 4.16.0rc4 +- resolves: #2042518 + +* Wed Feb 23 2022 Andreas Schneider - 4.16.0-0.3.rc3 +- resolves: rhbz#2036443 - Fix samba-tool on builds with samba-dc + +* Tue Feb 15 2022 Pavel Filipenský - 4.16.0rc3 +- Update to Samba 4.16.0rc3 +- resolves: #2042518 + +* Tue Feb 01 2022 Pavel Filipenský - 4.16.0rc2 +- Update to Samba 4.16.0rc2 +- resolves: #2046120, #2048566 - Security fixes for CVE-2021-44141 +- resolves: #2046146, #2048570 - Security fixes for CVE-2021-44142 +- resolves: #2046134, #2048568 - Security fixes for CVE-2022-0336 +- resolves: #2042518 + +* Wed Jan 26 2022 Pavel Filipenský - 4.16.0rc1 +- Exclude temporarily ceph on ppc64le to fix failing build + +* Tue Jan 25 2022 Pavel Filipenský - 4.16.0rc1 +- Update to Samba 4.16.0rc1 +- resolves: #2042518 + +* Thu Jan 20 2022 Pavel Filipenský - 4.15.4-0 +- Update to Samba 4.15.4 +- resolves: #2009673, #2039034 - Security fixes for CVE-2021-20316 +- resolves: #2042518 + +* Wed Dec 15 2021 Pavel Filipenský - 4.15.3-1 +- Fix resolv_wrapper with glibc 2.34 +- resolves: #2019669 + +* Wed Dec 08 2021 Pavel Filipenský - 4.15.3-0 +- Update to Samba 4.15.3 +- resolves: #2030382 + +* Sat Nov 13 2021 Guenther Deschner - 4.15.2-3 +- Fix IPA DC schannel support + +* Thu Nov 11 2021 Guenther Deschner - 4.15.2-2 +- Fix winbind trusted domain regression +- related: #2021716 +- Fix logfile handling +- Fix smbclient -N failures in container setups + +* Tue Nov 09 2021 Guenther Deschner - 4.15.2-0 +- Update to Samba 4.15.2 +- resolves: #2019660, #2021711 - Security fixes for CVE-2016-2124 +- resolves: #2019672, #2021716 - Security fixes for CVE-2020-25717 +- resolves: #2019726, #2021718 - Security fixes for CVE-2020-25718 +- resolves: #2019732, #2021719 - Security fixes for CVE-2020-25719 +- resolves: #2021728, #2021729 - Security fixes for CVE-2020-25721 +- resolves: #2019764, #2021721 - Security fixes for CVE-2020-25722 +- resolves: #2021726, #2021727 - Security fixes for CVE-2021-3738 +- resolves: #2019666, #2021715 - Security fixes for CVE-2021-23192 +- resolves: #2021625 + +* Fri Nov 05 2021 Guenther Deschner - 4.15.1-1 +- Fix winexe core dump +- resolves: #2020376 + +* Wed Oct 27 2021 Guenther Deschner - 4.15.1-0 +- Update to Samba 4.15.1 +- resolves: #2017847 + +* Mon Sep 20 2021 Guenther Deschner - 4.15.0-13 +- Update to Samba 4.15.0 +- resolves: #2005817 + +* Mon Sep 13 2021 Guenther Deschner - 4.15.0-0.12.rc7 +- Update to Samba 4.15.0rc7 +- resolves: #2003740 + +* Thu Sep 09 2021 Guenther Deschner - 4.15.0-0.11.rc6 +- Update to Samba 4.15.0rc6 +- resolves: #2002546 + +* Tue Sep 07 2021 Guenther Deschner - 4.15.0-0.10.rc5 +- Update to Samba 4.15.0rc5 +- resolves: #2001827 + +* Wed Sep 01 2021 Guenther Deschner - 4.15.0-0.9.rc4 +- Update to Samba 4.15.0rc4 +- resolves: #2000079 + +* Thu Aug 26 2021 Guenther Deschner - 4.15.0-0.8.rc3 +- Update to Samba 4.15.0rc3 +- resolves: #1998024 + +* Wed Aug 25 2021 Guenther Deschner - 4.15.0-0.7.rc2 +- Add ceph and etcd mutex helpers for CTDB + +* Mon Aug 16 2021 Anoop C S - 4.15.0-0.6.rc2 +- Avoid removing PyDSDB library files from buildroot for non AD DC build + +* Fri Aug 13 2021 Adam Williamson - 4.15.0-0.5.rc2 +- Fix samba-common-tools dependency + +* Thu Aug 12 2021 Andreas Schneider - 4.15.0-0.4.rc2 +- Package samba-tool correctly + +* Mon Aug 09 2021 Guenther Deschner - 4.15.0-0.3.rc2 +- Update to Samba 4.15.0rc2 +- resolves: #1991634 + +* Fri Jul 23 2021 Fedora Release Engineering - 2:4.15.0-0.2.rc1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild + +* Mon Jul 19 2021 Guenther Deschner - 4.15.0rc1-1 +- Fix ctdb-pcp-pmda install +- resolves: #1983369 + +* Thu Jul 15 2021 Guenther Deschner - 4.15.0rc1-0 +- Update to Samba 4.15.0rc1 +- resolves: #1982623 + +* Wed Jul 14 2021 Guenther Deschner - 4.14.6-1 +- Build with pcp-pmda support by default on Fedora +- resolves: #1552276 + +* Tue Jul 13 2021 Guenther Deschner - 4.14.6-0 +- Update to Samba 4.14.6 +- resolves: #1981764 + +* Thu Jun 24 2021 Andreas Schneider - 4.14.5-3 +- Create a subpackage for vfs-io-uring + +* Fri Jun 04 2021 Python Maint - 2:4.14.5-1 +- Rebuilt for Python 3.10 + +* Tue Jun 01 2021 Guenther Deschner - 4.14.5-0 +- Update to Samba 4.14.5 +- resolves: #1966456 + +* Fri May 21 2021 Jitka Plesnikova - 2:4.14.4-3 +- Perl 5.34 rebuild + +* Wed May 19 2021 Pete Walter - 2:4.14.4-2 +- Rebuild for ICU 69 + +* Tue May 18 2021 Andreas Schneider - 4.14.4-1 +- Fixed building with gcc 11.x +- Fixed quota support + +* Thu Apr 29 2021 Guenther Deschner - 4.14.4-0 +- Update to Samba 4.14.4 +- resolves: #1949442, #1955027 - Security fixes for CVE-2021-20254 +- resolves: #1955011 + +* Wed Apr 28 2021 Anoop C S - 4.14.3-2 +- resolves: #1954263 - wrong conditional build check of AD DC + +* Tue Apr 20 2021 Andreas Schneider - 4.14.3-1 +- resolves: #1942378 - Drop NIS support + +* Tue Apr 20 2021 Guenther Deschner - 4.14.3-0 +- Update to Samba 4.14.3 +- resolves: #1951531 + +* Mon Apr 19 2021 Michal Ambroz - 4.14.2-4 + - Added python3-ldb to BR + +* Mon Apr 19 2021 Andreas Schneider - 4.12.2-3 +- resolves: #1949295 - Remove findsmb script + +* Wed Apr 14 2021 Richard W.M. Jones - 2:4.14.2-2 +- Rebuild for updated liburing. + +* Wed Apr 07 2021 Alexander Bokovoy - 4.14.2-1 +- Fix memory leaks in RPC server +- resolves: #1946950 + +* Thu Mar 25 2021 Guenther Deschner - 4.14.2-0 +- Update to Samba 4.14.2 +- related: #1941400, #1942496 - Security fixes for CVE-2020-27840 +- related: #1941402, #1942497 - Security fixes for CVE-2021-20277 + +* Wed Mar 24 2021 Guenther Deschner - 4.14.1-0 +- Update to Samba 4.14.1 +- resolves: #1941400, #1942496 - Security fixes for CVE-2020-27840 +- resolves: #1941402, #1942497 - Security fixes for CVE-2021-20277 + +* Tue Mar 09 2021 Guenther Deschner - 4.14.0-3 +- Update to Samba 4.14.0 + +* Tue Mar 02 2021 Zbigniew Jędrzejewski-Szmek - 2:4.14.0-0.0.rc4.2 +- Rebuilt for updated systemd-rpm-macros + See https://pagure.io/fesco/issue/2583. + +* Mon Mar 01 2021 Guenther Deschner - 4.14.0rc4-0 +- Update to Samba 4.14.0rc4 + +* Thu Feb 18 2021 Guenther Deschner - 4.14.0rc3-0 +- Update to Samba 4.14.0rc3 + +* Thu Feb 04 2021 Guenther Deschner - 4.14.0rc2-0 +- Update to Samba 4.14.0rc2 + +* Wed Jan 27 2021 Guenther Deschner - 4.14.0rc1-0 +- Update to Samba 4.14.0rc1 + +* Tue Jan 26 2021 Guenther Deschner - 4.13.4-0 +- Update to Samba 4.13.4 + +* Wed Dec 16 2020 Guenther Deschner - 4.13.3-1 +- Rebuild against krb5-1.19 +- Resolves: rhbz#1915928 + +* Tue Dec 15 2020 Guenther Deschner - 4.13.3-0 +- Update to Samba 4.13.3 + +* Wed Nov 25 2020 Alexander Bokovoy - 4.13.2-2 +- rhbz#1892745, rhbz#1900232: smbclient mget crashes (upstream bug 14517) +- Merge RHEL 8.4 patches: + - FIPS-related enhancements + - FreeIPA Global Catalog patches + +* Tue Nov 03 2020 Andreas Schneider - 4.13.2-1 +- Create a python3-samba-devel package to avoid unnessary dependencies + +* Tue Nov 03 2020 Guenther Deschner - 4.13.2-0 +- Update to Samba 4.13.2 + +* Thu Oct 29 2020 Guenther Deschner - 4.13.1-0 +- Update to Samba 4.13.1 +- resolves: #1892631, #1892634 - Security fixes for CVE-2020-14318 +- resolves: #1891685, #1892628 - Security fixes for CVE-2020-14323 +- resolves: #1892636, #1892640 - Security fixes for CVE-2020-14383 + +* Mon Oct 26 2020 Andreas Schneider - 4.13.0-14 +- Fixed dbcheck running in a release tarball +- Updated internal resolv_wrapper copy to verison 1.1.7 + +* Sun Oct 25 2020 Alexander Bokovoy - 4.13.0-13 +- Report 'samba' daemon status back to systemd +- Support dnspython 2.0.0 or later in samba_dnsupdate + +* Thu Oct 22 2020 Alexander Bokovoy - 4.13.0-12 +- Add preliminary support for S4U operations in Samba AD DC + resolves: #1836630 - Samba DC: Remote Desktop cannot access files +- Fix lookup_unix_user_name to allow lookup of realm-qualified users and groups + required for upcoming FreeIPA Global Catalog support + +* Tue Sep 22 2020 Guenther Deschner - 4.13.0-11 +- Update to Samba 4.13.0 + +* Fri Sep 18 2020 Guenther Deschner - 4.13.0rc6-10 +- Update to Samba 4.13.0rc6 +- resolves: #1879822, #1880703 - Security fixes for CVE-2020-1472 + +* Wed Sep 16 2020 Guenther Deschner - 4.13.0rc5-9 +- Update to Samba 4.13.0rc5 + +* Mon Sep 07 2020 Guenther Deschner - 4.13.0rc4-8 +- Update to Samba 4.13.0rc4 + +* Fri Aug 28 2020 Neal Gompa - 4.13.0rc3-6 +- Enable winexe by default everywhere + +* Fri Aug 28 2020 Guenther Deschner - 4.13.0rc3-5 +- Update to Samba 4.13.0rc3 + +* Fri Aug 14 2020 Guenther Deschner - 4.13.0rc2-4 +- Update to Samba 4.13.0rc2 + +* Wed Aug 12 2020 Andreas Schneider - 4.13.0rc1-3 +- resolves: #1865831 - Add missing /usr/lib64/samba/krb5 directory +- resolves: #1866989 - Remove obsolete python3-crypto dependency + +* Wed Jul 29 2020 Fedora Release Engineering - 2:4.13.0-0.2.rc1.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild + +* Tue Jul 14 2020 Tom Stellard - 2:4.13.0-0.2.rc1 +- Use make macros + https://fedoraproject.org/wiki/Changes/UseMakeBuildInstallMacro + +* Tue Jul 14 2020 Andreas Schneider - 4.13.0rc1-1 +- Move mdssvc data files to correct package + +* Thu Jul 09 2020 Guenther Deschner - 4.13.0rc1-0 +- Update to Samba 4.13.0rc1 + +* Wed Jul 08 2020 Merlin Mathesius - 4.12.5-1 +- Remove nonexistent --without-winexe option from configure + +* Thu Jul 02 2020 Guenther Deschner - 4.12.5-0 +- Update to Samba 4.12.5 + +* Thu Jul 02 2020 Guenther Deschner - 4.12.4-0 +- Update to Samba 4.12.4 +- resolves: #1849489, #1853255 - Security fixes for CVE-2020-10730 +- resolves: #1849491, #1853256 - Security fixes for CVE-2020-10745 +- resolves: #1849509, #1853276 - Security fixes for CVE-2020-10760 +- resolves: #1851298, #1853259 - Security fixes for CVE-2020-14303 + +* Sat Jun 27 2020 Jitka Plesnikova - 2:4.12.3-1.1 +- Perl 5.32 re-rebuild updated packages + +* Thu Jun 25 2020 Guenther Deschner - 4.12.3-1 +- Add BuildRequires for python3-setuptools + +* Thu Jun 25 2020 Jitka Plesnikova - 2:4.12.3-0.4 +- Perl 5.32 rebuild + +* Tue May 26 2020 Miro Hrončok - 2:4.12.3-0.3 +- Rebuilt for Python 3.9 + +* Tue May 19 2020 Guenther Deschner - 4.12.3-0 +- Update to Samba 4.12.3 + +* Fri May 15 2020 Pete Walter - 2:4.12.2-1.2 +- Rebuild for ICU 67 + +* Wed May 13 2020 Guenther Deschner - 4.12.2-1 +- Add support for building the new experimental io_uring VFS module + +* Tue Apr 28 2020 Guenther Deschner - 4.12.2-0 +- Update to Samba 4.12.2 +- resolves: #1825731, #1828870 - Security fixes for CVE-2020-10700 +- resolves: #1825734, #1828872 - Security fixes for CVE-2020-10704 + +* Sun Apr 12 2020 Alexander Bokovoy - 4.12.1-1 +- Revert POSIX stat tuning in libsmbclient +- Resolves: rhbz#1801442 + +* Tue Apr 07 2020 Guenther Deschner - 4.12.1-0 +- Update to Samba 4.12.1 + +* Sat Mar 21 2020 Alexander Bokovoy - 4.12.0-6 +- Fix samba_requires_eq macro definition +- Resolves rhbz#1815739 + +* Tue Mar 10 2020 Guenther Deschner - 4.12.0-5 +- Add build requirement for perl-FindBin +- resolves: #1661213 - Add winexe subpackage for remote windows command execution + +* Tue Mar 03 2020 Guenther Deschner - 4.12.0-3 +- Update to Samba 4.12.0 + +* Wed Feb 26 2020 Guenther Deschner - 4.12.0rc4-2 +- Update to Samba 4.12.0rc4 + +* Wed Feb 19 2020 Guenther Deschner - 4.12.0rc3-2 +- Update to Samba 4.12.0rc3 + +* Tue Feb 04 2020 Guenther Deschner - 4.12.0rc2-2 +- Update to Samba 4.12.0rc2 + +* Thu Jan 30 2020 Fedora Release Engineering - 2:4.12.0-0.1.rc1.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild + +* Fri Jan 24 2020 Alexander Bokovoy - 4.12.0.rc1-1 +- Allow building against krb5 1.18 beta and require it for Rawhide + +* Wed Jan 22 2020 Guenther Deschner - 4.12.0rc1-0 +- Update to Samba 4.12.0rc1 + +* Tue Jan 21 2020 Guenther Deschner - 4.11.5-0 +- Update to Samba 4.11.5 +- resolves: #1791201, #1793405 - Security fixes for CVE-2019-14902 +- resolves: #1791207, #1793407 - Security fixes for CVE-2019-14907 +- resolves: #1791204, #1793406 - Security fixes for CVE-2019-19344 + +* Mon Dec 16 2019 Guenther Deschner - 4.11.4-0 +- Update to Samba 4.11.4 + +* Tue Dec 10 2019 Guenther Deschner - 4.11.3-0 +- Update to Samba 4.11.3 +- resolves: #1778586, #1781542 - Security fixes for CVE-2019-14861 +- resolves: #1778589, #1781545 - Security fixes for CVE-2019-14870 + +* Thu Dec 05 2019 Andreas Schneider - 4.11.2-2 +- Restart winbindd on samba-winbind package upgrade + +* Wed Nov 06 2019 Alexander Bokovoy - 4.11.2-1 +- Update DES removal patch + +* Tue Oct 29 2019 Guenther Deschner - 4.11.2-0 +- Update to Samba 4.11.2 +- resolves: #1763137, #1766558 - Security fixes for CVE-2019-10218 +- resolves: #1764126, #1766559 - Security fixes for CVE-2019-14833 + +* Sun Oct 27 2019 Alexander Bokovoy - 4.11.1-1 +- resolves: #1757071 - Deploy new samba DC fails + +* Fri Oct 18 2019 Guenther Deschner - 4.11.1-0 +- Update to Samba 4.11.1 + +* Tue Sep 17 2019 Guenther Deschner - 4.11.0-3 +- Update to Samba 4.11.0 + +* Wed Sep 11 2019 Guenther Deschner - 4.11.0rc4-2 +- Update to Samba 4.11.0rc4 + +* Tue Sep 03 2019 Guenther Deschner - 4.11.0rc3-2 +- Update to Samba 4.11.0rc3 +- resolves: #1746225, #1748308 - Security fixes for CVE-2019-10197 + +* Tue Aug 27 2019 Guenther Deschner - 4.11.0rc2-2 +- resolves: #1746014 - re-add pidl + +* Mon Aug 26 2019 Lubomir Rintel - 2:4.11.0-0.1.rc2 +- Move the NetworkManager dispatcher script out of /etc + +* Wed Aug 21 2019 Guenther Deschner - 4.11.0rc2-0 +- Update to Samba 4.11.0rc2 + +* Tue Aug 20 2019 Guenther Deschner - 4.11.0rc1-0 +- Update to Samba 4.11.0rc1 + +* Mon Aug 19 2019 Miro Hrončok - 2:4.10.6-1.1 +- Rebuilt for Python 3.8 + +* Fri Aug 16 2019 Alexander Bokovoy - 2:4.10.6-1 +- Fix Samba bug https://bugzilla.samba.org/show_bug.cgi?id=14091 +- Fixes: Windows systems cannot resolve IPA users and groups over LSA RPC + +* Fri Jul 26 2019 Fedora Release Engineering - 2:4.10.6-0.2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild + +* Mon Jul 08 2019 Guenther Deschner - 4.10.6-0 +- Update to Samba 4.10.6 + +* Mon Jul 01 2019 Guenther Deschner - 4.10.5-2 +- resolves: #1718113 - Avoid deprecated time.clock in wafsamba +- resolves: #1711638 - Update to latest waf version 2.0.17 + +* Thu Jun 20 2019 Guenther Deschner - 4.10.5-1 +- resolves: #1602824 - Make vfs_fruit operable with other remote VFS modules +- resolves: #1716455 - Avoid pathconf() in get_real_filename() VFS calls +- resolves: #1706090, #1700791 - Fix smbspool + +* Wed Jun 19 2019 Guenther Deschner - 4.10.5-0 +- Update to Samba 4.10.5 +- resolves: #1711816, #1721872 - Security fixes for CVE-2019-12435 +- resolves: #1711837, #1721873 - Security fixes for CVE-2019-12436 + +* Fri May 31 2019 Jitka Plesnikova - 2:4.10.4-1.1 +- Perl 5.30 rebuild + +* Tue May 28 2019 Guenther Deschner - 4.10.4-1 +- Add missing ctdb directories +- resolves: #1656777 + +* Wed May 22 2019 Guenther Deschner - 4.10.4-0 +- Update to Samba 4.10.4 + +* Tue May 14 2019 Guenther Deschner - 4.10.3-0 +- Update to Samba 4.10.3 +- resolves: #1705877, #1709679 - Security fixes for CVE-2018-16860 + +* Mon Apr 15 2019 Andreas Schneider - 4.10.2-1 +- resolves: #1699230 - Rebuild for MIT Kerberos soname bump of libkadm5srv + +* Mon Apr 08 2019 Guenther Deschner - 4.10.2-0 +- Update to Samba 4.10.2 +- resolves: #1689010, #1697718 - Security fixes for CVE-2019-3870 +- resolves: #1691518, #1697717 - Security fixes for CVE-2019-3880 + +* Wed Apr 03 2019 Guenther Deschner - 4.10.1-0 +- Update to Samba 4.10.1 + +* Mon Mar 25 2019 Andreas Schneider - 4.10.0-6 +- resolves: #1692347 - Add missing DC requirement for its python3 tools + +* Wed Mar 20 2019 Guenther Deschner - 4.10.0-5 +- Fix build failure (duplication during install) + +* Tue Mar 19 2019 Guenther Deschner - 4.10.0-4 +- Update to Samba 4.10.0 + +* Wed Mar 06 2019 Guenther Deschner - 4.10.0rc4-2 +- Update to Samba 4.10.0rc4 + +* Fri Feb 22 2019 Guenther Deschner - 4.10.0rc3-2 +- Update to Samba 4.10.0rc3 + +* Sun Feb 17 2019 Igor Gnatenko - 2:4.10.0-0.2.rc2.1 +- Rebuild for readline 8.0 + +* Thu Feb 14 2019 Andreas Schneider - 4.10.0rc2-2 +- resolves: #1672231 - Fix public NDR API + +* Tue Feb 12 2019 Guenther Deschner - 4.10.0rc2-1 +- resolves: #1674547 - Move samba.xattr modules out of python3 test package + +* Wed Feb 06 2019 Guenther Deschner - 4.10.0rc2-0 +- Update to Samba 4.10.0rc2 + +* Tue Jan 15 2019 Guenther Deschner - 4.10.0rc1-0 +- Update to Samba 4.10.0rc1 + +* Mon Jan 14 2019 Björn Esser - 2:4.9.4-0.1 +- Rebuilt for libcrypt.so.2 (#1666033) + +* Thu Dec 20 2018 Guenther Deschner - 4.9.4-0 +- Update to Samba 4.9.4 + +* Tue Nov 27 2018 Guenther Deschner - 4.9.3-0 +- Update to Samba 4.9.3 +- resolves: #1625449, #1654078 - Security fixes for CVE-2018-14629 +- resolves: #1642545, #1654082 - Security fixes for CVE-2018-16841 +- resolves: #1646377, #1654091 - Security fixes for CVE-2018-16851 +- resolves: #1646386, #1654092 - Security fixes for CVE-2018-16852 +- resolves: #1647246, #1654093 - Security fixes for CVE-2018-16853 +- resolves: #1649278, #1654095 - Security fixes for CVE-2018-16857 + +* Thu Nov 08 2018 Guenther Deschner - 4.9.2-0 +- Update to Samba 4.9.2 + +* Wed Sep 26 2018 Alexander Bokovoy - 4.9.1-2 +- Package ctdb/doc/examples + +* Mon Sep 24 2018 Andreas Schneider - 4.9.1-1 +- Update to Samba 4.9.1 + +* Thu Sep 13 2018 Guenther Deschner - 4.9.0-4 +- Update to Samba 4.9.0 + +* Thu Sep 06 2018 Andreas Schneider - 4.9.0rc5-3 +- Update to Samba 4.9.0rc5 + +* Wed Aug 29 2018 Guenther Deschner - 4.9.0rc4-3 +- Update to Samba 4.9.0rc4 + +* Thu Aug 16 2018 Andreas Schneider - 4.9.0rc3-3 +- Fix python3 packaging + +* Wed Aug 15 2018 Guenther Deschner - 4.9.0rc3-2 +- Update to Samba 4.9.0rc3 +- resolves: #1589651, #1617916 - Security fixes for CVE-2018-1139 +- resolves: #1580230, #1618613 - Security fixes for CVE-2018-1140 +- resolves: #1612805, #1618697 - Security fixes for CVE-2018-10858 +- resolves: #1610640, #1617910 - Security fixes for CVE-2018-10918 +- resolves: #1610645, #1617911 - Security fixes for CVE-2018-10919 + +* Wed Aug 01 2018 Andreas Schneider - 4.9.0rc2-2 +- Add some spec file cleanups + +* Wed Aug 01 2018 Guenther Deschner - 4.9.0rc2-0 +- Update to Samba 4.9.0rc2 + +* Thu Jul 12 2018 Guenther Deschner - 4.9.0rc1-0 +- Update to Samba 4.9.0rc1 + +* Thu Jul 12 2018 Alexander Bokovoy - 2:4.8.3-4.1 +- Scope to local __bss_start symbol (typo in a patch) +- Fixes https://bugzilla.redhat.com/show_bug.cgi?id=1600035 + +* Thu Jul 12 2018 Alexander Bokovoy - 2:4.8.3-4 +- Change scope to local for symbols automatically added by upcoming binutils 2.31 +- Fixes https://bugzilla.redhat.com/show_bug.cgi?id=1600035 + +* Wed Jul 11 2018 Alexander Bokovoy - 2:4.8.3-3 +- Rebuild Samba against binutils 2.30.90-2.fc29 +- Fixes https://bugzilla.redhat.com/show_bug.cgi?id=1600035 +- Add explicit BuildRequires for gcc + +* Fri Jul 06 2018 Petr Pisar +- Perl 5.28 rebuild + +* Thu Jul 05 2018 Alexander Bokovoy - 2:4.8.3-2 +- Fix rawhide build by explicitly using /usr/bin/python2 + +* Tue Jul 03 2018 Petr Pisar +- Perl 5.28 rebuild + +* Mon Jul 02 2018 Miro Hrončok - 2:4.8.3-1.2 +- Rebuilt for Python 3.7 + +* Thu Jun 28 2018 Jitka Plesnikova - 2:4.8.3-1.1 +- Perl 5.28 rebuild + +* Tue Jun 26 2018 Andreas Schneider - 4.8.3-1 +- Update to Samba 4.8.3 +- Remove python(2|3)-subunit dependency + +* Tue Jun 19 2018 Miro Hrončok - 2:4.8.2-1.1 +- Rebuilt for Python 3.7 + +* Wed May 16 2018 Guenther Deschner - 4.8.2-0 +- Update to Samba 4.8.2 + +* Wed May 09 2018 Andreas Schneider - 4.8.1-1 +- resolves: #1574177 - Fix smbspool command line argument handling + +* Thu Apr 26 2018 Guenther Deschner - 4.8.1-0 +- Update to Samba 4.8.1 + +* Wed Mar 14 2018 Guenther Deschner - 4.8.0-7 +- resolves: #1554754, #1554756 - Security fixes for CVE-2018-1050 CVE-2018-1057 +- resolves: #1555112 - Update to Samba 4.8.0 + +* Tue Mar 13 2018 Andreas Schneider - 4.8.0rc4-6 +- resolves: #1552652 - Fix usage of nc in ctdb tests and only recommned it + +* Fri Mar 02 2018 Guenther Deschner - 4.8.0rc4-5 +- Update to Samba 4.8.0rc4 + +* Mon Feb 12 2018 Guenther Deschner - 4.8.0rc3-4 +- Update to Samba 4.8.0rc3 + +* Fri Feb 09 2018 Igor Gnatenko - 2:4.8.0-0.3.rc2.1 +- Escape macros in %%changelog + +* Fri Jan 26 2018 Guenther Deschner - 4.8.0rc2-3 +- Update to Samba 4.8.0rc2 + +* Sun Jan 21 2018 Björn Esser - 2:4.8.0-0.2.rc1 +- Explicitly BR: rpcsvc-proto-devel + +* Sat Jan 20 2018 Björn Esser - 2:4.8.0-0.1.rc1.1 +- Rebuilt for switch to libxcrypt + +* Mon Jan 15 2018 Guenther Deschner - 4.8.0rc1-1 +- Update to Samba 4.8.0rc1 + +* Mon Jan 08 2018 Andreas Schneider - 4.7.4-1 +- resolves: #1508092 - Add missing dependency for tdbbackup + +* Mon Dec 25 2017 Guenther Deschner - 4.7.4-0 +- Update to Samba 4.7.4 + +* Mon Dec 04 2017 Andreas Schneider - 4.7.3-3 +- resolves: #1520163 - Link libaesni-intel-samba4.so with -z noexecstack + +* Thu Nov 30 2017 Andreas Schneider - 4.7.3-2 +- Fix deamon startup with systemd + +* Thu Nov 23 2017 Bastien Nocera - 4.7.3-1 +- Enable AES acceleration on Intel compatible CPUs by default + +* Tue Nov 21 2017 Guenther Deschner - 4.7.3-0 +- Update to Samba 4.7.3 +- resolves: #1515692 - Security fix for CVE-2017-14746 and CVE-2017-15275 + +* Wed Nov 15 2017 Guenther Deschner - 4.7.2-0 +- resolves: #1513452 - Update to Samba 4.7.2 + +* Mon Nov 13 2017 Andreas Schneider - 4.7.1-2 +- Fix release number + +* Tue Nov 07 2017 Igor Gnatenko - 4.7.1-1 +- Remove old crufty coreutils requires + +* Thu Nov 02 2017 Guenther Deschner - 4.7.1-0 +- resolves: #1508871 - Update to Samba 4.7.1 + +* Mon Oct 30 2017 Alexander Bokovoy - 4.7.0-18 +- Force samba-dc to use the same libldb version as LDB modules compiled +- resolves: #1507420 - LDB / Samba module version mismatch + +* Fri Oct 27 2017 Andreas Schneider - 4.7.0-17 +- Move dsdb libs to python2-samba-dc + +* Thu Oct 26 2017 Andreas Schneider - 4.7.0-16 +- Create python[2|3]-samba-dc packages + +* Wed Oct 25 2017 Andreas Schneider - 4.7.0-15 +- related: #1499140 - Fix several dependency issues +- Fix building with MIT Kerberos 1.16 + +* Fri Oct 13 2017 Andreas Schneider - 4.7.0-14 +- resolves: #1499140 - Move libdfs-server-ad to the correct subpackage + +* Fri Oct 06 2017 Alexander Bokovoy - 4.7.0-13 +- Move /usr/lib{64,}/samba/libdsdb-garbage-collect-tombstones-samba4.so to samba-dc-libs +- Rebuild in rawhide against new krb5 1.16 and docbook-xml + +* Thu Sep 21 2017 Guenther Deschner - 4.7.0-12 +- Update to Samba 4.7.0 +- resolves: #1493441 - Security fix for CVE-2017-12150 CVE-2017-12151 CVE-2017-12163 + +* Sun Sep 17 2017 Guenther Deschner - 4.7.0-0.11.rc6 +- Update to Samba 4.7.0rc6 + +* Wed Sep 13 2017 Alexander Bokovoy - 4.7.0-0.11.rc5 +- resolves: #1491137 - dcerpc/__init__.py is not packaged for py3 + +* Tue Sep 12 2017 Andreas Schneider - 4.7.0-0.10.rc5 +- resolves: #1476175 - Create seperate package for bind_dlz module + +* Tue Aug 29 2017 Guenther Deschner - 4.7.0-0.9.rc5 +- Update to Samba 4.7.0rc5 + +* Tue Aug 08 2017 Andreas Schneider - 4.7.0-0.9.rc3 +- Add printadmin group for printer driver handling + +* Sun Jul 30 2017 Florian Weimer - 2:4.7.0-0.8.rc3.2 +- Rebuild with binutils fix for ppc64le (#1475636) + +* Thu Jul 27 2017 Fedora Release Engineering - 2:4.7.0-0.8.rc3.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild + +* Wed Jul 26 2017 Andreas Schneider - 4.7.0-0.8.rc3 +- resolves: #1301002 - Enable avahi support + +* Tue Jul 25 2017 Guenther Deschner - 4.7.0-0.7.rc3 +- Update to Samba 4.7.0rc3 + +* Mon Jul 24 2017 Andreas Schneider - 4.7.0-0.7.rc1 +- Rename samba-python to python2-samba +- Update build requirement for libcephfs + +* Thu Jul 20 2017 Alexander Bokovoy - 4.7.0-0.6.rc1 +- Use Python 2 explicitly for samba-tool and other Python-based tools +- Install samba.service as it is required for the AD DC case + +* Tue Jul 18 2017 Alexander Bokovoy - 4.7.0-0.5.rc1 +- Convert more rpc modules to python3 +- Explicitly specify Python artifacts in the spec to be able to catch unpackaged ones +- Split 'make test' Python code into separate python2-samba-test/python3-samba-test sub-packages +- Remove embedded python2-dns version, require python{2,3}-dns instead + +* Thu Jul 06 2017 Andreas Schneider - 4.7.0-0.4.rc1 +- Add python3 support +- Fix %%posttrans for libwbclient-devel + +* Thu Jul 06 2017 Andreas Schneider - 4.7.0-0.3.rc1 +- Do not install conflicting file _ldb_text.py + +* Wed Jul 05 2017 Andreas Schneider - 4.7.0-0.2.rc1 +- Fix requirement generation for shared libraries + +* Wed Jul 05 2017 Andreas Schneider - 4.7.0-0.1.rc1 +- Build Samba with Active Directory support! + +* Mon Jun 12 2017 Guenther Deschner - 4.7.0-0.0.rc1 +- Update to Samba 4.7.0rc1 + +* Mon Jun 12 2017 Guenther Deschner - 4.6.5-0 +- Update to Samba 4.6.5 + +* Sun Jun 04 2017 Jitka Plesnikova - 2:4.6.4-1.1 +- Perl 5.26 rebuild + +* Wed May 24 2017 Andreas Schneider - 4.6.4-1 +- #resolves: #1451486 - Add source tarball comment + +* Wed May 24 2017 Guenther Deschner - 4.6.4-0 +- Update to Samba 4.6.4 +- resolves: #1455050 - Security fix for CVE-2017-7494 + +* Tue Apr 25 2017 Guenther Deschner - 4.6.3-0 +- Update to Samba 4.6.3 + +* Fri Mar 31 2017 Guenther Deschner - 4.6.2-0 +- Update to Samba 4.6.2 +- related: #1435156 - Security fix for CVE-2017-2619 + +* Thu Mar 23 2017 Guenther Deschner - 4.6.1-0 +- Update to Samba 4.6.1 +- resolves: #1435156 - Security fix for CVE-2017-2619 + +* Wed Mar 15 2017 Alexander Bokovoy - 4.6.0-4 +- Export arcfour_crypt_blob to Python as samba.crypto.arcfour_encrypt +- Makes possible to run trust to AD in FreeIPA in FIPS mode + +* Fri Mar 10 2017 Alexander Bokovoy - 4.6.0-3 +- auth/credentials: Always set the the realm if we set the principal from the ccache +- resolves: #1430761 - credentials_crb5: use gss_acquire_cred for client-side GSSAPI use case + +* Thu Mar 09 2017 Alexander Bokovoy - 4.6.0-2 +- resolves: #1430761 - credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case + +* Tue Mar 07 2017 Andreas Schneider - 4.6.0-1 +- Update to Samba 4.6.0 + +* Wed Mar 01 2017 Andreas Schneider - 4.6.0-0.3.rc4 +- Update to Samba 4.6.0rc4 + +* Tue Feb 14 2017 Andreas Schneider - 4.6.0-0.1.rc3 +- Update to Samba 4.6.0rc3 + +* Sat Feb 11 2017 Fedora Release Engineering - 4.6.0-0.1.rc2.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild + +* Fri Jan 27 2017 Guenther Deschner - 4.6.0-0.1.rc2 +- Update to Samba 4.6.0rc2 + +* Thu Jan 12 2017 Andreas Schneider - 4.6.0-0.1.rc1 +- resolves: #1319098 - Add missing Requires for pre-required packages + +* Thu Jan 05 2017 Guenther Deschner - 4.6.0-0.1.rc1 +- Update to Samba 4.6.0rc1 + +* Mon Dec 19 2016 Guenther Deschner - 4.5.3-0 +- Update to Samba 4.5.3 +- resolves: #1405984 - CVE-2016-2123,CVE-2016-2125 and CVE-2016-2126 + +* Wed Dec 07 2016 Guenther Deschner - 4.5.2-0 +- Update to Samba 4.5.2 + +* Mon Dec 05 2016 Rex Dieter - - +- rebuild (libldb) + +* Fri Nov 04 2016 Anoop C S - 4.5.1-1 +- Fix glfs_realpath allocation in vfs_glusterfs + +* Wed Oct 26 2016 Guenther Deschner - 4.5.1-0 +- Update to Samba 4.5.1 + +* Mon Oct 17 2016 Andreas Schneider - 4.5.0-3 +- resolves: 1375973 - Fix tevent incompatibility issue + +* Wed Sep 14 2016 Guenther Deschner - 4.5.0-2 +- Fix smbspool alternatives handling during samba-client uninstall + +* Wed Sep 07 2016 Guenther Deschner - 4.5.0-1 +- Update to Samba 4.5.0 + +* Mon Aug 29 2016 Guenther Deschner - 4.5.0rc3-0 +- Update to Samba 4.5.0rc3 + +* Mon Aug 15 2016 Guenther Deschner - 4.5.0rc2-0 +- Update to Samba 4.5.0rc2 + +* Thu Jul 28 2016 Guenther Deschner - 4.5.0rc1-0 +- Update to Samba 4.5.0rc1 + +* Tue Jul 19 2016 Fedora Release Engineering - 2:4.4.5-1.1 +- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages + +* Thu Jul 07 2016 Guenther Deschner - 4.4.5-1 +- Update to Samba 4.4.5 +- resolves: #1353504 - CVE-2016-2119 + +* Thu Jun 23 2016 Guenther Deschner - 4.4.4-4 +- resolves: #1348899 - Import of samba.ntacls fails + +* Mon Jun 20 2016 Andreas Schneider - 4.4.4-3 +- resolves: #1337260 - Small fix to the example smb.conf file + +* Wed Jun 15 2016 Andreas Schneider - 4.4.4-2 +- Fix resolving trusted domain users on domain member + +* Tue Jun 07 2016 Guenther Deschner - 4.4.4-1 +- Update to Samba 4.4.4 +- resolves: #1343529 + +* Wed May 25 2016 Alexander Bokovoy - 2:4.4.3-2 +- Fix libsystemd patch (#1125086) so that it actually works + +* Mon May 23 2016 Zbigniew Jędrzejewski-Szmek - 2:4.4.3-1.2 +- Rebuild to drop libsystemd-daemon dependency (#1125086) + +* Sun May 15 2016 Jitka Plesnikova - 2:4.4.3-1.1 +- Perl 5.24 rebuild + +* Mon May 02 2016 Guenther Deschner - 4.4.3-1 +- Update to Samba 4.4.3 +- resolves: #1332178 + +* Tue Apr 12 2016 Guenther Deschner - 4.4.2-1 +- Update to Samba 4.4.2, fix badlock security bug +- resolves: #1326453 - CVE-2015-5370 +- resolves: #1326453 - CVE-2016-2110 +- resolves: #1326453 - CVE-2016-2111 +- resolves: #1326453 - CVE-2016-2112 +- resolves: #1326453 - CVE-2016-2113 +- resolves: #1326453 - CVE-2016-2114 +- resolves: #1326453 - CVE-2016-2115 +- resolves: #1326453 - CVE-2016-2118 + +* Tue Mar 22 2016 Guenther Deschner - 4.4.0-1 +- Update to Samba 4.4.0 + +* Wed Mar 16 2016 Guenther Deschner - 4.4.0-0.8.rc5 +- Update to Samba 4.4.0rc5 + +* Tue Mar 08 2016 Guenther Deschner - 4.4.0-0.7.rc4 +- Update to Samba 4.4.0rc4 +- resolves: #1315942 - CVE-2015-7560 Incorrect ACL get/set allowed on symlink path + +* Tue Feb 23 2016 Guenther Deschner - 4.4.0-0.6.rc3 +- Update to Samba 4.4.0rc3 + +* Wed Feb 17 2016 Guenther Deschner - 4.4.0-0.5.rc2 +- Activate multi channel support (switched off by default) + +* Mon Feb 15 2016 Andreas Schneider - 4.4.0-0.4.rc2 +- More spec file fixes +- resolves: #1306542 - scriptlet failure because of comments + +* Mon Feb 15 2016 Andreas Schneider - 4.4.0-0.3.rc2 +- More spec file fixes + +* Mon Feb 15 2016 Andreas Schneider - 4.4.0-0.2.rc2 +- More spec file fixes + +* Wed Feb 10 2016 Guenther Deschner - 4.4.0-0.1.rc2 +- Update to Samba 4.4.0rc2 + +* Thu Feb 04 2016 Fedora Release Engineering - 2:4.4.0-0.1.rc1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild + +* Wed Jan 27 2016 Guenther Deschner - 4.4.0-0.0.rc1 +- Update to Samba 4.4.0rc1 + +* Fri Jan 22 2016 Alexander Bokovoy - 4.3.4-1 +- resolves: #1300038 - PANIC: Bad talloc magic value - wrong talloc version used/mixed + +* Tue Jan 12 2016 Guenther Deschner - 4.3.4-0 +- resolves: #1261230 - Update to Samba 4.3.4 + +* Wed Dec 16 2015 Guenther Deschner - 4.3.3-0 +- Update to Samba 4.3.3 +- resolves: #1292069 +- CVE-2015-3223 Remote DoS in Samba (AD) LDAP server +- CVE-2015-5252 Insufficient symlink verification in smbd +- CVE-2015-5296 Samba client requesting encryption vulnerable to + downgrade attack +- CVE-2015-5299 Missing access control check in shadow copy code +- CVE-2015-7540 DoS to AD-DC due to insufficient checking of asn1 + memory allocation + +* Tue Dec 15 2015 Guenther Deschner - 4.3.2-2 +- revert dependencies to samba-common and -tools + +* Tue Dec 01 2015 Guenther Deschner - 4.3.2-1 +- resolves: #1261230 - Update to Samba 4.3.2 + +* Wed Nov 18 2015 Guenther Deschner - 4.3.1-3 +- resolves: #1282931 - Fix DCE/RPC bind nak parsing + +* Fri Oct 23 2015 Guenther Deschner - 4.3.1-2 +- Fix dependencies to samba-common + +* Tue Oct 20 2015 Guenther Deschner - 4.3.1-1 +- resolves: #1261230 - Update to Samba 4.3.1 + +* Mon Oct 12 2015 Guenther Deschner - 4.3.0-3 +- Use separate lockdir + +* Mon Oct 12 2015 Guenther Deschner - 4.3.0-2 +- resolves: #1270568 - Samba fails to start after update to 4.3.0 + +* Tue Sep 08 2015 Guenther Deschner - 4.3.0-1 +- resolves: #1088911 - Update to Samba 4.3.0 + +* Tue Sep 01 2015 Andreas Schneider - 4.3.0-0.1rc4 +- Update to Samba 4.3.0rc4 + +* Mon Aug 31 2015 Andreas Schneider - 4.3.0-0.1rc3 +- Update to Samba 4.3.0rc3 + +* Tue Jul 14 2015 Guenther Deschner - 4.2.3-0 +- resolves: #1088911 - Update to Samba 4.2.3 + +* Fri Jun 19 2015 Andreas Schneider - 4.2.2-1 +- resolves: #1227911 - Enable tar support for smbclient +- resolves: #1234908 - Own the /var/lib/samba directory +- Enable hardened build + +* Fri Jun 19 2015 Fedora Release Engineering - 2:4.2.2-0.2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild + +* Thu Jun 04 2015 Jitka Plesnikova - 2:4.2.2-0.1 +- Perl 5.22 rebuild + +* Thu May 28 2015 Guenther Deschner - 4.2.2-0 +- Update to Samba 4.2.2 + +* Mon May 11 2015 Alexander Bokovoy - 4.2.1-8 +- Fixes: #1219832: Samba 4.2 broke FreeIPA trusts to AD +- Remove usage of deprecated API from gnutls + +* Thu Apr 30 2015 Alexander Bokovoy - 4.2.1-7 +- Fix LSASD daemon +- resolves: #1217346 - FreeIPA trusts to AD broken due to Samba 4.2 failure to run LSARPC pipe externally + +* Mon Apr 27 2015 Alexander Bokovoy - 4.2.1-6 +- Remove samba-common-tools from samba-client package as it brings back Python 2.7 + +* Mon Apr 27 2015 Alexander Bokovoy - 4.2.1-5 +- Require samba-common-tools in samba package +- Require samba-common-tools in samba-client package +- resolves: #1215631 - /usr/bin/net moved to samba-common-tools but the package is not required by samba + +* Sat Apr 25 2015 Alexander Bokovoy - 4.2.1-4 +- Fix systemd library detection (incomplete patch upstream) + +* Fri Apr 24 2015 Andreas Schneider - 4.2.1-3 +- resolves: #1214973 - Fix libwbclient alternatives link. + +* Wed Apr 22 2015 Guenther Deschner - 4.2.1-2 +- Add vfs snapper module. + +* Tue Apr 21 2015 Andreas Schneider - 4.2.1-1 +- Update to Samba 4.2.1 +- resolves: #1213373 - Fix DEBUG macro issues in public headers + +* Wed Apr 08 2015 Andreas Schneider - 4.2.0-3 +- resolves: #1207381 - Fix libsystemd detection. + +* Tue Mar 10 2015 Andreas Schneider - 4.2.0-2 +- Fix the AD build. +- Create samba-client-libs subpackage. +- Fix multiarch issues by splitting the samba-common package. + +* Thu Mar 05 2015 Guenther Deschner - 4.2.0-1 +- Update to Samba 4.2.0 + +* Tue Mar 03 2015 Andreas Schneider - 4.2.0-0.5.rc5 +- Update to Samba 4.2.0rc5 + +* Fri Jan 16 2015 - Andreas Schneider - 4.2.0-0.4.rc4 +- Update to Samba 4.2.0rc4 +- resolves: #1154600 - Install missing samba pam.d configuration file. + +* Mon Jan 12 2015 Guenther Deschner - 4.2.0-0.6.rc3 +- Fix awk as a dependency (and require gawk) + +* Mon Jan 12 2015 Michael Adam - 4.2.0-0.5.rc3 +- Add dependencies for ctdb. + +* Fri Jan 09 2015 Stephen Gallagher 4.2.0-0.4.rc3 +- Apply the DEBUG patch + +* Fri Jan 09 2015 Andreas Schneider - 4.2.0-0.3.rc3 +- Fix issues with conflicting DEBUG macros. + +* Tue Jan 06 2015 Michael Adam - 4.2.0-0.2.rc3 +- Improve dependencies of vfs-glusterfs and vfs-cephfs. +- Remove unused python_libdir. +- Fix malformed changelog entries. + +* Tue Jan 06 2015 Guenther Deschner - 4.2.0-0.2.rc3 +- Fix ctdb and libcephfs dependencies. + +* Mon Jan 05 2015 Andreas Schneider - 4.2.0-0.1.rc3 +- Update to Samba 4.2.0rc3 + + Samba provides ctdb packages now. + +* Tue Dec 16 2014 Andreas Schneider - 4.2.0-0.3.rc2 +- resolves: #1174412 - Build VFS Ceph module. +- resolves: #1169067 - Move libsamba-cluster-support.so to samba-libs package. +- resolves: #1016122 - Move smbpasswd to samba-common package. + +* Fri Nov 21 2014 Andreas Schneider - 4.2.0-0.2.rc2 +- Use alternatives for libwbclient. +- Add cwrap to BuildRequires. + +* Wed Nov 12 2014 Andreas Schneider - 4.2.0-0.1.rc2 +- Update to Samba 4.2.0rc2. + +* Tue Oct 07 2014 Andreas Schneider - 4.1.12-5 +- resolves: #1033595 - Fix segfault in winbind. + +* Wed Sep 24 2014 Andreas Schneider - 4.1.12-1 +- Update to Samba 4.1.12. + +* Tue Sep 09 2014 Jitka Plesnikova - 2:4.1.11-1.4 +- Perl 5.20 mass + +* Wed Aug 27 2014 Jitka Plesnikova - 2:4.1.11-1.3 +- Perl 5.20 rebuild + +* Wed Aug 20 2014 Kalev Lember - 2:4.1.11-1.2 +- Rebuilt for rpm dependency generator failure (#1131892) + +* Mon Aug 18 2014 Fedora Release Engineering - 0:4.1.11-1.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild + +* Fri Aug 1 2014 Jared Smith - 4.1.11-1 +- Update to upstream Samba 4.1.11 release +- resolves: #1126015 - Fix CVE-2014-3560 + +* Mon Jun 23 2014 Guenther Deschner - 4.1.9-3 +- Update to Samba 4.1.9. +- resolves: #1112251 - Fix CVE-2014-0244 and CVE-2014-3493. + +* Wed Jun 11 2014 Guenther Deschner - 4.1.8-3 +- Update to Samba 4.1.8. +- resolves: #1102528 - CVE-2014-0178. + +* Sun Jun 08 2014 Fedora Release Engineering - 2:4.1.6-3.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild + +* Thu Apr 03 2014 Andreas Schneider - 4.1.6-3 +- Add systemd integration to the service daemons. + +* Tue Mar 18 2014 Andreas Schneider - 4.1.6-2 +- Created a samba-test-libs package. + +* Tue Mar 11 2014 Andreas Schneider - 4.1.6-1 +- Fix CVE-2013-4496 and CVE-2013-6442. +- Fix installation of pidl. + +* Fri Feb 21 2014 Andreas Schneider - 4.1.5-1 +- Update to Samba 4.1.5. + +* Fri Feb 07 2014 Andreas Schneider - 4.1.4-1 +- Update to Samba 4.1.4. + +* Wed Jan 08 2014 Andreas Schneider - 4.1.3-3 +- resolves: #1042845 - Do not build with libbsd. + +* Tue Dec 10 2013 Guenther Deschner - 4.1.3-2 +- resolves: #1019469 - Fix winbind debug message NULL pointer derreference. + +* Mon Dec 09 2013 Andreas Schneider - 4.1.3-1 +- Update to Samba 4.1.3. +- resolves: #1039454 - CVE-2013-4408. +- resolves: #1039500 - CVE-2012-6150. + +* Mon Nov 25 2013 Andreas Schneider - 4.1.2-1 +- Update to Samba 4.1.2. + +* Mon Nov 18 2013 Guenther Deschner - 4.1.1-3 +- resolves: #948509 - Fix manpage correctness. + +* Fri Nov 15 2013 Andreas Schneider - 4.1.1-2 +- related: #884169 - Fix strict aliasing warnings. + +* Mon Nov 11 2013 Andreas Schneider - 4.1.1-1 +- resolves: #1024544 - Fix CVE-2013-4475. +- Update to Samba 4.1.1. + +* Mon Nov 11 2013 Andreas Schneider - 4.1.0-5 +- related: #884169 - Fix the upgrade path. + +* Wed Oct 30 2013 Andreas Schneider - 4.1.0-4 +- related: #884169 - Add direct dependency to samba-libs in the + glusterfs package. +- resolves: #996567 - Fix userPrincipalName composition. +- related: #884169 - Fix memset call with zero length in in ntdb. + +* Fri Oct 18 2013 Andreas Schneider - 4.1.0-3 +- resolves: #1020329 - Build glusterfs VFS plguin. + +* Tue Oct 15 2013 Andreas Schneider - 4.1.0-2 +- resolves: #1018856 - Fix installation of pam_winbind after upgrade. +- related: #1010722 - Split out a samba-winbind-modules package. +- related: #985609 + +* Fri Oct 11 2013 Andreas Schneider - 4.1.0-1 +- related: #985609 - Update to Samba 4.1.0. + +* Tue Oct 01 2013 Andreas Schneider - 2:4.1.0-0.8 +- related: #985609 - Update to Samba 4.1.0rc4. +- resolves: #1010722 - Split out a samba-winbind-modules package. + +* Wed Sep 11 2013 Andreas Schneider - 2:4.1.0-0.7 +- related: #985609 - Update to Samba 4.1.0rc3. +- resolves: #1005422 - Add support for KEYRING ccache type in pam_winbindd. + +* Wed Sep 04 2013 Andreas Schneider - 2:4.1.0-0.6 +- resolves: #717484 - Enable profiling data support. + +* Thu Aug 22 2013 Guenther Deschner - 2:4.1.0-0.5 +- resolves: #996160 - Fix winbind with trusted domains. + +* Wed Aug 14 2013 Andreas Schneider 2:4.1.0-0.4 +- resolves: #996160 - Fix winbind nbt name lookup segfault. + +* Mon Aug 12 2013 Andreas Schneider - 2:4.1.0-0.3 +- related: #985609 - Update to Samba 4.1.0rc2. + +* Sat Aug 03 2013 Petr Pisar - 2:4.1.0-0.2.rc1.1 +- Perl 5.18 rebuild + +* Wed Jul 24 2013 Andreas Schneider - 2:4.1.0-0.2 +- resolves: #985985 - Fix file conflict between samba and wine. +- resolves: #985107 - Add support for new default location for Kerberos + credential caches. + +* Sat Jul 20 2013 Petr Pisar - 2:4.1.0-0.1.rc1.1 +- Perl 5.18 rebuild + +* Wed Jul 17 2013 Andreas Schneider - 2:4.1.0-0.1 +- Update to Samba 4.1.0rc1. + +* Mon Jul 15 2013 Andreas Schneider - 2:4.0.7-2 +- resolves: #972692 - Build with PIE and full RELRO. +- resolves: #884169 - Add explicit dependencies suggested by rpmdiff. +- resolves: #981033 - Local user's krb5cc deleted by winbind. +- resolves: #984331 - Fix samba-common tmpfiles configuration file in wrong + directory. + +* Wed Jul 03 2013 Andreas Schneider - 2:4.0.7-1 +- Update to Samba 4.0.7. + +* Fri Jun 07 2013 Andreas Schneider - 2:4.0.6-3 +- Add UPN enumeration to passdb internal API (bso #9779). + +* Wed May 22 2013 Andreas Schneider - 2:4.0.6-2 +- resolves: #966130 - Fix build with MIT Kerberos. +- List vfs modules in spec file. + +* Tue May 21 2013 Andreas Schneider - 2:4.0.6-1 +- Update to Samba 4.0.6. +- Remove SWAT. + +* Wed Apr 10 2013 Andreas Schneider - 2:4.0.5-1 +- Update to Samba 4.0.5. +- Add UPN enumeration to passdb internal API (bso #9779). +- resolves: #928947 - samba-doc is obsolete now. +- resolves: #948606 - LogRotate should be optional, and not a hard "Requires". + +* Fri Mar 22 2013 Andreas Schneider - 2:4.0.4-3 +- resolves: #919405 - Fix and improve large_readx handling for broken clients. +- resolves: #924525 - Don't use waf caching. + +* Wed Mar 20 2013 Andreas Schneider - 2:4.0.4-2 +- resolves: #923765 - Improve packaging of README files. + +* Wed Mar 20 2013 Andreas Schneider - 2:4.0.4-1 +- Update to Samba 4.0.4. + +* Mon Mar 11 2013 Andreas Schneider - 2:4.0.3-4 +- resolves: #919333 - Create /run/samba too. + +* Mon Mar 04 2013 Andreas Schneider - 2:4.0.3-3 +- Fix the cache dir to be /var/lib/samba to support upgrades. + +* Thu Feb 14 2013 Andreas Schneider - 2:4.0.3-2 +- resolves: #907915 - libreplace.so => not found + +* Thu Feb 07 2013 Andreas Schneider - 2:4.0.3-1 +- Update to Samba 4.0.3. +- resolves: #907544 - Add unowned directory /usr/lib64/samba. +- resolves: #906517 - Fix pidl code generation with gcc 4.8. +- resolves: #908353 - Fix passdb backend ldapsam as module. + +* Wed Jan 30 2013 Andreas Schneider - 2:4.0.2-1 +- Update to Samba 4.0.2. +- Fixes CVE-2013-0213. +- Fixes CVE-2013-0214. +- resolves: #906002 +- resolves: #905700 +- resolves: #905704 +- Fix conn->share_access which is reset between user switches. +- resolves: #903806 +- Add missing example and make sure we don't introduce perl dependencies. +- resolves: #639470 + +* Wed Jan 16 2013 Andreas Schneider - 2:4.0.1-1 +- Update to Samba 4.0.1. +- Fixes CVE-2013-0172. + +* Mon Dec 17 2012 Andreas Schneider - 2:4.0.0-174 +- Fix typo in winbind-krb-locator post uninstall script. + +* Tue Dec 11 2012 Andreas Schneider - 2:4.0.0-173 +- Update to Samba 4.0.0. + +* Thu Dec 06 2012 Andreas Schneider - 2:4.0.0-171.rc6 +- Fix typo in winbind-krb-locator post uninstall script. + +* Tue Dec 04 2012 Andreas Schneider - 2:4.0.0-170.rc6 +- Update to Samba 4.0.0rc6. +- Add /etc/pam.d/samba for swat to work correctly. +- resolves #882700 + +* Fri Nov 23 2012 Guenther Deschner - 2:4.0.0-169.rc5 +- Make sure ncacn_ip_tcp client code looks for NBT_NAME_SERVER name types. + +* Thu Nov 15 2012 Andreas Schneider - 2:4.0.0-168.rc5 +- Reduce dependencies of samba-devel and create samba-test-devel package. + +* Tue Nov 13 2012 Andreas Schneider - 2:4.0.0-167.rc5 +- Use workaround for winbind default domain only when set. +- Build with old ctdb support. + +* Tue Nov 13 2012 Andreas Schneider - 2:4.0.0-166.rc5 +- Update to Samba 4.0.0rc5. + +* Mon Nov 05 2012 Andreas Schneider - 2:4.0.0-165.rc4 +- Fix library dependencies of libnetapi. + +* Mon Nov 05 2012 Andreas Schneider - 2:4.0.0-164.rc4 +- resolves: #872818 - Fix perl dependencies. + +* Tue Oct 30 2012 Andreas Schneider - 2:4.0.0-163.rc4 +- Update to Samba 4.0.0rc4. + +* Mon Oct 29 2012 Andreas Schneider - 2:4.0.0-162.rc3 +- resolves: #870630 - Fix scriptlets interpeting a comment as argument. + +* Fri Oct 26 2012 Andreas Schneider - 2:4.0.0-161.rc3 +- Add missing Requries for python modules. +- Add NetworkManager dispatcher script for winbind. + +* Fri Oct 19 2012 Andreas Schneider - 2:4.0.0-160.rc3 +- resolves: #867893 - Move /var/log/samba to samba-common package for + winbind which requires it. + +* Thu Oct 18 2012 Andreas Schneider - 2:4.0.0-159.rc3 +- Compile default auth methods into smbd. + +* Tue Oct 16 2012 Andreas Schneider - 2:4.0.0-158.rc3 +- Move pam_winbind.conf and the manpages to the right package. + +* Tue Oct 16 2012 Andreas Schneider - 2:4.0.0-157.rc3 +* resolves: #866959 - Build auth_builtin as static module. + +* Tue Oct 16 2012 Andreas Schneider - 2:4.0.0-156.rc3 +- Update systemd Requires to reflect latest packaging guidelines. + +* Tue Oct 16 2012 Andreas Schneider - 2:4.0.0-155.rc3 +- Add back the AES patches which didn't make it in rc3. + +* Tue Oct 16 2012 Andreas Schneider - 2:4.0.0-154.rc3 +- Update to 4.0.0rc3. +- resolves: #805562 - Unable to share print queues. +- resolves: #863388 - Unable to reload smbd configuration with systemctl. + +* Wed Oct 10 2012 Alexander Bokovoy - 2:4.0.0-153.rc2 +- Use alternatives to configure winbind_krb5_locator.so +- Fix Requires for winbind. + +* Thu Oct 04 2012 Andreas Schneider - 2:4.0.0-152.rc2 +- Add kerberos AES support. +- Fix printing initialization. + +* Tue Oct 02 2012 Andreas Schneider - 2:4.0.0-151.rc2 +- Update to 4.0.0rc2. + +* Wed Sep 26 2012 Andreas Schneider - 2:4.0.0-150.rc1 +- Fix Obsoletes/Provides for update from samba4. +- Bump release number to be bigger than samba4. + +* Wed Sep 26 2012 Andreas Schneider - 2:4.0.0-96.rc1 +- Package smbprint again. + +* Wed Sep 26 2012 Andreas Schneider - 2:4.0.0-95.rc1 +- Update to 4.0.0rc1. + +* Mon Aug 20 2012 Guenther Deschner - 2:3.6.7-94.2 +- Update to 3.6.7 + +* Sat Jul 21 2012 Fedora Release Engineering - 2:3.6.6-93.2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild + +* Thu Jul 19 2012 Guenther Deschner - 2:3.6.6-93 +- Fix printing tdb upgrade for 3.6.6 +- resolves: #841609 + +* Sun Jul 15 2012 Ville Skyttä - 2:3.6.6-92 +- Call ldconfig at libwbclient and -winbind-clients post(un)install time. +- Fix empty localization files, use %%find_lang to find and %%lang-mark them. +- Escape macros in %%changelog. +- Fix source tarball URL. + +* Tue Jun 26 2012 Guenther Deschner - 2:3.6.6-91 +- Update to 3.6.6 + +* Thu Jun 21 2012 Andreas Schneider - 2:3.6.5-90 +- Fix ldonfig. +- Require systemd for samba-common package. +- resolves: #829197 + +* Mon Jun 18 2012 Andreas Schneider - 2:3.6.5-89 +- Fix usrmove paths. +- resolves: #829197 + +* Tue May 15 2012 Andreas Schneider - 2:3.6.5-88 +- Move tmpfiles.d config to common package as it is needed for smbd and + winbind. +- Make sure tmpfiles get created after installation. + +* Wed May 09 2012 Guenther Deschner - 2:3.6.5-87 +- Correctly use system iniparser library + +* Fri May 04 2012 Andreas Schneider - 2:3.6.5-86 +- Bump Epoch to fix a problem with a Samba4 update in testing. + +* Mon Apr 30 2012 Guenther Deschner - 1:3.6.5-85 +- Security Release, fixes CVE-2012-2111 +- resolves: #817551 + +* Mon Apr 23 2012 Andreas Schneider - 1:3.6.4-84 +- Fix creation of /var/run/samba. +- resolves: #751625 + +* Fri Apr 20 2012 Guenther Deschner - 1:3.6.4-83 +- Avoid private krb5_locate_kdc usage +- resolves: #754783 + +* Thu Apr 12 2012 Jon Ciesla - 1:3.6.4-82 +- Update to 3.6.4 +- Fixes CVE-2012-1182 + +* Mon Mar 19 2012 Andreas Schneider - 1:3.6.3-81 +- Fix provides for of libwclient-devel for samba-winbind-devel. + +* Thu Feb 23 2012 Andreas Schneider - 1:3.6.3-80 +- Add commented out 'max protocol' to the default config. + +* Mon Feb 13 2012 Andreas Schneider - 1:3.6.3-79 +- Create a libwbclient package. +- Replace winbind-devel with libwbclient-devel package. + +* Mon Jan 30 2012 Andreas Schneider - 1:3.6.3-78 +- Update to 3.6.3 +- Fixes CVE-2012-0817 + +* Sat Jan 14 2012 Fedora Release Engineering - 1:3.6.1-77.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild + +* Mon Dec 05 2011 Andreas Schneider - 1:3.6.1-77 +- Fix winbind cache upgrade. +- resolves: #760137 + +* Fri Nov 18 2011 Andreas Schneider - 1:3.6.1-76 +- Fix piddir to match with systemd files. +- Fix crash bug in the debug system. +- resolves: #754525 + +* Fri Nov 04 2011 Andreas Schneider - 1:3.6.1-75 +- Fix systemd dependencies +- resolves: #751397 + +* Wed Oct 26 2011 Andreas Schneider - 1:3.6.1-74 +- Update to 3.6.1 + +* Tue Oct 04 2011 Guenther Deschner - 1:3.6.0-73 +- Fix nmbd startup +- resolves: #741630 + +* Tue Sep 20 2011 Tom Callaway - 1:3.6.0-72 +- convert to systemd +- restore epoch from f15 + +* Sat Aug 13 2011 Guenther Deschner - 3.6.0-71 +- Update to 3.6.0 final + +* Sun Jul 31 2011 Guenther Deschner - 3.6.0rc3-70 +- Update to 3.6.0rc3 + +* Tue Jun 07 2011 Guenther Deschner - 3.6.0rc2-69 +- Update to 3.6.0rc2 + +* Tue May 17 2011 Guenther Deschner - 3.6.0rc1-68 +- Update to 3.6.0rc1 + +* Wed Apr 27 2011 Guenther Deschner - 3.6.0pre3-67 +- Update to 3.6.0pre3 + +* Wed Apr 13 2011 Guenther Deschner - 3.6.0pre2-66 +- Update to 3.6.0pre2 + +* Fri Mar 11 2011 Guenther Deschner - 3.6.0pre1-65 +- Enable quota support + +* Wed Feb 09 2011 Fedora Release Engineering - 0:3.6.0-64pre1.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild + +* Wed Nov 24 2010 Guenther Deschner - 3.6.0pre1-64 +- Add %%ghost entry for /var/run using tmpfs +- resolves: #656685 + +* Thu Aug 26 2010 Guenther Deschner - 3.6.0pre1-63 +- Put winbind krb5 locator plugin into a separate rpm +- resolves: #627181 + +* Tue Aug 03 2010 Guenther Deschner - 3.6.0pre1-62 +- Update to 3.6.0pre1 + +* Wed Jun 23 2010 Guenther Deschner - 3.5.4-61 +- Update to 3.5.4 + +* Wed May 19 2010 Guenther Deschner - 3.5.3-60 +- Update to 3.5.3 +- Make sure nmb and smb initscripts return LSB compliant return codes +- Fix winbind over ipv6 + +* Wed Apr 07 2010 Guenther Deschner - 3.5.2-59 +- Update to 3.5.2 + +* Mon Mar 08 2010 Simo Sorce - 3.5.1-58 +- Security update to 3.5.1 +- Fixes CVE-2010-0728 + +* Mon Mar 08 2010 Guenther Deschner - 3.5.0-57 +- Remove cifs.upcall and mount.cifs entirely + +* Mon Mar 01 2010 Guenther Deschner - 3.5.0-56 +- Update to 3.5.0 + +* Fri Feb 19 2010 Guenther Deschner - 3.5.0rc3-55 +- Update to 3.5.0rc3 + +* Tue Jan 26 2010 Guenther Deschner - 3.5.0rc2-54 +- Update to 3.5.0rc2 + +* Fri Jan 15 2010 Jeff Layton - 3.5.0rc1-53 +- separate out CIFS tools into cifs-utils package + +* Fri Jan 08 2010 Guenther Deschner - 3.5.0rc1-52 +- Update to 3.5.0rc1 + +* Tue Dec 15 2009 Guenther Deschner - 3.5.0pre2-51 +- Update to 3.5.0pre2 +- Remove umount.cifs + +* Wed Nov 25 2009 Guenther Deschner - 3.4.3-49 +- Various updates to inline documentation in default smb.conf file +- resolves: #483703 + +* Thu Oct 29 2009 Guenther Deschner - 3.4.3-48 +- Update to 3.4.3 + +* Fri Oct 09 2009 Simo Sorce - 3.4.2-47 +- Spec file cleanup +- Fix sources upstream location +- Remove conditionals to build talloc and tdb, now they are completely indepent + packages in Fedora +- Add defattr() where missing +- Turn all tabs into 4 spaces +- Remove unused migration script +- Split winbind-clients out of main winbind package to avoid multilib to include + huge packages for no good reason + +* Thu Oct 01 2009 Guenther Deschner - 3.4.2-0.46 +- Update to 3.4.2 +- Security Release, fixes CVE-2009-2813, CVE-2009-2948 and CVE-2009-2906 + +* Wed Sep 16 2009 Tomas Mraz - 3.4.1-0.45 +- Use password-auth common PAM configuration instead of system-auth + +* Wed Sep 09 2009 Guenther Deschner - 3.4.1-0.44 +- Update to 3.4.1 + +* Thu Aug 20 2009 Guenther Deschner - 3.4.0-0.43 +- Fix cli_read() +- resolves: #516165 + +* Thu Aug 06 2009 Guenther Deschner - 3.4.0-0.42 +- Fix required talloc version number +- resolves: #516086 + +* Sun Jul 26 2009 Fedora Release Engineering - 0:3.4.0-0.41.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild + +* Fri Jul 17 2009 Guenther Deschner - 3.4.0-0.41 +- Fix Bug #6551 (vuid and tid not set in sessionsetupX and tconX) +- Specify required talloc and tdb version for BuildRequires + +* Fri Jul 03 2009 Guenther Deschner - 3.4.0-0.40 +- Update to 3.4.0 + +* Fri Jun 19 2009 Guenther Deschner - 3.4.0rc1-0.39 +- Update to 3.4.0rc1 + +* Mon Jun 08 2009 Guenther Deschner - 3.4.0pre2-0.38 +- Update to 3.4.0pre2 + +* Thu Apr 30 2009 Guenther Deschner - 3.4.0pre1-0.37 +- Update to 3.4.0pre1 + +* Wed Apr 29 2009 Guenther Deschner - 3.3.4-0.36 +- Update to 3.3.4 + +* Mon Apr 20 2009 Guenther Deschner - 3.3.3-0.35 +- Enable build of idmap_tdb2 for clustered setups + +* Wed Apr 1 2009 Guenther Deschner - 3.3.3-0.34 +- Update to 3.3.3 + +* Thu Mar 26 2009 Simo Sorce - 3.3.2-0.33 +- Fix nmbd init script nmbd reload was causing smbd not nmbd to reload the + configuration +- Fix upstream bug 6224, nmbd was waiting 5+ minutes before running elections on + startup, causing your own machine not to show up in the network for 5 minutes + if it was the only client in that workgroup (fix committed upstream) + +* Thu Mar 12 2009 Guenther Deschner - 3.3.2-0.31 +- Update to 3.3.2 +- resolves: #489547 + +* Thu Mar 5 2009 Guenther Deschner - 3.3.1-0.30 +- Add libcap-devel to requires list (resolves: #488559) + +* Tue Mar 3 2009 Simo Sorce - 3.3.1-0.29 +- Make the talloc and ldb packages optionsl and disable their build within + the samba3 package, they are now built as part of the samba4 package + until they will both be released as independent packages. + +* Wed Feb 25 2009 Guenther Deschner - 3.3.1-0.28 +- Enable cluster support + +* Tue Feb 24 2009 Guenther Deschner - 3.3.1-0.27 +- Update to 3.3.1 + +* Sat Feb 21 2009 Simo Sorce - 3.3.0-0.26 +- Rename ldb* tools to ldb3* to avoid conflicts with newer ldb releases + +* Tue Feb 3 2009 Guenther Deschner - 3.3.0-0.25 +- Update to 3.3.0 final +- Add upstream fix for ldap connections to AD (Bug #6073) +- Remove bogus perl dependencies (resolves: #473051) + +* Fri Nov 28 2008 Guenther Deschner - 3.3.0-0rc1.24 +- Update to 3.3.0rc1 + +* Thu Nov 27 2008 Simo Sorce - 3.2.5-0.23 +- Security Release, fixes CVE-2008-4314 + +* Thu Sep 18 2008 Guenther Deschner - 3.2.4-0.22 +- Update to 3.2.4 +- resolves: #456889 +- move cifs.upcall to /usr/sbin + +* Wed Aug 27 2008 Guenther Deschner - 3.2.3-0.21 +- Security fix for CVE-2008-3789 + +* Mon Aug 25 2008 Guenther Deschner - 3.2.2-0.20 +- Update to 3.2.2 + +* Mon Aug 11 2008 Simo Sorce - 3.2.1-0.19 +- Add fix for CUPS problem, fixes bug #453951 + +* Wed Aug 6 2008 Simo Sorce - 3.2.1-0.18 +- Update to 3.2.1 + +* Tue Jul 1 2008 Guenther Deschner - 3.2.0-2.17 +- Update to 3.2.0 final +- resolves: #452622 + +* Tue Jun 10 2008 Guenther Deschner - 3.2.0-1.rc2.16 +- Update to 3.2.0rc2 +- resolves: #449522 +- resolves: #448107 + +* Fri May 30 2008 Guenther Deschner - 3.2.0-1.rc1.15 +- Fix security=server +- resolves: #449038, #449039 + +* Wed May 28 2008 Guenther Deschner - 3.2.0-1.rc1.14 +- Add fix for CVE-2008-1105 +- resolves: #446724 + +* Fri May 23 2008 Guenther Deschner - 3.2.0-1.rc1.13 +- Update to 3.2.0rc1 + +* Wed May 21 2008 Simo Sorce - 3.2.0-1.pre3.12 +- make it possible to print against Vista and XP SP3 as servers +- resolves: #439154 + +* Thu May 15 2008 Guenther Deschner - 3.2.0-1.pre3.11 +- Add "net ads join createcomputer=ou1/ou2/ou3" fix (BZO #5465) + +* Fri May 09 2008 Guenther Deschner - 3.2.0-1.pre3.10 +- Add smbclient fix (BZO #5452) + +* Fri Apr 25 2008 Guenther Deschner - 3.2.0-1.pre3.9 +- Update to 3.2.0pre3 + +* Tue Mar 18 2008 Guenther Deschner - 3.2.0-1.pre2.8 +- Add fixes for libsmbclient and support for r/o relocations + +* Mon Mar 10 2008 Guenther Deschner - 3.2.0-1.pre2.7 +- Fix libnetconf, libnetapi and msrpc DSSETUP call + +* Thu Mar 06 2008 Guenther Deschner - 3.2.0-1.pre2.6 +- Create separate packages for samba-winbind and samba-winbind-devel +- Add cifs.spnego helper + +* Wed Mar 05 2008 Guenther Deschner - 3.2.0-1.pre2.3 +- Update to 3.2.0pre2 +- Add talloc and tdb lib and devel packages +- Add domainjoin-gui package + +* Fri Feb 22 2008 Simo Sorce - 3.2.0-0.pre1.3 +- Try to fix GCC 4.3 build +- Add --with-dnsupdate flag and also make sure other flags are required just to + be sure the features are included without relying on autodetection to be + successful + +* Tue Feb 19 2008 Fedora Release Engineering - 0:3.2.0-1.pre1.2 +- Autorebuild for GCC 4.3 + +* Tue Dec 04 2007 Release Engineering - 3.2.0-0.pre1.2 +- Rebuild for openldap bump + +* Thu Oct 18 2007 Guenther Deschner 3.2.0-0.pre1.1.fc9 +- 32/64bit padding fix (affects multilib installations) + +* Mon Oct 8 2007 Simo Sorce 3.2.0-0.pre1.fc9 +- New major relase, minor switched from 0 to 2 +- License change, the code is now GPLv3+ +- Numerous improvements and bugfixes included +- package libsmbsharemodes too +- remove smbldap-tools as they are already packaged separately in Fedora +- Fix bug 245506 + +* Tue Oct 2 2007 Simo Sorce 3.0.26a-1.fc8 +- rebuild with AD DNS Update support + +* Tue Sep 11 2007 Simo Sorce 3.0.26a-0.fc8 +- upgrade to the latest upstream realease +- includes security fixes released today in 3.0.26 + +* Fri Aug 24 2007 Simo Sorce 3.0.25c-4.fc8 +- add fix reported upstream for heavy idmap_ldap memleak + +* Tue Aug 21 2007 Simo Sorce 3.0.25c-3.fc8 +- fix a few places were "open" is used an interfere with the new glibc + +* Tue Aug 21 2007 Simo Sorce 3.0.25c-2.fc8 +- remove old source +- add patch to fix samba bugzilla 4772 + +* Tue Aug 21 2007 Guenther Deschner 3.0.25c-0.fc8 +- update to 3.0.25c + +* Fri Jun 29 2007 Simo Sorce 3.0.25b-3.fc8 +- handle cases defined in #243766 + +* Tue Jun 26 2007 Simo Sorce 3.0.25b-2.fc8 +- update to 3.0.25b +- better error codes for init scripts: #244823 + +* Tue May 29 2007 Günther Deschner +- fix pam_smbpass patch. + +* Fri May 25 2007 Simo Sorce +- update to 3.0.25a as it contains many fixes +- add a fix for pam_smbpass made by Günther but committed upstream after 3.0.25a was cut. + +* Mon May 14 2007 Simo Sorce +- final 3.0.25 +- includes security fixes for CVE-2007-2444,CVE-2007-2446,CVE-2007-2447 + +* Mon Apr 30 2007 Günther Deschner +- move to 3.0.25rc3 + +* Thu Apr 19 2007 Simo Sorce +- fixes in the spec file +- moved to 3.0.25rc1 +- addedd patches (merged upstream so they will be removed in 3.0.25rc2) + +* Wed Apr 4 2007 Simo Sorce 3.0.24-12.fc7 +- fixes in smb.conf +- advice in smb.conf to put scripts in /var/lib/samba/scripts +- create /var/lib/samba/scripts so that selinux can be happy +- fix Vista problems with msdfs errors + +* Tue Apr 03 2007 Guenther Deschner 3.0.24-11.fc7 +- enable PAM and NSS dlopen checks during build +- fix unresolved symbols in libnss_wins.so (bug #198230) + +* Fri Mar 30 2007 Simo Sorce 3.0.24-10.fc7 +- set passdb backend = tdbsam as default in smb.conf +- remove samba-docs dependency from swat, that was a mistake +- put back COPYING and other files in samba-common +- put examples in samba not in samba-docs +- leave only stuff under docs/ in samba-doc + +* Thu Mar 29 2007 Simo Sorce 3.0.24-9.fc7 +- integrate most of merge review proposed changes (bug #226387) +- remove libsmbclient-devel-static and simply stop shipping the + static version of smbclient as it seem this is deprecated and + actively discouraged + +* Wed Mar 28 2007 Simo Sorce 3.0.24-8.fc7 +- fix for bug #176649 + +* Mon Mar 26 2007 Simo Sorce +- remove patch for bug 106483 as it introduces a new bug that prevents + the use of a credentials file with the smbclient tar command +- move the samba private dir from being the same as the config dir + (/etc/samba) to /var/lib/samba/private + +* Mon Mar 26 2007 Simo Sorce 3.0.24-7.fc7 +- make winbindd start earlier in the init process, at the same time + ypbind is usually started as well +- add a sepoarate init script for nmbd called nmb, we need to be able + to restart nmbd without dropping al smbd connections unnecessarily + +* Fri Mar 23 2007 Simo Sorce +- add samba.schema to /etc/openldap/schema + +* Thu Mar 22 2007 Florian La Roche +- adjust the Requires: for the scripts, add "chkconfig --add smb" + +* Tue Mar 20 2007 Simo Sorce 3.0.24-6.fc7 +- do not put comments inline on smb.conf options, they may be read + as part of the value (for example log files names) + +* Mon Mar 19 2007 Simo Sorce 3.0.24-5.fc7 +- actually use the correct samba.pamd file not the old samba.pamd.stack file +- fix logifles and use upstream convention of log.* instead of our old *.log + Winbindd creates its own log.* files anyway so we will be more consistent +- install our own (enhanced) default smb.conf file +- Fix pam_winbind acct_mgmt PAM result code (prevented local users from + logging in). Fixed by Guenther. +- move some files from samba to samba-common as they are used with winbindd + as well + +* Fri Mar 16 2007 Guenther Deschner 3.0.24-4.fc7 +- fix arch macro which reported Vista to Samba clients. + +* Thu Mar 15 2007 Simo Sorce 3.0.24-3.fc7 +- Directories reorg, tdb files must go to /var/lib, not + to /var/cache, add migration script in %%post common +- Split out libsmbclient, devel and doc packages +- Remove libmsrpc.[h|so] for now as they are not really usable +- Remove kill -HUP from rotate, samba use -HUP for other things + noit to reopen logs + +* Tue Feb 20 2007 Simo Sorce 3.0.24-2.fc7 +- New upstream release +- Fix packaging issue wrt idmap modules used only by smbd +- Addedd Vista Patchset for compatibility with Windows Vista +- Change default of "msdfs root", it seem to cause problems with + some applications and it has been proposed to change it for + 3.0.25 upstream + +* Fri Sep 1 2006 Jay Fenlason 3.0.23c-2 +- New upstream release. + +* Tue Aug 8 2006 Jay Fenlason 3.0.23b-2 +- New upstream release. + +* Mon Jul 24 2006 Jay Fenlason 3.0.23a-3 +- Fix the -logfiles patch to close + bz#199607 Samba compiled with wrong log path. + bz#199206 smb.conf has incorrect log file path + +* Mon Jul 24 2006 Jay Fenlason 3.0.23a-2 +- Upgrade to new upstream 3.0.23a +- include upstream samr_alias patch + +* Tue Jul 11 2006 Jay Fenlason 3.0.23-2 +- New upstream release. +- Use modified filter-requires-samba.sh from packaging/RHEL/setup/ + to get rid of bogus dependency on perl(Unicode::MapUTF8) +- Update the -logfiles and -smb.conf patches to work with 3.0.23 + +* Thu Jul 6 2006 Jay Fenlason 3.0.23-0.RC3 +- New upstream RC release. +- Update the -logfiles, and -passwd patches for + 3.0.23rc3 +- Include the change to smb.init from Bastien Nocera ) + to close + bz#182560 Wrong retval for initscript when smbd is dead +- Update this spec file to build with 3.0.23rc3 +- Remove the -install.mount.smbfs patch, since we don't install + mount.smbfs any more. + +* Wed Jun 14 2006 Tomas Mraz - 2.0.21c-3 +- rebuilt with new gnutls + +* Fri Mar 17 2006 Jay Fenlason 2.0.21c-2 +- New upstream version. + +* Mon Feb 13 2006 Jay Fenlason 3.0.21b-2 +- New upstream version. +- Since the rawhide kernel has dropped support for smbfs, remove smbmount + and smbumount. Users should use mount.cifs instead. +- Upgrade to 3.0.21b + +* Fri Feb 10 2006 Jesse Keating - 0:3.0.20b-2.1.1 +- bump again for double-long bug on ppc(64) + +* Fri Dec 09 2005 Jesse Keating +- rebuilt + +* Sun Nov 13 2005 Jay Fenlason 3.0.20b-2 +- turn on -DLDAP_DEPRECATED to allow access to ldap functions that have + been depricated in 2.3.11, but which don't have well-documented + replacements (ldap_simple_bind_s(), for example). +- Upgrade to 3.0.20b, which includes all the previous upstream patches. +- Updated the -warnings patch for 3.0.20a. +- Include --with-shared-modules=idmap_ad,idmap_rid to close + bz#156810 --with-shared-modules=idmap_ad,idmap_rid +- Include the new samba.pamd from Tomas Mraz (tmraz@redhat.com) to close + bz#170259 pam_stack is deprecated + +* Sun Nov 13 2005 Warren Togami 3.0.20-3 +- epochs from deps, req exact release +- rebuild against new openssl + +* Mon Aug 22 2005 Jay Fenlason 3.0.20-2 +- New upstream release + Includes five upstream patches -bug3010_v1, -groupname_enumeration_v3, + -regcreatekey_winxp_v1, -usrmgr_groups_v1, and -winbindd_v1 + This obsoletes the -pie and -delim patches + the -warning and -gcc4 patches are obsolete too + The -man, -passwd, and -smbspool patches were updated to match 3.0.20pre1 + Also, the -quoting patch was implemented differently upstream + There is now a umount.cifs executable and manpage + We run autogen.sh as part of the build phase + The testprns command is now gone + libsmbclient now has a man page +- Include -bug106483 patch to close + bz#106483 smbclient: -N negates the provided password, despite documentation +- Added the -warnings patch to quiet some compiler warnings. +- Removed many obsolete patches from CVS. + +* Mon May 2 2005 Jay Fenlason 3.0.14a-2 +- New upstream release. +- the -64bit-timestamps, -clitar, -establish_trust, user_rights_v1, + winbind_find_dc_v2 patches are now obsolete. + +* Thu Apr 7 2005 Jay Fenlason 3.0.13-2 +- New upstream release +- add my -quoting patch, to fix swat with strings that contain + html meta-characters, and to use correct quote characters in + lists, closing bz#134310 +- include the upstream winbindd_2k3sp1 patch +- include the -smbclient patch. +- include the -hang patch from upstream. + +* Thu Mar 24 2005 Florian La Roche +- add a "exit 0" to the postun of the main samba package + +* Wed Mar 2 2005 Tomas Mraz 3.0.11-5 +- rebuild with openssl-0.9.7e + +* Thu Feb 24 2005 Jay Fenlason 3.0.11-4 +- Use the updated filter-requires-samba.sh file, so we don't accidentally + pick up a dependency on perl(Crypt::SmbHash) + +* Fri Feb 18 2005 Jay Fenlason 3.0.11-3 +- add -gcc4 patch to compile with gcc 4. +- remove the now obsolete -smbclient-kerberos.patch +- Include four upstream patches from + http://samba.org/~jerry/patches/post-3.0.11/ + (Slightly modified the winbind_find_dc_v2 patch to apply easily with + rpmbuild). + +* Fri Feb 4 2005 Jay Fenlason 3.0.11-2 +- include -smbspool patch to close bz#104136 + +* Wed Jan 12 2005 Jay Fenlason 3.0.10-4 +- Update the -man patch to fix ntlm_auth.1 too. +- Move pam_smbpass.so to the -common package, so both the 32 + and 64-bit versions will be installed on multiarch platforms. + This closes bz#143617 +- Added new -delim patch to fix mount.cifs so it can accept + passwords with commas in them (via environment or credentials + file) to close bz#144198 + +* Wed Jan 12 2005 Tim Waugh 3.0.10-3 +- Rebuilt for new readline. + +* Fri Dec 17 2004 Jay Fenlason 3.0.10-2 +- New upstream release that closes CAN-2004-1154 bz#142544 +- Include the -64bit patch from Nalin. This closes bz#142873 +- Update the -logfiles patch to work with 3.0.10 +- Create /var/run/winbindd and make it part of the -common rpm to close + bz#142242 + +* Mon Nov 22 2004 Jay Fenlason 3.0.9-2 +- New upstream release. This obsoletes the -secret patch. + Include my changetrustpw patch to make "net ads changetrustpw" stop + aborting. This closes #134694 +- Remove obsolete triggers for ancient samba versions. +- Move /var/log/samba to the -common rpm. This closes #76628 +- Remove the hack needed to get around the bad docs files in the + 3.0.8 tarball. +- Change the comment in winbind.init to point at the correct pidfile. + This closes #76641 + +* Mon Nov 22 2004 Than Ngo 3.0.8-4 +- fix unresolved symbols in libsmbclient which caused applications + such as KDE's konqueror to fail when accessing smb:// URLs. #139894 + +* Thu Nov 11 2004 Jay Fenlason 3.0.8-3.1 +- Rescue the install.mount.smbfs patch from Juanjo Villaplana + (villapla@si.uji.es) to prevent building the srpm from trashing your + installed /usr/bin/smbmount + +* Tue Nov 9 2004 Jay Fenlason 3.0.8-3 +- Include the corrected docs tarball, and use it instead of the + obsolete docs from the upstream 3.0.8 tarball. +- Update the logfiles patch to work with the updated docs. + +* Mon Nov 8 2004 Jay Fenlason 3.0.8-2 +- New upstream version fixes CAN-2004-0930. This obsoletes the + disable-sendfile, salt, signing-shortkey and fqdn patches. +- Add my ugly non-ascii-domain patch. +- Updated the pie patch for 3.0.8. +- Updated the logfiles patch for 3.0.8. + +* Tue Oct 26 2004 Jay Fenlason 3.0.8-0.pre2 +- New upstream version +- Add Nalin's signing-shortkey patch. + +* Tue Oct 19 2004 Jay Fenlason 3.0.8-0.pre1.3 +- disable the -salt patch, because it causes undefined references in + libsmbclient that prevent gnome-vfs from building. + +* Fri Oct 15 2004 Jay Fenlason 3.0.8-0.pre1.2 +- Re-enable the x_fclose patch that was accidentally disabled + in 3.0.8-0.pre1.1. This closes #135832 +- include Nalin's -fqdn and -salt patches. + +* Wed Oct 13 2004 Jay Fenlason 3.0.8-0.pre1.1 +- Include disable-sendfile patch to default "use sendfile" to "no". + This closes #132779 + +* Wed Oct 6 2004 Jay Fenlason +- Include patch from Steven Lawrance (slawrance@yahoo.com) that modifies + smbmnt to work with 32-bit uids. + +* Mon Sep 27 2004 Jay Fenlason 3.0.8-0.pre1 +- new upstream release. This obsoletes the ldapsam_compat patches. + +* Wed Sep 15 2004 Jay Fenlason 3.0.7-4 +- Update docs section to not carryover the docs/manpages directory + This moved many files from /usr/share/doc/samba-3.0.7/docs/* to + /usr/share/doc/samba-3.0.7/* +- Modify spec file as suggested by Rex Dieter (rdieter@math.unl.edu) + to correctly create libsmbclient.so.0 and to use %%_initrddir instead + of rolling our own. This closes #132642 +- Add patch to default "use sendfile" to no, since sendfile appears to + be broken +- Add patch from Volker Lendecke to help make + ldapsam_compat work again. +- Add patch from "Vince Brimhall" for ldapsam_compat + These two patches close bugzilla #132169 + +* Mon Sep 13 2004 Jay Fenlason 3.0.7-3 +- Upgrade to 3.0.7, which fixes CAN-2004-0807 CAN-2004-0808 + This obsoletes the 3.0.6-schema patch. +- Update BuildRequires line to include openldap-devel openssl-devel + and cups-devel + +* Mon Aug 16 2004 Jay Fenlason 3.0.6-3 +- New upstream version. +- Include post 3.0.6 patch from "Gerald (Jerry) Carter" + to fix a duplicate in the LDAP schema. +- Include 64-bit timestamp patch from Ravikumar (rkumar@hp.com) + to allow correct timestamp handling on 64-bit platforms and fix #126109. +- reenable the -pie patch. Samba is too widely used, and too vulnerable + to potential security holes to disable an important security feature + like -pie. The correct fix is to have the toolchain not create broken + executables when programs compiled -pie are stripped. +- Remove obsolete patches. +- Modify this spec file to put libsmbclient.{a,so} in the right place on + x86_64 machines. + +* Thu Aug 5 2004 Jason Vas Dias 3.0.5-3 +- Removed '-pie' patch - 3.0.5 uses -fPIC/-PIC, and the combination +- resulted in executables getting corrupt stacks, causing smbmnt to +- get a SIGBUS in the mount() call (bug 127420). + +* Fri Jul 30 2004 Jay Fenlason 3.0.5-2 +- Upgrade to 3.0.5, which is a regression from 3.0.5pre1 for a + security fix. +- Include the 3.0.4-backport patch from the 3E branch. This restores + some of the 3.0.5pre1 and 3.0.5rc1 functionality. + +* Tue Jul 20 2004 Jay Fenlason 3.0.5-0.pre1.1 +- Backport base64_decode patche to close CAN-2004-0500 +- Backport hash patch to close CAN-2004-0686 +- use_authtok patch from Nalin Dahyabhai +- smbclient-kerberos patch from Alexander Larsson +- passwd patch uses "*" instead of "x" for "hashed" passwords for + accounts created by winbind. "x" means "password is in /etc/shadow" to + brain-damaged pam_unix module. + +* Fri Jul 2 2004 Jay Fenlason 3.0.5.0pre1.0 +- New upstream version +- use %% { SOURCE1 } instead of a hardcoded path +- include -winbind patch from Gerald (Jerry) Carter (jerry@samba.org) + https://bugzilla.samba.org/show_bug.cgi?id=1315 + to make winbindd work against Windows versions that do not have + 128 bit encryption enabled. +- Moved %%{_bindir}/net to the -common package, so that folks who just + want to use winbind, etc don't have to install -client in order to + "net join" their domain. +- New upstream version obsoletes the patches added in 3.0.3-5 +- Remove smbgetrc.5 man page, since we don't ship smbget. + +* Tue Jun 15 2004 Elliot Lee +- rebuilt + +* Tue May 4 2004 Jay Fenlason 3.0.3-5 +- Patch to allow password changes from machines patched with + Microsoft hotfix MS04-011. +- Include patches for https://bugzilla.samba.org/show_bug.cgi?id=1302 + and https://bugzilla.samba.org/show_bug.cgi?id=1309 + +* Thu Apr 29 2004 Jay Fenlason 3.0.3-4 +- Samba 3.0.3 released. + +* Wed Apr 21 2004 jay Fenlason 3.0.3-3.rc1 +- New upstream version +- updated spec file to make libsmbclient.so executable. This closes + bugzilla #121356 + +* Mon Apr 5 2004 Jay Fenlason 3.0.3-2.pre2 +- New upstream version +- Updated configure line to remove --with-fhs and to explicitly set all + the directories that --with-fhs was setting. We were overriding most of + them anyway. This closes #118598 + +* Mon Mar 15 2004 Jay Fenlason 3.0.3-1.pre1 +- New upstream version. +- Updated -pie and -logfiles patches for 3.0.3pre1 +- add krb5-devel to buildrequires, fixes #116560 +- Add patch from Miloslav Trmac (mitr@volny.cz) to allow non-root to run + "service smb status". This fixes #116559 + +* Tue Mar 02 2004 Elliot Lee +- rebuilt + +* Mon Feb 16 2004 Jay Fenlason 3.0.2a-1 +- Upgrade to 3.0.2a + +* Mon Feb 16 2004 Karsten Hopp 3.0.2-7 +- fix ownership in -common package + +* Fri Feb 13 2004 Elliot Lee +- rebuilt + +* Fri Feb 13 2004 Jay Fenlason +- Change all requires lines to list an explicit epoch. Closes #102715 +- Add an explicit Epoch so that %%{epoch} is defined. + +* Mon Feb 9 2004 Jay Fenlason 3.0.2-5 +- New upstream version: 3.0.2 final includes security fix for #114995 + (CAN-2004-0082) +- Edit postun script for the -common package to restart winbind when + appropriate. Fixes bugzilla #114051. + +* Mon Feb 2 2004 Jay Fenlason 3.0.2-3rc2 +- add %%dir entries for %%{_libdir}/samba and %%{_libdir}/samba/charset +- Upgrade to new upstream version +- build mount.cifs for the new cifs filesystem in the 2.6 kernel. + +* Mon Jan 19 2004 Jay Fenlason 3.0.2-1rc1 +- Upgrade to new upstream version + +* Wed Dec 17 2003 Felipe Alfaro Solana 3.0.1-1 +- Update to 3.0.1 +- Removed testparm patch as it's already merged +- Removed Samba.7* man pages +- Fixed .buildroot patch +- Fixed .pie patch +- Added new /usr/bin/tdbdump file + +* Thu Sep 25 2003 Jay Fenlason 3.0.0-15 +- New 3.0.0 final release +- merge nmbd-netbiosname and testparm patches from 3E branch +- updated the -logfiles patch to work against 3.0.0 +- updated the pie patch +- update the VERSION file during build +- use make -j if avaliable +- merge the winbindd_privileged change from 3E +- merge the "rm /usr/lib" patch that allows Samba to build on 64-bit + platforms despite the broken Makefile + +* Mon Aug 18 2003 Jay Fenlason +- Merge from samba-3E-branch after samba-3.0.0rc1 was released + +* Wed Jul 23 2003 Jay Fenlason 3.0.0-3beta3 +- Merge from 3.0.0-2beta3.3E +- (Correct log file names (#100981).) +- (Fix pidfile directory in samab.log) +- (Remove obsolete samba-3.0.0beta2.tar.bz2.md5 file) +- (Move libsmbclient to the -common package (#99449)) + +* Sun Jun 22 2003 Nalin Dahyabhai 2.2.8a-4 +- rebuild + +* Wed Jun 04 2003 Elliot Lee +- rebuilt + +* Wed May 28 2003 Jay Fenlason 2.2.8a-2 +- add libsmbclient.so for gnome-vfs-extras +- Edit specfile to specify /var/run for pid files +- Move /tmp/.winbindd/socket to /var/run/winbindd/socket + +* Wed May 14 2003 Florian La Roche +- add proper ldconfig calls + +* Thu Apr 24 2003 Jay Fenlason 2.2.8a-1 +- upgrade to 2.2.8a +- remove old .md5 files +- add "pid directory = /var/run" to the smb.conf file. Fixes #88495 +- Patch from jra@dp.samba.org to fix a delete-on-close regression + +* Mon Mar 24 2003 Jay Fenlason 2.2.8-0 +- Upgrade to 2.2.8 +- removed commented out patches. +- removed old patches and .md5 files from the repository. +- remove duplicate /sbin/chkconfig --del winbind which causes + warnings when removing samba. +- Fixed minor bug in smbprint that causes it to fail when called with + more than 10 parameters: the accounting file (and spool directory + derived from it) were being set wrong due to missing {}. This closes + bug #86473. +- updated smb.conf patch, includes new defaults to close bug #84822. + +* Mon Feb 24 2003 Elliot Lee +- rebuilt + +* Thu Feb 20 2003 Jonathan Blandford 2.2.7a-5 +- remove swat.desktop file + +* Thu Feb 20 2003 Nalin Dahyabhai 2.2.7a-4 +- relink libnss_wins.so with SHLD="%%{__cc} -lnsl" to force libnss_wins.so to + link with libnsl, avoiding unresolved symbol errors on functions in libnsl + +* Mon Feb 10 2003 Jay Fenlason 2.2.7a-3 +- edited spec file to put .so files in the correct directories + on 64-bit platforms that have 32-bit compatability issues + (sparc64, x86_64, etc). This fixes bugzilla #83782. +- Added samba-2.2.7a-error.patch from twaugh. This fixes + bugzilla #82454. + +* Wed Jan 22 2003 Tim Powers +- rebuilt + +* Thu Jan 9 2003 Jay Fenlason 2.2.7a-1 +- Update to 2.2.7a +- Change default printing system to CUPS +- Turn on pam_smbpass +- Turn on msdfs + +* Sat Jan 4 2003 Jeff Johnson 2.2.7-5 +- use internal dep generator. + +* Sat Dec 14 2002 Tim Powers 2.2.7-4 +- don't use rpms internal dep generator + +* Mon Dec 02 2002 Elliot Lee 2.2.7-3 +- Fix missing doc files. +- Fix multilib issues + +* Wed Nov 20 2002 Bill Nottingham 2.2.7-2 +- update to 2.2.7 +- add patch for LFS in smbclient () + +* Wed Aug 28 2002 Trond Eivind Glomsød 2.2.5-10 +- logrotate fixes (#65007) + +* Mon Aug 26 2002 Trond Eivind Glomsrød 2.2.5-9 +- /usr/lib was used in place of %%{_libdir} in three locations (#72554) + +* Mon Aug 5 2002 Trond Eivind Glomsrød 2.2.5-8 +- Initscript fix (#70720) + +* Fri Jul 26 2002 Trond Eivind Glomsrød 2.2.5-7 +- Enable VFS support and compile the "recycling" module (#69796) +- more selective includes of the examples dir + +* Tue Jul 23 2002 Trond Eivind Glomsrød 2.2.5-6 +- Fix the lpq parser for better handling of LPRng systems (#69352) + +* Tue Jul 23 2002 Trond Eivind Glomsrød 2.2.5-5 +- desktop file fixes (#69505) + +* Wed Jun 26 2002 Trond Eivind Glomsrød 2.2.5-4 +- Enable ACLs + +* Tue Jun 25 2002 Trond Eivind Glomsrød 2.2.5-3 +- Make it not depend on Net::LDAP - those are doc files and examples + +* Fri Jun 21 2002 Tim Powers +- automated rebuild + +* Thu Jun 20 2002 Trond Eivind Glomsrød 2.2.5-1 +- 2.2.5 + +* Fri Jun 14 2002 Trond Eivind Glomsrød 2.2.4-5 +- Move the post/preun of winbind into the -common subpackage, + where the script is (#66128) + +* Tue Jun 4 2002 Trond Eivind Glomsrød 2.2.4-4 +- Fix pidfile locations so it runs properly again (2.2.4 + added a new directtive - #65007) + +* Thu May 23 2002 Tim Powers +- automated rebuild + +* Tue May 14 2002 Trond Eivind Glomsrød 2.2.4-2 +- Fix #64804 + +* Thu May 9 2002 Trond Eivind Glomsrød 2.2.4-1 +- 2.2.4 +- Removed some zero-length and CVS internal files +- Make it build + +* Wed Apr 10 2002 Trond Eivind Glomsrød 2.2.3a-6 +- Don't use /etc/samba.d in smbadduser, it should be /etc/samba + +* Thu Apr 4 2002 Trond Eivind Glomsrød 2.2.3a-5 +- Add libsmbclient.a w/headerfile for KDE (#62202) + +* Tue Mar 26 2002 Trond Eivind Glomsrød 2.2.3a-4 +- Make the logrotate script look the correct place for the pid files + +* Thu Mar 14 2002 Nalin Dahyabhai 2.2.3a-3 +- include interfaces.o in pam_smbpass.so, which needs symbols from interfaces.o + (patch posted to samba-list by Ilia Chipitsine) + +* Thu Feb 21 2002 Trond Eivind Glomsrød 2.2.3a-2 +- Rebuild + +* Thu Feb 7 2002 Trond Eivind Glomsrød 2.2.3a-1 +- 2.2.3a + +* Mon Feb 4 2002 Trond Eivind Glomsrød 2.2.3-1 +- 2.2.3 + +* Thu Nov 29 2001 Trond Eivind Glomsrød 2.2.2-8 +- New pam configuration file for samba + +* Tue Nov 27 2001 Trond Eivind Glomsrød 2.2.2-7 +- Enable PAM session controll and password sync + +* Tue Nov 13 2001 Trond Eivind Glomsrød 2.2.2-6 +- Move winbind files to samba-common. Add separate initscript for + winbind +- Fixes for winbind - protect global variables with mutex, use + more secure getenv + +* Thu Nov 8 2001 Trond Eivind Glomsrød 2.2.2-5 +- Teach smbadduser about "getent passwd" +- Fix more pid-file references +- Add (conditional) winbindd startup to the initscript, configured in + /etc/sysconfig/samba + +* Wed Nov 7 2001 Trond Eivind Glomsrød 2.2.2-4 +- Fix pid-file reference in logrotate script +- include pam and nss modules for winbind + +* Mon Nov 5 2001 Trond Eivind Glomsrød 2.2.2-3 +- Add "--with-utmp" to configure options (#55372) +- Include winbind, pam_smbpass.so, rpcclient and smbcacls +- start using /var/cache/samba, we need to keep state and there is + more than just locks involved + +* Sat Nov 03 2001 Florian La Roche 2.2.2-2 +- add "reload" to the usage string in the startup script + +* Mon Oct 15 2001 Trond Eivind Glomsrød 2.2.2-1 +- 2.2.2 + +* Tue Sep 18 2001 Trond Eivind Glomsrød 2.2.1a-5 +- Add patch from Jeremy Allison to fix IA64 alignment problems (#51497) + +* Mon Aug 13 2001 Trond Eivind Glomsrød +- Don't include smbpasswd in samba, it's in samba-common (#51598) +- Add a disabled "obey pam restrictions" statement - it's not + active, as we use encrypted passwords, but if the admin turns + encrypted passwords off the choice is available. (#31351) + +* Wed Aug 8 2001 Trond Eivind Glomsrød +- Use /var/cache/samba instead of /var/lock/samba +- Remove "domain controller" keyword from smb.conf, it's + deprecated (from #13704) +- Sync some examples with smb.conf.default +- Fix password synchronization (#16987) + +* Fri Jul 20 2001 Trond Eivind Glomsrød +- Tweaks of BuildRequires (#49581) + +* Wed Jul 11 2001 Trond Eivind Glomsrød +- 2.2.1a bugfix release + +* Tue Jul 10 2001 Trond Eivind Glomsrød +- 2.2.1, which should work better for XP + +* Sat Jun 23 2001 Trond Eivind Glomsrød +- 2.2.0a security fix +- Mark lograte and pam configuration files as noreplace + +* Fri Jun 22 2001 Trond Eivind Glomsrød +- Add the /etc/samba directory to samba-common + +* Thu Jun 21 2001 Trond Eivind Glomsrød +- Add improvements to the smb.conf as suggested in #16931 + +* Tue Jun 19 2001 Trond Eivind Glomsrød +- (these changes are from the non-head version) +- Don't include /usr/sbin/samba, it's the same as the initscript +- unset TMPDIR, as samba can't write into a TMPDIR owned + by root (#41193) +- Add pidfile: lines for smbd and nmbd and a config: line + in the initscript (#15343) +- don't use make -j +- explicitly include /usr/share/samba, not just the files in it + +* Tue Jun 19 2001 Bill Nottingham +- mount.smb/mount.smbfs go in /sbin, *not* %%{_sbindir} + +* Fri Jun 8 2001 Preston Brown +- enable encypted passwords by default + +* Thu Jun 7 2001 Helge Deller +- build as 2.2.0-1 release +- skip the documentation-directories docbook, manpages and yodldocs +- don't include *.sgml documentation in package +- moved codepage-directory to /usr/share/samba/codepages +- make it compile with glibc-2.2.3-10 and kernel-headers-2.4.2-2 + +* Mon May 21 2001 Helge Deller +- updated to samba 2.2.0 +- moved codepages to %%{_datadir}/samba/codepages +- use all available CPUs for building rpm packages +- use %%{_xxx} defines at most places in spec-file +- "License:" replaces "Copyright:" +- dropped excludearch sparc +- de-activated japanese patches 100 and 200 for now + (they need to be fixed and tested wth 2.2.0) +- separated swat.desktop file from spec-file and added + german translations +- moved /etc/sysconfig/samba to a separate source-file +- use htmlview instead of direct call to netscape in + swat.desktop-file + +* Mon May 7 2001 Bill Nottingham +- device-remove security fix again () + +* Fri Apr 20 2001 Bill Nottingham +- fix tempfile security problems, officially () +- update to 2.0.8 + +* Sun Apr 8 2001 Bill Nottingham +- turn of SSL, kerberos + +* Thu Apr 5 2001 Bill Nottingham +- fix tempfile security problems (patch from ) + +* Thu Mar 29 2001 Bill Nottingham +- fix quota support, and quotas with the 2.4 kernel (#31362, #33915) + +* Mon Mar 26 2001 Nalin Dahyabhai +- tweak the PAM code some more to try to do a setcred() after initgroups() +- pull in all of the optflags on i386 and sparc +- don't explicitly enable Kerberos support -- it's only used for password + checking, and if PAM is enabled it's a no-op anyway + +* Mon Mar 5 2001 Tim Waugh +- exit successfully from preun script (bug #30644). + +* Fri Mar 2 2001 Nalin Dahyabhai +- rebuild in new environment + +* Wed Feb 14 2001 Bill Nottingham +- updated japanese stuff (#27683) + +* Fri Feb 9 2001 Bill Nottingham +- fix trigger (#26859) + +* Wed Feb 7 2001 Bill Nottingham +- add i18n support, japanese patch (#26253) + +* Wed Feb 7 2001 Trond Eivind Glomsrød +- i18n improvements in initscript (#26537) + +* Wed Jan 31 2001 Bill Nottingham +- put smbpasswd in samba-common (#25429) + +* Wed Jan 24 2001 Bill Nottingham +- new i18n stuff + +* Sun Jan 21 2001 Bill Nottingham +- rebuild + +* Thu Jan 18 2001 Bill Nottingham +- i18n-ize initscript +- add a sysconfig file for daemon options (#23550) +- clarify smbpasswd man page (#23370) +- build with LFS support (#22388) +- avoid extraneous pam error messages (#10666) +- add Urban Widmark's bug fixes for smbmount (#19623) +- fix setgid directory modes (#11911) +- split swat into subpackage (#19706) + +* Wed Oct 25 2000 Nalin Dahyabhai +- set a default CA certificate path in smb.conf (#19010) +- require openssl >= 0.9.5a-20 to make sure we have a ca-bundle.crt file + +* Mon Oct 16 2000 Bill Nottingham +- fix swat only_from line (#18726, others) +- fix attempt to write outside buildroot on install (#17943) + +* Mon Aug 14 2000 Bill Nottingham +- add smbspool back in (#15827) +- fix absolute symlinks (#16125) + +* Sun Aug 6 2000 Philipp Knirsch +- bugfix for smbadduser script (#15148) + +* Mon Jul 31 2000 Matt Wilson +- patch configure.ing (patch11) to disable cups test +- turn off swat by default + +* Fri Jul 28 2000 Bill Nottingham +- fix condrestart stuff + +* Fri Jul 21 2000 Bill Nottingham +- add copytruncate to logrotate file (#14360) +- fix init script (#13708) + +* Sat Jul 15 2000 Bill Nottingham +- move initscript back +- remove 'Using Samba' book from %%doc +- move stuff to /etc/samba (#13708) +- default configuration tweaks (#13704) +- some logrotate tweaks + +* Wed Jul 12 2000 Prospector +- automatic rebuild + +* Tue Jul 11 2000 Bill Nottingham +- fix logrotate script (#13698) + +* Thu Jul 6 2000 Bill Nottingham +- fix initscripts req (prereq /etc/init.d) + +* Wed Jul 5 2000 Than Ngo +- add initdir macro to handle the initscript directory +- add a new macro to handle /etc/pam.d/system-auth + +* Thu Jun 29 2000 Nalin Dahyabhai +- enable Kerberos 5 and SSL support +- patch for duplicate profile.h headers + +* Thu Jun 29 2000 Bill Nottingham +- fix init script + +* Tue Jun 27 2000 Bill Nottingham +- rename samba logs (#11606) + +* Mon Jun 26 2000 Bill Nottingham +- initscript munging + +* Fri Jun 16 2000 Bill Nottingham +- configure the swat stuff usefully +- re-integrate some specfile tweaks that got lost somewhere + +* Thu Jun 15 2000 Bill Nottingham +- rebuild to get rid of cups dependency + +* Wed Jun 14 2000 Nalin Dahyabhai +- tweak logrotate configurations to use the PID file in /var/lock/samba + +* Sun Jun 11 2000 Bill Nottingham +- rebuild in new environment + +* Thu Jun 1 2000 Nalin Dahyabhai +- change PAM setup to use system-auth + +* Mon May 8 2000 Bill Nottingham +- fixes for ia64 + +* Sat May 6 2000 Bill Nottingham +- switch to %%configure + +* Wed Apr 26 2000 Nils Philippsen +- version 2.0.7 + +* Sun Mar 26 2000 Florian La Roche +- simplify preun + +* Thu Mar 16 2000 Bill Nottingham +- fix yp_get_default_domain in autoconf +- only link against readline for smbclient +- fix log rotation (#9909) + +* Fri Feb 25 2000 Bill Nottingham +- fix trigger, again. + +* Mon Feb 7 2000 Bill Nottingham +- fix trigger. + +* Fri Feb 4 2000 Bill Nottingham +- turn on quota support + +* Mon Jan 31 2000 Cristian Gafton +- rebuild to fox dependencies +- man pages are compressed + +* Fri Jan 21 2000 Bill Nottingham +- munge post scripts slightly + +* Wed Jan 19 2000 Bill Nottingham +- turn on mmap again. Wheee. +- ship smbmount on alpha + +* Mon Dec 6 1999 Bill Nottingham +- turn off mmap. ;) + +* Wed Dec 1 1999 Bill Nottingham +- change /var/log/samba to 0700 +- turn on mmap support + +* Thu Nov 11 1999 Bill Nottingham +- update to 2.0.6 + +* Fri Oct 29 1999 Bill Nottingham +- add a %%defattr for -common + +* Tue Oct 5 1999 Bill Nottingham +- shift some files into -client +- remove /home/samba from package. + +* Tue Sep 28 1999 Bill Nottingham +- initscript oopsie. killproc -HUP, not other way around. + +* Sun Sep 26 1999 Bill Nottingham +- script cleanups. Again. + +* Wed Sep 22 1999 Bill Nottingham +- add a patch to fix dropped reconnection attempts + +* Mon Sep 6 1999 Jeff Johnson +- use cp rather than mv to preserve /etc/services perms (#4938 et al). +- use mktemp to generate /etc/tmp.XXXXXX file name. +- add prereqs on sed/mktemp/killall (need to move killall to /bin). +- fix trigger syntax (i.e. "samba < 1.9.18p7" not "samba < samba-1.9.18p7") + +* Mon Aug 30 1999 Bill Nottingham +- sed "s|nawk|gawk|" /usr/bin/convert_smbpasswd + +* Sat Aug 21 1999 Bill Nottingham +- fix typo in mount.smb + +* Fri Aug 20 1999 Bill Nottingham +- add a %%trigger to work around (sort of) broken scripts in + previous releases + +* Mon Aug 16 1999 Bill Nottingham +- initscript munging + +* Mon Aug 9 1999 Bill Nottingham +- add domain parsing to mount.smb + +* Fri Aug 6 1999 Bill Nottingham +- add a -common package, shuffle files around. + +* Fri Jul 23 1999 Bill Nottingham +- add a chmod in %%postun so /etc/services & inetd.conf don't become unreadable + +* Wed Jul 21 1999 Bill Nottingham +- update to 2.0.5 +- fix mount.smb - smbmount options changed again......... +- fix postun. oops. +- update some stuff from the samba team's spec file. + +* Fri Jun 18 1999 Bill Nottingham +- split off clients into separate package +- don't run samba by default + +* Mon Jun 14 1999 Bill Nottingham +- fix one problem with mount.smb script +- fix smbpasswd on sparc with a really ugly kludge + +* Thu Jun 10 1999 Dale Lovelace +- fixed logrotate script + +* Tue May 25 1999 Bill Nottingham +- turn of 64-bit locking on 32-bit platforms + +* Thu May 20 1999 Bill Nottingham +- so many releases, so little time +- explicitly uncomment 'printing = bsd' in sample config + +* Tue May 18 1999 Bill Nottingham +- update to 2.0.4a +- fix mount.smb arg ordering + +* Fri Apr 16 1999 Bill Nottingham +- go back to stop/start for restart (-HUP didn't work in testing) + +* Fri Mar 26 1999 Bill Nottingham +- add a mount.smb to make smb mounting a little easier. +- smb filesystems apparently don't work on alpha. Oops. + +* Thu Mar 25 1999 Bill Nottingham +- always create codepages + +* Tue Mar 23 1999 Bill Nottingham +- logrotate changes + +* Sun Mar 21 1999 Cristian Gafton +- auto rebuild in the new build environment (release 3) + +* Fri Mar 19 1999 Preston Brown +- updated init script to use graceful restart (not stop/start) + +* Tue Mar 9 1999 Bill Nottingham +- update to 2.0.3 + +* Thu Feb 18 1999 Bill Nottingham +- update to 2.0.2 + +* Mon Feb 15 1999 Bill Nottingham +- swat swat + +* Tue Feb 9 1999 Bill Nottingham +- fix bash2 breakage in post script + +* Fri Feb 5 1999 Bill Nottingham +- update to 2.0.0 + +* Mon Oct 12 1998 Cristian Gafton +- make sure all binaries are stripped + +* Thu Sep 17 1998 Jeff Johnson +- update to 1.9.18p10. +- fix %%triggerpostun. + +* Tue Jul 07 1998 Erik Troan +- updated postun triggerscript to check $0 +- clear /etc/codepages from %%preun instead of %%postun + +* Mon Jun 08 1998 Erik Troan +- made the %%postun script a tad less agressive; no reason to remove + the logs or lock file (after all, if the lock file is still there, + samba is still running) +- the %%postun and %%preun should only exectute if this is the final + removal +- migrated %%triggerpostun from Red Hat's samba package to work around + packaging problems in some Red Hat samba releases + +* Sun Apr 26 1998 John H Terpstra +- minor tidy up in preparation for release of 1.9.18p5 +- added findsmb utility from SGI package + +* Wed Mar 18 1998 John H Terpstra +- Updated version and codepage info. +- Release to test name resolve order + +* Sat Jan 24 1998 John H Terpstra +- Many optimisations (some suggested by Manoj Kasichainula +- Use of chkconfig in place of individual symlinks to /etc/rc.d/init/smb +- Compounded make line +- Updated smb.init restart mechanism +- Use compound mkdir -p line instead of individual calls to mkdir +- Fixed smb.conf file path for log files +- Fixed smb.conf file path for incoming smb print spool directory +- Added a number of options to smb.conf file +- Added smbadduser command (missed from all previous RPMs) - Doooh! +- Added smbuser file and smb.conf file updates for username map diff --git a/filter-requires-samba.sh b/filter-requires-samba.sh deleted file mode 100755 index 1ec1679..0000000 --- a/filter-requires-samba.sh +++ /dev/null @@ -1,3 +0,0 @@ -#!/bin/sh - -/usr/lib/rpm/perl.req $* | grep -E -v '(Net::LDAP|Crypt::SmbHash|CGI|Unicode::MapUTF8|smbldap_tools|Carp|Convert::ASN1|Getopt::Long|Getopt::Std|IO::Socket|POSIX|Time::Local|strict)' diff --git a/gating.yaml b/gating.yaml new file mode 100644 index 0000000..c2182c7 --- /dev/null +++ b/gating.yaml @@ -0,0 +1,6 @@ +--- !Policy +product_versions: + - fedora-* +decision_context: bodhi_update_push_stable +rules: + - !PassingTestCaseRule {test_case_name: fedora-ci.koji-build.tier0.functional} diff --git a/plans.fmf b/plans.fmf new file mode 100644 index 0000000..e6427de --- /dev/null +++ b/plans.fmf @@ -0,0 +1,4 @@ +discover: + how: fmf +execute: + how: tmt diff --git a/rpminspect.yaml b/rpminspect.yaml new file mode 100644 index 0000000..f736bfa --- /dev/null +++ b/rpminspect.yaml @@ -0,0 +1,35 @@ +--- +inspections: + disttag: off + +badfuncs: + ignore: + - /usr/bin/nmbd + - /usr/bin/nmblookup + - /usr/bin/smbtorture + - /usr/lib*/libndr.so.* + - /usr/lib*/libsmbconf.so.* + - /usr/lib*/samba/libgse-private-samba.so + - /usr/lib*/samba/libsamba-sockets-private-samba.so + - /usr/lib*/samba/service/nbtd.so + - /usr/libexec/ctdb/smnotify + - /usr/sbin/nmbd + +runpath: + allowed_paths: + - /usr/lib/samba + - /usr/lib64/samba + +abidiff: + suppression_file: samba.abignore + +debuginfo: + ignore: + - /usr/lib*/libdcerpc-samr.so.* + +annocheck: + ignore: + - /usr/bin/gentest + - /usr/bin/locktest + - /usr/bin/masktest + - /usr/bin/smbtorture diff --git a/samba-4.13-fix-winbind-no-trusted-domain.patch b/samba-4.13-fix-winbind-no-trusted-domain.patch deleted file mode 100644 index 4924872..0000000 --- a/samba-4.13-fix-winbind-no-trusted-domain.patch +++ /dev/null @@ -1,41 +0,0 @@ -From 2edaf32b4204b9fe363c441c25b6989fe76911a4 Mon Sep 17 00:00:00 2001 -From: Stefan Metzmacher -Date: Tue, 9 Nov 2021 20:50:20 +0100 -Subject: [PATCH] s3:winbindd: fix "allow trusted domains = no" regression - -add_trusted_domain() should only reject domains -based on is_allowed_domain(), which now also -checks "allow trusted domains = no", if we don't -have an explicit trust to the domain (SEC_CHAN_NULL). - -We use at least SEC_CHAN_LOCAL for local domains like -BUILTIN. - -BUG: https://bugzilla.samba.org/show_bug.cgi?id=14899 - -Signed-off-by: Stefan Metzmacher - -Autobuild-User(master): Stefan Metzmacher -Autobuild-Date(master): Wed Nov 10 11:21:31 UTC 2021 on sn-devel-184 - -(cherry picked from commit a7f6c60cb037b4bc9eee276236539b8282213935) ---- - source3/winbindd/winbindd_util.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/source3/winbindd/winbindd_util.c b/source3/winbindd/winbindd_util.c -index 42ddbfd2f44..9d54e462c42 100644 ---- a/source3/winbindd/winbindd_util.c -+++ b/source3/winbindd/winbindd_util.c -@@ -134,7 +134,7 @@ static NTSTATUS add_trusted_domain(const char *domain_name, - return NT_STATUS_INVALID_PARAMETER; - } - -- if (!is_allowed_domain(domain_name)) { -+ if (secure_channel_type == SEC_CHAN_NULL && !is_allowed_domain(domain_name)) { - return NT_STATUS_NO_SUCH_DOMAIN; - } - --- -2.33.1 - diff --git a/samba-4.13-ipa-dc-schannel.patch b/samba-4.13-ipa-dc-schannel.patch deleted file mode 100644 index d315a5d..0000000 --- a/samba-4.13-ipa-dc-schannel.patch +++ /dev/null @@ -1,45 +0,0 @@ -From 3fc4d1d3998f3956a84c855cb60a9dcb335e1f59 Mon Sep 17 00:00:00 2001 -From: Alexander Bokovoy -Date: Fri, 12 Nov 2021 19:06:01 +0200 -Subject: [PATCH] IPA DC: add missing checks - -When introducing FreeIPA support, two places were forgotten: - - - schannel gensec module needs to be aware of IPA DC - - _lsa_QueryInfoPolicy should treat IPA DC as PDC - -BUG: https://bugzilla.samba.org/show_bug.cgi?id=14903 - -Signed-off-by: Alexander Bokovoy ---- - auth/gensec/schannel.c | 1 + - source3/rpc_server/lsa/srv_lsa_nt.c | 1 + - 2 files changed, 2 insertions(+) - -diff --git a/auth/gensec/schannel.c b/auth/gensec/schannel.c -index 0cdae141ead..6ebbe8f3179 100644 ---- a/auth/gensec/schannel.c -+++ b/auth/gensec/schannel.c -@@ -1080,6 +1080,7 @@ static NTSTATUS schannel_server_start(struct gensec_security *gensec_security) - case ROLE_DOMAIN_BDC: - case ROLE_DOMAIN_PDC: - case ROLE_ACTIVE_DIRECTORY_DC: -+ case ROLE_IPA_DC: - return NT_STATUS_OK; - default: - return NT_STATUS_NOT_IMPLEMENTED; -diff --git a/source3/rpc_server/lsa/srv_lsa_nt.c b/source3/rpc_server/lsa/srv_lsa_nt.c -index 8d71b5252ab..ea92a22cbc9 100644 ---- a/source3/rpc_server/lsa/srv_lsa_nt.c -+++ b/source3/rpc_server/lsa/srv_lsa_nt.c -@@ -683,6 +683,7 @@ NTSTATUS _lsa_QueryInfoPolicy(struct pipes_struct *p, - switch (lp_server_role()) { - case ROLE_DOMAIN_PDC: - case ROLE_DOMAIN_BDC: -+ case ROLE_IPA_DC: - name = get_global_sam_name(); - sid = dom_sid_dup(p->mem_ctx, get_global_sam_sid()); - if (!sid) { --- -2.33.1 - diff --git a/samba-4.13-redhat.patch b/samba-4.13-redhat.patch deleted file mode 100644 index b380020..0000000 --- a/samba-4.13-redhat.patch +++ /dev/null @@ -1,12303 +0,0 @@ -From 3b80faa8b0592c35fe884cea5b01169ae9ec3243 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Mon, 13 Jul 2020 16:15:03 +0200 -Subject: [PATCH 001/103] libcli:smb2: Do not leak ptext on error - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - libcli/smb/smb2_signing.c | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/libcli/smb/smb2_signing.c b/libcli/smb/smb2_signing.c -index 230475480c2..cfb3b613f9d 100644 ---- a/libcli/smb/smb2_signing.c -+++ b/libcli/smb/smb2_signing.c -@@ -515,6 +515,7 @@ NTSTATUS smb2_signing_encrypt_pdu(struct smb2_signing_key *encryption_key, - - ctext = talloc_size(talloc_tos(), ctext_size); - if (ctext == NULL) { -+ TALLOC_FREE(ptext); - status = NT_STATUS_NO_MEMORY; - goto out; - } --- -2.33.1 - - -From 87aed0a5891d81d4e49e5dfa68bd9c61a52eb511 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Mon, 13 Jul 2020 17:23:37 +0200 -Subject: [PATCH 002/103] libcli:smb2: Use talloc NULL context if we don't have - a stackframe - -If we execute this code from python we don't have a talloc stackframe -around and segfault with talloc_tos(). - -To fix the crash we use the NULL context as we take care for freeing the -memory as soon as possible. - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - libcli/smb/smb2_signing.c | 30 ++++++++++++++++++++++++++---- - 1 file changed, 26 insertions(+), 4 deletions(-) - -diff --git a/libcli/smb/smb2_signing.c b/libcli/smb/smb2_signing.c -index cfb3b613f9d..b1e0253948f 100644 ---- a/libcli/smb/smb2_signing.c -+++ b/libcli/smb/smb2_signing.c -@@ -506,14 +506,25 @@ NTSTATUS smb2_signing_encrypt_pdu(struct smb2_signing_key *encryption_key, - uint8_t *ctext = NULL; - size_t len = 0; - int i; -+ TALLOC_CTX *tmp_ctx = NULL; - -- ptext = talloc_size(talloc_tos(), ptext_size); -+ /* -+ * If we come from python bindings, we don't have a stackframe -+ * around, so use the NULL context. -+ * -+ * This is fine as we make sure we free the memory. -+ */ -+ if (talloc_stackframe_exists()) { -+ tmp_ctx = talloc_tos(); -+ } -+ -+ ptext = talloc_size(tmp_ctx, ptext_size); - if (ptext == NULL) { - status = NT_STATUS_NO_MEMORY; - goto out; - } - -- ctext = talloc_size(talloc_tos(), ctext_size); -+ ctext = talloc_size(tmp_ctx, ctext_size); - if (ctext == NULL) { - TALLOC_FREE(ptext); - status = NT_STATUS_NO_MEMORY; -@@ -705,16 +716,27 @@ NTSTATUS smb2_signing_decrypt_pdu(struct smb2_signing_key *decryption_key, - uint8_t *ptext = NULL; - size_t len = 0; - int i; -+ TALLOC_CTX *tmp_ctx = NULL; -+ -+ /* -+ * If we come from python bindings, we don't have a stackframe -+ * around, so use the NULL context. -+ * -+ * This is fine as we make sure we free the memory. -+ */ -+ if (talloc_stackframe_exists()) { -+ tmp_ctx = talloc_tos(); -+ } - - /* GnuTLS doesn't have a iovec API for decryption yet */ - -- ptext = talloc_size(talloc_tos(), ptext_size); -+ ptext = talloc_size(tmp_ctx, ptext_size); - if (ptext == NULL) { - status = NT_STATUS_NO_MEMORY; - goto out; - } - -- ctext = talloc_size(talloc_tos(), ctext_size); -+ ctext = talloc_size(tmp_ctx, ctext_size); - if (ctext == NULL) { - TALLOC_FREE(ptext); - status = NT_STATUS_NO_MEMORY; --- -2.33.1 - - -From 0005c4c973fac93c74b1c958a29f0574b15fe63f Mon Sep 17 00:00:00 2001 -From: Stefan Metzmacher -Date: Wed, 6 Nov 2019 17:37:45 +0100 -Subject: [PATCH 003/103] auth:creds: Introduce CRED_SMB_CONF - -We have several places where we check '> CRED_UNINITIALISED', -so we better don't use CRED_UNINITIALISED for values from -our smb.conf. - -Signed-off-by: Stefan Metzmacher -Reviewed-by: Andreas Schneider ---- - auth/credentials/credentials.c | 6 +++--- - auth/credentials/credentials.h | 1 + - auth/credentials/pycredentials.c | 1 + - python/samba/tests/credentials.py | 4 ++-- - 4 files changed, 7 insertions(+), 5 deletions(-) - -diff --git a/auth/credentials/credentials.c b/auth/credentials/credentials.c -index 81f9dbb9eb3..80a31b248ae 100644 ---- a/auth/credentials/credentials.c -+++ b/auth/credentials/credentials.c -@@ -902,12 +902,12 @@ _PUBLIC_ void cli_credentials_set_conf(struct cli_credentials *cred, - if (lpcfg_parm_is_cmdline(lp_ctx, "workgroup")) { - cli_credentials_set_domain(cred, lpcfg_workgroup(lp_ctx), CRED_SPECIFIED); - } else { -- cli_credentials_set_domain(cred, lpcfg_workgroup(lp_ctx), CRED_UNINITIALISED); -+ cli_credentials_set_domain(cred, lpcfg_workgroup(lp_ctx), CRED_SMB_CONF); - } - if (lpcfg_parm_is_cmdline(lp_ctx, "netbios name")) { - cli_credentials_set_workstation(cred, lpcfg_netbios_name(lp_ctx), CRED_SPECIFIED); - } else { -- cli_credentials_set_workstation(cred, lpcfg_netbios_name(lp_ctx), CRED_UNINITIALISED); -+ cli_credentials_set_workstation(cred, lpcfg_netbios_name(lp_ctx), CRED_SMB_CONF); - } - if (realm != NULL && strlen(realm) == 0) { - realm = NULL; -@@ -915,7 +915,7 @@ _PUBLIC_ void cli_credentials_set_conf(struct cli_credentials *cred, - if (lpcfg_parm_is_cmdline(lp_ctx, "realm")) { - cli_credentials_set_realm(cred, realm, CRED_SPECIFIED); - } else { -- cli_credentials_set_realm(cred, realm, CRED_UNINITIALISED); -+ cli_credentials_set_realm(cred, realm, CRED_SMB_CONF); - } - - sep = lpcfg_winbind_separator(lp_ctx); -diff --git a/auth/credentials/credentials.h b/auth/credentials/credentials.h -index 9fe6a82b1ea..7154c2a008c 100644 ---- a/auth/credentials/credentials.h -+++ b/auth/credentials/credentials.h -@@ -42,6 +42,7 @@ struct db_context; - /* In order of priority */ - enum credentials_obtained { - CRED_UNINITIALISED = 0, /* We don't even have a guess yet */ -+ CRED_SMB_CONF, /* Current value should be used, which comes from smb.conf */ - CRED_CALLBACK, /* Callback should be used to obtain value */ - CRED_GUESS_ENV, /* Current value should be used, which was guessed */ - CRED_GUESS_FILE, /* A guess from a file (or file pointed at in env variable) */ -diff --git a/auth/credentials/pycredentials.c b/auth/credentials/pycredentials.c -index e583b83d9a4..171be1b0c6a 100644 ---- a/auth/credentials/pycredentials.c -+++ b/auth/credentials/pycredentials.c -@@ -1273,6 +1273,7 @@ MODULE_INIT_FUNC(credentials) - return NULL; - - PyModule_AddObject(m, "UNINITIALISED", PyLong_FromLong(CRED_UNINITIALISED)); -+ PyModule_AddObject(m, "SMB_CONF", PyLong_FromLong(CRED_SMB_CONF)); - PyModule_AddObject(m, "CALLBACK", PyLong_FromLong(CRED_CALLBACK)); - PyModule_AddObject(m, "GUESS_ENV", PyLong_FromLong(CRED_GUESS_ENV)); - PyModule_AddObject(m, "GUESS_FILE", PyLong_FromLong(CRED_GUESS_FILE)); -diff --git a/python/samba/tests/credentials.py b/python/samba/tests/credentials.py -index d2a81506de3..6454ac9ff7c 100644 ---- a/python/samba/tests/credentials.py -+++ b/python/samba/tests/credentials.py -@@ -332,7 +332,7 @@ class CredentialsTests(samba.tests.TestCaseInTempDir): - os.environ["USER"] = "env_user" - creds.guess(lp) - realm = "realm.example.com" -- creds.set_realm(realm, credentials.UNINITIALISED) -+ creds.set_realm(realm, credentials.SMB_CONF) - creds.parse_string("user") - self.assertEqual(creds.get_username(), "user") - self.assertEqual(creds.get_domain(), lp.get("workgroup").upper()) -@@ -360,7 +360,7 @@ class CredentialsTests(samba.tests.TestCaseInTempDir): - os.environ["USER"] = "env_user" - creds.guess(lp) - realm = "realm.example.com" -- creds.set_realm(realm, credentials.UNINITIALISED) -+ creds.set_realm(realm, credentials.SMB_CONF) - self.assertEqual(creds.get_username(), "env_user") - self.assertEqual(creds.get_domain(), lp.get("workgroup").upper()) - self.assertEqual(creds.get_realm(), realm.upper()) --- -2.33.1 - - -From b5fb9f7a12dc900487e32296a42278ae91b7673f Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 10 Oct 2019 14:18:23 +0200 -Subject: [PATCH 004/103] param: Add 'server smb encrypt' parameter - -And this also makes 'smb encrypt' a synonym of that. - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - .../smbdotconf/security/serversmbencrypt.xml | 241 ++++++++++++++++++ - docs-xml/smbdotconf/security/smbencrypt.xml | 241 +----------------- - source3/param/loadparm.c | 2 +- - source3/smbd/service.c | 4 +- - source3/smbd/smb2_negprot.c | 2 +- - source3/smbd/smb2_sesssetup.c | 4 +- - source3/smbd/smb2_tcon.c | 4 +- - source3/smbd/trans2.c | 2 +- - 8 files changed, 257 insertions(+), 243 deletions(-) - create mode 100644 docs-xml/smbdotconf/security/serversmbencrypt.xml - -diff --git a/docs-xml/smbdotconf/security/serversmbencrypt.xml b/docs-xml/smbdotconf/security/serversmbencrypt.xml -new file mode 100644 -index 00000000000..714aacbf1ca ---- /dev/null -+++ b/docs-xml/smbdotconf/security/serversmbencrypt.xml -@@ -0,0 +1,241 @@ -+ -+ -+ -+ This parameter controls whether a remote client is allowed or required -+ to use SMB encryption. It has different effects depending on whether -+ the connection uses SMB1 or SMB2 and newer: -+ -+ -+ -+ -+ -+ If the connection uses SMB1, then this option controls the use -+ of a Samba-specific extension to the SMB protocol introduced in -+ Samba 3.2 that makes use of the Unix extensions. -+ -+ -+ -+ -+ -+ If the connection uses SMB2 or newer, then this option controls -+ the use of the SMB-level encryption that is supported in SMB -+ version 3.0 and above and available in Windows 8 and newer. -+ -+ -+ -+ -+ -+ This parameter can be set globally and on a per-share bases. -+ Possible values are -+ -+ off, -+ if_required, -+ desired, -+ and -+ required. -+ A special value is default which is -+ the implicit default setting of if_required. -+ -+ -+ -+ -+ Effects for SMB1 -+ -+ -+ The Samba-specific encryption of SMB1 connections is an -+ extension to the SMB protocol negotiated as part of the UNIX -+ extensions. SMB encryption uses the GSSAPI (SSPI on Windows) -+ ability to encrypt and sign every request/response in a SMB -+ protocol stream. When enabled it provides a secure method of -+ SMB/CIFS communication, similar to an ssh protected session, but -+ using SMB/CIFS authentication to negotiate encryption and -+ signing keys. Currently this is only supported smbclient of by -+ Samba 3.2 and newer, and hopefully soon Linux CIFSFS and MacOS/X -+ clients. Windows clients do not support this feature. -+ -+ -+ This may be set on a per-share -+ basis, but clients may chose to encrypt the entire session, not -+ just traffic to a specific share. If this is set to mandatory -+ then all traffic to a share must -+ be encrypted once the connection has been made to the share. -+ The server would return "access denied" to all non-encrypted -+ requests on such a share. Selecting encrypted traffic reduces -+ throughput as smaller packet sizes must be used (no huge UNIX -+ style read/writes allowed) as well as the overhead of encrypting -+ and signing all the data. -+ -+ -+ -+ If SMB encryption is selected, Windows style SMB signing (see -+ the option) is no longer -+ necessary, as the GSSAPI flags use select both signing and -+ sealing of the data. -+ -+ -+ -+ When set to auto or default, SMB encryption is offered, but not -+ enforced. When set to mandatory, SMB encryption is required and -+ if set to disabled, SMB encryption can not be negotiated. -+ -+ -+ -+ -+ -+ Effects for SMB2 and newer -+ -+ -+ Native SMB transport encryption is available in SMB version 3.0 -+ or newer. It is only offered by Samba if -+ server max protocol is set to -+ SMB3 or newer. -+ Clients supporting this type of encryption include -+ Windows 8 and newer, -+ Windows server 2012 and newer, -+ and smbclient of Samba 4.1 and newer. -+ -+ -+ -+ The protocol implementation offers various options: -+ -+ -+ -+ -+ -+ The capability to perform SMB encryption can be -+ negotiated during protocol negotiation. -+ -+ -+ -+ -+ -+ Data encryption can be enabled globally. In that case, -+ an encryption-capable connection will have all traffic -+ in all its sessions encrypted. In particular all share -+ connections will be encrypted. -+ -+ -+ -+ -+ -+ Data encryption can also be enabled per share if not -+ enabled globally. For an encryption-capable connection, -+ all connections to an encryption-enabled share will be -+ encrypted. -+ -+ -+ -+ -+ -+ Encryption can be enforced. This means that session -+ setups will be denied on non-encryption-capable -+ connections if data encryption has been enabled -+ globally. And tree connections will be denied for -+ non-encryption capable connections to shares with data -+ encryption enabled. -+ -+ -+ -+ -+ -+ These features can be controlled with settings of -+ server smb encrypt as follows: -+ -+ -+ -+ -+ -+ Leaving it as default, explicitly setting -+ default, or setting it to -+ if_required globally will enable -+ negotiation of encryption but will not turn on -+ data encryption globally or per share. -+ -+ -+ -+ -+ -+ Setting it to desired globally -+ will enable negotiation and will turn on data encryption -+ on sessions and share connections for those clients -+ that support it. -+ -+ -+ -+ -+ -+ Setting it to required globally -+ will enable negotiation and turn on data encryption -+ on sessions and share connections. Clients that do -+ not support encryption will be denied access to the -+ server. -+ -+ -+ -+ -+ -+ Setting it to off globally will -+ completely disable the encryption feature for all -+ connections. Setting server smb encrypt = -+ required for individual shares (while it's -+ globally off) will deny access to this shares for all -+ clients. -+ -+ -+ -+ -+ -+ Setting it to desired on a share -+ will turn on data encryption for this share for clients -+ that support encryption if negotiation has been -+ enabled globally. -+ -+ -+ -+ -+ -+ Setting it to required on a share -+ will enforce data encryption for this share if -+ negotiation has been enabled globally. I.e. clients that -+ do not support encryption will be denied access to the -+ share. -+ -+ -+ Note that this allows per-share enforcing to be -+ controlled in Samba differently from Windows: -+ In Windows, RejectUnencryptedAccess -+ is a global setting, and if it is set, all shares with -+ data encryption turned on -+ are automatically enforcing encryption. In order to -+ achieve the same effect in Samba, one -+ has to globally set server smb encrypt to -+ if_required, and then set all shares -+ that should be encrypted to -+ required. -+ Additionally, it is possible in Samba to have some -+ shares with encryption required -+ and some other shares with encryption only -+ desired, which is not possible in -+ Windows. -+ -+ -+ -+ -+ -+ Setting it to off or -+ if_required for a share has -+ no effect. -+ -+ -+ -+ -+ -+ -+ -+ -+default -+ -diff --git a/docs-xml/smbdotconf/security/smbencrypt.xml b/docs-xml/smbdotconf/security/smbencrypt.xml -index 32a22cb58f5..798e616b765 100644 ---- a/docs-xml/smbdotconf/security/smbencrypt.xml -+++ b/docs-xml/smbdotconf/security/smbencrypt.xml -@@ -1,241 +1,14 @@ - -+ context="S" -+ type="enum" -+ enumlist="enum_smb_signing_vals" -+ function="server_smb_encrypt" -+ synonym="1" -+ xmlns:samba="http://www.samba.org/samba/DTD/samba-doc"> - - -- This parameter controls whether a remote client is allowed or required -- to use SMB encryption. It has different effects depending on whether -- the connection uses SMB1 or SMB2 and newer: -+ This is a synonym for . - -- -- -- -- -- If the connection uses SMB1, then this option controls the use -- of a Samba-specific extension to the SMB protocol introduced in -- Samba 3.2 that makes use of the Unix extensions. -- -- -- -- -- -- If the connection uses SMB2 or newer, then this option controls -- the use of the SMB-level encryption that is supported in SMB -- version 3.0 and above and available in Windows 8 and newer. -- -- -- -- -- -- This parameter can be set globally and on a per-share bases. -- Possible values are -- off (or disabled), -- enabled (or auto, or -- if_required), -- desired, -- and -- required -- (or mandatory). -- A special value is default which is -- the implicit default setting of enabled. -- -- -- -- -- Effects for SMB1 -- -- -- The Samba-specific encryption of SMB1 connections is an -- extension to the SMB protocol negotiated as part of the UNIX -- extensions. SMB encryption uses the GSSAPI (SSPI on Windows) -- ability to encrypt and sign every request/response in a SMB -- protocol stream. When enabled it provides a secure method of -- SMB/CIFS communication, similar to an ssh protected session, but -- using SMB/CIFS authentication to negotiate encryption and -- signing keys. Currently this is only supported smbclient of by -- Samba 3.2 and newer, and hopefully soon Linux CIFSFS and MacOS/X -- clients. Windows clients do not support this feature. -- -- -- This may be set on a per-share -- basis, but clients may chose to encrypt the entire session, not -- just traffic to a specific share. If this is set to mandatory -- then all traffic to a share must -- be encrypted once the connection has been made to the share. -- The server would return "access denied" to all non-encrypted -- requests on such a share. Selecting encrypted traffic reduces -- throughput as smaller packet sizes must be used (no huge UNIX -- style read/writes allowed) as well as the overhead of encrypting -- and signing all the data. -- -- -- -- If SMB encryption is selected, Windows style SMB signing (see -- the option) is no longer -- necessary, as the GSSAPI flags use select both signing and -- sealing of the data. -- -- -- -- When set to auto or default, SMB encryption is offered, but not -- enforced. When set to mandatory, SMB encryption is required and -- if set to disabled, SMB encryption can not be negotiated. -- -- -- -- -- -- Effects for SMB2 -- -- -- Native SMB transport encryption is available in SMB version 3.0 -- or newer. It is only offered by Samba if -- server max protocol is set to -- SMB3 or newer. -- Clients supporting this type of encryption include -- Windows 8 and newer, -- Windows server 2012 and newer, -- and smbclient of Samba 4.1 and newer. -- -- -- -- The protocol implementation offers various options: -- -- -- -- -- -- The capability to perform SMB encryption can be -- negotiated during protocol negotiation. -- -- -- -- -- -- Data encryption can be enabled globally. In that case, -- an encryption-capable connection will have all traffic -- in all its sessions encrypted. In particular all share -- connections will be encrypted. -- -- -- -- -- -- Data encryption can also be enabled per share if not -- enabled globally. For an encryption-capable connection, -- all connections to an encryption-enabled share will be -- encrypted. -- -- -- -- -- -- Encryption can be enforced. This means that session -- setups will be denied on non-encryption-capable -- connections if data encryption has been enabled -- globally. And tree connections will be denied for -- non-encryption capable connections to shares with data -- encryption enabled. -- -- -- -- -- -- These features can be controlled with settings of -- smb encrypt as follows: -- -- -- -- -- -- Leaving it as default, explicitly setting -- default, or setting it to -- enabled globally will enable -- negotiation of encryption but will not turn on -- data encryption globally or per share. -- -- -- -- -- -- Setting it to desired globally -- will enable negotiation and will turn on data encryption -- on sessions and share connections for those clients -- that support it. -- -- -- -- -- -- Setting it to required globally -- will enable negotiation and turn on data encryption -- on sessions and share connections. Clients that do -- not support encryption will be denied access to the -- server. -- -- -- -- -- -- Setting it to off globally will -- completely disable the encryption feature for all -- connections. Setting smb encrypt = -- required for individual shares (while it's -- globally off) will deny access to this shares for all -- clients. -- -- -- -- -- -- Setting it to desired on a share -- will turn on data encryption for this share for clients -- that support encryption if negotiation has been -- enabled globally. -- -- -- -- -- -- Setting it to required on a share -- will enforce data encryption for this share if -- negotiation has been enabled globally. I.e. clients that -- do not support encryption will be denied access to the -- share. -- -- -- Note that this allows per-share enforcing to be -- controlled in Samba differently from Windows: -- In Windows, RejectUnencryptedAccess -- is a global setting, and if it is set, all shares with -- data encryption turned on -- are automatically enforcing encryption. In order to -- achieve the same effect in Samba, one -- has to globally set smb encrypt to -- enabled, and then set all shares -- that should be encrypted to -- required. -- Additionally, it is possible in Samba to have some -- shares with encryption required -- and some other shares with encryption only -- desired, which is not possible in -- Windows. -- -- -- -- -- -- Setting it to off or -- enabled for a share has -- no effect. -- -- -- -- -- -- - - - default -diff --git a/source3/param/loadparm.c b/source3/param/loadparm.c -index 56cf0abb33a..cf969c18c66 100644 ---- a/source3/param/loadparm.c -+++ b/source3/param/loadparm.c -@@ -241,7 +241,7 @@ static const struct loadparm_service _sDefault = - .aio_write_size = 1, - .map_readonly = MAP_READONLY_NO, - .directory_name_cache_size = 100, -- .smb_encrypt = SMB_SIGNING_DEFAULT, -+ .server_smb_encrypt = SMB_SIGNING_DEFAULT, - .kernel_share_modes = true, - .durable_handles = true, - .check_parent_directory_delete_on_close = false, -diff --git a/source3/smbd/service.c b/source3/smbd/service.c -index 3802d16179b..9aa89e3eb02 100644 ---- a/source3/smbd/service.c -+++ b/source3/smbd/service.c -@@ -558,9 +558,9 @@ static NTSTATUS make_connection_snum(struct smbXsrv_connection *xconn, - /* Case options for the share. */ - conn_setup_case_options(conn); - -- conn->encrypt_level = lp_smb_encrypt(snum); -+ conn->encrypt_level = lp_server_smb_encrypt(snum); - if (conn->encrypt_level > SMB_SIGNING_OFF) { -- if (lp_smb_encrypt(-1) == SMB_SIGNING_OFF) { -+ if (lp_server_smb_encrypt(-1) == SMB_SIGNING_OFF) { - if (conn->encrypt_level == SMB_SIGNING_REQUIRED) { - DBG_ERR("Service [%s] requires encryption, but " - "it is disabled globally!\n", -diff --git a/source3/smbd/smb2_negprot.c b/source3/smbd/smb2_negprot.c -index 4071f42b5e0..674942b71de 100644 ---- a/source3/smbd/smb2_negprot.c -+++ b/source3/smbd/smb2_negprot.c -@@ -335,7 +335,7 @@ NTSTATUS smbd_smb2_request_process_negprot(struct smbd_smb2_request *req) - } - - if ((protocol >= PROTOCOL_SMB2_24) && -- (lp_smb_encrypt(-1) != SMB_SIGNING_OFF) && -+ (lp_server_smb_encrypt(-1) != SMB_SIGNING_OFF) && - (in_capabilities & SMB2_CAP_ENCRYPTION)) { - capabilities |= SMB2_CAP_ENCRYPTION; - } -diff --git a/source3/smbd/smb2_sesssetup.c b/source3/smbd/smb2_sesssetup.c -index 2b6b3a820d4..8957411e167 100644 ---- a/source3/smbd/smb2_sesssetup.c -+++ b/source3/smbd/smb2_sesssetup.c -@@ -292,12 +292,12 @@ static NTSTATUS smbd_smb2_auth_generic_return(struct smbXsrv_session *session, - x->global->signing_flags = SMBXSRV_SIGNING_REQUIRED; - } - -- if ((lp_smb_encrypt(-1) >= SMB_SIGNING_DESIRED) && -+ if ((lp_server_smb_encrypt(-1) >= SMB_SIGNING_DESIRED) && - (xconn->smb2.client.capabilities & SMB2_CAP_ENCRYPTION)) { - x->global->encryption_flags = SMBXSRV_ENCRYPTION_DESIRED; - } - -- if (lp_smb_encrypt(-1) == SMB_SIGNING_REQUIRED) { -+ if (lp_server_smb_encrypt(-1) == SMB_SIGNING_REQUIRED) { - x->global->encryption_flags = SMBXSRV_ENCRYPTION_REQUIRED | - SMBXSRV_ENCRYPTION_DESIRED; - } -diff --git a/source3/smbd/smb2_tcon.c b/source3/smbd/smb2_tcon.c -index 76112d04889..0dd3c653b4b 100644 ---- a/source3/smbd/smb2_tcon.c -+++ b/source3/smbd/smb2_tcon.c -@@ -302,13 +302,13 @@ static NTSTATUS smbd_smb2_tree_connect(struct smbd_smb2_request *req, - TALLOC_FREE(proxy); - } - -- if ((lp_smb_encrypt(snum) >= SMB_SIGNING_DESIRED) && -+ if ((lp_server_smb_encrypt(snum) >= SMB_SIGNING_DESIRED) && - (conn->smb2.server.cipher != 0)) - { - encryption_desired = true; - } - -- if (lp_smb_encrypt(snum) == SMB_SIGNING_REQUIRED) { -+ if (lp_server_smb_encrypt(snum) == SMB_SIGNING_REQUIRED) { - encryption_desired = true; - encryption_required = true; - } -diff --git a/source3/smbd/trans2.c b/source3/smbd/trans2.c -index 7acde285a90..b745e0906b1 100644 ---- a/source3/smbd/trans2.c -+++ b/source3/smbd/trans2.c -@@ -4484,7 +4484,7 @@ static void call_trans2setfsinfo(connection_struct *conn, - return; - } - -- if (lp_smb_encrypt(SNUM(conn)) == SMB_SIGNING_OFF) { -+ if (lp_server_smb_encrypt(SNUM(conn)) == SMB_SIGNING_OFF) { - reply_nterror( - req, - NT_STATUS_NOT_SUPPORTED); --- -2.33.1 - - -From bc64cc476c6bb5a1bb01ad734004ab1fdb167a1b Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 28 May 2020 10:04:19 +0200 -Subject: [PATCH 005/103] param: Create and use enum_smb_encryption_vals - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - .../smbdotconf/security/serversmbencrypt.xml | 2 +- - docs-xml/smbdotconf/security/smbencrypt.xml | 2 +- - lib/param/param_table.c | 23 +++++++++++++++++++ - libcli/smb/smb_constants.h | 9 ++++++++ - 4 files changed, 34 insertions(+), 2 deletions(-) - -diff --git a/docs-xml/smbdotconf/security/serversmbencrypt.xml b/docs-xml/smbdotconf/security/serversmbencrypt.xml -index 714aacbf1ca..5f38b46419e 100644 ---- a/docs-xml/smbdotconf/security/serversmbencrypt.xml -+++ b/docs-xml/smbdotconf/security/serversmbencrypt.xml -@@ -1,7 +1,7 @@ - - - -diff --git a/docs-xml/smbdotconf/security/smbencrypt.xml b/docs-xml/smbdotconf/security/smbencrypt.xml -index 798e616b765..60271200c0a 100644 ---- a/docs-xml/smbdotconf/security/smbencrypt.xml -+++ b/docs-xml/smbdotconf/security/smbencrypt.xml -@@ -1,7 +1,7 @@ - -diff --git a/lib/param/param_table.c b/lib/param/param_table.c -index 780252017d2..3dc5fc59991 100644 ---- a/lib/param/param_table.c -+++ b/lib/param/param_table.c -@@ -139,6 +139,29 @@ static const struct enum_list enum_smb_signing_vals[] = { - {-1, NULL} - }; - -+static const struct enum_list enum_smb_encryption_vals[] = { -+ {SMB_ENCRYPTION_DEFAULT, "default"}, -+ {SMB_ENCRYPTION_OFF, "No"}, -+ {SMB_ENCRYPTION_OFF, "False"}, -+ {SMB_ENCRYPTION_OFF, "0"}, -+ {SMB_ENCRYPTION_OFF, "Off"}, -+ {SMB_ENCRYPTION_OFF, "disabled"}, -+ {SMB_ENCRYPTION_IF_REQUIRED, "if_required"}, -+ {SMB_ENCRYPTION_IF_REQUIRED, "Yes"}, -+ {SMB_ENCRYPTION_IF_REQUIRED, "True"}, -+ {SMB_ENCRYPTION_IF_REQUIRED, "1"}, -+ {SMB_ENCRYPTION_IF_REQUIRED, "On"}, -+ {SMB_ENCRYPTION_IF_REQUIRED, "enabled"}, -+ {SMB_ENCRYPTION_IF_REQUIRED, "auto"}, -+ {SMB_ENCRYPTION_DESIRED, "desired"}, -+ {SMB_ENCRYPTION_REQUIRED, "required"}, -+ {SMB_ENCRYPTION_REQUIRED, "mandatory"}, -+ {SMB_ENCRYPTION_REQUIRED, "force"}, -+ {SMB_ENCRYPTION_REQUIRED, "forced"}, -+ {SMB_ENCRYPTION_REQUIRED, "enforced"}, -+ {-1, NULL} -+}; -+ - static const struct enum_list enum_mdns_name_values[] = { - {MDNS_NAME_NETBIOS, "netbios"}, - {MDNS_NAME_MDNS, "mdns"}, -diff --git a/libcli/smb/smb_constants.h b/libcli/smb/smb_constants.h -index af8e7204013..8e757dbc5b5 100644 ---- a/libcli/smb/smb_constants.h -+++ b/libcli/smb/smb_constants.h -@@ -106,6 +106,15 @@ enum smb_signing_setting { - SMB_SIGNING_REQUIRED = 3, - }; - -+/* This MUST align with 'enum smb_signing_setting' */ -+enum smb_encryption_setting { -+ SMB_ENCRYPTION_DEFAULT = SMB_SIGNING_DEFAULT, -+ SMB_ENCRYPTION_OFF = SMB_SIGNING_OFF, -+ SMB_ENCRYPTION_IF_REQUIRED = SMB_SIGNING_IF_REQUIRED, -+ SMB_ENCRYPTION_DESIRED = SMB_SIGNING_DESIRED, -+ SMB_ENCRYPTION_REQUIRED = SMB_SIGNING_REQUIRED, -+}; -+ - /* types of buffers in core SMB protocol */ - #define SMB_DATA_BLOCK 0x1 - #define SMB_ASCII4 0x4 --- -2.33.1 - - -From c18739c3022304776864f558b8c712e5f000722f Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Tue, 26 May 2020 09:34:54 +0200 -Subject: [PATCH 006/103] s3:smbd: Use 'enum smb_encryption_setting' values - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - source3/param/loadparm.c | 2 +- - source3/smbd/service.c | 8 ++++---- - source3/smbd/smb2_negprot.c | 2 +- - source3/smbd/smb2_sesssetup.c | 4 ++-- - source3/smbd/smb2_tcon.c | 4 ++-- - source3/smbd/trans2.c | 3 ++- - 6 files changed, 12 insertions(+), 11 deletions(-) - -diff --git a/source3/param/loadparm.c b/source3/param/loadparm.c -index cf969c18c66..1df42ed530e 100644 ---- a/source3/param/loadparm.c -+++ b/source3/param/loadparm.c -@@ -241,7 +241,7 @@ static const struct loadparm_service _sDefault = - .aio_write_size = 1, - .map_readonly = MAP_READONLY_NO, - .directory_name_cache_size = 100, -- .server_smb_encrypt = SMB_SIGNING_DEFAULT, -+ .server_smb_encrypt = SMB_ENCRYPTION_DEFAULT, - .kernel_share_modes = true, - .durable_handles = true, - .check_parent_directory_delete_on_close = false, -diff --git a/source3/smbd/service.c b/source3/smbd/service.c -index 9aa89e3eb02..d7d17d3dee1 100644 ---- a/source3/smbd/service.c -+++ b/source3/smbd/service.c -@@ -559,16 +559,16 @@ static NTSTATUS make_connection_snum(struct smbXsrv_connection *xconn, - conn_setup_case_options(conn); - - conn->encrypt_level = lp_server_smb_encrypt(snum); -- if (conn->encrypt_level > SMB_SIGNING_OFF) { -- if (lp_server_smb_encrypt(-1) == SMB_SIGNING_OFF) { -- if (conn->encrypt_level == SMB_SIGNING_REQUIRED) { -+ if (conn->encrypt_level > SMB_ENCRYPTION_OFF) { -+ if (lp_server_smb_encrypt(-1) == SMB_ENCRYPTION_OFF) { -+ if (conn->encrypt_level == SMB_ENCRYPTION_REQUIRED) { - DBG_ERR("Service [%s] requires encryption, but " - "it is disabled globally!\n", - lp_const_servicename(snum)); - status = NT_STATUS_ACCESS_DENIED; - goto err_root_exit; - } -- conn->encrypt_level = SMB_SIGNING_OFF; -+ conn->encrypt_level = SMB_ENCRYPTION_OFF; - } - } - -diff --git a/source3/smbd/smb2_negprot.c b/source3/smbd/smb2_negprot.c -index 674942b71de..99303f1b07b 100644 ---- a/source3/smbd/smb2_negprot.c -+++ b/source3/smbd/smb2_negprot.c -@@ -335,7 +335,7 @@ NTSTATUS smbd_smb2_request_process_negprot(struct smbd_smb2_request *req) - } - - if ((protocol >= PROTOCOL_SMB2_24) && -- (lp_server_smb_encrypt(-1) != SMB_SIGNING_OFF) && -+ (lp_server_smb_encrypt(-1) != SMB_ENCRYPTION_OFF) && - (in_capabilities & SMB2_CAP_ENCRYPTION)) { - capabilities |= SMB2_CAP_ENCRYPTION; - } -diff --git a/source3/smbd/smb2_sesssetup.c b/source3/smbd/smb2_sesssetup.c -index 8957411e167..907dd92321e 100644 ---- a/source3/smbd/smb2_sesssetup.c -+++ b/source3/smbd/smb2_sesssetup.c -@@ -292,12 +292,12 @@ static NTSTATUS smbd_smb2_auth_generic_return(struct smbXsrv_session *session, - x->global->signing_flags = SMBXSRV_SIGNING_REQUIRED; - } - -- if ((lp_server_smb_encrypt(-1) >= SMB_SIGNING_DESIRED) && -+ if ((lp_server_smb_encrypt(-1) >= SMB_ENCRYPTION_DESIRED) && - (xconn->smb2.client.capabilities & SMB2_CAP_ENCRYPTION)) { - x->global->encryption_flags = SMBXSRV_ENCRYPTION_DESIRED; - } - -- if (lp_server_smb_encrypt(-1) == SMB_SIGNING_REQUIRED) { -+ if (lp_server_smb_encrypt(-1) == SMB_ENCRYPTION_REQUIRED) { - x->global->encryption_flags = SMBXSRV_ENCRYPTION_REQUIRED | - SMBXSRV_ENCRYPTION_DESIRED; - } -diff --git a/source3/smbd/smb2_tcon.c b/source3/smbd/smb2_tcon.c -index 0dd3c653b4b..d7e0cf90f47 100644 ---- a/source3/smbd/smb2_tcon.c -+++ b/source3/smbd/smb2_tcon.c -@@ -302,13 +302,13 @@ static NTSTATUS smbd_smb2_tree_connect(struct smbd_smb2_request *req, - TALLOC_FREE(proxy); - } - -- if ((lp_server_smb_encrypt(snum) >= SMB_SIGNING_DESIRED) && -+ if ((lp_server_smb_encrypt(snum) >= SMB_ENCRYPTION_DESIRED) && - (conn->smb2.server.cipher != 0)) - { - encryption_desired = true; - } - -- if (lp_server_smb_encrypt(snum) == SMB_SIGNING_REQUIRED) { -+ if (lp_server_smb_encrypt(snum) == SMB_ENCRYPTION_REQUIRED) { - encryption_desired = true; - encryption_required = true; - } -diff --git a/source3/smbd/trans2.c b/source3/smbd/trans2.c -index b745e0906b1..2f2fdcb7260 100644 ---- a/source3/smbd/trans2.c -+++ b/source3/smbd/trans2.c -@@ -4484,7 +4484,8 @@ static void call_trans2setfsinfo(connection_struct *conn, - return; - } - -- if (lp_server_smb_encrypt(SNUM(conn)) == SMB_SIGNING_OFF) { -+ if (lp_server_smb_encrypt(SNUM(conn)) == -+ SMB_ENCRYPTION_OFF) { - reply_nterror( - req, - NT_STATUS_NOT_SUPPORTED); --- -2.33.1 - - -From a10ae5f534dd548049073e0991ef1000d8395e8d Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 9 Apr 2020 10:38:41 +0200 -Subject: [PATCH 007/103] docs-xml: Add 'client smb encrypt' - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - .../smbdotconf/security/clientsmbencrypt.xml | 126 ++++++++++++++++++ - lib/param/loadparm.c | 3 + - source3/param/loadparm.c | 1 + - 3 files changed, 130 insertions(+) - create mode 100644 docs-xml/smbdotconf/security/clientsmbencrypt.xml - -diff --git a/docs-xml/smbdotconf/security/clientsmbencrypt.xml b/docs-xml/smbdotconf/security/clientsmbencrypt.xml -new file mode 100644 -index 00000000000..05df152e734 ---- /dev/null -+++ b/docs-xml/smbdotconf/security/clientsmbencrypt.xml -@@ -0,0 +1,126 @@ -+ -+ -+ -+ This parameter controls whether a client should try or is required -+ to use SMB encryption. It has different effects depending on whether -+ the connection uses SMB1 or SMB3: -+ -+ -+ -+ -+ -+ If the connection uses SMB1, then this option controls the use -+ of a Samba-specific extension to the SMB protocol introduced in -+ Samba 3.2 that makes use of the Unix extensions. -+ -+ -+ -+ -+ -+ If the connection uses SMB2 or newer, then this option controls -+ the use of the SMB-level encryption that is supported in SMB -+ version 3.0 and above and available in Windows 8 and newer. -+ -+ -+ -+ -+ -+ This parameter can be set globally. Possible values are -+ -+ off, -+ if_required, -+ desired, -+ and -+ required. -+ A special value is default which is -+ the implicit default setting of if_required. -+ -+ -+ -+ -+ Effects for SMB1 -+ -+ -+ The Samba-specific encryption of SMB1 connections is an -+ extension to the SMB protocol negotiated as part of the UNIX -+ extensions. SMB encryption uses the GSSAPI (SSPI on Windows) -+ ability to encrypt and sign every request/response in a SMB -+ protocol stream. When enabled it provides a secure method of -+ SMB/CIFS communication, similar to an ssh protected session, but -+ using SMB/CIFS authentication to negotiate encryption and -+ signing keys. Currently this is only supported smbclient of by -+ Samba 3.2 and newer. Windows does not support this feature. -+ -+ -+ -+ When set to default, SMB encryption is probed, but not -+ enforced. When set to required, SMB encryption is required and -+ if set to disabled, SMB encryption can not be negotiated. -+ -+ -+ -+ -+ -+ Effects for SMB3 and newer -+ -+ -+ Native SMB transport encryption is available in SMB version 3.0 -+ or newer. It is only used by Samba if -+ client max protocol is set to -+ SMB3 or newer. -+ -+ -+ -+ These features can be controlled with settings of -+ client smb encrypt as follows: -+ -+ -+ -+ -+ -+ Leaving it as default, explicitly setting -+ default, or setting it to -+ if_required globally will enable -+ negotiation of encryption but will not turn on -+ data encryption globally. -+ -+ -+ -+ -+ -+ Setting it to desired globally -+ will enable negotiation and will turn on data encryption -+ on sessions and share connections for those servers -+ that support it. -+ -+ -+ -+ -+ -+ Setting it to required globally -+ will enable negotiation and turn on data encryption -+ on sessions and share connections. Clients that do -+ not support encryption will be denied access to the -+ server. -+ -+ -+ -+ -+ -+ Setting it to off globally will -+ completely disable the encryption feature for all -+ connections. -+ -+ -+ -+ -+ -+ -+ -+ -+default -+ -diff --git a/lib/param/loadparm.c b/lib/param/loadparm.c -index d2f6e6241ad..f894f3fa2d4 100644 ---- a/lib/param/loadparm.c -+++ b/lib/param/loadparm.c -@@ -3082,6 +3082,9 @@ struct loadparm_context *loadparm_init(TALLOC_CTX *mem_ctx) - lpcfg_do_global_parameter(lp_ctx, - "min domain uid", - "1000"); -+ lpcfg_do_global_parameter(lp_ctx, -+ "client smb encrypt", -+ "default"); - - for (i = 0; parm_table[i].label; i++) { - if (!(lp_ctx->flags[i] & FLAG_CMDLINE)) { -diff --git a/source3/param/loadparm.c b/source3/param/loadparm.c -index 1df42ed530e..96b4e3f39c0 100644 ---- a/source3/param/loadparm.c -+++ b/source3/param/loadparm.c -@@ -961,6 +961,7 @@ static void init_globals(struct loadparm_context *lp_ctx, bool reinit_globals) - Globals.ldap_max_search_request_size = 256000; - - Globals.min_domain_uid = 1000; -+ Globals.client_smb_encrypt = SMB_ENCRYPTION_DEFAULT; - - /* Now put back the settings that were set with lp_set_cmdline() */ - apply_lp_set_cmdline(); --- -2.33.1 - - -From 9bd56e83b5f03b02e771a7c993e5a949457bdb4e Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Wed, 22 Jul 2020 17:48:25 +0200 -Subject: [PATCH 008/103] lib:param: Add lpcfg_parse_enum_vals() - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - lib/param/loadparm.c | 30 ++++++++++++++++++++++++++++++ - lib/param/loadparm.h | 2 ++ - 2 files changed, 32 insertions(+) - -diff --git a/lib/param/loadparm.c b/lib/param/loadparm.c -index f894f3fa2d4..521ce78b548 100644 ---- a/lib/param/loadparm.c -+++ b/lib/param/loadparm.c -@@ -3678,3 +3678,33 @@ char *lpcfg_substituted_string(TALLOC_CTX *mem_ctx, - raw_value, - lp_sub->private_data); - } -+ -+/** -+ * @brief Parse a string value of a given parameter to its integer enum value. -+ * -+ * @param[in] param_name The parameter name (e.g. 'client smb encrypt') -+ * -+ * @param[in] param_value The parameter value (e.g. 'required'). -+ * -+ * @return The integer value of the enum the param_value matches or INT32_MIN -+ * on error. -+ */ -+int32_t lpcfg_parse_enum_vals(const char *param_name, -+ const char *param_value) -+{ -+ struct parm_struct *parm = NULL; -+ int32_t ret = INT32_MIN; -+ bool ok; -+ -+ parm = lpcfg_parm_struct(NULL, param_name); -+ if (parm == NULL) { -+ return INT32_MIN; -+ } -+ -+ ok = lp_set_enum_parm(parm, param_value, &ret); -+ if (!ok) { -+ return INT32_MIN; -+ } -+ -+ return ret; -+} -diff --git a/lib/param/loadparm.h b/lib/param/loadparm.h -index 323fcf84523..e66ce2324b4 100644 ---- a/lib/param/loadparm.h -+++ b/lib/param/loadparm.h -@@ -316,6 +316,8 @@ bool lp_do_section(const char *pszSectionName, void *userdata); - bool store_lp_set_cmdline(const char *pszParmName, const char *pszParmValue); - - int num_parameters(void); -+int32_t lpcfg_parse_enum_vals(const char *param_name, -+ const char *param_value); - - struct loadparm_substitution; - #ifdef LOADPARM_SUBSTITUTION_INTERNALS --- -2.33.1 - - -From ed8db9c1a25596fb294f15b27d8e5f96101e3c6e Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Wed, 9 Oct 2019 09:38:08 +0200 -Subject: [PATCH 009/103] libcli:smb: Add smb_signing_setting_translate() - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - libcli/smb/smb_util.h | 7 ++++ - libcli/smb/test_util_translate.c | 64 ++++++++++++++++++++++++++++++++ - libcli/smb/util.c | 20 ++++++++++ - libcli/smb/wscript | 5 +++ - selftest/tests.py | 2 + - 5 files changed, 98 insertions(+) - create mode 100644 libcli/smb/test_util_translate.c - -diff --git a/libcli/smb/smb_util.h b/libcli/smb/smb_util.h -index 8861741c92f..15bdbe856d1 100644 ---- a/libcli/smb/smb_util.h -+++ b/libcli/smb/smb_util.h -@@ -24,6 +24,9 @@ - #include "smb_constants.h" - #include - -+#ifndef _SMB_UTIL_H -+#define _SMB_UTIL_H -+ - const char *smb_protocol_types_string(enum protocol_types protocol); - char *attrib_string(TALLOC_CTX *mem_ctx, uint32_t attrib); - uint32_t unix_perms_to_wire(mode_t perms); -@@ -46,3 +49,7 @@ NTSTATUS smb_bytes_pull_str(TALLOC_CTX *mem_ctx, char **_str, bool ucs2, - const uint8_t *buf, size_t buf_len, - const uint8_t *position, - size_t *_consumed); -+ -+enum smb_signing_setting smb_signing_setting_translate(const char *str); -+ -+#endif /* _SMB_UTIL_H */ -diff --git a/libcli/smb/test_util_translate.c b/libcli/smb/test_util_translate.c -new file mode 100644 -index 00000000000..4b81984affa ---- /dev/null -+++ b/libcli/smb/test_util_translate.c -@@ -0,0 +1,64 @@ -+/* -+ * Unix SMB/CIFS implementation. -+ * -+ * Copyright (C) 2020 Andreas Schneider -+ * -+ * This program is free software; you can redistribute it and/or modify -+ * it under the terms of the GNU General Public License as published by -+ * the Free Software Foundation; either version 3 of the License, or -+ * (at your option) any later version. -+ * -+ * This program is distributed in the hope that it will be useful, -+ * but WITHOUT ANY WARRANTY; without even the implied warranty of -+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the -+ * GNU General Public License for more details. -+ * -+ * You should have received a copy of the GNU General Public License -+ * along with this program. If not, see . -+ */ -+ -+#include -+#include -+#include -+#include -+#include -+ -+#include "lib/replace/replace.h" -+#include -+ -+#include "libcli/smb/util.c" -+ -+static void test_smb_signing_setting_translate(void **state) -+{ -+ enum smb_signing_setting signing_state; -+ -+ signing_state = smb_signing_setting_translate("wurst"); -+ assert_int_equal(signing_state, SMB_SIGNING_REQUIRED); -+ -+ signing_state = smb_signing_setting_translate("off"); -+ assert_int_equal(signing_state, SMB_SIGNING_OFF); -+ -+ signing_state = smb_signing_setting_translate("if_required"); -+ assert_int_equal(signing_state, SMB_SIGNING_IF_REQUIRED); -+ -+ signing_state = smb_signing_setting_translate("mandatory"); -+ assert_int_equal(signing_state, SMB_SIGNING_REQUIRED); -+ -+} -+ -+int main(int argc, char *argv[]) -+{ -+ int rc; -+ const struct CMUnitTest tests[] = { -+ cmocka_unit_test(test_smb_signing_setting_translate), -+ }; -+ -+ if (argc == 2) { -+ cmocka_set_test_filter(argv[1]); -+ } -+ cmocka_set_message_output(CM_OUTPUT_SUBUNIT); -+ -+ rc = cmocka_run_group_tests(tests, NULL, NULL); -+ -+ return rc; -+} -diff --git a/libcli/smb/util.c b/libcli/smb/util.c -index 6fdf35fbbf3..da0e4db2bf3 100644 ---- a/libcli/smb/util.c -+++ b/libcli/smb/util.c -@@ -22,6 +22,7 @@ - #include "includes.h" - #include "libcli/smb/smb_common.h" - #include "system/filesys.h" -+#include "lib/param/loadparm.h" - - const char *smb_protocol_types_string(enum protocol_types protocol) - { -@@ -428,3 +429,22 @@ NTSTATUS smb_bytes_pull_str(TALLOC_CTX *mem_ctx, char **_str, bool ucs2, - return internal_bytes_pull_str(mem_ctx, _str, ucs2, true, - buf, buf_len, position, _consumed); - } -+ -+/** -+ * @brief Translate SMB signing settings as string to an enum. -+ * -+ * @param[in] str The string to translate. -+ * -+ * @return A corresponding enum @smb_signing_setting tranlated from the string. -+ */ -+enum smb_signing_setting smb_signing_setting_translate(const char *str) -+{ -+ enum smb_signing_setting signing_state = SMB_SIGNING_REQUIRED; -+ int32_t val = lpcfg_parse_enum_vals("client signing", str); -+ -+ if (val != INT32_MIN) { -+ signing_state = val; -+ } -+ -+ return signing_state; -+} -diff --git a/libcli/smb/wscript b/libcli/smb/wscript -index 86e377f570b..c047fd33278 100644 ---- a/libcli/smb/wscript -+++ b/libcli/smb/wscript -@@ -72,3 +72,8 @@ def build(bld): - source='test_smb1cli_session.c', - deps='cmocka cli_smb_common', - for_selftest=True) -+ -+ bld.SAMBA_BINARY('test_util_translate', -+ source='test_util_translate.c', -+ deps='cmocka cli_smb_common', -+ for_selftest=True) -diff --git a/selftest/tests.py b/selftest/tests.py -index a2b8bf5c4d5..68cbcd5fbf1 100644 ---- a/selftest/tests.py -+++ b/selftest/tests.py -@@ -378,6 +378,8 @@ plantestsuite("samba.unittests.lib_util_modules", "none", - - plantestsuite("samba.unittests.smb1cli_session", "none", - [os.path.join(bindir(), "default/libcli/smb/test_smb1cli_session")]) -+plantestsuite("samba.unittests.smb_util_translate", "none", -+ [os.path.join(bindir(), "default/libcli/smb/test_util_translate")]) - - plantestsuite("samba.unittests.talloc_keep_secret", "none", - [os.path.join(bindir(), "default/lib/util/test_talloc_keep_secret")]) --- -2.33.1 - - -From cbe5aaf56bc96993bcb463540371cd4b15b065e2 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Tue, 26 May 2020 08:39:34 +0200 -Subject: [PATCH 010/103] libcli:smb: Add smb_encryption_setting_translate() - -Add encryption enum and function to avoid confusion when reading the -code. - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - libcli/smb/smb_util.h | 1 + - libcli/smb/test_util_translate.c | 19 +++++++++++++++++++ - libcli/smb/util.c | 20 ++++++++++++++++++++ - 3 files changed, 40 insertions(+) - -diff --git a/libcli/smb/smb_util.h b/libcli/smb/smb_util.h -index 15bdbe856d1..2a727db8b6f 100644 ---- a/libcli/smb/smb_util.h -+++ b/libcli/smb/smb_util.h -@@ -51,5 +51,6 @@ NTSTATUS smb_bytes_pull_str(TALLOC_CTX *mem_ctx, char **_str, bool ucs2, - size_t *_consumed); - - enum smb_signing_setting smb_signing_setting_translate(const char *str); -+enum smb_encryption_setting smb_encryption_setting_translate(const char *str); - - #endif /* _SMB_UTIL_H */ -diff --git a/libcli/smb/test_util_translate.c b/libcli/smb/test_util_translate.c -index 4b81984affa..b300af52c09 100644 ---- a/libcli/smb/test_util_translate.c -+++ b/libcli/smb/test_util_translate.c -@@ -46,11 +46,30 @@ static void test_smb_signing_setting_translate(void **state) - - } - -+static void test_smb_encryption_setting_translate(void **state) -+{ -+ enum smb_encryption_setting encryption_state; -+ -+ encryption_state = smb_encryption_setting_translate("wurst"); -+ assert_int_equal(encryption_state, SMB_ENCRYPTION_REQUIRED); -+ -+ encryption_state = smb_encryption_setting_translate("off"); -+ assert_int_equal(encryption_state, SMB_ENCRYPTION_OFF); -+ -+ encryption_state = smb_encryption_setting_translate("if_required"); -+ assert_int_equal(encryption_state, SMB_ENCRYPTION_IF_REQUIRED); -+ -+ encryption_state = smb_encryption_setting_translate("mandatory"); -+ assert_int_equal(encryption_state, SMB_ENCRYPTION_REQUIRED); -+ -+} -+ - int main(int argc, char *argv[]) - { - int rc; - const struct CMUnitTest tests[] = { - cmocka_unit_test(test_smb_signing_setting_translate), -+ cmocka_unit_test(test_smb_encryption_setting_translate), - }; - - if (argc == 2) { -diff --git a/libcli/smb/util.c b/libcli/smb/util.c -index da0e4db2bf3..ac2887ee5c4 100644 ---- a/libcli/smb/util.c -+++ b/libcli/smb/util.c -@@ -448,3 +448,23 @@ enum smb_signing_setting smb_signing_setting_translate(const char *str) - - return signing_state; - } -+ -+/** -+ * @brief Translate SMB encryption settings as string to an enum. -+ * -+ * @param[in] str The string to translate. -+ * -+ * @return A corresponding enum @smb_encryption_setting tranlated from the -+ * string. -+ */ -+enum smb_encryption_setting smb_encryption_setting_translate(const char *str) -+{ -+ enum smb_encryption_setting encryption_state = SMB_ENCRYPTION_REQUIRED; -+ int32_t val = lpcfg_parse_enum_vals("client smb encrypt", str); -+ -+ if (val != INT32_MIN) { -+ encryption_state = val; -+ } -+ -+ return encryption_state; -+} --- -2.33.1 - - -From 717b0a825460d1fbfe8f35864ba3ee3393ba5117 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Wed, 9 Oct 2019 09:47:59 +0200 -Subject: [PATCH 011/103] s3:lib: Use smb_signing_setting_translate for cmdline - parsing - -The function will be removed soon. - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - source3/lib/util_cmdline.c | 17 +++-------------- - source3/wscript_build | 2 +- - 2 files changed, 4 insertions(+), 15 deletions(-) - -diff --git a/source3/lib/util_cmdline.c b/source3/lib/util_cmdline.c -index 90ee67c4cb7..bc1f1c3ed25 100644 ---- a/source3/lib/util_cmdline.c -+++ b/source3/lib/util_cmdline.c -@@ -28,6 +28,7 @@ - #include "librpc/gen_ndr/samr.h" - #include "auth/credentials/credentials.h" - #include "auth/gensec/gensec.h" -+#include "libcli/smb/smb_util.h" - - /**************************************************************************n - Code to cope with username/password auth options from the commandline. -@@ -240,20 +241,8 @@ void set_cmdline_auth_info_password(struct user_auth_info *auth_info, - bool set_cmdline_auth_info_signing_state(struct user_auth_info *auth_info, - const char *arg) - { -- auth_info->signing_state = SMB_SIGNING_DEFAULT; -- if (strequal(arg, "off") || strequal(arg, "no") || -- strequal(arg, "false")) { -- auth_info->signing_state = SMB_SIGNING_OFF; -- } else if (strequal(arg, "on") || strequal(arg, "yes") || -- strequal(arg, "if_required") || -- strequal(arg, "true") || strequal(arg, "auto")) { -- auth_info->signing_state = SMB_SIGNING_IF_REQUIRED; -- } else if (strequal(arg, "force") || strequal(arg, "required") || -- strequal(arg, "forced")) { -- auth_info->signing_state = SMB_SIGNING_REQUIRED; -- } else { -- return false; -- } -+ auth_info->signing_state = smb_signing_setting_translate(arg); -+ - return true; - } - -diff --git a/source3/wscript_build b/source3/wscript_build -index 46c914c7b22..8178d5b6ab3 100644 ---- a/source3/wscript_build -+++ b/source3/wscript_build -@@ -279,7 +279,7 @@ bld.SAMBA3_LIBRARY('popt_samba3_cmdline', - - bld.SAMBA3_LIBRARY('util_cmdline', - source='lib/util_cmdline.c', -- deps='secrets3 samba-credentials', -+ deps='secrets3 samba-credentials cli_smb_common', - private_library=True) - - bld.SAMBA3_LIBRARY('cmdline_contexts', --- -2.33.1 - - -From 7b83c50814e121a0fd5b5e0f11b2e6e0d3efd3c1 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 23 Jul 2020 07:47:18 +0200 -Subject: [PATCH 012/103] auth:creds: Remove unused credentials autoproto - header - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - auth/credentials/credentials_krb5.c | 1 - - auth/credentials/credentials_secrets.c | 1 - - auth/credentials/wscript_build | 1 - - source4/auth/kerberos/kerberos_util.c | 1 - - source4/auth/tests/kerberos.c | 1 - - 5 files changed, 5 deletions(-) - -diff --git a/auth/credentials/credentials_krb5.c b/auth/credentials/credentials_krb5.c -index 61e55f7032d..2d2fccfff88 100644 ---- a/auth/credentials/credentials_krb5.c -+++ b/auth/credentials/credentials_krb5.c -@@ -27,7 +27,6 @@ - #include "auth/kerberos/kerberos.h" - #include "auth/credentials/credentials.h" - #include "auth/credentials/credentials_internal.h" --#include "auth/credentials/credentials_proto.h" - #include "auth/credentials/credentials_krb5.h" - #include "auth/kerberos/kerberos_credentials.h" - #include "auth/kerberos/kerberos_srv_keytab.h" -diff --git a/auth/credentials/credentials_secrets.c b/auth/credentials/credentials_secrets.c -index 54f3ce2d078..52a89d4d5b4 100644 ---- a/auth/credentials/credentials_secrets.c -+++ b/auth/credentials/credentials_secrets.c -@@ -29,7 +29,6 @@ - #include "system/filesys.h" - #include "auth/credentials/credentials.h" - #include "auth/credentials/credentials_internal.h" --#include "auth/credentials/credentials_proto.h" - #include "auth/credentials/credentials_krb5.h" - #include "auth/kerberos/kerberos_util.h" - #include "param/param.h" -diff --git a/auth/credentials/wscript_build b/auth/credentials/wscript_build -index f5aba1de248..564a04fe8dd 100644 ---- a/auth/credentials/wscript_build -+++ b/auth/credentials/wscript_build -@@ -2,7 +2,6 @@ - - bld.SAMBA_LIBRARY('samba-credentials', - source='credentials.c', -- autoproto='credentials_proto.h', - public_headers='credentials.h', - pc_files='samba-credentials.pc', - deps='LIBCRYPTO samba-errors events LIBCLI_AUTH samba-security CREDENTIALS_SECRETS CREDENTIALS_KRB5', -diff --git a/source4/auth/kerberos/kerberos_util.c b/source4/auth/kerberos/kerberos_util.c -index ffef24f285c..544d9d853cc 100644 ---- a/source4/auth/kerberos/kerberos_util.c -+++ b/source4/auth/kerberos/kerberos_util.c -@@ -24,7 +24,6 @@ - #include "system/kerberos.h" - #include "auth/kerberos/kerberos.h" - #include "auth/credentials/credentials.h" --#include "auth/credentials/credentials_proto.h" - #include "auth/credentials/credentials_krb5.h" - #include "auth/kerberos/kerberos_credentials.h" - #include "auth/kerberos/kerberos_util.h" -diff --git a/source4/auth/tests/kerberos.c b/source4/auth/tests/kerberos.c -index 7711eac2afa..d9be3562adb 100644 ---- a/source4/auth/tests/kerberos.c -+++ b/source4/auth/tests/kerberos.c -@@ -10,7 +10,6 @@ - #include "system/kerberos.h" - #include "auth/kerberos/kerberos.h" - #include "auth/credentials/credentials.h" --#include "auth/credentials/credentials_proto.h" - #include "auth/credentials/credentials_krb5.h" - #include "auth/kerberos/kerberos_credentials.h" - #include "auth/kerberos/kerberos_util.h" --- -2.33.1 - - -From 63e3da5b79de2aa774106bffcd77ad78f1111af7 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Tue, 26 May 2020 09:32:44 +0200 -Subject: [PATCH 013/103] auth:creds: Add - cli_credentials_(get|set)_smb_signing() - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - auth/credentials/credentials.c | 45 +++++++++++++++++++++++++ - auth/credentials/credentials.h | 7 ++++ - auth/credentials/credentials_internal.h | 4 +++ - 3 files changed, 56 insertions(+) - -diff --git a/auth/credentials/credentials.c b/auth/credentials/credentials.c -index 80a31b248ae..365a6def7ea 100644 ---- a/auth/credentials/credentials.c -+++ b/auth/credentials/credentials.c -@@ -44,6 +44,8 @@ _PUBLIC_ struct cli_credentials *cli_credentials_init(TALLOC_CTX *mem_ctx) - - cred->winbind_separator = '\\'; - -+ cred->signing_state = SMB_SIGNING_DEFAULT; -+ - return cred; - } - -@@ -922,6 +924,12 @@ _PUBLIC_ void cli_credentials_set_conf(struct cli_credentials *cred, - if (sep != NULL && sep[0] != '\0') { - cred->winbind_separator = *lpcfg_winbind_separator(lp_ctx); - } -+ -+ if (cred->signing_state_obtained <= CRED_SMB_CONF) { -+ /* Will be set to default for invalid smb.conf values */ -+ cred->signing_state = lpcfg_client_signing(lp_ctx); -+ cred->signing_state_obtained = CRED_SMB_CONF; -+ } - } - - /** -@@ -1304,6 +1312,43 @@ _PUBLIC_ bool cli_credentials_parse_password_fd(struct cli_credentials *credenti - return true; - } - -+/** -+ * @brief Set the SMB signing state to request for a SMB connection. -+ * -+ * @param[in] creds The credentials structure to update. -+ * -+ * @param[in] signing_state The signing state to set. -+ * -+ * @param obtained This way the described signing state was specified. -+ * -+ * @return true if we could set the signing state, false otherwise. -+ */ -+_PUBLIC_ bool cli_credentials_set_smb_signing(struct cli_credentials *creds, -+ enum smb_signing_setting signing_state, -+ enum credentials_obtained obtained) -+{ -+ if (obtained >= creds->signing_state_obtained) { -+ creds->signing_state_obtained = obtained; -+ creds->signing_state = signing_state; -+ return true; -+ } -+ -+ return false; -+} -+ -+/** -+ * @brief Obtain the SMB signing state from a credentials structure. -+ * -+ * @param[in] creds The credential structure to obtain the SMB signing state -+ * from. -+ * -+ * @return The SMB singing state. -+ */ -+_PUBLIC_ enum smb_signing_setting -+cli_credentials_get_smb_signing(struct cli_credentials *creds) -+{ -+ return creds->signing_state; -+} - - /** - * Encrypt a data blob using the session key and the negotiated encryption -diff --git a/auth/credentials/credentials.h b/auth/credentials/credentials.h -index 7154c2a008c..422391ad585 100644 ---- a/auth/credentials/credentials.h -+++ b/auth/credentials/credentials.h -@@ -38,6 +38,7 @@ struct gssapi_creds_container; - struct smb_krb5_context; - struct keytab_container; - struct db_context; -+enum smb_signing_setting; - - /* In order of priority */ - enum credentials_obtained { -@@ -290,6 +291,12 @@ void *_cli_credentials_callback_data(struct cli_credentials *cred); - #define cli_credentials_callback_data_void(_cred) \ - _cli_credentials_callback_data(_cred) - -+bool cli_credentials_set_smb_signing(struct cli_credentials *cred, -+ enum smb_signing_setting signing_state, -+ enum credentials_obtained obtained); -+enum smb_signing_setting -+cli_credentials_get_smb_signing(struct cli_credentials *cred); -+ - /** - * Return attached NETLOGON credentials - */ -diff --git a/auth/credentials/credentials_internal.h b/auth/credentials/credentials_internal.h -index 68f1f25dce1..9cde0000b5f 100644 ---- a/auth/credentials/credentials_internal.h -+++ b/auth/credentials/credentials_internal.h -@@ -24,6 +24,7 @@ - - #include "../lib/util/data_blob.h" - #include "librpc/gen_ndr/misc.h" -+#include "libcli/smb/smb_constants.h" - - struct cli_credentials { - enum credentials_obtained workstation_obtained; -@@ -36,6 +37,7 @@ struct cli_credentials { - enum credentials_obtained principal_obtained; - enum credentials_obtained keytab_obtained; - enum credentials_obtained server_gss_creds_obtained; -+ enum credentials_obtained signing_state_obtained; - - /* Threshold values (essentially a MAX() over a number of the - * above) for the ccache and GSS credentials, to ensure we -@@ -117,6 +119,8 @@ struct cli_credentials { - char winbind_separator; - - bool password_will_be_nt_hash; -+ -+ enum smb_signing_setting signing_state; - }; - - #endif /* __CREDENTIALS_INTERNAL_H__ */ --- -2.33.1 - - -From 4d16dcc995e0854c9b14d44ea065fda4ebccdcd6 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Wed, 3 Jun 2020 11:56:01 +0200 -Subject: [PATCH 014/103] auth:creds: Add python bindings for - (get|set)_smb_signing - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - auth/credentials/pycredentials.c | 63 +++++++++++++++++++++++++++++++ - python/samba/tests/credentials.py | 6 +++ - 2 files changed, 69 insertions(+) - -diff --git a/auth/credentials/pycredentials.c b/auth/credentials/pycredentials.c -index 171be1b0c6a..60fecbe494c 100644 ---- a/auth/credentials/pycredentials.c -+++ b/auth/credentials/pycredentials.c -@@ -34,6 +34,7 @@ - #include "auth/credentials/credentials_internal.h" - #include "system/kerberos.h" - #include "auth/kerberos/kerberos.h" -+#include "libcli/smb/smb_constants.h" - - void initcredentials(void); - -@@ -927,6 +928,52 @@ static PyObject *py_creds_encrypt_netr_crypt_password(PyObject *self, - Py_RETURN_NONE; - } - -+static PyObject *py_creds_get_smb_signing(PyObject *self, PyObject *unused) -+{ -+ enum smb_signing_setting signing_state; -+ struct cli_credentials *creds = NULL; -+ -+ creds = PyCredentials_AsCliCredentials(self); -+ if (creds == NULL) { -+ PyErr_Format(PyExc_TypeError, "Credentials expected"); -+ return NULL; -+ } -+ -+ signing_state = cli_credentials_get_smb_signing(creds); -+ return PyLong_FromLong(signing_state); -+} -+ -+static PyObject *py_creds_set_smb_signing(PyObject *self, PyObject *args) -+{ -+ enum smb_signing_setting signing_state; -+ struct cli_credentials *creds = NULL; -+ enum credentials_obtained obt = CRED_SPECIFIED; -+ -+ creds = PyCredentials_AsCliCredentials(self); -+ if (creds == NULL) { -+ PyErr_Format(PyExc_TypeError, "Credentials expected"); -+ return NULL; -+ } -+ if (!PyArg_ParseTuple(args, "i|i", &signing_state, &obt)) { -+ return NULL; -+ } -+ -+ switch (signing_state) { -+ case SMB_SIGNING_DEFAULT: -+ case SMB_SIGNING_OFF: -+ case SMB_SIGNING_IF_REQUIRED: -+ case SMB_SIGNING_DESIRED: -+ case SMB_SIGNING_REQUIRED: -+ break; -+ default: -+ PyErr_Format(PyExc_TypeError, "Invalid signing state value"); -+ return NULL; -+ } -+ -+ cli_credentials_set_smb_signing(creds, signing_state, obt); -+ Py_RETURN_NONE; -+} -+ - static PyMethodDef py_creds_methods[] = { - { - .ml_name = "get_username", -@@ -1207,6 +1254,16 @@ static PyMethodDef py_creds_methods[] = { - "Encrypt the supplied password using the session key and\n" - "the negotiated encryption algorithm in place\n" - "i.e. it overwrites the original data"}, -+ { -+ .ml_name = "get_smb_signing", -+ .ml_meth = py_creds_get_smb_signing, -+ .ml_flags = METH_NOARGS, -+ }, -+ { -+ .ml_name = "set_smb_signing", -+ .ml_meth = py_creds_set_smb_signing, -+ .ml_flags = METH_VARARGS, -+ }, - { .ml_name = NULL } - }; - -@@ -1293,6 +1350,12 @@ MODULE_INIT_FUNC(credentials) - PyModule_AddObject(m, "CLI_CRED_NTLM_AUTH", PyLong_FromLong(CLI_CRED_NTLM_AUTH)); - PyModule_AddObject(m, "CLI_CRED_CLEAR_AUTH", PyLong_FromLong(CLI_CRED_CLEAR_AUTH)); - -+ PyModule_AddObject(m, "SMB_SIGNING_DEFAULT", PyLong_FromLong(SMB_SIGNING_DEFAULT)); -+ PyModule_AddObject(m, "SMB_SIGNING_OFF", PyLong_FromLong(SMB_SIGNING_OFF)); -+ PyModule_AddObject(m, "SMB_SIGNING_IF_REQUIRED", PyLong_FromLong(SMB_SIGNING_IF_REQUIRED)); -+ PyModule_AddObject(m, "SMB_SIGNING_DESIRED", PyLong_FromLong(SMB_SIGNING_DESIRED)); -+ PyModule_AddObject(m, "SMB_SIGNING_REQUIRED", PyLong_FromLong(SMB_SIGNING_REQUIRED)); -+ - Py_INCREF(&PyCredentials); - PyModule_AddObject(m, "Credentials", (PyObject *)&PyCredentials); - Py_INCREF(&PyCredentialCacheContainer); -diff --git a/python/samba/tests/credentials.py b/python/samba/tests/credentials.py -index 6454ac9ff7c..e5f8122fa21 100644 ---- a/python/samba/tests/credentials.py -+++ b/python/samba/tests/credentials.py -@@ -456,3 +456,9 @@ class CredentialsTests(samba.tests.TestCaseInTempDir): - self.assertEqual(creds.get_principal(), "user@samba.org") - self.assertEqual(creds.is_anonymous(), False) - self.assertEqual(creds.authentication_requested(), True) -+ -+ def test_smb_signing(self): -+ creds = credentials.Credentials() -+ self.assertEqual(creds.get_smb_signing(), credentials.SMB_SIGNING_DEFAULT) -+ creds.set_smb_signing(credentials.SMB_SIGNING_REQUIRED) -+ self.assertEqual(creds.get_smb_signing(), credentials.SMB_SIGNING_REQUIRED) --- -2.33.1 - - -From 9e5ac9604f7b59c5a6af8892eefed79d558f505b Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 28 May 2020 16:31:35 +0200 -Subject: [PATCH 015/103] auth:creds: Add - cli_credentials_(get|set)_smb_ipc_signing() - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - auth/credentials/credentials.c | 51 +++++++++++++++++++++++++ - auth/credentials/credentials.h | 6 +++ - auth/credentials/credentials_internal.h | 3 ++ - 3 files changed, 60 insertions(+) - -diff --git a/auth/credentials/credentials.c b/auth/credentials/credentials.c -index 365a6def7ea..dc5d51f1424 100644 ---- a/auth/credentials/credentials.c -+++ b/auth/credentials/credentials.c -@@ -46,6 +46,12 @@ _PUBLIC_ struct cli_credentials *cli_credentials_init(TALLOC_CTX *mem_ctx) - - cred->signing_state = SMB_SIGNING_DEFAULT; - -+ /* -+ * The default value of lpcfg_client_ipc_signing() is REQUIRED, so use -+ * the same value here. -+ */ -+ cred->ipc_signing_state = SMB_SIGNING_REQUIRED; -+ - return cred; - } - -@@ -930,6 +936,12 @@ _PUBLIC_ void cli_credentials_set_conf(struct cli_credentials *cred, - cred->signing_state = lpcfg_client_signing(lp_ctx); - cred->signing_state_obtained = CRED_SMB_CONF; - } -+ -+ if (cred->ipc_signing_state_obtained <= CRED_SMB_CONF) { -+ /* Will be set to required for invalid smb.conf values */ -+ cred->ipc_signing_state = lpcfg_client_ipc_signing(lp_ctx); -+ cred->ipc_signing_state_obtained = CRED_SMB_CONF; -+ } - } - - /** -@@ -1350,6 +1362,45 @@ cli_credentials_get_smb_signing(struct cli_credentials *creds) - return creds->signing_state; - } - -+/** -+ * @brief Set the SMB IPC signing state to request for a SMB connection. -+ * -+ * @param[in] creds The credentials structure to update. -+ * -+ * @param[in] signing_state The signing state to set. -+ * -+ * @param obtained This way the described signing state was specified. -+ * -+ * @return true if we could set the signing state, false otherwise. -+ */ -+_PUBLIC_ bool -+cli_credentials_set_smb_ipc_signing(struct cli_credentials *creds, -+ enum smb_signing_setting ipc_signing_state, -+ enum credentials_obtained obtained) -+{ -+ if (obtained >= creds->ipc_signing_state_obtained) { -+ creds->ipc_signing_state_obtained = obtained; -+ creds->ipc_signing_state = ipc_signing_state; -+ return true; -+ } -+ -+ return false; -+} -+ -+/** -+ * @brief Obtain the SMB IPC signing state from a credentials structure. -+ * -+ * @param[in] creds The credential structure to obtain the SMB IPC signing -+ * state from. -+ * -+ * @return The SMB singing state. -+ */ -+_PUBLIC_ enum smb_signing_setting -+cli_credentials_get_smb_ipc_signing(struct cli_credentials *creds) -+{ -+ return creds->ipc_signing_state; -+} -+ - /** - * Encrypt a data blob using the session key and the negotiated encryption - * algorithm -diff --git a/auth/credentials/credentials.h b/auth/credentials/credentials.h -index 422391ad585..25bec916278 100644 ---- a/auth/credentials/credentials.h -+++ b/auth/credentials/credentials.h -@@ -297,6 +297,12 @@ bool cli_credentials_set_smb_signing(struct cli_credentials *cred, - enum smb_signing_setting - cli_credentials_get_smb_signing(struct cli_credentials *cred); - -+bool cli_credentials_set_smb_ipc_signing(struct cli_credentials *cred, -+ enum smb_signing_setting ipc_signing_state, -+ enum credentials_obtained obtained); -+enum smb_signing_setting -+cli_credentials_get_smb_ipc_signing(struct cli_credentials *cred); -+ - /** - * Return attached NETLOGON credentials - */ -diff --git a/auth/credentials/credentials_internal.h b/auth/credentials/credentials_internal.h -index 9cde0000b5f..54e8271471f 100644 ---- a/auth/credentials/credentials_internal.h -+++ b/auth/credentials/credentials_internal.h -@@ -38,6 +38,7 @@ struct cli_credentials { - enum credentials_obtained keytab_obtained; - enum credentials_obtained server_gss_creds_obtained; - enum credentials_obtained signing_state_obtained; -+ enum credentials_obtained ipc_signing_state_obtained; - - /* Threshold values (essentially a MAX() over a number of the - * above) for the ccache and GSS credentials, to ensure we -@@ -121,6 +122,8 @@ struct cli_credentials { - bool password_will_be_nt_hash; - - enum smb_signing_setting signing_state; -+ -+ enum smb_signing_setting ipc_signing_state; - }; - - #endif /* __CREDENTIALS_INTERNAL_H__ */ --- -2.33.1 - - -From 53ddf5030b8f9c1dc9610903a8da4f176fc7a38a Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Wed, 3 Jun 2020 12:32:46 +0200 -Subject: [PATCH 016/103] auth:creds: Add python bindings for - (get|set)_smb_ipc_signing - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - auth/credentials/pycredentials.c | 56 +++++++++++++++++++++++++++++++ - python/samba/tests/credentials.py | 6 ++++ - 2 files changed, 62 insertions(+) - -diff --git a/auth/credentials/pycredentials.c b/auth/credentials/pycredentials.c -index 60fecbe494c..b270eabeb6c 100644 ---- a/auth/credentials/pycredentials.c -+++ b/auth/credentials/pycredentials.c -@@ -974,6 +974,52 @@ static PyObject *py_creds_set_smb_signing(PyObject *self, PyObject *args) - Py_RETURN_NONE; - } - -+static PyObject *py_creds_get_smb_ipc_signing(PyObject *self, PyObject *unused) -+{ -+ enum smb_signing_setting signing_state; -+ struct cli_credentials *creds = NULL; -+ -+ creds = PyCredentials_AsCliCredentials(self); -+ if (creds == NULL) { -+ PyErr_Format(PyExc_TypeError, "Credentials expected"); -+ return NULL; -+ } -+ -+ signing_state = cli_credentials_get_smb_ipc_signing(creds); -+ return PyLong_FromLong(signing_state); -+} -+ -+static PyObject *py_creds_set_smb_ipc_signing(PyObject *self, PyObject *args) -+{ -+ enum smb_signing_setting signing_state; -+ struct cli_credentials *creds = NULL; -+ enum credentials_obtained obt = CRED_SPECIFIED; -+ -+ creds = PyCredentials_AsCliCredentials(self); -+ if (creds == NULL) { -+ PyErr_Format(PyExc_TypeError, "Credentials expected"); -+ return NULL; -+ } -+ if (!PyArg_ParseTuple(args, "i|i", &signing_state, &obt)) { -+ return NULL; -+ } -+ -+ switch (signing_state) { -+ case SMB_SIGNING_DEFAULT: -+ case SMB_SIGNING_OFF: -+ case SMB_SIGNING_IF_REQUIRED: -+ case SMB_SIGNING_DESIRED: -+ case SMB_SIGNING_REQUIRED: -+ break; -+ default: -+ PyErr_Format(PyExc_TypeError, "Invalid signing state value"); -+ return NULL; -+ } -+ -+ cli_credentials_set_smb_ipc_signing(creds, signing_state, obt); -+ Py_RETURN_NONE; -+} -+ - static PyMethodDef py_creds_methods[] = { - { - .ml_name = "get_username", -@@ -1264,6 +1310,16 @@ static PyMethodDef py_creds_methods[] = { - .ml_meth = py_creds_set_smb_signing, - .ml_flags = METH_VARARGS, - }, -+ { -+ .ml_name = "get_smb_ipc_signing", -+ .ml_meth = py_creds_get_smb_ipc_signing, -+ .ml_flags = METH_NOARGS, -+ }, -+ { -+ .ml_name = "set_smb_ipc_signing", -+ .ml_meth = py_creds_set_smb_ipc_signing, -+ .ml_flags = METH_VARARGS, -+ }, - { .ml_name = NULL } - }; - -diff --git a/python/samba/tests/credentials.py b/python/samba/tests/credentials.py -index e5f8122fa21..8edf13ce6ff 100644 ---- a/python/samba/tests/credentials.py -+++ b/python/samba/tests/credentials.py -@@ -462,3 +462,9 @@ class CredentialsTests(samba.tests.TestCaseInTempDir): - self.assertEqual(creds.get_smb_signing(), credentials.SMB_SIGNING_DEFAULT) - creds.set_smb_signing(credentials.SMB_SIGNING_REQUIRED) - self.assertEqual(creds.get_smb_signing(), credentials.SMB_SIGNING_REQUIRED) -+ -+ def test_smb_ipc_signing(self): -+ creds = credentials.Credentials() -+ self.assertEqual(creds.get_smb_ipc_signing(), credentials.SMB_SIGNING_REQUIRED) -+ creds.set_smb_ipc_signing(credentials.SMB_SIGNING_OFF) -+ self.assertEqual(creds.get_smb_ipc_signing(), credentials.SMB_SIGNING_OFF) --- -2.33.1 - - -From 90381fa63e531bf0cd7b5ec71205bc1c6de6696c Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 28 May 2020 16:10:52 +0200 -Subject: [PATCH 017/103] auth:creds: Add - cli_credentials_(get|set)_smb_encryption() - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - auth/credentials/credentials.c | 45 +++++++++++++++++++++++++ - auth/credentials/credentials.h | 7 ++++ - auth/credentials/credentials_internal.h | 3 ++ - 3 files changed, 55 insertions(+) - -diff --git a/auth/credentials/credentials.c b/auth/credentials/credentials.c -index dc5d51f1424..9168b92d3ec 100644 ---- a/auth/credentials/credentials.c -+++ b/auth/credentials/credentials.c -@@ -51,6 +51,7 @@ _PUBLIC_ struct cli_credentials *cli_credentials_init(TALLOC_CTX *mem_ctx) - * the same value here. - */ - cred->ipc_signing_state = SMB_SIGNING_REQUIRED; -+ cred->encryption_state = SMB_ENCRYPTION_DEFAULT; - - return cred; - } -@@ -942,6 +943,12 @@ _PUBLIC_ void cli_credentials_set_conf(struct cli_credentials *cred, - cred->ipc_signing_state = lpcfg_client_ipc_signing(lp_ctx); - cred->ipc_signing_state_obtained = CRED_SMB_CONF; - } -+ -+ if (cred->encryption_state_obtained <= CRED_SMB_CONF) { -+ /* Will be set to default for invalid smb.conf values */ -+ cred->encryption_state = lpcfg_client_smb_encrypt(lp_ctx); -+ cred->encryption_state_obtained = CRED_SMB_CONF; -+ } - } - - /** -@@ -1401,6 +1408,44 @@ cli_credentials_get_smb_ipc_signing(struct cli_credentials *creds) - return creds->ipc_signing_state; - } - -+/** -+ * @brief Set the SMB encryption state to request for a SMB connection. -+ * -+ * @param[in] creds The credentials structure to update. -+ * -+ * @param[in] encryption_state The encryption state to set. -+ * -+ * @param obtained This way the described encryption state was specified. -+ * -+ * @return true if we could set the encryption state, false otherwise. -+ */ -+_PUBLIC_ bool cli_credentials_set_smb_encryption(struct cli_credentials *creds, -+ enum smb_encryption_setting encryption_state, -+ enum credentials_obtained obtained) -+{ -+ if (obtained >= creds->encryption_state_obtained) { -+ creds->encryption_state_obtained = obtained; -+ creds->encryption_state = encryption_state; -+ return true; -+ } -+ -+ return false; -+} -+ -+/** -+ * @brief Obtain the SMB encryption state from a credentials structure. -+ * -+ * @param[in] creds The credential structure to obtain the SMB encryption state -+ * from. -+ * -+ * @return The SMB singing state. -+ */ -+_PUBLIC_ enum smb_encryption_setting -+cli_credentials_get_smb_encryption(struct cli_credentials *creds) -+{ -+ return creds->encryption_state; -+} -+ - /** - * Encrypt a data blob using the session key and the negotiated encryption - * algorithm -diff --git a/auth/credentials/credentials.h b/auth/credentials/credentials.h -index 25bec916278..7d0cf53194b 100644 ---- a/auth/credentials/credentials.h -+++ b/auth/credentials/credentials.h -@@ -39,6 +39,7 @@ struct smb_krb5_context; - struct keytab_container; - struct db_context; - enum smb_signing_setting; -+enum smb_encryption_setting; - - /* In order of priority */ - enum credentials_obtained { -@@ -303,6 +304,12 @@ bool cli_credentials_set_smb_ipc_signing(struct cli_credentials *cred, - enum smb_signing_setting - cli_credentials_get_smb_ipc_signing(struct cli_credentials *cred); - -+bool cli_credentials_set_smb_encryption(struct cli_credentials *cred, -+ enum smb_encryption_setting encryption_state, -+ enum credentials_obtained obtained); -+enum smb_encryption_setting -+cli_credentials_get_smb_encryption(struct cli_credentials *cred); -+ - /** - * Return attached NETLOGON credentials - */ -diff --git a/auth/credentials/credentials_internal.h b/auth/credentials/credentials_internal.h -index 54e8271471f..3b86b742448 100644 ---- a/auth/credentials/credentials_internal.h -+++ b/auth/credentials/credentials_internal.h -@@ -39,6 +39,7 @@ struct cli_credentials { - enum credentials_obtained server_gss_creds_obtained; - enum credentials_obtained signing_state_obtained; - enum credentials_obtained ipc_signing_state_obtained; -+ enum credentials_obtained encryption_state_obtained; - - /* Threshold values (essentially a MAX() over a number of the - * above) for the ccache and GSS credentials, to ensure we -@@ -124,6 +125,8 @@ struct cli_credentials { - enum smb_signing_setting signing_state; - - enum smb_signing_setting ipc_signing_state; -+ -+ enum smb_encryption_setting encryption_state; - }; - - #endif /* __CREDENTIALS_INTERNAL_H__ */ --- -2.33.1 - - -From c89917cb2313398d2610458e278b48019e7d468c Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Wed, 3 Jun 2020 12:38:30 +0200 -Subject: [PATCH 018/103] auth:creds: Add python bindings for - (get|set)_smb_encryption - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - auth/credentials/pycredentials.c | 62 +++++++++++++++++++++++++++++++ - python/samba/tests/credentials.py | 6 +++ - 2 files changed, 68 insertions(+) - -diff --git a/auth/credentials/pycredentials.c b/auth/credentials/pycredentials.c -index b270eabeb6c..a27039d8cfd 100644 ---- a/auth/credentials/pycredentials.c -+++ b/auth/credentials/pycredentials.c -@@ -1020,6 +1020,52 @@ static PyObject *py_creds_set_smb_ipc_signing(PyObject *self, PyObject *args) - Py_RETURN_NONE; - } - -+static PyObject *py_creds_get_smb_encryption(PyObject *self, PyObject *unused) -+{ -+ enum smb_encryption_setting encryption_state; -+ struct cli_credentials *creds = NULL; -+ -+ creds = PyCredentials_AsCliCredentials(self); -+ if (creds == NULL) { -+ PyErr_Format(PyExc_TypeError, "Credentials expected"); -+ return NULL; -+ } -+ -+ encryption_state = cli_credentials_get_smb_encryption(creds); -+ return PyLong_FromLong(encryption_state); -+} -+ -+static PyObject *py_creds_set_smb_encryption(PyObject *self, PyObject *args) -+{ -+ enum smb_encryption_setting encryption_state; -+ struct cli_credentials *creds = NULL; -+ enum credentials_obtained obt = CRED_SPECIFIED; -+ -+ creds = PyCredentials_AsCliCredentials(self); -+ if (creds == NULL) { -+ PyErr_Format(PyExc_TypeError, "Credentials expected"); -+ return NULL; -+ } -+ if (!PyArg_ParseTuple(args, "i|i", &encryption_state, &obt)) { -+ return NULL; -+ } -+ -+ switch (encryption_state) { -+ case SMB_ENCRYPTION_DEFAULT: -+ case SMB_ENCRYPTION_OFF: -+ case SMB_ENCRYPTION_IF_REQUIRED: -+ case SMB_ENCRYPTION_DESIRED: -+ case SMB_ENCRYPTION_REQUIRED: -+ break; -+ default: -+ PyErr_Format(PyExc_TypeError, "Invalid encryption state value"); -+ return NULL; -+ } -+ -+ cli_credentials_set_smb_encryption(creds, encryption_state, obt); -+ Py_RETURN_NONE; -+} -+ - static PyMethodDef py_creds_methods[] = { - { - .ml_name = "get_username", -@@ -1320,6 +1366,16 @@ static PyMethodDef py_creds_methods[] = { - .ml_meth = py_creds_set_smb_ipc_signing, - .ml_flags = METH_VARARGS, - }, -+ { -+ .ml_name = "get_smb_encryption", -+ .ml_meth = py_creds_get_smb_encryption, -+ .ml_flags = METH_NOARGS, -+ }, -+ { -+ .ml_name = "set_smb_encryption", -+ .ml_meth = py_creds_set_smb_encryption, -+ .ml_flags = METH_VARARGS, -+ }, - { .ml_name = NULL } - }; - -@@ -1412,6 +1468,12 @@ MODULE_INIT_FUNC(credentials) - PyModule_AddObject(m, "SMB_SIGNING_DESIRED", PyLong_FromLong(SMB_SIGNING_DESIRED)); - PyModule_AddObject(m, "SMB_SIGNING_REQUIRED", PyLong_FromLong(SMB_SIGNING_REQUIRED)); - -+ PyModule_AddObject(m, "SMB_ENCRYPTION_DEFAULT", PyLong_FromLong(SMB_ENCRYPTION_DEFAULT)); -+ PyModule_AddObject(m, "SMB_ENCRYPTION_OFF", PyLong_FromLong(SMB_ENCRYPTION_OFF)); -+ PyModule_AddObject(m, "SMB_ENCRYPTION_IF_REQUIRED", PyLong_FromLong(SMB_ENCRYPTION_IF_REQUIRED)); -+ PyModule_AddObject(m, "SMB_ENCRYPTION_DESIRED", PyLong_FromLong(SMB_ENCRYPTION_DESIRED)); -+ PyModule_AddObject(m, "SMB_ENCRYPTION_REQUIRED", PyLong_FromLong(SMB_ENCRYPTION_REQUIRED)); -+ - Py_INCREF(&PyCredentials); - PyModule_AddObject(m, "Credentials", (PyObject *)&PyCredentials); - Py_INCREF(&PyCredentialCacheContainer); -diff --git a/python/samba/tests/credentials.py b/python/samba/tests/credentials.py -index 8edf13ce6ff..e0a6248d37a 100644 ---- a/python/samba/tests/credentials.py -+++ b/python/samba/tests/credentials.py -@@ -468,3 +468,9 @@ class CredentialsTests(samba.tests.TestCaseInTempDir): - self.assertEqual(creds.get_smb_ipc_signing(), credentials.SMB_SIGNING_REQUIRED) - creds.set_smb_ipc_signing(credentials.SMB_SIGNING_OFF) - self.assertEqual(creds.get_smb_ipc_signing(), credentials.SMB_SIGNING_OFF) -+ -+ def test_smb_encryption(self): -+ creds = credentials.Credentials() -+ self.assertEqual(creds.get_smb_encryption(), credentials.SMB_ENCRYPTION_DEFAULT) -+ creds.set_smb_encryption(credentials.SMB_ENCRYPTION_REQUIRED) -+ self.assertEqual(creds.get_smb_encryption(), credentials.SMB_ENCRYPTION_REQUIRED) --- -2.33.1 - - -From 7c0b661f8f6fc39ee6e2a24636186653d9236843 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 4 Jun 2020 11:19:53 +0200 -Subject: [PATCH 019/103] auth:creds: Add python bindings for - cli_credentials_set_conf() - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - auth/credentials/pycredentials.c | 41 +++++++++++++++++++++++++++++++ - python/samba/tests/credentials.py | 33 +++++++++++++++++++++++++ - 2 files changed, 74 insertions(+) - -diff --git a/auth/credentials/pycredentials.c b/auth/credentials/pycredentials.c -index a27039d8cfd..f588d6c962e 100644 ---- a/auth/credentials/pycredentials.c -+++ b/auth/credentials/pycredentials.c -@@ -618,6 +618,42 @@ static PyObject *py_creds_set_forced_sasl_mech(PyObject *self, PyObject *args) - Py_RETURN_NONE; - } - -+static PyObject *py_creds_set_conf(PyObject *self, PyObject *args) -+{ -+ PyObject *py_lp_ctx = Py_None; -+ struct loadparm_context *lp_ctx; -+ TALLOC_CTX *mem_ctx; -+ struct cli_credentials *creds; -+ -+ creds = PyCredentials_AsCliCredentials(self); -+ if (creds == NULL) { -+ PyErr_Format(PyExc_TypeError, "Credentials expected"); -+ return NULL; -+ } -+ -+ if (!PyArg_ParseTuple(args, "|O", &py_lp_ctx)) { -+ return NULL; -+ } -+ -+ mem_ctx = talloc_new(NULL); -+ if (mem_ctx == NULL) { -+ PyErr_NoMemory(); -+ return NULL; -+ } -+ -+ lp_ctx = lpcfg_from_py_object(mem_ctx, py_lp_ctx); -+ if (lp_ctx == NULL) { -+ talloc_free(mem_ctx); -+ return NULL; -+ } -+ -+ cli_credentials_set_conf(creds, lp_ctx); -+ -+ talloc_free(mem_ctx); -+ -+ Py_RETURN_NONE; -+} -+ - static PyObject *py_creds_guess(PyObject *self, PyObject *args) - { - PyObject *py_lp_ctx = Py_None; -@@ -1277,6 +1313,11 @@ static PyMethodDef py_creds_methods[] = { - .ml_meth = py_creds_set_krb_forwardable, - .ml_flags = METH_VARARGS, - }, -+ { -+ .ml_name = "set_conf", -+ .ml_meth = py_creds_set_conf, -+ .ml_flags = METH_VARARGS, -+ }, - { - .ml_name = "guess", - .ml_meth = py_creds_guess, -diff --git a/python/samba/tests/credentials.py b/python/samba/tests/credentials.py -index e0a6248d37a..6187bded0b6 100644 ---- a/python/samba/tests/credentials.py -+++ b/python/samba/tests/credentials.py -@@ -463,14 +463,47 @@ class CredentialsTests(samba.tests.TestCaseInTempDir): - creds.set_smb_signing(credentials.SMB_SIGNING_REQUIRED) - self.assertEqual(creds.get_smb_signing(), credentials.SMB_SIGNING_REQUIRED) - -+ def test_smb_signing_set_conf(self): -+ lp = samba.tests.env_loadparm() -+ -+ creds = credentials.Credentials() -+ creds.set_conf(lp) -+ self.assertEqual(creds.get_smb_signing(), credentials.SMB_SIGNING_DEFAULT) -+ creds.set_smb_signing(credentials.SMB_SIGNING_OFF) -+ self.assertEqual(creds.get_smb_signing(), credentials.SMB_SIGNING_OFF) -+ creds.set_conf(lp) -+ self.assertEqual(creds.get_smb_signing(), credentials.SMB_SIGNING_OFF) -+ - def test_smb_ipc_signing(self): - creds = credentials.Credentials() - self.assertEqual(creds.get_smb_ipc_signing(), credentials.SMB_SIGNING_REQUIRED) - creds.set_smb_ipc_signing(credentials.SMB_SIGNING_OFF) - self.assertEqual(creds.get_smb_ipc_signing(), credentials.SMB_SIGNING_OFF) - -+ def test_smb_ipc_signing_set_conf(self): -+ lp = samba.tests.env_loadparm() -+ -+ creds = credentials.Credentials() -+ creds.set_conf(lp) -+ self.assertEqual(creds.get_smb_ipc_signing(), credentials.SMB_SIGNING_REQUIRED) -+ creds.set_smb_ipc_signing(credentials.SMB_SIGNING_OFF) -+ self.assertEqual(creds.get_smb_ipc_signing(), credentials.SMB_SIGNING_OFF) -+ creds.set_conf(lp) -+ self.assertEqual(creds.get_smb_ipc_signing(), credentials.SMB_SIGNING_OFF) -+ - def test_smb_encryption(self): - creds = credentials.Credentials() - self.assertEqual(creds.get_smb_encryption(), credentials.SMB_ENCRYPTION_DEFAULT) - creds.set_smb_encryption(credentials.SMB_ENCRYPTION_REQUIRED) - self.assertEqual(creds.get_smb_encryption(), credentials.SMB_ENCRYPTION_REQUIRED) -+ -+ def test_smb_encryption_set_conf(self): -+ lp = samba.tests.env_loadparm() -+ -+ creds = credentials.Credentials() -+ creds.set_conf(lp) -+ self.assertEqual(creds.get_smb_encryption(), credentials.SMB_ENCRYPTION_DEFAULT) -+ creds.set_smb_encryption(credentials.SMB_ENCRYPTION_OFF) -+ self.assertEqual(creds.get_smb_encryption(), credentials.SMB_ENCRYPTION_OFF) -+ creds.set_conf(lp) -+ self.assertEqual(creds.get_smb_encryption(), credentials.SMB_ENCRYPTION_OFF) --- -2.33.1 - - -From 6be418fb4ff2f4be546c6bcf3bee296cd9a8edd8 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 23 Jul 2020 08:14:23 +0200 -Subject: [PATCH 020/103] auth:creds: Bump library version - -We added new functions so bump the version. - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - auth/credentials/wscript_build | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/auth/credentials/wscript_build b/auth/credentials/wscript_build -index 564a04fe8dd..1e3302e3e48 100644 ---- a/auth/credentials/wscript_build -+++ b/auth/credentials/wscript_build -@@ -5,7 +5,7 @@ bld.SAMBA_LIBRARY('samba-credentials', - public_headers='credentials.h', - pc_files='samba-credentials.pc', - deps='LIBCRYPTO samba-errors events LIBCLI_AUTH samba-security CREDENTIALS_SECRETS CREDENTIALS_KRB5', -- vnum='0.0.1' -+ vnum='0.1.0' - ) - - bld.SAMBA_SUBSYSTEM('CREDENTIALS_KRB5', --- -2.33.1 - - -From cc6c0f99b9ded4801b5f86f6a6bb5a8471620557 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Wed, 27 May 2020 11:10:30 +0200 -Subject: [PATCH 021/103] s3:lib: Use cli_credential_(get|set)_smb_signing() - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - source3/lib/util_cmdline.c | 18 ++++++++++++------ - 1 file changed, 12 insertions(+), 6 deletions(-) - -diff --git a/source3/lib/util_cmdline.c b/source3/lib/util_cmdline.c -index bc1f1c3ed25..6038ec11515 100644 ---- a/source3/lib/util_cmdline.c -+++ b/source3/lib/util_cmdline.c -@@ -40,7 +40,6 @@ struct user_auth_info { - struct loadparm_context *lp_ctx; - bool got_username; - bool got_pass; -- int signing_state; - bool smb_encrypt; - bool use_machine_account; - bool use_pw_nt_hash; -@@ -70,7 +69,6 @@ struct user_auth_info *user_auth_info_init(TALLOC_CTX *mem_ctx) - - cli_credentials_set_conf(result->creds, result->lp_ctx); - -- result->signing_state = SMB_SIGNING_DEFAULT; - return result; - } - -@@ -241,15 +239,23 @@ void set_cmdline_auth_info_password(struct user_auth_info *auth_info, - bool set_cmdline_auth_info_signing_state(struct user_auth_info *auth_info, - const char *arg) - { -- auth_info->signing_state = smb_signing_setting_translate(arg); -+ enum smb_signing_setting signing_state = -+ smb_signing_setting_translate(arg); -+ bool ok; - -- return true; -+ ok = cli_credentials_set_smb_signing(auth_info->creds, -+ signing_state, -+ CRED_SPECIFIED); -+ -+ return ok; - } - - void set_cmdline_auth_info_signing_state_raw(struct user_auth_info *auth_info, - int signing_state) - { -- auth_info->signing_state = signing_state; -+ cli_credentials_set_smb_signing(auth_info->creds, -+ signing_state, -+ CRED_SPECIFIED); - } - - int get_cmdline_auth_info_signing_state(const struct user_auth_info *auth_info) -@@ -257,7 +263,7 @@ int get_cmdline_auth_info_signing_state(const struct user_auth_info *auth_info) - if (auth_info->smb_encrypt) { - return SMB_SIGNING_REQUIRED; - } -- return auth_info->signing_state; -+ return cli_credentials_get_smb_signing(auth_info->creds); - } - - void set_cmdline_auth_info_use_ccache(struct user_auth_info *auth_info, bool b) --- -2.33.1 - - -From abef02315ac0301c9cb0d39b9bafc927a54641d8 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Wed, 10 Jun 2020 12:45:34 +0200 -Subject: [PATCH 022/103] s3:lib: Set smb encryption also via cli creds API - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - source3/lib/util_cmdline.c | 3 +++ - 1 file changed, 3 insertions(+) - -diff --git a/source3/lib/util_cmdline.c b/source3/lib/util_cmdline.c -index 6038ec11515..9c9e2f0ac0f 100644 ---- a/source3/lib/util_cmdline.c -+++ b/source3/lib/util_cmdline.c -@@ -377,6 +377,9 @@ void set_cmdline_auth_info_use_krb5_ticket(struct user_auth_info *auth_info) - /* This should only be used by lib/popt_common.c JRA */ - void set_cmdline_auth_info_smb_encrypt(struct user_auth_info *auth_info) - { -+ cli_credentials_set_smb_encryption(auth_info->creds, -+ SMB_ENCRYPTION_REQUIRED, -+ CRED_SPECIFIED); - auth_info->smb_encrypt = true; - } - --- -2.33.1 - - -From 1be915e64b991bd1e4905be60ec1407ce34a6cdb Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 13 Aug 2020 10:40:23 +0200 -Subject: [PATCH 023/103] python: Remove unused sign argument from - smb_connection() - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - python/samba/netcmd/gpo.py | 9 ++++----- - 1 file changed, 4 insertions(+), 5 deletions(-) - -diff --git a/python/samba/netcmd/gpo.py b/python/samba/netcmd/gpo.py -index 1e2c2918ebe..ad60cda0690 100644 ---- a/python/samba/netcmd/gpo.py -+++ b/python/samba/netcmd/gpo.py -@@ -382,13 +382,13 @@ def create_directory_hier(conn, remotedir): - if not conn.chkpath(path): - conn.mkdir(path) - --def smb_connection(dc_hostname, service, lp, creds, sign=False): -+def smb_connection(dc_hostname, service, lp, creds): - # SMB connect to DC - try: - # the SMB bindings rely on having a s3 loadparm - s3_lp = s3param.get_context() - s3_lp.load(lp.configfile) -- conn = libsmb.Conn(dc_hostname, service, lp=s3_lp, creds=creds, sign=sign) -+ conn = libsmb.Conn(dc_hostname, service, lp=s3_lp, creds=creds, sign=True) - except Exception: - raise CommandError("Error connecting to '%s' using SMB" % dc_hostname) - return conn -@@ -998,7 +998,7 @@ class cmd_fetch(GPOCommand): - - # SMB connect to DC - conn = smb_connection(dc_hostname, service, lp=self.lp, -- creds=self.creds, sign=True) -+ creds=self.creds) - - # Copy GPT - tmpdir, gpodir = self.construct_tmpdir(tmpdir, gpo) -@@ -1629,8 +1629,7 @@ class cmd_admxload(Command): - conn = smb_connection(dc_hostname, - 'sysvol', - lp=self.lp, -- creds=self.creds, -- sign=True) -+ creds=self.creds) - - smb_dir = '\\'.join([self.lp.get('realm').lower(), - 'Policies', 'PolicyDefinitions']) --- -2.33.1 - - -From 9e9da4fa35dc4a49c60bcbf828dcee4b98dddf7b Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Wed, 3 Jun 2020 14:02:37 +0200 -Subject: [PATCH 024/103] python: Set smb signing via the creds API - -Pair-Programmed-With: Stefan Metzmacher - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - python/samba/gpclass.py | 7 +++++++ - python/samba/netcmd/domain_backup.py | 10 +++++++++- - python/samba/netcmd/gpo.py | 6 ++++++ - 3 files changed, 22 insertions(+), 1 deletion(-) - -diff --git a/python/samba/gpclass.py b/python/samba/gpclass.py -index cc574e12a42..1781a55a618 100644 ---- a/python/samba/gpclass.py -+++ b/python/samba/gpclass.py -@@ -38,6 +38,7 @@ from tempfile import NamedTemporaryFile - from samba.dcerpc import preg - from samba.dcerpc import misc - from samba.ndr import ndr_pack, ndr_unpack -+from samba.credentials import SMB_SIGNING_REQUIRED - - try: - from enum import Enum -@@ -421,7 +422,13 @@ def check_refresh_gpo_list(dc_hostname, lp, creds, gpos): - # the SMB bindings rely on having a s3 loadparm - s3_lp = s3param.get_context() - s3_lp.load(lp.configfile) -+ -+ # Force signing for the connection -+ saved_signing_state = creds.get_smb_signing() -+ creds.set_smb_signing(SMB_SIGNING_REQUIRED) - conn = libsmb.Conn(dc_hostname, 'sysvol', lp=s3_lp, creds=creds, sign=True) -+ # Reset signing state -+ creds.set_smb_signing(saved_signing_state) - cache_path = lp.cache_path('gpo_cache') - for gpo in gpos: - if not gpo.file_sys_path: -diff --git a/python/samba/netcmd/domain_backup.py b/python/samba/netcmd/domain_backup.py -index a629b31d70f..15704459fc1 100644 ---- a/python/samba/netcmd/domain_backup.py -+++ b/python/samba/netcmd/domain_backup.py -@@ -55,6 +55,7 @@ from subprocess import CalledProcessError - from samba import sites - from samba.dsdb import _dsdb_load_udv_v2 - from samba.ndr import ndr_pack -+from samba.credentials import SMB_SIGNING_REQUIRED - - - # work out a SID (based on a free RID) to use when the domain gets restored. -@@ -113,7 +114,14 @@ def smb_sysvol_conn(server, lp, creds): - # the SMB bindings rely on having a s3 loadparm - s3_lp = s3param.get_context() - s3_lp.load(lp.configfile) -- return libsmb.Conn(server, "sysvol", lp=s3_lp, creds=creds, sign=True) -+ -+ # Force signing for the connection -+ saved_signing_state = creds.get_smb_signing() -+ creds.set_smb_signing(SMB_SIGNING_REQUIRED) -+ conn = libsmb.Conn(server, "sysvol", lp=s3_lp, creds=creds, sign=True) -+ # Reset signing state -+ creds.set_smb_signing(saved_signing_state) -+ return conn - - - def get_timestamp(): -diff --git a/python/samba/netcmd/gpo.py b/python/samba/netcmd/gpo.py -index ad60cda0690..0f2f6520fc3 100644 ---- a/python/samba/netcmd/gpo.py -+++ b/python/samba/netcmd/gpo.py -@@ -62,6 +62,7 @@ from samba.gp_parse.gp_csv import GPAuditCsvParser - from samba.gp_parse.gp_inf import GptTmplInfParser - from samba.gp_parse.gp_aas import GPAasParser - from samba import param -+from samba.credentials import SMB_SIGNING_REQUIRED - - - def attr_default(msg, attrname, default): -@@ -384,6 +385,9 @@ def create_directory_hier(conn, remotedir): - - def smb_connection(dc_hostname, service, lp, creds): - # SMB connect to DC -+ # Force signing for the smb connection -+ saved_signing_state = creds.get_smb_signing() -+ creds.set_smb_signing(SMB_SIGNING_REQUIRED) - try: - # the SMB bindings rely on having a s3 loadparm - s3_lp = s3param.get_context() -@@ -391,6 +395,8 @@ def smb_connection(dc_hostname, service, lp, creds): - conn = libsmb.Conn(dc_hostname, service, lp=s3_lp, creds=creds, sign=True) - except Exception: - raise CommandError("Error connecting to '%s' using SMB" % dc_hostname) -+ # Reset signing state -+ creds.set_smb_signing(saved_signing_state) - return conn - - --- -2.33.1 - - -From 83bb2d950c6a5c303fad8af88dc268a790aad82d Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 28 May 2020 17:22:12 +0200 -Subject: [PATCH 025/103] s3:libsmb: Introduce CLI_FULL_CONNECTION_IPC - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - examples/winexe/winexe.c | 2 +- - source3/include/client.h | 1 + - source3/libnet/libnet_join.c | 6 +++--- - source3/libsmb/cliconnect.c | 3 ++- - source3/rpc_server/spoolss/srv_spoolss_nt.c | 4 +++- - source3/rpcclient/cmd_spoolss.c | 2 +- - source3/rpcclient/rpcclient.c | 2 +- - source3/utils/mdfind.c | 2 +- - source3/utils/net_ads.c | 3 ++- - source3/utils/net_util.c | 9 +++++++-- - source3/utils/netlookup.c | 4 +++- - 11 files changed, 25 insertions(+), 13 deletions(-) - -diff --git a/examples/winexe/winexe.c b/examples/winexe/winexe.c -index fc6b15f8e52..bb9c27e2e6d 100644 ---- a/examples/winexe/winexe.c -+++ b/examples/winexe/winexe.c -@@ -1919,7 +1919,7 @@ int main(int argc, const char *argv[]) - "IPC$", - "?????", - options.credentials, -- 0, -+ CLI_FULL_CONNECTION_IPC, - 0); - - if (!NT_STATUS_IS_OK(status)) { -diff --git a/source3/include/client.h b/source3/include/client.h -index 6a3b1b02ff3..19a738900b7 100644 ---- a/source3/include/client.h -+++ b/source3/include/client.h -@@ -121,5 +121,6 @@ struct file_info { - #define CLI_FULL_CONNECTION_FORCE_ASCII 0x0100 - #define CLI_FULL_CONNECTION_FORCE_SMB1 0x0400 - #define CLI_FULL_CONNECTION_DISABLE_SMB1 0x0800 -+#define CLI_FULL_CONNECTION_IPC 0x1000 - - #endif /* _CLIENT_H */ -diff --git a/source3/libnet/libnet_join.c b/source3/libnet/libnet_join.c -index 34938603606..392e3eff74f 100644 ---- a/source3/libnet/libnet_join.c -+++ b/source3/libnet/libnet_join.c -@@ -1068,7 +1068,7 @@ static NTSTATUS libnet_join_connect_dc_ipc(const char *dc, - bool use_ccache = false; - bool pw_nt_hash = false; - struct cli_credentials *creds = NULL; -- int flags = 0; -+ int flags = CLI_FULL_CONNECTION_IPC; - NTSTATUS status; - - if (use_kerberos && pass) { -@@ -1684,7 +1684,7 @@ NTSTATUS libnet_join_ok(struct messaging_context *msg_ctx, - struct netlogon_creds_CredentialState *creds = NULL; - uint32_t netlogon_flags = 0; - NTSTATUS status; -- int flags = 0; -+ int flags = CLI_FULL_CONNECTION_IPC; - - if (!dc_name) { - TALLOC_FREE(frame); -@@ -1734,7 +1734,7 @@ NTSTATUS libnet_join_ok(struct messaging_context *msg_ctx, - NULL, 0, - "IPC$", "IPC", - anon_creds, -- 0, -+ flags, - SMB_SIGNING_OFF); - } - -diff --git a/source3/libsmb/cliconnect.c b/source3/libsmb/cliconnect.c -index a79abfaf157..004a9a57af7 100644 ---- a/source3/libsmb/cliconnect.c -+++ b/source3/libsmb/cliconnect.c -@@ -2797,7 +2797,7 @@ static struct tevent_req *cli_start_connection_send( - } - state->ev = ev; - -- if (signing_state == SMB_SIGNING_IPC_DEFAULT) { -+ if (flags & CLI_FULL_CONNECTION_IPC) { - state->min_protocol = lp_client_ipc_min_protocol(); - state->max_protocol = lp_client_ipc_max_protocol(); - } else { -@@ -3682,6 +3682,7 @@ struct cli_state *get_ipc_connect(char *server, - uint32_t flags = CLI_FULL_CONNECTION_ANONYMOUS_FALLBACK; - - flags |= CLI_FULL_CONNECTION_FORCE_SMB1; -+ flags |= CLI_FULL_CONNECTION_IPC; - - nt_status = cli_full_connection_creds(&cli, NULL, server, server_ss, 0, "IPC$", "IPC", - get_cmdline_auth_info_creds(user_info), -diff --git a/source3/rpc_server/spoolss/srv_spoolss_nt.c b/source3/rpc_server/spoolss/srv_spoolss_nt.c -index 7951543747d..29afbb9ccb5 100644 ---- a/source3/rpc_server/spoolss/srv_spoolss_nt.c -+++ b/source3/rpc_server/spoolss/srv_spoolss_nt.c -@@ -2482,7 +2482,9 @@ static bool spoolss_connect_to_client(struct rpc_pipe_client **pp_pipe, struct c - /* setup the connection */ - ret = cli_full_connection_creds( pp_cli, lp_netbios_name(), remote_machine, - &rm_addr, 0, "IPC$", "IPC", -- anon_creds, 0, SMB_SIGNING_OFF); -+ anon_creds, -+ CLI_FULL_CONNECTION_IPC, -+ SMB_SIGNING_OFF); - TALLOC_FREE(anon_creds); - if ( !NT_STATUS_IS_OK( ret ) ) { - DEBUG(2,("spoolss_connect_to_client: connection to [%s] failed!\n", -diff --git a/source3/rpcclient/cmd_spoolss.c b/source3/rpcclient/cmd_spoolss.c -index a7e0c673a65..7198a451ab7 100644 ---- a/source3/rpcclient/cmd_spoolss.c -+++ b/source3/rpcclient/cmd_spoolss.c -@@ -3537,7 +3537,7 @@ static WERROR cmd_spoolss_printercmp(struct rpc_pipe_client *cli, - "IPC$", "IPC", - get_cmdline_auth_info_creds( - popt_get_cmdline_auth_info()), -- 0, /* flags */ -+ CLI_FULL_CONNECTION_IPC, - get_cmdline_auth_info_signing_state( - popt_get_cmdline_auth_info())); - -diff --git a/source3/rpcclient/rpcclient.c b/source3/rpcclient/rpcclient.c -index 67a1066fc15..c86474d08f1 100644 ---- a/source3/rpcclient/rpcclient.c -+++ b/source3/rpcclient/rpcclient.c -@@ -1019,7 +1019,7 @@ out_free: - static int opt_port = 0; - int result = 0; - TALLOC_CTX *frame = talloc_stackframe(); -- uint32_t flags = 0; -+ uint32_t flags = CLI_FULL_CONNECTION_IPC; - struct dcerpc_binding *binding = NULL; - enum dcerpc_transport_t transport; - uint32_t bflags = 0; -diff --git a/source3/utils/mdfind.c b/source3/utils/mdfind.c -index 2f952c29b4f..a3c879e75fb 100644 ---- a/source3/utils/mdfind.c -+++ b/source3/utils/mdfind.c -@@ -70,7 +70,7 @@ int main(int argc, char **argv) - const char *mds_query = NULL; - struct cli_state *cli = NULL; - char *basepath = NULL; -- uint32_t flags = 0; -+ uint32_t flags = CLI_FULL_CONNECTION_IPC; - int signing_state = SMB_SIGNING_IPC_DEFAULT; - uint64_t *cnids = NULL; - size_t ncnids; -diff --git a/source3/utils/net_ads.c b/source3/utils/net_ads.c -index e5db844c2f2..28ef6dc9974 100644 ---- a/source3/utils/net_ads.c -+++ b/source3/utils/net_ads.c -@@ -2437,7 +2437,8 @@ static int net_ads_printer_publish(struct net_context *c, int argc, const char * - nt_status = cli_full_connection_creds(&cli, lp_netbios_name(), servername, - &server_ss, 0, - "IPC$", "IPC", -- creds, 0, -+ creds, -+ CLI_FULL_CONNECTION_IPC, - SMB_SIGNING_IPC_DEFAULT); - - if (NT_STATUS_IS_ERR(nt_status)) { -diff --git a/source3/utils/net_util.c b/source3/utils/net_util.c -index c566ecc9000..d01b2d8c771 100644 ---- a/source3/utils/net_util.c -+++ b/source3/utils/net_util.c -@@ -110,6 +110,7 @@ NTSTATUS connect_to_service(struct net_context *c, - NTSTATUS nt_status; - enum smb_signing_setting signing_setting = SMB_SIGNING_DEFAULT; - struct cli_credentials *creds = NULL; -+ int flags = 0; - - creds = net_context_creds(c, c); - if (creds == NULL) { -@@ -119,12 +120,14 @@ NTSTATUS connect_to_service(struct net_context *c, - - if (strequal(service_type, "IPC")) { - signing_setting = SMB_SIGNING_IPC_DEFAULT; -+ flags |= CLI_FULL_CONNECTION_IPC; - } - - nt_status = cli_full_connection_creds(cli_ctx, NULL, server_name, - server_ss, c->opt_port, - service_name, service_type, -- creds, 0, -+ creds, -+ flags, - signing_setting); - if (!NT_STATUS_IS_OK(nt_status)) { - d_fprintf(stderr, _("Could not connect to server %s\n"), -@@ -195,7 +198,9 @@ NTSTATUS connect_to_ipc_anonymous(struct net_context *c, - nt_status = cli_full_connection_creds(cli_ctx, c->opt_requester_name, - server_name, server_ss, c->opt_port, - "IPC$", "IPC", -- anon_creds, 0, SMB_SIGNING_OFF); -+ anon_creds, -+ CLI_FULL_CONNECTION_IPC, -+ SMB_SIGNING_OFF); - - if (NT_STATUS_IS_OK(nt_status)) { - return nt_status; -diff --git a/source3/utils/netlookup.c b/source3/utils/netlookup.c -index 6cea2ee306c..2241beb331f 100644 ---- a/source3/utils/netlookup.c -+++ b/source3/utils/netlookup.c -@@ -98,7 +98,9 @@ static struct con_struct *create_cs(struct net_context *c, - nt_status = cli_full_connection_creds(&cs->cli, lp_netbios_name(), lp_netbios_name(), - &loopback_ss, 0, - "IPC$", "IPC", -- anon_creds, 0, SMB_SIGNING_OFF); -+ anon_creds, -+ CLI_FULL_CONNECTION_IPC, -+ SMB_SIGNING_OFF); - - if (!NT_STATUS_IS_OK(nt_status)) { - DEBUG(2,("create_cs: Connect failed. Error was %s\n", nt_errstr(nt_status))); --- -2.33.1 - - -From f0a5443694fdc47bcbd607bc0b0f1f862d331ccd Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 28 May 2020 17:29:25 +0200 -Subject: [PATCH 026/103] s3:pylibsmb: Add ipc=True support for - CLI_FULL_CONNECTION_IPC - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - source3/libsmb/pylibsmb.c | 13 +++++++++++-- - 1 file changed, 11 insertions(+), 2 deletions(-) - -diff --git a/source3/libsmb/pylibsmb.c b/source3/libsmb/pylibsmb.c -index 551f552527e..7eb99eba12b 100644 ---- a/source3/libsmb/pylibsmb.c -+++ b/source3/libsmb/pylibsmb.c -@@ -447,6 +447,8 @@ static int py_cli_state_init(struct py_cli_state *self, PyObject *args, - int signing_state = SMB_SIGNING_DEFAULT; - PyObject *py_force_smb1 = Py_False; - bool force_smb1 = false; -+ PyObject *py_ipc = Py_False; -+ bool use_ipc = false; - struct tevent_req *req; - bool ret; - int flags = 0; -@@ -454,6 +456,7 @@ static int py_cli_state_init(struct py_cli_state *self, PyObject *args, - static const char *kwlist[] = { - "host", "share", "lp", "creds", - "multi_threaded", "sign", "force_smb1", -+ "ipc", - NULL - }; - -@@ -464,12 +467,13 @@ static int py_cli_state_init(struct py_cli_state *self, PyObject *args, - } - - ret = ParseTupleAndKeywords( -- args, kwds, "ssO|O!OOO", kwlist, -+ args, kwds, "ssO|O!OOOO", kwlist, - &host, &share, &py_lp, - py_type_Credentials, &creds, - &py_multi_threaded, - &py_sign, -- &py_force_smb1); -+ &py_force_smb1, -+ &py_ipc); - - Py_DECREF(py_type_Credentials); - -@@ -495,6 +499,11 @@ static int py_cli_state_init(struct py_cli_state *self, PyObject *args, - flags = CLI_FULL_CONNECTION_FORCE_SMB1; - } - -+ use_ipc = PyObject_IsTrue(py_ipc); -+ if (use_ipc) { -+ flags |= CLI_FULL_CONNECTION_IPC; -+ } -+ - if (multi_threaded) { - #ifdef HAVE_PTHREAD - ret = py_cli_state_setup_mt_ev(self); --- -2.33.1 - - -From 232942c0d1914558c997b955a9e6f4b30d2bd46d Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Fri, 24 Jul 2020 09:47:11 +0200 -Subject: [PATCH 027/103] python:tests: Mark libsmb connection as an IPC - connection - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - python/samba/tests/dcerpc/raw_testcase.py | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/python/samba/tests/dcerpc/raw_testcase.py b/python/samba/tests/dcerpc/raw_testcase.py -index 7cffccbf1d0..16b58bfa4d7 100644 ---- a/python/samba/tests/dcerpc/raw_testcase.py -+++ b/python/samba/tests/dcerpc/raw_testcase.py -@@ -43,7 +43,7 @@ class smb_pipe_socket(object): - lp3 = s3param.get_context() - lp3.load(lp.configfile) - self.smbconn = libsmb.Conn(target_hostname, 'IPC$', lp3, -- creds=creds, sign=True) -+ creds=creds, ipc=True, sign=True) - self.smbfid = self.smbconn.create(pipename, - DesiredAccess=0x12019f, - ShareAccess=0x7, --- -2.33.1 - - -From 42079e65fa7c6b0b574538940f71d9220abdc329 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Mon, 17 Aug 2020 12:52:39 +0200 -Subject: [PATCH 028/103] python:tests: Set smb ipc signing via the creds API - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - python/samba/tests/dcerpc/raw_testcase.py | 4 ++++ - 1 file changed, 4 insertions(+) - -diff --git a/python/samba/tests/dcerpc/raw_testcase.py b/python/samba/tests/dcerpc/raw_testcase.py -index 16b58bfa4d7..97d9c7fada9 100644 ---- a/python/samba/tests/dcerpc/raw_testcase.py -+++ b/python/samba/tests/dcerpc/raw_testcase.py -@@ -36,14 +36,18 @@ from samba.ntstatus import ( - from samba import NTSTATUSError - from samba.samba3 import param as s3param - from samba.samba3 import libsmb_samba_internal as libsmb -+from samba.credentials import SMB_SIGNING_REQUIRED - - class smb_pipe_socket(object): - - def __init__(self, target_hostname, pipename, creds, impersonation_level, lp): - lp3 = s3param.get_context() - lp3.load(lp.configfile) -+ saved_signing_state = creds.get_smb_ipc_signing() -+ creds.set_smb_ipc_signing(SMB_SIGNING_REQUIRED) - self.smbconn = libsmb.Conn(target_hostname, 'IPC$', lp3, - creds=creds, ipc=True, sign=True) -+ creds.set_smb_ipc_signing(saved_signing_state) - self.smbfid = self.smbconn.create(pipename, - DesiredAccess=0x12019f, - ShareAccess=0x7, --- -2.33.1 - - -From 51c895807ae272520bb5ffa21f783eb64f3e028e Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 28 May 2020 17:59:19 +0200 -Subject: [PATCH 029/103] s3:libsmb: Use 'enum smb_signing_setting' in - cliconnect.c - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - source3/libsmb/cliconnect.c | 14 +++++++------- - source3/libsmb/proto.h | 10 +++++----- - 2 files changed, 12 insertions(+), 12 deletions(-) - -diff --git a/source3/libsmb/cliconnect.c b/source3/libsmb/cliconnect.c -index 004a9a57af7..c12c0c15f4d 100644 ---- a/source3/libsmb/cliconnect.c -+++ b/source3/libsmb/cliconnect.c -@@ -2640,7 +2640,7 @@ static NTSTATUS cli_connect_sock_recv(struct tevent_req *req, - - struct cli_connect_nb_state { - const char *desthost; -- int signing_state; -+ enum smb_signing_setting signing_state; - int flags; - struct cli_state *cli; - }; -@@ -2651,7 +2651,7 @@ static struct tevent_req *cli_connect_nb_send( - TALLOC_CTX *mem_ctx, struct tevent_context *ev, - const char *host, const struct sockaddr_storage *dest_ss, - uint16_t port, int name_type, const char *myname, -- int signing_state, int flags) -+ enum smb_signing_setting signing_state, int flags) - { - struct tevent_req *req, *subreq; - struct cli_connect_nb_state *state; -@@ -2736,7 +2736,7 @@ static NTSTATUS cli_connect_nb_recv(struct tevent_req *req, - - NTSTATUS cli_connect_nb(const char *host, const struct sockaddr_storage *dest_ss, - uint16_t port, int name_type, const char *myname, -- int signing_state, int flags, struct cli_state **pcli) -+ enum smb_signing_setting signing_state, int flags, struct cli_state **pcli) - { - struct tevent_context *ev; - struct tevent_req *req; -@@ -2785,7 +2785,7 @@ static struct tevent_req *cli_start_connection_send( - TALLOC_CTX *mem_ctx, struct tevent_context *ev, - const char *my_name, const char *dest_host, - const struct sockaddr_storage *dest_ss, int port, -- int signing_state, int flags) -+ enum smb_signing_setting signing_state, int flags) - { - struct tevent_req *req, *subreq; - struct cli_start_connection_state *state; -@@ -2890,7 +2890,7 @@ NTSTATUS cli_start_connection(struct cli_state **output_cli, - const char *my_name, - const char *dest_host, - const struct sockaddr_storage *dest_ss, int port, -- int signing_state, int flags) -+ enum smb_signing_setting signing_state, int flags) - { - struct tevent_context *ev; - struct tevent_req *req; -@@ -3370,7 +3370,7 @@ struct tevent_req *cli_full_connection_creds_send( - const struct sockaddr_storage *dest_ss, int port, - const char *service, const char *service_type, - struct cli_credentials *creds, -- int flags, int signing_state) -+ int flags, enum smb_signing_setting signing_state) - { - struct tevent_req *req, *subreq; - struct cli_full_connection_creds_state *state; -@@ -3529,7 +3529,7 @@ NTSTATUS cli_full_connection_creds(struct cli_state **output_cli, - const char *service, const char *service_type, - struct cli_credentials *creds, - int flags, -- int signing_state) -+ enum smb_signing_setting signing_state) - { - struct tevent_context *ev; - struct tevent_req *req; -diff --git a/source3/libsmb/proto.h b/source3/libsmb/proto.h -index d214cdabca4..995187e21b4 100644 ---- a/source3/libsmb/proto.h -+++ b/source3/libsmb/proto.h -@@ -86,12 +86,12 @@ NTSTATUS cli_tree_connect(struct cli_state *cli, const char *share, - NTSTATUS cli_tdis(struct cli_state *cli); - NTSTATUS cli_connect_nb(const char *host, const struct sockaddr_storage *dest_ss, - uint16_t port, int name_type, const char *myname, -- int signing_state, int flags, struct cli_state **pcli); -+ enum smb_signing_setting signing_state, int flags, struct cli_state **pcli); - NTSTATUS cli_start_connection(struct cli_state **output_cli, - const char *my_name, - const char *dest_host, - const struct sockaddr_storage *dest_ss, int port, -- int signing_state, int flags); -+ enum smb_signing_setting signing_state, int flags); - NTSTATUS cli_smb1_setup_encryption(struct cli_state *cli, - struct cli_credentials *creds); - struct tevent_req *cli_full_connection_creds_send( -@@ -100,7 +100,7 @@ struct tevent_req *cli_full_connection_creds_send( - const struct sockaddr_storage *dest_ss, int port, - const char *service, const char *service_type, - struct cli_credentials *creds, -- int flags, int signing_state); -+ int flags, enum smb_signing_setting signing_state); - NTSTATUS cli_full_connection_creds_recv(struct tevent_req *req, - struct cli_state **output_cli); - NTSTATUS cli_full_connection_creds(struct cli_state **output_cli, -@@ -110,7 +110,7 @@ NTSTATUS cli_full_connection_creds(struct cli_state **output_cli, - const char *service, const char *service_type, - struct cli_credentials *creds, - int flags, -- int signing_state); -+ enum smb_signing_setting signing_state); - NTSTATUS cli_raw_tcon(struct cli_state *cli, - const char *service, const char *pass, const char *dev, - uint16_t *max_xmit, uint16_t *tid); -@@ -177,7 +177,7 @@ extern struct GUID cli_state_client_guid; - struct cli_state *cli_state_create(TALLOC_CTX *mem_ctx, - int fd, - const char *remote_name, -- int signing_state, -+ enum smb_signing_setting signing_state, - int flags); - void cli_nt_pipes_close(struct cli_state *cli); - void cli_shutdown(struct cli_state *cli); --- -2.33.1 - - -From 88564455bb8d70d8bf7e79970c8b76b0445f0105 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 28 May 2020 18:11:31 +0200 -Subject: [PATCH 030/103] s3:client: Turn off smb signing for message op - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - python/samba/gpclass.py | 2 +- - python/samba/netcmd/domain_backup.py | 2 +- - python/samba/netcmd/gpo.py | 2 +- - python/samba/tests/dcerpc/raw_testcase.py | 2 +- - source3/client/client.c | 5 ++++- - source3/libsmb/pylibsmb.c | 20 +++++++++----------- - 6 files changed, 17 insertions(+), 16 deletions(-) - -diff --git a/python/samba/gpclass.py b/python/samba/gpclass.py -index 1781a55a618..2c00f5349a0 100644 ---- a/python/samba/gpclass.py -+++ b/python/samba/gpclass.py -@@ -426,7 +426,7 @@ def check_refresh_gpo_list(dc_hostname, lp, creds, gpos): - # Force signing for the connection - saved_signing_state = creds.get_smb_signing() - creds.set_smb_signing(SMB_SIGNING_REQUIRED) -- conn = libsmb.Conn(dc_hostname, 'sysvol', lp=s3_lp, creds=creds, sign=True) -+ conn = libsmb.Conn(dc_hostname, 'sysvol', lp=s3_lp, creds=creds) - # Reset signing state - creds.set_smb_signing(saved_signing_state) - cache_path = lp.cache_path('gpo_cache') -diff --git a/python/samba/netcmd/domain_backup.py b/python/samba/netcmd/domain_backup.py -index 15704459fc1..f441e7407ee 100644 ---- a/python/samba/netcmd/domain_backup.py -+++ b/python/samba/netcmd/domain_backup.py -@@ -118,7 +118,7 @@ def smb_sysvol_conn(server, lp, creds): - # Force signing for the connection - saved_signing_state = creds.get_smb_signing() - creds.set_smb_signing(SMB_SIGNING_REQUIRED) -- conn = libsmb.Conn(server, "sysvol", lp=s3_lp, creds=creds, sign=True) -+ conn = libsmb.Conn(server, "sysvol", lp=s3_lp, creds=creds) - # Reset signing state - creds.set_smb_signing(saved_signing_state) - return conn -diff --git a/python/samba/netcmd/gpo.py b/python/samba/netcmd/gpo.py -index 0f2f6520fc3..bbaa0c17881 100644 ---- a/python/samba/netcmd/gpo.py -+++ b/python/samba/netcmd/gpo.py -@@ -392,7 +392,7 @@ def smb_connection(dc_hostname, service, lp, creds): - # the SMB bindings rely on having a s3 loadparm - s3_lp = s3param.get_context() - s3_lp.load(lp.configfile) -- conn = libsmb.Conn(dc_hostname, service, lp=s3_lp, creds=creds, sign=True) -+ conn = libsmb.Conn(dc_hostname, service, lp=s3_lp, creds=creds) - except Exception: - raise CommandError("Error connecting to '%s' using SMB" % dc_hostname) - # Reset signing state -diff --git a/python/samba/tests/dcerpc/raw_testcase.py b/python/samba/tests/dcerpc/raw_testcase.py -index 97d9c7fada9..0a085a04171 100644 ---- a/python/samba/tests/dcerpc/raw_testcase.py -+++ b/python/samba/tests/dcerpc/raw_testcase.py -@@ -46,7 +46,7 @@ class smb_pipe_socket(object): - saved_signing_state = creds.get_smb_ipc_signing() - creds.set_smb_ipc_signing(SMB_SIGNING_REQUIRED) - self.smbconn = libsmb.Conn(target_hostname, 'IPC$', lp3, -- creds=creds, ipc=True, sign=True) -+ creds=creds, ipc=True) - creds.set_smb_ipc_signing(saved_signing_state) - self.smbfid = self.smbconn.create(pipename, - DesiredAccess=0x12019f, -diff --git a/source3/client/client.c b/source3/client/client.c -index 8c7ceb644aa..56309efcea7 100644 ---- a/source3/client/client.c -+++ b/source3/client/client.c -@@ -6164,7 +6164,10 @@ static int do_message_op(struct user_auth_info *a_info) - - status = cli_connect_nb(desthost, have_ip ? &dest_ss : NULL, - port ? port : NBT_SMB_PORT, name_type, -- lp_netbios_name(), SMB_SIGNING_DEFAULT, 0, &cli); -+ lp_netbios_name(), -+ SMB_SIGNING_OFF, -+ 0, -+ &cli); - if (!NT_STATUS_IS_OK(status)) { - d_printf("Connection to %s failed. Error %s\n", desthost, nt_errstr(status)); - return 1; -diff --git a/source3/libsmb/pylibsmb.c b/source3/libsmb/pylibsmb.c -index 7eb99eba12b..87a1c286b16 100644 ---- a/source3/libsmb/pylibsmb.c -+++ b/source3/libsmb/pylibsmb.c -@@ -442,9 +442,7 @@ static int py_cli_state_init(struct py_cli_state *self, PyObject *args, - PyObject *py_lp = Py_None; - PyObject *py_multi_threaded = Py_False; - bool multi_threaded = false; -- PyObject *py_sign = Py_False; -- bool sign = false; -- int signing_state = SMB_SIGNING_DEFAULT; -+ enum smb_signing_setting signing_state = SMB_SIGNING_DEFAULT; - PyObject *py_force_smb1 = Py_False; - bool force_smb1 = false; - PyObject *py_ipc = Py_False; -@@ -455,7 +453,7 @@ static int py_cli_state_init(struct py_cli_state *self, PyObject *args, - - static const char *kwlist[] = { - "host", "share", "lp", "creds", -- "multi_threaded", "sign", "force_smb1", -+ "multi_threaded", "force_smb1", - "ipc", - NULL - }; -@@ -467,11 +465,10 @@ static int py_cli_state_init(struct py_cli_state *self, PyObject *args, - } - - ret = ParseTupleAndKeywords( -- args, kwds, "ssO|O!OOOO", kwlist, -+ args, kwds, "ssO|O!OOO", kwlist, - &host, &share, &py_lp, - py_type_Credentials, &creds, - &py_multi_threaded, -- &py_sign, - &py_force_smb1, - &py_ipc); - -@@ -482,13 +479,8 @@ static int py_cli_state_init(struct py_cli_state *self, PyObject *args, - } - - multi_threaded = PyObject_IsTrue(py_multi_threaded); -- sign = PyObject_IsTrue(py_sign); - force_smb1 = PyObject_IsTrue(py_force_smb1); - -- if (sign) { -- signing_state = SMB_SIGNING_REQUIRED; -- } -- - if (force_smb1) { - /* - * As most of the cli_*_send() function -@@ -534,6 +526,12 @@ static int py_cli_state_init(struct py_cli_state *self, PyObject *args, - cli_creds = PyCredentials_AsCliCredentials(creds); - } - -+ if (use_ipc) { -+ signing_state = cli_credentials_get_smb_ipc_signing(cli_creds); -+ } else { -+ signing_state = cli_credentials_get_smb_signing(cli_creds); -+ } -+ - req = cli_full_connection_creds_send( - NULL, self->ev, "myname", host, NULL, 0, share, "?????", - cli_creds, flags, signing_state); --- -2.33.1 - - -From a3a45a76a3446078667658ee1b328c032abee866 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 28 May 2020 18:20:02 +0200 -Subject: [PATCH 031/103] s3:libsmb: Remove signing_state from - cli_full_connection_creds_send() - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - source3/libsmb/cliconnect.c | 11 +++++++++-- - source3/libsmb/proto.h | 2 +- - source3/libsmb/pylibsmb.c | 9 +-------- - 3 files changed, 11 insertions(+), 11 deletions(-) - -diff --git a/source3/libsmb/cliconnect.c b/source3/libsmb/cliconnect.c -index c12c0c15f4d..40d82070232 100644 ---- a/source3/libsmb/cliconnect.c -+++ b/source3/libsmb/cliconnect.c -@@ -3370,10 +3370,11 @@ struct tevent_req *cli_full_connection_creds_send( - const struct sockaddr_storage *dest_ss, int port, - const char *service, const char *service_type, - struct cli_credentials *creds, -- int flags, enum smb_signing_setting signing_state) -+ int flags) - { - struct tevent_req *req, *subreq; - struct cli_full_connection_creds_state *state; -+ enum smb_signing_setting signing_state; - - req = tevent_req_create(mem_ctx, &state, - struct cli_full_connection_creds_state); -@@ -3388,6 +3389,12 @@ struct tevent_req *cli_full_connection_creds_send( - state->creds = creds; - state->flags = flags; - -+ if (flags & CLI_FULL_CONNECTION_IPC) { -+ signing_state = cli_credentials_get_smb_ipc_signing(creds); -+ } else { -+ signing_state = cli_credentials_get_smb_signing(creds); -+ } -+ - subreq = cli_start_connection_send( - state, ev, my_name, dest_host, dest_ss, port, - signing_state, flags); -@@ -3541,7 +3548,7 @@ NTSTATUS cli_full_connection_creds(struct cli_state **output_cli, - } - req = cli_full_connection_creds_send( - ev, ev, my_name, dest_host, dest_ss, port, service, -- service_type, creds, flags, signing_state); -+ service_type, creds, flags); - if (req == NULL) { - goto fail; - } -diff --git a/source3/libsmb/proto.h b/source3/libsmb/proto.h -index 995187e21b4..bef04d32638 100644 ---- a/source3/libsmb/proto.h -+++ b/source3/libsmb/proto.h -@@ -100,7 +100,7 @@ struct tevent_req *cli_full_connection_creds_send( - const struct sockaddr_storage *dest_ss, int port, - const char *service, const char *service_type, - struct cli_credentials *creds, -- int flags, enum smb_signing_setting signing_state); -+ int flags); - NTSTATUS cli_full_connection_creds_recv(struct tevent_req *req, - struct cli_state **output_cli); - NTSTATUS cli_full_connection_creds(struct cli_state **output_cli, -diff --git a/source3/libsmb/pylibsmb.c b/source3/libsmb/pylibsmb.c -index 87a1c286b16..7715f4108f3 100644 ---- a/source3/libsmb/pylibsmb.c -+++ b/source3/libsmb/pylibsmb.c -@@ -442,7 +442,6 @@ static int py_cli_state_init(struct py_cli_state *self, PyObject *args, - PyObject *py_lp = Py_None; - PyObject *py_multi_threaded = Py_False; - bool multi_threaded = false; -- enum smb_signing_setting signing_state = SMB_SIGNING_DEFAULT; - PyObject *py_force_smb1 = Py_False; - bool force_smb1 = false; - PyObject *py_ipc = Py_False; -@@ -526,15 +525,9 @@ static int py_cli_state_init(struct py_cli_state *self, PyObject *args, - cli_creds = PyCredentials_AsCliCredentials(creds); - } - -- if (use_ipc) { -- signing_state = cli_credentials_get_smb_ipc_signing(cli_creds); -- } else { -- signing_state = cli_credentials_get_smb_signing(cli_creds); -- } -- - req = cli_full_connection_creds_send( - NULL, self->ev, "myname", host, NULL, 0, share, "?????", -- cli_creds, flags, signing_state); -+ cli_creds, flags); - if (!py_tevent_req_wait_exc(self, req)) { - return -1; - } --- -2.33.1 - - -From d0ff800cfe39cf6fb0c41bf0dcdf5c7c8462f53a Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 4 Jun 2020 14:59:14 +0200 -Subject: [PATCH 032/103] s3:libsmb: Remove signing_state from - cli_full_connection_creds() - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - examples/fuse/smb2mount.c | 3 +-- - examples/winexe/winexe.c | 4 +--- - source3/libnet/libnet_join.c | 9 +++------ - source3/libsmb/cliconnect.c | 6 ++---- - source3/libsmb/libsmb_server.c | 8 +------- - source3/libsmb/proto.h | 3 +-- - source3/rpc_server/spoolss/srv_spoolss_nt.c | 3 +-- - source3/rpcclient/cmd_spoolss.c | 5 +---- - source3/rpcclient/rpcclient.c | 3 +-- - source3/torture/locktest2.c | 11 +++++++++-- - source3/torture/torture.c | 6 ++---- - source3/utils/mdfind.c | 3 +-- - source3/utils/net_ads.c | 3 +-- - source3/utils/net_util.c | 8 ++------ - source3/utils/netlookup.c | 3 +-- - source3/utils/smbcacls.c | 3 +-- - source3/utils/smbcquotas.c | 4 +--- - 17 files changed, 30 insertions(+), 55 deletions(-) - -diff --git a/examples/fuse/smb2mount.c b/examples/fuse/smb2mount.c -index ea1d9a11e0b..6206c3a9701 100644 ---- a/examples/fuse/smb2mount.c -+++ b/examples/fuse/smb2mount.c -@@ -37,8 +37,7 @@ static struct cli_state *connect_one(const struct user_auth_info *auth_info, - NULL, port, - share, "?????", - get_cmdline_auth_info_creds(auth_info), -- flags, -- get_cmdline_auth_info_signing_state(auth_info)); -+ flags); - if (!NT_STATUS_IS_OK(nt_status)) { - DBG_ERR("cli_full_connection failed! (%s)\n", - nt_errstr(nt_status)); -diff --git a/examples/winexe/winexe.c b/examples/winexe/winexe.c -index bb9c27e2e6d..03e7ec85198 100644 ---- a/examples/winexe/winexe.c -+++ b/examples/winexe/winexe.c -@@ -360,7 +360,6 @@ static NTSTATUS winexe_svc_upload( - "ADMIN$", - "?????", - credentials, -- 0, - 0); - if (!NT_STATUS_IS_OK(status)) { - DBG_WARNING("cli_full_connection_creds failed: %s\n", -@@ -1919,8 +1918,7 @@ int main(int argc, const char *argv[]) - "IPC$", - "?????", - options.credentials, -- CLI_FULL_CONNECTION_IPC, -- 0); -+ CLI_FULL_CONNECTION_IPC); - - if (!NT_STATUS_IS_OK(status)) { - DBG_WARNING("cli_full_connection_creds failed: %s\n", -diff --git a/source3/libnet/libnet_join.c b/source3/libnet/libnet_join.c -index 392e3eff74f..f3bf27e6c00 100644 ---- a/source3/libnet/libnet_join.c -+++ b/source3/libnet/libnet_join.c -@@ -1095,8 +1095,7 @@ static NTSTATUS libnet_join_connect_dc_ipc(const char *dc, - NULL, 0, - "IPC$", "IPC", - creds, -- flags, -- SMB_SIGNING_IPC_DEFAULT); -+ flags); - if (!NT_STATUS_IS_OK(status)) { - TALLOC_FREE(frame); - return status; -@@ -1716,8 +1715,7 @@ NTSTATUS libnet_join_ok(struct messaging_context *msg_ctx, - NULL, 0, - "IPC$", "IPC", - cli_creds, -- flags, -- SMB_SIGNING_IPC_DEFAULT); -+ flags); - - if (!NT_STATUS_IS_OK(status)) { - struct cli_credentials *anon_creds = NULL; -@@ -1734,8 +1732,7 @@ NTSTATUS libnet_join_ok(struct messaging_context *msg_ctx, - NULL, 0, - "IPC$", "IPC", - anon_creds, -- flags, -- SMB_SIGNING_OFF); -+ flags); - } - - if (!NT_STATUS_IS_OK(status)) { -diff --git a/source3/libsmb/cliconnect.c b/source3/libsmb/cliconnect.c -index 40d82070232..ca5d3e77da7 100644 ---- a/source3/libsmb/cliconnect.c -+++ b/source3/libsmb/cliconnect.c -@@ -3535,8 +3535,7 @@ NTSTATUS cli_full_connection_creds(struct cli_state **output_cli, - const struct sockaddr_storage *dest_ss, int port, - const char *service, const char *service_type, - struct cli_credentials *creds, -- int flags, -- enum smb_signing_setting signing_state) -+ int flags) - { - struct tevent_context *ev; - struct tevent_req *req; -@@ -3693,8 +3692,7 @@ struct cli_state *get_ipc_connect(char *server, - - nt_status = cli_full_connection_creds(&cli, NULL, server, server_ss, 0, "IPC$", "IPC", - get_cmdline_auth_info_creds(user_info), -- flags, -- SMB_SIGNING_DEFAULT); -+ flags); - - if (NT_STATUS_IS_OK(nt_status)) { - return cli; -diff --git a/source3/libsmb/libsmb_server.c b/source3/libsmb/libsmb_server.c -index 3d1cd602f6c..33dc8419deb 100644 ---- a/source3/libsmb/libsmb_server.c -+++ b/source3/libsmb/libsmb_server.c -@@ -785,7 +785,6 @@ SMBC_attr_server(TALLOC_CTX *ctx, - pp_workgroup, pp_username, pp_password); - if (!ipc_srv) { - struct cli_credentials *creds = NULL; -- int signing_state = SMB_SIGNING_DEFAULT; - - /* We didn't find a cached connection. Get the password */ - if (!*pp_password || (*pp_password)[0] == '\0') { -@@ -812,16 +811,11 @@ SMBC_attr_server(TALLOC_CTX *ctx, - return NULL; - } - -- if (context->internal->smb_encryption_level != SMBC_ENCRYPTLEVEL_NONE) { -- signing_state = SMB_SIGNING_REQUIRED; -- } -- - nt_status = cli_full_connection_creds(&ipc_cli, - lp_netbios_name(), server, - NULL, 0, "IPC$", "?????", - creds, -- flags, -- signing_state); -+ flags); - if (! NT_STATUS_IS_OK(nt_status)) { - TALLOC_FREE(creds); - DEBUG(1,("cli_full_connection failed! (%s)\n", -diff --git a/source3/libsmb/proto.h b/source3/libsmb/proto.h -index bef04d32638..850cf12c8a6 100644 ---- a/source3/libsmb/proto.h -+++ b/source3/libsmb/proto.h -@@ -109,8 +109,7 @@ NTSTATUS cli_full_connection_creds(struct cli_state **output_cli, - const struct sockaddr_storage *dest_ss, int port, - const char *service, const char *service_type, - struct cli_credentials *creds, -- int flags, -- enum smb_signing_setting signing_state); -+ int flags); - NTSTATUS cli_raw_tcon(struct cli_state *cli, - const char *service, const char *pass, const char *dev, - uint16_t *max_xmit, uint16_t *tid); -diff --git a/source3/rpc_server/spoolss/srv_spoolss_nt.c b/source3/rpc_server/spoolss/srv_spoolss_nt.c -index 29afbb9ccb5..adbc0c9db10 100644 ---- a/source3/rpc_server/spoolss/srv_spoolss_nt.c -+++ b/source3/rpc_server/spoolss/srv_spoolss_nt.c -@@ -2483,8 +2483,7 @@ static bool spoolss_connect_to_client(struct rpc_pipe_client **pp_pipe, struct c - ret = cli_full_connection_creds( pp_cli, lp_netbios_name(), remote_machine, - &rm_addr, 0, "IPC$", "IPC", - anon_creds, -- CLI_FULL_CONNECTION_IPC, -- SMB_SIGNING_OFF); -+ CLI_FULL_CONNECTION_IPC); - TALLOC_FREE(anon_creds); - if ( !NT_STATUS_IS_OK( ret ) ) { - DEBUG(2,("spoolss_connect_to_client: connection to [%s] failed!\n", -diff --git a/source3/rpcclient/cmd_spoolss.c b/source3/rpcclient/cmd_spoolss.c -index 7198a451ab7..02889a0a666 100644 ---- a/source3/rpcclient/cmd_spoolss.c -+++ b/source3/rpcclient/cmd_spoolss.c -@@ -3537,10 +3537,7 @@ static WERROR cmd_spoolss_printercmp(struct rpc_pipe_client *cli, - "IPC$", "IPC", - get_cmdline_auth_info_creds( - popt_get_cmdline_auth_info()), -- CLI_FULL_CONNECTION_IPC, -- get_cmdline_auth_info_signing_state( -- popt_get_cmdline_auth_info())); -- -+ CLI_FULL_CONNECTION_IPC); - if ( !NT_STATUS_IS_OK(nt_status) ) - return WERR_GEN_FAILURE; - -diff --git a/source3/rpcclient/rpcclient.c b/source3/rpcclient/rpcclient.c -index c86474d08f1..2ead6cc7ba5 100644 ---- a/source3/rpcclient/rpcclient.c -+++ b/source3/rpcclient/rpcclient.c -@@ -1206,8 +1206,7 @@ out_free: - "IPC$", "IPC", - get_cmdline_auth_info_creds( - popt_get_cmdline_auth_info()), -- flags, -- SMB_SIGNING_IPC_DEFAULT); -+ flags); - - if (!NT_STATUS_IS_OK(nt_status)) { - DEBUG(0,("Cannot connect to server. Error was %s\n", nt_errstr(nt_status))); -diff --git a/source3/torture/locktest2.c b/source3/torture/locktest2.c -index 84c335f959f..92ddb7629b9 100644 ---- a/source3/torture/locktest2.c -+++ b/source3/torture/locktest2.c -@@ -217,8 +217,15 @@ static struct cli_state *connect_one(char *share) - - slprintf(myname,sizeof(myname), "lock-%lu-%u", (unsigned long)getpid(), count++); - -- nt_status = cli_full_connection_creds(&c, myname, server_n, NULL, 0, share, "?????", -- creds, 0, SMB_SIGNING_DEFAULT); -+ nt_status = cli_full_connection_creds(&c, -+ myname, -+ server_n, -+ NULL, -+ 0, -+ share, -+ "?????", -+ creds, -+ 0); - TALLOC_FREE(creds); - if (!NT_STATUS_IS_OK(nt_status)) { - DEBUG(0, ("cli_full_connection failed with error %s\n", nt_errstr(nt_status))); -diff --git a/source3/torture/torture.c b/source3/torture/torture.c -index 5e263797730..922d0c73193 100644 ---- a/source3/torture/torture.c -+++ b/source3/torture/torture.c -@@ -345,8 +345,7 @@ static bool torture_open_connection_share(struct cli_state **c, - sharename, - "?????", - torture_creds, -- flags, -- signing_state); -+ flags); - if (!NT_STATUS_IS_OK(status)) { - printf("failed to open share connection: //%s/%s port:%d - %s\n", - hostname, sharename, port_to_use, nt_errstr(status)); -@@ -1528,8 +1527,7 @@ static bool run_tcon_devtype_test(int dummy) - NULL, /* service */ - NULL, /* service_type */ - torture_creds, -- flags, -- signing_state); -+ flags); - - if (!NT_STATUS_IS_OK(status)) { - printf("could not open connection\n"); -diff --git a/source3/utils/mdfind.c b/source3/utils/mdfind.c -index a3c879e75fb..2ac4fde7daf 100644 ---- a/source3/utils/mdfind.c -+++ b/source3/utils/mdfind.c -@@ -153,8 +153,7 @@ int main(int argc, char **argv) - "IPC$", - "IPC", - creds, -- flags, -- SMB_SIGNING_IPC_DEFAULT); -+ flags); - if (!NT_STATUS_IS_OK(status)) { - DBG_ERR("Cannot connect to server: %s\n", nt_errstr(status)); - goto fail; -diff --git a/source3/utils/net_ads.c b/source3/utils/net_ads.c -index 28ef6dc9974..7f5b9c3a440 100644 ---- a/source3/utils/net_ads.c -+++ b/source3/utils/net_ads.c -@@ -2438,8 +2438,7 @@ static int net_ads_printer_publish(struct net_context *c, int argc, const char * - &server_ss, 0, - "IPC$", "IPC", - creds, -- CLI_FULL_CONNECTION_IPC, -- SMB_SIGNING_IPC_DEFAULT); -+ CLI_FULL_CONNECTION_IPC); - - if (NT_STATUS_IS_ERR(nt_status)) { - d_fprintf(stderr, _("Unable to open a connection to %s to " -diff --git a/source3/utils/net_util.c b/source3/utils/net_util.c -index d01b2d8c771..b139fb2d0da 100644 ---- a/source3/utils/net_util.c -+++ b/source3/utils/net_util.c -@@ -108,7 +108,6 @@ NTSTATUS connect_to_service(struct net_context *c, - const char *service_type) - { - NTSTATUS nt_status; -- enum smb_signing_setting signing_setting = SMB_SIGNING_DEFAULT; - struct cli_credentials *creds = NULL; - int flags = 0; - -@@ -119,7 +118,6 @@ NTSTATUS connect_to_service(struct net_context *c, - } - - if (strequal(service_type, "IPC")) { -- signing_setting = SMB_SIGNING_IPC_DEFAULT; - flags |= CLI_FULL_CONNECTION_IPC; - } - -@@ -127,8 +125,7 @@ NTSTATUS connect_to_service(struct net_context *c, - server_ss, c->opt_port, - service_name, service_type, - creds, -- flags, -- signing_setting); -+ flags); - if (!NT_STATUS_IS_OK(nt_status)) { - d_fprintf(stderr, _("Could not connect to server %s\n"), - server_name); -@@ -199,8 +196,7 @@ NTSTATUS connect_to_ipc_anonymous(struct net_context *c, - server_name, server_ss, c->opt_port, - "IPC$", "IPC", - anon_creds, -- CLI_FULL_CONNECTION_IPC, -- SMB_SIGNING_OFF); -+ CLI_FULL_CONNECTION_IPC); - - if (NT_STATUS_IS_OK(nt_status)) { - return nt_status; -diff --git a/source3/utils/netlookup.c b/source3/utils/netlookup.c -index 2241beb331f..aaf78b0977a 100644 ---- a/source3/utils/netlookup.c -+++ b/source3/utils/netlookup.c -@@ -99,8 +99,7 @@ static struct con_struct *create_cs(struct net_context *c, - &loopback_ss, 0, - "IPC$", "IPC", - anon_creds, -- CLI_FULL_CONNECTION_IPC, -- SMB_SIGNING_OFF); -+ CLI_FULL_CONNECTION_IPC); - - if (!NT_STATUS_IS_OK(nt_status)) { - DEBUG(2,("create_cs: Connect failed. Error was %s\n", nt_errstr(nt_status))); -diff --git a/source3/utils/smbcacls.c b/source3/utils/smbcacls.c -index f3209c31877..5983ebbd0a5 100644 ---- a/source3/utils/smbcacls.c -+++ b/source3/utils/smbcacls.c -@@ -778,8 +778,7 @@ static struct cli_state *connect_one(const struct user_auth_info *auth_info, - NULL, 0, - share, "?????", - get_cmdline_auth_info_creds(auth_info), -- flags, -- get_cmdline_auth_info_signing_state(auth_info)); -+ flags); - if (!NT_STATUS_IS_OK(nt_status)) { - DEBUG(0,("cli_full_connection failed! (%s)\n", nt_errstr(nt_status))); - return NULL; -diff --git a/source3/utils/smbcquotas.c b/source3/utils/smbcquotas.c -index 954d6eba804..fea066ce468 100644 ---- a/source3/utils/smbcquotas.c -+++ b/source3/utils/smbcquotas.c -@@ -527,9 +527,7 @@ static struct cli_state *connect_one(const char *share) - share, "?????", - get_cmdline_auth_info_creds( - popt_get_cmdline_auth_info()), -- flags, -- get_cmdline_auth_info_signing_state( -- popt_get_cmdline_auth_info())); -+ flags); - if (!NT_STATUS_IS_OK(nt_status)) { - DEBUG(0,("cli_full_connection failed! (%s)\n", nt_errstr(nt_status))); - return NULL; --- -2.33.1 - - -From e43c942a69eb70822e015b008828e432ca8889d0 Mon Sep 17 00:00:00 2001 -From: Stefan Metzmacher -Date: Mon, 8 Jun 2020 08:04:24 +0200 -Subject: [PATCH 033/103] s3:libsmb: Add encryption support to - cli_full_connection_creds*() - -Pair-Programmed-With: Andreas Schneider - -Signed-off-by: Andreas Schneider -Signed-off-by: Stefan Metzmacher -Reviewed-by: Andreas Schneider ---- - source3/libsmb/cliconnect.c | 166 ++++++++++++++++++++++++++++++++++++ - 1 file changed, 166 insertions(+) - -diff --git a/source3/libsmb/cliconnect.c b/source3/libsmb/cliconnect.c -index ca5d3e77da7..45eafa97885 100644 ---- a/source3/libsmb/cliconnect.c -+++ b/source3/libsmb/cliconnect.c -@@ -3361,6 +3361,10 @@ static int cli_full_connection_creds_state_destructor( - static void cli_full_connection_creds_conn_done(struct tevent_req *subreq); - static void cli_full_connection_creds_sess_start(struct tevent_req *req); - static void cli_full_connection_creds_sess_done(struct tevent_req *subreq); -+static void cli_full_connection_creds_enc_start(struct tevent_req *req); -+static void cli_full_connection_creds_enc_tcon(struct tevent_req *subreq); -+static void cli_full_connection_creds_enc_ver(struct tevent_req *subreq); -+static void cli_full_connection_creds_enc_done(struct tevent_req *subreq); - static void cli_full_connection_creds_tcon_start(struct tevent_req *req); - static void cli_full_connection_creds_tcon_done(struct tevent_req *subreq); - -@@ -3375,6 +3379,8 @@ struct tevent_req *cli_full_connection_creds_send( - struct tevent_req *req, *subreq; - struct cli_full_connection_creds_state *state; - enum smb_signing_setting signing_state; -+ enum smb_encryption_setting encryption_state = -+ cli_credentials_get_smb_encryption(creds); - - req = tevent_req_create(mem_ctx, &state, - struct cli_full_connection_creds_state); -@@ -3395,6 +3401,16 @@ struct tevent_req *cli_full_connection_creds_send( - signing_state = cli_credentials_get_smb_signing(creds); - } - -+ if (encryption_state == SMB_ENCRYPTION_REQUIRED) { -+ if (flags & CLI_FULL_CONNECTION_ANONYMOUS_FALLBACK) { -+ encryption_state = SMB_ENCRYPTION_DESIRED; -+ } -+ } -+ -+ if (encryption_state >= SMB_ENCRYPTION_DESIRED) { -+ signing_state = SMB_SIGNING_REQUIRED; -+ } -+ - subreq = cli_start_connection_send( - state, ev, my_name, dest_host, dest_ss, port, - signing_state, flags); -@@ -3469,6 +3485,156 @@ static void cli_full_connection_creds_sess_done(struct tevent_req *subreq) - return; - } - -+ cli_full_connection_creds_enc_start(req); -+} -+ -+static void cli_full_connection_creds_enc_start(struct tevent_req *req) -+{ -+ struct cli_full_connection_creds_state *state = tevent_req_data( -+ req, struct cli_full_connection_creds_state); -+ enum smb_encryption_setting encryption_state = -+ cli_credentials_get_smb_encryption(state->creds); -+ struct tevent_req *subreq = NULL; -+ NTSTATUS status; -+ -+ if (encryption_state < SMB_ENCRYPTION_DESIRED) { -+ cli_full_connection_creds_tcon_start(req); -+ return; -+ } -+ -+ if (smbXcli_conn_protocol(state->cli->conn) >= PROTOCOL_SMB2_02) { -+ status = smb2cli_session_encryption_on(state->cli->smb2.session); -+ if (NT_STATUS_EQUAL(status, NT_STATUS_NOT_SUPPORTED)) { -+ if (encryption_state < SMB_ENCRYPTION_REQUIRED) { -+ cli_full_connection_creds_tcon_start(req); -+ return; -+ } -+ d_printf("Encryption required and " -+ "server doesn't support " -+ "SMB3 encryption - failing connect\n"); -+ tevent_req_nterror(req, status); -+ return; -+ } else if (!NT_STATUS_IS_OK(status)) { -+ d_printf("Encryption required and " -+ "setup failed with error %s.\n", -+ nt_errstr(status)); -+ tevent_req_nterror(req, status); -+ return; -+ } -+ -+ cli_full_connection_creds_tcon_start(req); -+ return; -+ } -+ -+ if (!SERVER_HAS_UNIX_CIFS(state->cli)) { -+ if (encryption_state < SMB_ENCRYPTION_REQUIRED) { -+ cli_full_connection_creds_tcon_start(req); -+ return; -+ } -+ -+ status = NT_STATUS_NOT_SUPPORTED; -+ d_printf("Encryption required and " -+ "server doesn't support " -+ "SMB1 Unix Extensions - failing connect\n"); -+ tevent_req_nterror(req, status); -+ return; -+ } -+ -+ /* -+ * We do a tcon on IPC$ just to setup the encryption, -+ * the real tcon will be encrypted then. -+ */ -+ subreq = cli_tree_connect_send(state, state->ev, state->cli, -+ "IPC$", "IPC", NULL); -+ if (tevent_req_nomem(subreq, req)) { -+ return; -+ } -+ tevent_req_set_callback(subreq, cli_full_connection_creds_enc_tcon, req); -+} -+ -+static void cli_full_connection_creds_enc_tcon(struct tevent_req *subreq) -+{ -+ struct tevent_req *req = tevent_req_callback_data( -+ subreq, struct tevent_req); -+ struct cli_full_connection_creds_state *state = tevent_req_data( -+ req, struct cli_full_connection_creds_state); -+ NTSTATUS status; -+ -+ status = cli_tree_connect_recv(subreq); -+ TALLOC_FREE(subreq); -+ if (tevent_req_nterror(req, status)) { -+ return; -+ } -+ -+ subreq = cli_unix_extensions_version_send(state, state->ev, state->cli); -+ if (tevent_req_nomem(subreq, req)) { -+ return; -+ } -+ tevent_req_set_callback(subreq, cli_full_connection_creds_enc_ver, req); -+} -+ -+static void cli_full_connection_creds_enc_ver(struct tevent_req *subreq) -+{ -+ struct tevent_req *req = tevent_req_callback_data( -+ subreq, struct tevent_req); -+ struct cli_full_connection_creds_state *state = tevent_req_data( -+ req, struct cli_full_connection_creds_state); -+ enum smb_encryption_setting encryption_state = -+ cli_credentials_get_smb_encryption(state->creds); -+ uint16_t major, minor; -+ uint32_t caplow, caphigh; -+ NTSTATUS status; -+ -+ status = cli_unix_extensions_version_recv(subreq, -+ &major, &minor, -+ &caplow, -+ &caphigh); -+ TALLOC_FREE(subreq); -+ if (!NT_STATUS_IS_OK(status)) { -+ if (encryption_state < SMB_ENCRYPTION_REQUIRED) { -+ cli_full_connection_creds_tcon_start(req); -+ return; -+ } -+ DEBUG(10, ("%s: cli_unix_extensions_version " -+ "returned %s\n", __func__, nt_errstr(status))); -+ tevent_req_nterror(req, NT_STATUS_UNKNOWN_REVISION); -+ return; -+ } -+ -+ if (!(caplow & CIFS_UNIX_TRANSPORT_ENCRYPTION_CAP)) { -+ if (encryption_state < SMB_ENCRYPTION_REQUIRED) { -+ cli_full_connection_creds_tcon_start(req); -+ return; -+ } -+ DEBUG(10, ("%s: CIFS_UNIX_TRANSPORT_ENCRYPTION_CAP " -+ "not supported\n", __func__)); -+ tevent_req_nterror(req, NT_STATUS_UNSUPPORTED_COMPRESSION); -+ return; -+ } -+ -+ subreq = cli_smb1_setup_encryption_send(state, state->ev, -+ state->cli, -+ state->creds); -+ if (tevent_req_nomem(subreq, req)) { -+ return; -+ } -+ tevent_req_set_callback(subreq, -+ cli_full_connection_creds_enc_done, -+ req); -+} -+ -+static void cli_full_connection_creds_enc_done(struct tevent_req *subreq) -+{ -+ struct tevent_req *req = tevent_req_callback_data( -+ subreq, struct tevent_req); -+ NTSTATUS status; -+ -+ status = cli_smb1_setup_encryption_recv(subreq); -+ TALLOC_FREE(subreq); -+ if (tevent_req_nterror(req, status)) { -+ return; -+ } -+ - cli_full_connection_creds_tcon_start(req); - } - --- -2.33.1 - - -From 57bba0cd6455944d53a24cb23595fec4501084b7 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Wed, 10 Jun 2020 11:26:00 +0200 -Subject: [PATCH 034/103] python: Add a test for SMB encryption - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - python/samba/tests/libsmb.py | 37 ++++++++++++++++++++++++++++++++++++ - 1 file changed, 37 insertions(+) - -diff --git a/python/samba/tests/libsmb.py b/python/samba/tests/libsmb.py -index e8f8e7fe94d..81d4e482644 100644 ---- a/python/samba/tests/libsmb.py -+++ b/python/samba/tests/libsmb.py -@@ -21,10 +21,12 @@ from samba.samba3 import libsmb_samba_internal as libsmb - from samba.dcerpc import security - from samba.samba3 import param as s3param - from samba import credentials -+from samba.credentials import SMB_ENCRYPTION_REQUIRED - import samba.tests - import threading - import sys - import os -+import random - - - class LibsmbTestCase(samba.tests.TestCase): -@@ -77,6 +79,41 @@ class LibsmbTestCase(samba.tests.TestCase): - if t.exc: - raise t.exc[0](t.exc[1]) - -+ def test_SMB3EncryptionRequired(self): -+ test_dir = 'testing_%d' % random.randint(0, 0xFFFF) -+ -+ lp = s3param.get_context() -+ lp.load(os.getenv("SMB_CONF_PATH")) -+ -+ creds = credentials.Credentials() -+ creds.guess(lp) -+ creds.set_username(os.getenv("USERNAME")) -+ creds.set_password(os.getenv("PASSWORD")) -+ creds.set_smb_encryption(SMB_ENCRYPTION_REQUIRED) -+ -+ c = libsmb.Conn(os.getenv("SERVER_IP"), "tmp", -+ lp, creds) -+ -+ c.mkdir(test_dir) -+ c.rmdir(test_dir) -+ -+ def test_SMB1EncryptionRequired(self): -+ test_dir = 'testing_%d' % random.randint(0, 0xFFFF) -+ -+ lp = s3param.get_context() -+ lp.load(os.getenv("SMB_CONF_PATH")) -+ -+ creds = credentials.Credentials() -+ creds.guess(lp) -+ creds.set_username(os.getenv("USERNAME")) -+ creds.set_password(os.getenv("PASSWORD")) -+ creds.set_smb_encryption(SMB_ENCRYPTION_REQUIRED) -+ -+ c = libsmb.Conn(os.getenv("SERVER_IP"), "tmp", -+ lp, creds, force_smb1=True) -+ -+ c.mkdir(test_dir) -+ c.rmdir(test_dir) - - if __name__ == "__main__": - import unittest --- -2.33.1 - - -From 99f6e2a0b4ff21fb3c5ccf5e4c270d2abcbdaebc Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Wed, 10 Jun 2020 12:31:02 +0200 -Subject: [PATCH 035/103] s3:net: Use cli_credentials_set_smb_encryption() - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - source3/utils/net_util.c | 16 ++++++---------- - 1 file changed, 6 insertions(+), 10 deletions(-) - -diff --git a/source3/utils/net_util.c b/source3/utils/net_util.c -index b139fb2d0da..5829d891075 100644 ---- a/source3/utils/net_util.c -+++ b/source3/utils/net_util.c -@@ -148,16 +148,6 @@ NTSTATUS connect_to_service(struct net_context *c, - return nt_status; - } - -- if (c->smb_encrypt) { -- nt_status = cli_cm_force_encryption_creds(*cli_ctx, -- creds, -- service_name); -- if (!NT_STATUS_IS_OK(nt_status)) { -- cli_shutdown(*cli_ctx); -- *cli_ctx = NULL; -- } -- } -- - return nt_status; - } - -@@ -577,6 +567,12 @@ struct cli_credentials *net_context_creds(struct net_context *c, - CRED_SPECIFIED); - } - -+ if (c->smb_encrypt) { -+ cli_credentials_set_smb_encryption(creds, -+ SMB_ENCRYPTION_REQUIRED, -+ CRED_SPECIFIED); -+ } -+ - return creds; - } - --- -2.33.1 - - -From 346648850bfff3b98d4fdbe6868434692f95470f Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Wed, 10 Jun 2020 12:40:13 +0200 -Subject: [PATCH 036/103] s3:libsmb: Use cli_credentials_set_smb_encryption() - -This also adds a SMBC_ENCRYPTLEVEL_DEFAULT to 'enum -smbc_smb_encrypt_level' in order to use the smb.conf default value. - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - source3/include/libsmbclient.h | 1 + - source3/libsmb/ABI/smbclient-0.7.0.sigs | 188 ++++++++++++++++++++++++ - source3/libsmb/libsmb_context.c | 4 +- - source3/libsmb/libsmb_server.c | 72 +++------ - source3/libsmb/wscript | 2 +- - 5 files changed, 216 insertions(+), 51 deletions(-) - create mode 100644 source3/libsmb/ABI/smbclient-0.7.0.sigs - -diff --git a/source3/include/libsmbclient.h b/source3/include/libsmbclient.h -index c47e7c2a872..84c98089251 100644 ---- a/source3/include/libsmbclient.h -+++ b/source3/include/libsmbclient.h -@@ -225,6 +225,7 @@ typedef enum smbc_share_mode - */ - typedef enum smbc_smb_encrypt_level - { -+ SMBC_ENCRYPTLEVEL_DEFAULT = -1, - SMBC_ENCRYPTLEVEL_NONE = 0, - SMBC_ENCRYPTLEVEL_REQUEST = 1, - SMBC_ENCRYPTLEVEL_REQUIRE = 2 -diff --git a/source3/libsmb/ABI/smbclient-0.7.0.sigs b/source3/libsmb/ABI/smbclient-0.7.0.sigs -new file mode 100644 -index 00000000000..ee758e21b50 ---- /dev/null -+++ b/source3/libsmb/ABI/smbclient-0.7.0.sigs -@@ -0,0 +1,188 @@ -+smbc_chmod: int (const char *, mode_t) -+smbc_close: int (int) -+smbc_closedir: int (int) -+smbc_creat: int (const char *, mode_t) -+smbc_fgetxattr: int (int, const char *, const void *, size_t) -+smbc_flistxattr: int (int, char *, size_t) -+smbc_free_context: int (SMBCCTX *, int) -+smbc_fremovexattr: int (int, const char *) -+smbc_fsetxattr: int (int, const char *, const void *, size_t, int) -+smbc_fstat: int (int, struct stat *) -+smbc_fstatvfs: int (int, struct statvfs *) -+smbc_ftruncate: int (int, off_t) -+smbc_getDebug: int (SMBCCTX *) -+smbc_getFunctionAddCachedServer: smbc_add_cached_srv_fn (SMBCCTX *) -+smbc_getFunctionAuthData: smbc_get_auth_data_fn (SMBCCTX *) -+smbc_getFunctionAuthDataWithContext: smbc_get_auth_data_with_context_fn (SMBCCTX *) -+smbc_getFunctionCheckServer: smbc_check_server_fn (SMBCCTX *) -+smbc_getFunctionChmod: smbc_chmod_fn (SMBCCTX *) -+smbc_getFunctionClose: smbc_close_fn (SMBCCTX *) -+smbc_getFunctionClosedir: smbc_closedir_fn (SMBCCTX *) -+smbc_getFunctionCreat: smbc_creat_fn (SMBCCTX *) -+smbc_getFunctionFstat: smbc_fstat_fn (SMBCCTX *) -+smbc_getFunctionFstatVFS: smbc_fstatvfs_fn (SMBCCTX *) -+smbc_getFunctionFstatdir: smbc_fstatdir_fn (SMBCCTX *) -+smbc_getFunctionFtruncate: smbc_ftruncate_fn (SMBCCTX *) -+smbc_getFunctionGetCachedServer: smbc_get_cached_srv_fn (SMBCCTX *) -+smbc_getFunctionGetdents: smbc_getdents_fn (SMBCCTX *) -+smbc_getFunctionGetxattr: smbc_getxattr_fn (SMBCCTX *) -+smbc_getFunctionListPrintJobs: smbc_list_print_jobs_fn (SMBCCTX *) -+smbc_getFunctionListxattr: smbc_listxattr_fn (SMBCCTX *) -+smbc_getFunctionLseek: smbc_lseek_fn (SMBCCTX *) -+smbc_getFunctionLseekdir: smbc_lseekdir_fn (SMBCCTX *) -+smbc_getFunctionMkdir: smbc_mkdir_fn (SMBCCTX *) -+smbc_getFunctionNotify: smbc_notify_fn (SMBCCTX *) -+smbc_getFunctionOpen: smbc_open_fn (SMBCCTX *) -+smbc_getFunctionOpenPrintJob: smbc_open_print_job_fn (SMBCCTX *) -+smbc_getFunctionOpendir: smbc_opendir_fn (SMBCCTX *) -+smbc_getFunctionPrintFile: smbc_print_file_fn (SMBCCTX *) -+smbc_getFunctionPurgeCachedServers: smbc_purge_cached_fn (SMBCCTX *) -+smbc_getFunctionRead: smbc_read_fn (SMBCCTX *) -+smbc_getFunctionReaddir: smbc_readdir_fn (SMBCCTX *) -+smbc_getFunctionReaddirPlus: smbc_readdirplus_fn (SMBCCTX *) -+smbc_getFunctionReaddirPlus2: smbc_readdirplus2_fn (SMBCCTX *) -+smbc_getFunctionRemoveCachedServer: smbc_remove_cached_srv_fn (SMBCCTX *) -+smbc_getFunctionRemoveUnusedServer: smbc_remove_unused_server_fn (SMBCCTX *) -+smbc_getFunctionRemovexattr: smbc_removexattr_fn (SMBCCTX *) -+smbc_getFunctionRename: smbc_rename_fn (SMBCCTX *) -+smbc_getFunctionRmdir: smbc_rmdir_fn (SMBCCTX *) -+smbc_getFunctionSetxattr: smbc_setxattr_fn (SMBCCTX *) -+smbc_getFunctionSplice: smbc_splice_fn (SMBCCTX *) -+smbc_getFunctionStat: smbc_stat_fn (SMBCCTX *) -+smbc_getFunctionStatVFS: smbc_statvfs_fn (SMBCCTX *) -+smbc_getFunctionTelldir: smbc_telldir_fn (SMBCCTX *) -+smbc_getFunctionUnlink: smbc_unlink_fn (SMBCCTX *) -+smbc_getFunctionUnlinkPrintJob: smbc_unlink_print_job_fn (SMBCCTX *) -+smbc_getFunctionUtimes: smbc_utimes_fn (SMBCCTX *) -+smbc_getFunctionWrite: smbc_write_fn (SMBCCTX *) -+smbc_getNetbiosName: const char *(SMBCCTX *) -+smbc_getOptionBrowseMaxLmbCount: int (SMBCCTX *) -+smbc_getOptionCaseSensitive: smbc_bool (SMBCCTX *) -+smbc_getOptionDebugToStderr: smbc_bool (SMBCCTX *) -+smbc_getOptionFallbackAfterKerberos: smbc_bool (SMBCCTX *) -+smbc_getOptionFullTimeNames: smbc_bool (SMBCCTX *) -+smbc_getOptionNoAutoAnonymousLogin: smbc_bool (SMBCCTX *) -+smbc_getOptionOneSharePerServer: smbc_bool (SMBCCTX *) -+smbc_getOptionOpenShareMode: smbc_share_mode (SMBCCTX *) -+smbc_getOptionSmbEncryptionLevel: smbc_smb_encrypt_level (SMBCCTX *) -+smbc_getOptionUrlEncodeReaddirEntries: smbc_bool (SMBCCTX *) -+smbc_getOptionUseCCache: smbc_bool (SMBCCTX *) -+smbc_getOptionUseKerberos: smbc_bool (SMBCCTX *) -+smbc_getOptionUseNTHash: smbc_bool (SMBCCTX *) -+smbc_getOptionUserData: void *(SMBCCTX *) -+smbc_getPort: uint16_t (SMBCCTX *) -+smbc_getServerCacheData: struct smbc_server_cache *(SMBCCTX *) -+smbc_getTimeout: int (SMBCCTX *) -+smbc_getUser: const char *(SMBCCTX *) -+smbc_getWorkgroup: const char *(SMBCCTX *) -+smbc_getdents: int (unsigned int, struct smbc_dirent *, int) -+smbc_getxattr: int (const char *, const char *, const void *, size_t) -+smbc_init: int (smbc_get_auth_data_fn, int) -+smbc_init_context: SMBCCTX *(SMBCCTX *) -+smbc_lgetxattr: int (const char *, const char *, const void *, size_t) -+smbc_list_print_jobs: int (const char *, smbc_list_print_job_fn) -+smbc_listxattr: int (const char *, char *, size_t) -+smbc_llistxattr: int (const char *, char *, size_t) -+smbc_lremovexattr: int (const char *, const char *) -+smbc_lseek: off_t (int, off_t, int) -+smbc_lseekdir: int (int, off_t) -+smbc_lsetxattr: int (const char *, const char *, const void *, size_t, int) -+smbc_mkdir: int (const char *, mode_t) -+smbc_new_context: SMBCCTX *(void) -+smbc_notify: int (int, smbc_bool, uint32_t, unsigned int, smbc_notify_callback_fn, void *) -+smbc_open: int (const char *, int, mode_t) -+smbc_open_print_job: int (const char *) -+smbc_opendir: int (const char *) -+smbc_option_get: void *(SMBCCTX *, char *) -+smbc_option_set: void (SMBCCTX *, char *, ...) -+smbc_print_file: int (const char *, const char *) -+smbc_read: ssize_t (int, void *, size_t) -+smbc_readdir: struct smbc_dirent *(unsigned int) -+smbc_readdirplus: const struct libsmb_file_info *(unsigned int) -+smbc_readdirplus2: const struct libsmb_file_info *(unsigned int, struct stat *) -+smbc_removexattr: int (const char *, const char *) -+smbc_rename: int (const char *, const char *) -+smbc_rmdir: int (const char *) -+smbc_setConfiguration: int (SMBCCTX *, const char *) -+smbc_setDebug: void (SMBCCTX *, int) -+smbc_setFunctionAddCachedServer: void (SMBCCTX *, smbc_add_cached_srv_fn) -+smbc_setFunctionAuthData: void (SMBCCTX *, smbc_get_auth_data_fn) -+smbc_setFunctionAuthDataWithContext: void (SMBCCTX *, smbc_get_auth_data_with_context_fn) -+smbc_setFunctionCheckServer: void (SMBCCTX *, smbc_check_server_fn) -+smbc_setFunctionChmod: void (SMBCCTX *, smbc_chmod_fn) -+smbc_setFunctionClose: void (SMBCCTX *, smbc_close_fn) -+smbc_setFunctionClosedir: void (SMBCCTX *, smbc_closedir_fn) -+smbc_setFunctionCreat: void (SMBCCTX *, smbc_creat_fn) -+smbc_setFunctionFstat: void (SMBCCTX *, smbc_fstat_fn) -+smbc_setFunctionFstatVFS: void (SMBCCTX *, smbc_fstatvfs_fn) -+smbc_setFunctionFstatdir: void (SMBCCTX *, smbc_fstatdir_fn) -+smbc_setFunctionFtruncate: void (SMBCCTX *, smbc_ftruncate_fn) -+smbc_setFunctionGetCachedServer: void (SMBCCTX *, smbc_get_cached_srv_fn) -+smbc_setFunctionGetdents: void (SMBCCTX *, smbc_getdents_fn) -+smbc_setFunctionGetxattr: void (SMBCCTX *, smbc_getxattr_fn) -+smbc_setFunctionListPrintJobs: void (SMBCCTX *, smbc_list_print_jobs_fn) -+smbc_setFunctionListxattr: void (SMBCCTX *, smbc_listxattr_fn) -+smbc_setFunctionLseek: void (SMBCCTX *, smbc_lseek_fn) -+smbc_setFunctionLseekdir: void (SMBCCTX *, smbc_lseekdir_fn) -+smbc_setFunctionMkdir: void (SMBCCTX *, smbc_mkdir_fn) -+smbc_setFunctionNotify: void (SMBCCTX *, smbc_notify_fn) -+smbc_setFunctionOpen: void (SMBCCTX *, smbc_open_fn) -+smbc_setFunctionOpenPrintJob: void (SMBCCTX *, smbc_open_print_job_fn) -+smbc_setFunctionOpendir: void (SMBCCTX *, smbc_opendir_fn) -+smbc_setFunctionPrintFile: void (SMBCCTX *, smbc_print_file_fn) -+smbc_setFunctionPurgeCachedServers: void (SMBCCTX *, smbc_purge_cached_fn) -+smbc_setFunctionRead: void (SMBCCTX *, smbc_read_fn) -+smbc_setFunctionReaddir: void (SMBCCTX *, smbc_readdir_fn) -+smbc_setFunctionReaddirPlus: void (SMBCCTX *, smbc_readdirplus_fn) -+smbc_setFunctionReaddirPlus2: void (SMBCCTX *, smbc_readdirplus2_fn) -+smbc_setFunctionRemoveCachedServer: void (SMBCCTX *, smbc_remove_cached_srv_fn) -+smbc_setFunctionRemoveUnusedServer: void (SMBCCTX *, smbc_remove_unused_server_fn) -+smbc_setFunctionRemovexattr: void (SMBCCTX *, smbc_removexattr_fn) -+smbc_setFunctionRename: void (SMBCCTX *, smbc_rename_fn) -+smbc_setFunctionRmdir: void (SMBCCTX *, smbc_rmdir_fn) -+smbc_setFunctionSetxattr: void (SMBCCTX *, smbc_setxattr_fn) -+smbc_setFunctionSplice: void (SMBCCTX *, smbc_splice_fn) -+smbc_setFunctionStat: void (SMBCCTX *, smbc_stat_fn) -+smbc_setFunctionStatVFS: void (SMBCCTX *, smbc_statvfs_fn) -+smbc_setFunctionTelldir: void (SMBCCTX *, smbc_telldir_fn) -+smbc_setFunctionUnlink: void (SMBCCTX *, smbc_unlink_fn) -+smbc_setFunctionUnlinkPrintJob: void (SMBCCTX *, smbc_unlink_print_job_fn) -+smbc_setFunctionUtimes: void (SMBCCTX *, smbc_utimes_fn) -+smbc_setFunctionWrite: void (SMBCCTX *, smbc_write_fn) -+smbc_setLogCallback: void (SMBCCTX *, void *, smbc_debug_callback_fn) -+smbc_setNetbiosName: void (SMBCCTX *, const char *) -+smbc_setOptionBrowseMaxLmbCount: void (SMBCCTX *, int) -+smbc_setOptionCaseSensitive: void (SMBCCTX *, smbc_bool) -+smbc_setOptionDebugToStderr: void (SMBCCTX *, smbc_bool) -+smbc_setOptionFallbackAfterKerberos: void (SMBCCTX *, smbc_bool) -+smbc_setOptionFullTimeNames: void (SMBCCTX *, smbc_bool) -+smbc_setOptionNoAutoAnonymousLogin: void (SMBCCTX *, smbc_bool) -+smbc_setOptionOneSharePerServer: void (SMBCCTX *, smbc_bool) -+smbc_setOptionOpenShareMode: void (SMBCCTX *, smbc_share_mode) -+smbc_setOptionProtocols: smbc_bool (SMBCCTX *, const char *, const char *) -+smbc_setOptionSmbEncryptionLevel: void (SMBCCTX *, smbc_smb_encrypt_level) -+smbc_setOptionUrlEncodeReaddirEntries: void (SMBCCTX *, smbc_bool) -+smbc_setOptionUseCCache: void (SMBCCTX *, smbc_bool) -+smbc_setOptionUseKerberos: void (SMBCCTX *, smbc_bool) -+smbc_setOptionUseNTHash: void (SMBCCTX *, smbc_bool) -+smbc_setOptionUserData: void (SMBCCTX *, void *) -+smbc_setPort: void (SMBCCTX *, uint16_t) -+smbc_setServerCacheData: void (SMBCCTX *, struct smbc_server_cache *) -+smbc_setTimeout: void (SMBCCTX *, int) -+smbc_setUser: void (SMBCCTX *, const char *) -+smbc_setWorkgroup: void (SMBCCTX *, const char *) -+smbc_set_context: SMBCCTX *(SMBCCTX *) -+smbc_set_credentials: void (const char *, const char *, const char *, smbc_bool, const char *) -+smbc_set_credentials_with_fallback: void (SMBCCTX *, const char *, const char *, const char *) -+smbc_setxattr: int (const char *, const char *, const void *, size_t, int) -+smbc_stat: int (const char *, struct stat *) -+smbc_statvfs: int (char *, struct statvfs *) -+smbc_telldir: off_t (int) -+smbc_unlink: int (const char *) -+smbc_unlink_print_job: int (const char *, int) -+smbc_urldecode: int (char *, char *, size_t) -+smbc_urlencode: int (char *, char *, int) -+smbc_utime: int (const char *, struct utimbuf *) -+smbc_utimes: int (const char *, struct timeval *) -+smbc_version: const char *(void) -+smbc_write: ssize_t (int, const void *, size_t) -diff --git a/source3/libsmb/libsmb_context.c b/source3/libsmb/libsmb_context.c -index eaa0cdeca93..ea741f41c7d 100644 ---- a/source3/libsmb/libsmb_context.c -+++ b/source3/libsmb/libsmb_context.c -@@ -171,7 +171,7 @@ smbc_new_context(void) - - smbc_setOptionFullTimeNames(context, False); - smbc_setOptionOpenShareMode(context, SMBC_SHAREMODE_DENY_NONE); -- smbc_setOptionSmbEncryptionLevel(context, SMBC_ENCRYPTLEVEL_NONE); -+ smbc_setOptionSmbEncryptionLevel(context, SMBC_ENCRYPTLEVEL_DEFAULT); - smbc_setOptionUseCCache(context, True); - smbc_setOptionCaseSensitive(context, False); - smbc_setOptionBrowseMaxLmbCount(context, 3); /* # LMBs to query */ -@@ -474,6 +474,8 @@ smbc_option_get(SMBCCTX *context, - } else if (strcmp(option_name, "smb_encrypt_level") == 0) { - switch(smbc_getOptionSmbEncryptionLevel(context)) - { -+ case SMBC_ENCRYPTLEVEL_DEFAULT: -+ return discard_const_p(void, "default"); - case 0: - return discard_const_p(void, "none"); - case 1: -diff --git a/source3/libsmb/libsmb_server.c b/source3/libsmb/libsmb_server.c -index 33dc8419deb..eb58d7c6ac9 100644 ---- a/source3/libsmb/libsmb_server.c -+++ b/source3/libsmb/libsmb_server.c -@@ -284,6 +284,29 @@ static struct cli_credentials *SMBC_auth_credentials(TALLOC_CTX *mem_ctx, - return NULL; - } - -+ switch (context->internal->smb_encryption_level) { -+ case SMBC_ENCRYPTLEVEL_DEFAULT: -+ /* Use the config option */ -+ break; -+ case SMBC_ENCRYPTLEVEL_NONE: -+ cli_credentials_set_smb_encryption(creds, -+ SMB_ENCRYPTION_OFF, -+ CRED_SPECIFIED); -+ break; -+ case SMBC_ENCRYPTLEVEL_REQUEST: -+ cli_credentials_set_smb_encryption(creds, -+ SMB_ENCRYPTION_DESIRED, -+ CRED_SPECIFIED); -+ break; -+ case SMBC_ENCRYPTLEVEL_REQUIRE: -+ default: -+ cli_credentials_set_smb_encryption(creds, -+ SMB_ENCRYPTION_REQUIRED, -+ CRED_SPECIFIED); -+ break; -+ } -+ -+ - return creds; - } - -@@ -625,30 +648,6 @@ SMBC_server_internal(TALLOC_CTX *ctx, - smbXcli_tcon_set_fs_attributes(tcon, fs_attrs); - } - -- if (context->internal->smb_encryption_level) { -- /* Attempt encryption. */ -- status = cli_cm_force_encryption_creds(c, -- creds, -- share); -- if (!NT_STATUS_IS_OK(status)) { -- -- /* -- * context->smb_encryption_level == 1 -- * means don't fail if encryption can't be negotiated, -- * == 2 means fail if encryption can't be negotiated. -- */ -- -- DEBUG(4,(" SMB encrypt failed\n")); -- -- if (context->internal->smb_encryption_level == 2) { -- cli_shutdown(c); -- errno = EPERM; -- return NULL; -- } -- } -- DEBUG(4,(" SMB encrypt ok\n")); -- } -- - /* - * Ok, we have got a nice connection - * Let's allocate a server structure. -@@ -825,31 +824,6 @@ SMBC_attr_server(TALLOC_CTX *ctx, - } - talloc_steal(ipc_cli, creds); - -- if (context->internal->smb_encryption_level) { -- /* Attempt encryption. */ -- nt_status = cli_cm_force_encryption_creds(ipc_cli, -- creds, -- "IPC$"); -- if (!NT_STATUS_IS_OK(nt_status)) { -- -- /* -- * context->smb_encryption_level == -- * 1 means don't fail if encryption can't be -- * negotiated, == 2 means fail if encryption -- * can't be negotiated. -- */ -- -- DEBUG(4,(" SMB encrypt failed on IPC$\n")); -- -- if (context->internal->smb_encryption_level == 2) { -- cli_shutdown(ipc_cli); -- errno = EPERM; -- return NULL; -- } -- } -- DEBUG(4,(" SMB encrypt ok on IPC$\n")); -- } -- - ipc_srv = SMB_MALLOC_P(SMBCSRV); - if (!ipc_srv) { - errno = ENOMEM; -diff --git a/source3/libsmb/wscript b/source3/libsmb/wscript -index ec4a516b2ee..61503d0a98b 100644 ---- a/source3/libsmb/wscript -+++ b/source3/libsmb/wscript -@@ -26,5 +26,5 @@ def build(bld): - public_headers='../include/libsmbclient.h', - abi_directory='ABI', - abi_match='smbc_*', -- vnum='0.6.0', -+ vnum='0.7.0', - pc_files='smbclient.pc') --- -2.33.1 - - -From c1a9a8948749d3ad29eb38de86780e488a7331cd Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Wed, 10 Jun 2020 12:43:33 +0200 -Subject: [PATCH 037/103] s3:client: Remove unused smb encryption code - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - source3/client/smbspool.c | 10 ---------- - 1 file changed, 10 deletions(-) - -diff --git a/source3/client/smbspool.c b/source3/client/smbspool.c -index f56dc323b6e..16a8d44c069 100644 ---- a/source3/client/smbspool.c -+++ b/source3/client/smbspool.c -@@ -584,16 +584,6 @@ smb_complete_connection(struct cli_state **output_cli, - - return nt_status; - } --#if 0 -- /* Need to work out how to specify this on the URL. */ -- if (smb_encrypt) { -- if (!cli_cm_force_encryption_creds(cli, creds, share)) { -- fprintf(stderr, "ERROR: encryption setup failed\n"); -- cli_shutdown(cli); -- return NULL; -- } -- } --#endif - - *output_cli = cli; - return NT_STATUS_OK; --- -2.33.1 - - -From f3b752d28681c6f072399fbc76d1f995b795e337 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Wed, 10 Jun 2020 12:47:05 +0200 -Subject: [PATCH 038/103] s3:utils: Remove obsolete force encryption from - smbacls - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - source3/utils/smbcacls.c | 10 ---------- - 1 file changed, 10 deletions(-) - -diff --git a/source3/utils/smbcacls.c b/source3/utils/smbcacls.c -index 5983ebbd0a5..8fd9fcc5780 100644 ---- a/source3/utils/smbcacls.c -+++ b/source3/utils/smbcacls.c -@@ -784,16 +784,6 @@ static struct cli_state *connect_one(const struct user_auth_info *auth_info, - return NULL; - } - -- if (get_cmdline_auth_info_smb_encrypt(auth_info)) { -- nt_status = cli_cm_force_encryption_creds(c, -- get_cmdline_auth_info_creds(auth_info), -- share); -- if (!NT_STATUS_IS_OK(nt_status)) { -- cli_shutdown(c); -- c = NULL; -- } -- } -- - return c; - } - --- -2.33.1 - - -From 43c3b77a0b94d2e183552879739fdf7d14fcf606 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Wed, 10 Jun 2020 12:48:18 +0200 -Subject: [PATCH 039/103] s3:utils: Remove obsolete force encryption from - mdfind - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - source3/utils/mdfind.c | 7 ------- - 1 file changed, 7 deletions(-) - -diff --git a/source3/utils/mdfind.c b/source3/utils/mdfind.c -index 2ac4fde7daf..ef2657e4fa5 100644 ---- a/source3/utils/mdfind.c -+++ b/source3/utils/mdfind.c -@@ -159,13 +159,6 @@ int main(int argc, char **argv) - goto fail; - } - -- if (get_cmdline_auth_info_smb_encrypt(auth)) { -- status = cli_cm_force_encryption_creds(cli, creds, "IPC$"); -- if (!NT_STATUS_IS_OK(status)) { -- goto fail; -- } -- } -- - status = cli_rpc_pipe_open_noauth_transport(cli, - NCACN_NP, - &ndr_table_mdssvc, --- -2.33.1 - - -From da64006bca958b76435c43bcd7f8d033571180cc Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Wed, 10 Jun 2020 12:49:28 +0200 -Subject: [PATCH 040/103] s3:utils: Remove obsolete force encryption from - smbcquotas - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - source3/utils/smbcquotas.c | 11 ----------- - 1 file changed, 11 deletions(-) - -diff --git a/source3/utils/smbcquotas.c b/source3/utils/smbcquotas.c -index fea066ce468..4ceac7b3ab0 100644 ---- a/source3/utils/smbcquotas.c -+++ b/source3/utils/smbcquotas.c -@@ -533,17 +533,6 @@ static struct cli_state *connect_one(const char *share) - return NULL; - } - -- if (get_cmdline_auth_info_smb_encrypt(popt_get_cmdline_auth_info())) { -- nt_status = cli_cm_force_encryption_creds(c, -- get_cmdline_auth_info_creds( -- popt_get_cmdline_auth_info()), -- share); -- if (!NT_STATUS_IS_OK(nt_status)) { -- cli_shutdown(c); -- return NULL; -- } -- } -- - return c; - } - --- -2.33.1 - - -From a8c8f4e8476ad81b4d0f6d9536e52e412ee6a844 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Wed, 10 Jun 2020 12:51:18 +0200 -Subject: [PATCH 041/103] s3:rpcclient: Remove obsolete force encryption from - rpcclient - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - source3/rpcclient/rpcclient.c | 11 ----------- - 1 file changed, 11 deletions(-) - -diff --git a/source3/rpcclient/rpcclient.c b/source3/rpcclient/rpcclient.c -index 2ead6cc7ba5..575a42ebf70 100644 ---- a/source3/rpcclient/rpcclient.c -+++ b/source3/rpcclient/rpcclient.c -@@ -1214,17 +1214,6 @@ out_free: - goto done; - } - -- if (get_cmdline_auth_info_smb_encrypt(popt_get_cmdline_auth_info())) { -- nt_status = cli_cm_force_encryption_creds(cli, -- get_cmdline_auth_info_creds( -- popt_get_cmdline_auth_info()), -- "IPC$"); -- if (!NT_STATUS_IS_OK(nt_status)) { -- result = 1; -- goto done; -- } -- } -- - #if 0 /* COMMENT OUT FOR TESTING */ - memset(cmdline_auth_info.password,'X',sizeof(cmdline_auth_info.password)); - #endif --- -2.33.1 - - -From e06ad4469e48400c24ab4238f0e91ab528aaff7c Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Mon, 6 Jul 2020 10:58:36 +0200 -Subject: [PATCH 042/103] examples: Remove obsolete force encryption from - smb2mount - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - examples/fuse/smb2mount.c | 11 ----------- - 1 file changed, 11 deletions(-) - -diff --git a/examples/fuse/smb2mount.c b/examples/fuse/smb2mount.c -index 6206c3a9701..c64be573462 100644 ---- a/examples/fuse/smb2mount.c -+++ b/examples/fuse/smb2mount.c -@@ -44,17 +44,6 @@ static struct cli_state *connect_one(const struct user_auth_info *auth_info, - return NULL; - } - -- if (get_cmdline_auth_info_smb_encrypt(auth_info)) { -- nt_status = cli_cm_force_encryption_creds( -- c, -- get_cmdline_auth_info_creds(auth_info), -- share); -- if (!NT_STATUS_IS_OK(nt_status)) { -- cli_shutdown(c); -- c = NULL; -- } -- } -- - return c; - } - --- -2.33.1 - - -From 1f7fa4dce808e604ac108c31ef7fd1aca2ef6ff7 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Mon, 6 Jul 2020 11:05:59 +0200 -Subject: [PATCH 043/103] s3:libsmb: Make cli_cm_force_encryption_creds() - static - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - source3/libsmb/clidfs.c | 6 +++--- - source3/libsmb/proto.h | 3 --- - 2 files changed, 3 insertions(+), 6 deletions(-) - -diff --git a/source3/libsmb/clidfs.c b/source3/libsmb/clidfs.c -index 2a2509870e3..93b2525b204 100644 ---- a/source3/libsmb/clidfs.c -+++ b/source3/libsmb/clidfs.c -@@ -43,9 +43,9 @@ - Ensure a connection is encrypted. - ********************************************************************/ - --NTSTATUS cli_cm_force_encryption_creds(struct cli_state *c, -- struct cli_credentials *creds, -- const char *sharename) -+static NTSTATUS cli_cm_force_encryption_creds(struct cli_state *c, -+ struct cli_credentials *creds, -+ const char *sharename) - { - uint16_t major, minor; - uint32_t caplow, caphigh; -diff --git a/source3/libsmb/proto.h b/source3/libsmb/proto.h -index 850cf12c8a6..eeabcaa7463 100644 ---- a/source3/libsmb/proto.h -+++ b/source3/libsmb/proto.h -@@ -123,9 +123,6 @@ struct cli_state *get_ipc_connect_master_ip(TALLOC_CTX *ctx, - - /* The following definitions come from libsmb/clidfs.c */ - --NTSTATUS cli_cm_force_encryption_creds(struct cli_state *c, -- struct cli_credentials *creds, -- const char *sharename); - NTSTATUS cli_cm_open(TALLOC_CTX *ctx, - struct cli_state *referring_cli, - const char *server, --- -2.33.1 - - -From 77a43ba0dcadc63fba33816c9739158db0107b17 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 13 Aug 2020 16:16:55 +0200 -Subject: [PATCH 044/103] s4:libcli: Return NTSTATUS errors for - smb_composite_connect_send() - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - source4/libcli/smb_composite/connect.c | 40 +++++++++++++++++++------- - 1 file changed, 29 insertions(+), 11 deletions(-) - -diff --git a/source4/libcli/smb_composite/connect.c b/source4/libcli/smb_composite/connect.c -index 582d43ef173..ad50ae0ac81 100644 ---- a/source4/libcli/smb_composite/connect.c -+++ b/source4/libcli/smb_composite/connect.c -@@ -420,15 +420,25 @@ struct composite_context *smb_composite_connect_send(struct smb_composite_connec - struct connect_state *state; - - c = talloc_zero(mem_ctx, struct composite_context); -- if (c == NULL) goto failed; -- -- c->event_ctx = event_ctx; -- if (c->event_ctx == NULL) goto failed; -+ if (c == NULL) { -+ goto nomem; -+ } - - state = talloc_zero(c, struct connect_state); -- if (state == NULL) goto failed; -+ if (state == NULL) { -+ goto nomem; -+ } -+ -+ c->event_ctx = event_ctx; -+ if (c->event_ctx == NULL) { -+ composite_error(c, NT_STATUS_INVALID_PARAMETER_MIX); -+ return c; -+ } - -- if (io->in.gensec_settings == NULL) goto failed; -+ if (io->in.gensec_settings == NULL) { -+ composite_error(c, NT_STATUS_INVALID_PARAMETER_MIX); -+ return c; -+ } - state->io = io; - - c->state = COMPOSITE_STATE_IN_PROGRESS; -@@ -449,12 +459,14 @@ struct composite_context *smb_composite_connect_send(struct smb_composite_connec - &io->in.options, - &state->transport); - if (!NT_STATUS_IS_OK(status)) { -- goto failed; -+ composite_error(c, status); -+ return c; - } - - status = connect_send_session(c, io); - if (!NT_STATUS_IS_OK(status)) { -- goto failed; -+ composite_error(c, status); -+ return c; - } - - return c; -@@ -468,15 +480,18 @@ struct composite_context *smb_composite_connect_send(struct smb_composite_connec - io->in.socket_options, - &state->calling, - &state->called); -- if (state->creq == NULL) goto failed; -+ if (state->creq == NULL) { -+ composite_error(c, NT_STATUS_NO_MEMORY); -+ return c; -+ } - - state->stage = CONNECT_SOCKET; - state->creq->async.private_data = c; - state->creq->async.fn = composite_handler; - - return c; --failed: -- talloc_free(c); -+nomem: -+ TALLOC_FREE(c); - return NULL; - } - -@@ -506,5 +521,8 @@ NTSTATUS smb_composite_connect(struct smb_composite_connect *io, TALLOC_CTX *mem - struct tevent_context *ev) - { - struct composite_context *c = smb_composite_connect_send(io, mem_ctx, resolve_ctx, ev); -+ if (c == NULL) { -+ return NT_STATUS_NO_MEMORY; -+ } - return smb_composite_connect_recv(c, mem_ctx); - } --- -2.33.1 - - -From 27229818ac811f9abd5cc4c01617822f0fc17f83 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Tue, 7 Jul 2020 12:54:26 +0200 -Subject: [PATCH 045/103] s4:libcli: Return if encryption is requested for SMB1 - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - source4/libcli/smb_composite/sesssetup.c | 7 +++++++ - 1 file changed, 7 insertions(+) - -diff --git a/source4/libcli/smb_composite/sesssetup.c b/source4/libcli/smb_composite/sesssetup.c -index a0a1f4baa56..93f6ce55177 100644 ---- a/source4/libcli/smb_composite/sesssetup.c -+++ b/source4/libcli/smb_composite/sesssetup.c -@@ -622,10 +622,17 @@ struct composite_context *smb_composite_sesssetup_send(struct smbcli_session *se - NTSTATUS status; - enum credentials_use_kerberos krb5_state = - cli_credentials_get_kerberos_state(io->in.credentials); -+ enum smb_encryption_setting encryption_state = -+ cli_credentials_get_smb_encryption(io->in.credentials); - - c = composite_create(session, session->transport->ev); - if (c == NULL) return NULL; - -+ if (encryption_state > SMB_ENCRYPTION_DESIRED) { -+ composite_error(c, NT_STATUS_PROTOCOL_NOT_SUPPORTED); -+ return c; -+ } -+ - state = talloc_zero(c, struct sesssetup_state); - if (composite_nomem(state, c)) return c; - c->private_data = state; --- -2.33.1 - - -From b1d3cf8457ed85198b184869ceedf6ff987c6cfd Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Tue, 7 Jul 2020 12:29:39 +0200 -Subject: [PATCH 046/103] s3:libcli: Split out smb2_connect_tcon_start() - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - source4/libcli/smb2/connect.c | 13 ++++++++++++- - 1 file changed, 12 insertions(+), 1 deletion(-) - -diff --git a/source4/libcli/smb2/connect.c b/source4/libcli/smb2/connect.c -index 6fc3993a4e8..95ff05eac8f 100644 ---- a/source4/libcli/smb2/connect.c -+++ b/source4/libcli/smb2/connect.c -@@ -237,6 +237,7 @@ static void smb2_connect_session_start(struct tevent_req *req) - tevent_req_set_callback(subreq, smb2_connect_session_done, req); - } - -+static void smb2_connect_tcon_start(struct tevent_req *req); - static void smb2_connect_tcon_done(struct tevent_req *subreq); - - static void smb2_connect_session_done(struct tevent_req *subreq) -@@ -248,7 +249,6 @@ static void smb2_connect_session_done(struct tevent_req *subreq) - tevent_req_data(req, - struct smb2_connect_state); - NTSTATUS status; -- uint32_t timeout_msec; - - status = smb2_session_setup_spnego_recv(subreq); - TALLOC_FREE(subreq); -@@ -289,6 +289,17 @@ static void smb2_connect_session_done(struct tevent_req *subreq) - return; - } - -+ smb2_connect_tcon_start(req); -+} -+ -+static void smb2_connect_tcon_start(struct tevent_req *req) -+{ -+ struct smb2_connect_state *state = -+ tevent_req_data(req, -+ struct smb2_connect_state); -+ struct tevent_req *subreq = NULL; -+ uint32_t timeout_msec; -+ - timeout_msec = state->transport->options.request_timeout * 1000; - - subreq = smb2cli_tcon_send(state, state->ev, --- -2.33.1 - - -From 27484fd0b100a41ca8b187530c1174389034aa34 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Tue, 7 Jul 2020 12:44:26 +0200 -Subject: [PATCH 047/103] s4:libcli: Add smb2_connect_enc_start() - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - source4/libcli/smb2/connect.c | 38 +++++++++++++++++++++++++++++++++++ - 1 file changed, 38 insertions(+) - -diff --git a/source4/libcli/smb2/connect.c b/source4/libcli/smb2/connect.c -index 95ff05eac8f..3a3ecdf20e8 100644 ---- a/source4/libcli/smb2/connect.c -+++ b/source4/libcli/smb2/connect.c -@@ -237,6 +237,7 @@ static void smb2_connect_session_start(struct tevent_req *req) - tevent_req_set_callback(subreq, smb2_connect_session_done, req); - } - -+static void smb2_connect_enc_start(struct tevent_req *req); - static void smb2_connect_tcon_start(struct tevent_req *req); - static void smb2_connect_tcon_done(struct tevent_req *subreq); - -@@ -289,6 +290,43 @@ static void smb2_connect_session_done(struct tevent_req *subreq) - return; - } - -+ smb2_connect_enc_start(req); -+} -+ -+static void smb2_connect_enc_start(struct tevent_req *req) -+{ -+ struct smb2_connect_state *state = -+ tevent_req_data(req, -+ struct smb2_connect_state); -+ enum smb_encryption_setting encryption_state = -+ cli_credentials_get_smb_encryption(state->credentials); -+ NTSTATUS status; -+ -+ if (encryption_state < SMB_ENCRYPTION_DESIRED) { -+ smb2_connect_tcon_start(req); -+ return; -+ } -+ -+ status = smb2cli_session_encryption_on(state->session->smbXcli); -+ if (!NT_STATUS_IS_OK(status)) { -+ if (NT_STATUS_EQUAL(status, NT_STATUS_NOT_SUPPORTED)) { -+ if (encryption_state < SMB_ENCRYPTION_REQUIRED) { -+ smb2_connect_tcon_start(req); -+ return; -+ } -+ -+ DBG_ERR("Encryption required and server doesn't support " -+ "SMB3 encryption - failing connect\n"); -+ tevent_req_nterror(req, status); -+ return; -+ } -+ -+ DBG_ERR("Encryption required and setup failed with error %s.\n", -+ nt_errstr(status)); -+ tevent_req_nterror(req, NT_STATUS_PROTOCOL_NOT_SUPPORTED); -+ return; -+ } -+ - smb2_connect_tcon_start(req); - } - --- -2.33.1 - - -From a595827453d33b136af7d3955c7f4009e879e986 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Fri, 24 Jul 2020 10:18:52 +0200 -Subject: [PATCH 048/103] s4:libcli: Require signing for SMB encryption - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher ---- - source4/libcli/smb2/connect.c | 9 ++++++++- - 1 file changed, 8 insertions(+), 1 deletion(-) - -diff --git a/source4/libcli/smb2/connect.c b/source4/libcli/smb2/connect.c -index 3a3ecdf20e8..9540704491e 100644 ---- a/source4/libcli/smb2/connect.c -+++ b/source4/libcli/smb2/connect.c -@@ -31,6 +31,7 @@ - #include "param/param.h" - #include "auth/credentials/credentials.h" - #include "../libcli/smb/smbXcli_base.h" -+#include "smb2_constants.h" - - struct smb2_connect_state { - struct tevent_context *ev; -@@ -76,6 +77,8 @@ struct tevent_req *smb2_connect_send(TALLOC_CTX *mem_ctx, - struct smb2_connect_state *state; - struct composite_context *creq; - static const char *default_ports[] = { "445", "139", NULL }; -+ enum smb_encryption_setting encryption_state = -+ cli_credentials_get_smb_encryption(credentials); - - req = tevent_req_create(mem_ctx, &state, - struct smb2_connect_state); -@@ -99,6 +102,10 @@ struct tevent_req *smb2_connect_send(TALLOC_CTX *mem_ctx, - state->ports = default_ports; - } - -+ if (encryption_state >= SMB_ENCRYPTION_DESIRED) { -+ state->options.signing = SMB_SIGNING_REQUIRED; -+ } -+ - make_nbt_name_client(&state->calling, - cli_credentials_get_workstation(credentials)); - -@@ -116,7 +123,7 @@ struct tevent_req *smb2_connect_send(TALLOC_CTX *mem_ctx, - - status = smb2_transport_raw_init(state, ev, - existing_conn, -- options, -+ &state->options, - &state->transport); - if (tevent_req_nterror(req, status)) { - return tevent_req_post(req, ev); --- -2.33.1 - - -From fdab74deed1afb45152f3b1b73fbda0f92de1f1f Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Tue, 7 Jul 2020 14:27:07 +0200 -Subject: [PATCH 049/103] python:tests: Add test for SMB encrypted DCERPC - connection - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher - -Autobuild-User(master): Andreas Schneider -Autobuild-Date(master): Wed Aug 19 17:46:28 UTC 2020 on sn-devel-184 ---- - python/samba/tests/dcerpc/binding.py | 82 ++++++++++++++++++++++++++++ - selftest/tests.py | 1 + - 2 files changed, 83 insertions(+) - create mode 100644 python/samba/tests/dcerpc/binding.py - -diff --git a/python/samba/tests/dcerpc/binding.py b/python/samba/tests/dcerpc/binding.py -new file mode 100644 -index 00000000000..8e0d6a5ef0a ---- /dev/null -+++ b/python/samba/tests/dcerpc/binding.py -@@ -0,0 +1,82 @@ -+# -+# Unix SMB/CIFS implementation. -+# Copyright (c) 2020 Andreas Schneider -+# -+# This program is free software; you can redistribute it and/or modify -+# it under the terms of the GNU General Public License as published by -+# the Free Software Foundation; either version 3 of the License, or -+# (at your option) any later version. -+# -+# This program is distributed in the hope that it will be useful, -+# but WITHOUT ANY WARRANTY; without even the implied warranty of -+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the -+# GNU General Public License for more details. -+# -+# You should have received a copy of the GNU General Public License -+# along with this program. If not, see . -+# -+ -+"""Tests for samba.dcerpc., credentials and binding strings""" -+ -+import samba.tests -+from samba.tests import RpcInterfaceTestCase, TestCase -+from samba.dcerpc import lsa -+import samba.dcerpc.security as security -+from samba.credentials import Credentials, SMB_ENCRYPTION_REQUIRED -+from samba import NTSTATUSError -+ -+class RpcBindingTests(RpcInterfaceTestCase): -+ def setUp(self): -+ super(RpcBindingTests, self).setUp() -+ -+ def get_user_creds(self): -+ c = Credentials() -+ c.guess() -+ domain = samba.tests.env_get_var_value('DOMAIN') -+ username = samba.tests.env_get_var_value('USERNAME') -+ password = samba.tests.env_get_var_value('PASSWORD') -+ c.set_domain(domain) -+ c.set_username(username) -+ c.set_password(password) -+ return c -+ -+ def test_smb3_dcerpc_encryption(self): -+ creds = self.get_user_creds() -+ creds.set_smb_encryption(SMB_ENCRYPTION_REQUIRED) -+ -+ lp = self.get_loadparm() -+ lp.set('client ipc max protocol', 'SMB3') -+ lp.set('client ipc min protocol', 'SMB3') -+ -+ binding_string = ("ncacn_np:%s" % (samba.tests.env_get_var_value('SERVER'))) -+ lsa_conn = lsa.lsarpc(binding_string, lp, creds) -+ -+ objectAttr = lsa.ObjectAttribute() -+ objectAttr.sec_qos = lsa.QosInfo() -+ -+ pol_handle = lsa_conn.OpenPolicy2('', -+ objectAttr, -+ security.SEC_FLAG_MAXIMUM_ALLOWED) -+ self.assertIsNotNone(pol_handle) -+ -+ def test_smb2_dcerpc_encryption(self): -+ creds = self.get_user_creds() -+ creds.set_smb_encryption(SMB_ENCRYPTION_REQUIRED) -+ -+ lp = self.get_loadparm() -+ lp.set('client ipc max protocol', 'SMB2') -+ lp.set('client ipc min protocol', 'SMB2') -+ -+ binding_string = ("ncacn_np:%s" % (samba.tests.env_get_var_value('SERVER'))) -+ self.assertRaises(NTSTATUSError, lsa.lsarpc, binding_string, lp, creds) -+ -+ def test_smb1_dcerpc_encryption(self): -+ creds = self.get_user_creds() -+ creds.set_smb_encryption(SMB_ENCRYPTION_REQUIRED) -+ -+ lp = self.get_loadparm() -+ lp.set('client ipc max protocol', 'NT1') -+ lp.set('client ipc min protocol', 'NT1') -+ -+ binding_string = ("ncacn_np:%s" % (samba.tests.env_get_var_value('SERVER'))) -+ self.assertRaises(NTSTATUSError, lsa.lsarpc, binding_string, lp, creds) -diff --git a/selftest/tests.py b/selftest/tests.py -index 68cbcd5fbf1..f3fcdca4ab3 100644 ---- a/selftest/tests.py -+++ b/selftest/tests.py -@@ -93,6 +93,7 @@ planpythontestsuite( - extra_path=[os.path.join(samba4srcdir, "..", "buildtools"), - os.path.join(samba4srcdir, "..", "third_party", "waf")]) - planpythontestsuite("fileserver", "samba.tests.smbd_fuzztest") -+planpythontestsuite("nt4_dc_smb1", "samba.tests.dcerpc.binding") - - - def cmdline(script, *args): --- -2.33.1 - - -From 3442d029d320975c792b5a2876999c9852e4842c Mon Sep 17 00:00:00 2001 -From: Stefan Metzmacher -Date: Fri, 4 Sep 2020 10:47:54 +0200 -Subject: [PATCH 050/103] auth:gensec: Add gensec_security_sasl_names() - -Pair-Programmed-With: Andreas Schneider - -Signed-off-by: Andreas Schneider -Signed-off-by: Stefan Metzmacher -(cherry picked from commit b34e8dc8982b625d946e2ac8794ee41311bc41c2) ---- - auth/gensec/gensec.h | 2 + - auth/gensec/gensec_start.c | 87 ++++++++++++++++++++++++++++++++++++++ - 2 files changed, 89 insertions(+) - -diff --git a/auth/gensec/gensec.h b/auth/gensec/gensec.h -index d424067d02c..fe26fff171a 100644 ---- a/auth/gensec/gensec.h -+++ b/auth/gensec/gensec.h -@@ -308,6 +308,8 @@ const struct gensec_security_ops **gensec_use_kerberos_mechs(TALLOC_CTX *mem_ctx - - NTSTATUS gensec_start_mech_by_sasl_name(struct gensec_security *gensec_security, - const char *sasl_name); -+const char **gensec_security_sasl_names(struct gensec_security *gensec_security, -+ TALLOC_CTX *mem_ctx); - - int gensec_setting_int(struct gensec_settings *settings, const char *mechanism, const char *name, int default_value); - bool gensec_setting_bool(struct gensec_settings *settings, const char *mechanism, const char *name, bool default_value); -diff --git a/auth/gensec/gensec_start.c b/auth/gensec/gensec_start.c -index d2d62d6652e..4eb45643714 100644 ---- a/auth/gensec/gensec_start.c -+++ b/auth/gensec/gensec_start.c -@@ -299,6 +299,93 @@ const struct gensec_security_ops *gensec_security_by_name(struct gensec_security - return NULL; - } - -+static const char **gensec_security_sasl_names_from_ops( -+ struct gensec_security *gensec_security, -+ TALLOC_CTX *mem_ctx, -+ const struct gensec_security_ops * const *ops) -+{ -+ const char **sasl_names = NULL; -+ size_t i, sasl_names_count = 0; -+ -+ if (ops == NULL) { -+ return NULL; -+ } -+ -+ sasl_names = talloc_array(mem_ctx, const char *, 1); -+ if (sasl_names == NULL) { -+ return NULL; -+ } -+ -+ for (i = 0; ops[i] != NULL; i++) { -+ enum gensec_role role = GENSEC_SERVER; -+ const char **tmp = NULL; -+ -+ if (ops[i]->sasl_name == NULL) { -+ continue; -+ } -+ -+ if (gensec_security != NULL) { -+ if (!gensec_security_ops_enabled(ops[i], -+ gensec_security)) { -+ continue; -+ } -+ -+ role = gensec_security->gensec_role; -+ } -+ -+ switch (role) { -+ case GENSEC_CLIENT: -+ if (ops[i]->client_start == NULL) { -+ continue; -+ } -+ break; -+ case GENSEC_SERVER: -+ if (ops[i]->server_start == NULL) { -+ continue; -+ } -+ break; -+ } -+ -+ tmp = talloc_realloc(mem_ctx, -+ sasl_names, -+ const char *, -+ sasl_names_count + 2); -+ if (tmp == NULL) { -+ TALLOC_FREE(sasl_names); -+ return NULL; -+ } -+ sasl_names = tmp; -+ -+ sasl_names[sasl_names_count] = ops[i]->sasl_name; -+ sasl_names_count++; -+ } -+ sasl_names[sasl_names_count] = NULL; -+ -+ return sasl_names; -+} -+ -+/** -+ * @brief Get the sasl names from the gensec security context. -+ * -+ * @param[in] gensec_security The gensec security context. -+ * -+ * @param[in] mem_ctx The memory context to allocate memory on. -+ * -+ * @return An allocated array with sasl names, NULL on error. -+ */ -+_PUBLIC_ -+const char **gensec_security_sasl_names(struct gensec_security *gensec_security, -+ TALLOC_CTX *mem_ctx) -+{ -+ const struct gensec_security_ops **ops = NULL; -+ -+ ops = gensec_security_mechs(gensec_security, mem_ctx); -+ -+ return gensec_security_sasl_names_from_ops(gensec_security, -+ mem_ctx, -+ ops); -+} -+ - /** - * Return a unique list of security subsystems from those specified in - * the list of SASL names. --- -2.33.1 - - -From 51a7d8be1d4374394216ca12cb65f17bffaa27e6 Mon Sep 17 00:00:00 2001 -From: Stefan Metzmacher -Date: Fri, 4 Sep 2020 10:48:27 +0200 -Subject: [PATCH 051/103] s4:ldap_server: Use samba_server_gensec_start() in - ldapsrv_backend_Init() - -Signed-off-by: Stefan Metzmacher -Reviewed-by: Andreas Schneider -(cherry picked from commit 5e3363e0b82193700f91a9bae5080aae0b744e5c) ---- - source4/dsdb/samdb/ldb_modules/rootdse.c | 4 +- - source4/ldap_server/ldap_backend.c | 49 +++++++++++------------- - 2 files changed, 25 insertions(+), 28 deletions(-) - -diff --git a/source4/dsdb/samdb/ldb_modules/rootdse.c b/source4/dsdb/samdb/ldb_modules/rootdse.c -index 55340fa4f1e..4be9550747c 100644 ---- a/source4/dsdb/samdb/ldb_modules/rootdse.c -+++ b/source4/dsdb/samdb/ldb_modules/rootdse.c -@@ -230,7 +230,7 @@ static int rootdse_add_dynamic(struct rootdse_context *ac, struct ldb_message *m - struct ldb_context *ldb; - struct rootdse_private_data *priv = talloc_get_type(ldb_module_get_private(ac->module), struct rootdse_private_data); - const char * const *attrs = ac->req->op.search.attrs; -- char **server_sasl; -+ const char **server_sasl = NULL; - const struct dsdb_schema *schema; - int *val; - struct ldb_control *edn_control; -@@ -341,7 +341,7 @@ static int rootdse_add_dynamic(struct rootdse_context *ac, struct ldb_message *m - } - - server_sasl = talloc_get_type(ldb_get_opaque(ldb, "supportedSASLMechanisms"), -- char *); -+ const char *); - if (server_sasl && do_attribute(attrs, "supportedSASLMechanisms")) { - for (i = 0; server_sasl && server_sasl[i]; i++) { - char *sasl_name = talloc_strdup(msg, server_sasl[i]); -diff --git a/source4/ldap_server/ldap_backend.c b/source4/ldap_server/ldap_backend.c -index 2839082daef..915d9b94f9b 100644 ---- a/source4/ldap_server/ldap_backend.c -+++ b/source4/ldap_server/ldap_backend.c -@@ -33,6 +33,7 @@ - #include "ldb_wrap.h" - #include "lib/tsocket/tsocket.h" - #include "libcli/ldap/ldap_proto.h" -+#include "source4/auth/auth.h" - - static int map_ldb_error(TALLOC_CTX *mem_ctx, int ldb_err, - const char *add_err_string, const char **errstring) -@@ -199,37 +200,33 @@ int ldapsrv_backend_Init(struct ldapsrv_connection *conn, - } - - if (conn->server_credentials) { -- char **sasl_mechs = NULL; -- const struct gensec_security_ops * const *backends = gensec_security_all(); -- const struct gensec_security_ops **ops -- = gensec_use_kerberos_mechs(conn, backends, conn->server_credentials); -- unsigned int i, j = 0; -- for (i = 0; ops && ops[i]; i++) { -- if (!lpcfg_parm_bool(conn->lp_ctx, NULL, "gensec", ops[i]->name, ops[i]->enabled)) -- continue; -- -- if (ops[i]->sasl_name && ops[i]->server_start) { -- char *sasl_name = talloc_strdup(conn, ops[i]->sasl_name); -- -- if (!sasl_name) { -- return LDB_ERR_OPERATIONS_ERROR; -- } -- sasl_mechs = talloc_realloc(conn, sasl_mechs, char *, j + 2); -- if (!sasl_mechs) { -- return LDB_ERR_OPERATIONS_ERROR; -- } -- sasl_mechs[j] = sasl_name; -- talloc_steal(sasl_mechs, sasl_name); -- sasl_mechs[j+1] = NULL; -- j++; -- } -+ struct gensec_security *gensec_security = NULL; -+ const char **sasl_mechs = NULL; -+ NTSTATUS status; -+ -+ status = samba_server_gensec_start(conn, -+ conn->connection->event.ctx, -+ conn->connection->msg_ctx, -+ conn->lp_ctx, -+ conn->server_credentials, -+ "ldap", -+ &gensec_security); -+ if (!NT_STATUS_IS_OK(status)) { -+ DBG_ERR("samba_server_gensec_start failed: %s\n", -+ nt_errstr(status)); -+ return LDB_ERR_OPERATIONS_ERROR; - } -- talloc_unlink(conn, ops); - - /* ldb can have a different lifetime to conn, so we - need to ensure that sasl_mechs lives as long as the - ldb does */ -- talloc_steal(conn->ldb, sasl_mechs); -+ sasl_mechs = gensec_security_sasl_names(gensec_security, -+ conn->ldb); -+ TALLOC_FREE(gensec_security); -+ if (sasl_mechs == NULL) { -+ DBG_ERR("Failed to get sasl mechs!\n"); -+ return LDB_ERR_OPERATIONS_ERROR; -+ } - - ldb_set_opaque(conn->ldb, "supportedSASLMechanisms", sasl_mechs); - } --- -2.33.1 - - -From 1f2dca557a1295077f411ba1af522583d094f819 Mon Sep 17 00:00:00 2001 -From: Stefan Metzmacher -Date: Fri, 4 Sep 2020 14:39:15 +0200 -Subject: [PATCH 052/103] auth:gensec: Make gensec_use_kerberos_mechs() a - static function - -Signed-off-by: Stefan Metzmacher -Reviewed-by: Andreas Schneider -(cherry picked from commit 2186d4131ad4c7961d0c830bf9d48f3d06d27924) ---- - auth/gensec/gensec.h | 3 --- - auth/gensec/gensec_start.c | 7 ++++--- - 2 files changed, 4 insertions(+), 6 deletions(-) - -diff --git a/auth/gensec/gensec.h b/auth/gensec/gensec.h -index fe26fff171a..8bece3c3458 100644 ---- a/auth/gensec/gensec.h -+++ b/auth/gensec/gensec.h -@@ -302,9 +302,6 @@ NTSTATUS gensec_wrap(struct gensec_security *gensec_security, - - const struct gensec_security_ops * const *gensec_security_all(void); - bool gensec_security_ops_enabled(const struct gensec_security_ops *ops, struct gensec_security *security); --const struct gensec_security_ops **gensec_use_kerberos_mechs(TALLOC_CTX *mem_ctx, -- const struct gensec_security_ops * const *old_gensec_list, -- struct cli_credentials *creds); - - NTSTATUS gensec_start_mech_by_sasl_name(struct gensec_security *gensec_security, - const char *sasl_name); -diff --git a/auth/gensec/gensec_start.c b/auth/gensec/gensec_start.c -index 4eb45643714..ebcab76999a 100644 ---- a/auth/gensec/gensec_start.c -+++ b/auth/gensec/gensec_start.c -@@ -83,9 +83,10 @@ bool gensec_security_ops_enabled(const struct gensec_security_ops *ops, struct g - * more compplex. - */ - --_PUBLIC_ const struct gensec_security_ops **gensec_use_kerberos_mechs(TALLOC_CTX *mem_ctx, -- const struct gensec_security_ops * const *old_gensec_list, -- struct cli_credentials *creds) -+static const struct gensec_security_ops **gensec_use_kerberos_mechs( -+ TALLOC_CTX *mem_ctx, -+ const struct gensec_security_ops * const *old_gensec_list, -+ struct cli_credentials *creds) - { - const struct gensec_security_ops **new_gensec_list; - int i, j, num_mechs_in; --- -2.33.1 - - -From f32eacf0d4903a4e46da2506b47718eed0265980 Mon Sep 17 00:00:00 2001 -From: Stefan Metzmacher -Date: Fri, 4 Sep 2020 14:41:43 +0200 -Subject: [PATCH 053/103] auth:gensec: Pass use_kerberos and keep_schannel to - gensec_use_kerberos_mechs() - -Signed-off-by: Stefan Metzmacher -Reviewed-by: Andreas Schneider -(cherry picked from commit a33a40bbc848e5691869cf264009d23a03128f31) ---- - auth/gensec/gensec_start.c | 26 ++++++++++++++------------ - 1 file changed, 14 insertions(+), 12 deletions(-) - -diff --git a/auth/gensec/gensec_start.c b/auth/gensec/gensec_start.c -index ebcab76999a..8d1b41fec74 100644 ---- a/auth/gensec/gensec_start.c -+++ b/auth/gensec/gensec_start.c -@@ -86,19 +86,11 @@ bool gensec_security_ops_enabled(const struct gensec_security_ops *ops, struct g - static const struct gensec_security_ops **gensec_use_kerberos_mechs( - TALLOC_CTX *mem_ctx, - const struct gensec_security_ops * const *old_gensec_list, -- struct cli_credentials *creds) -+ enum credentials_use_kerberos use_kerberos, -+ bool keep_schannel) - { - const struct gensec_security_ops **new_gensec_list; - int i, j, num_mechs_in; -- enum credentials_use_kerberos use_kerberos = CRED_AUTO_USE_KERBEROS; -- bool keep_schannel = false; -- -- if (creds) { -- use_kerberos = cli_credentials_get_kerberos_state(creds); -- if (cli_credentials_get_netlogon_creds(creds) != NULL) { -- keep_schannel = true; -- } -- } - - for (num_mechs_in=0; old_gensec_list && old_gensec_list[num_mechs_in]; num_mechs_in++) { - /* noop */ -@@ -163,18 +155,28 @@ _PUBLIC_ const struct gensec_security_ops **gensec_security_mechs( - struct gensec_security *gensec_security, - TALLOC_CTX *mem_ctx) - { -- struct cli_credentials *creds = NULL; - const struct gensec_security_ops * const *backends = gensec_security_all(); -+ enum credentials_use_kerberos use_kerberos = CRED_AUTO_USE_KERBEROS; -+ bool keep_schannel = false; - - if (gensec_security != NULL) { -+ struct cli_credentials *creds = NULL; -+ - creds = gensec_get_credentials(gensec_security); -+ if (creds != NULL) { -+ use_kerberos = cli_credentials_get_kerberos_state(creds); -+ if (cli_credentials_get_netlogon_creds(creds) != NULL) { -+ keep_schannel = true; -+ } -+ } - - if (gensec_security->settings->backends) { - backends = gensec_security->settings->backends; - } - } - -- return gensec_use_kerberos_mechs(mem_ctx, backends, creds); -+ return gensec_use_kerberos_mechs(mem_ctx, backends, -+ use_kerberos, keep_schannel); - - } - --- -2.33.1 - - -From 5f95f53d05dc9d43676c397e244ab7632ef1bbcb Mon Sep 17 00:00:00 2001 -From: Stefan Metzmacher -Date: Fri, 4 Sep 2020 17:00:45 +0200 -Subject: [PATCH 054/103] auth:gensec: If Kerberos is required, keep schannel - for machine account auth - -Signed-off-by: Stefan Metzmacher -Signed-off-by: Andreas Schneider -(cherry picked from commit 515cffb1f20eacb041ff7b3d43f8a122a82ddfbd) ---- - auth/gensec/gensec_start.c | 9 +++++++++ - 1 file changed, 9 insertions(+) - -diff --git a/auth/gensec/gensec_start.c b/auth/gensec/gensec_start.c -index 8d1b41fec74..3f42d611140 100644 ---- a/auth/gensec/gensec_start.c -+++ b/auth/gensec/gensec_start.c -@@ -168,6 +168,15 @@ _PUBLIC_ const struct gensec_security_ops **gensec_security_mechs( - if (cli_credentials_get_netlogon_creds(creds) != NULL) { - keep_schannel = true; - } -+ -+ /* -+ * Even if Kerberos is set to REQUIRED, keep the -+ * schannel auth mechanism that machine accounts are -+ * able to authenticate via netlogon. -+ */ -+ if (gensec_security->gensec_role == GENSEC_SERVER) { -+ keep_schannel = true; -+ } - } - - if (gensec_security->settings->backends) { --- -2.33.1 - - -From 67b4e53ff5c23d23d3d452d4df044afc2e998377 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Fri, 4 Sep 2020 12:21:21 +0200 -Subject: [PATCH 055/103] auth:creds: Add cli_credentials_init_server() - -Signed-off-by: Andreas Schneider -Reviewed-by: Stefan Metzmacher -(cherry picked from commit 2c00bea2aefdcc69608dffdafa7ce581d31f9354) ---- - auth/credentials/credentials.c | 25 +++++++++++++++++++++++++ - auth/credentials/credentials.h | 2 ++ - 2 files changed, 27 insertions(+) - -diff --git a/auth/credentials/credentials.c b/auth/credentials/credentials.c -index 9168b92d3ec..77c35dd104b 100644 ---- a/auth/credentials/credentials.c -+++ b/auth/credentials/credentials.c -@@ -56,6 +56,31 @@ _PUBLIC_ struct cli_credentials *cli_credentials_init(TALLOC_CTX *mem_ctx) - return cred; - } - -+_PUBLIC_ -+struct cli_credentials *cli_credentials_init_server(TALLOC_CTX *mem_ctx, -+ struct loadparm_context *lp_ctx) -+{ -+ struct cli_credentials *server_creds = NULL; -+ NTSTATUS status; -+ -+ server_creds = cli_credentials_init(mem_ctx); -+ if (server_creds == NULL) { -+ return NULL; -+ } -+ -+ cli_credentials_set_conf(server_creds, lp_ctx); -+ -+ status = cli_credentials_set_machine_account(server_creds, lp_ctx); -+ if (!NT_STATUS_IS_OK(status)) { -+ DEBUG(1, ("Failed to obtain server credentials: %s\n", -+ nt_errstr(status))); -+ TALLOC_FREE(server_creds); -+ return NULL; -+ } -+ -+ return server_creds; -+} -+ - _PUBLIC_ void cli_credentials_set_callback_data(struct cli_credentials *cred, - void *callback_data) - { -diff --git a/auth/credentials/credentials.h b/auth/credentials/credentials.h -index 7d0cf53194b..438bcdce232 100644 ---- a/auth/credentials/credentials.h -+++ b/auth/credentials/credentials.h -@@ -76,6 +76,8 @@ bool cli_credentials_set_workstation(struct cli_credentials *cred, - enum credentials_obtained obtained); - bool cli_credentials_is_anonymous(struct cli_credentials *cred); - struct cli_credentials *cli_credentials_init(TALLOC_CTX *mem_ctx); -+struct cli_credentials *cli_credentials_init_server(TALLOC_CTX *mem_ctx, -+ struct loadparm_context *lp_ctx); - void cli_credentials_set_anonymous(struct cli_credentials *cred); - bool cli_credentials_wrong_password(struct cli_credentials *cred); - const char *cli_credentials_get_password(struct cli_credentials *cred); --- -2.33.1 - - -From d9769d2cc7c42392b72fd7f76f7beac799501f92 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Fri, 4 Sep 2020 12:21:36 +0200 -Subject: [PATCH 056/103] s4:rpc_server: Use cli_credentials_init_server() - -Signed-off-by: Andreas Schneider -(cherry picked from commit 6c94ebf77fdb7383be2042f5e20ba2ef598cd4a4) ---- - source4/rpc_server/dcerpc_server.c | 17 +++-------------- - 1 file changed, 3 insertions(+), 14 deletions(-) - -diff --git a/source4/rpc_server/dcerpc_server.c b/source4/rpc_server/dcerpc_server.c -index 084857a44bf..e64148ef788 100644 ---- a/source4/rpc_server/dcerpc_server.c -+++ b/source4/rpc_server/dcerpc_server.c -@@ -673,25 +673,14 @@ NTSTATUS dcesrv_gensec_prepare(TALLOC_CTX *mem_ctx, - struct cli_credentials *server_creds = NULL; - struct imessaging_context *imsg_ctx = - dcesrv_imessaging_context(call->conn); -- NTSTATUS status; - -- server_creds = cli_credentials_init(call->auth_state); -- if (!server_creds) { -+ server_creds = cli_credentials_init_server(call->auth_state, -+ call->conn->dce_ctx->lp_ctx); -+ if (server_creds == NULL) { - DEBUG(1, ("Failed to init server credentials\n")); - return NT_STATUS_NO_MEMORY; - } - -- cli_credentials_set_conf(server_creds, call->conn->dce_ctx->lp_ctx); -- -- status = cli_credentials_set_machine_account(server_creds, -- call->conn->dce_ctx->lp_ctx); -- if (!NT_STATUS_IS_OK(status)) { -- DEBUG(1, ("Failed to obtain server credentials: %s\n", -- nt_errstr(status))); -- talloc_free(server_creds); -- return status; -- } -- - return samba_server_gensec_start(mem_ctx, - call->event_ctx, - imsg_ctx, --- -2.33.1 - - -From 65911e611e461f8c53a4ee89f83906d6c38735ed Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Mon, 7 Sep 2020 09:19:43 +0200 -Subject: [PATCH 057/103] s4:smb_server: Use cli_credentials_init_server() for - negprot - -Signed-off-by: Andreas Schneider - -Autobuild-User(master): Stefan Metzmacher -Autobuild-Date(master): Mon Sep 7 13:22:26 UTC 2020 on sn-devel-184 - -(cherry picked from commit 0b742ec6a0558397d5cf01b99a401f8e2bc0e2e0) ---- - source4/smb_server/smb/negprot.c | 28 ++++++++++++++-------------- - source4/smb_server/smb2/negprot.c | 25 +++++++++++++------------ - 2 files changed, 27 insertions(+), 26 deletions(-) - -diff --git a/source4/smb_server/smb/negprot.c b/source4/smb_server/smb/negprot.c -index a6177a72019..04b69dd9883 100644 ---- a/source4/smb_server/smb/negprot.c -+++ b/source4/smb_server/smb/negprot.c -@@ -374,22 +374,22 @@ static void reply_nt1(struct smbsrv_request *req, uint16_t choice) - DATA_BLOB blob = data_blob_null; - const char *oid; - NTSTATUS nt_status; -- -- server_credentials -- = cli_credentials_init(req); -- if (!server_credentials) { -- smbsrv_terminate_connection(req->smb_conn, "Failed to init server credentials\n"); -- return; -- } -- -- cli_credentials_set_conf(server_credentials, req->smb_conn->lp_ctx); -- nt_status = cli_credentials_set_machine_account(server_credentials, req->smb_conn->lp_ctx); -- if (!NT_STATUS_IS_OK(nt_status)) { -- DEBUG(10, ("Failed to obtain server credentials, perhaps a standalone server?: %s\n", nt_errstr(nt_status))); -+ -+ server_credentials = -+ cli_credentials_init_server(req, req->smb_conn->lp_ctx); -+ if (server_credentials == NULL) { -+ DBG_DEBUG("Failed to obtain server credentials, " -+ "perhaps a standalone server?\n"); - /* -- * We keep the server_credentials as anonymous -- * this is required for the spoolss.notify test -+ * Create anon server credentials for for the -+ * spoolss.notify test. - */ -+ server_credentials = cli_credentials_init_anon(req); -+ if (server_credentials == NULL) { -+ smbsrv_terminate_connection(req->smb_conn, -+ "Failed to init server credentials\n"); -+ return; -+ } - } - - nt_status = samba_server_gensec_start(req, -diff --git a/source4/smb_server/smb2/negprot.c b/source4/smb_server/smb2/negprot.c -index 4aaaf46793b..c433eb194bd 100644 ---- a/source4/smb_server/smb2/negprot.c -+++ b/source4/smb_server/smb2/negprot.c -@@ -39,20 +39,21 @@ static NTSTATUS smb2srv_negprot_secblob(struct smb2srv_request *req, DATA_BLOB * - NTSTATUS nt_status; - struct cli_credentials *server_credentials; - -- server_credentials = cli_credentials_init(req); -- if (!server_credentials) { -- smbsrv_terminate_connection(req->smb_conn, "Failed to init server credentials\n"); -- return NT_STATUS_NO_MEMORY; -- } -- -- cli_credentials_set_conf(server_credentials, req->smb_conn->lp_ctx); -- nt_status = cli_credentials_set_machine_account(server_credentials, req->smb_conn->lp_ctx); -- if (!NT_STATUS_IS_OK(nt_status)) { -- DEBUG(10, ("Failed to obtain server credentials, perhaps a standalone server?: %s\n", nt_errstr(nt_status))); -+ server_credentials = -+ cli_credentials_init_server(req, req->smb_conn->lp_ctx); -+ if (server_credentials == NULL) { -+ DBG_DEBUG("Failed to obtain server credentials, " -+ "perhaps a standalone server?\n"); - /* -- * We keep the server_credentials as anonymous -- * this is required for the spoolss.notify test -+ * Create anon server credentials for for the -+ * spoolss.notify test. - */ -+ server_credentials = cli_credentials_init_anon(req); -+ if (server_credentials == NULL) { -+ smbsrv_terminate_connection(req->smb_conn, -+ "Failed to init server credentials\n"); -+ return NT_STATUS_NO_MEMORY; -+ } - } - - req->smb_conn->negotiate.server_credentials = talloc_steal(req->smb_conn, server_credentials); --- -2.33.1 - - -From ac7a244a45672197efdafceff0599c6ac405862e Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Tue, 8 Sep 2020 10:15:22 +0200 -Subject: [PATCH 058/103] selftest: Rename 'smb encrypt' to 'server smb - encrypt' - -This makes it more clear what we want. 'smb encrypt' is a synonym for -'server smb encrypt'. - -Signed-off-by: Andreas Schneider -Reviewed-by: Jeremy Allison -(cherry picked from commit c75e8ff47b4d79b37240f9461ddae10a4f03c892) ---- - selftest/target/Samba3.pm | 6 +++--- - 1 file changed, 3 insertions(+), 3 deletions(-) - -diff --git a/selftest/target/Samba3.pm b/selftest/target/Samba3.pm -index 39327964569..5119535b707 100755 ---- a/selftest/target/Samba3.pm -+++ b/selftest/target/Samba3.pm -@@ -1244,7 +1244,7 @@ sub setup_simpleserver - ntlm auth = yes - vfs objects = xattr_tdb streams_depot - change notify = no -- smb encrypt = off -+ server smb encrypt = off - - [vfs_aio_pthread] - path = $prefix_abs/share -@@ -1311,7 +1311,7 @@ sub setup_simpleserver - [enc_desired] - path = $prefix_abs/share - vfs objects = -- smb encrypt = desired -+ server smb encrypt = desired - - [hidenewfiles] - path = $prefix_abs/share -@@ -2432,7 +2432,7 @@ sub provision($$) - [tmpenc] - path = $shrdir - comment = encrypt smb username is [%U] -- smb encrypt = required -+ server smb encrypt = required - vfs objects = dirsort - [tmpguest] - path = $shrdir --- -2.33.1 - - -From 6bb81bdc8d04736693a0255a620febb39af6f8ea Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Tue, 8 Sep 2020 12:30:08 +0200 -Subject: [PATCH 059/103] selftest: Move enc_desired to provision to have it in - 'fileserver' too - -Signed-off-by: Andreas Schneider -Reviewed-by: Jeremy Allison -(cherry picked from commit 1b67943f938ae774360dc3db73db940f9982243b) ---- - selftest/target/Samba3.pm | 11 ++++++----- - 1 file changed, 6 insertions(+), 5 deletions(-) - -diff --git a/selftest/target/Samba3.pm b/selftest/target/Samba3.pm -index 5119535b707..d773e14746c 100755 ---- a/selftest/target/Samba3.pm -+++ b/selftest/target/Samba3.pm -@@ -1308,11 +1308,6 @@ sub setup_simpleserver - hide files = /hidefile/ - hide dot files = yes - --[enc_desired] -- path = $prefix_abs/share -- vfs objects = -- server smb encrypt = desired -- - [hidenewfiles] - path = $prefix_abs/share - hide new files timeout = 5 -@@ -2914,7 +2909,13 @@ sub provision($$) - [delete_readonly] - path = $prefix_abs/share - delete readonly = yes -+ -+[enc_desired] -+ path = $prefix_abs/share -+ vfs objects = -+ server smb encrypt = desired - "; -+ - close(CONF); - - my $net = Samba::bindir_path($self, "net"); --- -2.33.1 - - -From f7468c0c5654d24818639e2d2a44f64dc9c5b8d0 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Tue, 8 Sep 2020 10:15:20 +0200 -Subject: [PATCH 060/103] s3:tests: Add smbclient tests for 'client smb - encrypt' - -Signed-off-by: Andreas Schneider -Reviewed-by: Jeremy Allison -(cherry picked from commit e7577ab6cbc83b496ac091c3e425c7c7fea29cdb) ---- - selftest/knownfail.d/smbclient-encryption | 2 + - selftest/target/Samba3.pm | 5 ++ - .../script/tests/test_smbclient_encryption.sh | 72 +++++++++++++++++++ - source3/selftest/tests.py | 6 ++ - 4 files changed, 85 insertions(+) - create mode 100644 selftest/knownfail.d/smbclient-encryption - create mode 100755 source3/script/tests/test_smbclient_encryption.sh - -diff --git a/selftest/knownfail.d/smbclient-encryption b/selftest/knownfail.d/smbclient-encryption -new file mode 100644 -index 00000000000..972096bdc8b ---- /dev/null -+++ b/selftest/knownfail.d/smbclient-encryption -@@ -0,0 +1,2 @@ -+^samba3.blackbox.smbclient.encryption.smbclient.smb3.client.encrypt.required...LOCALSHARE4.enc_desired..simpleserver -+^samba3.blackbox.smbclient.encryption.smbclient.smb3.client.encrypt.required...LOCALSHARE4.tmp..simpleserver -diff --git a/selftest/target/Samba3.pm b/selftest/target/Samba3.pm -index d773e14746c..1c44b44edc4 100755 ---- a/selftest/target/Samba3.pm -+++ b/selftest/target/Samba3.pm -@@ -2914,6 +2914,11 @@ sub provision($$) - path = $prefix_abs/share - vfs objects = - server smb encrypt = desired -+ -+[enc_off] -+ path = $prefix_abs/share -+ vfs objects = -+ server smb encrypt = off - "; - - close(CONF); -diff --git a/source3/script/tests/test_smbclient_encryption.sh b/source3/script/tests/test_smbclient_encryption.sh -new file mode 100755 -index 00000000000..9a717cdac4f ---- /dev/null -+++ b/source3/script/tests/test_smbclient_encryption.sh -@@ -0,0 +1,72 @@ -+#!/bin/sh -+ -+if [ $# -lt 5 ]; then -+cat < -Date: Thu, 27 Aug 2020 15:19:27 +0200 -Subject: [PATCH 061/103] s3:client: Remove global smb_encrypt - -Signed-off-by: Andreas Schneider -Reviewed-by: Jeremy Allison -(cherry picked from commit 1189b20cb7ea09cfed5c246cf977442a51ef72cb) ---- - source3/client/client.c | 25 ++++++++++++++++--------- - 1 file changed, 16 insertions(+), 9 deletions(-) - -diff --git a/source3/client/client.c b/source3/client/client.c -index 56309efcea7..60d4fb3c5ee 100644 ---- a/source3/client/client.c -+++ b/source3/client/client.c -@@ -96,9 +96,6 @@ static unsigned int put_total_time_ms = 0; - /* totals globals */ - static double dir_total; - --/* encrypted state. */ --static bool smb_encrypt; -- - /* root cli_state connection */ - - struct cli_state *cli; -@@ -2758,7 +2755,7 @@ static int cmd_posix_encrypt(void) - d_printf("posix_encrypt failed with error %s\n", nt_errstr(status)); - } else { - d_printf("encryption on\n"); -- smb_encrypt = true; -+ set_cmdline_auth_info_smb_encrypt(popt_get_cmdline_auth_info()); - } - - return 0; -@@ -5283,6 +5280,9 @@ int cmd_iosize(void) - TALLOC_CTX *ctx = talloc_tos(); - char *buf; - int iosize; -+ bool smb_encrypt = -+ get_cmdline_auth_info_smb_encrypt( -+ popt_get_cmdline_auth_info()); - - if (!next_token_talloc(ctx, &cmd_ptr,&buf,NULL)) { - if (smbXcli_conn_protocol(cli->conn) < PROTOCOL_SMB2_02) { -@@ -5546,6 +5546,9 @@ static int process_command_string(const char *cmd_in) - TALLOC_CTX *ctx = talloc_tos(); - char *cmd = talloc_strdup(ctx, cmd_in); - int rc = 0; -+ bool smb_encrypt = -+ get_cmdline_auth_info_smb_encrypt( -+ popt_get_cmdline_auth_info()); - - if (!cmd) { - return 1; -@@ -5999,6 +6002,9 @@ static int process(const char *base_directory) - { - int rc = 0; - NTSTATUS status; -+ bool smb_encrypt = -+ get_cmdline_auth_info_smb_encrypt( -+ popt_get_cmdline_auth_info()); - - status = cli_cm_open(talloc_tos(), NULL, - desthost, -@@ -6037,6 +6043,9 @@ static int process(const char *base_directory) - static int do_host_query(const char *query_host) - { - NTSTATUS status; -+ bool smb_encrypt = -+ get_cmdline_auth_info_smb_encrypt( -+ popt_get_cmdline_auth_info()); - - status = cli_cm_open(talloc_tos(), NULL, - query_host, -@@ -6114,6 +6123,9 @@ static int do_tar_op(const char *base_directory) - { - struct tar *tar_ctx = tar_get_ctx(); - int ret = 0; -+ bool smb_encrypt = -+ get_cmdline_auth_info_smb_encrypt( -+ popt_get_cmdline_auth_info()); - - /* do we already have a connection? */ - if (!cli) { -@@ -6459,9 +6471,6 @@ int main(int argc,char *argv[]) - case 'q': - quiet=true; - break; -- case 'e': -- smb_encrypt=true; -- break; - case 'B': - return(do_smb_browse()); - -@@ -6531,8 +6540,6 @@ int main(int argc,char *argv[]) - - /* Ensure we have a password (or equivalent). */ - popt_common_credentials_post(); -- smb_encrypt = get_cmdline_auth_info_smb_encrypt( -- popt_get_cmdline_auth_info()); - - max_protocol = lp_client_max_protocol(); - --- -2.33.1 - - -From d62caf7a37fab43cd2fdd706cd1fb8b67233a720 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 27 Aug 2020 15:24:27 +0200 -Subject: [PATCH 062/103] s3:libsmb: Remove force_encrypt from cli_cm_open() - -Signed-off-by: Andreas Schneider -Reviewed-by: Jeremy Allison -(cherry picked from commit a9fbc8dae878ddfa54153e91cc1128c307816b76) ---- - source3/client/client.c | 21 ++++----------------- - source3/lib/netapi/cm.c | 1 - - source3/libsmb/clidfs.c | 4 ++-- - source3/libsmb/proto.h | 1 - - 4 files changed, 6 insertions(+), 21 deletions(-) - -diff --git a/source3/client/client.c b/source3/client/client.c -index 60d4fb3c5ee..3a610086511 100644 ---- a/source3/client/client.c -+++ b/source3/client/client.c -@@ -5546,9 +5546,6 @@ static int process_command_string(const char *cmd_in) - TALLOC_CTX *ctx = talloc_tos(); - char *cmd = talloc_strdup(ctx, cmd_in); - int rc = 0; -- bool smb_encrypt = -- get_cmdline_auth_info_smb_encrypt( -- popt_get_cmdline_auth_info()); - - if (!cmd) { - return 1; -@@ -5561,7 +5558,6 @@ static int process_command_string(const char *cmd_in) - status = cli_cm_open(talloc_tos(), NULL, - desthost, - service, popt_get_cmdline_auth_info(), -- smb_encrypt, - max_protocol, - have_ip ? &dest_ss : NULL, port, - name_type, -@@ -6002,14 +5998,11 @@ static int process(const char *base_directory) - { - int rc = 0; - NTSTATUS status; -- bool smb_encrypt = -- get_cmdline_auth_info_smb_encrypt( -- popt_get_cmdline_auth_info()); - - status = cli_cm_open(talloc_tos(), NULL, - desthost, - service, popt_get_cmdline_auth_info(), -- smb_encrypt, max_protocol, -+ max_protocol, - have_ip ? &dest_ss : NULL, port, - name_type, &cli); - if (!NT_STATUS_IS_OK(status)) { -@@ -6043,14 +6036,11 @@ static int process(const char *base_directory) - static int do_host_query(const char *query_host) - { - NTSTATUS status; -- bool smb_encrypt = -- get_cmdline_auth_info_smb_encrypt( -- popt_get_cmdline_auth_info()); - - status = cli_cm_open(talloc_tos(), NULL, - query_host, - "IPC$", popt_get_cmdline_auth_info(), -- smb_encrypt, max_protocol, -+ max_protocol, - have_ip ? &dest_ss : NULL, port, - name_type, &cli); - if (!NT_STATUS_IS_OK(status)) { -@@ -6097,7 +6087,7 @@ static int do_host_query(const char *query_host) - status = cli_cm_open(talloc_tos(), NULL, - query_host, - "IPC$", popt_get_cmdline_auth_info(), -- smb_encrypt, max_proto, -+ max_proto, - have_ip ? &dest_ss : NULL, NBT_SMB_PORT, - name_type, &cli); - if (!NT_STATUS_IS_OK(status)) { -@@ -6123,9 +6113,6 @@ static int do_tar_op(const char *base_directory) - { - struct tar *tar_ctx = tar_get_ctx(); - int ret = 0; -- bool smb_encrypt = -- get_cmdline_auth_info_smb_encrypt( -- popt_get_cmdline_auth_info()); - - /* do we already have a connection? */ - if (!cli) { -@@ -6134,7 +6121,7 @@ static int do_tar_op(const char *base_directory) - status = cli_cm_open(talloc_tos(), NULL, - desthost, - service, popt_get_cmdline_auth_info(), -- smb_encrypt, max_protocol, -+ max_protocol, - have_ip ? &dest_ss : NULL, port, - name_type, &cli); - if (!NT_STATUS_IS_OK(status)) { -diff --git a/source3/lib/netapi/cm.c b/source3/lib/netapi/cm.c -index 1b8f2a4e97a..0fd31ef3d5a 100644 ---- a/source3/lib/netapi/cm.c -+++ b/source3/lib/netapi/cm.c -@@ -110,7 +110,6 @@ static WERROR libnetapi_open_ipc_connection(struct libnetapi_ctx *ctx, - status = cli_cm_open(ctx, NULL, - server_name, "IPC$", - auth_info, -- false, - lp_client_ipc_max_protocol(), - NULL, 0, 0x20, &cli_ipc); - if (!NT_STATUS_IS_OK(status)) { -diff --git a/source3/libsmb/clidfs.c b/source3/libsmb/clidfs.c -index 93b2525b204..13613afb6e7 100644 ---- a/source3/libsmb/clidfs.c -+++ b/source3/libsmb/clidfs.c -@@ -407,7 +407,6 @@ NTSTATUS cli_cm_open(TALLOC_CTX *ctx, - const char *server, - const char *share, - const struct user_auth_info *auth_info, -- bool force_encrypt, - int max_protocol, - const struct sockaddr_storage *dest_ss, - int port, -@@ -417,6 +416,8 @@ NTSTATUS cli_cm_open(TALLOC_CTX *ctx, - /* Try to reuse an existing connection in this list. */ - struct cli_state *c = cli_cm_find(referring_cli, server, share); - NTSTATUS status; -+ bool force_encrypt = -+ get_cmdline_auth_info_smb_encrypt(auth_info); - - if (c) { - *pcli = c; -@@ -986,7 +987,6 @@ NTSTATUS cli_resolve_path(TALLOC_CTX *ctx, - smbXcli_conn_remote_name(rootcli->conn), - "IPC$", - dfs_auth_info, -- cli_state_is_encryption_on(rootcli), - smbXcli_conn_protocol(rootcli->conn), - NULL, /* dest_ss not needed, we reuse the transport */ - 0, -diff --git a/source3/libsmb/proto.h b/source3/libsmb/proto.h -index eeabcaa7463..bb3e9e6874e 100644 ---- a/source3/libsmb/proto.h -+++ b/source3/libsmb/proto.h -@@ -128,7 +128,6 @@ NTSTATUS cli_cm_open(TALLOC_CTX *ctx, - const char *server, - const char *share, - const struct user_auth_info *auth_info, -- bool force_encrypt, - int max_protocol, - const struct sockaddr_storage *dest_ss, - int port, --- -2.33.1 - - -From 2a6929e61014c731bd4202c4b8a983c800c8cf69 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 27 Aug 2020 15:26:39 +0200 -Subject: [PATCH 063/103] s3:libsmb: Remove force_encrypt from cli_cm_connect() - -Signed-off-by: Andreas Schneider -Reviewed-by: Jeremy Allison -(cherry picked from commit d27e237cf37fb254646d94827935d9c302c379ff) ---- - source3/libsmb/clidfs.c | 7 ++----- - 1 file changed, 2 insertions(+), 5 deletions(-) - -diff --git a/source3/libsmb/clidfs.c b/source3/libsmb/clidfs.c -index 13613afb6e7..9e5c9e57e74 100644 ---- a/source3/libsmb/clidfs.c -+++ b/source3/libsmb/clidfs.c -@@ -311,7 +311,6 @@ static NTSTATUS cli_cm_connect(TALLOC_CTX *ctx, - const char *server, - const char *share, - const struct user_auth_info *auth_info, -- bool force_encrypt, - int max_protocol, - const struct sockaddr_storage *dest_ss, - int port, -@@ -320,6 +319,8 @@ static NTSTATUS cli_cm_connect(TALLOC_CTX *ctx, - { - struct cli_state *cli = NULL; - NTSTATUS status; -+ bool force_encrypt = -+ get_cmdline_auth_info_smb_encrypt(auth_info); - - status = do_connect(ctx, server, share, - auth_info, -@@ -416,8 +417,6 @@ NTSTATUS cli_cm_open(TALLOC_CTX *ctx, - /* Try to reuse an existing connection in this list. */ - struct cli_state *c = cli_cm_find(referring_cli, server, share); - NTSTATUS status; -- bool force_encrypt = -- get_cmdline_auth_info_smb_encrypt(auth_info); - - if (c) { - *pcli = c; -@@ -438,7 +437,6 @@ NTSTATUS cli_cm_open(TALLOC_CTX *ctx, - server, - share, - auth_info, -- force_encrypt, - max_protocol, - dest_ss, - port, -@@ -1044,7 +1042,6 @@ NTSTATUS cli_resolve_path(TALLOC_CTX *ctx, - dfs_refs[count].server, - dfs_refs[count].share, - dfs_auth_info, -- cli_state_is_encryption_on(rootcli), - smbXcli_conn_protocol(rootcli->conn), - NULL, /* dest_ss */ - 0, /* port */ --- -2.33.1 - - -From 984ec1e557f7b6cd37b2c102abf390e3c83fa07e Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 27 Aug 2020 15:28:28 +0200 -Subject: [PATCH 064/103] s3:libsmb: Remove force_encrypt from clidfs - do_connect() - -Signed-off-by: Andreas Schneider -Reviewed-by: Jeremy Allison -(cherry picked from commit 615a9a68166bdeb0ab7dbacf395c6125ec70f288) ---- - source3/libsmb/clidfs.c | 9 ++++----- - 1 file changed, 4 insertions(+), 5 deletions(-) - -diff --git a/source3/libsmb/clidfs.c b/source3/libsmb/clidfs.c -index 9e5c9e57e74..c5b79bb37dd 100644 ---- a/source3/libsmb/clidfs.c -+++ b/source3/libsmb/clidfs.c -@@ -131,7 +131,6 @@ static NTSTATUS do_connect(TALLOC_CTX *ctx, - const char *server, - const char *share, - const struct user_auth_info *auth_info, -- bool force_encrypt, - int max_protocol, - const struct sockaddr_storage *dest_ss, - int port, -@@ -147,6 +146,8 @@ static NTSTATUS do_connect(TALLOC_CTX *ctx, - enum protocol_types protocol = PROTOCOL_NONE; - int signing_state = get_cmdline_auth_info_signing_state(auth_info); - struct cli_credentials *creds = NULL; -+ bool force_encrypt = -+ get_cmdline_auth_info_smb_encrypt(auth_info); - - if (force_encrypt) { - signing_state = SMB_SIGNING_REQUIRED; -@@ -267,7 +268,7 @@ static NTSTATUS do_connect(TALLOC_CTX *ctx, - cli_shutdown(c); - return do_connect(ctx, newserver, - newshare, auth_info, -- force_encrypt, max_protocol, -+ max_protocol, - NULL, port, name_type, pcli); - } - -@@ -319,12 +320,10 @@ static NTSTATUS cli_cm_connect(TALLOC_CTX *ctx, - { - struct cli_state *cli = NULL; - NTSTATUS status; -- bool force_encrypt = -- get_cmdline_auth_info_smb_encrypt(auth_info); - - status = do_connect(ctx, server, share, - auth_info, -- force_encrypt, max_protocol, -+ max_protocol, - dest_ss, port, name_type, &cli); - - if (!NT_STATUS_IS_OK(status)) { --- -2.33.1 - - -From 00f21bf822dabfffe4b61b9e3390f06617bab391 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 27 Aug 2020 15:52:11 +0200 -Subject: [PATCH 065/103] s3:libsmb: Remove force_encrypt from - cli_check_msdfs_proxy() - -Signed-off-by: Andreas Schneider -Reviewed-by: Jeremy Allison -(cherry picked from commit 4ddec1ca257fff418847c5d1e83a3fb7cb5ade1a) ---- - source3/libsmb/clidfs.c | 19 +++++++++++++------ - source3/libsmb/libsmb_server.c | 4 ---- - source3/libsmb/proto.h | 1 - - 3 files changed, 13 insertions(+), 11 deletions(-) - -diff --git a/source3/libsmb/clidfs.c b/source3/libsmb/clidfs.c -index c5b79bb37dd..8fb450b5327 100644 ---- a/source3/libsmb/clidfs.c -+++ b/source3/libsmb/clidfs.c -@@ -264,7 +264,7 @@ static NTSTATUS do_connect(TALLOC_CTX *ctx, - if (smbXcli_conn_dfs_supported(c->conn) && - cli_check_msdfs_proxy(ctx, c, sharename, - &newserver, &newshare, -- force_encrypt, creds)) { -+ creds)) { - cli_shutdown(c); - return do_connect(ctx, newserver, - newshare, auth_info, -@@ -1200,7 +1200,6 @@ bool cli_check_msdfs_proxy(TALLOC_CTX *ctx, - const char *sharename, - char **pp_newserver, - char **pp_newshare, -- bool force_encrypt, - struct cli_credentials *creds) - { - struct client_dfs_referral *refs = NULL; -@@ -1212,6 +1211,8 @@ bool cli_check_msdfs_proxy(TALLOC_CTX *ctx, - char *newextrapath = NULL; - NTSTATUS status; - const char *remote_name; -+ enum smb_encryption_setting encryption_state = -+ cli_credentials_get_smb_encryption(creds); - - if (!cli || !sharename) { - return false; -@@ -1247,12 +1248,18 @@ bool cli_check_msdfs_proxy(TALLOC_CTX *ctx, - return false; - } - -- if (force_encrypt) { -+ if (encryption_state >= SMB_ENCRYPTION_DESIRED) { - status = cli_cm_force_encryption_creds(cli, creds, "IPC$"); - if (!NT_STATUS_IS_OK(status)) { -- cli_tdis(cli); -- cli_state_restore_tcon(cli, orig_tcon); -- return false; -+ switch (encryption_state) { -+ case SMB_ENCRYPTION_DESIRED: -+ break; -+ case SMB_ENCRYPTION_REQUIRED: -+ default: -+ cli_tdis(cli); -+ cli_state_restore_tcon(cli, orig_tcon); -+ return false; -+ } - } - } - -diff --git a/source3/libsmb/libsmb_server.c b/source3/libsmb/libsmb_server.c -index eb58d7c6ac9..5a1055ba773 100644 ---- a/source3/libsmb/libsmb_server.c -+++ b/source3/libsmb/libsmb_server.c -@@ -587,10 +587,6 @@ SMBC_server_internal(TALLOC_CTX *ctx, - if (smbXcli_conn_dfs_supported(c->conn) && - cli_check_msdfs_proxy(ctx, c, share, - &newserver, &newshare, -- /* FIXME: cli_check_msdfs_proxy() does -- not support smbc_smb_encrypt_level type */ -- context->internal->smb_encryption_level ? -- true : false, - creds)) { - cli_shutdown(c); - srv = SMBC_server_internal(ctx, context, connect_if_not_found, -diff --git a/source3/libsmb/proto.h b/source3/libsmb/proto.h -index bb3e9e6874e..f2b0a8c5ff8 100644 ---- a/source3/libsmb/proto.h -+++ b/source3/libsmb/proto.h -@@ -161,7 +161,6 @@ bool cli_check_msdfs_proxy(TALLOC_CTX *ctx, - const char *sharename, - char **pp_newserver, - char **pp_newshare, -- bool force_encrypt, - struct cli_credentials *creds); - - /* The following definitions come from libsmb/clientgen.c */ --- -2.33.1 - - -From 8cd4318aa460b00db9c36aae638094ce8af24488 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Tue, 18 Aug 2020 17:15:09 +0200 -Subject: [PATCH 066/103] s3:libsmb: Pass cli_credentials to clidfs - do_connect() - -Signed-off-by: Andreas Schneider -Reviewed-by: Jeremy Allison -(cherry picked from commit 276563de06f2071ec2ed9a8b73f92215ab621bba) ---- - selftest/knownfail.d/smbclient-encryption | 2 -- - source3/libsmb/clidfs.c | 34 +++++++++++++---------- - 2 files changed, 20 insertions(+), 16 deletions(-) - delete mode 100644 selftest/knownfail.d/smbclient-encryption - -diff --git a/selftest/knownfail.d/smbclient-encryption b/selftest/knownfail.d/smbclient-encryption -deleted file mode 100644 -index 972096bdc8b..00000000000 ---- a/selftest/knownfail.d/smbclient-encryption -+++ /dev/null -@@ -1,2 +0,0 @@ --^samba3.blackbox.smbclient.encryption.smbclient.smb3.client.encrypt.required...LOCALSHARE4.enc_desired..simpleserver --^samba3.blackbox.smbclient.encryption.smbclient.smb3.client.encrypt.required...LOCALSHARE4.tmp..simpleserver -diff --git a/source3/libsmb/clidfs.c b/source3/libsmb/clidfs.c -index 8fb450b5327..396856842aa 100644 ---- a/source3/libsmb/clidfs.c -+++ b/source3/libsmb/clidfs.c -@@ -130,7 +130,7 @@ static NTSTATUS cli_cm_force_encryption_creds(struct cli_state *c, - static NTSTATUS do_connect(TALLOC_CTX *ctx, - const char *server, - const char *share, -- const struct user_auth_info *auth_info, -+ struct cli_credentials *creds, - int max_protocol, - const struct sockaddr_storage *dest_ss, - int port, -@@ -144,12 +144,12 @@ static NTSTATUS do_connect(TALLOC_CTX *ctx, - NTSTATUS status; - int flags = 0; - enum protocol_types protocol = PROTOCOL_NONE; -- int signing_state = get_cmdline_auth_info_signing_state(auth_info); -- struct cli_credentials *creds = NULL; -- bool force_encrypt = -- get_cmdline_auth_info_smb_encrypt(auth_info); -+ enum smb_signing_setting signing_state = -+ cli_credentials_get_smb_signing(creds); -+ enum smb_encryption_setting encryption_state = -+ cli_credentials_get_smb_encryption(creds); - -- if (force_encrypt) { -+ if (encryption_state >= SMB_ENCRYPTION_DESIRED) { - signing_state = SMB_SIGNING_REQUIRED; - } - -@@ -216,13 +216,12 @@ static NTSTATUS do_connect(TALLOC_CTX *ctx, - smb2cli_conn_set_max_credits(c->conn, DEFAULT_SMB2_MAX_CREDITS); - } - -- creds = get_cmdline_auth_info_creds(auth_info); -- - status = cli_session_setup_creds(c, creds); - if (!NT_STATUS_IS_OK(status)) { - /* If a password was not supplied then - * try again with a null username. */ -- if (force_encrypt || smbXcli_conn_signing_mandatory(c->conn) || -+ if (encryption_state == SMB_ENCRYPTION_REQUIRED || -+ smbXcli_conn_signing_mandatory(c->conn) || - cli_credentials_authentication_requested(creds) || - cli_credentials_is_anonymous(creds) || - !NT_STATUS_IS_OK(status = cli_session_setup_anon(c))) -@@ -246,13 +245,19 @@ static NTSTATUS do_connect(TALLOC_CTX *ctx, - - DEBUG(4,(" session setup ok\n")); - -- if (force_encrypt) { -+ if (encryption_state >= SMB_ENCRYPTION_DESIRED) { - status = cli_cm_force_encryption_creds(c, - creds, - sharename); - if (!NT_STATUS_IS_OK(status)) { -- cli_shutdown(c); -- return status; -+ switch (encryption_state) { -+ case SMB_ENCRYPTION_DESIRED: -+ break; -+ case SMB_ENCRYPTION_REQUIRED: -+ default: -+ cli_shutdown(c); -+ return status; -+ } - } - } - -@@ -267,7 +272,7 @@ static NTSTATUS do_connect(TALLOC_CTX *ctx, - creds)) { - cli_shutdown(c); - return do_connect(ctx, newserver, -- newshare, auth_info, -+ newshare, creds, - max_protocol, - NULL, port, name_type, pcli); - } -@@ -319,10 +324,11 @@ static NTSTATUS cli_cm_connect(TALLOC_CTX *ctx, - struct cli_state **pcli) - { - struct cli_state *cli = NULL; -+ struct cli_credentials *creds = get_cmdline_auth_info_creds(auth_info); - NTSTATUS status; - - status = do_connect(ctx, server, share, -- auth_info, -+ creds, - max_protocol, - dest_ss, port, name_type, &cli); - --- -2.33.1 - - -From b7e861f8b85b16351a74c302b1c3e4844f661329 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Tue, 18 Aug 2020 17:18:16 +0200 -Subject: [PATCH 067/103] s3:libsmb: Pass cli_credentials to cli_cm_connect() - -Signed-off-by: Andreas Schneider -Reviewed-by: Jeremy Allison -(cherry picked from commit c8349111243fec81a2b95484e56a6d6bebaba80e) ---- - source3/libsmb/clidfs.c | 9 +++++---- - 1 file changed, 5 insertions(+), 4 deletions(-) - -diff --git a/source3/libsmb/clidfs.c b/source3/libsmb/clidfs.c -index 396856842aa..e17c0b875fd 100644 ---- a/source3/libsmb/clidfs.c -+++ b/source3/libsmb/clidfs.c -@@ -316,7 +316,7 @@ static NTSTATUS cli_cm_connect(TALLOC_CTX *ctx, - struct cli_state *referring_cli, - const char *server, - const char *share, -- const struct user_auth_info *auth_info, -+ struct cli_credentials *creds, - int max_protocol, - const struct sockaddr_storage *dest_ss, - int port, -@@ -324,7 +324,6 @@ static NTSTATUS cli_cm_connect(TALLOC_CTX *ctx, - struct cli_state **pcli) - { - struct cli_state *cli = NULL; -- struct cli_credentials *creds = get_cmdline_auth_info_creds(auth_info); - NTSTATUS status; - - status = do_connect(ctx, server, share, -@@ -421,6 +420,7 @@ NTSTATUS cli_cm_open(TALLOC_CTX *ctx, - { - /* Try to reuse an existing connection in this list. */ - struct cli_state *c = cli_cm_find(referring_cli, server, share); -+ struct cli_credentials *creds = get_cmdline_auth_info_creds(auth_info); - NTSTATUS status; - - if (c) { -@@ -441,7 +441,7 @@ NTSTATUS cli_cm_open(TALLOC_CTX *ctx, - referring_cli, - server, - share, -- auth_info, -+ creds, - max_protocol, - dest_ss, - port, -@@ -910,6 +910,7 @@ NTSTATUS cli_resolve_path(TALLOC_CTX *ctx, - struct smbXcli_tcon *root_tcon = NULL; - struct smbXcli_tcon *target_tcon = NULL; - struct cli_dfs_path_split *dfs_refs = NULL; -+ struct cli_credentials *creds = get_cmdline_auth_info_creds(dfs_auth_info); - - if ( !rootcli || !path || !targetcli ) { - return NT_STATUS_INVALID_PARAMETER; -@@ -1046,7 +1047,7 @@ NTSTATUS cli_resolve_path(TALLOC_CTX *ctx, - status = cli_cm_connect(ctx, rootcli, - dfs_refs[count].server, - dfs_refs[count].share, -- dfs_auth_info, -+ creds, - smbXcli_conn_protocol(rootcli->conn), - NULL, /* dest_ss */ - 0, /* port */ --- -2.33.1 - - -From b6338098c53547645ff000ee945d337fa6bddf69 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Tue, 18 Aug 2020 17:26:54 +0200 -Subject: [PATCH 068/103] s3:libsmb: Pass cli_credentials to cli_cm_open() - -Signed-off-by: Andreas Schneider -Reviewed-by: Jeremy Allison -(cherry picked from commit df1623abd7267916696e2e60c146ef8fa6c9dfc9) ---- - source3/client/client.c | 23 ++++++++++++++++++----- - source3/lib/netapi/cm.c | 4 +++- - source3/libsmb/clidfs.c | 25 ++++++++++++------------- - source3/libsmb/proto.h | 18 +++++++++--------- - 4 files changed, 42 insertions(+), 28 deletions(-) - -diff --git a/source3/client/client.c b/source3/client/client.c -index 3a610086511..c54b5065b44 100644 ---- a/source3/client/client.c -+++ b/source3/client/client.c -@@ -5546,6 +5546,8 @@ static int process_command_string(const char *cmd_in) - TALLOC_CTX *ctx = talloc_tos(); - char *cmd = talloc_strdup(ctx, cmd_in); - int rc = 0; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - - if (!cmd) { - return 1; -@@ -5557,7 +5559,8 @@ static int process_command_string(const char *cmd_in) - - status = cli_cm_open(talloc_tos(), NULL, - desthost, -- service, popt_get_cmdline_auth_info(), -+ service, -+ creds, - max_protocol, - have_ip ? &dest_ss : NULL, port, - name_type, -@@ -5998,10 +6001,13 @@ static int process(const char *base_directory) - { - int rc = 0; - NTSTATUS status; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - - status = cli_cm_open(talloc_tos(), NULL, - desthost, -- service, popt_get_cmdline_auth_info(), -+ service, -+ creds, - max_protocol, - have_ip ? &dest_ss : NULL, port, - name_type, &cli); -@@ -6036,10 +6042,13 @@ static int process(const char *base_directory) - static int do_host_query(const char *query_host) - { - NTSTATUS status; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - - status = cli_cm_open(talloc_tos(), NULL, - query_host, -- "IPC$", popt_get_cmdline_auth_info(), -+ "IPC$", -+ creds, - max_protocol, - have_ip ? &dest_ss : NULL, port, - name_type, &cli); -@@ -6086,7 +6095,8 @@ static int do_host_query(const char *query_host) - d_printf("Reconnecting with SMB1 for workgroup listing.\n"); - status = cli_cm_open(talloc_tos(), NULL, - query_host, -- "IPC$", popt_get_cmdline_auth_info(), -+ "IPC$", -+ creds, - max_proto, - have_ip ? &dest_ss : NULL, NBT_SMB_PORT, - name_type, &cli); -@@ -6113,6 +6123,8 @@ static int do_tar_op(const char *base_directory) - { - struct tar *tar_ctx = tar_get_ctx(); - int ret = 0; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - - /* do we already have a connection? */ - if (!cli) { -@@ -6120,7 +6132,8 @@ static int do_tar_op(const char *base_directory) - - status = cli_cm_open(talloc_tos(), NULL, - desthost, -- service, popt_get_cmdline_auth_info(), -+ service, -+ creds, - max_protocol, - have_ip ? &dest_ss : NULL, port, - name_type, &cli); -diff --git a/source3/lib/netapi/cm.c b/source3/lib/netapi/cm.c -index 0fd31ef3d5a..943f7498e8c 100644 ---- a/source3/lib/netapi/cm.c -+++ b/source3/lib/netapi/cm.c -@@ -71,6 +71,7 @@ static WERROR libnetapi_open_ipc_connection(struct libnetapi_ctx *ctx, - struct cli_state *cli_ipc = NULL; - struct client_ipc_connection *p; - NTSTATUS status; -+ struct cli_credentials *creds = NULL; - - if (!ctx || !pp || !server_name) { - return WERR_INVALID_PARAMETER; -@@ -106,10 +107,11 @@ static WERROR libnetapi_open_ipc_connection(struct libnetapi_ctx *ctx, - if (ctx->use_ccache) { - set_cmdline_auth_info_use_ccache(auth_info, true); - } -+ creds = get_cmdline_auth_info_creds(auth_info); - - status = cli_cm_open(ctx, NULL, - server_name, "IPC$", -- auth_info, -+ creds, - lp_client_ipc_max_protocol(), - NULL, 0, 0x20, &cli_ipc); - if (!NT_STATUS_IS_OK(status)) { -diff --git a/source3/libsmb/clidfs.c b/source3/libsmb/clidfs.c -index e17c0b875fd..5b04b63634f 100644 ---- a/source3/libsmb/clidfs.c -+++ b/source3/libsmb/clidfs.c -@@ -408,19 +408,18 @@ static struct cli_state *cli_cm_find(struct cli_state *cli, - ****************************************************************************/ - - NTSTATUS cli_cm_open(TALLOC_CTX *ctx, -- struct cli_state *referring_cli, -- const char *server, -- const char *share, -- const struct user_auth_info *auth_info, -- int max_protocol, -- const struct sockaddr_storage *dest_ss, -- int port, -- int name_type, -- struct cli_state **pcli) -+ struct cli_state *referring_cli, -+ const char *server, -+ const char *share, -+ struct cli_credentials *creds, -+ int max_protocol, -+ const struct sockaddr_storage *dest_ss, -+ int port, -+ int name_type, -+ struct cli_state **pcli) - { - /* Try to reuse an existing connection in this list. */ - struct cli_state *c = cli_cm_find(referring_cli, server, share); -- struct cli_credentials *creds = get_cmdline_auth_info_creds(auth_info); - NTSTATUS status; - - if (c) { -@@ -428,11 +427,11 @@ NTSTATUS cli_cm_open(TALLOC_CTX *ctx, - return NT_STATUS_OK; - } - -- if (auth_info == NULL) { -+ if (creds == NULL) { - /* Can't do a new connection - * without auth info. */ - d_printf("cli_cm_open() Unable to open connection [\\%s\\%s] " -- "without auth info\n", -+ "without client credentials\n", - server, share ); - return NT_STATUS_INVALID_PARAMETER; - } -@@ -990,7 +989,7 @@ NTSTATUS cli_resolve_path(TALLOC_CTX *ctx, - rootcli, - smbXcli_conn_remote_name(rootcli->conn), - "IPC$", -- dfs_auth_info, -+ creds, - smbXcli_conn_protocol(rootcli->conn), - NULL, /* dest_ss not needed, we reuse the transport */ - 0, -diff --git a/source3/libsmb/proto.h b/source3/libsmb/proto.h -index f2b0a8c5ff8..0b8cf2a6036 100644 ---- a/source3/libsmb/proto.h -+++ b/source3/libsmb/proto.h -@@ -124,15 +124,15 @@ struct cli_state *get_ipc_connect_master_ip(TALLOC_CTX *ctx, - /* The following definitions come from libsmb/clidfs.c */ - - NTSTATUS cli_cm_open(TALLOC_CTX *ctx, -- struct cli_state *referring_cli, -- const char *server, -- const char *share, -- const struct user_auth_info *auth_info, -- int max_protocol, -- const struct sockaddr_storage *dest_ss, -- int port, -- int name_type, -- struct cli_state **pcli); -+ struct cli_state *referring_cli, -+ const char *server, -+ const char *share, -+ struct cli_credentials *creds, -+ int max_protocol, -+ const struct sockaddr_storage *dest_ss, -+ int port, -+ int name_type, -+ struct cli_state **pcli); - void cli_cm_display(struct cli_state *c); - struct client_dfs_referral; - NTSTATUS cli_dfs_get_referral_ex(TALLOC_CTX *ctx, --- -2.33.1 - - -From 5f3bd46bc86ca988491f9b3ce23a94ab13af471f Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Tue, 18 Aug 2020 17:42:25 +0200 -Subject: [PATCH 069/103] s3:libsmb: Pass cli_credentials to - cli_resolve_path(), using helper variables. - -Signed-off-by: Andreas Schneider -Signed-off-by: Jeremy Allison -(cherry picked from commit 5245ab3c4dacc88d5cbe3bb1e3e339e4fb77a4db) ---- - source3/client/client.c | 148 +++++++++++++++++++++++++++------- - source3/libsmb/clidfs.c | 5 +- - source3/libsmb/libsmb_dir.c | 43 ++++++++-- - source3/libsmb/libsmb_file.c | 13 ++- - source3/libsmb/libsmb_stat.c | 6 +- - source3/libsmb/libsmb_xattr.c | 13 ++- - source3/libsmb/proto.h | 2 +- - source3/utils/smbcacls.c | 5 +- - 8 files changed, 188 insertions(+), 47 deletions(-) - -diff --git a/source3/client/client.c b/source3/client/client.c -index c54b5065b44..13e48f80a01 100644 ---- a/source3/client/client.c -+++ b/source3/client/client.c -@@ -298,9 +298,14 @@ static int do_dskattr(void) - struct cli_state *targetcli = NULL; - char *targetpath = NULL; - TALLOC_CTX *ctx = talloc_tos(); -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), cli, -+ status = cli_resolve_path(ctx, -+ "", -+ creds, -+ cli, - client_get_cur_dir(), &targetcli, - &targetpath); - if (!NT_STATUS_IS_OK(status)) { -@@ -390,6 +395,8 @@ static int do_cd(const char *new_dir) - uint32_t attributes; - int ret = 1; - TALLOC_CTX *ctx = talloc_stackframe(); -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - - newdir = talloc_strdup(ctx, new_dir); -@@ -432,7 +439,8 @@ static int do_cd(const char *new_dir) - new_cd = client_clean_name(ctx, new_cd); - client_set_cur_dir(new_cd); - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, new_cd, &targetcli, &targetpath); - if (!NT_STATUS_IS_OK(status)) { - d_printf("cd %s: %s\n", new_cd, nt_errstr(status)); -@@ -809,6 +817,8 @@ NTSTATUS do_list(const char *mask, - TALLOC_CTX *ctx = talloc_tos(); - struct cli_state *targetcli = NULL; - char *targetpath = NULL; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS ret_status = NT_STATUS_OK; - NTSTATUS status = NT_STATUS_OK; - -@@ -832,7 +842,7 @@ NTSTATUS do_list(const char *mask, - /* check for dfs */ - - status = cli_resolve_path(ctx, "", -- popt_get_cmdline_auth_info(), -+ creds, - cli, head, &targetcli, &targetpath); - if (!NT_STATUS_IS_OK(status)) { - d_printf("do_list: [%s] %s\n", head, -@@ -1042,6 +1052,8 @@ static int do_get(const char *rname, const char *lname_in, bool reget) - struct cli_state *targetcli = NULL; - char *targetname = NULL; - char *lname = NULL; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - - lname = talloc_strdup(ctx, lname_in); -@@ -1056,7 +1068,8 @@ static int do_get(const char *rname, const char *lname_in, bool reget) - } - } - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, rname, &targetcli, &targetname); - if (!NT_STATUS_IS_OK(status)) { - d_printf("Failed to open %s: %s\n", rname, nt_errstr(status)); -@@ -1413,9 +1426,12 @@ static bool do_mkdir(const char *name) - TALLOC_CTX *ctx = talloc_tos(); - struct cli_state *targetcli; - char *targetname = NULL; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, name, &targetcli, &targetname); - if (!NT_STATUS_IS_OK(status)) { - d_printf("mkdir %s: %s\n", name, nt_errstr(status)); -@@ -1474,6 +1490,8 @@ static int cmd_mkdir(void) - TALLOC_CTX *ctx = talloc_tos(); - char *mask = NULL; - char *buf = NULL; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - - mask = talloc_strdup(ctx, client_get_cur_dir()); -@@ -1510,7 +1528,8 @@ static int cmd_mkdir(void) - } - - status = cli_resolve_path(ctx, "", -- popt_get_cmdline_auth_info(), cli, mask, -+ creds, -+ cli, mask, - &targetcli, &targetname); - if (!NT_STATUS_IS_OK(status)) { - return 1; -@@ -1824,9 +1843,12 @@ static int do_put(const char *rname, const char *lname, bool reput) - struct cli_state *targetcli; - char *targetname = NULL; - struct push_state state; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, rname, &targetcli, &targetname); - if (!NT_STATUS_IS_OK(status)) { - d_printf("Failed to open %s: %s\n", rname, nt_errstr(status)); -@@ -2601,6 +2623,8 @@ static int cmd_wdel(void) - uint32_t attribute; - struct cli_state *targetcli; - char *targetname = NULL; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - - if (!next_token_talloc(ctx, &cmd_ptr,&buf,NULL)) { -@@ -2626,7 +2650,8 @@ static int cmd_wdel(void) - return 1; - } - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, mask, &targetcli, &targetname); - if (!NT_STATUS_IS_OK(status)) { - d_printf("cmd_wdel %s: %s\n", mask, nt_errstr(status)); -@@ -2652,6 +2677,8 @@ static int cmd_open(void) - char *targetname = NULL; - struct cli_state *targetcli; - uint16_t fnum = (uint16_t)-1; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - - if (!next_token_talloc(ctx, &cmd_ptr,&buf,NULL)) { -@@ -2671,7 +2698,8 @@ static int cmd_open(void) - return 1; - } - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, mask, &targetcli, &targetname); - if (!NT_STATUS_IS_OK(status)) { - d_printf("open %s: %s\n", mask, nt_errstr(status)); -@@ -2773,6 +2801,8 @@ static int cmd_posix_open(void) - struct cli_state *targetcli; - mode_t mode; - uint16_t fnum; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - - if (!next_token_talloc(ctx, &cmd_ptr,&buf,NULL)) { -@@ -2797,7 +2827,8 @@ static int cmd_posix_open(void) - } - mode = (mode_t)strtol(buf, (char **)NULL, 8); - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, mask, &targetcli, &targetname); - if (!NT_STATUS_IS_OK(status)) { - d_printf("posix_open %s: %s\n", mask, nt_errstr(status)); -@@ -2832,6 +2863,8 @@ static int cmd_posix_mkdir(void) - char *targetname = NULL; - struct cli_state *targetcli; - mode_t mode; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - - if (!next_token_talloc(ctx, &cmd_ptr,&buf,NULL)) { -@@ -2856,7 +2889,8 @@ static int cmd_posix_mkdir(void) - } - mode = (mode_t)strtol(buf, (char **)NULL, 8); - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, mask, &targetcli, &targetname); - if (!NT_STATUS_IS_OK(status)) { - d_printf("posix_mkdir %s: %s\n", mask, nt_errstr(status)); -@@ -2880,6 +2914,8 @@ static int cmd_posix_unlink(void) - char *buf = NULL; - char *targetname = NULL; - struct cli_state *targetcli; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - - if (!next_token_talloc(ctx, &cmd_ptr,&buf,NULL)) { -@@ -2898,7 +2934,8 @@ static int cmd_posix_unlink(void) - return 1; - } - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, mask, &targetcli, &targetname); - if (!NT_STATUS_IS_OK(status)) { - d_printf("posix_unlink %s: %s\n", mask, nt_errstr(status)); -@@ -2923,6 +2960,8 @@ static int cmd_posix_rmdir(void) - char *buf = NULL; - char *targetname = NULL; - struct cli_state *targetcli; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - - if (!next_token_talloc(ctx, &cmd_ptr,&buf,NULL)) { -@@ -2941,7 +2980,8 @@ static int cmd_posix_rmdir(void) - return 1; - } - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, mask, &targetcli, &targetname); - if (!NT_STATUS_IS_OK(status)) { - d_printf("posix_rmdir %s: %s\n", mask, nt_errstr(status)); -@@ -3230,6 +3270,8 @@ static int cmd_rmdir(void) - char *buf = NULL; - char *targetname = NULL; - struct cli_state *targetcli; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - - if (!next_token_talloc(ctx, &cmd_ptr,&buf,NULL)) { -@@ -3248,7 +3290,8 @@ static int cmd_rmdir(void) - return 1; - } - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, mask, &targetcli, &targetname); - if (!NT_STATUS_IS_OK(status)) { - d_printf("rmdir %s: %s\n", mask, nt_errstr(status)); -@@ -3277,6 +3320,8 @@ static int cmd_link(void) - char *buf2 = NULL; - char *targetname = NULL; - struct cli_state *targetcli; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - - if (!next_token_talloc(ctx, &cmd_ptr,&buf,NULL) || -@@ -3307,7 +3352,8 @@ static int cmd_link(void) - return 1; - } - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, oldname, &targetcli, &targetname); - if (!NT_STATUS_IS_OK(status)) { - d_printf("link %s: %s\n", oldname, nt_errstr(status)); -@@ -3340,6 +3386,8 @@ static int cmd_readlink(void) - char *targetname = NULL; - char *linkname = NULL; - struct cli_state *targetcli; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - - if (!next_token_talloc(ctx, &cmd_ptr,&buf,NULL)) { -@@ -3358,7 +3406,8 @@ static int cmd_readlink(void) - return 1; - } - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, name, &targetcli, &targetname); - if (!NT_STATUS_IS_OK(status)) { - d_printf("readlink %s: %s\n", name, nt_errstr(status)); -@@ -3397,6 +3446,8 @@ static int cmd_symlink(void) - char *buf = NULL; - char *buf2 = NULL; - struct cli_state *newcli; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - - if (!next_token_talloc(ctx, &cmd_ptr,&buf,NULL) || -@@ -3419,7 +3470,8 @@ static int cmd_symlink(void) - } - /* New name must be present in share namespace. */ - status = cli_resolve_path(ctx, "", -- popt_get_cmdline_auth_info(), cli, newname, -+ creds, -+ cli, newname, - &newcli, &newname); - if (!NT_STATUS_IS_OK(status)) { - d_printf("link %s: %s\n", newname, -@@ -3455,6 +3507,8 @@ static int cmd_chmod(void) - char *targetname = NULL; - struct cli_state *targetcli; - mode_t mode; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - - if (!next_token_talloc(ctx, &cmd_ptr,&buf,NULL) || -@@ -3476,7 +3530,8 @@ static int cmd_chmod(void) - - mode = (mode_t)strtol(buf, NULL, 8); - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, src, &targetcli, &targetname); - if (!NT_STATUS_IS_OK(status)) { - d_printf("chmod %s: %s\n", src, nt_errstr(status)); -@@ -3620,6 +3675,8 @@ static int cmd_getfacl(void) - size_t num_dir_acls = 0; - size_t expected_buflen; - uint16_t i; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - - if (!next_token_talloc(ctx, &cmd_ptr,&name,NULL)) { -@@ -3638,7 +3695,8 @@ static int cmd_getfacl(void) - return 1; - } - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, src, &targetcli, &targetname); - if (!NT_STATUS_IS_OK(status)) { - d_printf("stat %s: %s\n", src, nt_errstr(status)); -@@ -3803,6 +3861,8 @@ static int cmd_geteas(void) - NTSTATUS status; - size_t i, num_eas; - struct ea_struct *eas; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - - if (!next_token_talloc(ctx, &cmd_ptr,&name,NULL)) { - d_printf("geteas filename\n"); -@@ -3820,7 +3880,8 @@ static int cmd_geteas(void) - return 1; - } - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, src, &targetcli, &targetname); - if (!NT_STATUS_IS_OK(status)) { - d_printf("stat %s: %s\n", src, nt_errstr(status)); -@@ -3859,6 +3920,8 @@ static int cmd_setea(void) - char *eavalue = NULL; - char *targetname = NULL; - struct cli_state *targetcli; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - - if (!next_token_talloc(ctx, &cmd_ptr, &name, NULL) -@@ -3881,7 +3944,8 @@ static int cmd_setea(void) - return 1; - } - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, src, &targetcli, &targetname); - if (!NT_STATUS_IS_OK(status)) { - d_printf("stat %s: %s\n", src, nt_errstr(status)); -@@ -3913,6 +3977,8 @@ static int cmd_stat(void) - SMB_STRUCT_STAT sbuf; - struct tm *lt; - time_t tmp_time; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - - if (!next_token_talloc(ctx, &cmd_ptr,&name,NULL)) { -@@ -3931,7 +3997,8 @@ static int cmd_stat(void) - return 1; - } - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, src, &targetcli, &targetname); - if (!NT_STATUS_IS_OK(status)) { - d_printf("stat %s: %s\n", src, nt_errstr(status)); -@@ -4020,6 +4087,8 @@ static int cmd_chown(void) - char *buf, *buf2, *buf3; - struct cli_state *targetcli; - char *targetname = NULL; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - - if (!next_token_talloc(ctx, &cmd_ptr,&buf,NULL) || -@@ -4043,7 +4112,8 @@ static int cmd_chown(void) - if (src == NULL) { - return 1; - } -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, src, &targetcli, &targetname); - if (!NT_STATUS_IS_OK(status)) { - d_printf("chown %s: %s\n", src, nt_errstr(status)); -@@ -4077,6 +4147,8 @@ static int cmd_rename(void) - struct cli_state *targetcli; - char *targetsrc; - char *targetdest; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - bool replace = false; - -@@ -4115,14 +4187,16 @@ static int cmd_rename(void) - replace = true; - } - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, src, &targetcli, &targetsrc); - if (!NT_STATUS_IS_OK(status)) { - d_printf("rename %s: %s\n", src, nt_errstr(status)); - return 1; - } - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, dest, &targetcli, &targetdest); - if (!NT_STATUS_IS_OK(status)) { - d_printf("rename %s: %s\n", dest, nt_errstr(status)); -@@ -4179,6 +4253,8 @@ static int cmd_scopy(void) - off_t written = 0; - struct scopy_timing st; - int rc = 0; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - - if (!next_token_talloc(ctx, &cmd_ptr,&buf,NULL) || -@@ -4211,14 +4287,16 @@ static int cmd_scopy(void) - return 1; - } - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, src, &targetcli, &targetsrc); - if (!NT_STATUS_IS_OK(status)) { - d_printf("scopy %s: %s\n", src, nt_errstr(status)); - return 1; - } - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, dest, &targetcli, &targetdest); - if (!NT_STATUS_IS_OK(status)) { - d_printf("scopy %s: %s\n", dest, nt_errstr(status)); -@@ -4317,6 +4395,8 @@ static int cmd_hardlink(void) - char *buf, *buf2; - struct cli_state *targetcli; - char *targetname; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - - if (!next_token_talloc(ctx, &cmd_ptr,&buf,NULL) || -@@ -4349,7 +4429,8 @@ static int cmd_hardlink(void) - return 1; - } - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, src, &targetcli, &targetname); - if (!NT_STATUS_IS_OK(status)) { - d_printf("hardlink %s: %s\n", src, nt_errstr(status)); -@@ -5023,9 +5104,13 @@ static int cmd_show_connect( void ) - TALLOC_CTX *ctx = talloc_tos(); - struct cli_state *targetcli; - char *targetpath; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), cli, -+ status = cli_resolve_path(ctx, "", -+ creds, -+ cli, - client_get_cur_dir(), &targetcli, - &targetpath); - if (!NT_STATUS_IS_OK(status)) { -@@ -5685,6 +5770,8 @@ static char **remote_completion(const char *text, int len) - struct cli_state *targetcli = NULL; - int i; - struct completion_remote info = { NULL, NULL, 1, 0, NULL, 0 }; -+ struct cli_credentials *creds = -+ get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()); - NTSTATUS status; - - /* can't have non-static initialisation on Sun CC, so do it -@@ -5745,7 +5832,8 @@ static char **remote_completion(const char *text, int len) - goto cleanup; - } - -- status = cli_resolve_path(ctx, "", popt_get_cmdline_auth_info(), -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, dirmask, &targetcli, &targetpath); - if (!NT_STATUS_IS_OK(status)) { - goto cleanup; -diff --git a/source3/libsmb/clidfs.c b/source3/libsmb/clidfs.c -index 5b04b63634f..b4b8057ed2f 100644 ---- a/source3/libsmb/clidfs.c -+++ b/source3/libsmb/clidfs.c -@@ -883,7 +883,7 @@ struct cli_dfs_path_split { - - NTSTATUS cli_resolve_path(TALLOC_CTX *ctx, - const char *mountpt, -- const struct user_auth_info *dfs_auth_info, -+ struct cli_credentials *creds, - struct cli_state *rootcli, - const char *path, - struct cli_state **targetcli, -@@ -909,7 +909,6 @@ NTSTATUS cli_resolve_path(TALLOC_CTX *ctx, - struct smbXcli_tcon *root_tcon = NULL; - struct smbXcli_tcon *target_tcon = NULL; - struct cli_dfs_path_split *dfs_refs = NULL; -- struct cli_credentials *creds = get_cmdline_auth_info_creds(dfs_auth_info); - - if ( !rootcli || !path || !targetcli ) { - return NT_STATUS_INVALID_PARAMETER; -@@ -1154,7 +1153,7 @@ NTSTATUS cli_resolve_path(TALLOC_CTX *ctx, - if (!strequal(*pp_targetpath, "\\") && !strequal(*pp_targetpath, "/")) { - status = cli_resolve_path(ctx, - newmount, -- dfs_auth_info, -+ creds, - *targetcli, - *pp_targetpath, - &newcli, -diff --git a/source3/libsmb/libsmb_dir.c b/source3/libsmb/libsmb_dir.c -index 12abb734c2d..0326f27125b 100644 ---- a/source3/libsmb/libsmb_dir.c -+++ b/source3/libsmb/libsmb_dir.c -@@ -911,6 +911,7 @@ SMBC_opendir_ctx(SMBCCTX *context, - */ - char *targetpath; - struct cli_state *targetcli; -+ struct cli_credentials *creds = NULL; - NTSTATUS status; - - /* We connect to the server and list the directory */ -@@ -943,8 +944,12 @@ SMBC_opendir_ctx(SMBCCTX *context, - return NULL; - } - -+ creds = get_cmdline_auth_info_creds( -+ context->internal->auth_info); -+ - status = cli_resolve_path( -- frame, "", context->internal->auth_info, -+ frame, "", -+ creds, - srv->cli, path, &targetcli, &targetpath); - if (!NT_STATUS_IS_OK(status)) { - d_printf("Could not resolve %s\n", path); -@@ -1543,6 +1548,7 @@ SMBC_mkdir_ctx(SMBCCTX *context, - char *targetpath = NULL; - uint16_t port = 0; - struct cli_state *targetcli = NULL; -+ struct cli_credentials *creds = NULL; - TALLOC_CTX *frame = talloc_stackframe(); - NTSTATUS status; - -@@ -1595,8 +1601,11 @@ SMBC_mkdir_ctx(SMBCCTX *context, - - } - -+ creds = get_cmdline_auth_info_creds(context->internal->auth_info); -+ - /*d_printf(">>>mkdir: resolving %s\n", path);*/ -- status = cli_resolve_path(frame, "", context->internal->auth_info, -+ status = cli_resolve_path(frame, "", -+ creds, - srv->cli, path, &targetcli, &targetpath); - if (!NT_STATUS_IS_OK(status)) { - d_printf("Could not resolve %s\n", path); -@@ -1654,6 +1663,7 @@ SMBC_rmdir_ctx(SMBCCTX *context, - char *targetpath = NULL; - uint16_t port = 0; - struct cli_state *targetcli = NULL; -+ struct cli_credentials *creds = NULL; - TALLOC_CTX *frame = talloc_stackframe(); - NTSTATUS status; - -@@ -1706,8 +1716,11 @@ SMBC_rmdir_ctx(SMBCCTX *context, - - } - -+ creds = get_cmdline_auth_info_creds(context->internal->auth_info), -+ - /*d_printf(">>>rmdir: resolving %s\n", path);*/ -- status = cli_resolve_path(frame, "", context->internal->auth_info, -+ status = cli_resolve_path(frame, "", -+ creds, - srv->cli, path, &targetcli, &targetpath); - if (!NT_STATUS_IS_OK(status)) { - d_printf("Could not resolve %s\n", path); -@@ -1959,6 +1972,7 @@ SMBC_chmod_ctx(SMBCCTX *context, - char *path = NULL; - uint32_t attr; - uint16_t port = 0; -+ struct cli_credentials *creds = NULL; - TALLOC_CTX *frame = talloc_stackframe(); - NTSTATUS status; - -@@ -2010,8 +2024,11 @@ SMBC_chmod_ctx(SMBCCTX *context, - return -1; /* errno set by SMBC_server */ - } - -+ creds = get_cmdline_auth_info_creds(context->internal->auth_info); -+ - /*d_printf(">>>unlink: resolving %s\n", path);*/ -- status = cli_resolve_path(frame, "", context->internal->auth_info, -+ status = cli_resolve_path(frame, "", -+ creds, - srv->cli, path, &targetcli, &targetpath); - if (!NT_STATUS_IS_OK(status)) { - d_printf("Could not resolve %s\n", path); -@@ -2152,6 +2169,7 @@ SMBC_unlink_ctx(SMBCCTX *context, - uint16_t port = 0; - struct cli_state *targetcli = NULL; - SMBCSRV *srv = NULL; -+ struct cli_credentials *creds = NULL; - TALLOC_CTX *frame = talloc_stackframe(); - NTSTATUS status; - -@@ -2204,8 +2222,11 @@ SMBC_unlink_ctx(SMBCCTX *context, - - } - -+ creds = get_cmdline_auth_info_creds(context->internal->auth_info); -+ - /*d_printf(">>>unlink: resolving %s\n", path);*/ -- status = cli_resolve_path(frame, "", context->internal->auth_info, -+ status = cli_resolve_path(frame, "", -+ creds, - srv->cli, path, &targetcli, &targetpath); - if (!NT_STATUS_IS_OK(status)) { - d_printf("Could not resolve %s\n", path); -@@ -2282,6 +2303,8 @@ SMBC_rename_ctx(SMBCCTX *ocontext, - SMBCSRV *srv = NULL; - uint16_t port1 = 0; - uint16_t port2 = 0; -+ struct cli_credentials *ocreds = NULL; -+ struct cli_credentials *ncreds = NULL; - TALLOC_CTX *frame = talloc_stackframe(); - NTSTATUS status; - -@@ -2375,7 +2398,10 @@ SMBC_rename_ctx(SMBCCTX *ocontext, - password1); - - /*d_printf(">>>rename: resolving %s\n", path1);*/ -- status = cli_resolve_path(frame, "", ocontext->internal->auth_info, -+ ocreds = get_cmdline_auth_info_creds(ocontext->internal->auth_info); -+ -+ status = cli_resolve_path(frame, "", -+ ocreds, - srv->cli, path1, &targetcli1, &targetpath1); - if (!NT_STATUS_IS_OK(status)) { - d_printf("Could not resolve %s\n", path1); -@@ -2392,7 +2418,10 @@ SMBC_rename_ctx(SMBCCTX *ocontext, - - /*d_printf(">>>rename: resolved path as %s\n", targetpath1);*/ - /*d_printf(">>>rename: resolving %s\n", path2);*/ -- status = cli_resolve_path(frame, "", ncontext->internal->auth_info, -+ ncreds = get_cmdline_auth_info_creds(ncontext->internal->auth_info); -+ -+ status = cli_resolve_path(frame, "", -+ ncreds, - srv->cli, path2, &targetcli2, &targetpath2); - if (!NT_STATUS_IS_OK(status)) { - d_printf("Could not resolve %s\n", path2); -diff --git a/source3/libsmb/libsmb_file.c b/source3/libsmb/libsmb_file.c -index 0791df36690..a44925e0e0e 100644 ---- a/source3/libsmb/libsmb_file.c -+++ b/source3/libsmb/libsmb_file.c -@@ -103,6 +103,8 @@ SMBC_open_ctx(SMBCCTX *context, - if (strlen(path) > 0 && path[strlen(path) - 1] == '\\') { - status = NT_STATUS_OBJECT_PATH_INVALID; - } else { -+ struct cli_credentials *creds = NULL; -+ - file = SMB_MALLOC_P(SMBCFILE); - if (!file) { - errno = ENOMEM; -@@ -112,9 +114,12 @@ SMBC_open_ctx(SMBCCTX *context, - - ZERO_STRUCTP(file); - -+ creds = get_cmdline_auth_info_creds( -+ context->internal->auth_info); - /*d_printf(">>>open: resolving %s\n", path);*/ - status = cli_resolve_path( -- frame, "", context->internal->auth_info, -+ frame, "", -+ creds, - srv->cli, path, &targetcli, &targetpath); - if (!NT_STATUS_IS_OK(status)) { - d_printf("Could not resolve %s\n", path); -@@ -461,6 +466,7 @@ SMBC_getatr(SMBCCTX * context, - struct timespec change_time_ts = {0}; - time_t write_time = 0; - SMB_INO_T ino = 0; -+ struct cli_credentials *creds = NULL; - TALLOC_CTX *frame = talloc_stackframe(); - NTSTATUS status; - -@@ -490,7 +496,10 @@ SMBC_getatr(SMBCCTX * context, - } - DEBUG(4,("SMBC_getatr: sending qpathinfo\n")); - -- status = cli_resolve_path(frame, "", context->internal->auth_info, -+ creds = get_cmdline_auth_info_creds(context->internal->auth_info); -+ -+ status = cli_resolve_path(frame, "", -+ creds, - srv->cli, fixedpath, - &targetcli, &targetpath); - if (!NT_STATUS_IS_OK(status)) { -diff --git a/source3/libsmb/libsmb_stat.c b/source3/libsmb/libsmb_stat.c -index 790934bd565..1260928d0ff 100644 ---- a/source3/libsmb/libsmb_stat.c -+++ b/source3/libsmb/libsmb_stat.c -@@ -242,6 +242,7 @@ SMBC_fstat_ctx(SMBCCTX *context, - struct cli_state *targetcli = NULL; - SMB_INO_T ino = 0; - uint16_t port = 0; -+ struct cli_credentials *creds = NULL; - TALLOC_CTX *frame = talloc_stackframe(); - NTSTATUS status; - -@@ -279,8 +280,11 @@ SMBC_fstat_ctx(SMBCCTX *context, - return -1; - } - -+ creds = get_cmdline_auth_info_creds(context->internal->auth_info); -+ - /*d_printf(">>>fstat: resolving %s\n", path);*/ -- status = cli_resolve_path(frame, "", context->internal->auth_info, -+ status = cli_resolve_path(frame, "", -+ creds, - file->srv->cli, path, - &targetcli, &targetpath); - if (!NT_STATUS_IS_OK(status)) { -diff --git a/source3/libsmb/libsmb_xattr.c b/source3/libsmb/libsmb_xattr.c -index d1b6548eb90..8b74d0a39e3 100644 ---- a/source3/libsmb/libsmb_xattr.c -+++ b/source3/libsmb/libsmb_xattr.c -@@ -860,13 +860,18 @@ cacl_get(SMBCCTX *context, - if (ipc_cli && (all || some_nt || all_nt_acls)) { - char *targetpath = NULL; - struct cli_state *targetcli = NULL; -+ struct cli_credentials *creds = NULL; - NTSTATUS status; - - /* Point to the portion after "system.nt_sec_desc." */ - name += 19; /* if (all) this will be invalid but unused */ - -+ creds = get_cmdline_auth_info_creds( -+ context->internal->auth_info); -+ - status = cli_resolve_path( -- ctx, "", context->internal->auth_info, -+ ctx, "", -+ creds, - cli, filename, &targetcli, &targetpath); - if (!NT_STATUS_IS_OK(status)) { - DEBUG(5, ("cacl_get Could not resolve %s\n", -@@ -1511,6 +1516,7 @@ cacl_set(SMBCCTX *context, - bool numeric = True; - char *targetpath = NULL; - struct cli_state *targetcli = NULL; -+ struct cli_credentials *creds = NULL; - NTSTATUS status; - - /* the_acl will be null for REMOVE_ALL operations */ -@@ -1540,7 +1546,10 @@ cacl_set(SMBCCTX *context, - return -1; - } - -- status = cli_resolve_path(ctx, "", context->internal->auth_info, -+ creds = get_cmdline_auth_info_creds(context->internal->auth_info); -+ -+ status = cli_resolve_path(ctx, "", -+ creds, - cli, filename, &targetcli, &targetpath); - if (!NT_STATUS_IS_OK(status)) { - DEBUG(5,("cacl_set: Could not resolve %s\n", filename)); -diff --git a/source3/libsmb/proto.h b/source3/libsmb/proto.h -index 0b8cf2a6036..517738dbcd7 100644 ---- a/source3/libsmb/proto.h -+++ b/source3/libsmb/proto.h -@@ -150,7 +150,7 @@ NTSTATUS cli_dfs_get_referral(TALLOC_CTX *ctx, - size_t *consumed); - NTSTATUS cli_resolve_path(TALLOC_CTX *ctx, - const char *mountpt, -- const struct user_auth_info *dfs_auth_info, -+ struct cli_credentials *creds, - struct cli_state *rootcli, - const char *path, - struct cli_state **targetcli, -diff --git a/source3/utils/smbcacls.c b/source3/utils/smbcacls.c -index 8fd9fcc5780..4989ec633c3 100644 ---- a/source3/utils/smbcacls.c -+++ b/source3/utils/smbcacls.c -@@ -806,6 +806,7 @@ int main(int argc, char *argv[]) - than going via LSA calls to resolve them */ - int numeric = 0; - struct cli_state *targetcli = NULL; -+ struct cli_credentials *creds = NULL; - char *targetfile = NULL; - NTSTATUS status; - -@@ -1069,9 +1070,11 @@ int main(int argc, char *argv[]) - } - } - -+ creds = get_cmdline_auth_info_creds(popt_get_cmdline_auth_info()), -+ - status = cli_resolve_path(frame, - "", -- popt_get_cmdline_auth_info(), -+ creds, - cli, - filename, - &targetcli, --- -2.33.1 - - -From e6f06ec0efd3138a4785fb762b39e03b326fc23a Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 27 Aug 2020 16:40:49 +0200 -Subject: [PATCH 070/103] s3:client: Remove global max_protocol - -Signed-off-by: Andreas Schneider -Reviewed-by: Jeremy Allison -(cherry picked from commit d07f28645f37c1f976017d5b89864791a18d1943) ---- - source3/client/client.c | 13 +++++-------- - 1 file changed, 5 insertions(+), 8 deletions(-) - -diff --git a/source3/client/client.c b/source3/client/client.c -index 13e48f80a01..902cdec8b64 100644 ---- a/source3/client/client.c -+++ b/source3/client/client.c -@@ -61,7 +61,6 @@ static int io_bufsize = 0; /* we use the default size */ - static int io_timeout = (CLIENT_TIMEOUT/1000); /* Per operation timeout (in seconds). */ - - static int name_type = 0x20; --static int max_protocol = -1; - - static int process_tok(char *tok); - static int cmd_help(void); -@@ -5646,7 +5645,7 @@ static int process_command_string(const char *cmd_in) - desthost, - service, - creds, -- max_protocol, -+ lp_client_max_protocol(), - have_ip ? &dest_ss : NULL, port, - name_type, - &cli); -@@ -6096,7 +6095,7 @@ static int process(const char *base_directory) - desthost, - service, - creds, -- max_protocol, -+ lp_client_max_protocol(), - have_ip ? &dest_ss : NULL, port, - name_type, &cli); - if (!NT_STATUS_IS_OK(status)) { -@@ -6137,7 +6136,7 @@ static int do_host_query(const char *query_host) - query_host, - "IPC$", - creds, -- max_protocol, -+ lp_client_max_protocol(), - have_ip ? &dest_ss : NULL, port, - name_type, &cli); - if (!NT_STATUS_IS_OK(status)) { -@@ -6172,7 +6171,7 @@ static int do_host_query(const char *query_host) - if (port != NBT_SMB_PORT || - smbXcli_conn_protocol(cli->conn) > PROTOCOL_NT1) - { -- int max_proto = MIN(max_protocol, PROTOCOL_NT1); -+ int max_proto = MIN(lp_client_max_protocol(), PROTOCOL_NT1); - - /* - * Workgroups simply don't make sense over anything -@@ -6222,7 +6221,7 @@ static int do_tar_op(const char *base_directory) - desthost, - service, - creds, -- max_protocol, -+ lp_client_max_protocol(), - have_ip ? &dest_ss : NULL, port, - name_type, &cli); - if (!NT_STATUS_IS_OK(status)) { -@@ -6629,8 +6628,6 @@ int main(int argc,char *argv[]) - /* Ensure we have a password (or equivalent). */ - popt_common_credentials_post(); - -- max_protocol = lp_client_max_protocol(); -- - if (tar_to_process(tar_ctx)) { - if (cmdstr) - process_command_string(cmdstr); --- -2.33.1 - - -From 62bf2411cfb8057e7ea98f826bf619244e3f1035 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 27 Aug 2020 16:43:46 +0200 -Subject: [PATCH 071/103] s3:libsmb: Remove max_protocol from cli_cm_open() - -Signed-off-by: Andreas Schneider -Reviewed-by: Jeremy Allison -(cherry picked from commit 4aac9daf095e7c2de6a27697a13385ee87a4b634) ---- - source3/client/client.c | 7 ------- - source3/lib/netapi/cm.c | 1 - - source3/libsmb/clidfs.c | 4 +--- - source3/libsmb/proto.h | 1 - - 4 files changed, 1 insertion(+), 12 deletions(-) - -diff --git a/source3/client/client.c b/source3/client/client.c -index 902cdec8b64..82764c5ca16 100644 ---- a/source3/client/client.c -+++ b/source3/client/client.c -@@ -5645,7 +5645,6 @@ static int process_command_string(const char *cmd_in) - desthost, - service, - creds, -- lp_client_max_protocol(), - have_ip ? &dest_ss : NULL, port, - name_type, - &cli); -@@ -6095,7 +6094,6 @@ static int process(const char *base_directory) - desthost, - service, - creds, -- lp_client_max_protocol(), - have_ip ? &dest_ss : NULL, port, - name_type, &cli); - if (!NT_STATUS_IS_OK(status)) { -@@ -6136,7 +6134,6 @@ static int do_host_query(const char *query_host) - query_host, - "IPC$", - creds, -- lp_client_max_protocol(), - have_ip ? &dest_ss : NULL, port, - name_type, &cli); - if (!NT_STATUS_IS_OK(status)) { -@@ -6171,8 +6168,6 @@ static int do_host_query(const char *query_host) - if (port != NBT_SMB_PORT || - smbXcli_conn_protocol(cli->conn) > PROTOCOL_NT1) - { -- int max_proto = MIN(lp_client_max_protocol(), PROTOCOL_NT1); -- - /* - * Workgroups simply don't make sense over anything - * else but port 139 and SMB1. -@@ -6184,7 +6179,6 @@ static int do_host_query(const char *query_host) - query_host, - "IPC$", - creds, -- max_proto, - have_ip ? &dest_ss : NULL, NBT_SMB_PORT, - name_type, &cli); - if (!NT_STATUS_IS_OK(status)) { -@@ -6221,7 +6215,6 @@ static int do_tar_op(const char *base_directory) - desthost, - service, - creds, -- lp_client_max_protocol(), - have_ip ? &dest_ss : NULL, port, - name_type, &cli); - if (!NT_STATUS_IS_OK(status)) { -diff --git a/source3/lib/netapi/cm.c b/source3/lib/netapi/cm.c -index 943f7498e8c..3f4e188b396 100644 ---- a/source3/lib/netapi/cm.c -+++ b/source3/lib/netapi/cm.c -@@ -112,7 +112,6 @@ static WERROR libnetapi_open_ipc_connection(struct libnetapi_ctx *ctx, - status = cli_cm_open(ctx, NULL, - server_name, "IPC$", - creds, -- lp_client_ipc_max_protocol(), - NULL, 0, 0x20, &cli_ipc); - if (!NT_STATUS_IS_OK(status)) { - cli_ipc = NULL; -diff --git a/source3/libsmb/clidfs.c b/source3/libsmb/clidfs.c -index b4b8057ed2f..eb7da18c5ce 100644 ---- a/source3/libsmb/clidfs.c -+++ b/source3/libsmb/clidfs.c -@@ -412,7 +412,6 @@ NTSTATUS cli_cm_open(TALLOC_CTX *ctx, - const char *server, - const char *share, - struct cli_credentials *creds, -- int max_protocol, - const struct sockaddr_storage *dest_ss, - int port, - int name_type, -@@ -441,7 +440,7 @@ NTSTATUS cli_cm_open(TALLOC_CTX *ctx, - server, - share, - creds, -- max_protocol, -+ lp_client_max_protocol(), - dest_ss, - port, - name_type, -@@ -989,7 +988,6 @@ NTSTATUS cli_resolve_path(TALLOC_CTX *ctx, - smbXcli_conn_remote_name(rootcli->conn), - "IPC$", - creds, -- smbXcli_conn_protocol(rootcli->conn), - NULL, /* dest_ss not needed, we reuse the transport */ - 0, - 0x20, -diff --git a/source3/libsmb/proto.h b/source3/libsmb/proto.h -index 517738dbcd7..8aaaff2cb1e 100644 ---- a/source3/libsmb/proto.h -+++ b/source3/libsmb/proto.h -@@ -128,7 +128,6 @@ NTSTATUS cli_cm_open(TALLOC_CTX *ctx, - const char *server, - const char *share, - struct cli_credentials *creds, -- int max_protocol, - const struct sockaddr_storage *dest_ss, - int port, - int name_type, --- -2.33.1 - - -From 7d1fb6232eb0769d2b5519cf1fb80bebbefe7200 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 27 Aug 2020 16:45:12 +0200 -Subject: [PATCH 072/103] s3:libcmb: Remove max_protocol from cli_cm_connect() - -Signed-off-by: Andreas Schneider -Reviewed-by: Jeremy Allison -(cherry picked from commit 2159582610ecc932047b85a77ec321b3d3ac806f) ---- - source3/libsmb/clidfs.c | 5 +---- - 1 file changed, 1 insertion(+), 4 deletions(-) - -diff --git a/source3/libsmb/clidfs.c b/source3/libsmb/clidfs.c -index eb7da18c5ce..88faf22507e 100644 ---- a/source3/libsmb/clidfs.c -+++ b/source3/libsmb/clidfs.c -@@ -317,7 +317,6 @@ static NTSTATUS cli_cm_connect(TALLOC_CTX *ctx, - const char *server, - const char *share, - struct cli_credentials *creds, -- int max_protocol, - const struct sockaddr_storage *dest_ss, - int port, - int name_type, -@@ -328,7 +327,7 @@ static NTSTATUS cli_cm_connect(TALLOC_CTX *ctx, - - status = do_connect(ctx, server, share, - creds, -- max_protocol, -+ lp_client_max_protocol(), - dest_ss, port, name_type, &cli); - - if (!NT_STATUS_IS_OK(status)) { -@@ -440,7 +439,6 @@ NTSTATUS cli_cm_open(TALLOC_CTX *ctx, - server, - share, - creds, -- lp_client_max_protocol(), - dest_ss, - port, - name_type, -@@ -1044,7 +1042,6 @@ NTSTATUS cli_resolve_path(TALLOC_CTX *ctx, - dfs_refs[count].server, - dfs_refs[count].share, - creds, -- smbXcli_conn_protocol(rootcli->conn), - NULL, /* dest_ss */ - 0, /* port */ - 0x20, --- -2.33.1 - - -From ec9acf69a3bc8ef8e90b18b84e772e705c8dc5ae Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 27 Aug 2020 16:46:29 +0200 -Subject: [PATCH 073/103] s3:libsmb: Remove max_protocol from clidfs - do_connect() - -The if check for max_protocol == 0 is part of lp_client_max_protocol(). - -Signed-off-by: Andreas Schneider -Reviewed-by: Jeremy Allison -(cherry picked from commit 50b59b4c28bc816094a4ca97f64450860e2495b2) ---- - source3/libsmb/clidfs.c | 8 +------- - 1 file changed, 1 insertion(+), 7 deletions(-) - -diff --git a/source3/libsmb/clidfs.c b/source3/libsmb/clidfs.c -index 88faf22507e..2c2e77b685a 100644 ---- a/source3/libsmb/clidfs.c -+++ b/source3/libsmb/clidfs.c -@@ -131,7 +131,6 @@ static NTSTATUS do_connect(TALLOC_CTX *ctx, - const char *server, - const char *share, - struct cli_credentials *creds, -- int max_protocol, - const struct sockaddr_storage *dest_ss, - int port, - int name_type, -@@ -191,14 +190,11 @@ static NTSTATUS do_connect(TALLOC_CTX *ctx, - return status; - } - -- if (max_protocol == 0) { -- max_protocol = PROTOCOL_LATEST; -- } - DEBUG(4,(" session request ok\n")); - - status = smbXcli_negprot(c->conn, c->timeout, - lp_client_min_protocol(), -- max_protocol); -+ lp_client_max_protocol()); - - if (!NT_STATUS_IS_OK(status)) { - d_printf("protocol negotiation failed: %s\n", -@@ -273,7 +269,6 @@ static NTSTATUS do_connect(TALLOC_CTX *ctx, - cli_shutdown(c); - return do_connect(ctx, newserver, - newshare, creds, -- max_protocol, - NULL, port, name_type, pcli); - } - -@@ -327,7 +322,6 @@ static NTSTATUS cli_cm_connect(TALLOC_CTX *ctx, - - status = do_connect(ctx, server, share, - creds, -- lp_client_max_protocol(), - dest_ss, port, name_type, &cli); - - if (!NT_STATUS_IS_OK(status)) { --- -2.33.1 - - -From 59037ca851f7072da88744a59e367f11742a895a Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Mon, 10 Aug 2020 15:47:35 +0200 -Subject: [PATCH 074/103] s3:include: Move loadparm prototypes to own header - file - -Signed-off-by: Andreas Schneider -Reviewed-by: Jeremy Allison -(cherry picked from commit d4d8218b9618dd289f54b41f13d7015f1b3994fd) ---- - source3/include/includes.h | 3 + - source3/include/proto.h | 167 ------------------------------- - source3/param/loadparm.h | 200 +++++++++++++++++++++++++++++++++++++ - 3 files changed, 203 insertions(+), 167 deletions(-) - create mode 100644 source3/param/loadparm.h - -diff --git a/source3/include/includes.h b/source3/include/includes.h -index 8fa65cc3122..c94f919ed59 100644 ---- a/source3/include/includes.h -+++ b/source3/include/includes.h -@@ -293,6 +293,9 @@ typedef char fstring[FSTRING_LEN]; - #endif - - #include "lib/param/loadparm.h" -+#include "source3/param/loadparm.h" -+/* Automatically generated by generate_param.py. */ -+#include "source3/param/param_proto.h" - - /* String routines */ - -diff --git a/source3/include/proto.h b/source3/include/proto.h -index de5d1be5208..4f14a2d546d 100644 ---- a/source3/include/proto.h -+++ b/source3/include/proto.h -@@ -740,173 +740,6 @@ NTSTATUS trust_pw_change(struct netlogon_creds_cli_context *context, - const char *dcname, - bool force); - --/* The following definitions come from param/loadparm.c */ -- --const struct loadparm_substitution *loadparm_s3_global_substitution(void); -- --char *lp_parm_substituted_string(TALLOC_CTX *mem_ctx, -- const struct loadparm_substitution *lp_sub, -- int snum, -- const char *type, -- const char *option, -- const char *def); -- --#include "source3/param/param_proto.h" -- --char *lp_servicename(TALLOC_CTX *ctx, const struct loadparm_substitution *, int); --const char *lp_const_servicename(int); --bool lp_autoloaded(int); --const char *lp_dnsdomain(void); --int lp_winbind_max_domain_connections(void); --bool lp_idmap_range(const char *domain_name, uint32_t *low, uint32_t *high); --bool lp_idmap_default_range(uint32_t *low, uint32_t *high); --const char *lp_idmap_backend(const char *domain_name); --const char *lp_idmap_default_backend (void); --int lp_security(void); --int lp_client_max_protocol(void); --int lp_client_ipc_min_protocol(void); --int lp_client_ipc_max_protocol(void); --int lp_client_ipc_signing(void); --int lp_smb2_max_credits(void); --int lp_cups_encrypt(void); --bool lp_widelinks(int ); --int lp_rpc_low_port(void); --int lp_rpc_high_port(void); --bool lp_lanman_auth(void); --enum samba_weak_crypto lp_weak_crypto(void); -- --int lp_wi_scan_global_parametrics( -- const char *regex, size_t max_matches, -- bool (*cb)(const char *string, regmatch_t matches[], -- void *private_data), -- void *private_data); -- --const char *lp_parm_const_string(int snum, const char *type, const char *option, const char *def); --struct loadparm_service; --const char *lp_parm_const_string_service(struct loadparm_service *service, const char *type, -- const char *option, const char *def); --const char **lp_parm_string_list(int snum, const char *type, const char *option, const char **def); --int lp_parm_int(int snum, const char *type, const char *option, int def); --unsigned long lp_parm_ulong(int snum, const char *type, const char *option, unsigned long def); --unsigned long long lp_parm_ulonglong(int snum, const char *type, -- const char *option, -- unsigned long long def); --bool lp_parm_bool(int snum, const char *type, const char *option, bool def); --struct enum_list; --int lp_parm_enum(int snum, const char *type, const char *option, -- const struct enum_list *_enum, int def); --char *canonicalize_servicename(TALLOC_CTX *ctx, const char *src); --bool lp_add_home(const char *pszHomename, int iDefaultService, -- const char *user, const char *pszHomedir); --int lp_add_service(const char *pszService, int iDefaultService); --bool lp_add_printer(const char *pszPrintername, int iDefaultService); --bool lp_parameter_is_valid(const char *pszParmName); --bool lp_parameter_is_global(const char *pszParmName); --bool lp_canonicalize_parameter(const char *parm_name, const char **canon_parm, -- bool *inverse); --bool lp_canonicalize_parameter_with_value(const char *parm_name, -- const char *val, -- const char **canon_parm, -- const char **canon_val); --void show_parameter_list(void); --bool lp_invert_boolean(const char *str, const char **inverse_str); --bool lp_canonicalize_boolean(const char *str, const char**canon_str); --bool process_registry_service(const char *service_name); --bool process_registry_shares(void); --bool lp_config_backend_is_registry(void); --bool lp_config_backend_is_file(void); --bool lp_file_list_changed(void); --const char *lp_ldap_machine_suffix(TALLOC_CTX *ctx); --const char *lp_ldap_user_suffix(TALLOC_CTX *ctx); --const char *lp_ldap_group_suffix(TALLOC_CTX *ctx); --const char *lp_ldap_idmap_suffix(TALLOC_CTX *ctx); --struct parm_struct; --/* Return a pointer to a service by name. */ --struct loadparm_service *lp_service(const char *pszServiceName); --struct loadparm_service *lp_servicebynum(int snum); --struct loadparm_service *lp_default_loadparm_service(void); --void *lp_parm_ptr(struct loadparm_service *service, struct parm_struct *parm); --void *lp_local_ptr_by_snum(int snum, struct parm_struct *parm); --bool lp_do_parameter(int snum, const char *pszParmName, const char *pszParmValue); --bool lp_set_cmdline(const char *pszParmName, const char *pszParmValue); --bool dump_a_parameter(int snum, char *parm_name, FILE * f, bool isGlobal); --bool lp_snum_ok(int iService); --void lp_add_one_printer(const char *name, const char *comment, -- const char *location, void *pdata); --bool lp_loaded(void); --void lp_killunused(struct smbd_server_connection *sconn, -- bool (*snumused) (struct smbd_server_connection *, int)); --void lp_kill_all_services(void); --void lp_killservice(int iServiceIn); --const char* server_role_str(uint32_t role); --enum usershare_err parse_usershare_file(TALLOC_CTX *ctx, -- SMB_STRUCT_STAT *psbuf, -- const char *servicename, -- int snum, -- char **lines, -- int numlines, -- char **pp_sharepath, -- char **pp_comment, -- char **pp_cp_share_name, -- struct security_descriptor **ppsd, -- bool *pallow_guest); --int load_usershare_service(const char *servicename); --int load_usershare_shares(struct smbd_server_connection *sconn, -- bool (*snumused) (struct smbd_server_connection *, int)); --void gfree_loadparm(void); --bool lp_load_initial_only(const char *pszFname); --bool lp_load_global(const char *file_name); --bool lp_load_with_shares(const char *file_name); --bool lp_load_client(const char *file_name); --bool lp_load_global_no_reinit(const char *file_name); --bool lp_load_no_reinit(const char *file_name); --bool lp_load_client_no_reinit(const char *file_name); --bool lp_load_with_registry_shares(const char *pszFname); --int lp_numservices(void); --void lp_dump(FILE *f, bool show_defaults, int maxtoprint); --void lp_dump_one(FILE * f, bool show_defaults, int snum); --int lp_servicenumber(const char *pszServiceName); --const char *volume_label(TALLOC_CTX *ctx, int snum); --bool lp_domain_master(void); --bool lp_preferred_master(void); --void lp_remove_service(int snum); --void lp_copy_service(int snum, const char *new_name); --int lp_default_server_announce(void); --const char *lp_printername(TALLOC_CTX *ctx, -- const struct loadparm_substitution *lp_sub, -- int snum); --void lp_set_logfile(const char *name); --int lp_maxprintjobs(int snum); --const char *lp_printcapname(void); --bool lp_disable_spoolss( void ); --void lp_set_spoolss_state( uint32_t state ); --uint32_t lp_get_spoolss_state( void ); --struct smb_signing_state; --void set_use_sendfile(int snum, bool val); --void lp_set_mangling_method(const char *new_method); --bool lp_posix_pathnames(void); --void lp_set_posix_pathnames(void); --enum brl_flavour lp_posix_cifsu_locktype(files_struct *fsp); --void lp_set_posix_default_cifsx_readwrite_locktype(enum brl_flavour val); --int lp_min_receive_file_size(void); --void widelinks_warning(int snum); --const char *lp_ncalrpc_dir(void); --void _lp_set_server_role(int server_role); -- --/* The following definitions come from param/loadparm_ctx.c */ -- --const struct loadparm_s3_helpers *loadparm_s3_helpers(void); -- --/* The following definitions come from param/loadparm_server_role.c */ -- --int lp_server_role(void); --void set_server_role(void); -- --/* The following definitions come from param/util.c */ -- --uint32_t get_int_param( const char* param ); --char* get_string_param( const char* param ); -- - /* The following definitions come from lib/server_contexts.c */ - struct tevent_context *global_event_context(void); - void global_event_context_free(void); -diff --git a/source3/param/loadparm.h b/source3/param/loadparm.h -new file mode 100644 -index 00000000000..7686877ccf1 ---- /dev/null -+++ b/source3/param/loadparm.h -@@ -0,0 +1,200 @@ -+/* -+ * -+ * Unix SMB/CIFS implementation. -+ * -+ * Type definitions for loadparm -+ * -+ * Copyright (c) 2020 Andreas Schneider -+ * This program is free software: you can redistribute it and/or modify -+ * it under the terms of the GNU General Public License as published by -+ * the Free Software Foundation, either version 3 of the License, or -+ * (at your option) any later version. -+ * -+ * This program is distributed in the hope that it will be useful, -+ * but WITHOUT ANY WARRANTY; without even the implied warranty of -+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the -+ * GNU General Public License for more details. -+ * -+ * You should have received a copy of the GNU General Public License -+ * along with this program. If not, see . -+ */ -+ -+#ifndef _S3_LOADPARM_H -+#define _S3_LOADPARM_H -+ -+#include -+#include -+ -+/* Forward declarations */ -+typedef struct stat_ex SMB_STRUCT_STAT; -+typedef struct files_struct files_struct; -+struct smbd_server_connection; -+struct security_descriptor; -+ -+/* The following definitions come from param/loadparm.c */ -+ -+const struct loadparm_substitution *loadparm_s3_global_substitution(void); -+ -+char *lp_parm_substituted_string(TALLOC_CTX *mem_ctx, -+ const struct loadparm_substitution *lp_sub, -+ int snum, -+ const char *type, -+ const char *option, -+ const char *def); -+ -+char *lp_servicename(TALLOC_CTX *ctx, const struct loadparm_substitution *, int); -+const char *lp_const_servicename(int); -+bool lp_autoloaded(int); -+const char *lp_dnsdomain(void); -+int lp_winbind_max_domain_connections(void); -+bool lp_idmap_range(const char *domain_name, uint32_t *low, uint32_t *high); -+bool lp_idmap_default_range(uint32_t *low, uint32_t *high); -+const char *lp_idmap_backend(const char *domain_name); -+const char *lp_idmap_default_backend (void); -+int lp_security(void); -+int lp_client_max_protocol(void); -+int lp_client_ipc_min_protocol(void); -+int lp_client_ipc_max_protocol(void); -+int lp_client_ipc_signing(void); -+int lp_smb2_max_credits(void); -+int lp_cups_encrypt(void); -+bool lp_widelinks(int ); -+int lp_rpc_low_port(void); -+int lp_rpc_high_port(void); -+bool lp_lanman_auth(void); -+enum samba_weak_crypto lp_weak_crypto(void); -+ -+int lp_wi_scan_global_parametrics( -+ const char *regex, size_t max_matches, -+ bool (*cb)(const char *string, regmatch_t matches[], -+ void *private_data), -+ void *private_data); -+ -+const char *lp_parm_const_string(int snum, const char *type, const char *option, const char *def); -+struct loadparm_service; -+const char *lp_parm_const_string_service(struct loadparm_service *service, const char *type, -+ const char *option, const char *def); -+const char **lp_parm_string_list(int snum, const char *type, const char *option, const char **def); -+int lp_parm_int(int snum, const char *type, const char *option, int def); -+unsigned long lp_parm_ulong(int snum, const char *type, const char *option, unsigned long def); -+unsigned long long lp_parm_ulonglong(int snum, const char *type, -+ const char *option, -+ unsigned long long def); -+bool lp_parm_bool(int snum, const char *type, const char *option, bool def); -+struct enum_list; -+int lp_parm_enum(int snum, const char *type, const char *option, -+ const struct enum_list *_enum, int def); -+char *canonicalize_servicename(TALLOC_CTX *ctx, const char *src); -+bool lp_add_home(const char *pszHomename, int iDefaultService, -+ const char *user, const char *pszHomedir); -+int lp_add_service(const char *pszService, int iDefaultService); -+bool lp_add_printer(const char *pszPrintername, int iDefaultService); -+bool lp_parameter_is_valid(const char *pszParmName); -+bool lp_parameter_is_global(const char *pszParmName); -+bool lp_canonicalize_parameter(const char *parm_name, const char **canon_parm, -+ bool *inverse); -+bool lp_canonicalize_parameter_with_value(const char *parm_name, -+ const char *val, -+ const char **canon_parm, -+ const char **canon_val); -+void show_parameter_list(void); -+bool lp_invert_boolean(const char *str, const char **inverse_str); -+bool lp_canonicalize_boolean(const char *str, const char**canon_str); -+bool process_registry_service(const char *service_name); -+bool process_registry_shares(void); -+bool lp_config_backend_is_registry(void); -+bool lp_config_backend_is_file(void); -+bool lp_file_list_changed(void); -+const char *lp_ldap_machine_suffix(TALLOC_CTX *ctx); -+const char *lp_ldap_user_suffix(TALLOC_CTX *ctx); -+const char *lp_ldap_group_suffix(TALLOC_CTX *ctx); -+const char *lp_ldap_idmap_suffix(TALLOC_CTX *ctx); -+struct parm_struct; -+/* Return a pointer to a service by name. */ -+struct loadparm_service *lp_service(const char *pszServiceName); -+struct loadparm_service *lp_servicebynum(int snum); -+struct loadparm_service *lp_default_loadparm_service(void); -+void *lp_parm_ptr(struct loadparm_service *service, struct parm_struct *parm); -+void *lp_local_ptr_by_snum(int snum, struct parm_struct *parm); -+bool lp_do_parameter(int snum, const char *pszParmName, const char *pszParmValue); -+bool lp_set_cmdline(const char *pszParmName, const char *pszParmValue); -+bool dump_a_parameter(int snum, char *parm_name, FILE * f, bool isGlobal); -+bool lp_snum_ok(int iService); -+void lp_add_one_printer(const char *name, const char *comment, -+ const char *location, void *pdata); -+bool lp_loaded(void); -+void lp_killunused(struct smbd_server_connection *sconn, -+ bool (*snumused) (struct smbd_server_connection *, int)); -+void lp_kill_all_services(void); -+void lp_killservice(int iServiceIn); -+const char* server_role_str(uint32_t role); -+enum usershare_err parse_usershare_file(TALLOC_CTX *ctx, -+ SMB_STRUCT_STAT *psbuf, -+ const char *servicename, -+ int snum, -+ char **lines, -+ int numlines, -+ char **pp_sharepath, -+ char **pp_comment, -+ char **pp_cp_share_name, -+ struct security_descriptor **ppsd, -+ bool *pallow_guest); -+int load_usershare_service(const char *servicename); -+int load_usershare_shares(struct smbd_server_connection *sconn, -+ bool (*snumused) (struct smbd_server_connection *, int)); -+void gfree_loadparm(void); -+bool lp_load_initial_only(const char *pszFname); -+bool lp_load_global(const char *file_name); -+bool lp_load_with_shares(const char *file_name); -+bool lp_load_client(const char *file_name); -+bool lp_load_global_no_reinit(const char *file_name); -+bool lp_load_no_reinit(const char *file_name); -+bool lp_load_client_no_reinit(const char *file_name); -+bool lp_load_with_registry_shares(const char *pszFname); -+int lp_numservices(void); -+void lp_dump(FILE *f, bool show_defaults, int maxtoprint); -+void lp_dump_one(FILE * f, bool show_defaults, int snum); -+int lp_servicenumber(const char *pszServiceName); -+const char *volume_label(TALLOC_CTX *ctx, int snum); -+bool lp_domain_master(void); -+bool lp_preferred_master(void); -+void lp_remove_service(int snum); -+void lp_copy_service(int snum, const char *new_name); -+int lp_default_server_announce(void); -+const char *lp_printername(TALLOC_CTX *ctx, -+ const struct loadparm_substitution *lp_sub, -+ int snum); -+void lp_set_logfile(const char *name); -+int lp_maxprintjobs(int snum); -+const char *lp_printcapname(void); -+bool lp_disable_spoolss( void ); -+void lp_set_spoolss_state( uint32_t state ); -+uint32_t lp_get_spoolss_state( void ); -+struct smb_signing_state; -+void set_use_sendfile(int snum, bool val); -+void lp_set_mangling_method(const char *new_method); -+bool lp_posix_pathnames(void); -+void lp_set_posix_pathnames(void); -+enum brl_flavour lp_posix_cifsu_locktype(files_struct *fsp); -+void lp_set_posix_default_cifsx_readwrite_locktype(enum brl_flavour val); -+int lp_min_receive_file_size(void); -+void widelinks_warning(int snum); -+const char *lp_ncalrpc_dir(void); -+void _lp_set_server_role(int server_role); -+uint32_t lp_get_async_dns_timeout(void); -+ -+/* The following definitions come from param/loadparm_ctx.c */ -+ -+const struct loadparm_s3_helpers *loadparm_s3_helpers(void); -+ -+/* The following definitions come from param/loadparm_server_role.c */ -+ -+int lp_server_role(void); -+void set_server_role(void); -+ -+/* The following definitions come from param/util.c */ -+ -+uint32_t get_int_param( const char* param ); -+char *get_string_param( const char* param ); -+ -+#endif /* _S3_LOADPARM_H */ --- -2.33.1 - - -From 02f7af27b6a13328fc5e081b43753f5f60e11114 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Tue, 11 Aug 2020 10:41:07 +0200 -Subject: [PATCH 075/103] s3:lib: Move interface prototypes to own header file - -Signed-off-by: Andreas Schneider -Reviewed-by: Jeremy Allison - -Autobuild-User(master): Jeremy Allison -Autobuild-Date(master): Fri Oct 9 20:36:13 UTC 2020 on sn-devel-184 - -(cherry picked from commit 925cc9aafbe17cb2cbd89f468fac70f96ae89475) ---- - source3/include/proto.h | 21 +------------------ - source3/lib/interface.h | 46 +++++++++++++++++++++++++++++++++++++++++ - 2 files changed, 47 insertions(+), 20 deletions(-) - create mode 100644 source3/lib/interface.h - -diff --git a/source3/include/proto.h b/source3/include/proto.h -index 4f14a2d546d..d3b758aa43d 100644 ---- a/source3/include/proto.h -+++ b/source3/include/proto.h -@@ -84,26 +84,7 @@ NTSTATUS vfs_at_fspcwd(TALLOC_CTX *mem_ctx, - struct connection_struct *conn, - struct files_struct **_fsp); - --/* The following definitions come from lib/interface.c */ -- --bool ismyaddr(const struct sockaddr *ip); --bool ismyip_v4(struct in_addr ip); --bool is_local_net(const struct sockaddr *from); --void setup_linklocal_scope_id(struct sockaddr *pss); --bool is_local_net_v4(struct in_addr from); --int iface_count(void); --int iface_count_v4_nl(void); --const struct in_addr *first_ipv4_iface(void); --struct interface *get_interface(int n); --const struct sockaddr_storage *iface_n_sockaddr_storage(int n); --const struct in_addr *iface_n_ip_v4(int n); --const struct in_addr *iface_n_bcast_v4(int n); --const struct sockaddr_storage *iface_n_bcast(int n); --const struct sockaddr_storage *iface_ip(const struct sockaddr *ip); --bool iface_local(const struct sockaddr *ip); --void load_interfaces(void); --void gfree_interfaces(void); --bool interfaces_changed(void); -+#include "source3/lib/interface.h" - - /* The following definitions come from lib/ldap_debug_handler.c */ - -diff --git a/source3/lib/interface.h b/source3/lib/interface.h -new file mode 100644 -index 00000000000..f45435b4a81 ---- /dev/null -+++ b/source3/lib/interface.h -@@ -0,0 +1,46 @@ -+/* -+ * -+ * Unix SMB/CIFS implementation. -+ * -+ * Type definitions for interfaces -+ * -+ * Copyright (c) 2020 Andreas Schneider -+ * This program is free software: you can redistribute it and/or modify -+ * it under the terms of the GNU General Public License as published by -+ * the Free Software Foundation, either version 3 of the License, or -+ * (at your option) any later version. -+ * -+ * This program is distributed in the hope that it will be useful, -+ * but WITHOUT ANY WARRANTY; without even the implied warranty of -+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the -+ * GNU General Public License for more details. -+ * -+ * You should have received a copy of the GNU General Public License -+ * along with this program. If not, see . -+ */ -+ -+#ifndef _INTERFACE_H -+#define _INTERFACE_H -+ -+#include -+ -+bool ismyaddr(const struct sockaddr *ip); -+bool ismyip_v4(struct in_addr ip); -+bool is_local_net(const struct sockaddr *from); -+void setup_linklocal_scope_id(struct sockaddr *pss); -+bool is_local_net_v4(struct in_addr from); -+int iface_count(void); -+int iface_count_v4_nl(void); -+const struct in_addr *first_ipv4_iface(void); -+struct interface *get_interface(int n); -+const struct sockaddr_storage *iface_n_sockaddr_storage(int n); -+const struct in_addr *iface_n_ip_v4(int n); -+const struct in_addr *iface_n_bcast_v4(int n); -+const struct sockaddr_storage *iface_n_bcast(int n); -+const struct sockaddr_storage *iface_ip(const struct sockaddr *ip); -+bool iface_local(const struct sockaddr *ip); -+void load_interfaces(void); -+void gfree_interfaces(void); -+bool interfaces_changed(void); -+ -+#endif /* _INTERFACE_H */ --- -2.33.1 - - -From 36596f29922a861ef1eb8ad05a29671031241279 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Fri, 7 Feb 2020 16:48:16 +0100 -Subject: [PATCH 076/103] idl: Add SID_SAMBA_SMB3 - -Signed-off-by: Andreas Schneider -Reviewed-by: Alexander Bokovoy -(cherry picked from commit 56879ec5876625346df89110f62d52e3fd5b8934) ---- - librpc/idl/security.idl | 3 +++ - 1 file changed, 3 insertions(+) - -diff --git a/librpc/idl/security.idl b/librpc/idl/security.idl -index 9845becd826..3df96dedbdd 100644 ---- a/librpc/idl/security.idl -+++ b/librpc/idl/security.idl -@@ -282,6 +282,9 @@ interface security - const string SID_SAMBA_UNIX_USER_OWNER = "S-1-22-1"; - const string SID_SAMBA_UNIX_GROUP_OWNER = "S-1-22-2"; - -+ /* Information passing via security token */ -+ const string SID_SAMBA_SMB3 = "S-1-22-1397571891"; -+ - /* SECURITY_NT_SERVICE */ - const string NAME_NT_SERVICE = "NT SERVICE"; - --- -2.33.1 - - -From 5ba8528b744b245b73f187b75b4bf39193d5a799 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Fri, 7 Feb 2020 16:48:29 +0100 -Subject: [PATCH 077/103] s3:smbd: Add SMB3 connection information to session - info - -Signed-off-by: Andreas Schneider -Reviewed-by: Alexander Bokovoy -(cherry picked from commit 905c2b9722a64ee57f3fbcff51e6bb591c6e3edc) ---- - source3/include/vfs.h | 1 + - source3/smbd/pipes.c | 82 +++++++++++++++++++++++++++++++++++++- - source3/smbd/smb2_server.c | 5 +++ - 3 files changed, 87 insertions(+), 1 deletion(-) - -diff --git a/source3/include/vfs.h b/source3/include/vfs.h -index d527f850628..c0d60636c31 100644 ---- a/source3/include/vfs.h -+++ b/source3/include/vfs.h -@@ -411,6 +411,7 @@ typedef struct files_struct { - bool use_ofd_locks : 1; - bool closing : 1; - bool lock_failure_seen : 1; -+ bool encryption_required : 1; - } fsp_flags; - - struct tevent_timer *update_write_time_event; -diff --git a/source3/smbd/pipes.c b/source3/smbd/pipes.c -index 2dd38bb7ab3..d51a3de9497 100644 ---- a/source3/smbd/pipes.c -+++ b/source3/smbd/pipes.c -@@ -30,13 +30,16 @@ - #include "smbd/globals.h" - #include "libcli/security/security.h" - #include "rpc_server/srv_pipe_hnd.h" -+#include "auth/auth_util.h" - - NTSTATUS open_np_file(struct smb_request *smb_req, const char *name, - struct files_struct **pfsp) - { -+ struct smbXsrv_connection *xconn = smb_req->xconn; - struct connection_struct *conn = smb_req->conn; - struct files_struct *fsp; - struct smb_filename *smb_fname = NULL; -+ struct auth_session_info *session_info = conn->session_info; - NTSTATUS status; - - status = file_new(smb_req, conn, &fsp); -@@ -68,10 +71,87 @@ NTSTATUS open_np_file(struct smb_request *smb_req, const char *name, - return status; - } - -+ if (smb_req->smb2req != NULL && smb_req->smb2req->was_encrypted) { -+ struct security_token *security_token = NULL; -+ uint16_t dialect = xconn->smb2.server.dialect; -+ uint16_t srv_smb_encrypt = 0x0002; -+ uint16_t cipher = xconn->smb2.server.cipher; -+ char smb3_sid_str[SID_MAX_SIZE]; -+ struct dom_sid smb3_dom_sid; -+ struct dom_sid smb3_sid; -+ uint32_t i; -+ bool ok; -+ int rc; -+ -+ session_info = copy_session_info(fsp, conn->session_info); -+ if (session_info == NULL) { -+ DBG_ERR("Failed to copy session info\n"); -+ file_free(smb_req, fsp); -+ return NT_STATUS_NO_MEMORY; -+ } -+ security_token = session_info->security_token; -+ -+ ok = dom_sid_parse(SID_SAMBA_SMB3, &smb3_dom_sid); -+ if (!ok) { -+ file_free(smb_req, fsp); -+ return NT_STATUS_BUFFER_TOO_SMALL; -+ } -+ -+ /* -+ * Security check: -+ * -+ * Make sure we don't have a SMB3 SID in the security token! -+ */ -+ for (i = 0; i < security_token->num_sids; i++) { -+ int cmp; -+ -+ cmp = dom_sid_compare_domain(&security_token->sids[i], -+ &smb3_dom_sid); -+ if (cmp == 0) { -+ DBG_ERR("ERROR: An SMB3 SID has already been " -+ "detected in the security token!\n"); -+ file_free(smb_req, fsp); -+ return NT_STATUS_ACCESS_DENIED; -+ } -+ } -+ -+ rc = snprintf(smb3_sid_str, -+ sizeof(smb3_sid_str), -+ "%s-%u-%u-%u", -+ SID_SAMBA_SMB3, -+ dialect, -+ srv_smb_encrypt, -+ cipher); -+ if (rc < 0) { -+ DBG_ERR("Buffer too small\n"); -+ file_free(smb_req, fsp); -+ return NT_STATUS_BUFFER_TOO_SMALL; -+ } -+ -+ ok = dom_sid_parse(smb3_sid_str, &smb3_sid); -+ if (!ok) { -+ DBG_ERR("Failed to parse SMB3 SID\n"); -+ file_free(smb_req, fsp); -+ return NT_STATUS_INVALID_PARAMETER; -+ } -+ -+ status = add_sid_to_array_unique(security_token, -+ &smb3_sid, -+ &security_token->sids, -+ &security_token->num_sids); -+ if (!NT_STATUS_IS_OK(status)) { -+ DBG_ERR("Failed to add SMB3 SID to security token\n"); -+ file_free(smb_req, fsp); -+ return status; -+ } -+ -+ fsp->fsp_flags.encryption_required = true; -+ } -+ - status = np_open(fsp, name, - conn->sconn->remote_address, - conn->sconn->local_address, -- conn->session_info, -+ session_info, - conn->sconn->ev_ctx, - conn->sconn->msg_ctx, - conn->sconn->dce_ctx, -diff --git a/source3/smbd/smb2_server.c b/source3/smbd/smb2_server.c -index cf9de185c1f..cd24b7d2ed5 100644 ---- a/source3/smbd/smb2_server.c -+++ b/source3/smbd/smb2_server.c -@@ -3232,6 +3232,11 @@ NTSTATUS smbd_smb2_request_dispatch(struct smbd_smb2_request *req) - return smbd_smb2_request_error(req, - NT_STATUS_FILE_CLOSED); - } -+ } else { -+ if (fsp->fsp_flags.encryption_required && !req->was_encrypted) { -+ return smbd_smb2_request_error(req, -+ NT_STATUS_ACCESS_DENIED); -+ } - } - } - --- -2.33.1 - - -From dcd118ced1389720b2123fe30bca21bdf714dda4 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 12 Mar 2020 14:11:56 +0100 -Subject: [PATCH 078/103] librpc: Add dcerpc helper - dcerpc_is_transport_encrypted() - -Signed-off-by: Andreas Schneider -Reviewed-by: Alexander Bokovoy -(cherry picked from commit 8bbe5c8c94aaf75d715f558c363e5b2de49f7bf9) ---- - librpc/rpc/dcerpc_helper.c | 137 +++++++++++++++++++++++++++++++++++++ - librpc/rpc/dcerpc_helper.h | 26 +++++++ - librpc/wscript_build | 9 +++ - 3 files changed, 172 insertions(+) - create mode 100644 librpc/rpc/dcerpc_helper.c - create mode 100644 librpc/rpc/dcerpc_helper.h - -diff --git a/librpc/rpc/dcerpc_helper.c b/librpc/rpc/dcerpc_helper.c -new file mode 100644 -index 00000000000..c5443764628 ---- /dev/null -+++ b/librpc/rpc/dcerpc_helper.c -@@ -0,0 +1,137 @@ -+/* -+ * Copyright (c) 2020 Andreas Schneider -+ * -+ * This program is free software: you can redistribute it and/or modify -+ * it under the terms of the GNU General Public License as published by -+ * the Free Software Foundation, either version 3 of the License, or -+ * (at your option) any later version. -+ * -+ * This program is distributed in the hope that it will be useful, -+ * but WITHOUT ANY WARRANTY; without even the implied warranty of -+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the -+ * GNU General Public License for more details. -+ * -+ * You should have received a copy of the GNU General Public License -+ * along with this program. If not, see . -+ */ -+ -+#include "includes.h" -+#include "librpc/gen_ndr/security.h" -+#include "librpc/gen_ndr/auth.h" -+#include "lib/crypto/gnutls_helpers.h" -+#include "libcli/security/dom_sid.h" -+#include "libcli/smb/smb2_constants.h" -+ -+#include "dcerpc_helper.h" -+ -+static bool smb3_sid_parse(const struct dom_sid *sid, -+ uint16_t *pdialect, -+ uint16_t *pencrypt, -+ uint16_t *pcipher) -+{ -+ uint16_t dialect; -+ uint16_t encrypt; -+ uint16_t cipher; -+ -+ if (sid->sub_auths[0] != 1397571891) { -+ return false; -+ } -+ -+ dialect = sid->sub_auths[1]; -+ if (dialect > 0x03ff) { -+ return false; -+ } -+ -+ encrypt = sid->sub_auths[2]; -+ if (encrypt > 0x0002) { -+ return false; -+ } -+ -+ cipher = sid->sub_auths[3]; -+ if (cipher > SMB2_ENCRYPTION_AES128_GCM) { -+ return false; -+ } -+ -+ if (pdialect != NULL) { -+ *pdialect = dialect; -+ } -+ -+ if (pencrypt != NULL) { -+ *pencrypt = encrypt; -+ } -+ -+ if (pcipher != NULL) { -+ *pcipher = cipher; -+ } -+ -+ return true; -+} -+ -+bool dcerpc_is_transport_encrypted(struct auth_session_info *session_info) -+{ -+ struct security_token *token = session_info->security_token; -+ struct dom_sid smb3_dom_sid; -+ const struct dom_sid *smb3_sid = NULL; -+ uint16_t dialect = 0; -+ uint16_t encrypt = 0; -+ uint16_t cipher = 0; -+ uint32_t i; -+ bool ok; -+ -+ ok = dom_sid_parse(SID_SAMBA_SMB3, &smb3_dom_sid); -+ if (!ok) { -+ return false; -+ } -+ -+ for (i = 0; i < token->num_sids; i++) { -+ int cmp; -+ -+ /* There is only one SMB3 SID allowed! */ -+ cmp = dom_sid_compare_domain(&token->sids[i], &smb3_dom_sid); -+ if (cmp == 0) { -+ if (smb3_sid == NULL) { -+ smb3_sid = &token->sids[i]; -+ } else { -+ DBG_ERR("ERROR: The SMB3 SID has been detected " -+ "multiple times\n"); -+ return false; -+ } -+ } -+ } -+ -+ if (smb3_sid == NULL) { -+ return false; -+ } -+ -+ ok = smb3_sid_parse(smb3_sid, &dialect, &encrypt, &cipher); -+ if (!ok) { -+ DBG_ERR("Failed to parse SMB3 SID!\n"); -+ return false; -+ } -+ -+ DBG_DEBUG("SMB SID - dialect: %#04x, encrypt: %#04x, cipher: %#04x\n", -+ dialect, -+ encrypt, -+ cipher); -+ -+ if (dialect < SMB3_DIALECT_REVISION_300) { -+ DBG_DEBUG("Invalid SMB3 dialect!\n"); -+ return false; -+ } -+ -+ if (encrypt != DCERPC_SMB_ENCRYPTION_REQUIRED) { -+ DBG_DEBUG("Invalid SMB3 encryption!\n"); -+ return false; -+ } -+ -+ switch (cipher) { -+ case SMB2_ENCRYPTION_AES128_CCM: -+ case SMB2_ENCRYPTION_AES128_GCM: -+ break; -+ default: -+ DBG_DEBUG("Invalid SMB3 cipher!\n"); -+ return false; -+ } -+ -+ return true; -+} -diff --git a/librpc/rpc/dcerpc_helper.h b/librpc/rpc/dcerpc_helper.h -new file mode 100644 -index 00000000000..c0f09ee494e ---- /dev/null -+++ b/librpc/rpc/dcerpc_helper.h -@@ -0,0 +1,26 @@ -+/* -+ * Copyright (c) 2020 Andreas Schneider -+ * -+ * This program is free software: you can redistribute it and/or modify -+ * it under the terms of the GNU General Public License as published by -+ * the Free Software Foundation, either version 3 of the License, or -+ * (at your option) any later version. -+ * -+ * This program is distributed in the hope that it will be useful, -+ * but WITHOUT ANY WARRANTY; without even the implied warranty of -+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the -+ * GNU General Public License for more details. -+ * -+ * You should have received a copy of the GNU General Public License -+ * along with this program. If not, see . -+ */ -+ -+#ifndef _DCERPC_HELPER_H -+#define _DCERPC_HELPER_H -+ -+#define DCERPC_SMB_ENCRYPTION_OFF 0x0000 -+#define DCERPC_SMB_ENCRYPTION_REQUIRED 0x0002 -+ -+bool dcerpc_is_transport_encrypted(struct auth_session_info *session_info); -+ -+#endif /* _DCERPC_HELPER_H */ -diff --git a/librpc/wscript_build b/librpc/wscript_build -index a1c3c994876..5e78d1e634b 100644 ---- a/librpc/wscript_build -+++ b/librpc/wscript_build -@@ -694,6 +694,15 @@ bld.SAMBA_LIBRARY('dcerpc-server-core', - autoproto='rpc/dcesrv_core_proto.h', - vnum='0.0.1') - -+bld.SAMBA_SUBSYSTEM('DCERPC_HELPER', -+ source='rpc/dcerpc_helper.c', -+ public_deps=''' -+ samba-hostconfig -+ samba-security -+ gnutls -+ GNUTLS_HELPERS -+ ''') -+ - bld.SAMBA_SUBSYSTEM('NDR_WINBIND', - source='gen_ndr/ndr_winbind.c', - public_deps='ndr NDR_LSA' --- -2.33.1 - - -From 007e530ce0194b77e17589f25465136f2df4c0a3 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Fri, 28 Aug 2020 16:31:17 +0200 -Subject: [PATCH 079/103] s3:smbd: Use defines to set 'srv_smb_encrypt' - -Signed-off-by: Andreas Schneider -Reviewed-by: Alexander Bokovoy -(cherry picked from commit 5f1a73be6311c68a21a550c0de5078baeb78f4ee) ---- - source3/smbd/pipes.c | 3 ++- - 1 file changed, 2 insertions(+), 1 deletion(-) - -diff --git a/source3/smbd/pipes.c b/source3/smbd/pipes.c -index d51a3de9497..785cbb23b5f 100644 ---- a/source3/smbd/pipes.c -+++ b/source3/smbd/pipes.c -@@ -31,6 +31,7 @@ - #include "libcli/security/security.h" - #include "rpc_server/srv_pipe_hnd.h" - #include "auth/auth_util.h" -+#include "librpc/rpc/dcerpc_helper.h" - - NTSTATUS open_np_file(struct smb_request *smb_req, const char *name, - struct files_struct **pfsp) -@@ -74,7 +75,7 @@ NTSTATUS open_np_file(struct smb_request *smb_req, const char *name, - if (smb_req->smb2req != NULL && smb_req->smb2req->was_encrypted) { - struct security_token *security_token = NULL; - uint16_t dialect = xconn->smb2.server.dialect; -- uint16_t srv_smb_encrypt = 0x0002; -+ uint16_t srv_smb_encrypt = DCERPC_SMB_ENCRYPTION_REQUIRED; - uint16_t cipher = xconn->smb2.server.cipher; - char smb3_sid_str[SID_MAX_SIZE]; - struct dom_sid smb3_dom_sid; --- -2.33.1 - - -From 21568b31f941d8b534036710dae71811b36b0f30 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Tue, 12 Nov 2019 16:56:45 +0100 -Subject: [PATCH 080/103] s3:rpc_server: Allow to use RC4 for setting passwords - -Signed-off-by: Andreas Schneider -Reviewed-by: Alexander Bokovoy -(cherry picked from commit c6a21e1897985f267bcfc681179cea95165c3c57) ---- - source3/rpc_server/samr/srv_samr_chgpasswd.c | 3 + - source3/rpc_server/samr/srv_samr_nt.c | 78 +++++++++++++++++++- - source3/rpc_server/wscript_build | 2 +- - 3 files changed, 81 insertions(+), 2 deletions(-) - -diff --git a/source3/rpc_server/samr/srv_samr_chgpasswd.c b/source3/rpc_server/samr/srv_samr_chgpasswd.c -index cb9837ecf01..e326745169e 100644 ---- a/source3/rpc_server/samr/srv_samr_chgpasswd.c -+++ b/source3/rpc_server/samr/srv_samr_chgpasswd.c -@@ -769,11 +769,13 @@ static NTSTATUS check_oem_password(const char *user, - .size = 16, - }; - -+ GNUTLS_FIPS140_SET_LAX_MODE(); - rc = gnutls_cipher_init(&cipher_hnd, - GNUTLS_CIPHER_ARCFOUR_128, - &enc_key, - NULL); - if (rc < 0) { -+ GNUTLS_FIPS140_SET_STRICT_MODE(); - return gnutls_error_to_ntstatus(rc, NT_STATUS_CRYPTO_SYSTEM_INVALID); - } - -@@ -781,6 +783,7 @@ static NTSTATUS check_oem_password(const char *user, - password_encrypted, - 516); - gnutls_cipher_deinit(cipher_hnd); -+ GNUTLS_FIPS140_SET_STRICT_MODE(); - if (rc < 0) { - return gnutls_error_to_ntstatus(rc, NT_STATUS_CRYPTO_SYSTEM_INVALID); - } -diff --git a/source3/rpc_server/samr/srv_samr_nt.c b/source3/rpc_server/samr/srv_samr_nt.c -index 5ffc3331185..77cb18b6a88 100644 ---- a/source3/rpc_server/samr/srv_samr_nt.c -+++ b/source3/rpc_server/samr/srv_samr_nt.c -@@ -46,6 +46,8 @@ - #include "rpc_server/srv_access_check.h" - #include "../lib/tsocket/tsocket.h" - #include "lib/util/base64.h" -+#include "param/param.h" -+#include "librpc/rpc/dcerpc_helper.h" - - #include "lib/crypto/gnutls_helpers.h" - #include -@@ -1887,6 +1889,7 @@ NTSTATUS _samr_ChangePasswordUser2(struct pipes_struct *p, - char *user_name = NULL; - char *rhost; - const char *wks = NULL; -+ bool encrypted; - - DEBUG(5,("_samr_ChangePasswordUser2: %d\n", __LINE__)); - -@@ -1915,6 +1918,12 @@ NTSTATUS _samr_ChangePasswordUser2(struct pipes_struct *p, - return NT_STATUS_NO_MEMORY; - } - -+ encrypted = dcerpc_is_transport_encrypted(p->session_info); -+ if (lp_weak_crypto() == SAMBA_WEAK_CRYPTO_DISALLOWED && -+ !encrypted) { -+ return NT_STATUS_ACCESS_DENIED; -+ } -+ - /* - * UNIX username case mangling not required, pass_oem_change - * is case insensitive. -@@ -1948,6 +1957,7 @@ NTSTATUS _samr_OemChangePasswordUser2(struct pipes_struct *p, - char *user_name = NULL; - const char *wks = NULL; - char *rhost; -+ bool encrypted; - - DEBUG(5,("_samr_OemChangePasswordUser2: %d\n", __LINE__)); - -@@ -1985,6 +1995,12 @@ NTSTATUS _samr_OemChangePasswordUser2(struct pipes_struct *p, - return NT_STATUS_NO_MEMORY; - } - -+ encrypted = dcerpc_is_transport_encrypted(p->session_info); -+ if (lp_weak_crypto() == SAMBA_WEAK_CRYPTO_DISALLOWED && -+ !encrypted) { -+ return NT_STATUS_ACCESS_DENIED; -+ } -+ - status = pass_oem_change(user_name, - rhost, - r->in.password->data, -@@ -5200,8 +5216,13 @@ NTSTATUS _samr_SetUserInfo(struct pipes_struct *p, - char *rhost; - DATA_BLOB session_key; - struct dom_sid_buf buf; -+ struct loadparm_context *lp_ctx = NULL; -+ bool encrypted; - -- DEBUG(5,("_samr_SetUserInfo: %d\n", __LINE__)); -+ lp_ctx = loadparm_init_s3(p->mem_ctx, loadparm_s3_helpers()); -+ if (lp_ctx == NULL) { -+ return NT_STATUS_NO_MEMORY; -+ } - - /* This is tricky. A WinXP domain join sets - (SAMR_USER_ACCESS_SET_PASSWORD|SAMR_USER_ACCESS_SET_ATTRIBUTES|SAMR_USER_ACCESS_GET_ATTRIBUTES) -@@ -5390,13 +5411,27 @@ NTSTATUS _samr_SetUserInfo(struct pipes_struct *p, - break; - - case 23: -+ encrypted = -+ dcerpc_is_transport_encrypted(p->session_info); -+ if (lp_weak_crypto() == SAMBA_WEAK_CRYPTO_DISALLOWED && -+ !encrypted) { -+ status = NT_STATUS_ACCESS_DENIED; -+ break; -+ } -+ - status = session_extract_session_key(p->session_info, &session_key, KEY_USE_16BYTES); - if(!NT_STATUS_IS_OK(status)) { - break; - } -+ /* -+ * This can be allowed as it requires a session key -+ * which we only have if we have a SMB session. -+ */ -+ GNUTLS_FIPS140_SET_LAX_MODE(); - status = arc4_decrypt_data(session_key, - info->info23.password.data, - 516); -+ GNUTLS_FIPS140_SET_STRICT_MODE(); - if(!NT_STATUS_IS_OK(status)) { - break; - } -@@ -5412,14 +5447,27 @@ NTSTATUS _samr_SetUserInfo(struct pipes_struct *p, - break; - - case 24: -+ encrypted = -+ dcerpc_is_transport_encrypted(p->session_info); -+ if (lp_weak_crypto() == SAMBA_WEAK_CRYPTO_DISALLOWED && -+ !encrypted) { -+ status = NT_STATUS_ACCESS_DENIED; -+ break; -+ } - - status = session_extract_session_key(p->session_info, &session_key, KEY_USE_16BYTES); - if(!NT_STATUS_IS_OK(status)) { - break; - } -+ /* -+ * This can be allowed as it requires a session key -+ * which we only have if we have a SMB session. -+ */ -+ GNUTLS_FIPS140_SET_LAX_MODE(); - status = arc4_decrypt_data(session_key, - info->info24.password.data, - 516); -+ GNUTLS_FIPS140_SET_STRICT_MODE(); - if(!NT_STATUS_IS_OK(status)) { - break; - } -@@ -5434,12 +5482,26 @@ NTSTATUS _samr_SetUserInfo(struct pipes_struct *p, - break; - - case 25: -+ encrypted = -+ dcerpc_is_transport_encrypted(p->session_info); -+ if (lp_weak_crypto() == SAMBA_WEAK_CRYPTO_DISALLOWED && -+ !encrypted) { -+ status = NT_STATUS_ACCESS_DENIED; -+ break; -+ } -+ - status = session_extract_session_key(p->session_info, &session_key, KEY_USE_16BYTES); - if(!NT_STATUS_IS_OK(status)) { - break; - } -+ /* -+ * This can be allowed as it requires a session key -+ * which we only have if we have a SMB session. -+ */ -+ GNUTLS_FIPS140_SET_LAX_MODE(); - status = decode_rc4_passwd_buffer(&session_key, - &info->info25.password); -+ GNUTLS_FIPS140_SET_STRICT_MODE(); - if (!NT_STATUS_IS_OK(status)) { - break; - } -@@ -5454,12 +5516,26 @@ NTSTATUS _samr_SetUserInfo(struct pipes_struct *p, - break; - - case 26: -+ encrypted = -+ dcerpc_is_transport_encrypted(p->session_info); -+ if (lp_weak_crypto() == SAMBA_WEAK_CRYPTO_DISALLOWED && -+ !encrypted) { -+ status = NT_STATUS_ACCESS_DENIED; -+ break; -+ } -+ - status = session_extract_session_key(p->session_info, &session_key, KEY_USE_16BYTES); - if(!NT_STATUS_IS_OK(status)) { - break; - } -+ /* -+ * This can be allowed as it requires a session key -+ * which we only have if we have a SMB session. -+ */ -+ GNUTLS_FIPS140_SET_LAX_MODE(); - status = decode_rc4_passwd_buffer(&session_key, - &info->info26.password); -+ GNUTLS_FIPS140_SET_STRICT_MODE(); - if (!NT_STATUS_IS_OK(status)) { - break; - } -diff --git a/source3/rpc_server/wscript_build b/source3/rpc_server/wscript_build -index 2af02ad6fa8..eb91ac09384 100644 ---- a/source3/rpc_server/wscript_build -+++ b/source3/rpc_server/wscript_build -@@ -85,7 +85,7 @@ bld.SAMBA3_SUBSYSTEM('RPC_SAMR', - source='''samr/srv_samr_nt.c - samr/srv_samr_util.c - samr/srv_samr_chgpasswd.c''', -- deps='PLAINTEXT_AUTH SRV_ACCESS_CHECK') -+ deps='PLAINTEXT_AUTH SRV_ACCESS_CHECK DCERPC_HELPER') - - bld.SAMBA3_SUBSYSTEM('RPC_SPOOLSS', - source='''spoolss/srv_spoolss_nt.c --- -2.33.1 - - -From d682c7a4e59c4f402096de5ddcd54ddb33886fe6 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Fri, 15 Nov 2019 13:49:40 +0100 -Subject: [PATCH 081/103] s4:rpc_server: Allow to use RC4 for setting passwords - -Signed-off-by: Andreas Schneider -Reviewed-by: Alexander Bokovoy -(cherry picked from commit a9c532c6d3e85fbe49b7040254cfc66ab54074bc) ---- - source4/rpc_server/samr/samr_password.c | 32 +++++++++++++++++++++++++ - source4/rpc_server/wscript_build | 2 +- - 2 files changed, 33 insertions(+), 1 deletion(-) - -diff --git a/source4/rpc_server/samr/samr_password.c b/source4/rpc_server/samr/samr_password.c -index 9144c23155b..437e8f66275 100644 ---- a/source4/rpc_server/samr/samr_password.c -+++ b/source4/rpc_server/samr/samr_password.c -@@ -32,6 +32,8 @@ - #include "../lib/util/util_ldb.h" - #include "rpc_server/samr/proto.h" - #include "auth/auth_sam.h" -+#include "lib/param/loadparm.h" -+#include "librpc/rpc/dcerpc_helper.h" - - #include "lib/crypto/gnutls_helpers.h" - #include -@@ -102,6 +104,8 @@ NTSTATUS dcesrv_samr_OemChangePasswordUser2(struct dcesrv_call_state *dce_call, - TALLOC_CTX *mem_ctx, - struct samr_OemChangePasswordUser2 *r) - { -+ struct auth_session_info *session_info = -+ dcesrv_call_session_info(dce_call); - struct imessaging_context *imsg_ctx = - dcesrv_imessaging_context(dce_call->conn); - NTSTATUS status = NT_STATUS_WRONG_PASSWORD; -@@ -128,6 +132,8 @@ NTSTATUS dcesrv_samr_OemChangePasswordUser2(struct dcesrv_call_state *dce_call, - struct dom_sid *user_objectSid = NULL; - gnutls_cipher_hd_t cipher_hnd = NULL; - gnutls_datum_t lm_session_key; -+ struct loadparm_context *lp_ctx = dce_call->conn->dce_ctx->lp_ctx; -+ bool encrypted; - int rc; - - if (pwbuf == NULL) { -@@ -143,6 +149,12 @@ NTSTATUS dcesrv_samr_OemChangePasswordUser2(struct dcesrv_call_state *dce_call, - return NT_STATUS_ACCESS_DISABLED_BY_POLICY_OTHER; - } - -+ encrypted = dcerpc_is_transport_encrypted(session_info); -+ if (lpcfg_weak_crypto(lp_ctx) == SAMBA_WEAK_CRYPTO_DISALLOWED && -+ !encrypted) { -+ return NT_STATUS_ACCESS_DENIED; -+ } -+ - /* Connect to a SAMDB with system privileges for fetching the old pw - * hashes. */ - sam_ctx = dcesrv_samdb_connect_as_system(mem_ctx, dce_call); -@@ -182,11 +194,13 @@ NTSTATUS dcesrv_samr_OemChangePasswordUser2(struct dcesrv_call_state *dce_call, - .size = sizeof(lm_pwd->hash), - }; - -+ GNUTLS_FIPS140_SET_LAX_MODE(); - rc = gnutls_cipher_init(&cipher_hnd, - GNUTLS_CIPHER_ARCFOUR_128, - &lm_session_key, - NULL); - if (rc < 0) { -+ GNUTLS_FIPS140_SET_STRICT_MODE(); - status = gnutls_error_to_ntstatus(rc, NT_STATUS_CRYPTO_SYSTEM_INVALID); - goto failed; - } -@@ -195,6 +209,7 @@ NTSTATUS dcesrv_samr_OemChangePasswordUser2(struct dcesrv_call_state *dce_call, - pwbuf->data, - 516); - gnutls_cipher_deinit(cipher_hnd); -+ GNUTLS_FIPS140_SET_STRICT_MODE(); - if (rc < 0) { - status = gnutls_error_to_ntstatus(rc, NT_STATUS_CRYPTO_SYSTEM_INVALID); - goto failed; -@@ -584,7 +599,17 @@ NTSTATUS samr_set_password(struct dcesrv_call_state *dce_call, - DATA_BLOB session_key = data_blob(NULL, 0); - gnutls_cipher_hd_t cipher_hnd = NULL; - gnutls_datum_t _session_key; -+ struct auth_session_info *session_info = -+ dcesrv_call_session_info(dce_call); -+ struct loadparm_context *lp_ctx = dce_call->conn->dce_ctx->lp_ctx; - int rc; -+ bool encrypted; -+ -+ encrypted = dcerpc_is_transport_encrypted(session_info); -+ if (lpcfg_weak_crypto(lp_ctx) == SAMBA_WEAK_CRYPTO_DISALLOWED && -+ !encrypted) { -+ return NT_STATUS_ACCESS_DENIED; -+ } - - nt_status = dcesrv_transport_session_key(dce_call, &session_key); - if (!NT_STATUS_IS_OK(nt_status)) { -@@ -598,11 +623,17 @@ NTSTATUS samr_set_password(struct dcesrv_call_state *dce_call, - .size = session_key.length, - }; - -+ /* -+ * This is safe to support as we only have a session key -+ * over a SMB connection which we force to be encrypted. -+ */ -+ GNUTLS_FIPS140_SET_LAX_MODE(); - rc = gnutls_cipher_init(&cipher_hnd, - GNUTLS_CIPHER_ARCFOUR_128, - &_session_key, - NULL); - if (rc < 0) { -+ GNUTLS_FIPS140_SET_STRICT_MODE(); - nt_status = gnutls_error_to_ntstatus(rc, NT_STATUS_CRYPTO_SYSTEM_INVALID); - goto out; - } -@@ -611,6 +642,7 @@ NTSTATUS samr_set_password(struct dcesrv_call_state *dce_call, - pwbuf->data, - 516); - gnutls_cipher_deinit(cipher_hnd); -+ GNUTLS_FIPS140_SET_STRICT_MODE(); - if (rc < 0) { - nt_status = gnutls_error_to_ntstatus(rc, NT_STATUS_CRYPTO_SYSTEM_INVALID); - goto out; -diff --git a/source4/rpc_server/wscript_build b/source4/rpc_server/wscript_build -index 765ae7ba62a..8c756721232 100644 ---- a/source4/rpc_server/wscript_build -+++ b/source4/rpc_server/wscript_build -@@ -80,7 +80,7 @@ bld.SAMBA_MODULE('dcesrv_samr', - autoproto='samr/proto.h', - subsystem='dcerpc_server', - init_function='dcerpc_server_samr_init', -- deps='samdb DCERPC_COMMON ndr-standard auth4_sam GNUTLS_HELPERS' -+ deps='samdb DCERPC_COMMON ndr-standard auth4_sam GNUTLS_HELPERS DCERPC_HELPER' - ) - - --- -2.33.1 - - -From 6fd9f85fbd60e1c78167a1c5a5f806a43e7add70 Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Thu, 20 Aug 2020 12:45:49 +0200 -Subject: [PATCH 082/103] lib:crypto: Add py binding for set_relax/strict fips - mode - -Signed-off-by: Isaac Boukris -Reviewed-by: Andreas Schneider -Reviewed-by: Alexander Bokovoy -(cherry picked from commit 32d4c75d6cbf9153068a0487347097707afb356a) ---- - lib/crypto/py_crypto.c | 16 ++++++++++++++++ - 1 file changed, 16 insertions(+) - -diff --git a/lib/crypto/py_crypto.c b/lib/crypto/py_crypto.c -index 32b946eee8f..ad18d3ada0f 100644 ---- a/lib/crypto/py_crypto.c -+++ b/lib/crypto/py_crypto.c -@@ -24,6 +24,7 @@ - - #include - #include -+#include "lib/crypto/gnutls_helpers.h" - - static PyObject *py_crypto_arcfour_crypt_blob(PyObject *module, PyObject *args) - { -@@ -85,12 +86,27 @@ static PyObject *py_crypto_arcfour_crypt_blob(PyObject *module, PyObject *args) - return result; - } - -+static PyObject *py_crypto_set_relax_mode(PyObject *module) -+{ -+ GNUTLS_FIPS140_SET_LAX_MODE(); -+ -+ Py_RETURN_NONE; -+} -+ -+static PyObject *py_crypto_set_strict_mode(PyObject *module) -+{ -+ GNUTLS_FIPS140_SET_STRICT_MODE(); -+ -+ Py_RETURN_NONE; -+} - - static const char py_crypto_arcfour_crypt_blob_doc[] = "arcfour_crypt_blob(data, key)\n" - "Encrypt the data with RC4 algorithm using the key"; - - static PyMethodDef py_crypto_methods[] = { - { "arcfour_crypt_blob", (PyCFunction)py_crypto_arcfour_crypt_blob, METH_VARARGS, py_crypto_arcfour_crypt_blob_doc }, -+ { "set_relax_mode", (PyCFunction)py_crypto_set_relax_mode, METH_NOARGS, "Set fips to relax mode" }, -+ { "set_strict_mode", (PyCFunction)py_crypto_set_strict_mode, METH_NOARGS, "Set fips to strict mode" }, - {0}, - }; - --- -2.33.1 - - -From 13d29ab8debfa0d92422849f85ec6bc7d9697adc Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Wed, 28 Oct 2020 17:05:36 +0100 -Subject: [PATCH 083/103] s4:param: Add 'weak crypto' getter to pyparam - -Signed-off-by: Andreas Schneider -Reviewed-by: Alexander Bokovoy -(cherry picked from commit 7d54e4b49c235dc571f47d15e6b0a6fa63340773) ---- - source4/param/pyparam.c | 22 ++++++++++++++++++++++ - 1 file changed, 22 insertions(+) - -diff --git a/source4/param/pyparam.c b/source4/param/pyparam.c -index 4023fac4dd6..e15592b5743 100644 ---- a/source4/param/pyparam.c -+++ b/source4/param/pyparam.c -@@ -463,6 +463,23 @@ static PyObject *py_lp_ctx_config_file(PyObject *self, void *closure) - return PyUnicode_FromString(configfile); - } - -+static PyObject *py_lp_ctx_weak_crypto(PyObject *self, void *closure) -+{ -+ enum samba_weak_crypto weak_crypto = -+ lpcfg_weak_crypto(PyLoadparmContext_AsLoadparmContext(self)); -+ -+ switch(weak_crypto) { -+ case SAMBA_WEAK_CRYPTO_UNKNOWN: -+ Py_RETURN_NONE; -+ case SAMBA_WEAK_CRYPTO_ALLOWED: -+ return PyUnicode_FromString("allowed"); -+ case SAMBA_WEAK_CRYPTO_DISALLOWED: -+ return PyUnicode_FromString("disallowed"); -+ } -+ -+ Py_RETURN_NONE; -+} -+ - static PyGetSetDef py_lp_ctx_getset[] = { - { - .name = discard_const_p(char, "default_service"), -@@ -473,6 +490,11 @@ static PyGetSetDef py_lp_ctx_getset[] = { - .get = (getter)py_lp_ctx_config_file, - .doc = discard_const_p(char, "Name of last config file that was loaded.") - }, -+ { -+ .name = discard_const_p(char, "weak_crypto"), -+ .get = (getter)py_lp_ctx_weak_crypto, -+ .doc = discard_const_p(char, "If weak crypto is allowed.") -+ }, - { .name = NULL } - }; - --- -2.33.1 - - -From a456c0ed4f3845a6d10efa9f2f96275daaa9d751 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Wed, 21 Oct 2020 10:09:22 +0200 -Subject: [PATCH 084/103] python:tests: Add SAMR password change tests for fips - -Signed-off-by: Andreas Schneider -Reviewed-by: Alexander Bokovoy -(cherry picked from commit 9a3ba502d8193b25799ef92917efafd52de2e8c2) ---- - .../tests/dcerpc/samr_change_password.py | 188 ++++++++++++++++++ - selftest/tests.py | 2 + - 2 files changed, 190 insertions(+) - create mode 100644 python/samba/tests/dcerpc/samr_change_password.py - -diff --git a/python/samba/tests/dcerpc/samr_change_password.py b/python/samba/tests/dcerpc/samr_change_password.py -new file mode 100644 -index 00000000000..109eeea98cc ---- /dev/null -+++ b/python/samba/tests/dcerpc/samr_change_password.py -@@ -0,0 +1,188 @@ -+# Unix SMB/CIFS implementation. -+# -+# Copyright © 2020 Andreas Schneider -+# -+# This program is free software; you can redistribute it and/or modify -+# it under the terms of the GNU General Public License as published by -+# the Free Software Foundation; either version 3 of the License, or -+# (at your option) any later version. -+# -+# This program is distributed in the hope that it will be useful, -+# but WITHOUT ANY WARRANTY; without even the implied warranty of -+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the -+# GNU General Public License for more details. -+# -+# You should have received a copy of the GNU General Public License -+# along with this program. If not, see . -+# -+ -+"""Tests for samba.dcerpc.samr.password""" -+ -+import os -+import ctypes -+import samba.tests -+ -+from samba import crypto, generate_random_password, generate_random_bytes, ntstatus -+from samba.auth import system_session -+from samba.credentials import Credentials -+from samba.credentials import SMB_ENCRYPTION_REQUIRED -+from samba.dcerpc import samr, security, lsa -+from samba.samdb import SamDB -+from samba.tests import RpcInterfaceTestCase -+ -+ -+class SamrPasswordTests(RpcInterfaceTestCase): -+ def setUp(self): -+ super(SamrPasswordTests, self).setUp() -+ self.open_samdb() -+ -+ self.create_user_account(10000) -+ -+ self.remote_server = samba.tests.env_get_var_value('SERVER') -+ self.remote_domain = samba.tests.env_get_var_value('DOMAIN') -+ self.remote_user = samba.tests.env_get_var_value('USERNAME') -+ self.remote_password = samba.tests.env_get_var_value('PASSWORD') -+ self.remote_binding_string = "ncacn_np:%s[krb5]" % (self.remote_server) -+ -+ self.remote_creds = Credentials() -+ self.remote_creds.guess(self.lp) -+ self.remote_creds.set_username(self.remote_user) -+ self.remote_creds.set_password(self.remote_password) -+ -+ def tearDown(self): -+ super(SamrPasswordTests, self).tearDown() -+ -+ samr.Close(self.user_handle) -+ samr.Close(self.domain_handle) -+ samr.Close(self.handle) -+ -+ samba.tests.delete_force(self.samdb, self.user_dn) -+ -+ # -+ # Open the samba database -+ # -+ def open_samdb(self): -+ self.lp = samba.tests.env_loadparm() -+ -+ self.local_creds = Credentials() -+ self.local_creds.guess(self.lp) -+ self.session = system_session() -+ self.samdb = SamDB(session_info=self.session, -+ credentials=self.local_creds, -+ lp=self.lp) -+ -+ # -+ # Open a SAMR Domain handle -+ # -+ def open_domain_handle(self): -+ self.handle = self.conn.Connect2(None, -+ security.SEC_FLAG_MAXIMUM_ALLOWED) -+ -+ self.domain_sid = self.conn.LookupDomain(self.handle, -+ lsa.String(self.remote_domain)) -+ -+ self.domain_handle = self.conn.OpenDomain(self.handle, -+ security.SEC_FLAG_MAXIMUM_ALLOWED, -+ self.domain_sid) -+ -+ def open_user_handle(self): -+ name = lsa.String(self.user_name) -+ -+ rids = self.conn.LookupNames(self.domain_handle, [name]) -+ -+ self.user_handle = self.conn.OpenUser(self.domain_handle, -+ security.SEC_FLAG_MAXIMUM_ALLOWED, -+ rids[0].ids[0]) -+ # -+ # Create a test user account -+ # -+ def create_user_account(self, user_id): -+ self.user_name = ("SAMR_USER_%d" % user_id) -+ self.user_pass = generate_random_password(32, 32) -+ self.user_dn = "cn=%s,cn=users,%s" % (self.user_name, self.samdb.domain_dn()) -+ -+ samba.tests.delete_force(self.samdb, self.user_dn) -+ -+ self.samdb.newuser(self.user_name, -+ self.user_pass, -+ description="Password for " + self.user_name + " is " + self.user_pass, -+ givenname=self.user_name, -+ surname=self.user_name) -+ -+ -+ def init_samr_CryptPassword(self, password, session_key): -+ -+ def encode_pw_buffer(password): -+ data = bytearray([0] * 516) -+ -+ p = samba.string_to_byte_array(password.encode('utf-16-le')) -+ plen = len(p) -+ -+ b = generate_random_bytes(512 - plen) -+ -+ i = 512 - plen -+ data[0:i] = b -+ data[i:i+plen] = p -+ data[512:516] = plen.to_bytes(4, byteorder='little') -+ -+ return bytes(data) -+ -+ # This is a test, so always allow to encrypt using RC4 -+ try: -+ crypto.set_relax_mode() -+ encrypted_blob = samba.arcfour_encrypt(session_key, encode_pw_buffer(password)) -+ finally: -+ crypto.set_strict_mode() -+ -+ out_blob = samr.CryptPassword() -+ out_blob.data = list(encrypted_blob) -+ -+ return out_blob -+ -+ -+ def test_setUserInfo2_Password(self, password='P@ssw0rd'): -+ self.conn = samr.samr(self.remote_binding_string, -+ self.get_loadparm(), -+ self.remote_creds) -+ self.open_domain_handle() -+ self.open_user_handle() -+ -+ password='P@ssw0rd' -+ -+ level = 24 -+ info = samr.UserInfo24() -+ -+ info.password_expired = 0 -+ info.password = self.init_samr_CryptPassword(password, self.conn.session_key) -+ -+ # If the server is in FIPS mode, it should reject the password change! -+ try: -+ self.conn.SetUserInfo2(self.user_handle, level, info) -+ except samba.NTSTATUSError as e: -+ code = ctypes.c_uint32(e.args[0]).value -+ print(code) -+ if ((code == ntstatus.NT_STATUS_ACCESS_DENIED) and -+ (self.lp.weak_crypto == 'disallowed')): -+ pass -+ else: -+ raise -+ -+ -+ def test_setUserInfo2_Password_Encrypted(self, password='P@ssw0rd'): -+ self.remote_creds.set_smb_encryption(SMB_ENCRYPTION_REQUIRED) -+ -+ self.conn = samr.samr(self.remote_binding_string, -+ self.get_loadparm(), -+ self.remote_creds) -+ self.open_domain_handle() -+ self.open_user_handle() -+ -+ password='P@ssw0rd' -+ -+ level = 24 -+ info = samr.UserInfo24() -+ -+ info.password_expired = 0 -+ info.password = self.init_samr_CryptPassword(password, self.conn.session_key) -+ -+ self.conn.SetUserInfo2(self.user_handle, level, info) -diff --git a/selftest/tests.py b/selftest/tests.py -index f3fcdca4ab3..7fdd9788014 100644 ---- a/selftest/tests.py -+++ b/selftest/tests.py -@@ -94,6 +94,8 @@ planpythontestsuite( - os.path.join(samba4srcdir, "..", "third_party", "waf")]) - planpythontestsuite("fileserver", "samba.tests.smbd_fuzztest") - planpythontestsuite("nt4_dc_smb1", "samba.tests.dcerpc.binding") -+for env in [ 'ad_dc:local', 'ad_dc_fips:local' ]: -+ planpythontestsuite(env, "samba.tests.dcerpc.samr_change_password") - - - def cmdline(script, *args): --- -2.33.1 - - -From ec553d4d01d03616d6c7fe630753652396081b15 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Wed, 21 Oct 2020 10:09:22 +0200 -Subject: [PATCH 085/103] python:tests: Add SAMR password change tests for fips - -Signed-off-by: Andreas Schneider -Reviewed-by: Alexander Bokovoy - -Autobuild-User(master): Andreas Schneider -Autobuild-Date(master): Thu Oct 29 15:41:37 UTC 2020 on sn-devel-184 - -(cherry picked from commit ebd687335b9accfdbae7dbc65c9882ab4d5c0986) ---- - selftest/target/Samba4.pm | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/selftest/target/Samba4.pm b/selftest/target/Samba4.pm -index 156dc16bda0..651faa73ec7 100755 ---- a/selftest/target/Samba4.pm -+++ b/selftest/target/Samba4.pm -@@ -1078,7 +1078,7 @@ servicePrincipalName: http/testupnspn.$ctx->{dnsname} - - $samba_tool_cmd = ${cmd_env}; - $samba_tool_cmd .= Samba::bindir_path($self, "samba-tool") -- . " group addmembers --configfile=$ctx->{smb_conf} 'Allowed RODC Password Replication Group' '$testallowed_account'"; -+ . " group addmembers --configfile=$ctx->{smb_conf} 'Allowed RODC Password Replication Group' '$testallowed_account' -d10"; - unless (system($samba_tool_cmd) == 0) { - warn("Unable to add '$testallowed_account' user to 'Allowed RODC Password Replication Group': \n$samba_tool_cmd\n"); - return undef; --- -2.33.1 - - -From 0f45e361a6bbb69b0e32ad163e91f0706826b3d5 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 20 Aug 2020 09:40:41 +0200 -Subject: [PATCH 086/103] auth:creds: Rename CRED_USE_KERBEROS values - -Signed-off-by: Andreas Schneider -Reviewed-by: Alexander Bokovoy -(cherry picked from commit 1298280a22ef7494fb85a6a5953bae15d22fa204) ---- - auth/credentials/credentials.c | 8 +++++--- - auth/credentials/credentials.h | 9 ++++++--- - auth/credentials/credentials_krb5.c | 4 ++-- - auth/credentials/credentials_ntlm.c | 2 +- - auth/credentials/credentials_secrets.c | 5 +++-- - auth/credentials/pycredentials.c | 6 +++--- - auth/credentials/tests/simple.c | 2 +- - auth/credentials/wscript_build | 2 +- - auth/gensec/gensec_start.c | 8 ++++---- - examples/winexe/winexe.c | 4 ++-- - source3/auth/auth_generic.c | 4 ++-- - source3/lib/util_cmdline.c | 18 +++++++++--------- - source3/libads/sasl.c | 8 ++++---- - source3/libnet/libnet_join.c | 2 +- - source3/libsmb/cliconnect.c | 18 +++++++++--------- - source3/passdb/passdb.c | 6 +++--- - source3/passdb/pdb_samba_dsdb.c | 4 ++-- - source3/rpc_client/cli_pipe.c | 2 +- - source3/rpcclient/rpcclient.c | 8 ++++---- - source3/utils/net_ads.c | 2 +- - source3/utils/net_util.c | 6 +++--- - source3/utils/ntlm_auth.c | 4 ++-- - source3/winbindd/winbindd_cm.c | 2 +- - source4/auth/gensec/gensec_gssapi.c | 2 +- - source4/auth/session.c | 2 +- - source4/lib/cmdline/popt_credentials.c | 4 ++-- - source4/libcli/smb_composite/sesssetup.c | 6 +++--- - source4/torture/ldap/session_expiry.c | 2 +- - source4/torture/raw/session.c | 4 ++-- - source4/torture/rpc/schannel.c | 4 ++-- - source4/torture/smb2/session.c | 12 ++++++------ - 31 files changed, 88 insertions(+), 82 deletions(-) - -diff --git a/auth/credentials/credentials.c b/auth/credentials/credentials.c -index 77c35dd104b..1bdd6f15a09 100644 ---- a/auth/credentials/credentials.c -+++ b/auth/credentials/credentials.c -@@ -44,6 +44,8 @@ _PUBLIC_ struct cli_credentials *cli_credentials_init(TALLOC_CTX *mem_ctx) - - cred->winbind_separator = '\\'; - -+ cred->use_kerberos = CRED_USE_KERBEROS_DESIRED; -+ - cred->signing_state = SMB_SIGNING_DEFAULT; - - /* -@@ -360,7 +362,7 @@ _PUBLIC_ bool cli_credentials_authentication_requested(struct cli_credentials *c - return true; - } - -- if (cli_credentials_get_kerberos_state(cred) == CRED_MUST_USE_KERBEROS) { -+ if (cli_credentials_get_kerberos_state(cred) == CRED_USE_KERBEROS_REQUIRED) { - return true; - } - -@@ -1018,7 +1020,7 @@ _PUBLIC_ void cli_credentials_guess(struct cli_credentials *cred, - } - - if (lp_ctx != NULL && -- cli_credentials_get_kerberos_state(cred) != CRED_DONT_USE_KERBEROS) { -+ cli_credentials_get_kerberos_state(cred) != CRED_USE_KERBEROS_DISABLED) { - cli_credentials_set_ccache(cred, lp_ctx, NULL, CRED_GUESS_FILE, - &error_string); - } -@@ -1097,7 +1099,7 @@ _PUBLIC_ void cli_credentials_set_anonymous(struct cli_credentials *cred) - cli_credentials_set_principal(cred, NULL, CRED_SPECIFIED); - cli_credentials_set_realm(cred, NULL, CRED_SPECIFIED); - cli_credentials_set_workstation(cred, "", CRED_UNINITIALISED); -- cli_credentials_set_kerberos_state(cred, CRED_DONT_USE_KERBEROS); -+ cli_credentials_set_kerberos_state(cred, CRED_USE_KERBEROS_DISABLED); - } - - /** -diff --git a/auth/credentials/credentials.h b/auth/credentials/credentials.h -index 438bcdce232..f468b8558dd 100644 ---- a/auth/credentials/credentials.h -+++ b/auth/credentials/credentials.h -@@ -53,9 +53,12 @@ enum credentials_obtained { - }; - - enum credentials_use_kerberos { -- CRED_AUTO_USE_KERBEROS = 0, /* Default, we try kerberos if available */ -- CRED_DONT_USE_KERBEROS, /* Sometimes trying kerberos just does 'bad things', so don't */ -- CRED_MUST_USE_KERBEROS /* Sometimes administrators are parinoid, so always do kerberos */ -+ /** Sometimes trying kerberos just does 'bad things', so don't */ -+ CRED_USE_KERBEROS_DISABLED = 0, -+ /** Default, we try kerberos if available */ -+ CRED_USE_KERBEROS_DESIRED, -+ /** Sometimes administrators are paranoid, so always do kerberos */ -+ CRED_USE_KERBEROS_REQUIRED, - }; - - enum credentials_krb_forwardable { -diff --git a/auth/credentials/credentials_krb5.c b/auth/credentials/credentials_krb5.c -index 2d2fccfff88..aeab550a0a6 100644 ---- a/auth/credentials/credentials_krb5.c -+++ b/auth/credentials/credentials_krb5.c -@@ -871,7 +871,7 @@ _PUBLIC_ int cli_credentials_get_client_gss_creds(struct cli_credentials *cred, - ret = cli_credentials_get_ccache(cred, event_ctx, lp_ctx, - &ccache, error_string); - if (ret) { -- if (cli_credentials_get_kerberos_state(cred) == CRED_MUST_USE_KERBEROS) { -+ if (cli_credentials_get_kerberos_state(cred) == CRED_USE_KERBEROS_REQUIRED) { - DEBUG(1, ("Failed to get kerberos credentials (kerberos required): %s\n", *error_string)); - } else { - DEBUG(4, ("Failed to get kerberos credentials: %s\n", *error_string)); -@@ -1431,7 +1431,7 @@ _PUBLIC_ void cli_credentials_set_impersonate_principal(struct cli_credentials * - cred->impersonate_principal = talloc_strdup(cred, principal); - talloc_free(cred->self_service); - cred->self_service = talloc_strdup(cred, self_service); -- cli_credentials_set_kerberos_state(cred, CRED_MUST_USE_KERBEROS); -+ cli_credentials_set_kerberos_state(cred, CRED_USE_KERBEROS_REQUIRED); - } - - /* -diff --git a/auth/credentials/credentials_ntlm.c b/auth/credentials/credentials_ntlm.c -index f1b22a6c9e2..1bec60e5dce 100644 ---- a/auth/credentials/credentials_ntlm.c -+++ b/auth/credentials/credentials_ntlm.c -@@ -53,7 +53,7 @@ _PUBLIC_ NTSTATUS cli_credentials_get_ntlm_response(struct cli_credentials *cred - const struct samr_Password *nt_hash = NULL; - int rc; - -- if (cred->use_kerberos == CRED_MUST_USE_KERBEROS) { -+ if (cred->use_kerberos == CRED_USE_KERBEROS_REQUIRED) { - TALLOC_FREE(frame); - return NT_STATUS_INVALID_PARAMETER_MIX; - } -diff --git a/auth/credentials/credentials_secrets.c b/auth/credentials/credentials_secrets.c -index 52a89d4d5b4..58067a5bece 100644 ---- a/auth/credentials/credentials_secrets.c -+++ b/auth/credentials/credentials_secrets.c -@@ -370,7 +370,8 @@ _PUBLIC_ NTSTATUS cli_credentials_set_machine_account_db_ctx(struct cli_credenti - } - - if (secrets_tdb_password_more_recent) { -- enum credentials_use_kerberos use_kerberos = CRED_DONT_USE_KERBEROS; -+ enum credentials_use_kerberos use_kerberos = -+ CRED_USE_KERBEROS_DISABLED; - char *machine_account = talloc_asprintf(tmp_ctx, "%s$", lpcfg_netbios_name(lp_ctx)); - cli_credentials_set_password(cred, secrets_tdb_password, CRED_SPECIFIED); - cli_credentials_set_old_password(cred, secrets_tdb_old_password, CRED_SPECIFIED); -@@ -386,7 +387,7 @@ _PUBLIC_ NTSTATUS cli_credentials_set_machine_account_db_ctx(struct cli_credenti - - FALL_THROUGH; - case ROLE_ACTIVE_DIRECTORY_DC: -- use_kerberos = CRED_AUTO_USE_KERBEROS; -+ use_kerberos = CRED_USE_KERBEROS_DESIRED; - break; - } - } -diff --git a/auth/credentials/pycredentials.c b/auth/credentials/pycredentials.c -index f588d6c962e..5a168e6dd7f 100644 ---- a/auth/credentials/pycredentials.c -+++ b/auth/credentials/pycredentials.c -@@ -1490,9 +1490,9 @@ MODULE_INIT_FUNC(credentials) - PyModule_AddObject(m, "CALLBACK_RESULT", PyLong_FromLong(CRED_CALLBACK_RESULT)); - PyModule_AddObject(m, "SPECIFIED", PyLong_FromLong(CRED_SPECIFIED)); - -- PyModule_AddObject(m, "AUTO_USE_KERBEROS", PyLong_FromLong(CRED_AUTO_USE_KERBEROS)); -- PyModule_AddObject(m, "DONT_USE_KERBEROS", PyLong_FromLong(CRED_DONT_USE_KERBEROS)); -- PyModule_AddObject(m, "MUST_USE_KERBEROS", PyLong_FromLong(CRED_MUST_USE_KERBEROS)); -+ PyModule_AddObject(m, "AUTO_USE_KERBEROS", PyLong_FromLong(CRED_USE_KERBEROS_DESIRED)); -+ PyModule_AddObject(m, "DONT_USE_KERBEROS", PyLong_FromLong(CRED_USE_KERBEROS_DISABLED)); -+ PyModule_AddObject(m, "MUST_USE_KERBEROS", PyLong_FromLong(CRED_USE_KERBEROS_REQUIRED)); - - PyModule_AddObject(m, "AUTO_KRB_FORWARDABLE", PyLong_FromLong(CRED_AUTO_KRB_FORWARDABLE)); - PyModule_AddObject(m, "NO_KRB_FORWARDABLE", PyLong_FromLong(CRED_NO_KRB_FORWARDABLE)); -diff --git a/auth/credentials/tests/simple.c b/auth/credentials/tests/simple.c -index 7f122bed3bc..b39d7a2251b 100644 ---- a/auth/credentials/tests/simple.c -+++ b/auth/credentials/tests/simple.c -@@ -73,7 +73,7 @@ static bool test_guess(struct torture_context *tctx) - const char *passwd_fd = getenv("PASSWD_FD"); - const char *passwd_file = getenv("PASSWD_FILE"); - -- cli_credentials_set_kerberos_state(creds, CRED_MUST_USE_KERBEROS); -+ cli_credentials_set_kerberos_state(creds, CRED_USE_KERBEROS_REQUIRED); - - unsetenv("USER"); - unsetenv("PASSWD_FD"); -diff --git a/auth/credentials/wscript_build b/auth/credentials/wscript_build -index 1e3302e3e48..ad16b7d8008 100644 ---- a/auth/credentials/wscript_build -+++ b/auth/credentials/wscript_build -@@ -5,7 +5,7 @@ bld.SAMBA_LIBRARY('samba-credentials', - public_headers='credentials.h', - pc_files='samba-credentials.pc', - deps='LIBCRYPTO samba-errors events LIBCLI_AUTH samba-security CREDENTIALS_SECRETS CREDENTIALS_KRB5', -- vnum='0.1.0' -+ vnum='1.0.0' - ) - - bld.SAMBA_SUBSYSTEM('CREDENTIALS_KRB5', -diff --git a/auth/gensec/gensec_start.c b/auth/gensec/gensec_start.c -index 3f42d611140..56306efed13 100644 ---- a/auth/gensec/gensec_start.c -+++ b/auth/gensec/gensec_start.c -@@ -117,18 +117,18 @@ static const struct gensec_security_ops **gensec_use_kerberos_mechs( - } - - switch (use_kerberos) { -- case CRED_AUTO_USE_KERBEROS: -+ case CRED_USE_KERBEROS_DESIRED: - keep = true; - break; - -- case CRED_DONT_USE_KERBEROS: -+ case CRED_USE_KERBEROS_DISABLED: - if (old_gensec_list[i]->kerberos == false) { - keep = true; - } - - break; - -- case CRED_MUST_USE_KERBEROS: -+ case CRED_USE_KERBEROS_REQUIRED: - if (old_gensec_list[i]->kerberos == true) { - keep = true; - } -@@ -156,7 +156,7 @@ _PUBLIC_ const struct gensec_security_ops **gensec_security_mechs( - TALLOC_CTX *mem_ctx) - { - const struct gensec_security_ops * const *backends = gensec_security_all(); -- enum credentials_use_kerberos use_kerberos = CRED_AUTO_USE_KERBEROS; -+ enum credentials_use_kerberos use_kerberos = CRED_USE_KERBEROS_DESIRED; - bool keep_schannel = false; - - if (gensec_security != NULL) { -diff --git a/examples/winexe/winexe.c b/examples/winexe/winexe.c -index 03e7ec85198..95386211c0a 100644 ---- a/examples/winexe/winexe.c -+++ b/examples/winexe/winexe.c -@@ -283,8 +283,8 @@ static void parse_args(int argc, const char *argv[], - if (opt_kerberos) { - cli_credentials_set_kerberos_state(cred, - strcmp(opt_kerberos, "yes") -- ? CRED_MUST_USE_KERBEROS -- : CRED_DONT_USE_KERBEROS); -+ ? CRED_USE_KERBEROS_REQUIRED -+ : CRED_USE_KERBEROS_DISABLED); - } - - if (options->runas == NULL && options->runas_file != NULL) { -diff --git a/source3/auth/auth_generic.c b/source3/auth/auth_generic.c -index b429c5f9f04..fa22a0b2339 100644 ---- a/source3/auth/auth_generic.c -+++ b/source3/auth/auth_generic.c -@@ -426,9 +426,9 @@ NTSTATUS auth_generic_prepare(TALLOC_CTX *mem_ctx, - cli_credentials_set_conf(server_credentials, lp_ctx); - - if (lp_security() == SEC_ADS || USE_KERBEROS_KEYTAB) { -- cli_credentials_set_kerberos_state(server_credentials, CRED_AUTO_USE_KERBEROS); -+ cli_credentials_set_kerberos_state(server_credentials, CRED_USE_KERBEROS_DESIRED); - } else { -- cli_credentials_set_kerberos_state(server_credentials, CRED_DONT_USE_KERBEROS); -+ cli_credentials_set_kerberos_state(server_credentials, CRED_USE_KERBEROS_DISABLED); - } - - nt_status = gensec_server_start(tmp_ctx, gensec_settings, -diff --git a/source3/lib/util_cmdline.c b/source3/lib/util_cmdline.c -index 9c9e2f0ac0f..d2af34ee19b 100644 ---- a/source3/lib/util_cmdline.c -+++ b/source3/lib/util_cmdline.c -@@ -307,9 +307,9 @@ void set_cmdline_auth_info_use_kerberos(struct user_auth_info *auth_info, - enum credentials_use_kerberos krb5_state; - - if (b) { -- krb5_state = CRED_MUST_USE_KERBEROS; -+ krb5_state = CRED_USE_KERBEROS_REQUIRED; - } else { -- krb5_state = CRED_DONT_USE_KERBEROS; -+ krb5_state = CRED_USE_KERBEROS_DISABLED; - } - - cli_credentials_set_kerberos_state(auth_info->creds, krb5_state); -@@ -321,7 +321,7 @@ bool get_cmdline_auth_info_use_kerberos(const struct user_auth_info *auth_info) - - krb5_state = cli_credentials_get_kerberos_state(auth_info->creds); - -- if (krb5_state == CRED_MUST_USE_KERBEROS) { -+ if (krb5_state == CRED_USE_KERBEROS_REQUIRED) { - return true; - } - -@@ -336,17 +336,17 @@ void set_cmdline_auth_info_fallback_after_kerberos(struct user_auth_info *auth_i - krb5_state = cli_credentials_get_kerberos_state(auth_info->creds); - - switch (krb5_state) { -- case CRED_MUST_USE_KERBEROS: -+ case CRED_USE_KERBEROS_REQUIRED: - if (b) { -- krb5_state = CRED_AUTO_USE_KERBEROS; -+ krb5_state = CRED_USE_KERBEROS_DESIRED; - } - break; -- case CRED_AUTO_USE_KERBEROS: -+ case CRED_USE_KERBEROS_DESIRED: - if (!b) { -- krb5_state = CRED_MUST_USE_KERBEROS; -+ krb5_state = CRED_USE_KERBEROS_REQUIRED; - } - break; -- case CRED_DONT_USE_KERBEROS: -+ case CRED_USE_KERBEROS_DISABLED: - /* nothing to do */ - break; - } -@@ -360,7 +360,7 @@ bool get_cmdline_auth_info_fallback_after_kerberos(const struct user_auth_info * - - krb5_state = cli_credentials_get_kerberos_state(auth_info->creds); - -- if (krb5_state == CRED_AUTO_USE_KERBEROS) { -+ if (krb5_state == CRED_USE_KERBEROS_DESIRED) { - return true; - } - -diff --git a/source3/libads/sasl.c b/source3/libads/sasl.c -index 87beeafe3ed..90ffa040ec0 100644 ---- a/source3/libads/sasl.c -+++ b/source3/libads/sasl.c -@@ -158,7 +158,7 @@ static ADS_STATUS ads_sasl_spnego_gensec_bind(ADS_STRUCT *ads, - use_spnego_principal = false; - } - -- if (krb5_state == CRED_DONT_USE_KERBEROS) { -+ if (krb5_state == CRED_USE_KERBEROS_DISABLED) { - use_spnego_principal = false; - } - -@@ -565,7 +565,7 @@ static ADS_STATUS ads_sasl_spnego_bind(ADS_STRUCT *ads) - { - - status = ads_sasl_spnego_gensec_bind(ads, "GSS-SPNEGO", -- CRED_MUST_USE_KERBEROS, -+ CRED_USE_KERBEROS_REQUIRED, - p.service, p.hostname, - blob); - if (ADS_ERR_OK(status)) { -@@ -581,7 +581,7 @@ static ADS_STATUS ads_sasl_spnego_bind(ADS_STRUCT *ads) - - if (ADS_ERR_OK(status)) { - status = ads_sasl_spnego_gensec_bind(ads, "GSS-SPNEGO", -- CRED_MUST_USE_KERBEROS, -+ CRED_USE_KERBEROS_REQUIRED, - p.service, p.hostname, - blob); - if (!ADS_ERR_OK(status)) { -@@ -616,7 +616,7 @@ static ADS_STATUS ads_sasl_spnego_bind(ADS_STRUCT *ads) - library for HMAC_MD4 encryption */ - mech = "NTLMSSP"; - status = ads_sasl_spnego_gensec_bind(ads, "GSS-SPNEGO", -- CRED_DONT_USE_KERBEROS, -+ CRED_USE_KERBEROS_DISABLED, - p.service, p.hostname, - data_blob_null); - done: -diff --git a/source3/libnet/libnet_join.c b/source3/libnet/libnet_join.c -index f3bf27e6c00..bd3aeec9434 100644 ---- a/source3/libnet/libnet_join.c -+++ b/source3/libnet/libnet_join.c -@@ -1707,7 +1707,7 @@ NTSTATUS libnet_join_ok(struct messaging_context *msg_ctx, - - if (use_kerberos) { - cli_credentials_set_kerberos_state(cli_creds, -- CRED_MUST_USE_KERBEROS); -+ CRED_USE_KERBEROS_REQUIRED); - } - - status = cli_full_connection_creds(&cli, NULL, -diff --git a/source3/libsmb/cliconnect.c b/source3/libsmb/cliconnect.c -index 45eafa97885..f8be0cd5a90 100644 ---- a/source3/libsmb/cliconnect.c -+++ b/source3/libsmb/cliconnect.c -@@ -124,13 +124,13 @@ struct cli_credentials *cli_session_creds_init(TALLOC_CTX *mem_ctx, - - if (use_kerberos && fallback_after_kerberos) { - cli_credentials_set_kerberos_state(creds, -- CRED_AUTO_USE_KERBEROS); -+ CRED_USE_KERBEROS_DESIRED); - } else if (use_kerberos) { - cli_credentials_set_kerberos_state(creds, -- CRED_MUST_USE_KERBEROS); -+ CRED_USE_KERBEROS_REQUIRED); - } else { - cli_credentials_set_kerberos_state(creds, -- CRED_DONT_USE_KERBEROS); -+ CRED_USE_KERBEROS_DISABLED); - } - - if (use_ccache) { -@@ -255,7 +255,7 @@ NTSTATUS cli_session_creds_prepare_krb5(struct cli_state *cli, - - krb5_state = cli_credentials_get_kerberos_state(creds); - -- if (krb5_state != CRED_DONT_USE_KERBEROS) { -+ if (krb5_state != CRED_USE_KERBEROS_DISABLED) { - try_kerberos = true; - } - -@@ -275,7 +275,7 @@ NTSTATUS cli_session_creds_prepare_krb5(struct cli_state *cli, - try_kerberos = false; - } - -- if (krb5_state == CRED_MUST_USE_KERBEROS && !try_kerberos) { -+ if (krb5_state == CRED_USE_KERBEROS_REQUIRED && !try_kerberos) { - DEBUG(0, ("Kerberos auth with '%s' (%s\\%s) to access " - "'%s' not possible\n", - user_principal, user_domain, user_account, -@@ -286,7 +286,7 @@ NTSTATUS cli_session_creds_prepare_krb5(struct cli_state *cli, - - if (pass == NULL || strlen(pass) == 0) { - need_kinit = false; -- } else if (krb5_state == CRED_MUST_USE_KERBEROS) { -+ } else if (krb5_state == CRED_USE_KERBEROS_REQUIRED) { - need_kinit = try_kerberos; - } else { - need_kinit = try_kerberos; -@@ -321,14 +321,14 @@ NTSTATUS cli_session_creds_prepare_krb5(struct cli_state *cli, - if (ret != 0) { - int dbglvl = DBGLVL_NOTICE; - -- if (krb5_state == CRED_MUST_USE_KERBEROS) { -+ if (krb5_state == CRED_USE_KERBEROS_REQUIRED) { - dbglvl = DBGLVL_ERR; - } - - DEBUG(dbglvl, ("Kinit for %s to access %s failed: %s\n", - user_principal, target_hostname, - error_message(ret))); -- if (krb5_state == CRED_MUST_USE_KERBEROS) { -+ if (krb5_state == CRED_USE_KERBEROS_REQUIRED) { - TALLOC_FREE(frame); - return krb5_to_nt_status(ret); - } -@@ -1486,7 +1486,7 @@ struct tevent_req *cli_session_setup_creds_send(TALLOC_CTX *mem_ctx, - return req; - } - -- if (krb5_state == CRED_MUST_USE_KERBEROS) { -+ if (krb5_state == CRED_USE_KERBEROS_REQUIRED) { - DBG_WARNING("Kerberos authentication requested, but " - "the server does not support SPNEGO authentication\n"); - tevent_req_nterror(req, NT_STATUS_NETWORK_CREDENTIAL_CONFLICT); -diff --git a/source3/passdb/passdb.c b/source3/passdb/passdb.c -index 8ed1bafcea3..b12c845d9d2 100644 ---- a/source3/passdb/passdb.c -+++ b/source3/passdb/passdb.c -@@ -2630,7 +2630,7 @@ NTSTATUS pdb_get_trust_credentials(const char *netbios_domain, - /* - * It's not possible to use NTLMSSP with a domain trust account. - */ -- cli_credentials_set_kerberos_state(creds, CRED_MUST_USE_KERBEROS); -+ cli_credentials_set_kerberos_state(creds, CRED_USE_KERBEROS_REQUIRED); - } else { - /* - * We can't use kerberos against an NT4 domain. -@@ -2638,7 +2638,7 @@ NTSTATUS pdb_get_trust_credentials(const char *netbios_domain, - * We should have a mode that also disallows NTLMSSP here, - * as only NETLOGON SCHANNEL is possible. - */ -- cli_credentials_set_kerberos_state(creds, CRED_DONT_USE_KERBEROS); -+ cli_credentials_set_kerberos_state(creds, CRED_USE_KERBEROS_DISABLED); - } - - ok = cli_credentials_set_username(creds, account_name, CRED_SPECIFIED); -@@ -2656,7 +2656,7 @@ NTSTATUS pdb_get_trust_credentials(const char *netbios_domain, - /* - * We currently can't do kerberos just with an NTHASH. - */ -- cli_credentials_set_kerberos_state(creds, CRED_DONT_USE_KERBEROS); -+ cli_credentials_set_kerberos_state(creds, CRED_USE_KERBEROS_DISABLED); - goto done; - } - -diff --git a/source3/passdb/pdb_samba_dsdb.c b/source3/passdb/pdb_samba_dsdb.c -index 276bda88efc..93e8f5bebe6 100644 ---- a/source3/passdb/pdb_samba_dsdb.c -+++ b/source3/passdb/pdb_samba_dsdb.c -@@ -2599,13 +2599,13 @@ static NTSTATUS pdb_samba_dsdb_get_trusteddom_creds(struct pdb_methods *m, - * Force kerberos if this is an active directory domain - */ - cli_credentials_set_kerberos_state(creds, -- CRED_MUST_USE_KERBEROS); -+ CRED_USE_KERBEROS_REQUIRED); - } else { - /* - * TODO: we should allow krb5 with the raw nt hash. - */ - cli_credentials_set_kerberos_state(creds, -- CRED_DONT_USE_KERBEROS); -+ CRED_USE_KERBEROS_DISABLED); - } - - *_creds = talloc_move(mem_ctx, &creds); -diff --git a/source3/rpc_client/cli_pipe.c b/source3/rpc_client/cli_pipe.c -index 408c0063baf..a51aa4b2f6d 100644 ---- a/source3/rpc_client/cli_pipe.c -+++ b/source3/rpc_client/cli_pipe.c -@@ -2638,7 +2638,7 @@ NTSTATUS rpccli_ncalrpc_bind_data(TALLOC_CTX *mem_ctx, - NAME_NT_AUTHORITY, /* domain */ - "SYSTEM", - NULL, /* password */ -- CRED_DONT_USE_KERBEROS, -+ CRED_USE_KERBEROS_DISABLED, - NULL, /* netlogon_creds_CredentialState */ - presult); - } -diff --git a/source3/rpcclient/rpcclient.c b/source3/rpcclient/rpcclient.c -index 575a42ebf70..a38f69f5592 100644 ---- a/source3/rpcclient/rpcclient.c -+++ b/source3/rpcclient/rpcclient.c -@@ -810,19 +810,19 @@ static NTSTATUS do_cmd(struct cli_state *cli, - case DCERPC_AUTH_TYPE_SPNEGO: - switch (pipe_default_auth_spnego_type) { - case PIPE_AUTH_TYPE_SPNEGO_NTLMSSP: -- krb5_state = CRED_DONT_USE_KERBEROS; -+ krb5_state = CRED_USE_KERBEROS_DISABLED; - break; - case PIPE_AUTH_TYPE_SPNEGO_KRB5: -- krb5_state = CRED_MUST_USE_KERBEROS; -+ krb5_state = CRED_USE_KERBEROS_REQUIRED; - break; - case PIPE_AUTH_TYPE_SPNEGO_NONE: -- krb5_state = CRED_AUTO_USE_KERBEROS; -+ krb5_state = CRED_USE_KERBEROS_DESIRED; - break; - } - FALL_THROUGH; - case DCERPC_AUTH_TYPE_NTLMSSP: - case DCERPC_AUTH_TYPE_KRB5: -- if (krb5_state != CRED_AUTO_USE_KERBEROS) { -+ if (krb5_state != CRED_USE_KERBEROS_DESIRED) { - cli_credentials_set_kerberos_state(creds, - krb5_state); - } -diff --git a/source3/utils/net_ads.c b/source3/utils/net_ads.c -index 7f5b9c3a440..1a0e8a5c9dd 100644 ---- a/source3/utils/net_ads.c -+++ b/source3/utils/net_ads.c -@@ -2432,7 +2432,7 @@ static int net_ads_printer_publish(struct net_context *c, int argc, const char * - talloc_destroy(mem_ctx); - return -1; - } -- cli_credentials_set_kerberos_state(creds, CRED_MUST_USE_KERBEROS); -+ cli_credentials_set_kerberos_state(creds, CRED_USE_KERBEROS_REQUIRED); - - nt_status = cli_full_connection_creds(&cli, lp_netbios_name(), servername, - &server_ss, 0, -diff --git a/source3/utils/net_util.c b/source3/utils/net_util.c -index 5829d891075..6c5321db0fd 100644 ---- a/source3/utils/net_util.c -+++ b/source3/utils/net_util.c -@@ -493,13 +493,13 @@ struct cli_credentials *net_context_creds(struct net_context *c, - - if (c->opt_kerberos && c->opt_user_specified) { - cli_credentials_set_kerberos_state(creds, -- CRED_AUTO_USE_KERBEROS); -+ CRED_USE_KERBEROS_DESIRED); - } else if (c->opt_kerberos) { - cli_credentials_set_kerberos_state(creds, -- CRED_MUST_USE_KERBEROS); -+ CRED_USE_KERBEROS_REQUIRED); - } else { - cli_credentials_set_kerberos_state(creds, -- CRED_DONT_USE_KERBEROS); -+ CRED_USE_KERBEROS_DISABLED); - } - - if (c->opt_ccache) { -diff --git a/source3/utils/ntlm_auth.c b/source3/utils/ntlm_auth.c -index 5541c58350b..c1854b83bc4 100644 ---- a/source3/utils/ntlm_auth.c -+++ b/source3/utils/ntlm_auth.c -@@ -1335,9 +1335,9 @@ static NTSTATUS ntlm_auth_prepare_gensec_server(TALLOC_CTX *mem_ctx, - cli_credentials_set_conf(server_credentials, lp_ctx); - - if (lp_server_role() == ROLE_ACTIVE_DIRECTORY_DC || lp_security() == SEC_ADS || USE_KERBEROS_KEYTAB) { -- cli_credentials_set_kerberos_state(server_credentials, CRED_AUTO_USE_KERBEROS); -+ cli_credentials_set_kerberos_state(server_credentials, CRED_USE_KERBEROS_DESIRED); - } else { -- cli_credentials_set_kerberos_state(server_credentials, CRED_DONT_USE_KERBEROS); -+ cli_credentials_set_kerberos_state(server_credentials, CRED_USE_KERBEROS_DISABLED); - } - - nt_status = gensec_server_start(tmp_ctx, gensec_settings, -diff --git a/source3/winbindd/winbindd_cm.c b/source3/winbindd/winbindd_cm.c -index bb819bbba19..809aed4376c 100644 ---- a/source3/winbindd/winbindd_cm.c -+++ b/source3/winbindd/winbindd_cm.c -@@ -706,7 +706,7 @@ static NTSTATUS cm_get_ipc_credentials(TALLOC_CTX *mem_ctx, - } - - cli_credentials_set_conf(creds, lp_ctx); -- cli_credentials_set_kerberos_state(creds, CRED_DONT_USE_KERBEROS); -+ cli_credentials_set_kerberos_state(creds, CRED_USE_KERBEROS_DISABLED); - - ok = cli_credentials_set_domain(creds, netbios_domain, CRED_SPECIFIED); - if (!ok) { -diff --git a/source4/auth/gensec/gensec_gssapi.c b/source4/auth/gensec/gensec_gssapi.c -index dbda18ede09..b2d4dcac8cc 100644 ---- a/source4/auth/gensec/gensec_gssapi.c -+++ b/source4/auth/gensec/gensec_gssapi.c -@@ -1560,7 +1560,7 @@ static NTSTATUS gensec_gssapi_session_info(struct gensec_security *gensec_securi - } - - /* This credential handle isn't useful for password authentication, so ensure nobody tries to do that */ -- cli_credentials_set_kerberos_state(session_info->credentials, CRED_MUST_USE_KERBEROS); -+ cli_credentials_set_kerberos_state(session_info->credentials, CRED_USE_KERBEROS_REQUIRED); - - /* It has been taken from this place... */ - gensec_gssapi_state->delegated_cred_handle = GSS_C_NO_CREDENTIAL; -diff --git a/source4/auth/session.c b/source4/auth/session.c -index c5fc226a7d7..8e44dcd24f1 100644 ---- a/source4/auth/session.c -+++ b/source4/auth/session.c -@@ -295,7 +295,7 @@ struct auth_session_info *auth_session_info_from_transport(TALLOC_CTX *mem_ctx, - /* This credential handle isn't useful for password - * authentication, so ensure nobody tries to do that */ - cli_credentials_set_kerberos_state(creds, -- CRED_MUST_USE_KERBEROS); -+ CRED_USE_KERBEROS_REQUIRED); - - } - #endif -diff --git a/source4/lib/cmdline/popt_credentials.c b/source4/lib/cmdline/popt_credentials.c -index 5dd61f6339c..7d8963da99e 100644 ---- a/source4/lib/cmdline/popt_credentials.c -+++ b/source4/lib/cmdline/popt_credentials.c -@@ -120,8 +120,8 @@ static void popt_common_credentials_callback(poptContext con, - cli_credentials_set_kerberos_state( - popt_get_cmdline_credentials(), - use_kerberos -- ? CRED_MUST_USE_KERBEROS -- : CRED_DONT_USE_KERBEROS); -+ ? CRED_USE_KERBEROS_REQUIRED -+ : CRED_USE_KERBEROS_DISABLED); - break; - } - -diff --git a/source4/libcli/smb_composite/sesssetup.c b/source4/libcli/smb_composite/sesssetup.c -index 93f6ce55177..01ca5d1341b 100644 ---- a/source4/libcli/smb_composite/sesssetup.c -+++ b/source4/libcli/smb_composite/sesssetup.c -@@ -644,7 +644,7 @@ struct composite_context *smb_composite_sesssetup_send(struct smbcli_session *se - - /* no session setup at all in earliest protocol varients */ - if (session->transport->negotiate.protocol < PROTOCOL_LANMAN1) { -- if (krb5_state == CRED_MUST_USE_KERBEROS) { -+ if (krb5_state == CRED_USE_KERBEROS_REQUIRED) { - composite_error(c, NT_STATUS_NETWORK_CREDENTIAL_CONFLICT); - return c; - } -@@ -655,14 +655,14 @@ struct composite_context *smb_composite_sesssetup_send(struct smbcli_session *se - - /* see what session setup interface we will use */ - if (session->transport->negotiate.protocol < PROTOCOL_NT1) { -- if (krb5_state == CRED_MUST_USE_KERBEROS) { -+ if (krb5_state == CRED_USE_KERBEROS_REQUIRED) { - composite_error(c, NT_STATUS_NETWORK_CREDENTIAL_CONFLICT); - return c; - } - status = session_setup_old(c, session, io, &state->req); - } else if (!session->transport->options.use_spnego || - !(io->in.capabilities & CAP_EXTENDED_SECURITY)) { -- if (krb5_state == CRED_MUST_USE_KERBEROS) { -+ if (krb5_state == CRED_USE_KERBEROS_REQUIRED) { - composite_error(c, NT_STATUS_NETWORK_CREDENTIAL_CONFLICT); - return c; - } -diff --git a/source4/torture/ldap/session_expiry.c b/source4/torture/ldap/session_expiry.c -index 35dda439b17..e5e38450745 100644 ---- a/source4/torture/ldap/session_expiry.c -+++ b/source4/torture/ldap/session_expiry.c -@@ -55,7 +55,7 @@ bool torture_ldap_session_expiry(struct torture_context *torture) - torture, url!=NULL, ret, fail, "talloc_asprintf failed"); - - cli_credentials_set_kerberos_state( -- credentials, CRED_MUST_USE_KERBEROS); -+ credentials, CRED_USE_KERBEROS_REQUIRED); - - ok = lpcfg_set_option( - torture->lp_ctx, "gensec_gssapi:requested_life_time=4"); -diff --git a/source4/torture/raw/session.c b/source4/torture/raw/session.c -index 0c460ae3069..e246d25e9fb 100644 ---- a/source4/torture/raw/session.c -+++ b/source4/torture/raw/session.c -@@ -245,12 +245,12 @@ static bool test_session_expire1(struct torture_context *tctx) - - use_kerberos = cli_credentials_get_kerberos_state( - popt_get_cmdline_credentials()); -- if (use_kerberos != CRED_MUST_USE_KERBEROS) { -+ if (use_kerberos != CRED_USE_KERBEROS_REQUIRED) { - torture_warning(tctx, "smb2.session.expire1 requires -k yes!"); - torture_skip(tctx, "smb2.session.expire1 requires -k yes!"); - } - -- torture_assert_int_equal(tctx, use_kerberos, CRED_MUST_USE_KERBEROS, -+ torture_assert_int_equal(tctx, use_kerberos, CRED_USE_KERBEROS_REQUIRED, - "please use -k yes"); - - lpcfg_set_option(tctx->lp_ctx, "gensec_gssapi:requested_life_time=4"); -diff --git a/source4/torture/rpc/schannel.c b/source4/torture/rpc/schannel.c -index 6dc58c86076..08a5120b66d 100644 ---- a/source4/torture/rpc/schannel.c -+++ b/source4/torture/rpc/schannel.c -@@ -965,8 +965,8 @@ bool torture_rpc_schannel_bench1(struct torture_context *torture) - torture_assert(torture, s->join_ctx2 != NULL, - "Failed to join domain with acct_flags=ACB_WSTRUST"); - -- cli_credentials_set_kerberos_state(s->wks_creds1, CRED_DONT_USE_KERBEROS); -- cli_credentials_set_kerberos_state(s->wks_creds2, CRED_DONT_USE_KERBEROS); -+ cli_credentials_set_kerberos_state(s->wks_creds1, CRED_USE_KERBEROS_DISABLED); -+ cli_credentials_set_kerberos_state(s->wks_creds2, CRED_USE_KERBEROS_DISABLED); - - for (i=0; i < s->nprocs; i++) { - struct cli_credentials *wks = s->wks_creds1; -diff --git a/source4/torture/smb2/session.c b/source4/torture/smb2/session.c -index 07c6faebb15..701dfc10a07 100644 ---- a/source4/torture/smb2/session.c -+++ b/source4/torture/smb2/session.c -@@ -956,7 +956,7 @@ bool test_session_reauth6(struct torture_context *tctx, struct smb2_tree *tree) - - krb_state = cli_credentials_get_kerberos_state( - popt_get_cmdline_credentials()); -- if (krb_state == CRED_MUST_USE_KERBEROS) { -+ if (krb_state == CRED_USE_KERBEROS_REQUIRED) { - torture_skip(tctx, - "Can't test failing session setup with kerberos."); - } -@@ -1064,12 +1064,12 @@ static bool test_session_expire1i(struct torture_context *tctx, - size_t i; - - use_kerberos = cli_credentials_get_kerberos_state(credentials); -- if (use_kerberos != CRED_MUST_USE_KERBEROS) { -+ if (use_kerberos != CRED_USE_KERBEROS_REQUIRED) { - torture_warning(tctx, "smb2.session.expire1 requires -k yes!"); - torture_skip(tctx, "smb2.session.expire1 requires -k yes!"); - } - -- torture_assert_int_equal(tctx, use_kerberos, CRED_MUST_USE_KERBEROS, -+ torture_assert_int_equal(tctx, use_kerberos, CRED_USE_KERBEROS_REQUIRED, - "please use -k yes"); - - cli_credentials_invalidate_ccache(credentials, CRED_SPECIFIED); -@@ -1250,12 +1250,12 @@ static bool test_session_expire2i(struct torture_context *tctx, - struct smb2_notify ntf2; - - use_kerberos = cli_credentials_get_kerberos_state(credentials); -- if (use_kerberos != CRED_MUST_USE_KERBEROS) { -+ if (use_kerberos != CRED_USE_KERBEROS_REQUIRED) { - torture_warning(tctx, "smb2.session.expire2 requires -k yes!"); - torture_skip(tctx, "smb2.session.expire2 requires -k yes!"); - } - -- torture_assert_int_equal(tctx, use_kerberos, CRED_MUST_USE_KERBEROS, -+ torture_assert_int_equal(tctx, use_kerberos, CRED_USE_KERBEROS_REQUIRED, - "please use -k yes"); - - cli_credentials_invalidate_ccache(credentials, CRED_SPECIFIED); -@@ -1612,7 +1612,7 @@ static bool test_session_expire_disconnect(struct torture_context *tctx) - bool connected; - - use_kerberos = cli_credentials_get_kerberos_state(credentials); -- if (use_kerberos != CRED_MUST_USE_KERBEROS) { -+ if (use_kerberos != CRED_USE_KERBEROS_REQUIRED) { - torture_warning(tctx, "smb2.session.expire1 requires -k yes!"); - torture_skip(tctx, "smb2.session.expire1 requires -k yes!"); - } --- -2.33.1 - - -From 764891873edeae581714601b75287868b9367a8c Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Tue, 1 Sep 2020 12:32:28 +0200 -Subject: [PATCH 087/103] auth:creds:tests: Migrate test to a cmocka unit test - -Signed-off-by: Andreas Schneider -Reviewed-by: Alexander Bokovoy -(cherry picked from commit 1a92994a9513f5e73d30604a1dc217ddeb1ac8d5) ---- - auth/credentials/tests/test_creds.c | 221 ++++++++++++++++++++++++++++ - auth/credentials/wscript_build | 6 + - selftest/tests.py | 2 + - source4/torture/local/local.c | 1 - - source4/torture/local/wscript_build | 2 +- - 5 files changed, 230 insertions(+), 2 deletions(-) - create mode 100644 auth/credentials/tests/test_creds.c - -diff --git a/auth/credentials/tests/test_creds.c b/auth/credentials/tests/test_creds.c -new file mode 100644 -index 00000000000..d2d3d30d73d ---- /dev/null -+++ b/auth/credentials/tests/test_creds.c -@@ -0,0 +1,221 @@ -+/* -+ * Unix SMB/CIFS implementation. -+ * -+ * Copyright (C) 2018-2019 Andreas Schneider -+ * -+ * This program is free software; you can redistribute it and/or modify -+ * it under the terms of the GNU General Public License as published by -+ * the Free Software Foundation; either version 3 of the License, or -+ * (at your option) any later version. -+ * -+ * This program is distributed in the hope that it will be useful, -+ * but WITHOUT ANY WARRANTY; without even the implied warranty of -+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the -+ * GNU General Public License for more details. -+ * -+ * You should have received a copy of the GNU General Public License -+ * along with this program. If not, see . -+ */ -+ -+#include -+#include -+#include -+#include -+#include -+ -+#include "lib/replace/replace.h" -+#include "auth/credentials/credentials.c" -+ -+static int setup_talloc_context(void **state) -+{ -+ TALLOC_CTX *frame = talloc_stackframe(); -+ -+ *state = frame; -+ return 0; -+} -+ -+static int teardown_talloc_context(void **state) -+{ -+ TALLOC_CTX *frame = *state; -+ TALLOC_FREE(frame); -+ return 0; -+} -+ -+static void torture_creds_init(void **state) -+{ -+ TALLOC_CTX *mem_ctx = *state; -+ struct cli_credentials *creds = NULL; -+ const char *username = NULL; -+ const char *domain = NULL; -+ const char *password = NULL; -+ bool ok; -+ -+ creds = cli_credentials_init(mem_ctx); -+ assert_non_null(creds); -+ assert_null(creds->username); -+ assert_int_equal(creds->username_obtained, CRED_UNINITIALISED); -+ -+ domain = cli_credentials_get_domain(creds); -+ assert_null(domain); -+ ok = cli_credentials_set_domain(creds, "WURST", CRED_SPECIFIED); -+ assert_true(ok); -+ assert_int_equal(creds->domain_obtained, CRED_SPECIFIED); -+ domain = cli_credentials_get_domain(creds); -+ assert_string_equal(domain, "WURST"); -+ -+ username = cli_credentials_get_username(creds); -+ assert_null(username); -+ ok = cli_credentials_set_username(creds, "brot", CRED_SPECIFIED); -+ assert_true(ok); -+ assert_int_equal(creds->username_obtained, CRED_SPECIFIED); -+ username = cli_credentials_get_username(creds); -+ assert_string_equal(username, "brot"); -+ -+ password = cli_credentials_get_password(creds); -+ assert_null(password); -+ ok = cli_credentials_set_password(creds, "SECRET", CRED_SPECIFIED); -+ assert_true(ok); -+ assert_int_equal(creds->password_obtained, CRED_SPECIFIED); -+ password = cli_credentials_get_password(creds); -+ assert_string_equal(password, "SECRET"); -+} -+ -+static void torture_creds_init_anonymous(void **state) -+{ -+ TALLOC_CTX *mem_ctx = *state; -+ struct cli_credentials *creds = NULL; -+ -+ creds = cli_credentials_init_anon(mem_ctx); -+ assert_non_null(creds); -+ -+ assert_string_equal(creds->domain, ""); -+ assert_int_equal(creds->domain_obtained, CRED_SPECIFIED); -+ -+ assert_string_equal(creds->username, ""); -+ assert_int_equal(creds->username_obtained, CRED_SPECIFIED); -+ -+ assert_null(creds->password); -+ assert_int_equal(creds->password_obtained, CRED_SPECIFIED); -+} -+ -+static void torture_creds_guess(void **state) -+{ -+ TALLOC_CTX *mem_ctx = *state; -+ struct cli_credentials *creds = NULL; -+ const char *env_user = getenv("USER"); -+ -+ creds = cli_credentials_init(mem_ctx); -+ assert_non_null(creds); -+ -+ setenv("PASSWD", "SECRET", 1); -+ cli_credentials_guess(creds, NULL); -+ -+ assert_string_equal(creds->username, env_user); -+ assert_int_equal(creds->username_obtained, CRED_GUESS_ENV); -+ -+ assert_string_equal(creds->password, "SECRET"); -+ assert_int_equal(creds->password_obtained, CRED_GUESS_ENV); -+ unsetenv("PASSWD"); -+} -+ -+static void torture_creds_anon_guess(void **state) -+{ -+ TALLOC_CTX *mem_ctx = *state; -+ struct cli_credentials *creds = NULL; -+ -+ creds = cli_credentials_init_anon(mem_ctx); -+ assert_non_null(creds); -+ -+ setenv("PASSWD", "SECRET", 1); -+ cli_credentials_guess(creds, NULL); -+ -+ assert_string_equal(creds->username, ""); -+ assert_int_equal(creds->username_obtained, CRED_SPECIFIED); -+ -+ assert_null(creds->password); -+ assert_int_equal(creds->password_obtained, CRED_SPECIFIED); -+ unsetenv("PASSWD"); -+} -+ -+static void torture_creds_parse_string(void **state) -+{ -+ TALLOC_CTX *mem_ctx = *state; -+ struct cli_credentials *creds = NULL; -+ -+ creds = cli_credentials_init(mem_ctx); -+ assert_non_null(creds); -+ -+ /* Anonymous */ -+ cli_credentials_parse_string(creds, "%", CRED_SPECIFIED); -+ -+ assert_string_equal(creds->domain, ""); -+ assert_int_equal(creds->domain_obtained, CRED_SPECIFIED); -+ -+ assert_string_equal(creds->username, ""); -+ assert_int_equal(creds->username_obtained, CRED_SPECIFIED); -+ -+ assert_null(creds->password); -+ assert_int_equal(creds->password_obtained, CRED_SPECIFIED); -+ -+ /* Username + password */ -+ cli_credentials_parse_string(creds, "wurst%BROT", CRED_SPECIFIED); -+ -+ assert_string_equal(creds->domain, ""); -+ assert_int_equal(creds->domain_obtained, CRED_SPECIFIED); -+ -+ assert_string_equal(creds->username, "wurst"); -+ assert_int_equal(creds->username_obtained, CRED_SPECIFIED); -+ -+ assert_string_equal(creds->password, "BROT"); -+ assert_int_equal(creds->password_obtained, CRED_SPECIFIED); -+ -+ /* Domain + username + password */ -+ cli_credentials_parse_string(creds, "XXL\\wurst%BROT", CRED_SPECIFIED); -+ -+ assert_string_equal(creds->domain, "XXL"); -+ assert_int_equal(creds->domain_obtained, CRED_SPECIFIED); -+ -+ assert_string_equal(creds->username, "wurst"); -+ assert_int_equal(creds->username_obtained, CRED_SPECIFIED); -+ -+ assert_string_equal(creds->password, "BROT"); -+ assert_int_equal(creds->password_obtained, CRED_SPECIFIED); -+ -+ /* Principal */ -+ cli_credentials_parse_string(creds, "wurst@brot.realm", CRED_SPECIFIED); -+ -+ assert_string_equal(creds->domain, ""); -+ assert_int_equal(creds->domain_obtained, CRED_SPECIFIED); -+ -+ assert_string_equal(creds->username, "wurst@brot.realm"); -+ assert_int_equal(creds->username_obtained, CRED_SPECIFIED); -+ -+ assert_string_equal(creds->principal, "wurst@brot.realm"); -+ assert_int_equal(creds->principal_obtained, CRED_SPECIFIED); -+ -+ assert_string_equal(creds->password, "BROT"); -+ assert_int_equal(creds->password_obtained, CRED_SPECIFIED); -+} -+ -+int main(int argc, char *argv[]) -+{ -+ int rc; -+ const struct CMUnitTest tests[] = { -+ cmocka_unit_test(torture_creds_init), -+ cmocka_unit_test(torture_creds_init_anonymous), -+ cmocka_unit_test(torture_creds_guess), -+ cmocka_unit_test(torture_creds_anon_guess), -+ cmocka_unit_test(torture_creds_parse_string), -+ }; -+ -+ if (argc == 2) { -+ cmocka_set_test_filter(argv[1]); -+ } -+ cmocka_set_message_output(CM_OUTPUT_SUBUNIT); -+ -+ rc = cmocka_run_group_tests(tests, -+ setup_talloc_context, -+ teardown_talloc_context); -+ -+ return rc; -+} -diff --git a/auth/credentials/wscript_build b/auth/credentials/wscript_build -index ad16b7d8008..46111164b36 100644 ---- a/auth/credentials/wscript_build -+++ b/auth/credentials/wscript_build -@@ -31,3 +31,9 @@ bld.SAMBA_PYTHON('pycredentials', - public_deps='samba-credentials cmdline-credentials %s %s CREDENTIALS_KRB5 CREDENTIALS_SECRETS' % (pytalloc_util, pyparam_util), - realname='samba/credentials.so' - ) -+ -+bld.SAMBA_BINARY('test_creds', -+ source='tests/test_creds.c', -+ deps='cmocka samba-credentials', -+ local_include=False, -+ for_selftest=True) -diff --git a/selftest/tests.py b/selftest/tests.py -index 7fdd9788014..7485fcc5370 100644 ---- a/selftest/tests.py -+++ b/selftest/tests.py -@@ -422,3 +422,5 @@ plantestsuite("samba.unittests.test_oLschema2ldif", "none", - if with_elasticsearch_backend: - plantestsuite("samba.unittests.mdsparser_es", "none", - [os.path.join(bindir(), "default/source3/test_mdsparser_es")] + [configuration]) -+plantestsuite("samba.unittests.credentials", "none", -+ [os.path.join(bindir(), "default/auth/credentials/test_creds")]) -diff --git a/source4/torture/local/local.c b/source4/torture/local/local.c -index a3186788524..d19b55e9502 100644 ---- a/source4/torture/local/local.c -+++ b/source4/torture/local/local.c -@@ -70,7 +70,6 @@ - torture_local_tevent_req, - torture_local_torture, - torture_local_dbspeed, -- torture_local_credentials, - torture_ldb, - torture_dsdb_dn, - torture_dsdb_syntax, -diff --git a/source4/torture/local/wscript_build b/source4/torture/local/wscript_build -index 38b6c8f4b6e..f0ab0357986 100644 ---- a/source4/torture/local/wscript_build -+++ b/source4/torture/local/wscript_build -@@ -16,7 +16,7 @@ TORTURE_LOCAL_SOURCE = '''../../../lib/util/charset/tests/iconv.c - ../../libcli/security/tests/sddl.c ../../../lib/tdr/testsuite.c - ../../../lib/tevent/testsuite.c ../../param/tests/share.c - ../../../lib/tevent/test_req.c -- ../../param/tests/loadparm.c ../../../auth/credentials/tests/simple.c local.c -+ ../../param/tests/loadparm.c local.c - dbspeed.c torture.c ../ldb/ldb.c ../../dsdb/common/tests/dsdb_dn.c - ../../dsdb/schema/tests/schema_syntax.c - ../../../lib/util/tests/anonymous_shared.c --- -2.33.1 - - -From b9e93f3dab2519458fc5dc3fee6da09ba9021ed9 Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Thu, 20 Aug 2020 12:09:05 +0200 -Subject: [PATCH 088/103] Add smb2cli_session_get_encryption_cipher() - -When 'session->smb2->should_encrypt' is true, the client MUST encrypt -all transport messages (see also MS-SMB2 3.2.4.1.8). - -Signed-off-by: Isaac Boukris -Reviewed-by: Stefan Metzmacher -Reviewed-by: Alexander Bokovoy -(cherry picked from commit f0f8de9d4a4e05445e427f00bb10eb34e1110a97) ---- - libcli/smb/smbXcli_base.c | 13 +++++++++++++ - libcli/smb/smbXcli_base.h | 1 + - 2 files changed, 14 insertions(+) - -diff --git a/libcli/smb/smbXcli_base.c b/libcli/smb/smbXcli_base.c -index bcb601dde59..91c670706fc 100644 ---- a/libcli/smb/smbXcli_base.c -+++ b/libcli/smb/smbXcli_base.c -@@ -6461,6 +6461,19 @@ NTSTATUS smb2cli_session_encryption_on(struct smbXcli_session *session) - return NT_STATUS_OK; - } - -+uint16_t smb2cli_session_get_encryption_cipher(struct smbXcli_session *session) -+{ -+ if (session->conn->protocol < PROTOCOL_SMB2_24) { -+ return 0; -+ } -+ -+ if (!session->smb2->should_encrypt) { -+ return 0; -+ } -+ -+ return session->conn->smb2.server.cipher; -+} -+ - struct smbXcli_tcon *smbXcli_tcon_create(TALLOC_CTX *mem_ctx) - { - struct smbXcli_tcon *tcon; -diff --git a/libcli/smb/smbXcli_base.h b/libcli/smb/smbXcli_base.h -index 4452cd808ea..247bac98904 100644 ---- a/libcli/smb/smbXcli_base.h -+++ b/libcli/smb/smbXcli_base.h -@@ -527,6 +527,7 @@ NTSTATUS smb2cli_session_set_channel_key(struct smbXcli_session *session, - const DATA_BLOB channel_key, - const struct iovec *recv_iov); - NTSTATUS smb2cli_session_encryption_on(struct smbXcli_session *session); -+uint16_t smb2cli_session_get_encryption_cipher(struct smbXcli_session *session); - - struct smbXcli_tcon *smbXcli_tcon_create(TALLOC_CTX *mem_ctx); - struct smbXcli_tcon *smbXcli_tcon_copy(TALLOC_CTX *mem_ctx, --- -2.33.1 - - -From 545a74f90e4ff7b74b55b84636be58eacc918af0 Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Thu, 20 Aug 2020 12:18:21 +0200 -Subject: [PATCH 089/103] Add dcerpc_transport_encrypted() - -Signed-off-by: Isaac Boukris -Reviewed-by: Stefan Metzmacher -Reviewed-by: Alexander Bokovoy -(cherry picked from commit 339bfcd67af2675d10287946d8f5dabba1022d57) ---- - source4/librpc/rpc/dcerpc.h | 2 ++ - source4/librpc/rpc/dcerpc_smb.c | 11 +++++++++++ - source4/librpc/rpc/dcerpc_util.c | 13 +++++++++++++ - 3 files changed, 26 insertions(+) - -diff --git a/source4/librpc/rpc/dcerpc.h b/source4/librpc/rpc/dcerpc.h -index 6b0b841d64d..57124f10778 100644 ---- a/source4/librpc/rpc/dcerpc.h -+++ b/source4/librpc/rpc/dcerpc.h -@@ -87,6 +87,7 @@ struct dcecli_connection { - struct dcerpc_transport { - enum dcerpc_transport_t transport; - void *private_data; -+ bool encrypted; - - struct tstream_context *stream; - /** to serialize write events */ -@@ -181,6 +182,7 @@ NTSTATUS dcerpc_bind_auth_none(struct dcerpc_pipe *p, - const struct ndr_interface_table *table); - NTSTATUS dcerpc_fetch_session_key(struct dcerpc_pipe *p, - DATA_BLOB *session_key); -+bool dcerpc_transport_encrypted(struct dcerpc_pipe *p); - struct composite_context; - NTSTATUS dcerpc_secondary_connection_recv(struct composite_context *c, - struct dcerpc_pipe **p2); -diff --git a/source4/librpc/rpc/dcerpc_smb.c b/source4/librpc/rpc/dcerpc_smb.c -index b20b154a1cb..101ed64f0cd 100644 ---- a/source4/librpc/rpc/dcerpc_smb.c -+++ b/source4/librpc/rpc/dcerpc_smb.c -@@ -145,6 +145,7 @@ static void dcerpc_pipe_open_smb_done(struct tevent_req *subreq) - struct dcerpc_pipe_open_smb_state); - struct composite_context *ctx = state->ctx; - struct dcecli_connection *c = state->c; -+ uint16_t enc_cipher; - - ctx->status = tstream_smbXcli_np_open_recv(subreq, - state->smb, -@@ -173,6 +174,16 @@ static void dcerpc_pipe_open_smb_done(struct tevent_req *subreq) - /* Over-ride the default session key with the SMB session key */ - c->security_state.session_key = smb_session_key; - -+ enc_cipher = smb2cli_session_get_encryption_cipher(state->smb->session); -+ switch (enc_cipher) { -+ case SMB2_ENCRYPTION_AES128_CCM: -+ case SMB2_ENCRYPTION_AES128_GCM: -+ c->transport.encrypted = true; -+ break; -+ default: -+ c->transport.encrypted = false; -+ } -+ - c->transport.private_data = talloc_move(c, &state->smb); - - composite_done(ctx); -diff --git a/source4/librpc/rpc/dcerpc_util.c b/source4/librpc/rpc/dcerpc_util.c -index bd79a072bc8..6ea27a8d9a3 100644 ---- a/source4/librpc/rpc/dcerpc_util.c -+++ b/source4/librpc/rpc/dcerpc_util.c -@@ -743,6 +743,19 @@ _PUBLIC_ NTSTATUS dcerpc_fetch_session_key(struct dcerpc_pipe *p, - return NT_STATUS_OK; - } - -+_PUBLIC_ bool dcerpc_transport_encrypted(struct dcerpc_pipe *p) -+{ -+ if (p == NULL) { -+ return false; -+ } -+ -+ if (p->conn == NULL) { -+ return false; -+ } -+ -+ return p->conn->transport.encrypted; -+} -+ - /* - create a secondary context from a primary connection - --- -2.33.1 - - -From 91188c527d6fda5238633de652f2c4d604af9277 Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Thu, 20 Aug 2020 12:35:01 +0200 -Subject: [PATCH 090/103] Add py binding for dcerpc_transport_encrypted - -Signed-off-by: Isaac Boukris -Reviewed-by: Stefan Metzmacher -Reviewed-by: Alexander Bokovoy -(cherry picked from commit eba91f0dfa8e3267689b4076302e257f4cecd63b) ---- - source4/librpc/rpc/pyrpc.c | 14 ++++++++++++++ - 1 file changed, 14 insertions(+) - -diff --git a/source4/librpc/rpc/pyrpc.c b/source4/librpc/rpc/pyrpc.c -index be914ed5f14..309a6d72e26 100644 ---- a/source4/librpc/rpc/pyrpc.c -+++ b/source4/librpc/rpc/pyrpc.c -@@ -293,11 +293,25 @@ static PyObject *py_iface_request(PyObject *self, PyObject *args, PyObject *kwar - return ret; - } - -+static PyObject *py_iface_transport_encrypted(PyObject *self) -+{ -+ dcerpc_InterfaceObject *iface = (dcerpc_InterfaceObject *)self; -+ -+ if (dcerpc_transport_encrypted(iface->pipe)) { -+ Py_RETURN_TRUE; -+ } -+ -+ Py_RETURN_FALSE; -+} -+ - static PyMethodDef dcerpc_interface_methods[] = { - { "request", PY_DISCARD_FUNC_SIG(PyCFunction, py_iface_request), - METH_VARARGS|METH_KEYWORDS, - "S.request(opnum, data, object=None) -> data\n" - "Make a raw request" }, -+ { "transport_encrypted", PY_DISCARD_FUNC_SIG(PyCFunction, py_iface_transport_encrypted), -+ METH_NOARGS, -+ "Check if the DCE transport is encrypted" }, - { NULL, NULL, 0, NULL }, - }; - --- -2.33.1 - - -From e107ce3136d1bda1bc1d2ee07194d1b380313ab4 Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Thu, 20 Aug 2020 12:44:08 +0200 -Subject: [PATCH 091/103] selftest: add a test for py dce transport_encrypted - -Signed-off-by: Isaac Boukris -Reviewed-by: Stefan Metzmacher -Reviewed-by: Alexander Bokovoy -(cherry picked from commit a77551bea969ce73a3dc27384d94b4126bef04f7) ---- - python/samba/tests/dcerpc/binding.py | 23 ++++++++++++++++++++++- - 1 file changed, 22 insertions(+), 1 deletion(-) - -diff --git a/python/samba/tests/dcerpc/binding.py b/python/samba/tests/dcerpc/binding.py -index 8e0d6a5ef0a..24e4ac77d89 100644 ---- a/python/samba/tests/dcerpc/binding.py -+++ b/python/samba/tests/dcerpc/binding.py -@@ -22,7 +22,7 @@ import samba.tests - from samba.tests import RpcInterfaceTestCase, TestCase - from samba.dcerpc import lsa - import samba.dcerpc.security as security --from samba.credentials import Credentials, SMB_ENCRYPTION_REQUIRED -+from samba.credentials import Credentials, SMB_ENCRYPTION_REQUIRED, SMB_ENCRYPTION_OFF - from samba import NTSTATUSError - - class RpcBindingTests(RpcInterfaceTestCase): -@@ -40,6 +40,26 @@ class RpcBindingTests(RpcInterfaceTestCase): - c.set_password(password) - return c - -+ def test_smb3_dcerpc_no_encryption(self): -+ creds = self.get_user_creds() -+ creds.set_smb_encryption(SMB_ENCRYPTION_OFF) -+ -+ lp = self.get_loadparm() -+ lp.set('client ipc max protocol', 'SMB3') -+ lp.set('client ipc min protocol', 'SMB3') -+ -+ binding_string = ("ncacn_np:%s" % (samba.tests.env_get_var_value('SERVER'))) -+ lsa_conn = lsa.lsarpc(binding_string, lp, creds) -+ self.assertFalse(lsa_conn.transport_encrypted()) -+ -+ objectAttr = lsa.ObjectAttribute() -+ objectAttr.sec_qos = lsa.QosInfo() -+ -+ pol_handle = lsa_conn.OpenPolicy2('', -+ objectAttr, -+ security.SEC_FLAG_MAXIMUM_ALLOWED) -+ self.assertIsNotNone(pol_handle) -+ - def test_smb3_dcerpc_encryption(self): - creds = self.get_user_creds() - creds.set_smb_encryption(SMB_ENCRYPTION_REQUIRED) -@@ -50,6 +70,7 @@ class RpcBindingTests(RpcInterfaceTestCase): - - binding_string = ("ncacn_np:%s" % (samba.tests.env_get_var_value('SERVER'))) - lsa_conn = lsa.lsarpc(binding_string, lp, creds) -+ self.assertTrue(lsa_conn.transport_encrypted()) - - objectAttr = lsa.ObjectAttribute() - objectAttr.sec_qos = lsa.QosInfo() --- -2.33.1 - - -From 562d70d899f3871ead10c339479be84eae1d90fa Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Thu, 20 Aug 2020 12:47:12 +0200 -Subject: [PATCH 092/103] Add CreateTrustedDomainRelax wrapper for fips mode - -Signed-off-by: Isaac Boukris -Reviewed-by: Stefan Metzmacher -Reviewed-by: Alexander Bokovoy -(cherry picked from commit c2644032b49b4160517a7c73634cebc54a76f827) ---- - python/samba/trust_utils.py | 62 +++++++++++++++++++++++++++++++++++++ - 1 file changed, 62 insertions(+) - create mode 100644 python/samba/trust_utils.py - -diff --git a/python/samba/trust_utils.py b/python/samba/trust_utils.py -new file mode 100644 -index 00000000000..b4df0fa5bb8 ---- /dev/null -+++ b/python/samba/trust_utils.py -@@ -0,0 +1,62 @@ -+# trust utils -+# -+# Copyright Isaac Boukris 2020 -+# -+# This program is free software; you can redistribute it and/or modify -+# it under the terms of the GNU General Public License as published by -+# the Free Software Foundation; either version 3 of the License, or -+# (at your option) any later version. -+# -+# This program is distributed in the hope that it will be useful, -+# but WITHOUT ANY WARRANTY; without even the implied warranty of -+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the -+# GNU General Public License for more details. -+# -+# You should have received a copy of the GNU General Public License -+# along with this program. If not, see . -+ -+ -+from samba.dcerpc import lsa, drsblobs -+from samba.ndr import ndr_pack -+from samba import arcfour_encrypt, string_to_byte_array -+import random -+from samba import crypto -+ -+def CreateTrustedDomainRelax(lsaconn, policy, trust_info, mask, in_blob, out_blob): -+ -+ def generate_AuthInfoInternal(session_key, incoming=None, outgoing=None): -+ confounder = [0] * 512 -+ for i in range(len(confounder)): -+ confounder[i] = random.randint(0, 255) -+ -+ trustpass = drsblobs.trustDomainPasswords() -+ -+ trustpass.confounder = confounder -+ trustpass.outgoing = outgoing -+ trustpass.incoming = incoming -+ -+ trustpass_blob = ndr_pack(trustpass) -+ -+ encrypted_trustpass = arcfour_encrypt(session_key, trustpass_blob) -+ -+ auth_blob = lsa.DATA_BUF2() -+ auth_blob.size = len(encrypted_trustpass) -+ auth_blob.data = string_to_byte_array(encrypted_trustpass) -+ -+ auth_info = lsa.TrustDomainInfoAuthInfoInternal() -+ auth_info.auth_blob = auth_blob -+ -+ return auth_info -+ -+ session_key = lsaconn.session_key -+ -+ try: -+ if lsaconn.transport_encrypted(): -+ crypto.set_relax_mode() -+ auth_info = generate_AuthInfoInternal(session_key, -+ incoming=in_blob, -+ outgoing=out_blob) -+ finally: -+ crypto.set_strict_mode() -+ -+ return lsaconn.CreateTrustedDomainEx2(policy, trust_info, auth_info, mask) --- -2.33.1 - - -From 62c20810029616fa2286b51ab473f9f7fcc2b766 Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Thu, 20 Aug 2020 12:49:17 +0200 -Subject: [PATCH 093/103] Use the new CreateTrustedDomainRelax() - -Signed-off-by: Isaac Boukris -Reviewed-by: Stefan Metzmacher -Reviewed-by: Alexander Bokovoy -(cherry picked from commit baf4e2930ee13b47c23c63c7e945fdc4444f0c69) ---- - python/samba/netcmd/domain.py | 57 ++++++++--------------------------- - 1 file changed, 13 insertions(+), 44 deletions(-) - -diff --git a/python/samba/netcmd/domain.py b/python/samba/netcmd/domain.py -index 1d12c362911..93a3258d28d 100644 ---- a/python/samba/netcmd/domain.py -+++ b/python/samba/netcmd/domain.py -@@ -102,6 +102,7 @@ from samba.netcmd.domain_backup import cmd_domain_backup - - from samba.compat import binary_type - from samba.compat import get_string -+from samba.trust_utils import CreateTrustedDomainRelax - - string_version_to_constant = { - "2008_R2": DS_DOMAIN_FUNCTION_2008_R2, -@@ -2528,54 +2529,20 @@ class cmd_domain_trust_create(DomainTrustCommand): - - return blob - -- def generate_AuthInfoInternal(session_key, incoming=None, outgoing=None): -- confounder = [0] * 512 -- for i in range(len(confounder)): -- confounder[i] = random.randint(0, 255) -- -- trustpass = drsblobs.trustDomainPasswords() -- -- trustpass.confounder = confounder -- trustpass.outgoing = outgoing -- trustpass.incoming = incoming -- -- trustpass_blob = ndr_pack(trustpass) -- -- encrypted_trustpass = arcfour_encrypt(session_key, trustpass_blob) -- -- auth_blob = lsa.DATA_BUF2() -- auth_blob.size = len(encrypted_trustpass) -- auth_blob.data = string_to_byte_array(encrypted_trustpass) -- -- auth_info = lsa.TrustDomainInfoAuthInfoInternal() -- auth_info.auth_blob = auth_blob -- -- return auth_info -- - update_time = samba.current_unix_time() - incoming_blob = generate_AuthInOutBlob(incoming_secret, update_time) - outgoing_blob = generate_AuthInOutBlob(outgoing_secret, update_time) - -- local_tdo_handle = None -- remote_tdo_handle = None -- -- local_auth_info = generate_AuthInfoInternal(local_lsa.session_key, -- incoming=incoming_blob, -- outgoing=outgoing_blob) -- if remote_trust_info: -- remote_auth_info = generate_AuthInfoInternal(remote_lsa.session_key, -- incoming=outgoing_blob, -- outgoing=incoming_blob) -- - try: - if remote_trust_info: - self.outf.write("Creating remote TDO.\n") - current_request = {"location": "remote", "name": "CreateTrustedDomainEx2"} -- remote_tdo_handle = \ -- remote_lsa.CreateTrustedDomainEx2(remote_policy, -- remote_trust_info, -- remote_auth_info, -- lsa.LSA_TRUSTED_DOMAIN_ALL_ACCESS) -+ remote_tdo_handle = CreateTrustedDomainRelax(remote_lsa, -+ remote_policy, -+ remote_trust_info, -+ lsa.LSA_TRUSTED_DOMAIN_ALL_ACCESS, -+ outgoing_blob, -+ incoming_blob) - self.outf.write("Remote TDO created.\n") - if enc_types: - self.outf.write("Setting supported encryption types on remote TDO.\n") -@@ -2586,10 +2553,12 @@ class cmd_domain_trust_create(DomainTrustCommand): - - self.outf.write("Creating local TDO.\n") - current_request = {"location": "local", "name": "CreateTrustedDomainEx2"} -- local_tdo_handle = local_lsa.CreateTrustedDomainEx2(local_policy, -- local_trust_info, -- local_auth_info, -- lsa.LSA_TRUSTED_DOMAIN_ALL_ACCESS) -+ local_tdo_handle = CreateTrustedDomainRelax(local_lsa, -+ local_policy, -+ local_trust_info, -+ lsa.LSA_TRUSTED_DOMAIN_ALL_ACCESS, -+ incoming_blob, -+ outgoing_blob) - self.outf.write("Local TDO created\n") - if enc_types: - self.outf.write("Setting supported encryption types on local TDO.\n") --- -2.33.1 - - -From 98d411336827fef8e6e650ea510f73dc4bb74d74 Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Tue, 1 Sep 2020 20:14:29 +0300 -Subject: [PATCH 094/103] selftest: add a test for the CreateTrustedDomainRelax - wrapper - -Originally copied from 'source4/scripting/devel/createtrust' -(had to drop the TRUST_AUTH_TYPE_VERSION part though, as it -fails against samba DC). - -Signed-off-by: Isaac Boukris -Reviewed-by: Stefan Metzmacher -Reviewed-by: Alexander Bokovoy -(cherry picked from commit cfaad16ff632df83a881fe5d8ec498bab102c9c9) ---- - python/samba/tests/dcerpc/createtrustrelax.py | 131 ++++++++++++++++++ - selftest/knownfail.d/createtrustrelax_server | 1 + - source4/selftest/tests.py | 4 + - 3 files changed, 136 insertions(+) - create mode 100644 python/samba/tests/dcerpc/createtrustrelax.py - create mode 100644 selftest/knownfail.d/createtrustrelax_server - -diff --git a/python/samba/tests/dcerpc/createtrustrelax.py b/python/samba/tests/dcerpc/createtrustrelax.py -new file mode 100644 -index 00000000000..48beb0f9680 ---- /dev/null -+++ b/python/samba/tests/dcerpc/createtrustrelax.py -@@ -0,0 +1,131 @@ -+# Unix SMB/CIFS implementation. -+# -+# Copyright (C) Andrew Bartlett 2011 -+# Copyright (C) Isaac Boukris 2020 -+# -+# This program is free software; you can redistribute it and/or modify -+# it under the terms of the GNU General Public License as published by -+# the Free Software Foundation; either version 3 of the License, or -+# (at your option) any later version. -+# -+# This program is distributed in the hope that it will be useful, -+# but WITHOUT ANY WARRANTY; without even the implied warranty of -+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the -+# GNU General Public License for more details. -+# -+# You should have received a copy of the GNU General Public License -+# along with this program. If not, see . -+# -+ -+"""Tests for the CreateTrustedDomainRelax wrapper""" -+ -+import os -+import samba -+from samba.tests import TestCase -+from samba.dcerpc import lsa, security, drsblobs -+from samba.credentials import Credentials, SMB_ENCRYPTION_REQUIRED, SMB_ENCRYPTION_OFF -+from samba.trust_utils import CreateTrustedDomainRelax -+ -+class CreateTrustedDomainRelaxTest(TestCase): -+ def setUp(self): -+ super(CreateTrustedDomainRelaxTest, self).setUp() -+ -+ def get_user_creds(self): -+ c = Credentials() -+ c.guess() -+ domain = samba.tests.env_get_var_value('DOMAIN') -+ username = samba.tests.env_get_var_value('USERNAME') -+ password = samba.tests.env_get_var_value('PASSWORD') -+ c.set_domain(domain) -+ c.set_username(username) -+ c.set_password(password) -+ return c -+ -+ def _create_trust_relax(self, smbencrypt=True): -+ creds = self.get_user_creds() -+ -+ if smbencrypt: -+ creds.set_smb_encryption(SMB_ENCRYPTION_REQUIRED) -+ else: -+ creds.set_smb_encryption(SMB_ENCRYPTION_OFF) -+ -+ lp = self.get_loadparm() -+ -+ binding_string = ("ncacn_np:%s" % (samba.tests.env_get_var_value('SERVER'))) -+ lsa_conn = lsa.lsarpc(binding_string, lp, creds) -+ -+ if smbencrypt: -+ self.assertTrue(lsa_conn.transport_encrypted()) -+ else: -+ self.assertFalse(lsa_conn.transport_encrypted()) -+ -+ objectAttr = lsa.ObjectAttribute() -+ objectAttr.sec_qos = lsa.QosInfo() -+ -+ pol_handle = lsa_conn.OpenPolicy2('', -+ objectAttr, -+ security.SEC_FLAG_MAXIMUM_ALLOWED) -+ self.assertIsNotNone(pol_handle) -+ -+ name = lsa.String() -+ name.string = "tests.samba.example.com" -+ try: -+ info = lsa_conn.QueryTrustedDomainInfoByName(pol_handle, name, -+ lsa.LSA_TRUSTED_DOMAIN_INFO_FULL_INFO) -+ -+ lsa_conn.DeleteTrustedDomain(pol_handle, info.info_ex.sid) -+ except RuntimeError: -+ pass -+ -+ info = lsa.TrustDomainInfoInfoEx() -+ info.domain_name.string = name.string -+ info.netbios_name.string = "createtrustrelax" -+ info.sid = security.dom_sid("S-1-5-21-538490383-3740119673-95748416") -+ info.trust_direction = lsa.LSA_TRUST_DIRECTION_INBOUND | lsa.LSA_TRUST_DIRECTION_OUTBOUND -+ info.trust_type = lsa.LSA_TRUST_TYPE_UPLEVEL -+ info.trust_attributes = lsa.LSA_TRUST_ATTRIBUTE_FOREST_TRANSITIVE -+ -+ password_blob = samba.string_to_byte_array("password".encode('utf-16-le')) -+ -+ clear_value = drsblobs.AuthInfoClear() -+ clear_value.size = len(password_blob) -+ clear_value.password = password_blob -+ -+ clear_authentication_information = drsblobs.AuthenticationInformation() -+ clear_authentication_information.LastUpdateTime = 0 -+ clear_authentication_information.AuthType = lsa.TRUST_AUTH_TYPE_CLEAR -+ clear_authentication_information.AuthInfo = clear_value -+ -+ authentication_information_array = drsblobs.AuthenticationInformationArray() -+ authentication_information_array.count = 1 -+ authentication_information_array.array = [clear_authentication_information] -+ -+ outgoing = drsblobs.trustAuthInOutBlob() -+ outgoing.count = 1 -+ outgoing.current = authentication_information_array -+ -+ trustdom_handle = None -+ try: -+ trustdom_handle = CreateTrustedDomainRelax(lsa_conn, -+ pol_handle, -+ info, -+ security.SEC_STD_DELETE, -+ outgoing, -+ outgoing) -+ except samba.NTSTATUSError as nt: -+ raise AssertionError(nt) -+ except OSError as e: -+ if smbencrypt: -+ raise AssertionError(e) -+ -+ if smbencrypt: -+ self.assertIsNotNone(trustdom_handle) -+ lsa_conn.DeleteTrustedDomain(pol_handle, info.sid) -+ else: -+ self.assertIsNone(trustdom_handle) -+ -+ def test_create_trust_relax_encrypt(self): -+ self._create_trust_relax(True) -+ -+ def test_create_trust_relax_no_enc(self): -+ self._create_trust_relax(False) -diff --git a/selftest/knownfail.d/createtrustrelax_server b/selftest/knownfail.d/createtrustrelax_server -new file mode 100644 -index 00000000000..80effda8343 ---- /dev/null -+++ b/selftest/knownfail.d/createtrustrelax_server -@@ -0,0 +1 @@ -+^samba.tests.dcerpc.createtrustrelax.samba.tests.dcerpc.createtrustrelax.CreateTrustedDomainRelaxTest.test_create_trust_relax_encrypt\(ad_dc_fips\) -diff --git a/source4/selftest/tests.py b/source4/selftest/tests.py -index cdc7bc77c0a..8864a710bfb 100755 ---- a/source4/selftest/tests.py -+++ b/source4/selftest/tests.py -@@ -705,6 +705,10 @@ def planoldpythontestsuite(env, module, name=None, extra_path=[], environ={}, ex - name = module - plantestsuite_loadlist(name, env, args) - -+if have_gnutls_crypto_policies: -+ planoldpythontestsuite("ad_dc", "samba.tests.dcerpc.createtrustrelax", environ={'GNUTLS_FORCE_FIPS_MODE':'1'}) -+ planoldpythontestsuite("ad_dc_fips", "samba.tests.dcerpc.createtrustrelax", environ={'GNUTLS_FORCE_FIPS_MODE':'1'}) -+ - # Run complex search expressions test once for each database backend. - # Right now ad_dc has mdb and ad_dc_ntvfs has tdb - mdb_testenv = "ad_dc" --- -2.33.1 - - -From 84b03e21fc234735bbd59e1797126c2013d0ac38 Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Thu, 5 Nov 2020 15:38:19 +0200 -Subject: [PATCH 095/103] Remove source4/scripting/devel/createtrust script - -We now have the 'samba-tool domain trust' command. - -Signed-off-by: Isaac Boukris -Reviewed-by: Stefan Metzmacher -Reviewed-by: Alexander Bokovoy - -Autobuild-User(master): Isaac Boukris -Autobuild-Date(master): Fri Nov 6 11:25:02 UTC 2020 on sn-devel-184 - -(cherry picked from commit 604153525afc892f57a1df710c41ffca275b0dd3) ---- - source4/scripting/devel/createtrust | 125 ---------------------------- - 1 file changed, 125 deletions(-) - delete mode 100755 source4/scripting/devel/createtrust - -diff --git a/source4/scripting/devel/createtrust b/source4/scripting/devel/createtrust -deleted file mode 100755 -index 26b0d0dcb68..00000000000 ---- a/source4/scripting/devel/createtrust -+++ /dev/null -@@ -1,125 +0,0 @@ --#!/usr/bin/env python3 -- --# create a domain trust -- --import sys --from optparse import OptionParser -- --sys.path.insert(0, "bin/python") -- --import samba --import samba.getopt as options --from samba.dcerpc import lsa, security, drsblobs --from samba.ndr import ndr_pack --from samba import arcfour_encrypt, string_to_byte_array --import random -- --########### main code ########### --if __name__ == "__main__": -- parser = OptionParser("createtrust [options] server") -- sambaopts = options.SambaOptions(parser) -- credopts = options.CredentialsOptionsDouble(parser) -- parser.add_option_group(credopts) -- -- (opts, args) = parser.parse_args() -- -- lp = sambaopts.get_loadparm() -- creds = credopts.get_credentials(lp) -- -- if len(args) != 1: -- parser.error("You must supply a server") -- -- if not creds.authentication_requested(): -- parser.error("You must supply credentials") -- -- server = args[0] -- -- binding_str = "ncacn_np:%s[print]" % server -- -- lsaconn = lsa.lsarpc(binding_str, lp, creds) -- -- objectAttr = lsa.ObjectAttribute() -- objectAttr.sec_qos = lsa.QosInfo() -- -- pol_handle = lsaconn.OpenPolicy2(''.decode('utf-8'), -- objectAttr, security.SEC_FLAG_MAXIMUM_ALLOWED) -- -- name = lsa.String() -- name.string = "sub2.win2k3.obed.home.abartlet.net" -- try: -- info = lsaconn.QueryTrustedDomainInfoByName(pol_handle, name, lsa.LSA_TRUSTED_DOMAIN_INFO_FULL_INFO) -- -- lsaconn.DeleteTrustedDomain(pol_handle, info.info_ex.sid) -- except RuntimeError: -- pass -- -- info = lsa.TrustDomainInfoInfoEx() -- info.domain_name.string = "sub2.win2k3.obed.home.abartlet.net" -- info.netbios_name.string = "sub2" -- info.sid = security.dom_sid("S-1-5-21-538090388-3760119675-95745416") -- info.trust_direction = lsa.LSA_TRUST_DIRECTION_INBOUND | lsa.LSA_TRUST_DIRECTION_OUTBOUND -- info.trust_type = lsa.LSA_TRUST_TYPE_UPLEVEL -- info.trust_attributes = lsa.LSA_TRUST_ATTRIBUTE_WITHIN_FOREST -- -- password_blob = string_to_byte_array("password".encode('utf-16-le')) -- -- clear_value = drsblobs.AuthInfoClear() -- clear_value.size = len(password_blob) -- clear_value.password = password_blob -- -- clear_authentication_information = drsblobs.AuthenticationInformation() -- clear_authentication_information.LastUpdateTime = 0 -- clear_authentication_information.AuthType = lsa.TRUST_AUTH_TYPE_CLEAR -- clear_authentication_information.AuthInfo = clear_value -- -- version_value = drsblobs.AuthInfoVersion() -- version_value.version = 1 -- -- version = drsblobs.AuthenticationInformation() -- version.LastUpdateTime = 0 -- version.AuthType = lsa.TRUST_AUTH_TYPE_VERSION -- version.AuthInfo = version_value -- -- authentication_information_array = drsblobs.AuthenticationInformationArray() -- authentication_information_array.count = 2 -- authentication_information_array.array = [clear_authentication_information, version] -- -- outgoing = drsblobs.trustAuthInOutBlob() -- outgoing.count = 1 -- outgoing.current = authentication_information_array -- -- trustpass = drsblobs.trustDomainPasswords() -- confounder = [3] * 512 -- -- for i in range(512): -- confounder[i] = random.randint(0, 255) -- -- trustpass.confounder = confounder -- --# print "confounder: ", trustpass.confounder -- -- trustpass.outgoing = outgoing -- trustpass.incoming = outgoing -- -- trustpass_blob = ndr_pack(trustpass) -- --# print "trustpass_blob: ", list(trustpass_blob) -- -- encrypted_trustpass = arcfour_encrypt(lsaconn.session_key, trustpass_blob) -- --# print "encrypted_trustpass: ", list(encrypted_trustpass) -- -- auth_blob = lsa.DATA_BUF2() -- auth_blob.size = len(encrypted_trustpass) -- auth_blob.data = string_to_byte_array(encrypted_trustpass) -- -- auth_info = lsa.TrustDomainInfoAuthInfoInternal() -- auth_info.auth_blob = auth_blob -- -- --# print "auth_info.auth_blob.data: ", auth_info.auth_blob.data -- -- trustdom_handle = lsaconn.CreateTrustedDomainEx2(pol_handle, -- info, -- auth_info, -- security.SEC_STD_DELETE) --- -2.33.1 - - -From 55b91ef9d792b99d3dcf95dd913cf7799889b24f Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Fri, 6 Nov 2020 14:30:26 +0100 -Subject: [PATCH 096/103] s3:rpc_server: Use gnutls_cipher_decrypt() in - get_trustdom_auth_blob() - -It doesn't matter for RC4, but just to be correct. - -Signed-off-by: Andreas Schneider -Reviewed-by: Alexander Bokovoy -(cherry picked from commit 6c11e5f42ba3248c97d85c989d422b256d2465a9) ---- - source3/rpc_server/lsa/srv_lsa_nt.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/source3/rpc_server/lsa/srv_lsa_nt.c b/source3/rpc_server/lsa/srv_lsa_nt.c -index 198387424e6..e749caf2551 100644 ---- a/source3/rpc_server/lsa/srv_lsa_nt.c -+++ b/source3/rpc_server/lsa/srv_lsa_nt.c -@@ -1726,7 +1726,7 @@ static NTSTATUS get_trustdom_auth_blob(struct pipes_struct *p, - goto out; - } - -- rc = gnutls_cipher_encrypt(cipher_hnd, -+ rc = gnutls_cipher_decrypt(cipher_hnd, - auth_blob->data, - auth_blob->length); - gnutls_cipher_deinit(cipher_hnd); --- -2.33.1 - - -From 04fbc570271973c15c4a28a95bd6ef3b0fd5de95 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Fri, 6 Nov 2020 14:33:38 +0100 -Subject: [PATCH 097/103] s4:rpc_server: Use gnutls_cipher_decrypt() in - get_trustdom_auth_blob() - -It doesn't matter for RC4, but just to be correct. - -Signed-off-by: Andreas Schneider -Reviewed-by: Alexander Bokovoy -(cherry picked from commit c93ccebdfedd60c1d19f1b1436ac30062259952a) ---- - source4/rpc_server/lsa/dcesrv_lsa.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/source4/rpc_server/lsa/dcesrv_lsa.c b/source4/rpc_server/lsa/dcesrv_lsa.c -index 8333cb149b6..4bb8aaa9592 100644 ---- a/source4/rpc_server/lsa/dcesrv_lsa.c -+++ b/source4/rpc_server/lsa/dcesrv_lsa.c -@@ -889,7 +889,7 @@ static NTSTATUS get_trustdom_auth_blob(struct dcesrv_call_state *dce_call, - goto out; - } - -- rc = gnutls_cipher_encrypt(cipher_hnd, -+ rc = gnutls_cipher_decrypt(cipher_hnd, - auth_blob->data, - auth_blob->length); - gnutls_cipher_deinit(cipher_hnd); --- -2.33.1 - - -From 8c423c8dc1a8ae63970616ff5b4ad5db8d083641 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 20 Aug 2020 13:40:21 +0200 -Subject: [PATCH 098/103] s3:rpc_server: Allow to use RC4 for creating trusts - -Signed-off-by: Andreas Schneider -Reviewed-by: Alexander Bokovoy -Reviewed-by: Stefan Metzmacher -(cherry picked from commit 4425f2c113a4dc33a8dc609d84a92018d61b4d2e) ---- - source3/rpc_server/lsa/srv_lsa_nt.c | 13 +++++++++++++ - 1 file changed, 13 insertions(+) - -diff --git a/source3/rpc_server/lsa/srv_lsa_nt.c b/source3/rpc_server/lsa/srv_lsa_nt.c -index e749caf2551..d6d606ddeca 100644 ---- a/source3/rpc_server/lsa/srv_lsa_nt.c -+++ b/source3/rpc_server/lsa/srv_lsa_nt.c -@@ -51,6 +51,8 @@ - #include "../libcli/lsarpc/util_lsarpc.h" - #include "lsa.h" - #include "librpc/rpc/dcesrv_core.h" -+#include "librpc/rpc/dcerpc_helper.h" -+#include "lib/param/loadparm.h" - - #include "lib/crypto/gnutls_helpers.h" - #include -@@ -1706,6 +1708,14 @@ static NTSTATUS get_trustdom_auth_blob(struct pipes_struct *p, - gnutls_datum_t my_session_key; - NTSTATUS status; - int rc; -+ bool encrypted; -+ -+ encrypted = -+ dcerpc_is_transport_encrypted(p->session_info); -+ if (lp_weak_crypto() == SAMBA_WEAK_CRYPTO_DISALLOWED && -+ !encrypted) { -+ return NT_STATUS_ACCESS_DENIED; -+ } - - status = session_extract_session_key(p->session_info, &lsession_key, KEY_USE_16BYTES); - if (!NT_STATUS_IS_OK(status)) { -@@ -1717,11 +1727,13 @@ static NTSTATUS get_trustdom_auth_blob(struct pipes_struct *p, - .size = lsession_key.length, - }; - -+ GNUTLS_FIPS140_SET_LAX_MODE(); - rc = gnutls_cipher_init(&cipher_hnd, - GNUTLS_CIPHER_ARCFOUR_128, - &my_session_key, - NULL); - if (rc < 0) { -+ GNUTLS_FIPS140_SET_STRICT_MODE(); - status = gnutls_error_to_ntstatus(rc, NT_STATUS_CRYPTO_SYSTEM_INVALID); - goto out; - } -@@ -1730,6 +1742,7 @@ static NTSTATUS get_trustdom_auth_blob(struct pipes_struct *p, - auth_blob->data, - auth_blob->length); - gnutls_cipher_deinit(cipher_hnd); -+ GNUTLS_FIPS140_SET_STRICT_MODE(); - if (rc < 0) { - status = gnutls_error_to_ntstatus(rc, NT_STATUS_CRYPTO_SYSTEM_INVALID); - goto out; --- -2.33.1 - - -From a396fce11011d22dda9ff26027fef789bf2ab33a Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 20 Aug 2020 13:51:39 +0200 -Subject: [PATCH 099/103] s4:rpc_server: Allow to use RC4 for creating trusts - -Signed-off-by: Andreas Schneider -Reviewed-by: Alexander Bokovoy -Reviewed-by: Stefan Metzmacher -(cherry picked from commit c75dd1ea178325b8f65343cb5c35bb93f43a49a3) ---- - source4/rpc_server/lsa/dcesrv_lsa.c | 18 ++++++++++++++++++ - 1 file changed, 18 insertions(+) - -diff --git a/source4/rpc_server/lsa/dcesrv_lsa.c b/source4/rpc_server/lsa/dcesrv_lsa.c -index 4bb8aaa9592..5b3ef71d458 100644 ---- a/source4/rpc_server/lsa/dcesrv_lsa.c -+++ b/source4/rpc_server/lsa/dcesrv_lsa.c -@@ -33,6 +33,8 @@ - #include "libcli/lsarpc/util_lsarpc.h" - #include "lib/messaging/irpc.h" - #include "libds/common/roles.h" -+#include "lib/param/loadparm.h" -+#include "librpc/rpc/dcerpc_helper.h" - - #include "lib/crypto/gnutls_helpers.h" - #include -@@ -869,6 +871,19 @@ static NTSTATUS get_trustdom_auth_blob(struct dcesrv_call_state *dce_call, - gnutls_cipher_hd_t cipher_hnd = NULL; - gnutls_datum_t _session_key; - int rc; -+ struct auth_session_info *session_info = -+ dcesrv_call_session_info(dce_call); -+ struct loadparm_context *lp_ctx = dce_call->conn->dce_ctx->lp_ctx; -+ bool encrypted; -+ -+ encrypted = -+ dcerpc_is_transport_encrypted(session_info); -+ if (lpcfg_weak_crypto(lp_ctx) == SAMBA_WEAK_CRYPTO_DISALLOWED && -+ !encrypted) { -+ DBG_ERR("Transport isn't encrypted and weak crypto disallowed!\n"); -+ return NT_STATUS_ACCESS_DENIED; -+ } -+ - - nt_status = dcesrv_transport_session_key(dce_call, &session_key); - if (!NT_STATUS_IS_OK(nt_status)) { -@@ -880,11 +895,13 @@ static NTSTATUS get_trustdom_auth_blob(struct dcesrv_call_state *dce_call, - .size = session_key.length, - }; - -+ GNUTLS_FIPS140_SET_LAX_MODE(); - rc = gnutls_cipher_init(&cipher_hnd, - GNUTLS_CIPHER_ARCFOUR_128, - &_session_key, - NULL); - if (rc < 0) { -+ GNUTLS_FIPS140_SET_STRICT_MODE(); - nt_status = gnutls_error_to_ntstatus(rc, NT_STATUS_CRYPTO_SYSTEM_INVALID); - goto out; - } -@@ -893,6 +910,7 @@ static NTSTATUS get_trustdom_auth_blob(struct dcesrv_call_state *dce_call, - auth_blob->data, - auth_blob->length); - gnutls_cipher_deinit(cipher_hnd); -+ GNUTLS_FIPS140_SET_STRICT_MODE(); - if (rc < 0) { - nt_status = gnutls_error_to_ntstatus(rc, NT_STATUS_CRYPTO_SYSTEM_INVALID); - goto out; --- -2.33.1 - - -From e48534608b8a60428ef1aa8f5edc357ba9ffc9c0 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Fri, 6 Nov 2020 10:13:48 +0100 -Subject: [PATCH 100/103] sefltest: Enable the dcerpc.createtrustrelax test - against ad_dc_fips - -Signed-off-by: Andreas Schneider -Reviewed-by: Alexander Bokovoy -Reviewed-by: Stefan Metzmacher - -Autobuild-User(master): Andreas Schneider -Autobuild-Date(master): Mon Nov 9 10:22:51 UTC 2020 on sn-devel-184 - -(cherry picked from commit b89134013041e772418c2c8bcfffe8a9ade6db91) ---- - selftest/knownfail.d/createtrustrelax_server | 1 - - 1 file changed, 1 deletion(-) - delete mode 100644 selftest/knownfail.d/createtrustrelax_server - -diff --git a/selftest/knownfail.d/createtrustrelax_server b/selftest/knownfail.d/createtrustrelax_server -deleted file mode 100644 -index 80effda8343..00000000000 ---- a/selftest/knownfail.d/createtrustrelax_server -+++ /dev/null -@@ -1 +0,0 @@ --^samba.tests.dcerpc.createtrustrelax.samba.tests.dcerpc.createtrustrelax.CreateTrustedDomainRelaxTest.test_create_trust_relax_encrypt\(ad_dc_fips\) --- -2.33.1 - - -From a69a998ae5575e8bcd17162b5c75895a4dfc9aed Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Wed, 11 Nov 2020 13:42:06 +0100 -Subject: [PATCH 101/103] s3:smbd: Fix possible null pointer dereference in - token_contains_name() - -BUG: https://bugzilla.samba.org/show_bug.cgi?id=14572 - -Signed-off-by: Andreas Schneider -Reviewed-by: Alexander Bokovoy - -Autobuild-User(master): Alexander Bokovoy -Autobuild-Date(master): Thu Nov 12 15:13:47 UTC 2020 on sn-devel-184 - -(cherry picked from commit 8036bf9717f83e83c3e4a9cf00fded42e9a5de15) ---- - source3/smbd/share_access.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/source3/smbd/share_access.c b/source3/smbd/share_access.c -index 57754a0f766..694c0c290e8 100644 ---- a/source3/smbd/share_access.c -+++ b/source3/smbd/share_access.c -@@ -79,7 +79,7 @@ static bool token_contains_name(TALLOC_CTX *mem_ctx, - enum lsa_SidType type; - - if (username != NULL) { -- size_t domain_len = strlen(domain); -+ size_t domain_len = domain != NULL ? strlen(domain) : 0; - - /* Check if username starts with domain name */ - if (domain_len > 0) { --- -2.33.1 - - -From 8f0c383642177558e726c780debde7c8a6800b41 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Fri, 27 Nov 2020 11:22:15 +0100 -Subject: [PATCH 102/103] docs-xml: Add a section about weak crypto in testparm - manpage - -BUG: https://bugzilla.samba.org/show_bug.cgi?id=14583 - -Signed-off-by: Andreas Schneider -Reviewed-by: Alexander Bokovoy - -Autobuild-User(master): Andreas Schneider -Autobuild-Date(master): Fri Nov 27 13:48:20 UTC 2020 on sn-devel-184 - -(cherry picked from commit 5c27740aeff273bcd5f027d36874e56170234146) ---- - docs-xml/manpages/testparm.1.xml | 9 +++++++++ - 1 file changed, 9 insertions(+) - -diff --git a/docs-xml/manpages/testparm.1.xml b/docs-xml/manpages/testparm.1.xml -index 9099cda010f..7c7abf50e8b 100644 ---- a/docs-xml/manpages/testparm.1.xml -+++ b/docs-xml/manpages/testparm.1.xml -@@ -171,6 +171,15 @@ - errors and warnings if the file did not load. If the file was - loaded OK, the program then dumps all known service details - to stdout. -+ -+ For certain use cases, SMB protocol requires use of -+ cryptographic algorithms which are known to be weak and already -+ broken. DES and ARCFOUR (RC4) ciphers and the SHA1 and MD5 hash -+ algorithms are considered weak but they are required for backward -+ compatibility. The testparm utility shows whether the Samba tools -+ will fall back to these weak crypto algorithms if it is not possible -+ to use strong cryptography by default. -+ In FIPS mode weak crypto cannot be enabled. - - - --- -2.33.1 - - -From 60e8564f5cfff819b6d8e47ded1976003c2078a8 Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Tue, 15 Dec 2020 15:17:04 +0100 -Subject: [PATCH 103/103] HACK:s3:winbind: Rely on the domain child for online - check - ---- - source3/winbindd/winbindd_cm.c | 9 +++++++++ - source3/winbindd/winbindd_dual.c | 3 +++ - 2 files changed, 12 insertions(+) - -diff --git a/source3/winbindd/winbindd_cm.c b/source3/winbindd/winbindd_cm.c -index 809aed4376c..4f544f5ab50 100644 ---- a/source3/winbindd/winbindd_cm.c -+++ b/source3/winbindd/winbindd_cm.c -@@ -89,6 +89,8 @@ - #undef DBGC_CLASS - #define DBGC_CLASS DBGC_WINBIND - -+extern bool wb_idmap_child; -+ - struct dc_name_ip { - fstring name; - struct sockaddr_storage ss; -@@ -176,6 +178,13 @@ static void msg_try_to_go_online(struct messaging_context *msg, - continue; - } - -+ if (wb_child_domain() == NULL && !wb_idmap_child) { -+ DEBUG(5,("msg_try_to_go_online: domain %s " -+ "NOT CONNECTING IN MAIN PROCESS.\n", domainname)); -+ domain->online = true; -+ continue; -+ } -+ - /* This call takes care of setting the online - flag to true if we connected, or re-adding - the offline handler if false. Bypasses online -diff --git a/source3/winbindd/winbindd_dual.c b/source3/winbindd/winbindd_dual.c -index 4f07ff49445..a2b59b06208 100644 ---- a/source3/winbindd/winbindd_dual.c -+++ b/source3/winbindd/winbindd_dual.c -@@ -1674,6 +1674,8 @@ static void child_handler(struct tevent_context *ev, struct tevent_fd *fde, - } - } - -+bool wb_idmap_child; -+ - static bool fork_domain_child(struct winbindd_child *child) - { - int fdpair[2]; -@@ -1778,6 +1780,7 @@ static bool fork_domain_child(struct winbindd_child *child) - setproctitle("domain child [%s]", child_domain->name); - } else if (is_idmap_child(child)) { - setproctitle("idmap child"); -+ wb_idmap_child = true; - } - - /* Handle online/offline messages. */ --- -2.33.1 - diff --git a/samba-4.23-fix-cmocka.patch b/samba-4.23-fix-cmocka.patch new file mode 100644 index 0000000..26289d6 --- /dev/null +++ b/samba-4.23-fix-cmocka.patch @@ -0,0 +1,38 @@ +From b1ec803f420b2c6d3c5c83d70c6875a7f36b15fc Mon Sep 17 00:00:00 2001 +From: Andreas Schneider +Date: Fri, 21 Nov 2025 15:33:32 +0100 +Subject: [PATCH] s4:dsdb: Do not declare cm_print_error() + +This is part of the cmocka.h header file. + +Signed-off-by: Andreas Schneider +Reviewed-by: Martin Schwenke +Reviewed-by: Volker Lendecke + +Autobuild-User(master): Volker Lendecke +Autobuild-Date(master): Mon Nov 24 11:28:08 UTC 2025 on atb-devel-224 + +(cherry picked from commit 5a981663e4f677042ba80191770100aecff2120a) +--- + source4/dsdb/samdb/ldb_modules/tests/test_group_audit.c | 5 ----- + 1 file changed, 5 deletions(-) + +diff --git a/source4/dsdb/samdb/ldb_modules/tests/test_group_audit.c b/source4/dsdb/samdb/ldb_modules/tests/test_group_audit.c +index f7075f3485e..12c464b49c7 100644 +--- a/source4/dsdb/samdb/ldb_modules/tests/test_group_audit.c ++++ b/source4/dsdb/samdb/ldb_modules/tests/test_group_audit.c +@@ -103,11 +103,6 @@ void audit_message_send( + + #define check_group_change_message(m, u, a, e) \ + _check_group_change_message(m, u, a, e, __FILE__, __LINE__); +-/* +- * declare the internal cmocka cm_print_error so that we can output messages +- * in sub unit format +- */ +-void cm_print_error(const char * const format, ...); + + /* + * Validate a group change JSON audit message +-- +2.52.0 + diff --git a/samba-gc-lookup_unix_user_name-allow-lookup-for-own-realm.patch b/samba-gc-lookup_unix_user_name-allow-lookup-for-own-realm.patch deleted file mode 100644 index e0ed8ae..0000000 --- a/samba-gc-lookup_unix_user_name-allow-lookup-for-own-realm.patch +++ /dev/null @@ -1,210 +0,0 @@ -From 81d6949acdad70ecfb130d3286eeab1b3a51937f Mon Sep 17 00:00:00 2001 -From: Alexander Bokovoy -Date: Wed, 7 Oct 2020 19:25:24 +0300 -Subject: [PATCH 1/2] cli_credentials_parse_string: fix parsing of principals - -When parsing a principal-like name, user name was left with full -principal instead of taking only the left part before '@' sign. - ->>> from samba import credentials ->>> t = credentials.Credentials() ->>> t.parse_string('admin@realm.test', credentials.SPECIFIED) ->>> t.get_username() -'admin@realm.test' - -The issue is that cli_credentials_set_username() does a talloc_strdup() -of the argument, so we need to change order of assignment to allow -talloc_strdup() to copy the right part of the string. - -Signed-off-by: Alexander Bokovoy ---- - auth/credentials/credentials.c | 5 ++--- - 1 file changed, 2 insertions(+), 3 deletions(-) - -diff --git a/auth/credentials/credentials.c b/auth/credentials/credentials.c -index 77c35dd104b..06ac79058f9 100644 ---- a/auth/credentials/credentials.c -+++ b/auth/credentials/credentials.c -@@ -840,11 +840,10 @@ _PUBLIC_ void cli_credentials_parse_string(struct cli_credentials *credentials, - * in order to undo the effect of - * cli_credentials_guess(). - */ -- cli_credentials_set_username(credentials, uname, obtained); -- cli_credentials_set_domain(credentials, "", obtained); -- - cli_credentials_set_principal(credentials, uname, obtained); - *p = 0; -+ cli_credentials_set_username(credentials, uname, obtained); -+ cli_credentials_set_domain(credentials, "", obtained); - cli_credentials_set_realm(credentials, p+1, obtained); - return; - } else if ((p = strchr_m(uname,'\\')) --- -2.28.0 - - -From fa38bebb993011428612d51819530218d8358f5e Mon Sep 17 00:00:00 2001 -From: Alexander Bokovoy -Date: Mon, 13 Jan 2020 16:04:20 +0200 -Subject: [PATCH 2/2] lookup_name: allow lookup for own realm - -When using security tab in Windows Explorer, a lookup over a trusted -forest might come as realm\name instead of NetBIOS domain name: - --------------------------------------------------------------------- -[2020/01/13 11:12:39.859134, 1, pid=33253, effective(1732401004, 1732401004), real(1732401004, 0), class=rpc_parse] ../../librpc/ndr/ndr.c:471(ndr_print_function_debug) - lsa_LookupNames3: struct lsa_LookupNames3 - in: struct lsa_LookupNames3 - handle : * - handle: struct policy_handle - handle_type : 0x00000000 (0) - uuid : 0000000e-0000-0000-1c5e-a750e5810000 - num_names : 0x00000001 (1) - names: ARRAY(1) - names: struct lsa_String - length : 0x001e (30) - size : 0x0020 (32) - string : * - string : 'ipa.test\admins' - sids : * - sids: struct lsa_TransSidArray3 - count : 0x00000000 (0) - sids : NULL - level : LSA_LOOKUP_NAMES_UPLEVEL_TRUSTS_ONLY2 (6) - count : * - count : 0x00000000 (0) - lookup_options : LSA_LOOKUP_OPTION_SEARCH_ISOLATED_NAMES (0) - client_revision : LSA_CLIENT_REVISION_2 (2) --------------------------------------------------------------------- - -Allow this lookup using realm to be done against primary domain. - -Refactor user name parsing code to reuse cli_credentials_* API to be -consistent with other places. cli_credentials_parse_string() handles -both domain and realm-based user name variants. - -Signed-off-by: Alexander Bokovoy ---- - source3/passdb/lookup_sid.c | 75 ++++++++++++++++++++++++++----------- - 1 file changed, 53 insertions(+), 22 deletions(-) - -diff --git a/source3/passdb/lookup_sid.c b/source3/passdb/lookup_sid.c -index 82c47b3145b..39d599fed27 100644 ---- a/source3/passdb/lookup_sid.c -+++ b/source3/passdb/lookup_sid.c -@@ -29,6 +29,7 @@ - #include "../libcli/security/security.h" - #include "lib/winbind_util.h" - #include "../librpc/gen_ndr/idmap.h" -+#include "auth/credentials/credentials.h" - - static bool lookup_unix_user_name(const char *name, struct dom_sid *sid) - { -@@ -78,52 +79,82 @@ bool lookup_name(TALLOC_CTX *mem_ctx, - const char **ret_domain, const char **ret_name, - struct dom_sid *ret_sid, enum lsa_SidType *ret_type) - { -- char *p; - const char *tmp; - const char *domain = NULL; - const char *name = NULL; -+ const char *realm = NULL; - uint32_t rid; - struct dom_sid sid; - enum lsa_SidType type; - TALLOC_CTX *tmp_ctx = talloc_new(mem_ctx); -+ struct cli_credentials *creds = NULL; - - if (tmp_ctx == NULL) { - DEBUG(0, ("talloc_new failed\n")); - return false; - } - -- p = strchr_m(full_name, '\\'); -- -- if (p != NULL) { -- domain = talloc_strndup(tmp_ctx, full_name, -- PTR_DIFF(p, full_name)); -- name = talloc_strdup(tmp_ctx, p+1); -- } else { -- domain = talloc_strdup(tmp_ctx, ""); -- name = talloc_strdup(tmp_ctx, full_name); -+ creds = cli_credentials_init(tmp_ctx); -+ if (creds == NULL) { -+ DEBUG(0, ("cli_credentials_init failed\n")); -+ return false; - } - -- if ((domain == NULL) || (name == NULL)) { -- DEBUG(0, ("talloc failed\n")); -- TALLOC_FREE(tmp_ctx); -+ cli_credentials_parse_string(creds, full_name, CRED_SPECIFIED); -+ name = cli_credentials_get_username(creds); -+ domain = cli_credentials_get_domain(creds); -+ realm = cli_credentials_get_realm(creds); -+ -+ /* At this point we have: -+ * - name -- normal name or empty string -+ * - domain -- either NULL or domain name -+ * - realm -- either NULL or realm name -+ * -+ * domain and realm are exclusive to each other -+ * the code below in lookup_name assumes domain -+ * to be at least empty string, not NULL -+ */ -+ -+ if ((name == NULL) || (name[0] == '\0')) { -+ DEBUG(0, ("lookup_name with empty name, exit\n")); - return false; - } - -+ if ((domain == NULL) && (realm == NULL)) { -+ domain = talloc_strdup(creds, ""); -+ } -+ - DEBUG(10,("lookup_name: %s => domain=[%s], name=[%s]\n", - full_name, domain, name)); - DEBUG(10, ("lookup_name: flags = 0x0%x\n", flags)); - -- if (((flags & LOOKUP_NAME_DOMAIN) || (flags == 0)) && -- strequal(domain, get_global_sam_name())) -- { -+ /* Windows clients may send a LookupNames request with both NetBIOS -+ * domain name- and realm-qualified user names. Thus, we need to check -+ * both against both of the SAM domain name and realm, if set. Since -+ * domain name and realm in the request are exclusive, test the one -+ * that is specified. cli_credentials_parse_string() will either set -+ * realm or wouldn't so we can use it to detect if realm was specified. -+ */ -+ if ((flags & LOOKUP_NAME_DOMAIN) || (flags == 0)) { -+ const char *domain_name = realm ? realm : domain; -+ bool check_global_sam = false; -+ -+ if (domain_name[0] != '\0') { -+ check_global_sam = strequal(domain_name, get_global_sam_name()); -+ if (!check_global_sam && lp_realm() != NULL) { -+ check_global_sam = strequal(domain_name, lp_realm()); -+ } -+ } - -- /* It's our own domain, lookup the name in passdb */ -- if (lookup_global_sam_name(name, flags, &rid, &type)) { -- sid_compose(&sid, get_global_sam_sid(), rid); -- goto ok; -+ if (check_global_sam) { -+ /* It's our own domain, lookup the name in passdb */ -+ if (lookup_global_sam_name(name, flags, &rid, &type)) { -+ sid_compose(&sid, get_global_sam_sid(), rid); -+ goto ok; -+ } -+ TALLOC_FREE(tmp_ctx); -+ return false; - } -- TALLOC_FREE(tmp_ctx); -- return false; - } - - if ((flags & LOOKUP_NAME_BUILTIN) && --- -2.28.0 - diff --git a/samba-s4u.patch b/samba-s4u.patch deleted file mode 100644 index 120bac3..0000000 --- a/samba-s4u.patch +++ /dev/null @@ -1,697 +0,0 @@ -From e649f9aedfa8a0d5caa241743bb4191927430879 Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Fri, 27 Sep 2019 18:25:03 +0300 -Subject: [PATCH 1/3] mit-kdc: add basic loacl realm S4U support - -Signed-off-by: Isaac Boukris -Pair-Programmed-With: Andreas Schneider ---- - source4/kdc/mit-kdb/kdb_samba_policies.c | 124 +++++++++++------------ - source4/kdc/mit_samba.c | 47 ++------- - source4/kdc/mit_samba.h | 6 +- - 3 files changed, 71 insertions(+), 106 deletions(-) - -diff --git a/source4/kdc/mit-kdb/kdb_samba_policies.c b/source4/kdc/mit-kdb/kdb_samba_policies.c -index 7bc9a7b3347..fc20bfed2f4 100644 ---- a/source4/kdc/mit-kdb/kdb_samba_policies.c -+++ b/source4/kdc/mit-kdb/kdb_samba_policies.c -@@ -192,13 +192,17 @@ static krb5_error_code ks_verify_pac(krb5_context context, - krb5_keyblock *krbtgt_key, - krb5_timestamp authtime, - krb5_authdata **tgt_auth_data, -- krb5_pac *pac) -+ krb5_pac *out_pac) - { - struct mit_samba_context *mit_ctx; - krb5_authdata **authdata = NULL; -- krb5_pac ipac = NULL; -- DATA_BLOB logon_data = { NULL, 0 }; -+ krb5_keyblock *header_server_key = NULL; -+ krb5_key_data *impersonator_kd = NULL; -+ krb5_keyblock impersonator_key = {0}; - krb5_error_code code; -+ krb5_pac pac; -+ -+ *out_pac = NULL; - - mit_ctx = ks_get_context(context); - if (mit_ctx == NULL) { -@@ -230,41 +234,43 @@ static krb5_error_code ks_verify_pac(krb5_context context, - code = krb5_pac_parse(context, - authdata[0]->contents, - authdata[0]->length, -- &ipac); -+ &pac); - if (code != 0) { - goto done; - } - -- /* TODO: verify this is correct -- * -- * In the constrained delegation case, the PAC is from a service -- * ticket rather than a TGT; we must verify the server and KDC -- * signatures to assert that the server did not forge the PAC. -+ /* -+ * For constrained delegation in MIT version < 1.18 we aren't provided -+ * with the 2nd ticket server key to verify the PAC. -+ * We can workaround that by fetching the key from the client db entry, -+ * which is the impersonator account in that version. -+ * TODO: use the provided entry in the new 1.18 version. - */ - if (flags & KRB5_KDB_FLAG_CONSTRAINED_DELEGATION) { -- code = krb5_pac_verify(context, -- ipac, -- authtime, -- client_princ, -- server_key, -- krbtgt_key); -+ /* The impersonator must be local. */ -+ if (client == NULL) { -+ code = KRB5KDC_ERR_BADOPTION; -+ goto done; -+ } -+ /* Fetch and decrypt 2nd ticket server's current key. */ -+ code = krb5_dbe_find_enctype(context, client, -1, -1, 0, -+ &impersonator_kd); -+ if (code != 0) { -+ goto done; -+ } -+ code = krb5_dbe_decrypt_key_data(context, NULL, -+ impersonator_kd, -+ &impersonator_key, NULL); -+ if (code != 0) { -+ goto done; -+ } -+ header_server_key = &impersonator_key; - } else { -- code = krb5_pac_verify(context, -- ipac, -- authtime, -- client_princ, -- krbtgt_key, -- NULL); -- } -- if (code != 0) { -- goto done; -+ header_server_key = krbtgt_key; - } - -- /* check and update PAC */ -- code = krb5_pac_parse(context, -- authdata[0]->contents, -- authdata[0]->length, -- pac); -+ code = krb5_pac_verify(context, pac, authtime, client_princ, -+ header_server_key, NULL); - if (code != 0) { - goto done; - } -@@ -272,17 +278,22 @@ static krb5_error_code ks_verify_pac(krb5_context context, - code = mit_samba_reget_pac(mit_ctx, - context, - flags, -- client_princ, - client, - server, - krbtgt, - krbtgt_key, -- pac); -+ &pac); -+ if (code != 0) { -+ goto done; -+ } -+ -+ *out_pac = pac; -+ pac = NULL; - - done: -+ krb5_free_keyblock_contents(context, &impersonator_key); - krb5_free_authdata(context, authdata); -- krb5_pac_free(context, ipac); -- free(logon_data.data); -+ krb5_pac_free(context, pac); - - return code; - } -@@ -328,6 +339,7 @@ krb5_error_code kdb_samba_db_sign_auth_data(krb5_context context, - krb5_authdata **pac_auth_data = NULL; - krb5_authdata **authdata = NULL; - krb5_boolean is_as_req; -+ krb5_const_principal pac_client; - krb5_error_code code; - krb5_pac pac = NULL; - krb5_data pac_data; -@@ -341,11 +353,6 @@ krb5_error_code kdb_samba_db_sign_auth_data(krb5_context context, - krbtgt_key = krbtgt_key == NULL ? local_krbtgt_key : krbtgt_key; - #endif - -- /* FIXME: We don't support S4U yet */ -- if (flags & KRB5_KDB_FLAGS_S4U) { -- return KRB5_KDB_DBTYPE_NOSUP; -- } -- - is_as_req = ((flags & KRB5_KDB_FLAG_CLIENT_REFERRALS_ONLY) != 0); - - /* -@@ -406,6 +413,16 @@ krb5_error_code kdb_samba_db_sign_auth_data(krb5_context context, - ks_client_princ = client->princ; - } - -+ /* In protocol transition, we are currently not provided with the tgt -+ * client name to verify the PAC, we could probably skip the name -+ * verification and just verify the signatures, but since we don't -+ * support cross-realm nor aliases, we can just use server->princ */ -+ if (flags & KRB5_KDB_FLAG_PROTOCOL_TRANSITION) { -+ pac_client = server->princ; -+ } else { -+ pac_client = ks_client_princ; -+ } -+ - if (client_entry == NULL) { - client_entry = client; - } -@@ -470,7 +487,7 @@ krb5_error_code kdb_samba_db_sign_auth_data(krb5_context context, - - code = ks_verify_pac(context, - flags, -- ks_client_princ, -+ pac_client, - client_entry, - server, - krbtgt, -@@ -510,7 +527,7 @@ krb5_error_code kdb_samba_db_sign_auth_data(krb5_context context, - is_as_req ? "AS-REQ" : "TGS-REQ", - client_name); - code = krb5_pac_sign(context, pac, authtime, ks_client_princ, -- server_key, krbtgt_key, &pac_data); -+ server_key, krbtgt_key, &pac_data); - if (code != 0) { - DBG_ERR("krb5_pac_sign failed: %d\n", code); - goto done; -@@ -536,12 +553,6 @@ krb5_error_code kdb_samba_db_sign_auth_data(krb5_context context, - KRB5_AUTHDATA_IF_RELEVANT, - authdata, - signed_auth_data); -- if (code != 0) { -- goto done; -- } -- -- code = 0; -- - done: - if (client_entry != NULL && client_entry != client) { - ks_free_principal(context, client_entry); -@@ -567,32 +578,13 @@ krb5_error_code kdb_samba_db_check_allowed_to_delegate(krb5_context context, - * server; -> delegating service - * proxy; -> target principal - */ -- krb5_db_entry *delegating_service = discard_const_p(krb5_db_entry, server); -- -- char *target_name = NULL; -- bool is_enterprise; -- krb5_error_code code; - - mit_ctx = ks_get_context(context); - if (mit_ctx == NULL) { - return KRB5_KDB_DBNOTINITED; - } - -- code = krb5_unparse_name(context, proxy, &target_name); -- if (code) { -- goto done; -- } -- -- is_enterprise = (proxy->type == KRB5_NT_ENTERPRISE_PRINCIPAL); -- -- code = mit_samba_check_s4u2proxy(mit_ctx, -- delegating_service, -- target_name, -- is_enterprise); -- --done: -- free(target_name); -- return code; -+ return mit_samba_check_s4u2proxy(mit_ctx, server, proxy); - } - - -diff --git a/source4/kdc/mit_samba.c b/source4/kdc/mit_samba.c -index e015c5a52db..2a48d731501 100644 ---- a/source4/kdc/mit_samba.c -+++ b/source4/kdc/mit_samba.c -@@ -475,7 +475,6 @@ int mit_samba_get_pac(struct mit_samba_context *smb_ctx, - krb5_error_code mit_samba_reget_pac(struct mit_samba_context *ctx, - krb5_context context, - int flags, -- krb5_const_principal client_principal, - krb5_db_entry *client, - krb5_db_entry *server, - krb5_db_entry *krbtgt, -@@ -639,7 +638,7 @@ krb5_error_code mit_samba_reget_pac(struct mit_samba_context *ctx, - context, - *pac, - server->princ, -- discard_const(client_principal), -+ client->princ, - deleg_blob); - if (!NT_STATUS_IS_OK(nt_status)) { - DEBUG(0, ("Update delegation info failed: %s\n", -@@ -961,41 +960,17 @@ int mit_samba_check_client_access(struct mit_samba_context *ctx, - } - - int mit_samba_check_s4u2proxy(struct mit_samba_context *ctx, -- krb5_db_entry *kentry, -- const char *target_name, -- bool is_nt_enterprise_name) -+ const krb5_db_entry *server, -+ krb5_const_principal target_principal) - { --#if 1 -- /* -- * This is disabled because mit_samba_update_pac_data() does not handle -- * S4U_DELEGATION_INFO -- */ -- -- return KRB5KDC_ERR_BADOPTION; --#else -- krb5_principal target_principal; -- int flags = 0; -- int ret; -- -- if (is_nt_enterprise_name) { -- flags = KRB5_PRINCIPAL_PARSE_ENTERPRISE; -- } -- -- ret = krb5_parse_name_flags(ctx->context, target_name, -- flags, &target_principal); -- if (ret) { -- return ret; -- } -- -- ret = samba_kdc_check_s4u2proxy(ctx->context, -- ctx->db_ctx, -- skdc_entry, -- target_principal); -- -- krb5_free_principal(ctx->context, target_principal); -- -- return ret; --#endif -+ struct samba_kdc_entry *server_skdc_entry = -+ talloc_get_type_abort(server->e_data, -+ struct samba_kdc_entry); -+ -+ return samba_kdc_check_s4u2proxy(ctx->context, -+ ctx->db_ctx, -+ server_skdc_entry, -+ target_principal); - } - - static krb5_error_code mit_samba_change_pwd_error(krb5_context context, -diff --git a/source4/kdc/mit_samba.h b/source4/kdc/mit_samba.h -index 636c77ec97c..9cb00c9610e 100644 ---- a/source4/kdc/mit_samba.h -+++ b/source4/kdc/mit_samba.h -@@ -56,7 +56,6 @@ int mit_samba_get_pac(struct mit_samba_context *smb_ctx, - krb5_error_code mit_samba_reget_pac(struct mit_samba_context *ctx, - krb5_context context, - int flags, -- krb5_const_principal client_principal, - krb5_db_entry *client, - krb5_db_entry *server, - krb5_db_entry *krbtgt, -@@ -73,9 +72,8 @@ int mit_samba_check_client_access(struct mit_samba_context *ctx, - DATA_BLOB *e_data); - - int mit_samba_check_s4u2proxy(struct mit_samba_context *ctx, -- krb5_db_entry *kentry, -- const char *target_name, -- bool is_nt_enterprise_name); -+ const krb5_db_entry *server, -+ krb5_const_principal target_principal); - - int mit_samba_kpasswd_change_password(struct mit_samba_context *ctx, - char *pwd, --- -2.33.1 - - -From 9eca7b08a3987d6320d6584e146005bbc01720f6 Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Fri, 27 Sep 2019 18:35:30 +0300 -Subject: [PATCH 2/3] krb5-mit: enable S4U client support for MIT build - -Signed-off-by: Isaac Boukris -Pair-Programmed-With: Andreas Schneider ---- - lib/krb5_wrap/krb5_samba.c | 185 ++++++++++++++++++++++++++ - lib/krb5_wrap/krb5_samba.h | 2 - - source4/auth/kerberos/kerberos_util.c | 11 -- - 3 files changed, 185 insertions(+), 13 deletions(-) - -diff --git a/lib/krb5_wrap/krb5_samba.c b/lib/krb5_wrap/krb5_samba.c -index fff5b4e2a22..791b417d5ba 100644 ---- a/lib/krb5_wrap/krb5_samba.c -+++ b/lib/krb5_wrap/krb5_samba.c -@@ -2694,6 +2694,191 @@ krb5_error_code smb_krb5_kinit_s4u2_ccache(krb5_context ctx, - - return 0; - } -+ -+#else /* MIT */ -+ -+static bool princ_compare_no_dollar(krb5_context ctx, -+ krb5_principal a, -+ krb5_principal b) -+{ -+ bool cmp; -+ krb5_principal mod = NULL; -+ -+ if (a->length == 1 && b->length == 1 && -+ a->data[0].length != 0 && b->data[0].length != 0 && -+ a->data[0].data[a->data[0].length -1] != -+ b->data[0].data[b->data[0].length -1]) { -+ if (a->data[0].data[a->data[0].length -1] == '$') { -+ mod = a; -+ mod->data[0].length--; -+ } else if (b->data[0].data[b->data[0].length -1] == '$') { -+ mod = b; -+ mod->data[0].length--; -+ } -+ } -+ -+ cmp = krb5_principal_compare_flags(ctx, a, b, -+ KRB5_PRINCIPAL_COMPARE_CASEFOLD); -+ -+ if (mod != NULL) { -+ mod->data[0].length++; -+ } -+ -+ return cmp; -+} -+ -+krb5_error_code smb_krb5_kinit_s4u2_ccache(krb5_context ctx, -+ krb5_ccache store_cc, -+ krb5_principal init_principal, -+ const char *init_password, -+ krb5_principal impersonate_principal, -+ const char *self_service, -+ const char *target_service, -+ krb5_get_init_creds_opt *krb_options, -+ time_t *expire_time, -+ time_t *kdc_time) -+{ -+ krb5_error_code code; -+ krb5_principal self_princ = NULL; -+ krb5_principal target_princ = NULL; -+ krb5_creds *store_creds; -+ krb5_creds *s4u2self_creds = NULL; -+ krb5_creds *s4u2proxy_creds = NULL; -+ krb5_creds init_creds = {0}; -+ krb5_creds mcreds = {0}; -+ krb5_flags options = KRB5_GC_NO_STORE; -+ krb5_ccache tmp_cc; -+ bool s4u2proxy; -+ -+ code = krb5_cc_new_unique(ctx, "MEMORY", NULL, &tmp_cc); -+ if (code != 0) { -+ return code; -+ } -+ -+ code = krb5_get_init_creds_password(ctx, &init_creds, -+ init_principal, -+ init_password, -+ NULL, NULL, -+ 0, -+ NULL, -+ krb_options); -+ if (code != 0) { -+ goto done; -+ } -+ -+ code = krb5_cc_initialize(ctx, tmp_cc, init_creds.client); -+ if (code != 0) { -+ goto done; -+ } -+ -+ code = krb5_cc_store_cred(ctx, tmp_cc, &init_creds); -+ if (code != 0) { -+ goto done; -+ } -+ -+ /* -+ * Check if we also need S4U2Proxy or if S4U2Self is -+ * enough in order to get a ticket for the target. -+ */ -+ if (target_service == NULL) { -+ s4u2proxy = false; -+ } else if (strcmp(target_service, self_service) == 0) { -+ s4u2proxy = false; -+ } else { -+ s4u2proxy = true; -+ } -+ -+ code = krb5_parse_name(ctx, self_service, &self_princ); -+ if (code != 0) { -+ goto done; -+ } -+ -+ /* MIT lacks aliases support in S4U, for S4U2Self we require the tgt -+ * client and the request server to be the same principal name. */ -+ if (!princ_compare_no_dollar(ctx, init_creds.client, self_princ)) { -+ code = KRB5KDC_ERR_PADATA_TYPE_NOSUPP; -+ goto done; -+ } -+ -+ mcreds.client = impersonate_principal; -+ mcreds.server = init_creds.client; -+ -+ code = krb5_get_credentials_for_user(ctx, options, tmp_cc, &mcreds, -+ NULL, &s4u2self_creds); -+ if (code != 0) { -+ goto done; -+ } -+ -+ if (s4u2proxy) { -+ code = krb5_parse_name(ctx, target_service, &target_princ); -+ if (code != 0) { -+ goto done; -+ } -+ -+ mcreds.client = init_creds.client; -+ mcreds.server = target_princ; -+ mcreds.second_ticket = s4u2self_creds->ticket; -+ -+ code = krb5_get_credentials(ctx, options | -+ KRB5_GC_CONSTRAINED_DELEGATION, -+ tmp_cc, &mcreds, &s4u2proxy_creds); -+ if (code != 0) { -+ goto done; -+ } -+ -+ /* Check KDC support of S4U2Proxy extension */ -+ if (!krb5_principal_compare(ctx, s4u2self_creds->client, -+ s4u2proxy_creds->client)) { -+ code = KRB5KDC_ERR_PADATA_TYPE_NOSUPP; -+ goto done; -+ } -+ -+ store_creds = s4u2proxy_creds; -+ } else { -+ store_creds = s4u2self_creds;; -+ -+ /* We need to save the ticket with the requested server name -+ * or the caller won't be able to find it in cache. */ -+ if (!krb5_principal_compare(ctx, self_princ, -+ store_creds->server)) { -+ krb5_free_principal(ctx, store_creds->server); -+ store_creds->server = NULL; -+ code = krb5_copy_principal(ctx, self_princ, -+ &store_creds->server); -+ if (code != 0) { -+ goto done; -+ } -+ } -+ } -+ -+ code = krb5_cc_initialize(ctx, store_cc, store_creds->client); -+ if (code != 0) { -+ goto done; -+ } -+ -+ code = krb5_cc_store_cred(ctx, store_cc, store_creds); -+ if (code != 0) { -+ goto done; -+ } -+ -+ if (expire_time) { -+ *expire_time = (time_t) store_creds->times.endtime; -+ } -+ -+ if (kdc_time) { -+ *kdc_time = (time_t) store_creds->times.starttime; -+ } -+ -+done: -+ krb5_cc_destroy(ctx, tmp_cc); -+ krb5_free_cred_contents(ctx, &init_creds); -+ krb5_free_creds(ctx, s4u2self_creds); -+ krb5_free_creds(ctx, s4u2proxy_creds); -+ krb5_free_principal(ctx, self_princ); -+ krb5_free_principal(ctx, target_princ); -+ -+ return code; -+} - #endif - - #if !defined(HAVE_KRB5_MAKE_PRINCIPAL) && defined(HAVE_KRB5_BUILD_PRINCIPAL_ALLOC_VA) -diff --git a/lib/krb5_wrap/krb5_samba.h b/lib/krb5_wrap/krb5_samba.h -index 56a2a975278..5af9c6d73c1 100644 ---- a/lib/krb5_wrap/krb5_samba.h -+++ b/lib/krb5_wrap/krb5_samba.h -@@ -252,7 +252,6 @@ krb5_error_code smb_krb5_kinit_password_ccache(krb5_context ctx, - krb5_get_init_creds_opt *krb_options, - time_t *expire_time, - time_t *kdc_time); --#ifdef SAMBA4_USES_HEIMDAL - krb5_error_code smb_krb5_kinit_s4u2_ccache(krb5_context ctx, - krb5_ccache store_cc, - krb5_principal init_principal, -@@ -263,7 +262,6 @@ krb5_error_code smb_krb5_kinit_s4u2_ccache(krb5_context ctx, - krb5_get_init_creds_opt *krb_options, - time_t *expire_time, - time_t *kdc_time); --#endif - - #if defined(HAVE_KRB5_MAKE_PRINCIPAL) - #define smb_krb5_make_principal krb5_make_principal -diff --git a/source4/auth/kerberos/kerberos_util.c b/source4/auth/kerberos/kerberos_util.c -index 544d9d853cc..c14d8c72d8c 100644 ---- a/source4/auth/kerberos/kerberos_util.c -+++ b/source4/auth/kerberos/kerberos_util.c -@@ -234,9 +234,7 @@ done: - { - krb5_error_code ret; - const char *password; --#ifdef SAMBA4_USES_HEIMDAL - const char *self_service; --#endif - const char *target_service; - time_t kdc_time = 0; - krb5_principal princ; -@@ -268,9 +266,7 @@ done: - return ret; - } - --#ifdef SAMBA4_USES_HEIMDAL - self_service = cli_credentials_get_self_service(credentials); --#endif - target_service = cli_credentials_get_target_service(credentials); - - password = cli_credentials_get_password(credentials); -@@ -331,7 +327,6 @@ done: - #endif - if (password) { - if (impersonate_principal) { --#ifdef SAMBA4_USES_HEIMDAL - ret = smb_krb5_kinit_s4u2_ccache(smb_krb5_context->krb5_context, - ccache, - princ, -@@ -342,12 +337,6 @@ done: - krb_options, - NULL, - &kdc_time); --#else -- talloc_free(mem_ctx); -- (*error_string) = "INTERNAL error: s4u2 ops " -- "are not supported with MIT build yet"; -- return EINVAL; --#endif - } else { - ret = smb_krb5_kinit_password_ccache(smb_krb5_context->krb5_context, - ccache, --- -2.33.1 - - -From 80289eca2bb614aacd0df86bcf7ad7027c080671 Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Sat, 19 Sep 2020 14:16:20 +0200 -Subject: [PATCH 3/3] wip: for canonicalization with new MIT kdc code - ---- - source4/heimdal/lib/hdb/hdb.h | 1 + - source4/kdc/db-glue.c | 8 ++++++-- - source4/kdc/mit_samba.c | 3 +++ - source4/kdc/sdb.h | 1 + - 4 files changed, 11 insertions(+), 2 deletions(-) - -diff --git a/source4/heimdal/lib/hdb/hdb.h b/source4/heimdal/lib/hdb/hdb.h -index 5ef9d9565f3..dafaffc6c2d 100644 ---- a/source4/heimdal/lib/hdb/hdb.h -+++ b/source4/heimdal/lib/hdb/hdb.h -@@ -63,6 +63,7 @@ enum hdb_lockop{ HDB_RLOCK, HDB_WLOCK }; - #define HDB_F_ALL_KVNOS 2048 /* we want all the keys, live or not */ - #define HDB_F_FOR_AS_REQ 4096 /* fetch is for a AS REQ */ - #define HDB_F_FOR_TGS_REQ 8192 /* fetch is for a TGS REQ */ -+#define HDB_F_FORCE_CANON 16384 /* force canonicalition */ - - /* hdb_capability_flags */ - #define HDB_CAP_F_HANDLE_ENTERPRISE_PRINCIPAL 1 -diff --git a/source4/kdc/db-glue.c b/source4/kdc/db-glue.c -index aff74f2ee71..d16b4c3329a 100644 ---- a/source4/kdc/db-glue.c -+++ b/source4/kdc/db-glue.c -@@ -916,17 +916,21 @@ static krb5_error_code samba_kdc_message2entry(krb5_context context, - } - } - -- } else if (ent_type == SAMBA_KDC_ENT_TYPE_ANY && principal == NULL) { -+ } else if (ent_type == SAMBA_KDC_ENT_TYPE_ANY && principal == NULL) { // was this supposed to be || ? - ret = smb_krb5_make_principal(context, &entry_ex->entry.principal, lpcfg_realm(lp_ctx), samAccountName, NULL); - if (ret) { - krb5_clear_error_message(context); - goto out; - } -- } else if ((flags & SDB_F_CANON) && (flags & SDB_F_FOR_AS_REQ)) { -+ } else if (((flags & SDB_F_CANON) && (flags & SDB_F_FOR_AS_REQ)) || (flags & SDB_F_FORCE_CANON)){ - /* - * SDB_F_CANON maps from the canonicalize flag in the - * packet, and has a different meaning between AS-REQ - * and TGS-REQ. We only change the principal in the AS-REQ case -+ * -+ * The SDB_F_FORCE_CANON if for the new MIT kdc code that wants -+ * the canonical name in all lookups, and takes care to canonicalize -+ * only when appropriate. - */ - ret = smb_krb5_make_principal(context, &entry_ex->entry.principal, lpcfg_realm(lp_ctx), samAccountName, NULL); - if (ret) { -diff --git a/source4/kdc/mit_samba.c b/source4/kdc/mit_samba.c -index 2a48d731501..a8d3e7ed493 100644 ---- a/source4/kdc/mit_samba.c -+++ b/source4/kdc/mit_samba.c -@@ -198,6 +198,9 @@ int mit_samba_get_principal(struct mit_samba_context *ctx, - if (kflags & KRB5_KDB_FLAG_CANONICALIZE) { - sflags |= SDB_F_CANON; - } -+#if KRB5_KDB_API_VERSION >= 10 -+ sflags |= SDB_F_FORCE_CANON; -+#endif - if (kflags & (KRB5_KDB_FLAG_CLIENT_REFERRALS_ONLY | - KRB5_KDB_FLAG_INCLUDE_PAC)) { - /* -diff --git a/source4/kdc/sdb.h b/source4/kdc/sdb.h -index c929acccce6..a9115ec23d7 100644 ---- a/source4/kdc/sdb.h -+++ b/source4/kdc/sdb.h -@@ -116,6 +116,7 @@ struct sdb_entry_ex { - #define SDB_F_KVNO_SPECIFIED 128 /* we want a particular KVNO */ - #define SDB_F_FOR_AS_REQ 4096 /* fetch is for a AS REQ */ - #define SDB_F_FOR_TGS_REQ 8192 /* fetch is for a TGS REQ */ -+#define SDB_F_FORCE_CANON 16384 /* force canonicalition */ - - void sdb_free_entry(struct sdb_entry_ex *e); - void free_sdb_entry(struct sdb_entry *s); --- -2.33.1 - diff --git a/samba-systemd-sysusers.conf b/samba-systemd-sysusers.conf new file mode 100644 index 0000000..60ad7a5 --- /dev/null +++ b/samba-systemd-sysusers.conf @@ -0,0 +1,2 @@ +#Type Name ID +g printadmin - diff --git a/samba-usershares-systemd-sysusers.conf b/samba-usershares-systemd-sysusers.conf new file mode 100644 index 0000000..33f8fcb --- /dev/null +++ b/samba-usershares-systemd-sysusers.conf @@ -0,0 +1,2 @@ +#Type Name ID +g usershares - diff --git a/samba-winbind-systemd-sysusers.conf b/samba-winbind-systemd-sysusers.conf new file mode 100644 index 0000000..7ccc216 --- /dev/null +++ b/samba-winbind-systemd-sysusers.conf @@ -0,0 +1,2 @@ +#Type Name ID +g wbpriv 88 diff --git a/samba.abignore b/samba.abignore new file mode 100644 index 0000000..718059d --- /dev/null +++ b/samba.abignore @@ -0,0 +1,5 @@ +################################################# +# This is a grouping library without any code +################################################# +[suppress_file] +file_name_regexp=.*libdcerpc-samr\\.so.* diff --git a/samba.logrotate b/samba.logrotate index 40f85aa..43bef68 100644 --- a/samba.logrotate +++ b/samba.logrotate @@ -1,4 +1,4 @@ -/var/log/samba/log.* { +/var/log/samba/*log* { compress dateext maxage 365 diff --git a/samba.spec b/samba.spec index f3b678a..b49a21a 100644 --- a/samba.spec +++ b/samba.spec @@ -1,29 +1,193 @@ -# rpmbuild --rebuild --with testsuite --without clustering samba.src.rpm +# The testsuite is disabled by default. # -# The testsuite is disabled by default. Set --with testsuite or bcond_without -# to run the Samba torture testsuite. -%bcond_with testsuite -# ctdb is enabled by default, you can disable it with: --without clustering -%bcond_without clustering - -%define samba_requires_eq() %(LC_ALL="C" echo '%*' | xargs -r rpm -q --qf 'Requires: %%{name} = %%{epoch}:%%{version}\\n' | sed -e 's/ (none):/ /' -e 's/ 0:/ /' | grep -v "is not") - -%define main_release 2 - -%define samba_version 4.13.14 -%define talloc_version 2.3.1 -%define tdb_version 1.4.3 -%define tevent_version 0.10.2 -%define ldb_version 2.2.3 -# This should be rc1 or nil -%define pre_release %nil - -%if "x%{?pre_release}" != "x" -%define samba_release 0.%{main_release}.%{pre_release}%{?dist} -%else -%define samba_release %{main_release}%{?dist} +# To build and run the tests use: +# +# fedpkg mockbuild --with testsuite +# or +# rpmbuild --rebuild --with testsuite samba.src.rpm +# +# If you just want to run a single test, you can use: +# fedpkg mockbuild --with testsuite -- --define 'SAMBA_TESTS regex' samba.src.rpm +# or +# rpmbuild --rebuild --with testsuite --define='SAMBA_TESTS regex' samba.src.rpm +# +%bcond testsuite 0 +%if %{with testsuite} +# As the file list is empty for running just the tests, we have empty debuginfo +# package. Disable it to avoid error reporting. +%global debug_package %{nil} %endif +# Build with internal talloc, tevent, tdb +# +# fedpkg mockbuild --with=testsuite --with=includelibs +# or +# rpmbuild --rebuild --with=testsuite --with=includelibs samba.src.rpm +# +%bcond includelibs 0 + +# fedpkg mockbuild --with=ccache +%bcond ccache 0 + +# ctdb is enabled by default, you can disable it with: --without clustering +%bcond clustering 1 + +# Define _make_verbose if it doesn't exist (RHEL8) +%{!?_make_verbose:%define _make_verbose V=1 VERBOSE=1} + +# Build with Active Directory Domain Controller support by default on Fedora +%if 0%{?fedora} +%bcond dc 1 +%else +%bcond dc 0 +%endif + +# Build a libsmbclient package by default +%bcond libsmbclient 1 + +# Build a libwbclient package by default +%bcond libwbclient 1 + +# Build with winexe by default +%if 0%{?rhel} + +%ifarch x86_64 +%bcond winexe 1 +%else +%bcond winexe 0 +#endifarch +%endif + +%else +%bcond winexe 1 +%endif + +# Build vfs_ceph module and ctdb cepth mutex helper by default on 64bit Fedora +%if 0%{?fedora} + +%ifarch aarch64 ppc64le s390x x86_64 riscv64 +%bcond vfs_cephfs 1 +%bcond ceph_mutex 1 +%else +%bcond vfs_cephfs 0 +%bcond ceph_mutex 0 +#endifarch +%endif + +%else +%bcond vfs_cephfs 0 +%bcond ceph_mutex 0 +#endif fedora +%endif + +%if 0%{?fedora} + +%ifarch aarch64 ppc64le s390x x86_64 riscv64 +%bcond vfs_glusterfs 1 +%else +%bcond vfs_glusterfs 0 +#endifarch +%endif + +#endif fedora +%endif + +# Build vfs_io_uring module by default on 64bit Fedora +%ifarch aarch64 ppc64le s390x x86_64 riscv64 +%bcond vfs_io_uring 1 +%else +%bcond vfs_io_uring 0 +#endifarch +%endif + +# Build the ctdb-pcp-pmda package by default on Fedora, except for i686 where +# pcp is no longer supported +%if 0%{?fedora} +%ifnarch i686 +%bcond pcp_pmda 1 +%endif +%else +%bcond pcp_pmda 0 +%endif + +# Build the etcd helpers by default on Fedora +%if 0%{?fedora} +# disable etcd mutex helper as etcd is orphaned in Fedora now +%bcond etcd_mutex 0 +%else +%bcond etcd_mutex 0 +%endif + +# Build the prometheus exporter by default on Fedora +%if 0%{?fedora} +%bcond prometheus 1 +%else +%bcond prometheus 0 +%endif + +%ifarch aarch64 ppc64le s390x x86_64 riscv64 +%bcond lmdb 1 +%else +%bcond lmdb 0 +%endif + +%if 0%{?fedora} >= 43 +%bcond varlink 1 +%else +%bcond varlink 0 +%endif + +%global samba_version 4.23.4 + +# The release field is extended: +# [.][.]%%{?dist}[.] +# Square brackets indicate an optional item. +# +# The autorelease macro accepts these parameters to allow packagers to specify +# those added fields: +# +# -p: Designates a pre-release, i.e. pkgrel will be prefixed with '0.'. +# -e : Allows specifying the extraver portion of the release. +# -b : Allows specifying a custom base release number (the +# default is 1). +%global samba_release %autorelease + +%global pre_release %nil +%if "x%{?pre_release}" != "x" +%global samba_release %autorelease -p -e %pre_release +%endif + + +# If one of those versions change, we need to make sure we rebuilt or adapt +# projects comsuming those. This is e.g. sssd, openchange, evolution-mapi, ... +%global libdcerpc_binding_so_version 0 +%global libdcerpc_server_core_so_version 0 +%global libdcerpc_so_version 0 +%global libndr_krb5pac_so_version 0 +%global libndr_nbt_so_version 0 +%global libndr_so_version 6 +%global libndr_standard_so_version 0 +%global libnetapi_so_version 1 +%global libsamba_credentials_so_version 1 +%global libsamba_errors_so_version 1 +%global libsamba_hostconfig_so_version 0 +%global libsamba_passdb_so_version 0 +%global libsamba_policy_so_version 0 +%global libsamba_util_so_version 0 +%global libsamdb_so_version 0 +%global libsmbconf_so_version 0 +%global libsmbldap_so_version 2 +%global libtevent_util_so_version 0 + +%global libsmbclient_so_version 0 +%global libwbclient_so_version 0 + +%global talloc_version 2.4.3 +%global tdb_version 1.4.14 +%global tevent_version 0.17.1 + +%global required_mit_krb5 1.20.1 + # This is a network daemon, do a hardened build # Enables PIE and full RELRO protection %global _hardened_build 1 @@ -34,87 +198,26 @@ # https://src.fedoraproject.org/rpms/redhat-rpm-config/blob/master/f/buildflags.md %undefine _strict_symbol_defs_build -%global with_libsmbclient 1 -%global with_libwbclient 1 - -%global with_profiling 1 - -%global with_vfs_cephfs 0 -%if 0%{?fedora} -%ifarch aarch64 ppc64le s390x x86_64 -%global with_vfs_cephfs 1 -#endifarch -%endif -#endif fedora -%endif - -%global with_vfs_glusterfs 1 -%if 0%{?rhel} -%global with_vfs_glusterfs 0 -# Only enable on x86_64 -%ifarch x86_64 -%global with_vfs_glusterfs 1 -#endif arch -%endif -#endif rhel -%endif - -%global libwbc_alternatives_version 0.15 -%global libwbc_alternatives_suffix %nil -%if 0%{?__isa_bits} == 64 -%global libwbc_alternatives_suffix -64 -%endif - -%global with_dc 1 - -%if 0%{?rhel} -%global with_dc 0 -%endif - -%if %{with testsuite} -%global with_dc 1 -%endif - -%global required_mit_krb5 1.18 - -%global with_clustering_support 0 - -%if %{with clustering} -%global with_clustering_support 1 -%endif - -# Enable winexe by default -%bcond_without winexe - -%global with_vfs_io_uring 0 -# We need liburing >= 0.4 which is not available in RHEL yet -%if 0%{?fedora} -%ifarch aarch64 ppc64le s390x x86_64 i686 -%global with_vfs_io_uring 1 -%endif -# /fedora -%endif - %global _systemd_extra "Environment=KRB5CCNAME=FILE:/run/samba/krb5cc_samba" +# Make a copy of this variable to prevent repeated evaluation of the +# embedded shell command. Avoid recursive macro definition if undefined. +%{?python3_sitearch: %global python3_sitearch %{python3_sitearch}} + Name: samba Version: %{samba_version} Release: %{samba_release} -%if 0%{?rhel} -Epoch: 0 -%else +%if 0%{?fedora} Epoch: 2 +%else +Epoch: 0 %endif -%if 0%{?epoch} > 0 -%define samba_depver %{epoch}:%{version}-%{release} -%else -%define samba_depver %{version}-%{release} -%endif +%global samba_depver %{epoch}:%{version}-%{release} Summary: Server and Client software to interoperate with Windows machines -License: GPLv3+ and LGPLv3+ +License: GPL-3.0-or-later AND LGPL-3.0-or-later URL: https://www.samba.org # This is a xz recompressed file of https://ftp.samba.org/pub/samba/samba-%%{version}%%{pre_release}.tar.gz @@ -128,29 +231,27 @@ Source11: smb.conf.vendor Source12: smb.conf.example Source13: pam_winbind.conf Source14: samba.pamd +Source15: usershares.conf.vendor +Source16: samba-systemd-sysusers.conf +Source17: samba-usershares-systemd-sysusers.conf +Source18: samba-winbind-systemd-sysusers.conf Source201: README.downgrade -Patch1: samba-s4u.patch -# Backport bug fixes to https://gitlab.com/samba-redhat/samba/-/tree/v4-13-redhat -# This will give us CI and makes it easy to generate patchsets. -# -# Generate the patchset using: git format-patch -l1 --stdout -N > samba-4.13-redhat.patch -Patch2: samba-4.13-redhat.patch -Patch3: samba-4.13-fix-winbind-no-trusted-domain.patch -Patch4: samba-4.13-ipa-dc-schannel.patch +Source202: samba.abignore -Requires(pre): /usr/sbin/groupadd -Requires(post): systemd -Requires(preun): systemd -Requires(postun): systemd +Patch0: samba-4.23-fix-cmocka.patch Requires(pre): %{name}-common = %{samba_depver} Requires: %{name}-common = %{samba_depver} -Requires: %{name}-common-libs = %{samba_depver} +Requires: %{name}-ndr-libs = %{samba_depver} Requires: %{name}-common-tools = %{samba_depver} Requires: %{name}-client-libs = %{samba_depver} Requires: %{name}-libs = %{samba_depver} -%if %with_libwbclient +Requires: %{name}-dcerpc = %{samba_depver} +Requires: libldb = %{samba_depver} +Requires: libnetapi = %{samba_depver} +%if %{with libwbclient} +Requires(post): libwbclient = %{samba_depver} Requires: libwbclient = %{samba_depver} %endif @@ -174,12 +275,17 @@ Obsoletes: samba-swat < %{samba_depver} Provides: samba4-swat = %{samba_depver} Obsoletes: samba4-swat < %{samba_depver} +Provides: bundled(libreplace) = %{samba_depver} + +BuildRequires: make BuildRequires: gcc +BuildRequires: glibc-gconv-extra BuildRequires: avahi-devel BuildRequires: bison BuildRequires: cups-devel BuildRequires: dbus-devel BuildRequires: docbook-style-xsl +BuildRequires: doxygen BuildRequires: e2fsprogs-devel BuildRequires: flex BuildRequires: gawk @@ -195,11 +301,14 @@ BuildRequires: libattr-devel BuildRequires: libcap-devel BuildRequires: libicu-devel BuildRequires: libcmocka-devel -BuildRequires: libnsl2-devel BuildRequires: libtirpc-devel BuildRequires: libuuid-devel +BuildRequires: libxcrypt-devel BuildRequires: libxslt +%if %{with lmdb} BuildRequires: lmdb +BuildRequires: lmdb-devel >= 0.9.16 +%endif %if %{with winexe} BuildRequires: mingw32-gcc BuildRequires: mingw64-gcc @@ -212,13 +321,17 @@ BuildRequires: perl-generators BuildRequires: perl(Archive::Tar) BuildRequires: perl(Test::More) BuildRequires: popt-devel +BuildRequires: python3-cryptography BuildRequires: python3-devel +BuildRequires: python3-dns +BuildRequires: python3-requests BuildRequires: python3-setuptools BuildRequires: quota-devel BuildRequires: readline-devel BuildRequires: rpcgen BuildRequires: rpcsvc-proto-devel BuildRequires: sed +BuildRequires: systemd-rpm-macros BuildRequires: libtasn1-devel # We need asn1Parser BuildRequires: libtasn1-tools @@ -227,35 +340,58 @@ BuildRequires: xz BuildRequires: zlib-devel >= 1.2.3 BuildRequires: pkgconfig(libsystemd) +# TODO FIXME This is not in RHEL yet +%if 0%{?fedora} >= 43 +BuildRequires: pkgconfig(libngtcp2) +BuildRequires: pkgconfig(libngtcp2_crypto_gnutls) +%else +Provides: bundled(ngtcp2) +%endif -%if %{with_vfs_glusterfs} +%if %{with varlink} +BuildRequires: pkgconfig(libvarlink) >= 24 +%endif + +%ifnarch i686 +%if 0%{?fedora} >= 37 +BuildRequires: mold +%endif +%endif + +%if %{with vfs_glusterfs} BuildRequires: glusterfs-api-devel >= 3.4.0.16 BuildRequires: glusterfs-devel >= 3.4.0.16 %endif -%if %{with_vfs_cephfs} +%if %{with vfs_cephfs} BuildRequires: libcephfs-devel %endif -%if %{with_vfs_io_uring} +%if %{with vfs_io_uring} BuildRequires: liburing-devel >= 0.4 %endif -%if %{with_dc} -# Add python3-iso8601 to avoid that the -# version in Samba is being packaged -BuildRequires: python3-iso8601 - -BuildRequires: bind -BuildRequires: krb5-server >= %{required_mit_krb5} -#endif with_dc +%if %{with pcp_pmda} +BuildRequires: pcp-libs-devel %endif +%if %{with ceph_mutex} +BuildRequires: librados-devel +%endif +%if %{with etcd_mutex} +BuildRequires: python3-etcd +%endif +%if %{with prometheus} +BuildRequires: libevent-devel +%endif + +BuildRequires: cepces-certmonger >= 0.3.8 # pidl requirements BuildRequires: perl(ExtUtils::MakeMaker) BuildRequires: perl(FindBin) BuildRequires: perl(Parse::Yapp) +%if %{without includelibs} BuildRequires: libtalloc-devel >= %{talloc_version} BuildRequires: python3-talloc-devel >= %{talloc_version} @@ -264,20 +400,55 @@ BuildRequires: python3-tevent >= %{tevent_version} BuildRequires: libtdb-devel >= %{tdb_version} BuildRequires: python3-tdb >= %{tdb_version} - -BuildRequires: libldb-devel >= %{ldb_version} -BuildRequires: python3-ldb-devel >= %{ldb_version} - -%if %{with testsuite} || %{with_dc} -BuildRequires: ldb-tools -BuildRequires: tdb-tools -BuildRequires: python3-gpg -BuildRequires: python3-markdown %endif -%if %{with_dc} -BuildRequires: krb5-server >= %{required_mit_krb5} +%if %{with dc} BuildRequires: bind +BuildRequires: krb5-server >= %{required_mit_krb5} +%if 0%{?fedora} || 0%{?rhel} >= 9 +BuildRequires: python3-dateutil +%else +BuildRequires: python3-iso8601 +%endif +BuildRequires: python3-gpg +BuildRequires: python3-markdown +BuildRequires: python3-pyasn1 >= 0.4.8 +BuildRequires: python3-setproctitle + +%if %{without includelibs} +BuildRequires: tdb-tools +#endif without includelibs +%endif + +#endif with dc +%endif + +%if %{with testsuite} +BuildRequires: bind-utils +BuildRequires: glibc-langpack-en +BuildRequires: git +BuildRequires: gnutls-utils +BuildRequires: jq +BuildRequires: krb5-pkinit +BuildRequires: krb5-workstation +BuildRequires: lmdb +BuildRequires: nss_wrapper +BuildRequires: pam_wrapper +BuildRequires: perl-Archive-Tar +BuildRequires: perl-Digest-MD5 +BuildRequires: perl-ExtUtils-MakeMaker +BuildRequires: perl-JSON +BuildRequires: perl-JSON-Parse +BuildRequires: perl-Parse-Yapp +BuildRequires: perl-Test-Base +BuildRequires: psmisc +BuildRequires: python3-libpamtest +BuildRequires: resolv_wrapper +BuildRequires: rsync +BuildRequires: socket_wrapper +BuildRequires: sudo +BuildRequires: uid_wrapper +#endif with testsuite %endif # filter out perl requirements pulled in from examples in the docdir. @@ -294,12 +465,13 @@ Unix. Summary: Samba client programs Requires(pre): %{name}-common = %{samba_depver} Requires: %{name}-common = %{samba_depver} -Requires: %{name}-common-libs = %{samba_depver} +Requires: %{name}-ndr-libs = %{samba_depver} Requires: %{name}-client-libs = %{samba_depver} -%if %with_libsmbclient +Requires: libldb = %{samba_depver} +%if %{with libsmbclient} Requires: libsmbclient = %{samba_depver} %endif -%if %with_libwbclient +%if %{with libwbclient} Requires: libwbclient = %{samba_depver} %endif @@ -309,21 +481,76 @@ Obsoletes: samba4-client < %{samba_depver} Requires(post): %{_sbindir}/update-alternatives Requires(postun): %{_sbindir}/update-alternatives +Provides: bundled(libreplace) = %{samba_depver} + %description client The %{name}-client package provides some SMB/CIFS clients to complement the built-in SMB/CIFS filesystem in Linux. These clients allow access of SMB/CIFS shares and printing to SMB/CIFS printers. +### CORE-LIBS +%package core-libs +Summary: Samba core libraries +Requires(pre): %{name}-common = %{samba_depver} +Requires: %{name}-common = %{samba_depver} + +Provides: bundled(libreplace) = %{samba_depver} + +%description core-libs +The samba-core-libs package contains foundational libraries needed by +both Samba servers and clients. This includes error handling, utilities, +and basic support libraries. + +### NDR-LIBS +%package ndr-libs +Summary: Samba NDR libraries +Requires(pre): %{name}-common = %{samba_depver} +Requires: %{name}-common = %{samba_depver} +Requires: %{name}-core-libs = %{samba_depver} + +Provides: %{name}-common-libs = %{samba_depver} +Obsoletes: %{name}-common-libs < %{samba_depver} + +%if %{without dc} && %{without testsuite} +Obsoletes: samba-dc < %{samba_depver} +Obsoletes: samba-dc-libs < %{samba_depver} +Obsoletes: samba-dc-bind-dlz < %{samba_depver} +%endif + +# ctdb-tests package has been dropped if we do not build the testsuite +%if %{with clustering} +%if %{without testsuite} +Obsoletes: ctdb-tests < %{samba_depver} +Obsoletes: ctdb-tests-debuginfo < %{samba_depver} +# endif without testsuite +%endif +# endif with clustering +%endif + +# We only build glusterfs for RHGS and Fedora, so obsolete it on other versions +# of the distro +%if %{without vfs_glusterfs} +Obsoletes: samba-vfs-glusterfs < %{samba_depver} +# endif without vfs_glusterfs +%endif + +%description ndr-libs +The samba-ndr-libs package contains NDR (Network Data Representation) +encoding libraries used by both Samba servers and clients. + ### CLIENT-LIBS %package client-libs Summary: Samba client libraries Requires(pre): %{name}-common = %{samba_depver} Requires: %{name}-common = %{samba_depver} -Requires: %{name}-common-libs = %{samba_depver} -%if %with_libwbclient +Requires: %{name}-ndr-libs = %{samba_depver} +Requires: libldb = %{samba_depver} +%if %{with libwbclient} Requires: libwbclient = %{samba_depver} %endif Requires: krb5-libs >= %{required_mit_krb5} +# This is needed for charset conversion +Requires: glibc-gconv-extra %description client-libs The samba-client-libs package contains internal libraries needed by the @@ -334,76 +561,103 @@ SMB/CIFS clients. Summary: Files used by both Samba servers and clients BuildArch: noarch -Requires(post): systemd +Requires(post): (systemd-standalone-tmpfiles or systemd) +%if 0%{?fedora} Recommends: logrotate +%endif Provides: samba4-common = %{samba_depver} Obsoletes: samba4-common < %{samba_depver} -%if ! %{with_dc} -Obsoletes: samba-dc < %{samba_depver} -Obsoletes: samba-dc-libs < %{samba_depver} -Obsoletes: samba-dc-bind-dlz < %{samba_depver} -%endif - %description common samba-common provides files necessary for both the server and client packages of Samba. -### COMMON-LIBS -%package common-libs -Summary: Libraries used by both Samba servers and clients -Requires(pre): samba-common = %{samba_depver} -Requires: samba-common = %{samba_depver} -Requires: %{name}-client-libs = %{samba_depver} -%if %with_libwbclient -Requires: libwbclient = %{samba_depver} -%endif - -%description common-libs -The samba-common-libs package contains internal libraries needed by the -SMB/CIFS clients. - ### COMMON-TOOLS %package common-tools -Summary: Tools for Samba servers and clients -Requires: samba-common-libs = %{samba_depver} +Summary: Tools for Samba clients +Requires: samba-ndr-libs = %{samba_depver} Requires: samba-client-libs = %{samba_depver} Requires: samba-libs = %{samba_depver} -%if %with_libwbclient +Requires: samba-ldb-ldap-modules = %{samba_depver} +Requires: libldb = %{samba_depver} +Requires: libnetapi = %{samba_depver} +%if %{with libwbclient} Requires: libwbclient = %{samba_depver} %endif +Provides: bundled(libreplace) = %{samba_depver} + %description common-tools -The samba-common-tools package contains tools for Samba servers and -SMB/CIFS clients. +The samba-common-tools package contains tools for SMB/CIFS clients. + +### SAMBA-TOOLS +%package tools +Summary: Tools for Samba servers +# samba-tool needs python3-samba +Requires: python3-%{name} = %{samba_depver} +# samba-tool needs python3-samba-dc also on non-dc build +Requires: python3-%{name}-dc = %{samba_depver} +%if %{with dc} +# samba-tool needs mdb_copy and tdbackup for domain backup or upgrade provision +%if %{with lmdb} +Requires: lmdb +%endif +Requires: tdb-tools +Requires: python3-gpg +%endif + +%description tools +The samba-tools package contains tools for Samba servers +and for GPO management on domain members. + +### RPC +%package dcerpc +Summary: DCE RPC binaries +Requires: samba-ndr-libs = %{samba_depver} +Requires: samba-client-libs = %{samba_depver} +Requires: samba-libs = %{samba_depver} +Requires: libldb = %{samba_depver} +Requires: libnetapi = %{samba_depver} +%if %{with libwbclient} +Requires: libwbclient = %{samba_depver} +%endif + +%description dcerpc +The samba-dcerpc package contains binaries that serve DCERPC over named pipes. ### DC -%if %{with_dc} +%if %{with dc} || %{with testsuite} %package dc Summary: Samba AD Domain Controller Requires: %{name} = %{samba_depver} +Requires: %{name}-client-libs = %{samba_depver} +Requires: %{name}-ndr-libs = %{samba_depver} +Requires: %{name}-common-tools = %{samba_depver} +Requires: %{name}-tools = %{samba_depver} Requires: %{name}-libs = %{samba_depver} Requires: %{name}-dc-provision = %{samba_depver} Requires: %{name}-dc-libs = %{samba_depver} Requires: %{name}-winbind = %{samba_depver} -# samba-tool needs tdbbackup -Requires: tdb-tools -# samba-tool needs mdb_copy -Requires: lmdb -Requires: ldb-tools -# Force using libldb version to be the same as build version -# Otherwise LDB modules will not be loaded and samba-tool will fail -# See bug 1507420 -%samba_requires_eq libldb +%if %{with libwbclient} +Requires(post): libwbclient = %{samba_depver} +Requires: libwbclient = %{samba_depver} +%endif + +Requires: ldb-tools +Requires: python3-setproctitle +Requires: libldb = %{samba_depver} Requires: python3-%{name} = %{samba_depver} Requires: python3-%{name}-dc = %{samba_depver} Requires: krb5-server >= %{required_mit_krb5} +Requires: bind-utils Provides: samba4-dc = %{samba_depver} Obsoletes: samba4-dc < %{samba_depver} +Provides: bundled(libreplace) = %{samba_depver} + %description dc The samba-dc package provides AD Domain Controller functionality @@ -415,41 +669,62 @@ BuildArch: noarch %description dc-provision The samba-dc-provision package provides files to setup a domain controller +#endif with dc || with testsuite +%endif + ### DC-LIBS %package dc-libs Summary: Samba AD Domain Controller Libraries -Requires: %{name}-common-libs = %{samba_depver} +Requires: %{name}-client-libs = %{samba_depver} +Requires: %{name}-ndr-libs = %{samba_depver} Requires: %{name}-libs = %{samba_depver} +Requires: libldb = %{samba_depver} +Requires: libwbclient = %{samba_depver} Provides: samba4-dc-libs = %{samba_depver} Obsoletes: samba4-dc-libs < %{samba_depver} +Provides: bundled(libreplace) = %{samba_depver} + %description dc-libs The %{name}-dc-libs package contains the libraries needed by the DC to link against the SMB, RPC and other protocols. +%if %{with dc} || %{with testsuite} ### DC-BIND %package dc-bind-dlz Summary: Bind DLZ module for Samba AD +Requires: %{name}-client-libs = %{samba_depver} Requires: %{name}-common = %{samba_depver} Requires: %{name}-dc-libs = %{samba_depver} Requires: %{name}-dc = %{samba_depver} +Requires: %{name}-libs = %{samba_depver} Requires: bind +Requires: libldb = %{samba_depver} +Requires: libwbclient = %{samba_depver} + +Provides: bundled(libreplace) = %{samba_depver} %description dc-bind-dlz The %{name}-dc-bind-dlz package contains the libraries for bind to manage all name server related details of Samba AD. -#endif with_dc +#endif with dc %endif ### DEVEL %package devel Summary: Developer tools for Samba libraries -Requires: %{name}-libs = %{samba_depver} +Requires: %{name}-core-libs = %{samba_depver} Requires: %{name}-client-libs = %{samba_depver} +Requires: %{name}-ndr-libs = %{samba_depver} +Requires: %{name}-libs = %{samba_depver} +Requires: %{name}-dc-libs = %{samba_depver} +Requires: libnetapi = %{samba_depver} Provides: samba4-devel = %{samba_depver} Obsoletes: samba4-devel < %{samba_depver} +Provides: python3-samba-devel = %{samba_depver} +Obsoletes: python3-samba-devel < %{samba_depver} %description devel The %{name}-devel package contains the header files for the libraries @@ -457,38 +732,78 @@ needed to develop programs that link against the SMB, RPC and other libraries in the Samba suite. ### CEPH -%if %{with_vfs_cephfs} +%if %{with vfs_cephfs} %package vfs-cephfs Summary: Samba VFS module for Ceph distributed storage system Requires: %{name} = %{samba_depver} +Requires: %{name}-client-libs = %{samba_depver} Requires: %{name}-libs = %{samba_depver} +Requires: libldb = %{samba_depver} +Requires: libwbclient = %{samba_depver} + +Provides: bundled(libreplace) = %{samba_depver} %description vfs-cephfs Samba VFS module for Ceph distributed storage system integration. -#endif with_vfs_cephfs +#endif with vfs_cephfs +%endif + +### IOURING +%if %{with vfs_io_uring} +%package vfs-iouring +Summary: Samba VFS module for io_uring +Requires: %{name} = %{samba_depver} +Requires: %{name}-libs = %{samba_depver} +Requires: %{name}-client-libs = %{samba_depver} +Requires: libldb = %{samba_depver} +Requires: libwbclient = %{samba_depver} + +Provides: bundled(libreplace) = %{samba_depver} + +%description vfs-iouring +Samba VFS module for io_uring instance integration. +#endif with vfs_io_uring %endif ### GLUSTER -%if %{with_vfs_glusterfs} +%if %{with vfs_glusterfs} %package vfs-glusterfs Summary: Samba VFS module for GlusterFS Requires: glusterfs-api >= 3.4.0.16 Requires: glusterfs >= 3.4.0.16 Requires: %{name} = %{samba_depver} -Requires: %{name}-common-libs = %{samba_depver} +Requires: %{name}-ndr-libs = %{samba_depver} Requires: %{name}-client-libs = %{samba_depver} Requires: %{name}-libs = %{samba_depver} -%if %with_libwbclient +Requires: libldb = %{samba_depver} +%if %{with libwbclient} Requires: libwbclient = %{samba_depver} %endif Obsoletes: samba-glusterfs < %{samba_depver} Provides: samba-glusterfs = %{samba_depver} +Provides: bundled(libreplace) = %{samba_depver} + %description vfs-glusterfs Samba VFS module for GlusterFS integration. %endif +### GPUPDATE +%package gpupdate +Summary: Samba GPO support for clients +Requires: cepces-certmonger +Requires: certmonger +Requires: %{name}-ldb-ldap-modules = %{samba_depver} +Requires: python3-%{name} = %{samba_depver} +# samba-tool needs python3-samba-dc also on non-dc build +Requires: python3-%{name}-dc = %{samba_depver} +BuildArch: noarch + +%description gpupdate +This package provides the samba-gpupdate tool to apply Group Policy Objects +(GPO) on Samba clients. + ### KRB5-PRINTING %package krb5-printing Summary: Samba CUPS backend for printing with Kerberos @@ -504,31 +819,68 @@ If you need Kerberos for print jobs to a printer connection to cups via the SMB backend, then you need to install that package. It will allow cups to access the Kerberos credentials cache of the user issuing the print job. +### LDB-LDAP-MODULES +%package ldb-ldap-modules +Summary: Samba ldap modules for ldb +Requires: %{name}-client-libs = %{samba_depver} +Requires: %{name}-ndr-libs = %{samba_depver} +Requires: libldb = %{samba_depver} +Requires: libwbclient = %{samba_depver} + +%description ldb-ldap-modules +This package contains the ldb ldap modules required by samba-tool and +samba-gpupdate. + ### LIBS %package libs Summary: Samba libraries -Requires: %{name}-common-libs = %{samba_depver} +Requires: %{name}-ndr-libs = %{samba_depver} Requires: %{name}-client-libs = %{samba_depver} -%if %with_libwbclient +Requires: libldb = %{samba_depver} +%if %{with libwbclient} Requires: libwbclient = %{samba_depver} %endif Provides: samba4-libs = %{samba_depver} Obsoletes: samba4-libs < %{samba_depver} +Provides: bundled(libreplace) = %{samba_depver} + %description libs The %{name}-libs package contains the libraries needed by programs that link against the SMB, RPC and other protocols provided by the Samba suite. +### LIBNETAPI +%package -n libnetapi +Summary: The NETAPI library +Requires(pre): %{name}-common = %{samba_depver} +Requires: %{name}-common = %{samba_depver} +Requires: %{name}-ndr-libs = %{samba_depver} +Requires: %{name}-client-libs = %{samba_depver} +Requires: libldb = %{samba_depver} +Requires: libwbclient = %{samba_depver} + +%description -n libnetapi +This contains the NETAPI library from the Samba suite. + +%package -n libnetapi-devel +Summary: Developer tools for the NETAPI library +Requires: libnetapi = %{samba_depver} + +%description -n libnetapi-devel +The libnetapi-devel package contains the header files and libraries needed to +develop programs that link against the NETAPI library in the Samba suite. + ### LIBSMBCLIENT -%if %with_libsmbclient +%if %{with libsmbclient} %package -n libsmbclient Summary: The SMB client library Requires(pre): %{name}-common = %{samba_depver} Requires: %{name}-common = %{samba_depver} -Requires: %{name}-common-libs = %{samba_depver} +Requires: %{name}-ndr-libs = %{samba_depver} Requires: %{name}-client-libs = %{samba_depver} -%if %with_libwbclient +Requires: libldb = %{samba_depver} +%if %{with libwbclient} Requires: libwbclient = %{samba_depver} %endif @@ -543,14 +895,15 @@ Requires: libsmbclient = %{samba_depver} The libsmbclient-devel package contains the header files and libraries needed to develop programs that link against the SMB client library in the Samba suite. -#endif with_libsmbclient +#endif {with libsmbclient} %endif ### LIBWBCLIENT -%if %with_libwbclient +%if %{with libwbclient} %package -n libwbclient Summary: The winbind client library -Requires: %{name}-client-libs = %{samba_depver} +# libwbclient.so only links to libc - no samba library dependencies needed +Conflicts: sssd-libwbclient %description -n libwbclient The libwbclient package contains the winbind client library from the Samba @@ -559,6 +912,7 @@ suite. %package -n libwbclient-devel Summary: Developer tools for the winbind library Requires: libwbclient = %{samba_depver} +Conflicts: sssd-libwbclient-devel Provides: samba-winbind-devel = %{samba_depver} Obsoletes: samba-winbind-devel < %{samba_depver} @@ -566,39 +920,37 @@ Obsoletes: samba-winbind-devel < %{samba_depver} %description -n libwbclient-devel The libwbclient-devel package provides developer tools for the wbclient library. -#endif with_libwbclient +#endif {with libwbclient} %endif ### PYTHON3 %package -n python3-%{name} Summary: Samba Python3 libraries -Requires: %{name} = %{samba_depver} Requires: %{name}-client-libs = %{samba_depver} -Requires: %{name}-common-libs = %{samba_depver} +Requires: %{name}-ndr-libs = %{samba_depver} Requires: %{name}-libs = %{samba_depver} -Requires: python3-talloc -Requires: python3-tevent -Requires: python3-tdb -Requires: python3-ldb +Requires: %{name}-dc-libs = %{samba_depver} +Requires: python3-cryptography Requires: python3-dns -%if %with_libsmbclient +Requires: python3-ldb +Requires: python3-requests +Requires: python3-talloc +Requires: python3-tdb +Requires: python3-tevent +Requires: libldb = %{samba_depver} +%if %{with libsmbclient} Requires: libsmbclient = %{samba_depver} %endif -%if %with_libwbclient +%if %{with libwbclient} Requires: libwbclient = %{samba_depver} %endif +Provides: bundled(libreplace) = %{samba_depver} + %description -n python3-%{name} The python3-%{name} package contains the Python 3 libraries needed by programs that use SMB, RPC and other Samba provided protocols in Python 3 programs. -%package -n python3-%{name}-devel -Summary: Samba python devel files -Requires: python3-%{name} = %{samba_depver} - -%description -n python3-%{name}-devel -The python3-%{name}-devel package contains the Python 3 defel files. - %package -n python3-samba-test Summary: Samba Python libraries Requires: python3-%{name} = %{samba_depver} @@ -609,15 +961,19 @@ Requires: %{name}-libs = %{samba_depver} The python3-%{name}-test package contains the Python libraries used by the test suite of Samba. If you want to run full set of Samba tests, you need to install this package. -%if %{with_dc} %package -n python3-samba-dc Summary: Samba Python libraries for Samba AD +Requires: %{name}-client-libs = %{samba_depver} +Requires: %{name}-dc-libs = %{samba_depver} Requires: python3-%{name} = %{samba_depver} +# for ms_forest_updates_markdown.py and ms_schema_markdown.py +Requires: python3-markdown +Requires: libldb = %{samba_depver} +Requires: libwbclient = %{samba_depver} %description -n python3-samba-dc The python3-%{name}-dc package contains the Python libraries needed by programs to manage Samba AD. -%endif ### PIDL %package pidl @@ -625,7 +981,6 @@ Summary: Perl IDL compiler Requires: perl-interpreter Requires: perl(FindBin) Requires: perl(Parse::Yapp) -Requires: perl(:MODULE_COMPAT_%(eval "`%{__perl} -V:version`"; echo $version)) BuildArch: noarch Provides: samba4-pidl = %{samba_depver} @@ -642,18 +997,20 @@ Requires: %{name} = %{samba_depver} Requires: %{name}-common = %{samba_depver} Requires: %{name}-winbind = %{samba_depver} -Requires: %{name}-common-libs = %{samba_depver} +Requires: %{name}-ndr-libs = %{samba_depver} Requires: %{name}-client-libs = %{samba_depver} Requires: %{name}-libs = %{samba_depver} Requires: %{name}-test-libs = %{samba_depver} -%if %with_dc +%if %{with dc} || %{with testsuite} Requires: %{name}-dc-libs = %{samba_depver} %endif Requires: %{name}-libs = %{samba_depver} -%if %with_libsmbclient +Requires: libldb = %{samba_depver} +Requires: libnetapi = %{samba_depver} +%if %{with libsmbclient} Requires: libsmbclient = %{samba_depver} %endif -%if %with_libwbclient +%if %{with libwbclient} Requires: libwbclient = %{samba_depver} %endif Requires: python3-%{name} = %{samba_depver} @@ -662,6 +1019,8 @@ Requires: perl(Archive::Tar) Provides: samba4-test = %{samba_depver} Obsoletes: samba4-test < %{samba_depver} +Provides: bundled(libreplace) = %{samba_depver} + %description test %{name}-test provides testing tools for both the server and client packages of Samba. @@ -669,30 +1028,55 @@ packages of Samba. ### TEST-LIBS %package test-libs Summary: Libraries need by the testing tools for Samba servers and clients -Requires: %{name}-common-libs = %{samba_depver} +Requires: %{name}-ndr-libs = %{samba_depver} Requires: %{name}-client-libs = %{samba_depver} Requires: %{name}-libs = %{samba_depver} -%if %with_libwbclient +Requires: libldb = %{samba_depver} +%if %{with libwbclient} Requires: libwbclient = %{samba_depver} %endif Provides: %{name}-test-devel = %{samba_depver} Obsoletes: %{name}-test-devel < %{samba_depver} +Provides: bundled(libreplace) = %{samba_depver} + %description test-libs %{name}-test-libs provides libraries required by the testing tools. +### USERSHARES +%package usershares +Summary: Provides support for non-root user shares +Requires: %{name} = %{samba_depver} +Requires: %{name}-common-tools = %{samba_depver} +BuildArch: noarch + +%description usershares +Installing this package will provide a configuration file, group and +directories to support non-root user shares. You can configure them +as a user using the `net usershare` command. + ### WINBIND %package winbind Summary: Samba winbind Requires(pre): %{name}-common = %{samba_depver} Requires: %{name}-common = %{samba_depver} -Requires: %{name}-common-libs = %{samba_depver} +Requires: %{name}-ndr-libs = %{samba_depver} +Requires(post): %{name}-ndr-libs = %{samba_depver} Requires: %{name}-common-tools = %{samba_depver} Requires: %{name}-client-libs = %{samba_depver} +Requires(post): %{name}-client-libs = %{samba_depver} Requires: %{name}-libs = %{samba_depver} +Requires(post): %{name}-libs = %{samba_depver} Requires: %{name}-winbind-modules = %{samba_depver} +Suggests: %{name}-tools = %{samba_depver} +Requires: libldb = %{samba_depver} + +%if %{with libwbclient} +Requires(post): libwbclient = %{samba_depver} Requires: libwbclient = %{samba_depver} +%endif +Requires: %{name}-dcerpc = %{samba_depver} Provides: samba4-winbind = %{samba_depver} Obsoletes: samba4-winbind < %{samba_depver} @@ -700,6 +1084,8 @@ Obsoletes: samba4-winbind < %{samba_depver} # Old NetworkManager expects the dispatcher scripts in a different place Conflicts: NetworkManager < 1.20 +Provides: bundled(libreplace) = %{samba_depver} + %description winbind The samba-winbind package provides the winbind NSS library, and some client tools. Winbind enables Linux to be a full member in Windows domains and to use @@ -709,17 +1095,20 @@ Windows user and group accounts on Linux. %package winbind-clients Summary: Samba winbind clients Requires: %{name}-common = %{samba_depver} -Requires: %{name}-common-libs = %{samba_depver} +Requires: %{name}-ndr-libs = %{samba_depver} Requires: %{name}-client-libs = %{samba_depver} Requires: %{name}-libs = %{samba_depver} Requires: %{name}-winbind = %{samba_depver} -%if %with_libwbclient +Requires: libldb = %{samba_depver} +%if %{with libwbclient} Requires: libwbclient = %{samba_depver} %endif Provides: samba4-winbind-clients = %{samba_depver} Obsoletes: samba4-winbind-clients < %{samba_depver} +Provides: bundled(libreplace) = %{samba_depver} + %description winbind-clients The samba-winbind-clients package provides the wbinfo and ntlm_auth tool. @@ -727,13 +1116,14 @@ tool. ### WINBIND-KRB5-LOCATOR %package winbind-krb5-locator Summary: Samba winbind krb5 locator -%if %with_libwbclient +%if %{with libwbclient} Requires: libwbclient = %{samba_depver} Requires: %{name}-winbind = %{samba_depver} %else Requires: %{name}-libs = %{samba_depver} %endif Requires: samba-client-libs = %{samba_depver} +Requires: libldb = %{samba_depver} Provides: samba4-winbind-krb5-locator = %{samba_depver} Obsoletes: samba4-winbind-krb5-locator < %{samba_depver} @@ -747,6 +1137,8 @@ Requires(post): %{_sbindir}/update-alternatives Requires(postun): %{_sbindir}/update-alternatives Requires(preun): %{_sbindir}/update-alternatives +Provides: bundled(libreplace) = %{samba_depver} + %description winbind-krb5-locator The winbind krb5 locator is a plugin for the system kerberos library to allow the local kerberos library to use the same KDC as samba and winbind use @@ -756,11 +1148,13 @@ the local kerberos library to use the same KDC as samba and winbind use Summary: Samba winbind modules Requires: %{name}-client-libs = %{samba_depver} Requires: %{name}-libs = %{samba_depver} -%if %with_libwbclient +%if %{with libwbclient} Requires: libwbclient = %{samba_depver} %endif Requires: pam +Provides: bundled(libreplace) = %{samba_depver} + %description winbind-modules The samba-winbind-modules package provides the NSS library and a PAM module necessary to communicate to the Winbind Daemon @@ -769,19 +1163,26 @@ necessary to communicate to the Winbind Daemon %if %{with winexe} %package winexe Summary: Samba Winexe Windows Binary -License: GPLv3 +License: GPL-3.0-only +Requires: %{name}-client-libs = %{samba_depver} +Requires: %{name}-ndr-libs = %{samba_depver} +Requires: libldb = %{samba_depver} +Requires: libwbclient = %{samba_depver} + +Provides: bundled(libreplace) = %{samba_depver} %description winexe -Winexe is a Remote Windows®-command executor +Winexe is a Remote Windows-command executor %endif ### CTDB -%if %with_clustering_support +%if %{with clustering} %package -n ctdb Summary: A Clustered Database based on Samba's Trivial Database (TDB) -Requires: %{name}-common-libs = %{samba_depver} +Requires: %{name}-ndr-libs = %{samba_depver} Requires: %{name}-client-libs = %{samba_depver} +Requires: %{name}-winbind-clients = %{samba_depver} Requires: coreutils # for ps and killall @@ -804,79 +1205,228 @@ Requires(post): systemd-units Requires(preun): systemd-units Requires(postun): systemd-units +Provides: bundled(libreplace) = %{samba_depver} + %description -n ctdb CTDB is a cluster implementation of the TDB database used by Samba and other projects to store temporary data. If an application is already using TDB for temporary data it is very easy to convert that application to be cluster aware and use CTDB instead. -### CTDB-TEST -%package -n ctdb-tests -Summary: CTDB clustered database test suite +%if %{with pcp_pmda} -Requires: %{name}-common-libs = %{samba_depver} +%package -n ctdb-pcp-pmda +Summary: CTDB PCP pmda support +Requires: ctdb = %{samba_depver} +Requires: pcp-libs Requires: %{name}-client-libs = %{samba_depver} -Requires: ctdb = %{samba_depver} -Recommends: nc +%description -n ctdb-pcp-pmda +Performance Co-Pilot (PCP) support for CTDB -Provides: ctdb-devel = %{samba_depver} -Obsoletes: ctdb-devel < %{samba_depver} - -%description -n ctdb-tests -Test suite for CTDB. -CTDB is a cluster implementation of the TDB database used by Samba and other -projects to store temporary data. If an application is already using TDB for -temporary data it is very easy to convert that application to be cluster aware -and use CTDB instead. -#endif with_clustering_support +#endif with pcp_pmda %endif +%if %{with etcd_mutex} +%package -n ctdb-etcd-mutex +Summary: CTDB ETCD mutex helper +Requires: ctdb = %{samba_depver} +Requires: python3-etcd +BuildArch: noarch + +%description -n ctdb-etcd-mutex +Support for using an existing ETCD cluster as a mutex helper for CTDB + +#endif with etcd_mutex +%endif + +%if %{with ceph_mutex} + +%package -n ctdb-ceph-mutex +Summary: CTDB ceph mutex helper +Requires: ctdb = %{samba_depver} + +%description -n ctdb-ceph-mutex +Support for using an existing CEPH cluster as a mutex helper for CTDB + +#endif with ceph_mutex +%endif + +#endif with clustering +%endif + +%if %{with prometheus} + +%package prometheus +Summary: SMB Prometheus exporter +Requires: samba = %{samba_depver} + +%description prometheus +Support for exporting metrics via Prometheus + +#endif with prometheus +%endif + +### LIBLDB +%package -n libldb +Summary: A schema-less, ldap like, API and database +License: LGPL-3.0-or-later +%if %{without includelibs} +Requires: libtalloc%{?_isa} >= %{talloc_version} +Requires: libtdb%{?_isa} >= %{tdb_version} +Requires: libtevent%{?_isa} >= %{tevent_version} +# /endif without includelibs +%endif + +Obsoletes: libldb < 0:2.10 +Provides: libldb = 0:2.10 +Provides: libldb = %{samba_depver} + +%description -n libldb +An extensible library that implements an LDAP like API to access remote LDAP +servers, or use local tdb databases. + +### LIBLDB-DEVEL +%package -n libldb-devel +Summary: Developer tools for the LDB library +License: LGPL-3.0-or-later +Requires: libldb%{?_isa} = %{samba_depver} +%if %{without includelibs} +Requires: libtdb-devel%{?_isa} >= %{tdb_version} +Requires: libtalloc-devel%{?_isa} >= %{talloc_version} +Requires: libtevent-devel%{?_isa} >= %{tevent_version} +# /endif without includelibs +%endif + +Obsoletes: libldb-devel < 0:2.10 +Provides: libldb-devel = 0:2.10 +Provides: libldb-devel = %{samba_depver} + +%description -n libldb-devel +Header files needed to develop programs that link against the LDB library. + +### LDB-TOOLS +%package -n ldb-tools +Summary: Tools to manage LDB files +License: LGPL-3.0-or-later +Requires: libldb%{?_isa} = %{samba_depver} +Obsoletes: ldb-tools < 0:2.10 +Provides: ldb-tools = %{samba_depver} + +%description -n ldb-tools +Tools to manage LDB files + +### PYTHON3-LDB +%package -n python3-ldb +Summary: Python bindings for the LDB library +License: LGPL-3.0-or-later +Requires: libldb%{?_isa} = %{samba_depver} +%if %{without includelibs} +Requires: python3-tdb%{?_isa} >= %{tdb_version} +# /endif without includelibs +%endif +Requires: samba-client-libs = %{samba_depver} +%{?python_provide:%python_provide python3-ldb} + +Obsoletes: python3-ldb < 0:2.10 +Provides: python3-ldb = %{samba_depver} +# These were the C bindings, only used by Samba +Obsoletes: python-ldb-devel-common < 2.10 +Provides: python-ldb-devel-common = 2.10 +Provides: python-ldb-devel-common = %{samba_depver} +Obsoletes: python3-ldb-devel < 2.10 +Provides: python3-ldb-devel = 2.10 +Provides: python3-ldb-devel = %{samba_depver} + +%description -n python3-ldb +Python bindings for the LDB library %prep +%if 0%{?fedora} || 0%{?rhel} >= 9 +xzcat %{SOURCE0} | %{gpgverify} --keyring='%{SOURCE2}' --signature='%{SOURCE1}' --data=- +%else xzcat %{SOURCE0} | gpgv2 --quiet --keyring %{SOURCE2} %{SOURCE1} - +%endif %autosetup -n samba-%{version}%{pre_release} -p1 +# Make sure we do not build with heimdal code +rm -rfv third_party/heimdal + +%if %{with testsuite} +# WARNING: Don't change that for production! +# +# Shorten the priviliged dir, as unix sockets only have 108 chars +sed -i 's/#define WINBINDD_PRIV_SOCKET_SUBDIR.*/#define WINBINDD_PRIV_SOCKET_SUBDIR "wb_priv"/' nsswitch/winbind_struct_protocol.h +%endif + %build +%if %{with includelibs} %global _talloc_lib ,talloc,pytalloc,pytalloc-util %global _tevent_lib ,tevent,pytevent %global _tdb_lib ,tdb,pytdb -%global _ldb_lib ,ldb,pyldb,pyldb-util - +%else %global _talloc_lib ,!talloc,!pytalloc,!pytalloc-util %global _tevent_lib ,!tevent,!pytevent %global _tdb_lib ,!tdb,!pytdb -%global _ldb_lib ,!ldb,!pyldb,!pyldb-util +#endif with includelibs +%endif -%global _samba_libraries !zlib,!popt%{_talloc_lib}%{_tevent_lib}%{_tdb_lib}%{_ldb_lib} +%global _samba_bundled_libraries !popt%{_talloc_lib}%{_tevent_lib}%{_tdb_lib} %global _samba_idmap_modules idmap_ad,idmap_rid,idmap_ldap,idmap_hash,idmap_tdb2 %global _samba_pdb_modules pdb_tdbsam,pdb_ldap,pdb_smbpasswd,pdb_wbc_sam,pdb_samba4 + +%if %{with testsuite} +%global _samba_auth_modules auth_wbc,auth_unix,auth_server,auth_samba4,auth_skel +%global _samba_vfs_modules vfs_dfs_samba4,vfs_fake_dfq +%else %global _samba_auth_modules auth_wbc,auth_unix,auth_server,auth_samba4 %global _samba_vfs_modules vfs_dfs_samba4 +%endif %global _samba_modules %{_samba_idmap_modules},%{_samba_pdb_modules},%{_samba_auth_modules},%{_samba_vfs_modules} %global _libsmbclient %nil %global _libwbclient %nil -%if ! %with_libsmbclient +%if %{without libsmbclient} %global _libsmbclient smbclient, %endif -%if ! %with_libwbclient +%if %{without libwbclient} %global _libwbclient wbclient, %endif -%global _samba_private_libraries %{_libsmbclient}%{_libwbclient} +%global _default_private_libraries !ldb,!dcerpc-samr,!samba-policy,!tevent-util,!dcerpc,!samba-hostconfig,!samba-credentials,!dcerpc_server,!samdb, +%global _samba_private_libraries %{_default_private_libraries}%{_libsmbclient}%{_libwbclient} # TODO: resolve underlinked python modules export python_LDFLAGS="$(echo %{__global_ldflags} | sed -e 's/-Wl,-z,defs//g')" -# Use the gold linker -export LDFLAGS="%{__global_ldflags} -fuse-ld=gold" +# Use the mold linker if possible +export python_LDFLAGS="$(echo %{__global_ldflags} | sed -e 's/-Wl,-z,defs//g')" +%ifnarch i686 riscv64 +%if 0%{?fedora} >= 37 +export LDFLAGS="%{__global_ldflags} -fuse-ld=mold" +export python_LDFLAGS="$(echo ${LDFLAGS} | sed -e 's/-Wl,-z,defs//g')" +#endif fedora >= 37 +%endif +#endif narch i686 +%endif + +# Add support for mock ccache plugin +%if %{with ccache} +CCACHE="$(command -v ccache)" +if [ -n "${CCACHE}" ]; then + ${CCACHE} -s + export CC="${CCACHE} gcc" +fi +%endif + +# workaround https://gitlab.com/ita1024/waf/-/issues/2472 +export PYTHONARCHDIR=%{python3_sitearch} %configure \ --enable-fhs \ --with-piddir=/run \ @@ -888,40 +1438,56 @@ export LDFLAGS="%{__global_ldflags} -fuse-ld=gold" --with-cachedir=/var/lib/samba \ --disable-rpath-install \ --with-shared-modules=%{_samba_modules} \ - --bundled-libraries=%{_samba_libraries} \ + --bundled-libraries=%{_samba_bundled_libraries} \ + --private-libraries=%{_samba_private_libraries} \ --with-pam \ --with-pie \ --with-relro \ --without-fam \ -%if (! %with_libsmbclient) || (! %with_libwbclient) - --private-libraries=%{_samba_private_libraries} \ -%endif --with-system-mitkrb5 \ --with-experimental-mit-ad-dc \ -%if ! %with_dc +%if %{without dc} && %{without testsuite} --without-ad-dc \ %endif -%if ! %with_vfs_glusterfs +%if %{without vfs_glusterfs} --disable-glusterfs \ %endif -%if %with_clustering_support +%if %{with clustering} --with-cluster-support \ %endif -%if %with_profiling - --with-profiling-data \ -%endif %if %{with testsuite} --enable-selftest \ %endif +%if %{with pcp_pmda} + --enable-pmda \ +%endif +%if %{with ceph_mutex} + --enable-ceph-reclock \ +%endif +%if %{with etcd_mutex} + --enable-etcd-reclock \ +%endif +%if %{with prometheus} + --with-prometheus-exporter \ +%endif +%if %{with varlink} + --with-systemd-userdb \ +%endif + --with-profiling-data \ --with-systemd \ + --with-quotas \ --systemd-install-services \ --with-systemddir=/usr/lib/systemd/system \ --systemd-smb-extra=%{_systemd_extra} \ --systemd-nmb-extra=%{_systemd_extra} \ --systemd-winbind-extra=%{_systemd_extra} \ +%if %{with clustering} + --systemd-ctdb-extra=%{_systemd_extra} \ +%endif --systemd-samba-extra=%{_systemd_extra} -%make_build +# Do not use %%make_build, make is just a wrapper around waf in Samba! +%{__make} %{?_smp_mflags} %{_make_verbose} pushd pidl %__perl Makefile.PL PREFIX=%{_prefix} @@ -929,37 +1495,35 @@ pushd pidl %make_build popd +pushd lib/ldb +doxygen Doxyfile +popd + %install -%make_install +%if !%{with testsuite} +# Do not use %%make_install, make is just a wrapper around waf in Samba! +%{__make} %{?_smp_mflags} %{_make_verbose} install DESTDIR=%{buildroot} install -d -m 0755 %{buildroot}/usr/{sbin,bin} install -d -m 0755 %{buildroot}%{_libdir}/security install -d -m 0755 %{buildroot}/var/lib/samba +install -d -m 0755 %{buildroot}/var/lib/samba/certs install -d -m 0755 %{buildroot}/var/lib/samba/drivers install -d -m 0755 %{buildroot}/var/lib/samba/lock install -d -m 0755 %{buildroot}/var/lib/samba/private +install -d -m 0755 %{buildroot}/var/lib/samba/private/certs install -d -m 0755 %{buildroot}/var/lib/samba/scripts install -d -m 0755 %{buildroot}/var/lib/samba/sysvol +install -d -m 0755 %{buildroot}/var/lib/samba/usershares install -d -m 0755 %{buildroot}/var/lib/samba/winbindd_privileged install -d -m 0755 %{buildroot}/var/log/samba/old -install -d -m 0755 %{buildroot}/var/spool/samba +install -d -m 0755 %{buildroot}/run/ctdb install -d -m 0755 %{buildroot}/run/samba install -d -m 0755 %{buildroot}/run/winbindd install -d -m 0755 %{buildroot}/%{_libdir}/samba install -d -m 0755 %{buildroot}/%{_libdir}/samba/ldb install -d -m 0755 %{buildroot}/%{_libdir}/pkgconfig -# Move libwbclient.so* into private directory, it cannot be just libdir/samba -# because samba uses rpath with this directory. -install -d -m 0755 %{buildroot}/%{_libdir}/samba/wbclient -mv %{buildroot}/%{_libdir}/libwbclient.so* %{buildroot}/%{_libdir}/samba/wbclient -if [ ! -f %{buildroot}/%{_libdir}/samba/wbclient/libwbclient.so.%{libwbc_alternatives_version} ] -then - echo "Expected libwbclient version not found, please check if version has changed." - exit -1 -fi - - touch %{buildroot}%{_libexecdir}/samba/cups_backend_smb # Install other stuff @@ -968,6 +1532,7 @@ install -m 0644 %{SOURCE10} %{buildroot}%{_sysconfdir}/logrotate.d/samba install -m 0644 %{SOURCE11} %{buildroot}%{_sysconfdir}/samba/smb.conf install -m 0644 %{SOURCE12} %{buildroot}%{_sysconfdir}/samba/smb.conf.example +install -m 0644 %{SOURCE15} %{buildroot}%{_sysconfdir}/samba/usershares.conf install -d -m 0755 %{buildroot}%{_sysconfdir}/security install -m 0644 %{SOURCE13} %{buildroot}%{_sysconfdir}/security/pam_winbind.conf @@ -986,13 +1551,18 @@ install -m 0744 packaging/printing/smbprint %{buildroot}%{_bindir}/smbprint install -d -m 0755 %{buildroot}%{_tmpfilesdir} # Create /run/samba. echo "d /run/samba 755 root root" > %{buildroot}%{_tmpfilesdir}/samba.conf -%if %with_clustering_support +%if %{with clustering} echo "d /run/ctdb 755 root root" > %{buildroot}%{_tmpfilesdir}/ctdb.conf %endif +install -d -m 0755 %{buildroot}%{_sysusersdir} +install -m 0644 %{SOURCE16} %{buildroot}%{_sysusersdir}/samba.conf +install -m 0644 %{SOURCE17} %{buildroot}%{_sysusersdir}/samba-usershares.conf +install -m 0644 %{SOURCE18} %{buildroot}%{_sysusersdir}/samba-winbind.conf + install -d -m 0755 %{buildroot}%{_sysconfdir}/sysconfig install -m 0644 packaging/systemd/samba.sysconfig %{buildroot}%{_sysconfdir}/sysconfig/samba -%if %with_clustering_support +%if %{with clustering} cat > %{buildroot}%{_sysconfdir}/sysconfig/ctdb < selftest/knownfail.d/fedora%{dist} << EOF +^samba3.smb2.timestamps.time_t_15032385535 +^samba3.smb2.timestamps.time_t_10000000000 +^samba3.smb2.timestamps.time_t_4294967295 +EOF +fi + +echo +echo "Content of selftest/knownfail.d/fedora%{dist}:" +cat selftest/knownfail.d/fedora%{dist} || true + +cat >> selftest/skip << EOF +# FIXME: Investigate why it fails. Might be CUPS is not running? +^samba3.rpc.spoolss.printserver +EOF + +echo +echo "Content of selftest/skip:" +cat selftest/skip + +export TDB_NO_FSYNC=1 +export NMBD_DONT_LOG_STDOUT=1 +export SMBD_DONT_LOG_STDOUT=1 +export WINBINDD_DONT_LOG_STDOUT=1 +export SAMBA_DCERPCD_DONT_LOG_STDOUT=1 +%if "x%{?SAMBA_TESTS}" != "x" +%{__make} %{?_smp_mflags} test FAIL_IMMEDIATELY=1 TESTS="%{SAMBA_TESTS}" +%else +%{__make} %{?_smp_mflags} test FAIL_IMMEDIATELY=1 +%endif #endif with testsuite %endif +%if !%{with testsuite} %post +%systemd_post samba-bgqd.service %systemd_post smb.service %systemd_post nmb.service %preun +%systemd_preun samba-bgqd.service %systemd_preun smb.service %systemd_preun nmb.service %postun +%systemd_postun_with_restart samba-bgqd.service %systemd_postun_with_restart smb.service %systemd_postun_with_restart nmb.service %pre common -getent group printadmin >/dev/null || groupadd -r printadmin || : +# This creates the group 'printadmin' +%sysusers_create_compat %{SOURCE16} %post common %{?ldconfig} @@ -1148,9 +1727,9 @@ fi %ldconfig_scriptlets client-libs -%ldconfig_scriptlets common-libs +%ldconfig_scriptlets ndr-libs -%if %{with_dc} +%if %{with dc} %ldconfig_scriptlets dc-libs %post dc @@ -1161,79 +1740,45 @@ fi %postun dc %systemd_postun_with_restart samba.service -#endif with_dc +#endif with dc %endif %post krb5-printing %{_sbindir}/update-alternatives --install %{_libexecdir}/samba/cups_backend_smb \ - cups_backend_smb \ - %{_libexecdir}/samba/smbspool_krb5_wrapper 50 + cups_backend_smb \ + %{_libexecdir}/samba/smbspool_krb5_wrapper 50 %postun krb5-printing if [ $1 -eq 0 ] ; then - %{_sbindir}/update-alternatives --remove cups_backend_smb %{_libexecdir}/samba/smbspool_krb5_wrapper + %{_sbindir}/update-alternatives --remove cups_backend_smb %{_libexecdir}/samba/smbspool_krb5_wrapper fi %ldconfig_scriptlets libs -%if %with_libsmbclient +%if %{with libsmbclient} %ldconfig_scriptlets -n libsmbclient %endif -%if %with_libwbclient -%posttrans -n libwbclient -# It has to be posttrans here to make sure all files of a previous version -# without alternatives support are removed -%{_sbindir}/update-alternatives \ - --install \ - %{_libdir}/libwbclient.so.%{libwbc_alternatives_version} \ - libwbclient.so.%{libwbc_alternatives_version}%{libwbc_alternatives_suffix} \ - %{_libdir}/samba/wbclient/libwbclient.so.%{libwbc_alternatives_version} \ - 10 +%if %{with libwbclient} +%pre -n libwbclient +if [ $1 -gt 1 ] ; then + rm -rf %{_libdir}/samba/wbclient/ 2>/dev/null + rm -f /etc/alternatives/libwbclient.so* 2>/dev/null + rm -f /var/lib/alternatives/libwbclient.so* 2>/dev/null +fi %{?ldconfig} - -%preun -n libwbclient -if [ $1 -eq 0 ]; then - %{_sbindir}/update-alternatives \ - --remove \ - libwbclient.so.%{libwbc_alternatives_version}%{libwbc_alternatives_suffix} \ - %{_libdir}/samba/wbclient/libwbclient.so.%{libwbc_alternatives_version} -fi -/sbin/ldconfig - -%posttrans -n libwbclient-devel -%{_sbindir}/update-alternatives \ - --install %{_libdir}/libwbclient.so \ - libwbclient.so%{libwbc_alternatives_suffix} \ - %{_libdir}/samba/wbclient/libwbclient.so \ - 10 - -%preun -n libwbclient-devel -# alternatives checks if the file which should be removed is a link or not, but -# not if it points to the /etc/alternatives directory or to some other place. -# When downgrading to a version where alternatives is not used and -# libwbclient.so is a link and not a file it will be removed. The following -# check removes the alternatives files manually if that is the case. -if [ $1 -eq 0 ]; then - if [ "`readlink %{_libdir}/libwbclient.so`" == "libwbclient.so.%{libwbc_alternatives_version}" ]; then - /bin/rm -f \ - /etc/alternatives/libwbclient.so%{libwbc_alternatives_suffix} \ - /var/lib/alternatives/libwbclient.so%{libwbc_alternatives_suffix} 2> /dev/null - else - %{_sbindir}/update-alternatives \ - --remove \ - libwbclient.so%{libwbc_alternatives_suffix} \ - %{_libdir}/samba/wbclient/libwbclient.so - fi -fi - -#endif with_libwbclient +#endif {with libwbclient} %endif %ldconfig_scriptlets test +%pre usershares +# This creates the group 'usershares' +%sysusers_create_compat %{SOURCE17} + %pre winbind -/usr/sbin/groupadd -g 88 wbpriv >/dev/null 2>&1 || : +# This creates the group 'wbpriv' +%sysusers_create_compat %{SOURCE18} %post winbind %systemd_post winbind.service @@ -1262,7 +1807,7 @@ fi %ldconfig_scriptlets winbind-modules -%if %with_clustering_support +%if %{with clustering} %post -n ctdb /usr/bin/systemd-tmpfiles --create %{_tmpfilesdir}/ctdb.conf %systemd_post ctdb.service @@ -1274,11 +1819,11 @@ fi %systemd_postun_with_restart ctdb.service %endif +%ldconfig_scriptlets -n libldb +%ldconfig_scriptlets -n python3-ldb ### SAMBA %files -%license COPYING -%doc README.md WHATSNEW.txt %doc examples/autofs examples/LDAP examples/misc %doc examples/printer-accounting examples/printing %doc packaging/README.downgrade @@ -1286,9 +1831,9 @@ fi %{_sbindir}/eventlogadm %{_sbindir}/nmbd %{_sbindir}/smbd -%if %{with_dc} +%if %{with dc} # This is only used by vfs_dfs_samba4 -%{_libdir}/samba/libdfs-server-ad-samba4.so +%{_libdir}/samba/libdfs-server-ad-private-samba.so %endif %dir %{_libdir}/samba/auth %{_libdir}/samba/auth/unix.so @@ -1304,7 +1849,7 @@ fi %{_libdir}/samba/vfs/commit.so %{_libdir}/samba/vfs/crossrename.so %{_libdir}/samba/vfs/default_quota.so -%if %{with_dc} +%if %{with dc} %{_libdir}/samba/vfs/dfs_samba4.so %endif %{_libdir}/samba/vfs/dirsort.so @@ -1316,9 +1861,6 @@ fi %{_libdir}/samba/vfs/full_audit.so %{_libdir}/samba/vfs/gpfs.so %{_libdir}/samba/vfs/glusterfs_fuse.so -%if %{with_vfs_io_uring} -%{_libdir}/samba/vfs/io_uring.so -%endif %{_libdir}/samba/vfs/linux_xfs_sgid.so %{_libdir}/samba/vfs/media_harmony.so %{_libdir}/samba/vfs/offline.so @@ -1340,18 +1882,22 @@ fi %{_libdir}/samba/vfs/worm.so %{_libdir}/samba/vfs/xattr_tdb.so +%dir %{_libexecdir}/samba +%{_libexecdir}/samba/samba-bgqd + %dir %{_datadir}/samba %dir %{_datadir}/samba/mdssvc %{_datadir}/samba/mdssvc/elasticsearch_mappings.json %{_unitdir}/nmb.service %{_unitdir}/smb.service -%attr(1777,root,root) %dir /var/spool/samba +%{_unitdir}/samba-bgqd.service %dir %{_sysconfdir}/openldap/schema %config %{_sysconfdir}/openldap/schema/samba.schema %config(noreplace) %{_sysconfdir}/pam.d/samba %{_mandir}/man1/smbstatus.1* %{_mandir}/man8/eventlogadm.8* +%{_mandir}/man8/samba-bgqd.8* %{_mandir}/man8/smbd.8* %{_mandir}/man8/nmbd.8* %{_mandir}/man8/vfs_acl_tdb.8* @@ -1366,6 +1912,7 @@ fi %{_mandir}/man8/vfs_crossrename.8* %{_mandir}/man8/vfs_default_quota.8* %{_mandir}/man8/vfs_dirsort.8* +%{_mandir}/man8/vfs_expand_msdfs.8* %{_mandir}/man8/vfs_extd_audit.8* %{_mandir}/man8/vfs_fake_perms.8* %{_mandir}/man8/vfs_fileid.8* @@ -1373,9 +1920,6 @@ fi %{_mandir}/man8/vfs_full_audit.8* %{_mandir}/man8/vfs_gpfs.8* %{_mandir}/man8/vfs_glusterfs_fuse.8* -%if %{with_vfs_io_uring} -%{_mandir}/man8/vfs_io_uring.8* -%endif %{_mandir}/man8/vfs_linux_xfs_sgid.8* %{_mandir}/man8/vfs_media_harmony.8* %{_mandir}/man8/vfs_offline.8* @@ -1405,9 +1949,8 @@ fi %{_bindir}/cifsdd %{_bindir}/dbwrap_tool %{_bindir}/dumpmscat -%{_bindir}/findsmb %{_bindir}/mvxattr -%{_bindir}/mdfind +%{_bindir}/mdsearch %{_bindir}/nmblookup %{_bindir}/oLschema2ldif %{_bindir}/regdiff @@ -1425,6 +1968,7 @@ fi %{_bindir}/smbspool %{_bindir}/smbtar %{_bindir}/smbtree +%{_bindir}/wspsearch %dir %{_libexecdir}/samba %ghost %{_libexecdir}/samba/cups_backend_smb %{_mandir}/man1/dbwrap_tool.1* @@ -1434,9 +1978,8 @@ fi %{_mandir}/man1/regpatch.1* %{_mandir}/man1/regshell.1* %{_mandir}/man1/regtree.1* -%{_mandir}/man1/findsmb.1* %{_mandir}/man1/log2pcap.1* -%{_mandir}/man1/mdfind.1* +%{_mandir}/man1/mdsearch.1* %{_mandir}/man1/mvxattr.1* %{_mandir}/man1/rpcclient.1* %{_mandir}/man1/sharesec.1* @@ -1444,132 +1987,227 @@ fi %{_mandir}/man1/smbclient.1* %{_mandir}/man1/smbcquotas.1* %{_mandir}/man1/smbget.1* -%{_mandir}/man5/smbgetrc.5* %{_mandir}/man1/smbtar.1* %{_mandir}/man1/smbtree.1* +%{_mandir}/man1/wspsearch.1* %{_mandir}/man7/traffic_learner.7.* %{_mandir}/man7/traffic_replay.7.* %{_mandir}/man8/cifsdd.8.* %{_mandir}/man8/samba-regedit.8* %{_mandir}/man8/smbspool.8* -### CLIENT-LIBS -%files client-libs -%{_libdir}/libdcerpc-binding.so.* -%{_libdir}/libndr.so.* -%{_libdir}/libndr-krb5pac.so.* -%{_libdir}/libndr-nbt.so.* -%{_libdir}/libndr-standard.so.* -%{_libdir}/libnetapi.so.* -%{_libdir}/libsamba-credentials.so.* -%{_libdir}/libsamba-errors.so.* -%{_libdir}/libsamba-passdb.so.* -%{_libdir}/libsamba-util.so.* -%{_libdir}/libsamba-hostconfig.so.* -%{_libdir}/libsamdb.so.* -%{_libdir}/libsmbconf.so.* -%{_libdir}/libsmbldap.so.* -%{_libdir}/libtevent-util.so.* -%{_libdir}/libdcerpc.so.* +%if %{with includelibs} +%{_bindir}/ldbadd +%{_bindir}/ldbdel +%{_bindir}/ldbedit +%{_bindir}/ldbmodify +%{_bindir}/ldbrename +%{_bindir}/ldbsearch +%{_bindir}/tdbbackup +%{_bindir}/tdbdump +%{_bindir}/tdbrestore +%{_bindir}/tdbtool -%dir %{_libdir}/samba -%{_libdir}/samba/libCHARSET3-samba4.so -%{_libdir}/samba/libMESSAGING-SEND-samba4.so -%{_libdir}/samba/libMESSAGING-samba4.so -%{_libdir}/samba/libaddns-samba4.so -%{_libdir}/samba/libads-samba4.so -%{_libdir}/samba/libasn1util-samba4.so -%{_libdir}/samba/libauth-samba4.so -%{_libdir}/samba/libauthkrb5-samba4.so -%{_libdir}/samba/libcli-cldap-samba4.so -%{_libdir}/samba/libcli-ldap-common-samba4.so -%{_libdir}/samba/libcli-ldap-samba4.so -%{_libdir}/samba/libcli-nbt-samba4.so -%{_libdir}/samba/libcli-smb-common-samba4.so -%{_libdir}/samba/libcli-spoolss-samba4.so -%{_libdir}/samba/libcliauth-samba4.so -%{_libdir}/samba/libclidns-samba4.so -%{_libdir}/samba/libcluster-samba4.so -%{_libdir}/samba/libcmdline-contexts-samba4.so -%{_libdir}/samba/libcmdline-credentials-samba4.so -%{_libdir}/samba/libcommon-auth-samba4.so -%{_libdir}/samba/libctdb-event-client-samba4.so -%{_libdir}/samba/libdbwrap-samba4.so -%{_libdir}/samba/libdcerpc-pkt-auth-samba4.so -%{_libdir}/samba/libdcerpc-samba-samba4.so -%{_libdir}/samba/libevents-samba4.so -%{_libdir}/samba/libflag-mapping-samba4.so -%{_libdir}/samba/libgenrand-samba4.so -%{_libdir}/samba/libgensec-samba4.so -%{_libdir}/samba/libgpext-samba4.so -%{_libdir}/samba/libgpo-samba4.so -%{_libdir}/samba/libgse-samba4.so -%{_libdir}/samba/libhttp-samba4.so -%{_libdir}/samba/libinterfaces-samba4.so -%{_libdir}/samba/libiov-buf-samba4.so -%{_libdir}/samba/libkrb5samba-samba4.so -%{_libdir}/samba/libldbsamba-samba4.so -%{_libdir}/samba/liblibcli-lsa3-samba4.so -%{_libdir}/samba/liblibcli-netlogon3-samba4.so -%{_libdir}/samba/liblibsmb-samba4.so -%{_libdir}/samba/libmessages-dgm-samba4.so -%{_libdir}/samba/libmessages-util-samba4.so -%{_libdir}/samba/libmscat-samba4.so -%{_libdir}/samba/libmsghdr-samba4.so -%{_libdir}/samba/libmsrpc3-samba4.so -%{_libdir}/samba/libndr-samba-samba4.so -%{_libdir}/samba/libndr-samba4.so -%{_libdir}/samba/libnet-keytab-samba4.so -%{_libdir}/samba/libnetif-samba4.so -%{_libdir}/samba/libnpa-tstream-samba4.so -%{_libdir}/samba/libposix-eadb-samba4.so -%{_libdir}/samba/libprinter-driver-samba4.so -%{_libdir}/samba/libprinting-migrate-samba4.so -%{_libdir}/samba/libreplace-samba4.so -%{_libdir}/samba/libregistry-samba4.so -%{_libdir}/samba/libsamba-cluster-support-samba4.so -%{_libdir}/samba/libsamba-debug-samba4.so -%{_libdir}/samba/libsamba-modules-samba4.so -%{_libdir}/samba/libsamba-security-samba4.so -%{_libdir}/samba/libsamba-sockets-samba4.so -%{_libdir}/samba/libsamba3-util-samba4.so -%{_libdir}/samba/libsamdb-common-samba4.so -%{_libdir}/samba/libsecrets3-samba4.so -%{_libdir}/samba/libserver-id-db-samba4.so -%{_libdir}/samba/libserver-role-samba4.so -%{_libdir}/samba/libsmb-transport-samba4.so -%{_libdir}/samba/libsmbclient-raw-samba4.so -%{_libdir}/samba/libsmbd-base-samba4.so -%{_libdir}/samba/libsmbd-shim-samba4.so -%{_libdir}/samba/libsmbldaphelper-samba4.so -%{_libdir}/samba/libsys-rw-samba4.so -%{_libdir}/samba/libsocket-blocking-samba4.so -%{_libdir}/samba/libtalloc-report-printf-samba4.so -%{_libdir}/samba/libtalloc-report-samba4.so -%{_libdir}/samba/libtdb-wrap-samba4.so -%{_libdir}/samba/libtime-basic-samba4.so -%{_libdir}/samba/libtorture-samba4.so -%{_libdir}/samba/libtrusts-util-samba4.so -%{_libdir}/samba/libutil-cmdline-samba4.so -%{_libdir}/samba/libutil-reg-samba4.so -%{_libdir}/samba/libutil-setid-samba4.so -%{_libdir}/samba/libutil-tdb-samba4.so - -%if ! %with_libwbclient -%{_libdir}/samba/libwbclient.so.* -%{_libdir}/samba/libwinbind-client-samba4.so -#endif ! with_libwbclient +%{_mandir}/man1/ldbadd.1.gz +%{_mandir}/man1/ldbdel.1.gz +%{_mandir}/man1/ldbedit.1.gz +%{_mandir}/man1/ldbmodify.1.gz +%{_mandir}/man1/ldbrename.1.gz +%{_mandir}/man1/ldbsearch.1.gz +%{_mandir}/man8/tdbbackup.8.gz +%{_mandir}/man8/tdbdump.8.gz +%{_mandir}/man8/tdbrestore.8.gz +%{_mandir}/man8/tdbtool.8.gz +#endif with includelibs %endif -%if ! %with_libsmbclient -%{_libdir}/samba/libsmbclient.so.* +### CORE-LIBS +%files core-libs +%dir %{_libdir}/samba + +# +# Tier 0: Private libraries - libc only dependencies +# +%{_libdir}/samba/libreplace-private-samba.so +%{_libdir}/samba/libsocket-blocking-private-samba.so +%{_libdir}/samba/libsys-rw-private-samba.so +%{_libdir}/samba/libtime-basic-private-samba.so + +# +# Tier 1: Private libraries - system libs (libtalloc, libsystemd) +# +%{_libdir}/samba/libsamba-debug-private-samba.so +%{_libdir}/samba/libserver-role-private-samba.so + +# +# Tier 1: Public libraries - system libs (libtalloc) +# +%{_libdir}/libsamba-errors.so.%{libsamba_errors_so_version}* + +# +# Tier 2: Private libraries - adds gnutls +# +%{_libdir}/samba/libgenrand-private-samba.so + +# +# Tier 2: Public libraries - adds gnutls, icu, tevent +# +%{_libdir}/libsamba-util.so.%{libsamba_util_so_version}* +%{_libdir}/libtevent-util.so.%{libtevent_util_so_version}* + +### NDR-LIBS +%files ndr-libs + +# +# Core NDR library +# +%{_libdir}/libndr.so.%{libndr_so_version}* + +# +# Tier 0: libc only dependencies +# +%{_libdir}/samba/libutil-setid-private-samba.so +%{_libdir}/samba/libutil-tdb-private-samba.so + +# +# Tier 1: system libs only (libtalloc) +# +%{_libdir}/samba/libiov-buf-private-samba.so +%{_libdir}/samba/libstable-sort-private-samba.so +%{_libdir}/samba/libtalloc-report-private-samba.so +%{_libdir}/samba/libtalloc-report-printf-private-samba.so + +# +# Tier 2: depends on core-libs (debug, replace) +# +%{_libdir}/samba/libflag-mapping-private-samba.so +%{_libdir}/samba/libinterfaces-private-samba.so +%{_libdir}/samba/libtdb-wrap-private-samba.so + +# +# Tier 3: depends on core-libs (util, errors, ndr) +# +%{_libdir}/samba/libdbwrap-private-samba.so +%{_libdir}/samba/libsamba3-util-private-samba.so +%{_libdir}/samba/libutil-reg-private-samba.so + +# +# Tier 4: depends on core-libs + Tier 3 libs +# +%{_libdir}/samba/libsamba-security-private-samba.so + +# +# NDR encoding libraries +# +%{_libdir}/libndr-nbt.so.%{libndr_nbt_so_version}* +%{_libdir}/libndr-standard.so.%{libndr_standard_so_version}* +%{_libdir}/libndr-krb5pac.so.%{libndr_krb5pac_so_version}* + +### CLIENT-LIBS +%files client-libs +%{_libdir}/libdcerpc-binding.so.%{libdcerpc_binding_so_version}* +%{_libdir}/libdcerpc-server-core.so.%{libdcerpc_server_core_so_version}* +%{_libdir}/libdcerpc.so.%{libdcerpc_so_version}* +%{_libdir}/libsamba-credentials.so.%{libsamba_credentials_so_version}* +%{_libdir}/libsamba-hostconfig.so.%{libsamba_hostconfig_so_version}* +%{_libdir}/libsamba-passdb.so.%{libsamba_passdb_so_version}* +%{_libdir}/libsamdb.so.%{libsamdb_so_version}* +%{_libdir}/libsmbconf.so.%{libsmbconf_so_version}* +%{_libdir}/libsmbldap.so.%{libsmbldap_so_version}* +%{_libdir}/samba/libCHARSET3-private-samba.so +%{_libdir}/samba/libMESSAGING-SEND-private-samba.so +%{_libdir}/samba/libaddns-private-samba.so +%{_libdir}/samba/libads-private-samba.so +%{_libdir}/samba/libasn1util-private-samba.so +%{_libdir}/samba/libauthkrb5-private-samba.so +%{_libdir}/samba/libcli-cldap-private-samba.so +%{_libdir}/samba/libcli-ldap-common-private-samba.so +%{_libdir}/samba/libcli-ldap-private-samba.so +%{_libdir}/samba/libcli-nbt-private-samba.so +%{_libdir}/samba/libcli-smb-common-private-samba.so +%{_libdir}/samba/libcli-spoolss-private-samba.so +%{_libdir}/samba/libcliauth-private-samba.so +%{_libdir}/samba/libclidns-private-samba.so +%{_libdir}/samba/libcluster-private-samba.so +%{_libdir}/samba/libcmdline-contexts-private-samba.so +%{_libdir}/samba/libcommon-auth-private-samba.so +%{_libdir}/samba/libdcerpc-pkt-auth-private-samba.so +%{_libdir}/samba/libdcerpc-samba-private-samba.so +%{_libdir}/samba/libevents-private-samba.so +%{_libdir}/samba/libgensec-private-samba.so +%{_libdir}/samba/libgse-private-samba.so +%{_libdir}/samba/libhttp-private-samba.so +%{_libdir}/samba/libkrb5samba-private-samba.so +%{_libdir}/samba/libldbsamba-private-samba.so +%{_libdir}/samba/liblibcli-lsa3-private-samba.so +%{_libdir}/samba/liblibcli-netlogon3-private-samba.so +%{_libdir}/samba/liblibsmb-private-samba.so +%{_libdir}/samba/libmessages-dgm-private-samba.so +%{_libdir}/samba/libmessages-util-private-samba.so +%{_libdir}/samba/libmscat-private-samba.so +%{_libdir}/samba/libmsghdr-private-samba.so +%{_libdir}/samba/libmsrpc3-private-samba.so +%{_libdir}/samba/libndr-samba-private-samba.so +%{_libdir}/samba/libndr-samba4-private-samba.so +%{_libdir}/samba/libnetif-private-samba.so +%if 0%{?rhel} +%{_libdir}/samba/libngtcp2-crypto-gnutls-private-samba.so +%{_libdir}/samba/libngtcp2-private-samba.so +%endif +%{_libdir}/samba/libnpa-tstream-private-samba.so +%{_libdir}/samba/libquic-private-samba.so +%{_libdir}/samba/libregistry-private-samba.so +%{_libdir}/samba/libsamba-cluster-support-private-samba.so +%{_libdir}/samba/libsamba-modules-private-samba.so +%{_libdir}/samba/libsamba-security-trusts-private-samba.so +%{_libdir}/samba/libsamba-sockets-private-samba.so +%{_libdir}/samba/libsamdb-common-private-samba.so +%{_libdir}/samba/libsecrets3-private-samba.so +%{_libdir}/samba/libserver-id-db-private-samba.so +%{_libdir}/samba/libsmbclient-raw-private-samba.so +%{_libdir}/samba/libsmbd-shim-private-samba.so + +# +# Command line library +# +%{_libdir}/samba/libcmdline-private-samba.so + +# +# Password database modules (depend on libsamba-passdb) +# +%dir %{_libdir}/samba/ldb +%dir %{_libdir}/samba/pdb +%{_libdir}/samba/pdb/smbpasswd.so +%{_libdir}/samba/pdb/tdbsam.so + +%if %{without libwbclient} +%{_libdir}/samba/libwbclient.so.* +#endif without libwbclient +%endif + +%if %{without libsmbclient} +%{_libdir}/samba/libsmbclient.so.%{libsmbclient_so_version}* %{_mandir}/man7/libsmbclient.7* -#endif ! with_libsmbclient +#endif without libsmbclient +%endif + +%if %{with includelibs} +%{_libdir}/samba/libldb-*.so +%{_libdir}/samba/libtalloc-private-samba.so +%{_libdir}/samba/libtdb-private-samba.so +%{_libdir}/samba/libtevent-private-samba.so + +%{_mandir}/man3/ldb.3.gz +%{_mandir}/man3/talloc.3.gz +#endif with includelibs %endif ### COMMON %files common +%doc README.md WHATSNEW.txt +%license COPYING %{_tmpfilesdir}/samba.conf +%{_sysusersdir}/samba.conf %dir %{_sysconfdir}/logrotate.d/ %config(noreplace) %{_sysconfdir}/logrotate.d/samba %attr(0700,root,root) %dir /var/log/samba @@ -1577,7 +2215,9 @@ fi %ghost %dir /run/samba %ghost %dir /run/winbindd %dir /var/lib/samba +%dir /var/lib/samba/certs %attr(700,root,root) %dir /var/lib/samba/private +%attr(700,root,root) %dir /var/lib/samba/private/certs %dir /var/lib/samba/lock %attr(755,root,root) %dir %{_sysconfdir}/samba %config(noreplace) %{_sysconfdir}/samba/smb.conf @@ -1589,42 +2229,50 @@ fi %{_mandir}/man5/smbpasswd.5* %{_mandir}/man7/samba.7* -### COMMON-libs -%files common-libs -# common libraries -%{_libdir}/samba/libpopt-samba3-cmdline-samba4.so -%{_libdir}/samba/libpopt-samba3-samba4.so - -%dir %{_libdir}/samba/ldb - -%dir %{_libdir}/samba/pdb -%{_libdir}/samba/pdb/ldapsam.so -%{_libdir}/samba/pdb/smbpasswd.so -%{_libdir}/samba/pdb/tdbsam.so - +### COMMON-TOOLS %files common-tools %{_bindir}/net %{_bindir}/pdbedit %{_bindir}/profiles +%{_bindir}/samba-log-parser %{_bindir}/smbcontrol %{_bindir}/smbpasswd %{_bindir}/testparm %{_mandir}/man1/profiles.1* +%{_mandir}/man1/samba-log-parser.1* %{_mandir}/man1/smbcontrol.1* %{_mandir}/man1/testparm.1* %{_mandir}/man8/net.8* %{_mandir}/man8/pdbedit.8* %{_mandir}/man8/smbpasswd.8* +%{_datadir}/locale/*/LC_MESSAGES/net.mo + +### TOOLS +%files tools +%{_bindir}/samba-tool +%{_mandir}/man8/samba-tool.8* + +### RPC +%files dcerpc +%dir %{_libexecdir}/samba +%{_libexecdir}/samba/samba-dcerpcd +%{_libexecdir}/samba/rpcd_classic +%{_libexecdir}/samba/rpcd_epmapper +%{_libexecdir}/samba/rpcd_fsrvp +%{_libexecdir}/samba/rpcd_lsad +%{_libexecdir}/samba/rpcd_mdssvc +%{_libexecdir}/samba/rpcd_spoolss +%{_libexecdir}/samba/rpcd_winreg +%{_libexecdir}/samba/rpcd_witness +%{_mandir}/man8/samba-dcerpcd.8* ### DC -%if %{with_dc} +%if %{with dc} %files dc %{_unitdir}/samba.service -%{_bindir}/samba-tool %{_sbindir}/samba %{_sbindir}/samba_dnsupdate %{_sbindir}/samba_downgrade_db -%{_sbindir}/samba-gpupdate %{_sbindir}/samba_kcc %{_sbindir}/samba_spnupdate %{_sbindir}/samba_upgradedns @@ -1632,7 +2280,6 @@ fi %{_libdir}/krb5/plugins/kdb/samba.so %{_libdir}/samba/auth/samba4.so -%{_libdir}/samba/libpac-samba4.so %dir %{_libdir}/samba/gensec %{_libdir}/samba/gensec/krb5.so %{_libdir}/samba/ldb/acl.so @@ -1649,10 +2296,8 @@ fi %{_libdir}/samba/ldb/extended_dn_out.so %{_libdir}/samba/ldb/extended_dn_store.so %{_libdir}/samba/ldb/group_audit_log.so -%{_libdir}/samba/ldb/ildap.so %{_libdir}/samba/ldb/instancetype.so %{_libdir}/samba/ldb/lazy_commit.so -%{_libdir}/samba/ldb/ldbsamba_extensions.so %{_libdir}/samba/ldb/linked_attributes.so %{_libdir}/samba/ldb/new_partition.so %{_libdir}/samba/ldb/objectclass.so @@ -1678,30 +2323,43 @@ fi %{_libdir}/samba/ldb/subtree_delete.so %{_libdir}/samba/ldb/subtree_rename.so %{_libdir}/samba/ldb/tombstone_reanimate.so +%{_libdir}/samba/ldb/trust_notify.so %{_libdir}/samba/ldb/unique_object_sids.so %{_libdir}/samba/ldb/update_keytab.so %{_libdir}/samba/ldb/vlv.so %{_libdir}/samba/ldb/wins_ldb.so + %{_libdir}/samba/vfs/posix_eadb.so %dir /var/lib/samba/sysvol %{_mandir}/man8/samba.8* %{_mandir}/man8/samba_downgrade_db.8* -%{_mandir}/man8/samba-gpupdate.8* -%{_mandir}/man8/samba-tool.8* %dir %{_datadir}/samba/admx +%{_datadir}/samba/admx/GNOME_Settings.admx %{_datadir}/samba/admx/samba.admx %dir %{_datadir}/samba/admx/en-US +%{_datadir}/samba/admx/en-US/GNOME_Settings.adml %{_datadir}/samba/admx/en-US/samba.adml +%dir %{_datadir}/samba/admx/ru-RU +%{_datadir}/samba/admx/ru-RU/GNOME_Settings.adml %files dc-provision %license source4/setup/ad-schema/licence.txt %{_datadir}/samba/setup +#endif with dc +%endif ### DC-LIBS %files dc-libs -%{_libdir}/samba/libdb-glue-samba4.so -%{_libdir}/samba/libprocess-model-samba4.so -%{_libdir}/samba/libservice-samba4.so +%{_libdir}/libsamba-policy.so.%{libsamba_policy_so_version}* +%{_libdir}/samba/libauth4-private-samba.so +%{_libdir}/samba/libsamba-net-private-samba.so + +%if %{with dc} +%{_libdir}/samba/libdb-glue-private-samba.so +%{_libdir}/samba/libpac-private-samba.so +%{_libdir}/samba/libprocess-model-private-samba.so +%{_libdir}/samba/libservice-private-samba.so + %dir %{_libdir}/samba/process_model %{_libdir}/samba/process_model/prefork.so %{_libdir}/samba/process_model/standard.so @@ -1711,6 +2369,7 @@ fi %{_libdir}/samba/service/dns.so %{_libdir}/samba/service/dns_update.so %{_libdir}/samba/service/drepl.so +%{_libdir}/samba/service/ft_scanner.so %{_libdir}/samba/service/kcc.so %{_libdir}/samba/service/kdc.so %{_libdir}/samba/service/ldap.so @@ -1719,24 +2378,25 @@ fi %{_libdir}/samba/service/s3fs.so %{_libdir}/samba/service/winbindd.so %{_libdir}/samba/service/wrepl.so + %{_libdir}/libdcerpc-server.so.* -%{_libdir}/samba/libdnsserver-common-samba4.so -%{_libdir}/samba/libdsdb-module-samba4.so -%{_libdir}/samba/libdsdb-garbage-collect-tombstones-samba4.so -%{_libdir}/samba/libscavenge-dns-records-samba4.so +%{_libdir}/samba/libad-claims-private-samba.so +%{_libdir}/samba/libauthn-policy-util-private-samba.so +%{_libdir}/samba/libdsdb-module-private-samba.so +%{_libdir}/samba/libdsdb-garbage-collect-tombstones-private-samba.so +%{_libdir}/samba/libscavenge-dns-records-private-samba.so ### DC-BIND %files dc-bind-dlz %attr(770,root,named) %dir /var/lib/samba/bind-dns %dir %{_libdir}/samba/bind9 -%{_libdir}/samba/bind9/dlz_bind9.so -%{_libdir}/samba/bind9/dlz_bind9_9.so %{_libdir}/samba/bind9/dlz_bind9_10.so %{_libdir}/samba/bind9/dlz_bind9_11.so %{_libdir}/samba/bind9/dlz_bind9_12.so %{_libdir}/samba/bind9/dlz_bind9_14.so %{_libdir}/samba/bind9/dlz_bind9_16.so -#endif with_dc +%{_libdir}/samba/bind9/dlz_bind9_18.so +#endif with dc %endif ### DEVEL @@ -1755,6 +2415,7 @@ fi %{_includedir}/samba-4.0/domain_credentials.h %{_includedir}/samba-4.0/gen_ndr/atsvc.h %{_includedir}/samba-4.0/gen_ndr/auth.h +%{_includedir}/samba-4.0/gen_ndr/claims.h %{_includedir}/samba-4.0/gen_ndr/dcerpc.h %{_includedir}/samba-4.0/gen_ndr/krb5pac.h %{_includedir}/samba-4.0/gen_ndr/lsa.h @@ -1789,7 +2450,6 @@ fi %{_includedir}/samba-4.0/ndr/ndr_krb5pac.h %{_includedir}/samba-4.0/ndr/ndr_svcctl.h %{_includedir}/samba-4.0/ndr/ndr_nbt.h -%{_includedir}/samba-4.0/netapi.h %{_includedir}/samba-4.0/param.h %{_includedir}/samba-4.0/passdb.h %{_includedir}/samba-4.0/policy.h @@ -1798,6 +2458,7 @@ fi %{_includedir}/samba-4.0/samba/version.h %{_includedir}/samba-4.0/share.h %{_includedir}/samba-4.0/smb2_lease_struct.h +%{_includedir}/samba-4.0/smb3posix.h %{_includedir}/samba-4.0/smbconf.h %{_includedir}/samba-4.0/smb_ldap.h %{_includedir}/samba-4.0/smbldap.h @@ -1815,7 +2476,6 @@ fi %{_includedir}/samba-4.0/util/idtree.h %{_includedir}/samba-4.0/util/idtree_random.h %{_includedir}/samba-4.0/util/signal.h -%{_includedir}/samba-4.0/util/string_wrappers.h %{_includedir}/samba-4.0/util/substitute.h %{_includedir}/samba-4.0/util/tevent_ntstatus.h %{_includedir}/samba-4.0/util/tevent_unix.h @@ -1831,7 +2491,6 @@ fi %{_libdir}/libndr-nbt.so %{_libdir}/libndr-standard.so %{_libdir}/libndr.so -%{_libdir}/libnetapi.so %{_libdir}/libsamba-credentials.so %{_libdir}/libsamba-errors.so %{_libdir}/libsamba-hostconfig.so @@ -1845,66 +2504,121 @@ fi %{_libdir}/pkgconfig/ndr_krb5pac.pc %{_libdir}/pkgconfig/ndr_nbt.pc %{_libdir}/pkgconfig/ndr_standard.pc -%{_libdir}/pkgconfig/netapi.pc %{_libdir}/pkgconfig/samba-credentials.pc %{_libdir}/pkgconfig/samba-hostconfig.pc +%{_libdir}/pkgconfig/samba-policy.pc %{_libdir}/pkgconfig/samba-util.pc %{_libdir}/pkgconfig/samdb.pc %{_libdir}/libsamba-passdb.so +%{_libdir}/libsamba-policy.so %{_libdir}/libsmbldap.so -%if %with_dc +%if %{with dc} %{_includedir}/samba-4.0/dcerpc_server.h %{_libdir}/libdcerpc-server.so %{_libdir}/pkgconfig/dcerpc_server.pc %endif -%if ! %with_libsmbclient +%if %{without libsmbclient} %{_includedir}/samba-4.0/libsmbclient.h -#endif ! with_libsmbclient +#endif without libsmbclient %endif -%if ! %with_libwbclient +%if %{without libwbclient} %{_includedir}/samba-4.0/wbclient.h -#endif ! with_libwbclient +#endif without libwbclient %endif ### VFS-CEPHFS -%if %{with_vfs_cephfs} +%if %{with vfs_cephfs} %files vfs-cephfs %{_libdir}/samba/vfs/ceph.so +%{_libdir}/samba/vfs/ceph_new.so %{_libdir}/samba/vfs/ceph_snapshots.so %{_mandir}/man8/vfs_ceph.8* +%{_mandir}/man8/vfs_ceph_new.8* %{_mandir}/man8/vfs_ceph_snapshots.8* %endif +### VFS-IOURING +%if %{with vfs_io_uring} +%files vfs-iouring +%{_libdir}/samba/vfs/io_uring.so +%{_mandir}/man8/vfs_io_uring.8* +%endif + ### VFS-GLUSTERFS -%if %{with_vfs_glusterfs} +%if %{with vfs_glusterfs} %files vfs-glusterfs %{_libdir}/samba/vfs/glusterfs.so %{_mandir}/man8/vfs_glusterfs.8* %endif +### GPUPDATE +%files gpupdate +%{_mandir}/man8/samba-gpupdate.8* +%{_sbindir}/samba-gpupdate + ### KRB5-PRINTING %files krb5-printing %attr(0700,root,root) %{_libexecdir}/samba/smbspool_krb5_wrapper %{_mandir}/man8/smbspool_krb5_wrapper.8* +### LDB-LDAP-MODULES +%files ldb-ldap-modules +%{_libdir}/samba/ldb/ldbsamba_extensions.so +%{_libdir}/samba/ldb/ildap.so +%{_libdir}/samba/ldb/ldap.so + ### LIBS %files libs %{_libdir}/libdcerpc-samr.so.* -%{_libdir}/libdcerpc-server-core.so.* -%{_libdir}/samba/libLIBWBCLIENT-OLD-samba4.so -%{_libdir}/samba/libauth4-samba4.so -%{_libdir}/samba/libauth-unix-token-samba4.so -%{_libdir}/samba/libdcerpc-samba4.so -%{_libdir}/samba/libshares-samba4.so -%{_libdir}/samba/libsmbpasswdparser-samba4.so -%{_libdir}/samba/libxattr-tdb-samba4.so +%{_libdir}/samba/libLIBWBCLIENT-OLD-private-samba.so +%{_libdir}/samba/libauth-unix-token-private-samba.so +%{_libdir}/samba/libdcerpc-samba4-private-samba.so +%{_libdir}/samba/libdnsserver-common-private-samba.so +%{_libdir}/samba/libshares-private-samba.so +%{_libdir}/samba/libsmbpasswdparser-private-samba.so +%{_libdir}/samba/libxattr-tdb-private-samba.so +%{_libdir}/samba/libREG-FULL-private-samba.so +%{_libdir}/samba/libRPC-SERVER-LOOP-private-samba.so +%{_libdir}/samba/libRPC-WORKER-private-samba.so + +# +# Server-side libraries (not used by libsmbclient) +# +%{_libdir}/samba/libauth-private-samba.so +%{_libdir}/samba/libctdb-event-client-private-samba.so +%{_libdir}/samba/libgpext-private-samba.so +%{_libdir}/samba/libgpo-private-samba.so +%{_libdir}/samba/libMESSAGING-private-samba.so +%{_libdir}/samba/libnet-keytab-private-samba.so +%{_libdir}/samba/libposix-eadb-private-samba.so +%{_libdir}/samba/libprinter-driver-private-samba.so +%{_libdir}/samba/libprinting-migrate-private-samba.so +%{_libdir}/samba/libsmbd-base-private-samba.so +%{_libdir}/samba/libsmbldaphelper-private-samba.so +%{_libdir}/samba/libtorture-private-samba.so +%{_libdir}/samba/libutil-crypt-private-samba.so + +# +# Password database modules (server-side, links to libsmbldaphelper) +# +%{_libdir}/samba/pdb/ldapsam.so + +### LIBNETAPI +%files -n libnetapi +%{_libdir}/libnetapi.so.%{libnetapi_so_version}* + +### LIBNETAPI-DEVEL +%files -n libnetapi-devel +%{_includedir}/samba-4.0/netapi.h +%{_libdir}/libnetapi.so +%{_libdir}/pkgconfig/netapi.pc ### LIBSMBCLIENT -%if %with_libsmbclient +%if %{with libsmbclient} %files -n libsmbclient %{_libdir}/libsmbclient.so.* @@ -1914,21 +2628,20 @@ fi %{_libdir}/libsmbclient.so %{_libdir}/pkgconfig/smbclient.pc %{_mandir}/man7/libsmbclient.7* -#endif with_libsmbclient +#endif {with libsmbclient} %endif ### LIBWBCLIENT -%if %with_libwbclient +%if %{with libwbclient} %files -n libwbclient -%{_libdir}/samba/wbclient/libwbclient.so.* -%{_libdir}/samba/libwinbind-client-samba4.so +%{_libdir}/libwbclient.so.%{libwbclient_so_version}* ### LIBWBCLIENT-DEVEL %files -n libwbclient-devel %{_includedir}/samba-4.0/wbclient.h -%{_libdir}/samba/wbclient/libwbclient.so +%{_libdir}/libwbclient.so %{_libdir}/pkgconfig/wbclient.pc -#endif with_libwbclient +#endif {with libwbclient} %endif ### PIDL @@ -1986,31 +2699,31 @@ fi %{python3_sitearch}/samba/__pycache__/auth_util.*.pyc %{python3_sitearch}/samba/__pycache__/colour.*.pyc %{python3_sitearch}/samba/__pycache__/common.*.pyc -%{python3_sitearch}/samba/__pycache__/compat.*.pyc %{python3_sitearch}/samba/__pycache__/dbchecker.*.pyc %{python3_sitearch}/samba/__pycache__/descriptor.*.pyc %{python3_sitearch}/samba/__pycache__/dnsresolver.*.pyc %{python3_sitearch}/samba/__pycache__/drs_utils.*.pyc +%{python3_sitearch}/samba/__pycache__/functional_level.*.pyc %{python3_sitearch}/samba/__pycache__/getopt.*.pyc -%{python3_sitearch}/samba/__pycache__/gpclass.*.pyc -%{python3_sitearch}/samba/__pycache__/gp_ext_loader.*.pyc -%{python3_sitearch}/samba/__pycache__/gp_scripts_ext.*.pyc -%{python3_sitearch}/samba/__pycache__/gp_sec_ext.*.pyc +%{python3_sitearch}/samba/__pycache__/gkdi.*.pyc %{python3_sitearch}/samba/__pycache__/graph.*.pyc %{python3_sitearch}/samba/__pycache__/hostconfig.*.pyc %{python3_sitearch}/samba/__pycache__/idmap.*.pyc %{python3_sitearch}/samba/__pycache__/join.*.pyc +%{python3_sitearch}/samba/__pycache__/lsa_utils.*.pyc %{python3_sitearch}/samba/__pycache__/logger.*.pyc %{python3_sitearch}/samba/__pycache__/mdb_util.*.pyc %{python3_sitearch}/samba/__pycache__/ms_display_specifiers.*.pyc %{python3_sitearch}/samba/__pycache__/ms_schema.*.pyc %{python3_sitearch}/samba/__pycache__/ndr.*.pyc %{python3_sitearch}/samba/__pycache__/ntacls.*.pyc +%{python3_sitearch}/samba/__pycache__/nt_time.*.pyc +%{python3_sitearch}/samba/__pycache__/policies.*.pyc +%{python3_sitearch}/samba/__pycache__/safe_tarfile.*.pyc %{python3_sitearch}/samba/__pycache__/sd_utils.*.pyc %{python3_sitearch}/samba/__pycache__/sites.*.pyc %{python3_sitearch}/samba/__pycache__/subnets.*.pyc %{python3_sitearch}/samba/__pycache__/tdb_util.*.pyc -%{python3_sitearch}/samba/__pycache__/trust_utils.*.pyc %{python3_sitearch}/samba/__pycache__/upgrade.*.pyc %{python3_sitearch}/samba/__pycache__/upgradehelpers.*.pyc %{python3_sitearch}/samba/__pycache__/xattr.*.pyc @@ -2021,7 +2734,7 @@ fi %{python3_sitearch}/samba/dbchecker.py %{python3_sitearch}/samba/colour.py %{python3_sitearch}/samba/common.py -%{python3_sitearch}/samba/compat.py +%{python3_sitearch}/samba/compression.*.so %{python3_sitearch}/samba/credentials.*.so %{python3_sitearch}/samba/crypto.*.so %dir %{python3_sitearch}/samba/dcerpc @@ -2031,6 +2744,9 @@ fi %{python3_sitearch}/samba/dcerpc/atsvc.*.so %{python3_sitearch}/samba/dcerpc/auth.*.so %{python3_sitearch}/samba/dcerpc/base.*.so +%{python3_sitearch}/samba/dcerpc/bcrypt_rsakey_blob.*.so +%{python3_sitearch}/samba/dcerpc/claims.*.so +%{python3_sitearch}/samba/dcerpc/conditional_ace.*.so %{python3_sitearch}/samba/dcerpc/dcerpc.*.so %{python3_sitearch}/samba/dcerpc/dfs.*.so %{python3_sitearch}/samba/dcerpc/dns.*.so @@ -2039,9 +2755,12 @@ fi %{python3_sitearch}/samba/dcerpc/drsuapi.*.so %{python3_sitearch}/samba/dcerpc/echo.*.so %{python3_sitearch}/samba/dcerpc/epmapper.*.so +%{python3_sitearch}/samba/dcerpc/gkdi.*.so +%{python3_sitearch}/samba/dcerpc/gmsa.*.so %{python3_sitearch}/samba/dcerpc/idmap.*.so %{python3_sitearch}/samba/dcerpc/initshutdown.*.so %{python3_sitearch}/samba/dcerpc/irpc.*.so +%{python3_sitearch}/samba/dcerpc/keycredlink.*.so %{python3_sitearch}/samba/dcerpc/krb5ccache.*.so %{python3_sitearch}/samba/dcerpc/krb5pac.*.so %{python3_sitearch}/samba/dcerpc/lsa.*.so @@ -2054,12 +2773,16 @@ fi %{python3_sitearch}/samba/dcerpc/ntlmssp.*.so %{python3_sitearch}/samba/dcerpc/preg.*.so %{python3_sitearch}/samba/dcerpc/samr.*.so +%{python3_sitearch}/samba/dcerpc/schannel.*.so %{python3_sitearch}/samba/dcerpc/security.*.so %{python3_sitearch}/samba/dcerpc/server_id.*.so %{python3_sitearch}/samba/dcerpc/smb_acl.*.so +%{python3_sitearch}/samba/dcerpc/smb3posix.*.so +%{python3_sitearch}/samba/dcerpc/smbXsrv.*.so %{python3_sitearch}/samba/dcerpc/spoolss.*.so %{python3_sitearch}/samba/dcerpc/srvsvc.*.so %{python3_sitearch}/samba/dcerpc/svcctl.*.so +%{python3_sitearch}/samba/dcerpc/tpm20_rsakey_blob.*.so %{python3_sitearch}/samba/dcerpc/unixinfo.*.so %{python3_sitearch}/samba/dcerpc/winbind.*.so %{python3_sitearch}/samba/dcerpc/windows_event_ids.*.so @@ -2070,20 +2793,72 @@ fi %{python3_sitearch}/samba/dcerpc/xattr.*.so %{python3_sitearch}/samba/descriptor.py %{python3_sitearch}/samba/dnsresolver.py +%dir %{python3_sitearch}/samba/domain +%{python3_sitearch}/samba/domain/__init__.py +%dir %{python3_sitearch}/samba/domain/__pycache__ +%{python3_sitearch}/samba/domain/__pycache__/__init__.*.pyc +%dir %{python3_sitearch}/samba/domain/models +%{python3_sitearch}/samba/domain/models/__init__.py +%dir %{python3_sitearch}/samba/domain/models/__pycache__ +%{python3_sitearch}/samba/domain/models/__pycache__/__init__.*.pyc +%{python3_sitearch}/samba/domain/models/__pycache__/auth_policy.*.pyc +%{python3_sitearch}/samba/domain/models/__pycache__/auth_silo.*.pyc +%{python3_sitearch}/samba/domain/models/__pycache__/claim_type.*.pyc +%{python3_sitearch}/samba/domain/models/__pycache__/computer.*.pyc +%{python3_sitearch}/samba/domain/models/__pycache__/constants.*.pyc +%{python3_sitearch}/samba/domain/models/__pycache__/container.*.pyc +%{python3_sitearch}/samba/domain/models/__pycache__/exceptions.*.pyc +%{python3_sitearch}/samba/domain/models/__pycache__/fields.*.pyc +%{python3_sitearch}/samba/domain/models/__pycache__/gmsa.*.pyc +%{python3_sitearch}/samba/domain/models/__pycache__/group.*.pyc +%{python3_sitearch}/samba/domain/models/__pycache__/model.*.pyc +%{python3_sitearch}/samba/domain/models/__pycache__/org.*.pyc +%{python3_sitearch}/samba/domain/models/__pycache__/person.*.pyc +%{python3_sitearch}/samba/domain/models/__pycache__/query.*.pyc +%{python3_sitearch}/samba/domain/models/__pycache__/registry.*.pyc +%{python3_sitearch}/samba/domain/models/__pycache__/schema.*.pyc +%{python3_sitearch}/samba/domain/models/__pycache__/site.*.pyc +%{python3_sitearch}/samba/domain/models/__pycache__/subnet.*.pyc +%{python3_sitearch}/samba/domain/models/__pycache__/types.*.pyc +%{python3_sitearch}/samba/domain/models/__pycache__/user.*.pyc +%{python3_sitearch}/samba/domain/models/__pycache__/value_type.*.pyc +%{python3_sitearch}/samba/domain/models/auth_policy.py +%{python3_sitearch}/samba/domain/models/auth_silo.py +%{python3_sitearch}/samba/domain/models/claim_type.py +%{python3_sitearch}/samba/domain/models/computer.py +%{python3_sitearch}/samba/domain/models/constants.py +%{python3_sitearch}/samba/domain/models/container.py +%{python3_sitearch}/samba/domain/models/exceptions.py +%{python3_sitearch}/samba/domain/models/fields.py +%{python3_sitearch}/samba/domain/models/gmsa.py +%{python3_sitearch}/samba/domain/models/group.py +%{python3_sitearch}/samba/domain/models/model.py +%{python3_sitearch}/samba/domain/models/org.py +%{python3_sitearch}/samba/domain/models/person.py +%{python3_sitearch}/samba/domain/models/query.py +%{python3_sitearch}/samba/domain/models/registry.py +%{python3_sitearch}/samba/domain/models/schema.py +%{python3_sitearch}/samba/domain/models/site.py +%{python3_sitearch}/samba/domain/models/subnet.py +%{python3_sitearch}/samba/domain/models/types.py +%{python3_sitearch}/samba/domain/models/user.py +%{python3_sitearch}/samba/domain/models/value_type.py %{python3_sitearch}/samba/drs_utils.py +%{python3_sitearch}/samba/dsdb.*.so +%{python3_sitearch}/samba/dsdb_dns.*.so +%{python3_sitearch}/samba/functional_level.py %{python3_sitearch}/samba/gensec.*.so %{python3_sitearch}/samba/getopt.py -%{python3_sitearch}/samba/gpclass.py -%{python3_sitearch}/samba/gp_scripts_ext.py -%{python3_sitearch}/samba/gp_sec_ext.py -%{python3_sitearch}/samba/gpo.*.so +%{python3_sitearch}/samba/gkdi.py %{python3_sitearch}/samba/graph.py %{python3_sitearch}/samba/hostconfig.py %{python3_sitearch}/samba/idmap.py %{python3_sitearch}/samba/join.py +%{python3_sitearch}/samba/lsa_utils.py %{python3_sitearch}/samba/messaging.*.so %{python3_sitearch}/samba/ndr.py %{python3_sitearch}/samba/net.*.so +%{python3_sitearch}/samba/net_s3.*.so %{python3_sitearch}/samba/ntstatus.*.so %{python3_sitearch}/samba/posix_eadb.*.so %dir %{python3_sitearch}/samba/emulate @@ -2094,7 +2869,61 @@ fi %{python3_sitearch}/samba/emulate/__init__.py %{python3_sitearch}/samba/emulate/traffic.py %{python3_sitearch}/samba/emulate/traffic_packets.py -%{python3_sitearch}/samba/gp_ext_loader.py +%dir %{python3_sitearch}/samba/gp +%dir %{python3_sitearch}/samba/gp/__pycache__ +%{python3_sitearch}/samba/gp/__init__.py +%{python3_sitearch}/samba/gp/__pycache__/__init__.*.pyc +%{python3_sitearch}/samba/gp/__pycache__/gpclass.*.pyc +%{python3_sitearch}/samba/gp/__pycache__/gp_centrify_crontab_ext.*.pyc +%{python3_sitearch}/samba/gp/__pycache__/gp_centrify_sudoers_ext.*.pyc +%{python3_sitearch}/samba/gp/__pycache__/gp_cert_auto_enroll_ext.*.pyc +%{python3_sitearch}/samba/gp/__pycache__/gp_drive_maps_ext.*.pyc +%{python3_sitearch}/samba/gp/__pycache__/gp_chromium_ext.*.pyc +%{python3_sitearch}/samba/gp/__pycache__/gp_ext_loader.*.pyc +%{python3_sitearch}/samba/gp/__pycache__/gp_firefox_ext.*.pyc +%{python3_sitearch}/samba/gp/__pycache__/gp_firewalld_ext.*.pyc +%{python3_sitearch}/samba/gp/__pycache__/gp_gnome_settings_ext.*.pyc +%{python3_sitearch}/samba/gp/__pycache__/gp_msgs_ext.*.pyc +%{python3_sitearch}/samba/gp/__pycache__/gp_scripts_ext.*.pyc +%{python3_sitearch}/samba/gp/__pycache__/gp_sec_ext.*.pyc +%{python3_sitearch}/samba/gp/__pycache__/gp_smb_conf_ext.*.pyc +%{python3_sitearch}/samba/gp/__pycache__/gp_sudoers_ext.*.pyc +%{python3_sitearch}/samba/gp/__pycache__/vgp_access_ext.*.pyc +%{python3_sitearch}/samba/gp/__pycache__/vgp_files_ext.*.pyc +%{python3_sitearch}/samba/gp/__pycache__/vgp_issue_ext.*.pyc +%{python3_sitearch}/samba/gp/__pycache__/vgp_motd_ext.*.pyc +%{python3_sitearch}/samba/gp/__pycache__/vgp_openssh_ext.*.pyc +%{python3_sitearch}/samba/gp/__pycache__/vgp_startup_scripts_ext.*.pyc +%{python3_sitearch}/samba/gp/__pycache__/vgp_sudoers_ext.*.pyc +%{python3_sitearch}/samba/gp/__pycache__/vgp_symlink_ext.*.pyc +%{python3_sitearch}/samba/gp/gpclass.py +%{python3_sitearch}/samba/gp/gp_gnome_settings_ext.py +%{python3_sitearch}/samba/gp/gp_scripts_ext.py +%{python3_sitearch}/samba/gp/gp_sec_ext.py +%{python3_sitearch}/samba/gp/gp_centrify_crontab_ext.py +%{python3_sitearch}/samba/gp/gp_centrify_sudoers_ext.py +%{python3_sitearch}/samba/gp/gp_cert_auto_enroll_ext.py +%{python3_sitearch}/samba/gp/gp_drive_maps_ext.py +%{python3_sitearch}/samba/gp/gp_chromium_ext.py +%{python3_sitearch}/samba/gp/gp_ext_loader.py +%{python3_sitearch}/samba/gp/gp_firefox_ext.py +%{python3_sitearch}/samba/gp/gp_firewalld_ext.py +%{python3_sitearch}/samba/gp/gp_msgs_ext.py +%{python3_sitearch}/samba/gp/gp_smb_conf_ext.py +%{python3_sitearch}/samba/gp/gp_sudoers_ext.py +%dir %{python3_sitearch}/samba/gp/util +%dir %{python3_sitearch}/samba/gp/util/__pycache__ +%{python3_sitearch}/samba/gp/util/__pycache__/logging.*.pyc +%{python3_sitearch}/samba/gp/util/logging.py +%{python3_sitearch}/samba/gp/vgp_access_ext.py +%{python3_sitearch}/samba/gp/vgp_files_ext.py +%{python3_sitearch}/samba/gp/vgp_issue_ext.py +%{python3_sitearch}/samba/gp/vgp_motd_ext.py +%{python3_sitearch}/samba/gp/vgp_openssh_ext.py +%{python3_sitearch}/samba/gp/vgp_startup_scripts_ext.py +%{python3_sitearch}/samba/gp/vgp_sudoers_ext.py +%{python3_sitearch}/samba/gp/vgp_symlink_ext.py +%{python3_sitearch}/samba/gpo.*.so %dir %{python3_sitearch}/samba/gp_parse %{python3_sitearch}/samba/gp_parse/__init__.py %dir %{python3_sitearch}/samba/gp_parse/__pycache__ @@ -2109,6 +2938,7 @@ fi %{python3_sitearch}/samba/gp_parse/gp_inf.py %{python3_sitearch}/samba/gp_parse/gp_ini.py %{python3_sitearch}/samba/gp_parse/gp_pol.py +%{python3_sitearch}/samba/hresult.*.so %{python3_sitearch}/samba/logger.py %{python3_sitearch}/samba/mdb_util.py %{python3_sitearch}/samba/ms_display_specifiers.py @@ -2124,12 +2954,12 @@ fi %{python3_sitearch}/samba/netcmd/__pycache__/dbcheck.*.pyc %{python3_sitearch}/samba/netcmd/__pycache__/delegation.*.pyc %{python3_sitearch}/samba/netcmd/__pycache__/dns.*.pyc -%{python3_sitearch}/samba/netcmd/__pycache__/domain.*.pyc -%{python3_sitearch}/samba/netcmd/__pycache__/domain_backup.*.pyc %{python3_sitearch}/samba/netcmd/__pycache__/drs.*.pyc %{python3_sitearch}/samba/netcmd/__pycache__/dsacl.*.pyc +%{python3_sitearch}/samba/netcmd/__pycache__/encoders.*.pyc %{python3_sitearch}/samba/netcmd/__pycache__/forest.*.pyc %{python3_sitearch}/samba/netcmd/__pycache__/fsmo.*.pyc +%{python3_sitearch}/samba/netcmd/__pycache__/gpcommon.*.pyc %{python3_sitearch}/samba/netcmd/__pycache__/gpo.*.pyc %{python3_sitearch}/samba/netcmd/__pycache__/group.*.pyc %{python3_sitearch}/samba/netcmd/__pycache__/ldapcmp.*.pyc @@ -2140,24 +2970,105 @@ fi %{python3_sitearch}/samba/netcmd/__pycache__/processes.*.pyc %{python3_sitearch}/samba/netcmd/__pycache__/pso.*.pyc %{python3_sitearch}/samba/netcmd/__pycache__/rodc.*.pyc +%{python3_sitearch}/samba/netcmd/__pycache__/shell.*.pyc %{python3_sitearch}/samba/netcmd/__pycache__/schema.*.pyc %{python3_sitearch}/samba/netcmd/__pycache__/sites.*.pyc %{python3_sitearch}/samba/netcmd/__pycache__/spn.*.pyc %{python3_sitearch}/samba/netcmd/__pycache__/testparm.*.pyc -%{python3_sitearch}/samba/netcmd/__pycache__/user.*.pyc +%{python3_sitearch}/samba/netcmd/__pycache__/validators.*.pyc %{python3_sitearch}/samba/netcmd/__pycache__/visualize.*.pyc %{python3_sitearch}/samba/netcmd/common.py %{python3_sitearch}/samba/netcmd/computer.py %{python3_sitearch}/samba/netcmd/contact.py %{python3_sitearch}/samba/netcmd/dbcheck.py %{python3_sitearch}/samba/netcmd/delegation.py +%dir %{python3_sitearch}/samba/netcmd/domain +%{python3_sitearch}/samba/netcmd/domain/__init__.py +%dir %{python3_sitearch}/samba/netcmd/domain/__pycache__ +%{python3_sitearch}/samba/netcmd/domain/__pycache__/__init__.*.pyc +%{python3_sitearch}/samba/netcmd/domain/__pycache__/backup.*.pyc +%{python3_sitearch}/samba/netcmd/domain/__pycache__/classicupgrade.*.pyc +%{python3_sitearch}/samba/netcmd/domain/__pycache__/common.*.pyc +%{python3_sitearch}/samba/netcmd/domain/__pycache__/dcpromo.*.pyc +%{python3_sitearch}/samba/netcmd/domain/__pycache__/demote.*.pyc +%{python3_sitearch}/samba/netcmd/domain/__pycache__/functional_prep.*.pyc +%{python3_sitearch}/samba/netcmd/domain/__pycache__/info.*.pyc +%{python3_sitearch}/samba/netcmd/domain/__pycache__/join.*.pyc +%{python3_sitearch}/samba/netcmd/domain/__pycache__/keytab.*.pyc +%{python3_sitearch}/samba/netcmd/domain/__pycache__/leave.*.pyc +%{python3_sitearch}/samba/netcmd/domain/__pycache__/level.*.pyc +%{python3_sitearch}/samba/netcmd/domain/__pycache__/passwordsettings.*.pyc +%{python3_sitearch}/samba/netcmd/domain/__pycache__/provision.*.pyc +%{python3_sitearch}/samba/netcmd/domain/__pycache__/samba3upgrade.*.pyc +%{python3_sitearch}/samba/netcmd/domain/__pycache__/schemaupgrade.*.pyc +%{python3_sitearch}/samba/netcmd/domain/__pycache__/tombstones.*.pyc +%{python3_sitearch}/samba/netcmd/domain/__pycache__/trust.*.pyc +%dir %{python3_sitearch}/samba/netcmd/domain/auth +%{python3_sitearch}/samba/netcmd/domain/auth/__init__.py +%dir %{python3_sitearch}/samba/netcmd/domain/auth/__pycache__ +%{python3_sitearch}/samba/netcmd/domain/auth/__pycache__/__init__.*.pyc +%dir %{python3_sitearch}/samba/netcmd/domain/auth/policy +%{python3_sitearch}/samba/netcmd/domain/auth/policy/__init__.py +%dir %{python3_sitearch}/samba/netcmd/domain/auth/policy/__pycache__ +%{python3_sitearch}/samba/netcmd/domain/auth/policy/__pycache__/__init__.*.pyc +%{python3_sitearch}/samba/netcmd/domain/auth/policy/__pycache__/computer_allowed_to_authenticate_to.*.pyc +%{python3_sitearch}/samba/netcmd/domain/auth/policy/__pycache__/policy.*.pyc +%{python3_sitearch}/samba/netcmd/domain/auth/policy/__pycache__/service_allowed_to_authenticate_from.*.pyc +%{python3_sitearch}/samba/netcmd/domain/auth/policy/__pycache__/service_allowed_to_authenticate_to.*.pyc +%{python3_sitearch}/samba/netcmd/domain/auth/policy/__pycache__/user_allowed_to_authenticate_from.*.pyc +%{python3_sitearch}/samba/netcmd/domain/auth/policy/__pycache__/user_allowed_to_authenticate_to.*.pyc +%{python3_sitearch}/samba/netcmd/domain/auth/policy/computer_allowed_to_authenticate_to.py +%{python3_sitearch}/samba/netcmd/domain/auth/policy/policy.py +%{python3_sitearch}/samba/netcmd/domain/auth/policy/service_allowed_to_authenticate_from.py +%{python3_sitearch}/samba/netcmd/domain/auth/policy/service_allowed_to_authenticate_to.py +%{python3_sitearch}/samba/netcmd/domain/auth/policy/user_allowed_to_authenticate_from.py +%{python3_sitearch}/samba/netcmd/domain/auth/policy/user_allowed_to_authenticate_to.py +%dir %{python3_sitearch}/samba/netcmd/domain/auth/silo +%{python3_sitearch}/samba/netcmd/domain/auth/silo/__init__.py +%dir %{python3_sitearch}/samba/netcmd/domain/auth/silo/__pycache__ +%{python3_sitearch}/samba/netcmd/domain/auth/silo/__pycache__/__init__.*.pyc +%{python3_sitearch}/samba/netcmd/domain/auth/silo/__pycache__/member.*.pyc +%{python3_sitearch}/samba/netcmd/domain/auth/silo/__pycache__/silo.*.pyc +%{python3_sitearch}/samba/netcmd/domain/auth/silo/member.py +%{python3_sitearch}/samba/netcmd/domain/auth/silo/silo.py +%{python3_sitearch}/samba/netcmd/domain/backup.py +%dir %{python3_sitearch}/samba/netcmd/domain/claim +%{python3_sitearch}/samba/netcmd/domain/claim/__init__.py +%dir %{python3_sitearch}/samba/netcmd/domain/claim/__pycache__ +%{python3_sitearch}/samba/netcmd/domain/claim/__pycache__/__init__.*.pyc +%{python3_sitearch}/samba/netcmd/domain/claim/__pycache__/claim_type.*.pyc +%{python3_sitearch}/samba/netcmd/domain/claim/__pycache__/value_type.*.pyc +%{python3_sitearch}/samba/netcmd/domain/claim/claim_type.py +%{python3_sitearch}/samba/netcmd/domain/claim/value_type.py +%{python3_sitearch}/samba/netcmd/domain/classicupgrade.py +%{python3_sitearch}/samba/netcmd/domain/common.py +%{python3_sitearch}/samba/netcmd/domain/dcpromo.py +%{python3_sitearch}/samba/netcmd/domain/demote.py +%{python3_sitearch}/samba/netcmd/domain/functional_prep.py +%{python3_sitearch}/samba/netcmd/domain/info.py +%{python3_sitearch}/samba/netcmd/domain/join.py +%dir %{python3_sitearch}/samba/netcmd/domain/kds +%{python3_sitearch}/samba/netcmd/domain/kds/__init__.py +%dir %{python3_sitearch}/samba/netcmd/domain/kds/__pycache__ +%{python3_sitearch}/samba/netcmd/domain/kds/__pycache__/__init__.*.pyc +%{python3_sitearch}/samba/netcmd/domain/kds/__pycache__/root_key.*.pyc +%{python3_sitearch}/samba/netcmd/domain/kds/root_key.py +%{python3_sitearch}/samba/netcmd/domain/keytab.py +%{python3_sitearch}/samba/netcmd/domain/leave.py +%{python3_sitearch}/samba/netcmd/domain/level.py +%{python3_sitearch}/samba/netcmd/domain/passwordsettings.py +%{python3_sitearch}/samba/netcmd/domain/provision.py +%{python3_sitearch}/samba/netcmd/domain/samba3upgrade.py +%{python3_sitearch}/samba/netcmd/domain/schemaupgrade.py +%{python3_sitearch}/samba/netcmd/domain/tombstones.py +%{python3_sitearch}/samba/netcmd/domain/trust.py %{python3_sitearch}/samba/netcmd/dns.py -%{python3_sitearch}/samba/netcmd/domain.py -%{python3_sitearch}/samba/netcmd/domain_backup.py %{python3_sitearch}/samba/netcmd/drs.py %{python3_sitearch}/samba/netcmd/dsacl.py +%{python3_sitearch}/samba/netcmd/encoders.py %{python3_sitearch}/samba/netcmd/forest.py %{python3_sitearch}/samba/netcmd/fsmo.py +%{python3_sitearch}/samba/netcmd/gpcommon.py %{python3_sitearch}/samba/netcmd/gpo.py %{python3_sitearch}/samba/netcmd/group.py %{python3_sitearch}/samba/netcmd/ldapcmp.py @@ -2169,27 +3080,102 @@ fi %{python3_sitearch}/samba/netcmd/pso.py %{python3_sitearch}/samba/netcmd/rodc.py %{python3_sitearch}/samba/netcmd/schema.py +%dir %{python3_sitearch}/samba/netcmd/service_account +%{python3_sitearch}/samba/netcmd/service_account/__init__.py +%dir %{python3_sitearch}/samba/netcmd/service_account/__pycache__ +%{python3_sitearch}/samba/netcmd/service_account/__pycache__/__init__.*.pyc +%{python3_sitearch}/samba/netcmd/service_account/__pycache__/group_msa_membership.*.pyc +%{python3_sitearch}/samba/netcmd/service_account/__pycache__/service_account.*.pyc +%{python3_sitearch}/samba/netcmd/service_account/group_msa_membership.py +%{python3_sitearch}/samba/netcmd/service_account/service_account.py +%{python3_sitearch}/samba/netcmd/shell.py %{python3_sitearch}/samba/netcmd/sites.py %{python3_sitearch}/samba/netcmd/spn.py %{python3_sitearch}/samba/netcmd/testparm.py -%{python3_sitearch}/samba/netcmd/user.py +%dir %{python3_sitearch}/samba/netcmd/user +%{python3_sitearch}/samba/netcmd/user/__init__.py +%{python3_sitearch}/samba/netcmd/user/add.py +%{python3_sitearch}/samba/netcmd/user/add_unix_attrs.py +%dir %{python3_sitearch}/samba/netcmd/user/auth +%{python3_sitearch}/samba/netcmd/user/auth/__init__.py +%{python3_sitearch}/samba/netcmd/user/auth/policy.py +%dir %{python3_sitearch}/samba/netcmd/user/auth/__pycache__ +%{python3_sitearch}/samba/netcmd/user/auth/__pycache__/__init__.*.pyc +%{python3_sitearch}/samba/netcmd/user/auth/__pycache__/policy.*.pyc +%{python3_sitearch}/samba/netcmd/user/auth/__pycache__/silo.*.pyc +%{python3_sitearch}/samba/netcmd/user/auth/silo.py +%{python3_sitearch}/samba/netcmd/user/delete.py +%{python3_sitearch}/samba/netcmd/user/disable.py +%{python3_sitearch}/samba/netcmd/user/edit.py +%{python3_sitearch}/samba/netcmd/user/enable.py +%{python3_sitearch}/samba/netcmd/user/getgroups.py +%{python3_sitearch}/samba/netcmd/user/list.py +%{python3_sitearch}/samba/netcmd/user/move.py +%{python3_sitearch}/samba/netcmd/user/password.py +%dir %{python3_sitearch}/samba/netcmd/user/__pycache__ +%{python3_sitearch}/samba/netcmd/user/__pycache__/__init__.*.pyc +%{python3_sitearch}/samba/netcmd/user/__pycache__/add.*.pyc +%{python3_sitearch}/samba/netcmd/user/__pycache__/add_unix_attrs.*.pyc +%{python3_sitearch}/samba/netcmd/user/__pycache__/delete.*.pyc +%{python3_sitearch}/samba/netcmd/user/__pycache__/disable.*.pyc +%{python3_sitearch}/samba/netcmd/user/__pycache__/edit.*.pyc +%{python3_sitearch}/samba/netcmd/user/__pycache__/enable.*.pyc +%{python3_sitearch}/samba/netcmd/user/__pycache__/getgroups.*.pyc +%{python3_sitearch}/samba/netcmd/user/__pycache__/list.*.pyc +%{python3_sitearch}/samba/netcmd/user/__pycache__/move.*.pyc +%{python3_sitearch}/samba/netcmd/user/__pycache__/password.*.pyc +%{python3_sitearch}/samba/netcmd/user/__pycache__/rename.*.pyc +%{python3_sitearch}/samba/netcmd/user/__pycache__/sensitive.*.pyc +%{python3_sitearch}/samba/netcmd/user/__pycache__/setexpiry.*.pyc +%{python3_sitearch}/samba/netcmd/user/__pycache__/setpassword.*.pyc +%{python3_sitearch}/samba/netcmd/user/__pycache__/setprimarygroup.*.pyc +%{python3_sitearch}/samba/netcmd/user/__pycache__/unlock.*.pyc +%dir %{python3_sitearch}/samba/netcmd/user/readpasswords +%{python3_sitearch}/samba/netcmd/user/readpasswords/common.py +%{python3_sitearch}/samba/netcmd/user/readpasswords/get_kerberos_ticket.py +%{python3_sitearch}/samba/netcmd/user/readpasswords/getpassword.py +%{python3_sitearch}/samba/netcmd/user/readpasswords/__init__.py +%dir %{python3_sitearch}/samba/netcmd/user/readpasswords/__pycache__ +%{python3_sitearch}/samba/netcmd/user/readpasswords/__pycache__/__init__.*.pyc +%{python3_sitearch}/samba/netcmd/user/readpasswords/__pycache__/common.*.pyc +%{python3_sitearch}/samba/netcmd/user/readpasswords/__pycache__/get_kerberos_ticket.*.pyc +%{python3_sitearch}/samba/netcmd/user/readpasswords/__pycache__/getpassword.*.pyc +%{python3_sitearch}/samba/netcmd/user/readpasswords/__pycache__/show.*.pyc +%{python3_sitearch}/samba/netcmd/user/readpasswords/__pycache__/syncpasswords.*.pyc +%{python3_sitearch}/samba/netcmd/user/readpasswords/show.py +%{python3_sitearch}/samba/netcmd/user/readpasswords/syncpasswords.py +%{python3_sitearch}/samba/netcmd/user/rename.py +%{python3_sitearch}/samba/netcmd/user/sensitive.py +%{python3_sitearch}/samba/netcmd/user/setexpiry.py +%{python3_sitearch}/samba/netcmd/user/setpassword.py +%{python3_sitearch}/samba/netcmd/user/setprimarygroup.py +%{python3_sitearch}/samba/netcmd/user/unlock.py +%{python3_sitearch}/samba/netcmd/validators.py %{python3_sitearch}/samba/netcmd/visualize.py %{python3_sitearch}/samba/ntacls.py +%{python3_sitearch}/samba/nt_time.py %{python3_sitearch}/samba/param.*.so +%{python3_sitearch}/samba/policies.py %{python3_sitearch}/samba/policy.*.so %{python3_sitearch}/samba/registry.*.so +%{python3_sitearch}/samba/reparse_symlink.*.so %{python3_sitearch}/samba/security.*.so +%{python3_sitearch}/samba/safe_tarfile.py %dir %{python3_sitearch}/samba/samba3 %{python3_sitearch}/samba/samba3/__init__.py %dir %{python3_sitearch}/samba/samba3/__pycache__ %{python3_sitearch}/samba/samba3/__pycache__/__init__.*.pyc -%{python3_sitearch}/samba/samba3/libsmb_samba_internal.*.so +%{python3_sitearch}/samba/samba3/__pycache__/libsmb_samba_internal.*.pyc +%{python3_sitearch}/samba/samba3/libsmb_samba_cwrapper.cpython*.so +%{python3_sitearch}/samba/samba3/libsmb_samba_internal.py %{python3_sitearch}/samba/samba3/mdscli.*.so %{python3_sitearch}/samba/samba3/param.*.so %{python3_sitearch}/samba/samba3/passdb.*.so +%{python3_sitearch}/samba/samba3/smbconf.*.so %{python3_sitearch}/samba/samba3/smbd.*.so %{python3_sitearch}/samba/sd_utils.py %{python3_sitearch}/samba/sites.py +%{python3_sitearch}/samba/smbconf.*.so %{python3_sitearch}/samba/subnets.py %dir %{python3_sitearch}/samba/subunit %{python3_sitearch}/samba/subunit/__init__.py @@ -2198,26 +3184,32 @@ fi %{python3_sitearch}/samba/subunit/__pycache__/run.*.pyc %{python3_sitearch}/samba/subunit/run.py %{python3_sitearch}/samba/tdb_util.py -%dir %{python3_sitearch}/samba/third_party -%{python3_sitearch}/samba/third_party/__init__.py -%dir %{python3_sitearch}/samba/third_party/__pycache__ -%{python3_sitearch}/samba/third_party/__pycache__/__init__.*.pyc -%{python3_sitearch}/samba/trust_utils.py %{python3_sitearch}/samba/upgrade.py %{python3_sitearch}/samba/upgradehelpers.py %{python3_sitearch}/samba/werror.*.so %{python3_sitearch}/samba/xattr.py %{python3_sitearch}/samba/xattr_native.*.so %{python3_sitearch}/samba/xattr_tdb.*.so -%{_libdir}/libsamba-policy.cpython*.so.* -%{_libdir}/samba/libsamba-net.cpython*.so +%{_libdir}/samba/libsamba-net-join.cpython*.so %{_libdir}/samba/libsamba-python.cpython*.so -%files -n python3-%{name}-devel -%{_libdir}/libsamba-policy.cpython*.so -%{_libdir}/pkgconfig/samba-policy.*.pc +%if %{with includelibs} +%{_libdir}/samba/libpyldb-util.cpython*.so +%{_libdir}/samba/libpytalloc-util.cpython*.so + +%{python3_sitearch}/__pycache__/_ldb_text*.pyc +%{python3_sitearch}/__pycache__/_tdb_text*.pyc +%{python3_sitearch}/__pycache__/tevent*.pyc +%{python3_sitearch}/_ldb_text.py +%{python3_sitearch}/_tdb_text.py +%{python3_sitearch}/_tevent.cpython*.so +%{python3_sitearch}/ldb.cpython*.so +%{python3_sitearch}/talloc.cpython*.so +%{python3_sitearch}/tdb.cpython*.so +%{python3_sitearch}/tevent.py +#endif with includelibs +%endif -%if %{with_dc} %files -n python3-%{name}-dc %{python3_sitearch}/samba/samdb.py %{python3_sitearch}/samba/schema.py @@ -2233,9 +3225,9 @@ fi %{python3_sitearch}/samba/__pycache__/uptodateness.*.pyc %{python3_sitearch}/samba/dcerpc/dnsserver.*.so +%if %{with dc} %{python3_sitearch}/samba/dckeytab.*.so -%{python3_sitearch}/samba/dsdb.*.so -%{python3_sitearch}/samba/dsdb_dns.*.so +%endif %{python3_sitearch}/samba/domain_update.py %{python3_sitearch}/samba/forest_update.py %{python3_sitearch}/samba/ms_forest_updates_markdown.py @@ -2276,7 +3268,6 @@ fi %{python3_sitearch}/samba/remove_dc.py %{python3_sitearch}/samba/uptodateness.py -%endif %files -n python3-%{name}-test %dir %{python3_sitearch}/samba/tests @@ -2295,12 +3286,19 @@ fi %{python3_sitearch}/samba/tests/__pycache__/auth_log_netlogon_bad_creds.*.pyc %{python3_sitearch}/samba/tests/__pycache__/auth_log_samlogon.*.pyc %{python3_sitearch}/samba/tests/__pycache__/auth_log_winbind.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/bcrypt_rsakey_blob.*.pyc %{python3_sitearch}/samba/tests/__pycache__/common.*.pyc %{python3_sitearch}/samba/tests/__pycache__/complex_expressions.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/compression.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/conditional_ace_assembler.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/conditional_ace_bytes.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/conditional_ace_claims.*.pyc %{python3_sitearch}/samba/tests/__pycache__/core.*.pyc %{python3_sitearch}/samba/tests/__pycache__/credentials.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/cred_opt.*.pyc %{python3_sitearch}/samba/tests/__pycache__/dckeytab.*.pyc %{python3_sitearch}/samba/tests/__pycache__/dns.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/dns_aging.*.pyc %{python3_sitearch}/samba/tests/__pycache__/dns_base.*.pyc %{python3_sitearch}/samba/tests/__pycache__/dns_forwarder.*.pyc %{python3_sitearch}/samba/tests/__pycache__/dns_invalid.*.pyc @@ -2309,7 +3307,10 @@ fi %{python3_sitearch}/samba/tests/__pycache__/dns_wildcard.*.pyc %{python3_sitearch}/samba/tests/__pycache__/dsdb.*.pyc %{python3_sitearch}/samba/tests/__pycache__/dsdb_api.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/dsdb_dns.*.pyc %{python3_sitearch}/samba/tests/__pycache__/dsdb_lock.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/dsdb_quiet_env_tests.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/dsdb_quiet_provision_tests.*.pyc %{python3_sitearch}/samba/tests/__pycache__/dsdb_schema_attributes.*.pyc %{python3_sitearch}/samba/tests/__pycache__/docs.*.pyc %{python3_sitearch}/samba/tests/__pycache__/domain_backup.*.pyc @@ -2318,19 +3319,26 @@ fi %{python3_sitearch}/samba/tests/__pycache__/gensec.*.pyc %{python3_sitearch}/samba/tests/__pycache__/get_opt.*.pyc %{python3_sitearch}/samba/tests/__pycache__/getdcname.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/gkdi.*.pyc %{python3_sitearch}/samba/tests/__pycache__/glue.*.pyc %{python3_sitearch}/samba/tests/__pycache__/gpo.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/gpo_member.*.pyc %{python3_sitearch}/samba/tests/__pycache__/graph.*.pyc %{python3_sitearch}/samba/tests/__pycache__/group_audit.*.pyc %{python3_sitearch}/samba/tests/__pycache__/hostconfig.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/imports.*.pyc %{python3_sitearch}/samba/tests/__pycache__/join.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/key_credential_link.*.pyc %{python3_sitearch}/samba/tests/__pycache__/krb5_credentials.*.pyc %{python3_sitearch}/samba/tests/__pycache__/ldap_raw.*.pyc %{python3_sitearch}/samba/tests/__pycache__/ldap_referrals.*.pyc %{python3_sitearch}/samba/tests/__pycache__/ldap_spn.*.pyc %{python3_sitearch}/samba/tests/__pycache__/ldap_upn_sam_account.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/ldap_whoami.*.pyc %{python3_sitearch}/samba/tests/__pycache__/loadparm.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/logfiles.*.pyc %{python3_sitearch}/samba/tests/__pycache__/libsmb.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/libsmb-basic.*.pyc %{python3_sitearch}/samba/tests/__pycache__/lsa_string.*.pyc %{python3_sitearch}/samba/tests/__pycache__/messaging.*.pyc %{python3_sitearch}/samba/tests/__pycache__/netbios.*.pyc @@ -2346,6 +3354,7 @@ fi %{python3_sitearch}/samba/tests/__pycache__/ntlm_auth_krb5.*.pyc %{python3_sitearch}/samba/tests/__pycache__/pam_winbind.*.pyc %{python3_sitearch}/samba/tests/__pycache__/pam_winbind_chauthtok.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/pam_winbind_setcred.*.pyc %{python3_sitearch}/samba/tests/__pycache__/pam_winbind_warn_pwd_expire.*.pyc %{python3_sitearch}/samba/tests/__pycache__/param.*.pyc %{python3_sitearch}/samba/tests/__pycache__/password_hash.*.pyc @@ -2363,24 +3372,41 @@ fi %{python3_sitearch}/samba/tests/__pycache__/pso.*.pyc %{python3_sitearch}/samba/tests/__pycache__/py_credentials.*.pyc %{python3_sitearch}/samba/tests/__pycache__/registry.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/reparsepoints.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/rust.*.pyc %{python3_sitearch}/samba/tests/__pycache__/s3idmapdb.*.pyc %{python3_sitearch}/samba/tests/__pycache__/s3param.*.pyc %{python3_sitearch}/samba/tests/__pycache__/s3passdb.*.pyc %{python3_sitearch}/samba/tests/__pycache__/s3registry.*.pyc %{python3_sitearch}/samba/tests/__pycache__/s3windb.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/s3_net_join.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/safe_tarfile.*.pyc %{python3_sitearch}/samba/tests/__pycache__/samba_upgradedns_lmdb.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/samba_startup_fl_change.*.pyc %{python3_sitearch}/samba/tests/__pycache__/samba3sam.*.pyc %{python3_sitearch}/samba/tests/__pycache__/samdb.*.pyc %{python3_sitearch}/samba/tests/__pycache__/samdb_api.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/sddl.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/sddl_conditional_ace.*.pyc %{python3_sitearch}/samba/tests/__pycache__/security.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/security_descriptors.*.pyc %{python3_sitearch}/samba/tests/__pycache__/segfault.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/sid_strings.*.pyc %{python3_sitearch}/samba/tests/__pycache__/smb.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/smb1posix.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/smb2symlink.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/smb3unix.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/smbconf.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/smb-notify.*.pyc %{python3_sitearch}/samba/tests/__pycache__/smbd_base.*.pyc %{python3_sitearch}/samba/tests/__pycache__/smbd_fuzztest.*.pyc %{python3_sitearch}/samba/tests/__pycache__/source.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/source_chars.*.pyc %{python3_sitearch}/samba/tests/__pycache__/strings.*.pyc %{python3_sitearch}/samba/tests/__pycache__/subunitrun.*.pyc %{python3_sitearch}/samba/tests/__pycache__/tdb_util.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/token_factory.*.pyc +%{python3_sitearch}/samba/tests/__pycache__/tpm20_rsakey_blob.*.pyc %{python3_sitearch}/samba/tests/__pycache__/upgrade.*.pyc %{python3_sitearch}/samba/tests/__pycache__/upgradeprovision.*.pyc %{python3_sitearch}/samba/tests/__pycache__/upgradeprovisionneeddc.*.pyc @@ -2398,19 +3424,30 @@ fi %{python3_sitearch}/samba/tests/auth_log_pass_change.py %{python3_sitearch}/samba/tests/auth_log_samlogon.py %{python3_sitearch}/samba/tests/auth_log_winbind.py +%{python3_sitearch}/samba/tests/bcrypt_rsakey_blob.py %dir %{python3_sitearch}/samba/tests/blackbox %{python3_sitearch}/samba/tests/blackbox/__init__.py %dir %{python3_sitearch}/samba/tests/blackbox/__pycache__ %{python3_sitearch}/samba/tests/blackbox/__pycache__/__init__.*.pyc %{python3_sitearch}/samba/tests/blackbox/__pycache__/bug13653.*.pyc %{python3_sitearch}/samba/tests/blackbox/__pycache__/check_output.*.pyc +%{python3_sitearch}/samba/tests/blackbox/__pycache__/claims.*.pyc %{python3_sitearch}/samba/tests/blackbox/__pycache__/downgradedatabase.*.pyc -%{python3_sitearch}/samba/tests/blackbox/__pycache__/mdfind.*.pyc +%{python3_sitearch}/samba/tests/blackbox/__pycache__/gmsa.*.pyc +%{python3_sitearch}/samba/tests/blackbox/__pycache__/http_chunk.*.pyc +%{python3_sitearch}/samba/tests/blackbox/__pycache__/http_content.*.pyc +%{python3_sitearch}/samba/tests/blackbox/__pycache__/mdsearch.*.pyc +%{python3_sitearch}/samba/tests/blackbox/__pycache__/misc_dfs_widelink.*.pyc %{python3_sitearch}/samba/tests/blackbox/__pycache__/ndrdump.*.pyc +%{python3_sitearch}/samba/tests/blackbox/__pycache__/netads_dns.*.pyc %{python3_sitearch}/samba/tests/blackbox/__pycache__/netads_json.*.pyc +%{python3_sitearch}/samba/tests/blackbox/__pycache__/rpcd_witness_samba_only.*.pyc %{python3_sitearch}/samba/tests/blackbox/__pycache__/samba_dnsupdate.*.pyc %{python3_sitearch}/samba/tests/blackbox/__pycache__/smbcacls.*.pyc %{python3_sitearch}/samba/tests/blackbox/__pycache__/smbcacls_basic.*.pyc +%{python3_sitearch}/samba/tests/blackbox/__pycache__/smbcacls_dfs_propagate_inherit.*.pyc +%{python3_sitearch}/samba/tests/blackbox/__pycache__/smbcacls_propagate_inhertance.*.pyc +%{python3_sitearch}/samba/tests/blackbox/__pycache__/smbcacls_save_restore.*.pyc %{python3_sitearch}/samba/tests/blackbox/__pycache__/smbcontrol.*.pyc %{python3_sitearch}/samba/tests/blackbox/__pycache__/smbcontrol_process.*.pyc %{python3_sitearch}/samba/tests/blackbox/__pycache__/traffic_learner.*.pyc @@ -2418,33 +3455,49 @@ fi %{python3_sitearch}/samba/tests/blackbox/__pycache__/traffic_summary.*.pyc %{python3_sitearch}/samba/tests/blackbox/bug13653.py %{python3_sitearch}/samba/tests/blackbox/check_output.py +%{python3_sitearch}/samba/tests/blackbox/claims.py %{python3_sitearch}/samba/tests/blackbox/downgradedatabase.py -%{python3_sitearch}/samba/tests/blackbox/mdfind.py +%{python3_sitearch}/samba/tests/blackbox/gmsa.py +%{python3_sitearch}/samba/tests/blackbox/http_chunk.py +%{python3_sitearch}/samba/tests/blackbox/http_content.py +%{python3_sitearch}/samba/tests/blackbox/mdsearch.py +%{python3_sitearch}/samba/tests/blackbox/misc_dfs_widelink.py %{python3_sitearch}/samba/tests/blackbox/ndrdump.py +%{python3_sitearch}/samba/tests/blackbox/netads_dns.py %{python3_sitearch}/samba/tests/blackbox/netads_json.py +%{python3_sitearch}/samba/tests/blackbox/rpcd_witness_samba_only.py %{python3_sitearch}/samba/tests/blackbox/samba_dnsupdate.py %{python3_sitearch}/samba/tests/blackbox/smbcacls.py %{python3_sitearch}/samba/tests/blackbox/smbcacls_basic.py +%{python3_sitearch}/samba/tests/blackbox/smbcacls_dfs_propagate_inherit.py +%{python3_sitearch}/samba/tests/blackbox/smbcacls_propagate_inhertance.py +%{python3_sitearch}/samba/tests/blackbox/smbcacls_save_restore.py %{python3_sitearch}/samba/tests/blackbox/smbcontrol.py %{python3_sitearch}/samba/tests/blackbox/smbcontrol_process.py %{python3_sitearch}/samba/tests/blackbox/traffic_learner.py %{python3_sitearch}/samba/tests/blackbox/traffic_replay.py %{python3_sitearch}/samba/tests/blackbox/traffic_summary.py %{python3_sitearch}/samba/tests/common.py +%{python3_sitearch}/samba/tests/compression.py %{python3_sitearch}/samba/tests/complex_expressions.py +%{python3_sitearch}/samba/tests/conditional_ace_assembler.py +%{python3_sitearch}/samba/tests/conditional_ace_bytes.py +%{python3_sitearch}/samba/tests/conditional_ace_claims.py %{python3_sitearch}/samba/tests/core.py %{python3_sitearch}/samba/tests/credentials.py +%{python3_sitearch}/samba/tests/cred_opt.py %dir %{python3_sitearch}/samba/tests/dcerpc %{python3_sitearch}/samba/tests/dcerpc/__init__.py %dir %{python3_sitearch}/samba/tests/dcerpc/__pycache__ %{python3_sitearch}/samba/tests/dcerpc/__pycache__/__init__.*.pyc %{python3_sitearch}/samba/tests/dcerpc/__pycache__/array.*.pyc %{python3_sitearch}/samba/tests/dcerpc/__pycache__/bare.*.pyc -%{python3_sitearch}/samba/tests/dcerpc/__pycache__/createtrustrelax.*.pyc %{python3_sitearch}/samba/tests/dcerpc/__pycache__/binding.*.pyc +%{python3_sitearch}/samba/tests/dcerpc/__pycache__/dfs.*.pyc %{python3_sitearch}/samba/tests/dcerpc/__pycache__/dnsserver.*.pyc %{python3_sitearch}/samba/tests/dcerpc/__pycache__/integer.*.pyc %{python3_sitearch}/samba/tests/dcerpc/__pycache__/lsa.*.pyc +%{python3_sitearch}/samba/tests/dcerpc/__pycache__/lsa_utils.*.pyc %{python3_sitearch}/samba/tests/dcerpc/__pycache__/mdssvc.*.pyc %{python3_sitearch}/samba/tests/dcerpc/__pycache__/misc.*.pyc %{python3_sitearch}/samba/tests/dcerpc/__pycache__/raw_protocol.*.pyc @@ -2461,10 +3514,11 @@ fi %{python3_sitearch}/samba/tests/dcerpc/array.py %{python3_sitearch}/samba/tests/dcerpc/bare.py %{python3_sitearch}/samba/tests/dcerpc/binding.py -%{python3_sitearch}/samba/tests/dcerpc/createtrustrelax.py +%{python3_sitearch}/samba/tests/dcerpc/dfs.py %{python3_sitearch}/samba/tests/dcerpc/dnsserver.py %{python3_sitearch}/samba/tests/dcerpc/integer.py %{python3_sitearch}/samba/tests/dcerpc/lsa.py +%{python3_sitearch}/samba/tests/dcerpc/lsa_utils.py %{python3_sitearch}/samba/tests/dcerpc/mdssvc.py %{python3_sitearch}/samba/tests/dcerpc/misc.py %{python3_sitearch}/samba/tests/dcerpc/raw_protocol.py @@ -2480,6 +3534,7 @@ fi %{python3_sitearch}/samba/tests/dcerpc/unix.py %{python3_sitearch}/samba/tests/dckeytab.py %{python3_sitearch}/samba/tests/dns.py +%{python3_sitearch}/samba/tests/dns_aging.py %{python3_sitearch}/samba/tests/dns_base.py %{python3_sitearch}/samba/tests/dns_forwarder.py %dir %{python3_sitearch}/samba/tests/dns_forwarder_helpers @@ -2491,8 +3546,11 @@ fi %{python3_sitearch}/samba/tests/dns_wildcard.py %{python3_sitearch}/samba/tests/dsdb.py %{python3_sitearch}/samba/tests/dsdb_api.py +%{python3_sitearch}/samba/tests/dsdb_dns.py %{python3_sitearch}/samba/tests/dsdb_lock.py %{python3_sitearch}/samba/tests/dsdb_schema_attributes.py +%{python3_sitearch}/samba/tests/dsdb_quiet_env_tests.py +%{python3_sitearch}/samba/tests/dsdb_quiet_provision_tests.py %{python3_sitearch}/samba/tests/docs.py %{python3_sitearch}/samba/tests/domain_backup.py %{python3_sitearch}/samba/tests/domain_backup_offline.py @@ -2508,11 +3566,14 @@ fi %{python3_sitearch}/samba/tests/gensec.py %{python3_sitearch}/samba/tests/getdcname.py %{python3_sitearch}/samba/tests/get_opt.py +%{python3_sitearch}/samba/tests/gkdi.py %{python3_sitearch}/samba/tests/glue.py %{python3_sitearch}/samba/tests/gpo.py +%{python3_sitearch}/samba/tests/gpo_member.py %{python3_sitearch}/samba/tests/graph.py %{python3_sitearch}/samba/tests/group_audit.py %{python3_sitearch}/samba/tests/hostconfig.py +%{python3_sitearch}/samba/tests/imports.py %{python3_sitearch}/samba/tests/join.py %dir %{python3_sitearch}/samba/tests/kcc %{python3_sitearch}/samba/tests/kcc/__init__.py @@ -2526,71 +3587,128 @@ fi %{python3_sitearch}/samba/tests/kcc/graph_utils.py %{python3_sitearch}/samba/tests/kcc/kcc_utils.py %{python3_sitearch}/samba/tests/kcc/ldif_import_export.py +%{python3_sitearch}/samba/tests/key_credential_link.py %dir %{python3_sitearch}/samba/tests/krb5 %dir %{python3_sitearch}/samba/tests/krb5/__pycache__ %{python3_sitearch}/samba/tests/krb5/__pycache__/alias_tests.*.pyc %{python3_sitearch}/samba/tests/krb5/__pycache__/as_canonicalization_tests.*.pyc %{python3_sitearch}/samba/tests/krb5/__pycache__/as_req_tests.*.pyc +%{python3_sitearch}/samba/tests/krb5/__pycache__/authn_policy_tests.*.pyc +%{python3_sitearch}/samba/tests/krb5/__pycache__/claims_in_pac.*.pyc +%{python3_sitearch}/samba/tests/krb5/__pycache__/claims_tests.*.pyc %{python3_sitearch}/samba/tests/krb5/__pycache__/compatability_tests.*.pyc +%{python3_sitearch}/samba/tests/krb5/__pycache__/conditional_ace_tests.*.pyc +%{python3_sitearch}/samba/tests/krb5/__pycache__/device_tests.*.pyc +%{python3_sitearch}/samba/tests/krb5/__pycache__/etype_tests.*.pyc %{python3_sitearch}/samba/tests/krb5/__pycache__/fast_tests.*.pyc +%{python3_sitearch}/samba/tests/krb5/__pycache__/gkdi_tests.*.pyc +%{python3_sitearch}/samba/tests/krb5/__pycache__/gmsa_tests.*.pyc +%{python3_sitearch}/samba/tests/krb5/__pycache__/group_tests.*.pyc %{python3_sitearch}/samba/tests/krb5/__pycache__/kcrypto.*.pyc %{python3_sitearch}/samba/tests/krb5/__pycache__/kdc_base_test.*.pyc %{python3_sitearch}/samba/tests/krb5/__pycache__/kdc_tests.*.pyc %{python3_sitearch}/samba/tests/krb5/__pycache__/kdc_tgs_tests.*.pyc +%{python3_sitearch}/samba/tests/krb5/__pycache__/kdc_tgt_tests.*.pyc +%{python3_sitearch}/samba/tests/krb5/__pycache__/kpasswd_tests.*.pyc +%{python3_sitearch}/samba/tests/krb5/__pycache__/lockout_tests.*.pyc %{python3_sitearch}/samba/tests/krb5/__pycache__/ms_kile_client_principal_lookup_tests.*.pyc +%{python3_sitearch}/samba/tests/krb5/__pycache__/netlogon.*.pyc +%{python3_sitearch}/samba/tests/krb5/__pycache__/nt_hash_tests.*.pyc +%{python3_sitearch}/samba/tests/krb5/__pycache__/pac_align_tests.*.pyc +%{python3_sitearch}/samba/tests/krb5/__pycache__/pkinit_tests.*.pyc +%{python3_sitearch}/samba/tests/krb5/__pycache__/protected_users_tests.*.pyc %{python3_sitearch}/samba/tests/krb5/__pycache__/raw_testcase.*.pyc %{python3_sitearch}/samba/tests/krb5/__pycache__/rfc4120_constants.*.pyc %{python3_sitearch}/samba/tests/krb5/__pycache__/rfc4120_pyasn1.*.pyc -%{python3_sitearch}/samba/tests/krb5/__pycache__/rodc_tests*.pyc +%{python3_sitearch}/samba/tests/krb5/__pycache__/rfc4120_pyasn1_generated.*.pyc +%{python3_sitearch}/samba/tests/krb5/__pycache__/rodc_tests.*.pyc +%{python3_sitearch}/samba/tests/krb5/__pycache__/simple_tests.*.pyc %{python3_sitearch}/samba/tests/krb5/__pycache__/s4u_tests.*.pyc %{python3_sitearch}/samba/tests/krb5/__pycache__/salt_tests.*.pyc -%{python3_sitearch}/samba/tests/krb5/__pycache__/simple_tests.*.pyc %{python3_sitearch}/samba/tests/krb5/__pycache__/spn_tests.*.pyc %{python3_sitearch}/samba/tests/krb5/__pycache__/test_ccache.*.pyc +%{python3_sitearch}/samba/tests/krb5/__pycache__/test_idmap_nss.*.pyc %{python3_sitearch}/samba/tests/krb5/__pycache__/test_ldap.*.pyc %{python3_sitearch}/samba/tests/krb5/__pycache__/test_min_domain_uid.*.pyc %{python3_sitearch}/samba/tests/krb5/__pycache__/test_rpc.*.pyc %{python3_sitearch}/samba/tests/krb5/__pycache__/test_smb.*.pyc -%{python3_sitearch}/samba/tests/krb5/__pycache__/simple_tests.*.pyc %{python3_sitearch}/samba/tests/krb5/__pycache__/xrealm_tests.*.pyc %{python3_sitearch}/samba/tests/krb5/alias_tests.py %{python3_sitearch}/samba/tests/krb5/as_canonicalization_tests.py %{python3_sitearch}/samba/tests/krb5/as_req_tests.py +%{python3_sitearch}/samba/tests/krb5/authn_policy_tests.py +%{python3_sitearch}/samba/tests/krb5/claims_in_pac.py +%{python3_sitearch}/samba/tests/krb5/claims_tests.py %{python3_sitearch}/samba/tests/krb5/compatability_tests.py +%{python3_sitearch}/samba/tests/krb5/conditional_ace_tests.py +%{python3_sitearch}/samba/tests/krb5/device_tests.py +%{python3_sitearch}/samba/tests/krb5/etype_tests.py %{python3_sitearch}/samba/tests/krb5/fast_tests.py +%{python3_sitearch}/samba/tests/krb5/gkdi_tests.py +%{python3_sitearch}/samba/tests/krb5/gmsa_tests.py +%{python3_sitearch}/samba/tests/krb5/group_tests.py %{python3_sitearch}/samba/tests/krb5/kcrypto.py %{python3_sitearch}/samba/tests/krb5/kdc_base_test.py %{python3_sitearch}/samba/tests/krb5/kdc_tests.py %{python3_sitearch}/samba/tests/krb5/kdc_tgs_tests.py +%{python3_sitearch}/samba/tests/krb5/kdc_tgt_tests.py +%{python3_sitearch}/samba/tests/krb5/kpasswd_tests.py +%{python3_sitearch}/samba/tests/krb5/lockout_tests.py %{python3_sitearch}/samba/tests/krb5/ms_kile_client_principal_lookup_tests.py +%{python3_sitearch}/samba/tests/krb5/netlogon.py +%{python3_sitearch}/samba/tests/krb5/nt_hash_tests.py +%{python3_sitearch}/samba/tests/krb5/pac_align_tests.py +%{python3_sitearch}/samba/tests/krb5/pkinit_tests.py +%{python3_sitearch}/samba/tests/krb5/protected_users_tests.py %{python3_sitearch}/samba/tests/krb5/raw_testcase.py %{python3_sitearch}/samba/tests/krb5/rfc4120_constants.py %{python3_sitearch}/samba/tests/krb5/rfc4120_pyasn1.py +%{python3_sitearch}/samba/tests/krb5/rfc4120_pyasn1_generated.py %{python3_sitearch}/samba/tests/krb5/rodc_tests.py -%{python3_sitearch}/samba/tests/krb5/s4u_tests.py -%{python3_sitearch}/samba/tests/krb5/salt_tests.py %{python3_sitearch}/samba/tests/krb5/simple_tests.py -%{python3_sitearch}/samba/tests/krb5/spn_tests.py +%{python3_sitearch}/samba/tests/krb5/test_idmap_nss.py %{python3_sitearch}/samba/tests/krb5/test_ccache.py %{python3_sitearch}/samba/tests/krb5/test_ldap.py %{python3_sitearch}/samba/tests/krb5/test_min_domain_uid.py %{python3_sitearch}/samba/tests/krb5/test_rpc.py %{python3_sitearch}/samba/tests/krb5/test_smb.py +%{python3_sitearch}/samba/tests/krb5/s4u_tests.py +%{python3_sitearch}/samba/tests/krb5/salt_tests.py +%{python3_sitearch}/samba/tests/krb5/spn_tests.py %{python3_sitearch}/samba/tests/krb5/xrealm_tests.py %{python3_sitearch}/samba/tests/krb5_credentials.py %{python3_sitearch}/samba/tests/ldap_raw.py -%{python3_sitearch}/samba/tests/ldap_referrals.py %{python3_sitearch}/samba/tests/ldap_spn.py +%{python3_sitearch}/samba/tests/ldap_referrals.py %{python3_sitearch}/samba/tests/ldap_upn_sam_account.py +%{python3_sitearch}/samba/tests/ldap_whoami.py %{python3_sitearch}/samba/tests/libsmb.py +%{python3_sitearch}/samba/tests/libsmb-basic.py %{python3_sitearch}/samba/tests/loadparm.py +%{python3_sitearch}/samba/tests/logfiles.py %{python3_sitearch}/samba/tests/lsa_string.py %{python3_sitearch}/samba/tests/messaging.py +%dir %{python3_sitearch}/samba/tests/ndr +%{python3_sitearch}/samba/tests/ndr/gkdi.py +%{python3_sitearch}/samba/tests/ndr/gmsa.py +%{python3_sitearch}/samba/tests/ndr/sd.py +%dir %{python3_sitearch}/samba/tests/ndr/__pycache__ +%{python3_sitearch}/samba/tests/ndr/__pycache__/gkdi.*.pyc +%{python3_sitearch}/samba/tests/ndr/__pycache__/gmsa.*.pyc +%{python3_sitearch}/samba/tests/ndr/__pycache__/sd.*.pyc +%{python3_sitearch}/samba/tests/ndr/__pycache__/wbint.*.pyc +%{python3_sitearch}/samba/tests/ndr/wbint.py %{python3_sitearch}/samba/tests/netbios.py %{python3_sitearch}/samba/tests/netcmd.py %{python3_sitearch}/samba/tests/net_join_no_spnego.py %{python3_sitearch}/samba/tests/net_join.py %{python3_sitearch}/samba/tests/netlogonsvc.py +%dir %{python3_sitearch}/samba/tests/nss +%dir %{python3_sitearch}/samba/tests/nss/__pycache__ +%{python3_sitearch}/samba/tests/nss/__pycache__/base.*.pyc +%{python3_sitearch}/samba/tests/nss/__pycache__/group.*.pyc +%{python3_sitearch}/samba/tests/nss/base.py +%{python3_sitearch}/samba/tests/nss/group.py %{python3_sitearch}/samba/tests/ntacls.py %{python3_sitearch}/samba/tests/ntacls_backup.py %{python3_sitearch}/samba/tests/ntlmdisabled.py @@ -2599,6 +3717,7 @@ fi %{python3_sitearch}/samba/tests/ntlm_auth_krb5.py %{python3_sitearch}/samba/tests/pam_winbind.py %{python3_sitearch}/samba/tests/pam_winbind_chauthtok.py +%{python3_sitearch}/samba/tests/pam_winbind_setcred.py %{python3_sitearch}/samba/tests/pam_winbind_warn_pwd_expire.py %{python3_sitearch}/samba/tests/param.py %{python3_sitearch}/samba/tests/password_hash.py @@ -2616,12 +3735,17 @@ fi %{python3_sitearch}/samba/tests/pso.py %{python3_sitearch}/samba/tests/py_credentials.py %{python3_sitearch}/samba/tests/registry.py +%{python3_sitearch}/samba/tests/reparsepoints.py +%{python3_sitearch}/samba/tests/rust.py %{python3_sitearch}/samba/tests/s3idmapdb.py %{python3_sitearch}/samba/tests/s3param.py %{python3_sitearch}/samba/tests/s3passdb.py %{python3_sitearch}/samba/tests/s3registry.py %{python3_sitearch}/samba/tests/s3windb.py +%{python3_sitearch}/samba/tests/s3_net_join.py +%{python3_sitearch}/samba/tests/safe_tarfile.py %{python3_sitearch}/samba/tests/samba3sam.py +%{python3_sitearch}/samba/tests/samba_startup_fl_change.py %{python3_sitearch}/samba/tests/samba_upgradedns_lmdb.py %dir %{python3_sitearch}/samba/tests/samba_tool %{python3_sitearch}/samba/tests/samba_tool/__init__.py @@ -2632,15 +3756,22 @@ fi %{python3_sitearch}/samba/tests/samba_tool/__pycache__/contact.*.pyc %{python3_sitearch}/samba/tests/samba_tool/__pycache__/demote.*.pyc %{python3_sitearch}/samba/tests/samba_tool/__pycache__/dnscmd.*.pyc +%{python3_sitearch}/samba/tests/samba_tool/__pycache__/domain_auth_policy.*.pyc +%{python3_sitearch}/samba/tests/samba_tool/__pycache__/domain_auth_silo.*.pyc +%{python3_sitearch}/samba/tests/samba_tool/__pycache__/domain_claim.*.pyc +%{python3_sitearch}/samba/tests/samba_tool/__pycache__/domain_kds_root_key.*.pyc +%{python3_sitearch}/samba/tests/samba_tool/__pycache__/domain_models.*.pyc %{python3_sitearch}/samba/tests/samba_tool/__pycache__/drs_clone_dc_data_lmdb_size.*.pyc %{python3_sitearch}/samba/tests/samba_tool/__pycache__/dsacl.*.pyc %{python3_sitearch}/samba/tests/samba_tool/__pycache__/forest.*.pyc %{python3_sitearch}/samba/tests/samba_tool/__pycache__/fsmo.*.pyc %{python3_sitearch}/samba/tests/samba_tool/__pycache__/gpo.*.pyc +%{python3_sitearch}/samba/tests/samba_tool/__pycache__/gpo_exts.*.pyc %{python3_sitearch}/samba/tests/samba_tool/__pycache__/group.*.pyc %{python3_sitearch}/samba/tests/samba_tool/__pycache__/help.*.pyc %{python3_sitearch}/samba/tests/samba_tool/__pycache__/join.*.pyc %{python3_sitearch}/samba/tests/samba_tool/__pycache__/join_lmdb_size.*.pyc +%{python3_sitearch}/samba/tests/samba_tool/__pycache__/join_member.*.pyc %{python3_sitearch}/samba/tests/samba_tool/__pycache__/ntacl.*.pyc %{python3_sitearch}/samba/tests/samba_tool/__pycache__/ou.*.pyc %{python3_sitearch}/samba/tests/samba_tool/__pycache__/passwordsettings.*.pyc @@ -2648,12 +3779,19 @@ fi %{python3_sitearch}/samba/tests/samba_tool/__pycache__/promote_dc_lmdb_size.*.pyc %{python3_sitearch}/samba/tests/samba_tool/__pycache__/provision_lmdb_size.*.pyc %{python3_sitearch}/samba/tests/samba_tool/__pycache__/provision_password_check.*.pyc +%{python3_sitearch}/samba/tests/samba_tool/__pycache__/provision_userPassword_crypt.*.pyc %{python3_sitearch}/samba/tests/samba_tool/__pycache__/rodc.*.pyc %{python3_sitearch}/samba/tests/samba_tool/__pycache__/schema.*.pyc +%{python3_sitearch}/samba/tests/samba_tool/__pycache__/service_account.*.pyc +%{python3_sitearch}/samba/tests/samba_tool/__pycache__/silo_base.*.pyc %{python3_sitearch}/samba/tests/samba_tool/__pycache__/sites.*.pyc %{python3_sitearch}/samba/tests/samba_tool/__pycache__/timecmd.*.pyc %{python3_sitearch}/samba/tests/samba_tool/__pycache__/user.*.pyc +%{python3_sitearch}/samba/tests/samba_tool/__pycache__/user_auth_policy.*.pyc +%{python3_sitearch}/samba/tests/samba_tool/__pycache__/user_auth_silo.*.pyc %{python3_sitearch}/samba/tests/samba_tool/__pycache__/user_check_password_script.*.pyc +%{python3_sitearch}/samba/tests/samba_tool/__pycache__/user_get_kerberos_ticket.*.pyc +%{python3_sitearch}/samba/tests/samba_tool/__pycache__/user_getpassword_gmsa.*.pyc %{python3_sitearch}/samba/tests/samba_tool/__pycache__/user_virtualCryptSHA.*.pyc %{python3_sitearch}/samba/tests/samba_tool/__pycache__/user_virtualCryptSHA_base.*.pyc %{python3_sitearch}/samba/tests/samba_tool/__pycache__/user_virtualCryptSHA_gpg.*.pyc @@ -2666,15 +3804,22 @@ fi %{python3_sitearch}/samba/tests/samba_tool/contact.py %{python3_sitearch}/samba/tests/samba_tool/demote.py %{python3_sitearch}/samba/tests/samba_tool/dnscmd.py +%{python3_sitearch}/samba/tests/samba_tool/domain_auth_policy.py +%{python3_sitearch}/samba/tests/samba_tool/domain_auth_silo.py +%{python3_sitearch}/samba/tests/samba_tool/domain_claim.py +%{python3_sitearch}/samba/tests/samba_tool/domain_kds_root_key.py +%{python3_sitearch}/samba/tests/samba_tool/domain_models.py %{python3_sitearch}/samba/tests/samba_tool/drs_clone_dc_data_lmdb_size.py %{python3_sitearch}/samba/tests/samba_tool/dsacl.py %{python3_sitearch}/samba/tests/samba_tool/forest.py %{python3_sitearch}/samba/tests/samba_tool/fsmo.py %{python3_sitearch}/samba/tests/samba_tool/gpo.py +%{python3_sitearch}/samba/tests/samba_tool/gpo_exts.py %{python3_sitearch}/samba/tests/samba_tool/group.py %{python3_sitearch}/samba/tests/samba_tool/help.py %{python3_sitearch}/samba/tests/samba_tool/join.py %{python3_sitearch}/samba/tests/samba_tool/join_lmdb_size.py +%{python3_sitearch}/samba/tests/samba_tool/join_member.py %{python3_sitearch}/samba/tests/samba_tool/ntacl.py %{python3_sitearch}/samba/tests/samba_tool/ou.py %{python3_sitearch}/samba/tests/samba_tool/passwordsettings.py @@ -2682,12 +3827,19 @@ fi %{python3_sitearch}/samba/tests/samba_tool/promote_dc_lmdb_size.py %{python3_sitearch}/samba/tests/samba_tool/provision_lmdb_size.py %{python3_sitearch}/samba/tests/samba_tool/provision_password_check.py +%{python3_sitearch}/samba/tests/samba_tool/provision_userPassword_crypt.py %{python3_sitearch}/samba/tests/samba_tool/rodc.py %{python3_sitearch}/samba/tests/samba_tool/schema.py +%{python3_sitearch}/samba/tests/samba_tool/service_account.py +%{python3_sitearch}/samba/tests/samba_tool/silo_base.py %{python3_sitearch}/samba/tests/samba_tool/sites.py %{python3_sitearch}/samba/tests/samba_tool/timecmd.py %{python3_sitearch}/samba/tests/samba_tool/user.py +%{python3_sitearch}/samba/tests/samba_tool/user_auth_policy.py +%{python3_sitearch}/samba/tests/samba_tool/user_auth_silo.py %{python3_sitearch}/samba/tests/samba_tool/user_check_password_script.py +%{python3_sitearch}/samba/tests/samba_tool/user_get_kerberos_ticket.py +%{python3_sitearch}/samba/tests/samba_tool/user_getpassword_gmsa.py %{python3_sitearch}/samba/tests/samba_tool/user_virtualCryptSHA.py %{python3_sitearch}/samba/tests/samba_tool/user_virtualCryptSHA_base.py %{python3_sitearch}/samba/tests/samba_tool/user_virtualCryptSHA_gpg.py @@ -2697,19 +3849,41 @@ fi %{python3_sitearch}/samba/tests/samba_tool/visualize_drs.py %{python3_sitearch}/samba/tests/samdb.py %{python3_sitearch}/samba/tests/samdb_api.py +%{python3_sitearch}/samba/tests/sddl.py +%{python3_sitearch}/samba/tests/sddl_conditional_ace.py %{python3_sitearch}/samba/tests/security.py +%{python3_sitearch}/samba/tests/security_descriptors.py %{python3_sitearch}/samba/tests/segfault.py +%{python3_sitearch}/samba/tests/sid_strings.py %{python3_sitearch}/samba/tests/smb.py +%{python3_sitearch}/samba/tests/smb1posix.py +%{python3_sitearch}/samba/tests/smb2symlink.py +%{python3_sitearch}/samba/tests/smb3unix.py +%{python3_sitearch}/samba/tests/smbconf.py +%{python3_sitearch}/samba/tests/smb-notify.py %{python3_sitearch}/samba/tests/smbd_base.py %{python3_sitearch}/samba/tests/smbd_fuzztest.py %{python3_sitearch}/samba/tests/source.py +%{python3_sitearch}/samba/tests/source_chars.py %{python3_sitearch}/samba/tests/strings.py %{python3_sitearch}/samba/tests/subunitrun.py %{python3_sitearch}/samba/tests/tdb_util.py +%{python3_sitearch}/samba/tests/token_factory.py +%{python3_sitearch}/samba/tests/tpm20_rsakey_blob.py %{python3_sitearch}/samba/tests/upgrade.py %{python3_sitearch}/samba/tests/upgradeprovision.py %{python3_sitearch}/samba/tests/upgradeprovisionneeddc.py %{python3_sitearch}/samba/tests/usage.py +%dir %{python3_sitearch}/samba/tests/varlink +%dir %{python3_sitearch}/samba/tests/varlink/__pycache__ +%{python3_sitearch}/samba/tests/varlink/__pycache__/base.*.pyc +%{python3_sitearch}/samba/tests/varlink/__pycache__/getgrouprecord.*.pyc +%{python3_sitearch}/samba/tests/varlink/__pycache__/getmemberships.*.pyc +%{python3_sitearch}/samba/tests/varlink/__pycache__/getuserrecord.*.pyc +%{python3_sitearch}/samba/tests/varlink/base.py +%{python3_sitearch}/samba/tests/varlink/getgrouprecord.py +%{python3_sitearch}/samba/tests/varlink/getmemberships.py +%{python3_sitearch}/samba/tests/varlink/getuserrecord.py %{python3_sitearch}/samba/tests/xattr.py ### TEST @@ -2724,30 +3898,27 @@ fi %{_mandir}/man1/masktest.1* %{_mandir}/man1/ndrdump.1* %{_mandir}/man1/smbtorture.1* -%{_mandir}/man1/vfstest.1* - -%if %{with testsuite} -# files to ignore in testsuite mode -%{_libdir}/samba/libnss-wrapper.so -%{_libdir}/samba/libsocket-wrapper.so -%{_libdir}/samba/libuid-wrapper.so -%endif ### TEST-LIBS %files test-libs -%if %with_dc -%{_libdir}/samba/libdlz-bind9-for-torture-samba4.so -%else -%{_libdir}/samba/libdsdb-module-samba4.so +%if %{with dc} +%{_libdir}/samba/libdlz-bind9-for-torture-private-samba.so %endif +### USERSHARES +%files usershares +%config(noreplace) %{_sysconfdir}/samba/usershares.conf +%attr(1770,root,usershares) %dir /var/lib/samba/usershares +%{_sysusersdir}/samba-usershares.conf + ### WINBIND %files winbind %{_libdir}/samba/idmap %{_libdir}/samba/nss_info -%{_libdir}/samba/libnss-info-samba4.so -%{_libdir}/samba/libidmap-samba4.so +%{_libdir}/samba/libnss-info-private-samba.so +%{_libdir}/samba/libidmap-private-samba.so %{_sbindir}/winbindd +%{_sysusersdir}/samba-winbind.conf %attr(750,root,wbpriv) %dir /var/lib/samba/winbindd_privileged %{_unitdir}/winbind.service %{_prefix}/lib/NetworkManager @@ -2768,6 +3939,8 @@ fi %ghost %{_libdir}/krb5/plugins/libkrb5/winbind_krb5_locator.so %dir %{_libdir}/samba/krb5 %{_libdir}/samba/krb5/winbind_krb5_locator.so +# correct rpm package? +%{_libdir}/samba/krb5/async_dns_krb5_locator.so %{_mandir}/man8/winbind_krb5_locator.8* ### WINBIND-MODULES @@ -2778,8 +3951,9 @@ fi %config(noreplace) %{_sysconfdir}/security/pam_winbind.conf %{_mandir}/man5/pam_winbind.conf.5* %{_mandir}/man8/pam_winbind.8* +%{_datadir}/locale/*/LC_MESSAGES/pam_winbind.mo -%if %with_clustering_support +%if %{with clustering} %files -n ctdb %doc ctdb/README %doc ctdb/doc/examples @@ -2790,13 +3964,13 @@ fi %config(noreplace) %{_sysconfdir}/ctdb/ctdb.conf %config(noreplace) %{_sysconfdir}/ctdb/notify.sh %config(noreplace) %{_sysconfdir}/ctdb/debug-hung-script.sh +%config(noreplace) %{_sysconfdir}/ctdb/ctdb-backup-persistent-tdbs.sh %config(noreplace) %{_sysconfdir}/ctdb/ctdb-crash-cleanup.sh %config(noreplace) %{_sysconfdir}/ctdb/debug_locks.sh %{_sysconfdir}/ctdb/functions %{_sysconfdir}/ctdb/nfs-linux-kernel-callout -%{_sysconfdir}/ctdb/statd-callout -%config %{_sysconfdir}/sudoers.d/ctdb +%ghost %{_sysconfdir}/ctdb/statd-callout # CTDB scripts, no config files # script with executable bit means activated @@ -2817,13 +3991,11 @@ fi %config(noreplace) %{_sysconfdir}/ctdb/nfs-checks.d/50.rquotad.check %{_sbindir}/ctdbd -%{_sbindir}/ctdbd_wrapper %{_bindir}/ctdb -%{_bindir}/ctdb_local_daemons -%{_bindir}/ping_pong -%{_bindir}/ltdbtool %{_bindir}/ctdb_diagnostics +%{_bindir}/ltdbtool %{_bindir}/onnode +%{_bindir}/ping_pong %dir %{_libexecdir}/ctdb %{_libexecdir}/ctdb/ctdb-config @@ -2836,8 +4008,11 @@ fi %{_libexecdir}/ctdb/ctdb_natgw %{_libexecdir}/ctdb/ctdb-path %{_libexecdir}/ctdb/ctdb_recovery_helper +%{_libexecdir}/ctdb/ctdb_smnotify_helper %{_libexecdir}/ctdb/ctdb_takeover_helper -%{_libexecdir}/ctdb/smnotify +%{_libexecdir}/ctdb/statd_callout +%{_libexecdir}/ctdb/statd_callout_helper +%{_libexecdir}/ctdb/tdb_mutex_check %dir %{_localstatedir}/lib/ctdb/ %dir %{_localstatedir}/lib/ctdb/persistent @@ -2850,7 +4025,6 @@ fi %{_mandir}/man1/onnode.1.gz %{_mandir}/man1/ltdbtool.1.gz %{_mandir}/man1/ping_pong.1.gz -%{_mandir}/man1/ctdbd_wrapper.1.gz %{_mandir}/man5/ctdb.conf.5.gz %{_mandir}/man5/ctdb-script.options.5.gz %{_mandir}/man5/ctdb.sysconfig.5.gz @@ -2858,6 +4032,8 @@ fi %{_mandir}/man7/ctdb-tunables.7.gz %{_mandir}/man7/ctdb-statistics.7.gz +%ghost %dir /run/ctdb + %{_tmpfilesdir}/ctdb.conf %{_unitdir}/ctdb.service @@ -2868,7 +4044,6 @@ fi %{_datadir}/ctdb/events/legacy/00.ctdb.script %{_datadir}/ctdb/events/legacy/01.reclock.script %{_datadir}/ctdb/events/legacy/05.system.script -%{_datadir}/ctdb/events/legacy/06.nfs.script %{_datadir}/ctdb/events/legacy/10.interface.script %{_datadir}/ctdb/events/legacy/11.natgw.script %{_datadir}/ctdb/events/legacy/11.routing.script @@ -2877,795 +4052,46 @@ fi %{_datadir}/ctdb/events/legacy/31.clamd.script %{_datadir}/ctdb/events/legacy/40.vsftpd.script %{_datadir}/ctdb/events/legacy/41.httpd.script +%{_datadir}/ctdb/events/legacy/46.update-keytabs.script +%{_datadir}/ctdb/events/legacy/47.samba-dcerpcd.script %{_datadir}/ctdb/events/legacy/48.netbios.script %{_datadir}/ctdb/events/legacy/49.winbind.script %{_datadir}/ctdb/events/legacy/50.samba.script %{_datadir}/ctdb/events/legacy/60.nfs.script %{_datadir}/ctdb/events/legacy/70.iscsi.script %{_datadir}/ctdb/events/legacy/91.lvs.script +%{_datadir}/ctdb/events/legacy/95.database.script +%dir %{_datadir}/ctdb/scripts +%{_datadir}/ctdb/scripts/winbind_ctdb_updatekeytab.sh -%files -n ctdb-tests -%doc ctdb/tests/README -%{_bindir}/ctdb_run_tests -%{_bindir}/ctdb_run_cluster_tests +%if %{with pcp_pmda} +%files -n ctdb-pcp-pmda +%dir %{_localstatedir}/lib/pcp/pmdas/ctdb +%{_localstatedir}/lib/pcp/pmdas/ctdb/Install +%{_localstatedir}/lib/pcp/pmdas/ctdb/README +%{_localstatedir}/lib/pcp/pmdas/ctdb/Remove +%{_localstatedir}/lib/pcp/pmdas/ctdb/domain.h +%{_localstatedir}/lib/pcp/pmdas/ctdb/help +%{_localstatedir}/lib/pcp/pmdas/ctdb/pmdactdb +%{_localstatedir}/lib/pcp/pmdas/ctdb/pmns +#endif with pcp_pmda +%endif -%dir %{_libexecdir}/ctdb -%dir %{_libexecdir}/ctdb/tests -%{_libexecdir}/ctdb/tests/cluster_mutex_test -%{_libexecdir}/ctdb/tests/cmdline_test -%{_libexecdir}/ctdb/tests/comm_client_test -%{_libexecdir}/ctdb/tests/comm_server_test -%{_libexecdir}/ctdb/tests/comm_test -%{_libexecdir}/ctdb/tests/conf_test -%{_libexecdir}/ctdb/tests/ctdb-db-test -%{_libexecdir}/ctdb/tests/ctdb_io_test -%{_libexecdir}/ctdb/tests/ctdb_packet_parse -%{_libexecdir}/ctdb/tests/ctdb_takeover_tests -%{_libexecdir}/ctdb/tests/db_hash_test -%{_libexecdir}/ctdb/tests/dummy_client -%{_libexecdir}/ctdb/tests/errcode -%{_libexecdir}/ctdb/tests/event_protocol_test -%{_libexecdir}/ctdb/tests/event_script_test -%{_libexecdir}/ctdb/tests/fake_ctdbd -%{_libexecdir}/ctdb/tests/fetch_loop -%{_libexecdir}/ctdb/tests/fetch_loop_key -%{_libexecdir}/ctdb/tests/fetch_readonly -%{_libexecdir}/ctdb/tests/fetch_readonly_loop -%{_libexecdir}/ctdb/tests/fetch_ring -%{_libexecdir}/ctdb/tests/g_lock_loop -%{_libexecdir}/ctdb/tests/hash_count_test -%{_libexecdir}/ctdb/tests/line_test -%{_libexecdir}/ctdb/tests/lock_tdb -%{_libexecdir}/ctdb/tests/message_ring -%{_libexecdir}/ctdb/tests/pidfile_test -%{_libexecdir}/ctdb/tests/pkt_read_test -%{_libexecdir}/ctdb/tests/pkt_write_test -%{_libexecdir}/ctdb/tests/porting_tests -%{_libexecdir}/ctdb/tests/protocol_basic_test -%{_libexecdir}/ctdb/tests/protocol_ctdb_compat_test -%{_libexecdir}/ctdb/tests/protocol_ctdb_test -%{_libexecdir}/ctdb/tests/protocol_types_compat_test -%{_libexecdir}/ctdb/tests/protocol_types_test -%{_libexecdir}/ctdb/tests/protocol_util_test -%{_libexecdir}/ctdb/tests/rb_test -%{_libexecdir}/ctdb/tests/reqid_test -%{_libexecdir}/ctdb/tests/run_event_test -%{_libexecdir}/ctdb/tests/run_proc_test -%{_libexecdir}/ctdb/tests/sigcode -%{_libexecdir}/ctdb/tests/sock_daemon_test -%{_libexecdir}/ctdb/tests/sock_io_test -%{_libexecdir}/ctdb/tests/srvid_test -%{_libexecdir}/ctdb/tests/system_socket_test -%{_libexecdir}/ctdb/tests/transaction_loop -%{_libexecdir}/ctdb/tests/tunnel_cmd -%{_libexecdir}/ctdb/tests/tunnel_test -%{_libexecdir}/ctdb/tests/update_record -%{_libexecdir}/ctdb/tests/update_record_persistent +%if %{with etcd_mutex} +%files -n ctdb-etcd-mutex +%{_libexecdir}/ctdb/ctdb_etcd_lock +%{_mandir}/man7/ctdb-etcd.7.gz +#endif with etcd_mutex +%endif -%dir %{_datadir}/ctdb/tests -%dir %{_datadir}/ctdb/tests/CLUSTER -%dir %{_datadir}/ctdb/tests/CLUSTER/complex -%{_datadir}/ctdb/tests/CLUSTER/complex/11_ctdb_delip_removes_ip.sh -%{_datadir}/ctdb/tests/CLUSTER/complex/18_ctdb_reloadips.sh -%{_datadir}/ctdb/tests/CLUSTER/complex/30_nfs_tickle_killtcp.sh -%{_datadir}/ctdb/tests/CLUSTER/complex/31_nfs_tickle.sh -%{_datadir}/ctdb/tests/CLUSTER/complex/32_cifs_tickle.sh -%{_datadir}/ctdb/tests/CLUSTER/complex/33_gratuitous_arp.sh -%{_datadir}/ctdb/tests/CLUSTER/complex/34_nfs_tickle_restart.sh -%{_datadir}/ctdb/tests/CLUSTER/complex/36_smb_reset_server.sh -%{_datadir}/ctdb/tests/CLUSTER/complex/37_nfs_reset_server.sh -%{_datadir}/ctdb/tests/CLUSTER/complex/41_failover_ping_discrete.sh -%{_datadir}/ctdb/tests/CLUSTER/complex/42_failover_ssh_hostname.sh -%{_datadir}/ctdb/tests/CLUSTER/complex/43_failover_nfs_basic.sh -%{_datadir}/ctdb/tests/CLUSTER/complex/44_failover_nfs_oneway.sh -%{_datadir}/ctdb/tests/CLUSTER/complex/45_failover_nfs_kill.sh -%{_datadir}/ctdb/tests/CLUSTER/complex/60_rogueip_releaseip.sh -%{_datadir}/ctdb/tests/CLUSTER/complex/61_rogueip_takeip.sh -%{_datadir}/ctdb/tests/CLUSTER/complex/README +%if %{with ceph_mutex} +%files -n ctdb-ceph-mutex +%{_libexecdir}/ctdb/ctdb_mutex_ceph_rados_helper +%{_mandir}/man7/ctdb_mutex_ceph_rados_helper.7.gz +#endif with ceph_mutex +%endif -%dir %{_datadir}/ctdb/tests/CLUSTER/complex/scripts -%{_datadir}/ctdb/tests/CLUSTER/complex/scripts/local.bash - -%dir %{_datadir}/ctdb/tests/etc-ctdb -%dir %{_datadir}/ctdb/tests/etc-ctdb/events -%dir %{_datadir}/ctdb/tests/etc-ctdb/events/legacy -%{_datadir}/ctdb/tests/etc-ctdb/events/legacy/00.test.script -%dir %{_datadir}/ctdb/tests/INTEGRATION -%dir %{_datadir}/ctdb/tests/INTEGRATION/database -%{_datadir}/ctdb/tests/INTEGRATION/database/basics.001.attach.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/basics.002.attach.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/basics.003.detach.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/basics.004.wipe.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/basics.010.backup_restore.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/fetch.001.ring.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/fetch.002.ring-hotkeys.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/readonly.001.basic.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/recovery.001.volatile.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/recovery.002.large.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/recovery.003.no_resurrect.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/recovery.010.persistent.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/recovery.011.continue.sh -%dir %{_datadir}/ctdb/tests/INTEGRATION/database/scripts -%{_datadir}/ctdb/tests/INTEGRATION/database/scripts/local.bash -%{_datadir}/ctdb/tests/INTEGRATION/database/transaction.001.ptrans.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/transaction.002.loop.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/transaction.003.loop_recovery.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/transaction.004.update_record.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/transaction.010.loop_recovery.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/traverse.001.one.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/traverse.002.many.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/vacuum.001.fast.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/vacuum.002.full.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/vacuum.003.recreate.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/vacuum.030.locked.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/vacuum.031.locked.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/vacuum.032.locked.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/vacuum.033.locked.sh -%{_datadir}/ctdb/tests/INTEGRATION/database/vacuum.034.locked.sh -%dir %{_datadir}/ctdb/tests/INTEGRATION/failover -%{_datadir}/ctdb/tests/INTEGRATION/failover/pubips.001.list.sh -%{_datadir}/ctdb/tests/INTEGRATION/failover/pubips.010.addip.sh -%{_datadir}/ctdb/tests/INTEGRATION/failover/pubips.011.delip.sh -%{_datadir}/ctdb/tests/INTEGRATION/failover/pubips.012.reloadips.sh -%{_datadir}/ctdb/tests/INTEGRATION/failover/pubips.013.failover_noop.sh -%{_datadir}/ctdb/tests/INTEGRATION/failover/pubips.014.iface_gc.sh -%{_datadir}/ctdb/tests/INTEGRATION/failover/pubips.020.moveip.sh -%{_datadir}/ctdb/tests/INTEGRATION/failover/pubips.030.disable_enable.sh -%{_datadir}/ctdb/tests/INTEGRATION/failover/pubips.032.stop_continue.sh -%{_datadir}/ctdb/tests/INTEGRATION/failover/pubips.040.NoIPTakeover.sh -%{_datadir}/ctdb/tests/INTEGRATION/failover/pubips.050.missing_ip.sh -%dir %{_datadir}/ctdb/tests/INTEGRATION/simple -%{_datadir}/ctdb/tests/INTEGRATION/simple/basics.000.onnode.sh -%{_datadir}/ctdb/tests/INTEGRATION/simple/basics.001.listnodes.sh -%{_datadir}/ctdb/tests/INTEGRATION/simple/basics.002.tunables.sh -%{_datadir}/ctdb/tests/INTEGRATION/simple/basics.003.ping.sh -%{_datadir}/ctdb/tests/INTEGRATION/simple/basics.004.getpid.sh -%{_datadir}/ctdb/tests/INTEGRATION/simple/basics.005.process_exists.sh -%{_datadir}/ctdb/tests/INTEGRATION/simple/basics.010.statistics.sh -%{_datadir}/ctdb/tests/INTEGRATION/simple/basics.011.statistics_reset.sh -%{_datadir}/ctdb/tests/INTEGRATION/simple/cluster.001.isnotrecmaster.sh -%{_datadir}/ctdb/tests/INTEGRATION/simple/cluster.002.recmaster_yield.sh -%{_datadir}/ctdb/tests/INTEGRATION/simple/cluster.010.getrelock.sh -%{_datadir}/ctdb/tests/INTEGRATION/simple/cluster.012.reclock_command.sh -%{_datadir}/ctdb/tests/INTEGRATION/simple/cluster.015.reclock_remove_lock.sh -%{_datadir}/ctdb/tests/INTEGRATION/simple/cluster.016.reclock_move_lock_dir.sh -%{_datadir}/ctdb/tests/INTEGRATION/simple/cluster.020.message_ring.sh -%{_datadir}/ctdb/tests/INTEGRATION/simple/cluster.021.tunnel_ring.sh -%{_datadir}/ctdb/tests/INTEGRATION/simple/cluster.090.unreachable.sh -%{_datadir}/ctdb/tests/INTEGRATION/simple/cluster.091.version_check.sh -%{_datadir}/ctdb/tests/INTEGRATION/simple/debug.001.getdebug.sh -%{_datadir}/ctdb/tests/INTEGRATION/simple/debug.002.setdebug.sh -%{_datadir}/ctdb/tests/INTEGRATION/simple/debug.003.dumpmemory.sh -%{_datadir}/ctdb/tests/INTEGRATION/simple/eventscripts.001.zero_scripts.sh -%{_datadir}/ctdb/tests/INTEGRATION/simple/eventscripts.090.debug_hung.sh -%{_datadir}/ctdb/tests/INTEGRATION/simple/README -%dir %{_datadir}/ctdb/tests/scripts -%{_datadir}/ctdb/tests/scripts/cluster.bash -%{_datadir}/ctdb/tests/scripts/common.sh -%{_datadir}/ctdb/tests/scripts/integration.bash -%{_datadir}/ctdb/tests/scripts/integration_local_daemons.bash -%{_datadir}/ctdb/tests/scripts/integration_real_cluster.bash -%{_datadir}/ctdb/tests/scripts/script_install_paths.sh -%{_datadir}/ctdb/tests/scripts/test_wrap -%{_datadir}/ctdb/tests/scripts/unit.sh -%dir %{_datadir}/ctdb/tests/UNIT -%dir %{_datadir}/ctdb/tests/UNIT/cunit -%{_datadir}/ctdb/tests/UNIT/cunit/cluster_mutex_001.sh -%{_datadir}/ctdb/tests/UNIT/cunit/cluster_mutex_002.sh -%{_datadir}/ctdb/tests/UNIT/cunit/cluster_mutex_003.sh -%{_datadir}/ctdb/tests/UNIT/cunit/cmdline_test_001.sh -%{_datadir}/ctdb/tests/UNIT/cunit/comm_test_001.sh -%{_datadir}/ctdb/tests/UNIT/cunit/comm_test_002.sh -%{_datadir}/ctdb/tests/UNIT/cunit/config_test_001.sh -%{_datadir}/ctdb/tests/UNIT/cunit/config_test_002.sh -%{_datadir}/ctdb/tests/UNIT/cunit/config_test_003.sh -%{_datadir}/ctdb/tests/UNIT/cunit/config_test_004.sh -%{_datadir}/ctdb/tests/UNIT/cunit/config_test_005.sh -%{_datadir}/ctdb/tests/UNIT/cunit/config_test_006.sh -%{_datadir}/ctdb/tests/UNIT/cunit/config_test_007.sh -%{_datadir}/ctdb/tests/UNIT/cunit/conf_test_001.sh -%{_datadir}/ctdb/tests/UNIT/cunit/ctdb_io_test_001.sh -%{_datadir}/ctdb/tests/UNIT/cunit/db_hash_test_001.sh -%{_datadir}/ctdb/tests/UNIT/cunit/event_protocol_test_001.sh -%{_datadir}/ctdb/tests/UNIT/cunit/event_script_test_001.sh -%{_datadir}/ctdb/tests/UNIT/cunit/hash_count_test_001.sh -%{_datadir}/ctdb/tests/UNIT/cunit/line_test_001.sh -%{_datadir}/ctdb/tests/UNIT/cunit/path_tests_001.sh -%{_datadir}/ctdb/tests/UNIT/cunit/pidfile_test_001.sh -%{_datadir}/ctdb/tests/UNIT/cunit/pkt_read_001.sh -%{_datadir}/ctdb/tests/UNIT/cunit/pkt_write_001.sh -%{_datadir}/ctdb/tests/UNIT/cunit/porting_tests_001.sh -%{_datadir}/ctdb/tests/UNIT/cunit/protocol_test_001.sh -%{_datadir}/ctdb/tests/UNIT/cunit/protocol_test_002.sh -%{_datadir}/ctdb/tests/UNIT/cunit/protocol_test_012.sh -%{_datadir}/ctdb/tests/UNIT/cunit/protocol_test_101.sh -%{_datadir}/ctdb/tests/UNIT/cunit/protocol_test_111.sh -%{_datadir}/ctdb/tests/UNIT/cunit/protocol_test_201.sh -%{_datadir}/ctdb/tests/UNIT/cunit/rb_test_001.sh -%{_datadir}/ctdb/tests/UNIT/cunit/reqid_test_001.sh -%{_datadir}/ctdb/tests/UNIT/cunit/run_event_001.sh -%{_datadir}/ctdb/tests/UNIT/cunit/run_proc_001.sh -%{_datadir}/ctdb/tests/UNIT/cunit/sock_daemon_test_001.sh -%{_datadir}/ctdb/tests/UNIT/cunit/sock_io_test_001.sh -%{_datadir}/ctdb/tests/UNIT/cunit/srvid_test_001.sh -%{_datadir}/ctdb/tests/UNIT/cunit/system_socket_test_001.sh -%{_datadir}/ctdb/tests/UNIT/cunit/system_socket_test_002.sh -%{_datadir}/ctdb/tests/UNIT/cunit/system_socket_test_003.sh -%dir %{_datadir}/ctdb/tests/UNIT/eventd -%dir %{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb -%{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/ctdb.conf -%{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/debug-script.sh -%dir %{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/events -%dir %{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/events/data -%{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/events/data/03.notalink.script -%{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/events/data/README -%dir %{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/events/empty -%{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/events/empty/README -%dir %{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/events/multi -%{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/events/multi/01.test.script -%{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/events/multi/02.test.script -%{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/events/multi/03.test.script -%dir %{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/events/random -%{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/events/random/01.disabled.script -%{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/events/random/02.enabled.script -%{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/events/random/a.script -%{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/events/random/README.script -%dir %{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/share -%dir %{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/share/events -%dir %{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/share/events/data -%{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/share/events/data/01.dummy.script -%{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/share/events/data/02.disabled.script -%dir %{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/share/events/empty -%{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/share/events/empty/README -%dir %{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/share/events/random -%{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/share/events/random/01.disabled.script -%{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/share/events/random/02.enabled.script -%{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/share/events/random/a.script -%{_datadir}/ctdb/tests/UNIT/eventd/etc-ctdb/share/events/random/README.script -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_001.sh -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_002.sh -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_003.sh -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_004.sh -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_005.sh -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_006.sh -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_007.sh -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_008.sh -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_009.sh -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_011.sh -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_012.sh -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_013.sh -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_014.sh -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_021.sh -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_022.sh -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_023.sh -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_024.sh -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_031.sh -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_032.sh -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_033.sh -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_041.sh -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_042.sh -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_043.sh -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_044.sh -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_051.sh -%{_datadir}/ctdb/tests/UNIT/eventd/eventd_052.sh -%{_datadir}/ctdb/tests/UNIT/eventd/README -%dir %{_datadir}/ctdb/tests/UNIT/eventd/scripts -%{_datadir}/ctdb/tests/UNIT/eventd/scripts/local.sh -%dir %{_datadir}/ctdb/tests/UNIT/eventscripts -%{_datadir}/ctdb/tests/UNIT/eventscripts/00.ctdb.init.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/00.ctdb.init.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/00.ctdb.init.003.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/00.ctdb.init.004.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/00.ctdb.init.005.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/00.ctdb.init.006.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/00.ctdb.init.007.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/00.ctdb.init.008.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/00.ctdb.init.009.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/00.ctdb.setup.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/00.ctdb.setup.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/00.ctdb.setup.003.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/00.ctdb.setup.004.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/01.reclock.init.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/01.reclock.init.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/01.reclock.init.003.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/05.system.monitor.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/05.system.monitor.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/05.system.monitor.003.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/05.system.monitor.004.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/05.system.monitor.005.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/05.system.monitor.006.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/05.system.monitor.007.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/05.system.monitor.011.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/05.system.monitor.012.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/05.system.monitor.014.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/05.system.monitor.015.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/05.system.monitor.017.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/05.system.monitor.018.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/06.nfs.releaseip.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/06.nfs.releaseip.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/06.nfs.takeip.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/06.nfs.takeip.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.010.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.011.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.012.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.013.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.init.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.init.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.init.021.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.init.022.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.init.023.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.monitor.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.monitor.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.monitor.003.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.monitor.004.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.monitor.005.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.monitor.006.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.monitor.009.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.monitor.010.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.monitor.011.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.monitor.012.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.monitor.013.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.monitor.014.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.monitor.015.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.monitor.016.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.monitor.017.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.monitor.018.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.multi.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.releaseip.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.releaseip.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.startup.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.startup.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.takeip.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.takeip.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/10.interface.takeip.003.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/11.natgw.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/11.natgw.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/11.natgw.003.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/11.natgw.004.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/11.natgw.011.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/11.natgw.012.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/11.natgw.013.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/11.natgw.014.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/11.natgw.015.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/11.natgw.021.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/11.natgw.022.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/11.natgw.023.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/11.natgw.024.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/11.natgw.025.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/11.natgw.031.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/11.natgw.041.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/11.natgw.042.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/11.natgw.051.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/11.natgw.052.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/11.natgw.053.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/11.natgw.054.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/13.per_ip_routing.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/13.per_ip_routing.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/13.per_ip_routing.003.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/13.per_ip_routing.004.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/13.per_ip_routing.005.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/13.per_ip_routing.006.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/13.per_ip_routing.007.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/13.per_ip_routing.008.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/13.per_ip_routing.009.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/13.per_ip_routing.010.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/13.per_ip_routing.011.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/13.per_ip_routing.012.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/13.per_ip_routing.013.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/13.per_ip_routing.014.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/13.per_ip_routing.015.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/13.per_ip_routing.016.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/13.per_ip_routing.017.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/13.per_ip_routing.018.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/13.per_ip_routing.019.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/13.per_ip_routing.021.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/13.per_ip_routing.022.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/13.per_ip_routing.023.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/13.per_ip_routing.024.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/20.multipathd.monitor.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/20.multipathd.monitor.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/20.multipathd.monitor.003.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/20.multipathd.monitor.004.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/31.clamd.monitor.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/31.clamd.monitor.003.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/40.vsftpd.monitor.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/40.vsftpd.shutdown.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/40.vsftpd.startup.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/41.httpd.monitor.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/41.httpd.shutdown.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/41.httpd.startup.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/48.netbios.shutdown.011.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/48.netbios.startup.011.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/49.winbind.monitor.101.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/49.winbind.monitor.102.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/49.winbind.shutdown.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/49.winbind.startup.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/50.samba.monitor.101.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/50.samba.monitor.103.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/50.samba.monitor.104.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/50.samba.monitor.105.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/50.samba.monitor.106.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/50.samba.monitor.110.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/50.samba.monitor.111.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/50.samba.monitor.112.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/50.samba.monitor.113.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/50.samba.shutdown.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/50.samba.shutdown.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/50.samba.shutdown.011.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/50.samba.startup.011.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.101.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.102.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.103.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.104.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.105.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.106.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.107.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.108.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.109.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.111.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.112.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.113.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.114.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.121.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.122.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.131.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.132.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.141.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.142.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.143.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.144.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.151.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.152.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.153.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.161.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.monitor.162.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.multi.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.multi.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.releaseip.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.releaseip.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.shutdown.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.shutdown.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.startup.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.startup.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.takeip.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/60.nfs.takeip.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/91.lvs.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/91.lvs.ipreallocated.011.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/91.lvs.ipreallocated.012.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/91.lvs.ipreallocated.013.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/91.lvs.ipreallocated.014.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/91.lvs.monitor.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/91.lvs.monitor.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/91.lvs.monitor.003.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/91.lvs.shutdown.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/91.lvs.shutdown.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/91.lvs.startup.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/91.lvs.startup.002.sh -%dir %{_datadir}/ctdb/tests/UNIT/eventscripts/etc -%dir %{_datadir}/ctdb/tests/UNIT/eventscripts/etc-ctdb -%{_datadir}/ctdb/tests/UNIT/eventscripts/etc-ctdb/public_addresses -%{_datadir}/ctdb/tests/UNIT/eventscripts/etc-ctdb/rc.local -%dir %{_datadir}/ctdb/tests/UNIT/eventscripts/etc/init.d -%{_datadir}/ctdb/tests/UNIT/eventscripts/etc/init.d/nfs -%{_datadir}/ctdb/tests/UNIT/eventscripts/etc/init.d/nfslock -%dir %{_datadir}/ctdb/tests/UNIT/eventscripts/etc/samba -%{_datadir}/ctdb/tests/UNIT/eventscripts/etc/samba/smb.conf -%dir %{_datadir}/ctdb/tests/UNIT/eventscripts/etc/sysconfig -%{_datadir}/ctdb/tests/UNIT/eventscripts/etc/sysconfig/nfs -%{_datadir}/ctdb/tests/UNIT/eventscripts/README -%dir %{_datadir}/ctdb/tests/UNIT/eventscripts/scripts -%{_datadir}/ctdb/tests/UNIT/eventscripts/scripts/00.ctdb.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/scripts/01.reclock.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/scripts/05.system.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/scripts/06.nfs.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/scripts/10.interface.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/scripts/11.natgw.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/scripts/13.per_ip_routing.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/scripts/20.multipathd.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/scripts/31.clamd.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/scripts/40.vsftpd.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/scripts/41.httpd.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/scripts/48.netbios.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/scripts/49.winbind.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/scripts/50.samba.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/scripts/60.nfs.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/scripts/91.lvs.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/scripts/local.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/scripts/statd-callout.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/statd-callout.001.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/statd-callout.002.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/statd-callout.003.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/statd-callout.004.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/statd-callout.005.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/statd-callout.006.sh -%{_datadir}/ctdb/tests/UNIT/eventscripts/statd-callout.007.sh -%dir %{_datadir}/ctdb/tests/UNIT/eventscripts/stubs -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/ctdb -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/ctdb-config -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/ctdb_killtcp -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/ctdb_lvs -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/ctdb_natgw -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/date -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/df -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/ethtool -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/exportfs -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/id -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/ip -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/ip6tables -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/iptables -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/ipvsadm -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/kill -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/killall -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/multipath -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/nfsconf -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/net -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/pidof -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/pkill -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/ps -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/rm -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/rpcinfo -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/rpc.lockd -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/rpc.mountd -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/rpc.rquotad -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/rpc.statd -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/service -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/sleep -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/smnotify -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/ss -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/tdbdump -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/tdbtool -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/testparm -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/timeout -%{_datadir}/ctdb/tests/UNIT/eventscripts/stubs/wbinfo -%dir %{_datadir}/ctdb/tests/UNIT/onnode -%{_datadir}/ctdb/tests/UNIT/onnode/0001.sh -%{_datadir}/ctdb/tests/UNIT/onnode/0002.sh -%{_datadir}/ctdb/tests/UNIT/onnode/0003.sh -%{_datadir}/ctdb/tests/UNIT/onnode/0004.sh -%{_datadir}/ctdb/tests/UNIT/onnode/0005.sh -%{_datadir}/ctdb/tests/UNIT/onnode/0006.sh -%{_datadir}/ctdb/tests/UNIT/onnode/0010.sh -%{_datadir}/ctdb/tests/UNIT/onnode/0011.sh -%{_datadir}/ctdb/tests/UNIT/onnode/0070.sh -%{_datadir}/ctdb/tests/UNIT/onnode/0071.sh -%{_datadir}/ctdb/tests/UNIT/onnode/0072.sh -%{_datadir}/ctdb/tests/UNIT/onnode/0075.sh -%dir %{_datadir}/ctdb/tests/UNIT/onnode/etc-ctdb -%{_datadir}/ctdb/tests/UNIT/onnode/etc-ctdb/nodes -%dir %{_datadir}/ctdb/tests/UNIT/onnode/scripts -%{_datadir}/ctdb/tests/UNIT/onnode/scripts/local.sh -%dir %{_datadir}/ctdb/tests/UNIT/onnode/stubs -%{_datadir}/ctdb/tests/UNIT/onnode/stubs/ctdb -%{_datadir}/ctdb/tests/UNIT/onnode/stubs/ssh -%dir %{_datadir}/ctdb/tests/UNIT/shellcheck -%{_datadir}/ctdb/tests/UNIT/shellcheck/base_scripts.sh -%{_datadir}/ctdb/tests/UNIT/shellcheck/ctdbd_wrapper.sh -%{_datadir}/ctdb/tests/UNIT/shellcheck/ctdb_helpers.sh -%{_datadir}/ctdb/tests/UNIT/shellcheck/event_scripts.sh -%{_datadir}/ctdb/tests/UNIT/shellcheck/functions.sh -%{_datadir}/ctdb/tests/UNIT/shellcheck/init_script.sh -%dir %{_datadir}/ctdb/tests/UNIT/shellcheck/scripts -%{_datadir}/ctdb/tests/UNIT/shellcheck/scripts/local.sh -%{_datadir}/ctdb/tests/UNIT/shellcheck/tests.sh -%{_datadir}/ctdb/tests/UNIT/shellcheck/tools.sh -%dir %{_datadir}/ctdb/tests/UNIT/takeover -%{_datadir}/ctdb/tests/UNIT/takeover/det.001.sh -%{_datadir}/ctdb/tests/UNIT/takeover/det.002.sh -%{_datadir}/ctdb/tests/UNIT/takeover/det.003.sh -%dir %{_datadir}/ctdb/tests/UNIT/takeover_helper -%{_datadir}/ctdb/tests/UNIT/takeover_helper/000.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/010.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/011.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/012.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/013.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/014.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/016.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/017.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/018.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/019.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/021.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/022.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/023.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/024.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/025.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/026.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/027.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/028.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/030.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/031.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/110.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/111.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/120.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/121.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/122.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/130.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/131.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/132.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/140.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/150.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/160.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/210.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/211.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/220.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/230.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/240.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/250.sh -%{_datadir}/ctdb/tests/UNIT/takeover_helper/260.sh -%dir %{_datadir}/ctdb/tests/UNIT/takeover_helper/scripts -%{_datadir}/ctdb/tests/UNIT/takeover_helper/scripts/local.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.001.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.002.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.003.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.004.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.005.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.006.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.007.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.008.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.009.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.010.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.011.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.012.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.013.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.014.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.015.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.016.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.024.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.025.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.027.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.028.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.029.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.030.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.031.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.032.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.033.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.034.sh -%{_datadir}/ctdb/tests/UNIT/takeover/lcp2.035.sh -%{_datadir}/ctdb/tests/UNIT/takeover/nondet.001.sh -%{_datadir}/ctdb/tests/UNIT/takeover/nondet.002.sh -%{_datadir}/ctdb/tests/UNIT/takeover/nondet.003.sh -%{_datadir}/ctdb/tests/UNIT/takeover/README -%dir %{_datadir}/ctdb/tests/UNIT/takeover/scripts -%{_datadir}/ctdb/tests/UNIT/takeover/scripts/local.sh -%dir %{_datadir}/ctdb/tests/UNIT/tool -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.attach.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.attach.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.attach.003.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.ban.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.ban.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.ban.003.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.catdb.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.catdb.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.cattdb.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.cattdb.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.continue.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.continue.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.continue.003.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.deletekey.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.disable.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.disable.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.disable.003.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.disable.004.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.enable.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.enable.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.enable.003.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.getcapabilities.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.getcapabilities.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.getcapabilities.003.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.getcapabilities.004.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.getdbmap.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.getdbseqnum.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.getdbseqnum.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.getdbstatus.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.getdbstatus.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.getpid.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.getpid.010.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.getreclock.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.getreclock.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.getvar.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.getvar.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.ifaces.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.ip.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.ip.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.ip.003.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.ip.004.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.ip.005.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.ip.006.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.ip.007.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.ipinfo.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.ipinfo.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.ipinfo.003.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.listnodes.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.listnodes.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.listvars.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.lvs.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.lvs.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.lvs.003.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.lvs.004.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.lvs.005.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.lvs.006.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.lvs.007.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.lvs.008.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.lvs.010.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.natgw.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.natgw.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.natgw.003.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.natgw.004.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.natgw.005.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.natgw.006.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.natgw.007.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.natgw.008.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.natgw.010.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.nodestatus.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.nodestatus.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.nodestatus.003.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.nodestatus.004.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.nodestatus.005.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.nodestatus.006.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.pdelete.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.ping.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.pnn.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.process-exists.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.process-exists.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.process-exists.003.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.pstore.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.ptrans.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.readkey.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.recmaster.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.recmaster.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.recover.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.reloadnodes.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.reloadnodes.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.reloadnodes.003.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.reloadnodes.011.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.reloadnodes.012.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.reloadnodes.013.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.reloadnodes.014.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.reloadnodes.015.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.reloadnodes.016.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.reloadnodes.017.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.reloadnodes.018.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.reloadnodes.019.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.reloadnodes.020.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.reloadnodes.021.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.reloadnodes.023.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.reloadnodes.024.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.runstate.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.runstate.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.runstate.003.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.runstate.004.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.runstate.005.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.setdbreadonly.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.setdbreadonly.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.setdbreadonly.003.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.setdbreadonly.004.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.setdbreadonly.005.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.setdbsticky.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.setdbsticky.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.setdbsticky.003.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.setdbsticky.004.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.setdbsticky.005.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.setdebug.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.setdebug.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.setdebug.003.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.setifacelink.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.setifacelink.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.setvar.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.setvar.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.status.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.status.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.stop.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.stop.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.stop.003.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.unban.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.unban.002.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.unban.003.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.uptime.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/ctdb.writekey.001.sh -%{_datadir}/ctdb/tests/UNIT/tool/README -%dir %{_datadir}/ctdb/tests/UNIT/tool/scripts -%{_datadir}/ctdb/tests/UNIT/tool/scripts/local.sh - -#endif with_clustering_support +#endif with clustering %endif %if %{with winexe} @@ -3675,2586 +4101,71 @@ fi %{_mandir}/man1/winexe.1.gz %endif +%if %{with prometheus} +%files prometheus +%{_bindir}/smb_prometheus_endpoint +%{_mandir}/man8/smb_prometheus_endpoint.8.gz +#endif with prometheus + +%endif +%files -n libldb +%license lib/ldb/LICENSE +%{_libdir}/libldb.so.* +%dir %{_libdir}/samba +%{_libdir}/samba/libldb-key-value-private-samba.so +%{_libdir}/samba/libldb-tdb-err-map-private-samba.so +%{_libdir}/samba/libldb-tdb-int-private-samba.so +%if %{with lmdb} +%{_libdir}/samba/libldb-mdb-int-private-samba.so +%endif + +%dir %{_libdir}/samba/ldb +%{_libdir}/samba/ldb/asq.so +%{_libdir}/samba/ldb/ldb.so +%if %{with lmdb} +%{_libdir}/samba/ldb/mdb.so +%endif +%{_libdir}/samba/ldb/paged_searches.so +%{_libdir}/samba/ldb/rdn_name.so +%{_libdir}/samba/ldb/sample.so +%{_libdir}/samba/ldb/server_sort.so +%{_libdir}/samba/ldb/skel.so +%{_libdir}/samba/ldb/tdb.so + +%files -n libldb-devel +%{_includedir}/samba-4.0/ldb_module.h +%{_includedir}/samba-4.0/ldb_handlers.h +%{_includedir}/samba-4.0/ldb_errors.h +%{_includedir}/samba-4.0/ldb_version.h +%{_includedir}/samba-4.0/ldb.h +%{_libdir}/libldb.so + +%{_libdir}/pkgconfig/ldb.pc +%{_mandir}/man3/ldb*.gz +%{_mandir}/man3/ldif*.gz + +%files -n ldb-tools +%{_bindir}/ldbadd +%{_bindir}/ldbdel +%{_bindir}/ldbedit +%{_bindir}/ldbmodify +%{_bindir}/ldbrename +%{_bindir}/ldbsearch +%{_libdir}/samba/libldb-cmdline-private-samba.so +%{_mandir}/man1/ldbadd.1.* +%{_mandir}/man1/ldbdel.1.* +%{_mandir}/man1/ldbedit.1.* +%{_mandir}/man1/ldbmodify.1.* +%{_mandir}/man1/ldbrename.1.* +%{_mandir}/man1/ldbsearch.1.* + +%files -n python3-ldb +%{python3_sitearch}/ldb.cpython-*.so +%{_libdir}/samba/libpyldb-util.cpython-*-private-samba.so +%{python3_sitearch}/_ldb_text.py +%{python3_sitearch}/__pycache__/_ldb_text.cpython-*.py* +#endif !with testsuite +%endif + %changelog -* Sat Nov 13 2021 Guenther Deschner - 4.13.14-2 -- Fix IPA DC schannel support - -* Thu Nov 11 2021 Guenther Deschner - 4.13.14-1 -- Fix winbind trusted domain regression -- related: #2021716 - -* Tue Nov 09 2021 Guenther Deschner - 4.13.14-0 -- Update to Samba 4.13.14 -- resolves: #2019660, #2021711 - Security fixes for CVE-2016-2124 -- resolves: #2019672, #2021716 - Security fixes for CVE-2020-25717 -- resolves: #2019726, #2021718 - Security fixes for CVE-2020-25718 -- resolves: #2019732, #2021719 - Security fixes for CVE-2020-25719 -- resolves: #2021728, #2021729 - Security fixes for CVE-2020-25721 -- resolves: #2019764, #2021721 - Security fixes for CVE-2020-25722 -- resolves: #2021726, #2021727 - Security fixes for CVE-2021-3738 -- resolves: #2019666, #2021715 - Security fixes for CVE-2021-23192 - -* Fri Oct 29 2021 Guenther Deschner - 4.13.13-0 -- Update to Samba 4.13.13 - -* Wed Sep 22 2021 Guenther Deschner - 4.13.12-0 -- Update to Samba 4.13.12 - -* Tue Sep 07 2021 Guenther Deschner - 4.13.11-0 -- Update to Samba 4.13.11 - -* Wed Jul 14 2021 Guenther Deschner - 4.13.10-0 -- Update to Samba 4.13.10 - -* Tue May 11 2021 Guenther Deschner - 4.13.9-0 -- Update to Samba 4.13.9 - -* Thu Apr 29 2021 Guenther Deschner - 4.13.8-0 -- Update to Samba 4.13.8 -- resolves: #1949442, #1955027 - Security fixes for CVE-2021-20254 - -* Wed Apr 07 2021 Alexander Bokovoy - 4.13.7-1 -- Fix memory leaks in RPC server -- resolves: #1946950 - -* Thu Mar 25 2021 Guenther Deschner - 4.13.7-0 -- Update to Samba 4.13.7 -- related: #1941400, #1942496 - Security fixes for CVE-2020-27840 -- related: #1941402, #1942497 - Security fixes for CVE-2021-20277 - -* Wed Mar 24 2021 Guenther Deschner - 4.13.6-0 -- Update to Samba 4.13.6 -- resolves: #1941400, #1942496 - Security fixes for CVE-2020-27840 -- resolves: #1941402, #1942497 - Security fixes for CVE-2021-20277 - -* Tue Mar 09 2021 Guenther Deschner - 4.13.5-0 -- Update to Samba 4.13.5 - -* Tue Jan 26 2021 Guenther Deschner - 4.13.4-0 -- Update to Samba 4.13.4 - -* Tue Dec 15 2020 Guenther Deschner - 4.13.3-0 -- Update to Samba 4.13.3 - -* Wed Nov 25 2020 Alexander Bokovoy - 4.13.2-2 -- rhbz#1892745, rhbz#1900232: smbclient mget crashes (upstream bug 14517) -- Merge RHEL 8.4 patches: - - FIPS-related enhancements - - FreeIPA Global Catalog patches - -* Tue Nov 03 2020 Andreas Schneider - 4.13.2-1 -- Create a python3-samba-devel package to avoid unnessary dependencies - -* Tue Nov 03 2020 Guenther Deschner - 4.13.2-0 -- Update to Samba 4.13.2 - -* Thu Oct 29 2020 Guenther Deschner - 4.13.1-0 -- Update to Samba 4.13.1 -- resolves: #1892631, #1892634 - Security fixes for CVE-2020-14318 -- resolves: #1891685, #1892628 - Security fixes for CVE-2020-14323 -- resolves: #1892636, #1892640 - Security fixes for CVE-2020-14383 - -* Sun Oct 25 2020 Alexander Bokovoy - 4.13.0-13 -- Report 'samba' daemon status back to systemd -- Support dnspython 2.0.0 or later in samba_dnsupdate - -* Thu Oct 22 2020 Alexander Bokovoy - 4.13.0-12 -- Add preliminary support for S4U operations in Samba AD DC - resolves: #1836630 - Samba DC: Remote Desktop cannot access files -- Fix lookup_unix_user_name to allow lookup of realm-qualified users and groups - required for upcoming FreeIPA Global Catalog support - -* Tue Sep 22 2020 Guenther Deschner - 4.13.0-11 -- Update to Samba 4.13.0 - -* Fri Sep 18 2020 Guenther Deschner - 4.13.0rc6-10 -- Update to Samba 4.13.0rc6 -- resolves: #1879822, #1880703 - Security fixes for CVE-2020-1472 - -* Wed Sep 16 2020 Guenther Deschner - 4.13.0rc5-9 -- Update to Samba 4.13.0rc5 - -* Mon Sep 07 2020 Guenther Deschner - 4.13.0rc4-8 -- Update to Samba 4.13.0rc4 - -* Fri Aug 28 2020 Neal Gompa - 4.13.0rc3-6 -- Enable winexe by default everywhere - -* Fri Aug 28 2020 Guenther Deschner - 4.13.0rc3-5 -- Update to Samba 4.13.0rc3 - -* Fri Aug 14 2020 Guenther Deschner - 4.13.0rc2-4 -- Update to Samba 4.13.0rc2 - -* Wed Aug 12 2020 Andreas Schneider - 4.13.0rc1-3 -- resolves: #1865831 - Add missing /usr/lib64/samba/krb5 directory -- resolves: #1866989 - Remove obsolete python3-crypto dependency - -* Wed Jul 29 2020 Fedora Release Engineering - 2:4.13.0-0.2.rc1.1 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild - -* Tue Jul 14 2020 Tom Stellard - 2:4.13.0-0.2.rc1 -- Use make macros - https://fedoraproject.org/wiki/Changes/UseMakeBuildInstallMacro - -* Tue Jul 14 2020 Andreas Schneider - 4.13.0rc1-1 -- Move mdssvc data files to correct package - -* Thu Jul 09 2020 Guenther Deschner - 4.13.0rc1-0 -- Update to Samba 4.13.0rc1 - -* Wed Jul 08 2020 Merlin Mathesius - 4.12.5-1 -- Remove nonexistent --without-winexe option from configure - -* Thu Jul 02 2020 Guenther Deschner - 4.12.5-0 -- Update to Samba 4.12.5 - -* Thu Jul 02 2020 Guenther Deschner - 4.12.4-0 -- Update to Samba 4.12.4 -- resolves: #1849489, #1853255 - Security fixes for CVE-2020-10730 -- resolves: #1849491, #1853256 - Security fixes for CVE-2020-10745 -- resolves: #1849509, #1853276 - Security fixes for CVE-2020-10760 -- resolves: #1851298, #1853259 - Security fixes for CVE-2020-14303 - -* Sat Jun 27 2020 Jitka Plesnikova - 2:4.12.3-1.1 -- Perl 5.32 re-rebuild updated packages - -* Thu Jun 25 2020 Guenther Deschner - 4.12.3-1 -- Add BuildRequires for python3-setuptools - -* Thu Jun 25 2020 Jitka Plesnikova - 2:4.12.3-0.4 -- Perl 5.32 rebuild - -* Tue May 26 2020 Miro Hrončok - 2:4.12.3-0.3 -- Rebuilt for Python 3.9 - -* Tue May 19 2020 Guenther Deschner - 4.12.3-0 -- Update to Samba 4.12.3 - -* Fri May 15 2020 Pete Walter - 2:4.12.2-1.2 -- Rebuild for ICU 67 - -* Wed May 13 2020 Guenther Deschner - 4.12.2-1 -- Add support for building the new experimental io_uring VFS module - -* Tue Apr 28 2020 Guenther Deschner - 4.12.2-0 -- Update to Samba 4.12.2 -- resolves: #1825731, #1828870 - Security fixes for CVE-2020-10700 -- resolves: #1825734, #1828872 - Security fixes for CVE-2020-10704 - -* Sun Apr 12 2020 Alexander Bokovoy - 4.12.1-1 -- Revert POSIX stat tuning in libsmbclient -- Resolves: rhbz#1801442 - -* Tue Apr 07 2020 Guenther Deschner - 4.12.1-0 -- Update to Samba 4.12.1 - -* Sat Mar 21 2020 Alexander Bokovoy - 4.12.0-6 -- Fix samba_requires_eq macro definition -- Resolves rhbz#1815739 - -* Tue Mar 10 2020 Guenther Deschner - 4.12.0-5 -- Add build requirement for perl-FindBin -- resolves: #1661213 - Add winexe subpackage for remote windows command execution - -* Tue Mar 03 2020 Guenther Deschner - 4.12.0-3 -- Update to Samba 4.12.0 - -* Wed Feb 26 2020 Guenther Deschner - 4.12.0rc4-2 -- Update to Samba 4.12.0rc4 - -* Wed Feb 19 2020 Guenther Deschner - 4.12.0rc3-2 -- Update to Samba 4.12.0rc3 - -* Tue Feb 04 2020 Guenther Deschner - 4.12.0rc2-2 -- Update to Samba 4.12.0rc2 - -* Thu Jan 30 2020 Fedora Release Engineering - 2:4.12.0-0.1.rc1.1 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild - -* Fri Jan 24 2020 Alexander Bokovoy - 4.12.0.rc1-1 -- Allow building against krb5 1.18 beta and require it for Rawhide - -* Wed Jan 22 2020 Guenther Deschner - 4.12.0rc1-0 -- Update to Samba 4.12.0rc1 - -* Tue Jan 21 2020 Guenther Deschner - 4.11.5-0 -- Update to Samba 4.11.5 -- resolves: #1791201, #1793405 - Security fixes for CVE-2019-14902 -- resolves: #1791207, #1793407 - Security fixes for CVE-2019-14907 -- resolves: #1791204, #1793406 - Security fixes for CVE-2019-19344 - -* Mon Dec 16 2019 Guenther Deschner - 4.11.4-0 -- Update to Samba 4.11.4 - -* Tue Dec 10 2019 Guenther Deschner - 4.11.3-0 -- Update to Samba 4.11.3 -- resolves: #1778586, #1781542 - Security fixes for CVE-2019-14861 -- resolves: #1778589, #1781545 - Security fixes for CVE-2019-14870 - -* Thu Dec 05 2019 Andreas Schneider - 4.11.2-2 -- Restart winbindd on samba-winbind package upgrade - -* Wed Nov 06 2019 Alexander Bokovoy - 4.11.2-1 -- Update DES removal patch - -* Tue Oct 29 2019 Guenther Deschner - 4.11.2-0 -- Update to Samba 4.11.2 -- resolves: #1763137, #1766558 - Security fixes for CVE-2019-10218 -- resolves: #1764126, #1766559 - Security fixes for CVE-2019-14833 - -* Sun Oct 27 2019 Alexander Bokovoy - 4.11.1-1 -- resolves: #1757071 - Deploy new samba DC fails - -* Fri Oct 18 2019 Guenther Deschner - 4.11.1-0 -- Update to Samba 4.11.1 - -* Tue Sep 17 2019 Guenther Deschner - 4.11.0-3 -- Update to Samba 4.11.0 - -* Wed Sep 11 2019 Guenther Deschner - 4.11.0rc4-2 -- Update to Samba 4.11.0rc4 - -* Tue Sep 03 2019 Guenther Deschner - 4.11.0rc3-2 -- Update to Samba 4.11.0rc3 -- resolves: #1746225, #1748308 - Security fixes for CVE-2019-10197 - -* Tue Aug 27 2019 Guenther Deschner - 4.11.0rc2-2 -- resolves: #1746014 - re-add pidl - -* Mon Aug 26 2019 Lubomir Rintel - 2:4.11.0-0.1.rc2 -- Move the NetworkManager dispatcher script out of /etc - -* Wed Aug 21 2019 Guenther Deschner - 4.11.0rc2-0 -- Update to Samba 4.11.0rc2 - -* Tue Aug 20 2019 Guenther Deschner - 4.11.0rc1-0 -- Update to Samba 4.11.0rc1 - -* Mon Aug 19 2019 Miro Hrončok - 2:4.10.6-1.1 -- Rebuilt for Python 3.8 - -* Fri Aug 16 2019 Alexander Bokovoy - 2:4.10.6-1 -- Fix Samba bug https://bugzilla.samba.org/show_bug.cgi?id=14091 -- Fixes: Windows systems cannot resolve IPA users and groups over LSA RPC - -* Fri Jul 26 2019 Fedora Release Engineering - 2:4.10.6-0.2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild - -* Mon Jul 08 2019 Guenther Deschner - 4.10.6-0 -- Update to Samba 4.10.6 - -* Mon Jul 01 2019 Guenther Deschner - 4.10.5-2 -- resolves: #1718113 - Avoid deprecated time.clock in wafsamba -- resolves: #1711638 - Update to latest waf version 2.0.17 - -* Thu Jun 20 2019 Guenther Deschner - 4.10.5-1 -- resolves: #1602824 - Make vfs_fruit operable with other remote VFS modules -- resolves: #1716455 - Avoid pathconf() in get_real_filename() VFS calls -- resolves: #1706090, #1700791 - Fix smbspool - -* Wed Jun 19 2019 Guenther Deschner - 4.10.5-0 -- Update to Samba 4.10.5 -- resolves: #1711816, #1721872 - Security fixes for CVE-2019-12435 -- resolves: #1711837, #1721873 - Security fixes for CVE-2019-12436 - -* Fri May 31 2019 Jitka Plesnikova - 2:4.10.4-1.1 -- Perl 5.30 rebuild - -* Tue May 28 2019 Guenther Deschner - 4.10.4-1 -- Add missing ctdb directories -- resolves: #1656777 - -* Wed May 22 2019 Guenther Deschner - 4.10.4-0 -- Update to Samba 4.10.4 - -* Tue May 14 2019 Guenther Deschner - 4.10.3-0 -- Update to Samba 4.10.3 -- resolves: #1705877, #1709679 - Security fixes for CVE-2018-16860 - -* Mon Apr 15 2019 Andreas Schneider - 4.10.2-1 -- resolves: #1699230 - Rebuild for MIT Kerberos soname bump of libkadm5srv - -* Mon Apr 08 2019 Guenther Deschner - 4.10.2-0 -- Update to Samba 4.10.2 -- resolves: #1689010, #1697718 - Security fixes for CVE-2019-3870 -- resolves: #1691518, #1697717 - Security fixes for CVE-2019-3880 - -* Wed Apr 03 2019 Guenther Deschner - 4.10.1-0 -- Update to Samba 4.10.1 - -* Mon Mar 25 2019 Andreas Schneider - 4.10.0-6 -- resolves: #1692347 - Add missing DC requirement for its python3 tools - -* Wed Mar 20 2019 Guenther Deschner - 4.10.0-5 -- Fix build failure (duplication during install) - -* Tue Mar 19 2019 Guenther Deschner - 4.10.0-4 -- Update to Samba 4.10.0 - -* Wed Mar 06 2019 Guenther Deschner - 4.10.0rc4-2 -- Update to Samba 4.10.0rc4 - -* Fri Feb 22 2019 Guenther Deschner - 4.10.0rc3-2 -- Update to Samba 4.10.0rc3 - -* Sun Feb 17 2019 Igor Gnatenko - 2:4.10.0-0.2.rc2.1 -- Rebuild for readline 8.0 - -* Thu Feb 14 2019 Andreas Schneider - 4.10.0rc2-2 -- resolves: #1672231 - Fix public NDR API - -* Tue Feb 12 2019 Guenther Deschner - 4.10.0rc2-1 -- resolves: #1674547 - Move samba.xattr modules out of python3 test package - -* Wed Feb 06 2019 Guenther Deschner - 4.10.0rc2-0 -- Update to Samba 4.10.0rc2 - -* Tue Jan 15 2019 Guenther Deschner - 4.10.0rc1-0 -- Update to Samba 4.10.0rc1 - -* Mon Jan 14 2019 Björn Esser - 2:4.9.4-0.1 -- Rebuilt for libcrypt.so.2 (#1666033) - -* Thu Dec 20 2018 Guenther Deschner - 4.9.4-0 -- Update to Samba 4.9.4 - -* Tue Nov 27 2018 Guenther Deschner - 4.9.3-0 -- Update to Samba 4.9.3 -- resolves: #1625449, #1654078 - Security fixes for CVE-2018-14629 -- resolves: #1642545, #1654082 - Security fixes for CVE-2018-16841 -- resolves: #1646377, #1654091 - Security fixes for CVE-2018-16851 -- resolves: #1646386, #1654092 - Security fixes for CVE-2018-16852 -- resolves: #1647246, #1654093 - Security fixes for CVE-2018-16853 -- resolves: #1649278, #1654095 - Security fixes for CVE-2018-16857 - -* Thu Nov 08 2018 Guenther Deschner - 4.9.2-0 -- Update to Samba 4.9.2 - -* Wed Sep 26 2018 Alexander Bokovoy - 4.9.1-2 -- Package ctdb/doc/examples - -* Mon Sep 24 2018 Andreas Schneider - 4.9.1-1 -- Update to Samba 4.9.1 - -* Thu Sep 13 2018 Guenther Deschner - 4.9.0-4 -- Update to Samba 4.9.0 - -* Thu Sep 06 2018 Andreas Schneider - 4.9.0rc5-3 -- Update to Samba 4.9.0rc5 - -* Wed Aug 29 2018 Guenther Deschner - 4.9.0rc4-3 -- Update to Samba 4.9.0rc4 - -* Thu Aug 16 2018 Andreas Schneider - 4.9.0rc3-3 -- Fix python3 packaging - -* Wed Aug 15 2018 Guenther Deschner - 4.9.0rc3-2 -- Update to Samba 4.9.0rc3 -- resolves: #1589651, #1617916 - Security fixes for CVE-2018-1139 -- resolves: #1580230, #1618613 - Security fixes for CVE-2018-1140 -- resolves: #1612805, #1618697 - Security fixes for CVE-2018-10858 -- resolves: #1610640, #1617910 - Security fixes for CVE-2018-10918 -- resolves: #1610645, #1617911 - Security fixes for CVE-2018-10919 - -* Wed Aug 01 2018 Andreas Schneider - 4.9.0rc2-2 -- Add some spec file cleanups - -* Wed Aug 01 2018 Guenther Deschner - 4.9.0rc2-0 -- Update to Samba 4.9.0rc2 - -* Thu Jul 12 2018 Guenther Deschner - 4.9.0rc1-0 -- Update to Samba 4.9.0rc1 - -* Thu Jul 12 2018 Alexander Bokovoy - 2:4.8.3-4.1 -- Scope to local __bss_start symbol (typo in a patch) -- Fixes https://bugzilla.redhat.com/show_bug.cgi?id=1600035 - -* Thu Jul 12 2018 Alexander Bokovoy - 2:4.8.3-4 -- Change scope to local for symbols automatically added by upcoming binutils 2.31 -- Fixes https://bugzilla.redhat.com/show_bug.cgi?id=1600035 - -* Wed Jul 11 2018 Alexander Bokovoy - 2:4.8.3-3 -- Rebuild Samba against binutils 2.30.90-2.fc29 -- Fixes https://bugzilla.redhat.com/show_bug.cgi?id=1600035 -- Add explicit BuildRequires for gcc - -* Fri Jul 06 2018 Petr Pisar -- Perl 5.28 rebuild - -* Thu Jul 05 2018 Alexander Bokovoy - 2:4.8.3-2 -- Fix rawhide build by explicitly using /usr/bin/python2 - -* Tue Jul 03 2018 Petr Pisar -- Perl 5.28 rebuild - -* Mon Jul 02 2018 Miro Hrončok - 2:4.8.3-1.2 -- Rebuilt for Python 3.7 - -* Thu Jun 28 2018 Jitka Plesnikova - 2:4.8.3-1.1 -- Perl 5.28 rebuild - -* Tue Jun 26 2018 Andreas Schneider - 4.8.3-1 -- Update to Samba 4.8.3 -- Remove python(2|3)-subunit dependency - -* Tue Jun 19 2018 Miro Hrončok - 2:4.8.2-1.1 -- Rebuilt for Python 3.7 - -* Wed May 16 2018 Guenther Deschner - 4.8.2-0 -- Update to Samba 4.8.2 - -* Wed May 09 2018 Andreas Schneider - 4.8.1-1 -- resolves: #1574177 - Fix smbspool command line argument handling - -* Thu Apr 26 2018 Guenther Deschner - 4.8.1-0 -- Update to Samba 4.8.1 - -* Wed Mar 14 2018 Guenther Deschner - 4.8.0-7 -- resolves: #1554754, #1554756 - Security fixes for CVE-2018-1050 CVE-2018-1057 -- resolves: #1555112 - Update to Samba 4.8.0 - -* Tue Mar 13 2018 Andreas Schneider - 4.8.0rc4-6 -- resolves: #1552652 - Fix usage of nc in ctdb tests and only recommned it - -* Fri Mar 02 2018 Guenther Deschner - 4.8.0rc4-5 -- Update to Samba 4.8.0rc4 - -* Mon Feb 12 2018 Guenther Deschner - 4.8.0rc3-4 -- Update to Samba 4.8.0rc3 - -* Fri Feb 09 2018 Igor Gnatenko - 2:4.8.0-0.3.rc2.1 -- Escape macros in %%changelog - -* Fri Jan 26 2018 Guenther Deschner - 4.8.0rc2-3 -- Update to Samba 4.8.0rc2 - -* Sun Jan 21 2018 Björn Esser - 2:4.8.0-0.2.rc1 -- Explicitly BR: rpcsvc-proto-devel - -* Sat Jan 20 2018 Björn Esser - 2:4.8.0-0.1.rc1.1 -- Rebuilt for switch to libxcrypt - -* Mon Jan 15 2018 Guenther Deschner - 4.8.0rc1-1 -- Update to Samba 4.8.0rc1 - -* Mon Jan 08 2018 Andreas Schneider - 4.7.4-1 -- resolves: #1508092 - Add missing dependency for tdbbackup - -* Mon Dec 25 2017 Guenther Deschner - 4.7.4-0 -- Update to Samba 4.7.4 - -* Mon Dec 04 2017 Andreas Schneider - 4.7.3-3 -- resolves: #1520163 - Link libaesni-intel-samba4.so with -z noexecstack - -* Thu Nov 30 2017 Andreas Schneider - 4.7.3-2 -- Fix deamon startup with systemd - -* Thu Nov 23 2017 Bastien Nocera - 4.7.3-1 -- Enable AES acceleration on Intel compatible CPUs by default - -* Tue Nov 21 2017 Guenther Deschner - 4.7.3-0 -- Update to Samba 4.7.3 -- resolves: #1515692 - Security fix for CVE-2017-14746 and CVE-2017-15275 - -* Wed Nov 15 2017 Guenther Deschner - 4.7.2-0 -- resolves: #1513452 - Update to Samba 4.7.2 - -* Mon Nov 13 2017 Andreas Schneider - 4.7.1-2 -- Fix release number - -* Tue Nov 07 2017 Igor Gnatenko - 4.7.1-1 -- Remove old crufty coreutils requires - -* Thu Nov 02 2017 Guenther Deschner - 4.7.1-0 -- resolves: #1508871 - Update to Samba 4.7.1 - -* Mon Oct 30 2017 Alexander Bokovoy - 4.7.0-18 -- Force samba-dc to use the same libldb version as LDB modules compiled -- resolves: #1507420 - LDB / Samba module version mismatch - -* Fri Oct 27 2017 Andreas Schneider - 4.7.0-17 -- Move dsdb libs to python2-samba-dc - -* Thu Oct 26 2017 Andreas Schneider - 4.7.0-16 -- Create python[2|3]-samba-dc packages - -* Wed Oct 25 2017 Andreas Schneider - 4.7.0-15 -- related: #1499140 - Fix several dependency issues -- Fix building with MIT Kerberos 1.16 - -* Fri Oct 13 2017 Andreas Schneider - 4.7.0-14 -- resolves: #1499140 - Move libdfs-server-ad to the correct subpackage - -* Fri Oct 06 2017 Alexander Bokovoy - 4.7.0-13 -- Move /usr/lib{64,}/samba/libdsdb-garbage-collect-tombstones-samba4.so to samba-dc-libs -- Rebuild in rawhide against new krb5 1.16 and docbook-xml - -* Thu Sep 21 2017 Guenther Deschner - 4.7.0-12 -- Update to Samba 4.7.0 -- resolves: #1493441 - Security fix for CVE-2017-12150 CVE-2017-12151 CVE-2017-12163 - -* Sun Sep 17 2017 Guenther Deschner - 4.7.0-0.11.rc6 -- Update to Samba 4.7.0rc6 - -* Wed Sep 13 2017 Alexander Bokovoy - 4.7.0-0.11.rc5 -- resolves: #1491137 - dcerpc/__init__.py is not packaged for py3 - -* Tue Sep 12 2017 Andreas Schneider - 4.7.0-0.10.rc5 -- resolves: #1476175 - Create seperate package for bind_dlz module - -* Tue Aug 29 2017 Guenther Deschner - 4.7.0-0.9.rc5 -- Update to Samba 4.7.0rc5 - -* Tue Aug 08 2017 Andreas Schneider - 4.7.0-0.9.rc3 -- Add printadmin group for printer driver handling - -* Sun Jul 30 2017 Florian Weimer - 2:4.7.0-0.8.rc3.2 -- Rebuild with binutils fix for ppc64le (#1475636) - -* Thu Jul 27 2017 Fedora Release Engineering - 2:4.7.0-0.8.rc3.1 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild - -* Wed Jul 26 2017 Andreas Schneider - 4.7.0-0.8.rc3 -- resolves: #1301002 - Enable avahi support - -* Tue Jul 25 2017 Guenther Deschner - 4.7.0-0.7.rc3 -- Update to Samba 4.7.0rc3 - -* Mon Jul 24 2017 Andreas Schneider - 4.7.0-0.7.rc1 -- Rename samba-python to python2-samba -- Update build requirement for libcephfs - -* Thu Jul 20 2017 Alexander Bokovoy - 4.7.0-0.6.rc1 -- Use Python 2 explicitly for samba-tool and other Python-based tools -- Install samba.service as it is required for the AD DC case - -* Tue Jul 18 2017 Alexander Bokovoy - 4.7.0-0.5.rc1 -- Convert more rpc modules to python3 -- Explicitly specify Python artifacts in the spec to be able to catch unpackaged ones -- Split 'make test' Python code into separate python2-samba-test/python3-samba-test sub-packages -- Remove embedded python2-dns version, require python{2,3}-dns instead - -* Thu Jul 06 2017 Andreas Schneider - 4.7.0-0.4.rc1 -- Add python3 support -- Fix %%posttrans for libwbclient-devel - -* Thu Jul 06 2017 Andreas Schneider - 4.7.0-0.3.rc1 -- Do not install conflicting file _ldb_text.py - -* Wed Jul 05 2017 Andreas Schneider - 4.7.0-0.2.rc1 -- Fix requirement generation for shared libraries - -* Wed Jul 05 2017 Andreas Schneider - 4.7.0-0.1.rc1 -- Build Samba with Active Directory support! - -* Mon Jun 12 2017 Guenther Deschner - 4.7.0-0.0.rc1 -- Update to Samba 4.7.0rc1 - -* Mon Jun 12 2017 Guenther Deschner - 4.6.5-0 -- Update to Samba 4.6.5 - -* Sun Jun 04 2017 Jitka Plesnikova - 2:4.6.4-1.1 -- Perl 5.26 rebuild - -* Wed May 24 2017 Andreas Schneider - 4.6.4-1 -- #resolves: #1451486 - Add source tarball comment - -* Wed May 24 2017 Guenther Deschner - 4.6.4-0 -- Update to Samba 4.6.4 -- resolves: #1455050 - Security fix for CVE-2017-7494 - -* Tue Apr 25 2017 Guenther Deschner - 4.6.3-0 -- Update to Samba 4.6.3 - -* Fri Mar 31 2017 Guenther Deschner - 4.6.2-0 -- Update to Samba 4.6.2 -- related: #1435156 - Security fix for CVE-2017-2619 - -* Thu Mar 23 2017 Guenther Deschner - 4.6.1-0 -- Update to Samba 4.6.1 -- resolves: #1435156 - Security fix for CVE-2017-2619 - -* Wed Mar 15 2017 Alexander Bokovoy - 4.6.0-4 -- Export arcfour_crypt_blob to Python as samba.crypto.arcfour_encrypt -- Makes possible to run trust to AD in FreeIPA in FIPS mode - -* Fri Mar 10 2017 Alexander Bokovoy - 4.6.0-3 -- auth/credentials: Always set the the realm if we set the principal from the ccache -- resolves: #1430761 - credentials_crb5: use gss_acquire_cred for client-side GSSAPI use case - -* Thu Mar 09 2017 Alexander Bokovoy - 4.6.0-2 -- resolves: #1430761 - credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case - -* Tue Mar 07 2017 Andreas Schneider - 4.6.0-1 -- Update to Samba 4.6.0 - -* Wed Mar 01 2017 Andreas Schneider - 4.6.0-0.3.rc4 -- Update to Samba 4.6.0rc4 - -* Tue Feb 14 2017 Andreas Schneider - 4.6.0-0.1.rc3 -- Update to Samba 4.6.0rc3 - -* Sat Feb 11 2017 Fedora Release Engineering - 4.6.0-0.1.rc2.1 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild - -* Fri Jan 27 2017 Guenther Deschner - 4.6.0-0.1.rc2 -- Update to Samba 4.6.0rc2 - -* Thu Jan 12 2017 Andreas Schneider - 4.6.0-0.1.rc1 -- resolves: #1319098 - Add missing Requires for pre-required packages - -* Thu Jan 05 2017 Guenther Deschner - 4.6.0-0.1.rc1 -- Update to Samba 4.6.0rc1 - -* Mon Dec 19 2016 Guenther Deschner - 4.5.3-0 -- Update to Samba 4.5.3 -- resolves: #1405984 - CVE-2016-2123,CVE-2016-2125 and CVE-2016-2126 - -* Wed Dec 07 2016 Guenther Deschner - 4.5.2-0 -- Update to Samba 4.5.2 - -* Mon Dec 05 2016 Rex Dieter - - -- rebuild (libldb) - -* Fri Nov 04 2016 Anoop C S - 4.5.1-1 -- Fix glfs_realpath allocation in vfs_glusterfs - -* Wed Oct 26 2016 Guenther Deschner - 4.5.1-0 -- Update to Samba 4.5.1 - -* Mon Oct 17 2016 Andreas Schneider - 4.5.0-3 -- resolves: 1375973 - Fix tevent incompatibility issue - -* Wed Sep 14 2016 Guenther Deschner - 4.5.0-2 -- Fix smbspool alternatives handling during samba-client uninstall - -* Wed Sep 07 2016 Guenther Deschner - 4.5.0-1 -- Update to Samba 4.5.0 - -* Mon Aug 29 2016 Guenther Deschner - 4.5.0rc3-0 -- Update to Samba 4.5.0rc3 - -* Mon Aug 15 2016 Guenther Deschner - 4.5.0rc2-0 -- Update to Samba 4.5.0rc2 - -* Thu Jul 28 2016 Guenther Deschner - 4.5.0rc1-0 -- Update to Samba 4.5.0rc1 - -* Tue Jul 19 2016 Fedora Release Engineering - 2:4.4.5-1.1 -- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages - -* Thu Jul 07 2016 Guenther Deschner - 4.4.5-1 -- Update to Samba 4.4.5 -- resolves: #1353504 - CVE-2016-2119 - -* Thu Jun 23 2016 Guenther Deschner - 4.4.4-4 -- resolves: #1348899 - Import of samba.ntacls fails - -* Mon Jun 20 2016 Andreas Schneider - 4.4.4-3 -- resolves: #1337260 - Small fix to the example smb.conf file - -* Wed Jun 15 2016 Andreas Schneider - 4.4.4-2 -- Fix resolving trusted domain users on domain member - -* Tue Jun 07 2016 Guenther Deschner - 4.4.4-1 -- Update to Samba 4.4.4 -- resolves: #1343529 - -* Wed May 25 2016 Alexander Bokovoy - 2:4.4.3-2 -- Fix libsystemd patch (#1125086) so that it actually works - -* Mon May 23 2016 Zbigniew Jędrzejewski-Szmek - 2:4.4.3-1.2 -- Rebuild to drop libsystemd-daemon dependency (#1125086) - -* Sun May 15 2016 Jitka Plesnikova - 2:4.4.3-1.1 -- Perl 5.24 rebuild - -* Mon May 02 2016 Guenther Deschner - 4.4.3-1 -- Update to Samba 4.4.3 -- resolves: #1332178 - -* Tue Apr 12 2016 Guenther Deschner - 4.4.2-1 -- Update to Samba 4.4.2, fix badlock security bug -- resolves: #1326453 - CVE-2015-5370 -- resolves: #1326453 - CVE-2016-2110 -- resolves: #1326453 - CVE-2016-2111 -- resolves: #1326453 - CVE-2016-2112 -- resolves: #1326453 - CVE-2016-2113 -- resolves: #1326453 - CVE-2016-2114 -- resolves: #1326453 - CVE-2016-2115 -- resolves: #1326453 - CVE-2016-2118 - -* Tue Mar 22 2016 Guenther Deschner - 4.4.0-1 -- Update to Samba 4.4.0 - -* Wed Mar 16 2016 Guenther Deschner - 4.4.0-0.8.rc5 -- Update to Samba 4.4.0rc5 - -* Tue Mar 08 2016 Guenther Deschner - 4.4.0-0.7.rc4 -- Update to Samba 4.4.0rc4 -- resolves: #1315942 - CVE-2015-7560 Incorrect ACL get/set allowed on symlink path - -* Tue Feb 23 2016 Guenther Deschner - 4.4.0-0.6.rc3 -- Update to Samba 4.4.0rc3 - -* Wed Feb 17 2016 Guenther Deschner - 4.4.0-0.5.rc2 -- Activate multi channel support (switched off by default) - -* Mon Feb 15 2016 Andreas Schneider - 4.4.0-0.4.rc2 -- More spec file fixes -- resolves: #1306542 - scriptlet failure because of comments - -* Mon Feb 15 2016 Andreas Schneider - 4.4.0-0.3.rc2 -- More spec file fixes - -* Mon Feb 15 2016 Andreas Schneider - 4.4.0-0.2.rc2 -- More spec file fixes - -* Wed Feb 10 2016 Guenther Deschner - 4.4.0-0.1.rc2 -- Update to Samba 4.4.0rc2 - -* Thu Feb 04 2016 Fedora Release Engineering - 2:4.4.0-0.1.rc1 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild - -* Wed Jan 27 2016 Guenther Deschner - 4.4.0-0.0.rc1 -- Update to Samba 4.4.0rc1 - -* Fri Jan 22 2016 Alexander Bokovoy - 4.3.4-1 -- resolves: #1300038 - PANIC: Bad talloc magic value - wrong talloc version used/mixed - -* Tue Jan 12 2016 Guenther Deschner - 4.3.4-0 -- resolves: #1261230 - Update to Samba 4.3.4 - -* Wed Dec 16 2015 Guenther Deschner - 4.3.3-0 -- Update to Samba 4.3.3 -- resolves: #1292069 -- CVE-2015-3223 Remote DoS in Samba (AD) LDAP server -- CVE-2015-5252 Insufficient symlink verification in smbd -- CVE-2015-5296 Samba client requesting encryption vulnerable to - downgrade attack -- CVE-2015-5299 Missing access control check in shadow copy code -- CVE-2015-7540 DoS to AD-DC due to insufficient checking of asn1 - memory allocation - -* Tue Dec 15 2015 Guenther Deschner - 4.3.2-2 -- revert dependencies to samba-common and -tools - -* Tue Dec 01 2015 Guenther Deschner - 4.3.2-1 -- resolves: #1261230 - Update to Samba 4.3.2 - -* Wed Nov 18 2015 Guenther Deschner - 4.3.1-3 -- resolves: #1282931 - Fix DCE/RPC bind nak parsing - -* Fri Oct 23 2015 Guenther Deschner - 4.3.1-2 -- Fix dependencies to samba-common - -* Tue Oct 20 2015 Guenther Deschner - 4.3.1-1 -- resolves: #1261230 - Update to Samba 4.3.1 - -* Mon Oct 12 2015 Guenther Deschner - 4.3.0-3 -- Use separate lockdir - -* Mon Oct 12 2015 Guenther Deschner - 4.3.0-2 -- resolves: #1270568 - Samba fails to start after update to 4.3.0 - -* Tue Sep 08 2015 Guenther Deschner - 4.3.0-1 -- resolves: #1088911 - Update to Samba 4.3.0 - -* Tue Sep 01 2015 Andreas Schneider - 4.3.0-0.1rc4 -- Update to Samba 4.3.0rc4 - -* Mon Aug 31 2015 Andreas Schneider - 4.3.0-0.1rc3 -- Update to Samba 4.3.0rc3 - -* Tue Jul 14 2015 Guenther Deschner - 4.2.3-0 -- resolves: #1088911 - Update to Samba 4.2.3 - -* Fri Jun 19 2015 Andreas Schneider - 4.2.2-1 -- resolves: #1227911 - Enable tar support for smbclient -- resolves: #1234908 - Own the /var/lib/samba directory -- Enable hardened build - -* Fri Jun 19 2015 Fedora Release Engineering - 2:4.2.2-0.2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild - -* Thu Jun 04 2015 Jitka Plesnikova - 2:4.2.2-0.1 -- Perl 5.22 rebuild - -* Thu May 28 2015 Guenther Deschner - 4.2.2-0 -- Update to Samba 4.2.2 - -* Mon May 11 2015 Alexander Bokovoy - 4.2.1-8 -- Fixes: #1219832: Samba 4.2 broke FreeIPA trusts to AD -- Remove usage of deprecated API from gnutls - -* Thu Apr 30 2015 Alexander Bokovoy - 4.2.1-7 -- Fix LSASD daemon -- resolves: #1217346 - FreeIPA trusts to AD broken due to Samba 4.2 failure to run LSARPC pipe externally - -* Mon Apr 27 2015 Alexander Bokovoy - 4.2.1-6 -- Remove samba-common-tools from samba-client package as it brings back Python 2.7 - -* Mon Apr 27 2015 Alexander Bokovoy - 4.2.1-5 -- Require samba-common-tools in samba package -- Require samba-common-tools in samba-client package -- resolves: #1215631 - /usr/bin/net moved to samba-common-tools but the package is not required by samba - -* Sat Apr 25 2015 Alexander Bokovoy - 4.2.1-4 -- Fix systemd library detection (incomplete patch upstream) - -* Fri Apr 24 2015 Andreas Schneider - 4.2.1-3 -- resolves: #1214973 - Fix libwbclient alternatives link. - -* Wed Apr 22 2015 Guenther Deschner - 4.2.1-2 -- Add vfs snapper module. - -* Tue Apr 21 2015 Andreas Schneider - 4.2.1-1 -- Update to Samba 4.2.1 -- resolves: #1213373 - Fix DEBUG macro issues in public headers - -* Wed Apr 08 2015 Andreas Schneider - 4.2.0-3 -- resolves: #1207381 - Fix libsystemd detection. - -* Tue Mar 10 2015 Andreas Schneider - 4.2.0-2 -- Fix the AD build. -- Create samba-client-libs subpackage. -- Fix multiarch issues by splitting the samba-common package. - -* Thu Mar 05 2015 Guenther Deschner - 4.2.0-1 -- Update to Samba 4.2.0 - -* Tue Mar 03 2015 Andreas Schneider - 4.2.0-0.5.rc5 -- Update to Samba 4.2.0rc5 - -* Fri Jan 16 2015 - Andreas Schneider - 4.2.0-0.4.rc4 -- Update to Samba 4.2.0rc4 -- resolves: #1154600 - Install missing samba pam.d configuration file. - -* Mon Jan 12 2015 Guenther Deschner - 4.2.0-0.6.rc3 -- Fix awk as a dependency (and require gawk) - -* Mon Jan 12 2015 Michael Adam - 4.2.0-0.5.rc3 -- Add dependencies for ctdb. - -* Fri Jan 09 2015 Stephen Gallagher 4.2.0-0.4.rc3 -- Apply the DEBUG patch - -* Fri Jan 09 2015 Andreas Schneider - 4.2.0-0.3.rc3 -- Fix issues with conflicting DEBUG macros. - -* Tue Jan 06 2015 Michael Adam - 4.2.0-0.2.rc3 -- Improve dependencies of vfs-glusterfs and vfs-cephfs. -- Remove unused python_libdir. -- Fix malformed changelog entries. - -* Tue Jan 06 2015 Guenther Deschner - 4.2.0-0.2.rc3 -- Fix ctdb and libcephfs dependencies. - -* Mon Jan 05 2015 Andreas Schneider - 4.2.0-0.1.rc3 -- Update to Samba 4.2.0rc3 - + Samba provides ctdb packages now. - -* Tue Dec 16 2014 Andreas Schneider - 4.2.0-0.3.rc2 -- resolves: #1174412 - Build VFS Ceph module. -- resolves: #1169067 - Move libsamba-cluster-support.so to samba-libs package. -- resolves: #1016122 - Move smbpasswd to samba-common package. - -* Fri Nov 21 2014 Andreas Schneider - 4.2.0-0.2.rc2 -- Use alternatives for libwbclient. -- Add cwrap to BuildRequires. - -* Wed Nov 12 2014 Andreas Schneider - 4.2.0-0.1.rc2 -- Update to Samba 4.2.0rc2. - -* Tue Oct 07 2014 Andreas Schneider - 4.1.12-5 -- resolves: #1033595 - Fix segfault in winbind. - -* Wed Sep 24 2014 Andreas Schneider - 4.1.12-1 -- Update to Samba 4.1.12. - -* Tue Sep 09 2014 Jitka Plesnikova - 2:4.1.11-1.4 -- Perl 5.20 mass - -* Wed Aug 27 2014 Jitka Plesnikova - 2:4.1.11-1.3 -- Perl 5.20 rebuild - -* Wed Aug 20 2014 Kalev Lember - 2:4.1.11-1.2 -- Rebuilt for rpm dependency generator failure (#1131892) - -* Mon Aug 18 2014 Fedora Release Engineering - 0:4.1.11-1.1 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild - -* Fri Aug 1 2014 Jared Smith - 4.1.11-1 -- Update to upstream Samba 4.1.11 release -- resolves: #1126015 - Fix CVE-2014-3560 - -* Mon Jun 23 2014 Guenther Deschner - 4.1.9-3 -- Update to Samba 4.1.9. -- resolves: #1112251 - Fix CVE-2014-0244 and CVE-2014-3493. - -* Wed Jun 11 2014 Guenther Deschner - 4.1.8-3 -- Update to Samba 4.1.8. -- resolves: #1102528 - CVE-2014-0178. - -* Sun Jun 08 2014 Fedora Release Engineering - 2:4.1.6-3.1 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild - -* Thu Apr 03 2014 Andreas Schneider - 4.1.6-3 -- Add systemd integration to the service daemons. - -* Tue Mar 18 2014 Andreas Schneider - 4.1.6-2 -- Created a samba-test-libs package. - -* Tue Mar 11 2014 Andreas Schneider - 4.1.6-1 -- Fix CVE-2013-4496 and CVE-2013-6442. -- Fix installation of pidl. - -* Fri Feb 21 2014 Andreas Schneider - 4.1.5-1 -- Update to Samba 4.1.5. - -* Fri Feb 07 2014 Andreas Schneider - 4.1.4-1 -- Update to Samba 4.1.4. - -* Wed Jan 08 2014 Andreas Schneider - 4.1.3-3 -- resolves: #1042845 - Do not build with libbsd. - -* Tue Dec 10 2013 Guenther Deschner - 4.1.3-2 -- resolves: #1019469 - Fix winbind debug message NULL pointer derreference. - -* Mon Dec 09 2013 Andreas Schneider - 4.1.3-1 -- Update to Samba 4.1.3. -- resolves: #1039454 - CVE-2013-4408. -- resolves: #1039500 - CVE-2012-6150. - -* Mon Nov 25 2013 Andreas Schneider - 4.1.2-1 -- Update to Samba 4.1.2. - -* Mon Nov 18 2013 Guenther Deschner - 4.1.1-3 -- resolves: #948509 - Fix manpage correctness. - -* Fri Nov 15 2013 Andreas Schneider - 4.1.1-2 -- related: #884169 - Fix strict aliasing warnings. - -* Mon Nov 11 2013 Andreas Schneider - 4.1.1-1 -- resolves: #1024544 - Fix CVE-2013-4475. -- Update to Samba 4.1.1. - -* Mon Nov 11 2013 Andreas Schneider - 4.1.0-5 -- related: #884169 - Fix the upgrade path. - -* Wed Oct 30 2013 Andreas Schneider - 4.1.0-4 -- related: #884169 - Add direct dependency to samba-libs in the - glusterfs package. -- resolves: #996567 - Fix userPrincipalName composition. -- related: #884169 - Fix memset call with zero length in in ntdb. - -* Fri Oct 18 2013 Andreas Schneider - 4.1.0-3 -- resolves: #1020329 - Build glusterfs VFS plguin. - -* Tue Oct 15 2013 Andreas Schneider - 4.1.0-2 -- resolves: #1018856 - Fix installation of pam_winbind after upgrade. -- related: #1010722 - Split out a samba-winbind-modules package. -- related: #985609 - -* Fri Oct 11 2013 Andreas Schneider - 4.1.0-1 -- related: #985609 - Update to Samba 4.1.0. - -* Tue Oct 01 2013 Andreas Schneider - 2:4.1.0-0.8 -- related: #985609 - Update to Samba 4.1.0rc4. -- resolves: #1010722 - Split out a samba-winbind-modules package. - -* Wed Sep 11 2013 Andreas Schneider - 2:4.1.0-0.7 -- related: #985609 - Update to Samba 4.1.0rc3. -- resolves: #1005422 - Add support for KEYRING ccache type in pam_winbindd. - -* Wed Sep 04 2013 Andreas Schneider - 2:4.1.0-0.6 -- resolves: #717484 - Enable profiling data support. - -* Thu Aug 22 2013 Guenther Deschner - 2:4.1.0-0.5 -- resolves: #996160 - Fix winbind with trusted domains. - -* Wed Aug 14 2013 Andreas Schneider 2:4.1.0-0.4 -- resolves: #996160 - Fix winbind nbt name lookup segfault. - -* Mon Aug 12 2013 Andreas Schneider - 2:4.1.0-0.3 -- related: #985609 - Update to Samba 4.1.0rc2. - -* Sat Aug 03 2013 Petr Pisar - 2:4.1.0-0.2.rc1.1 -- Perl 5.18 rebuild - -* Wed Jul 24 2013 Andreas Schneider - 2:4.1.0-0.2 -- resolves: #985985 - Fix file conflict between samba and wine. -- resolves: #985107 - Add support for new default location for Kerberos - credential caches. - -* Sat Jul 20 2013 Petr Pisar - 2:4.1.0-0.1.rc1.1 -- Perl 5.18 rebuild - -* Wed Jul 17 2013 Andreas Schneider - 2:4.1.0-0.1 -- Update to Samba 4.1.0rc1. - -* Mon Jul 15 2013 Andreas Schneider - 2:4.0.7-2 -- resolves: #972692 - Build with PIE and full RELRO. -- resolves: #884169 - Add explicit dependencies suggested by rpmdiff. -- resolves: #981033 - Local user's krb5cc deleted by winbind. -- resolves: #984331 - Fix samba-common tmpfiles configuration file in wrong - directory. - -* Wed Jul 03 2013 Andreas Schneider - 2:4.0.7-1 -- Update to Samba 4.0.7. - -* Fri Jun 07 2013 Andreas Schneider - 2:4.0.6-3 -- Add UPN enumeration to passdb internal API (bso #9779). - -* Wed May 22 2013 Andreas Schneider - 2:4.0.6-2 -- resolves: #966130 - Fix build with MIT Kerberos. -- List vfs modules in spec file. - -* Tue May 21 2013 Andreas Schneider - 2:4.0.6-1 -- Update to Samba 4.0.6. -- Remove SWAT. - -* Wed Apr 10 2013 Andreas Schneider - 2:4.0.5-1 -- Update to Samba 4.0.5. -- Add UPN enumeration to passdb internal API (bso #9779). -- resolves: #928947 - samba-doc is obsolete now. -- resolves: #948606 - LogRotate should be optional, and not a hard "Requires". - -* Fri Mar 22 2013 Andreas Schneider - 2:4.0.4-3 -- resolves: #919405 - Fix and improve large_readx handling for broken clients. -- resolves: #924525 - Don't use waf caching. - -* Wed Mar 20 2013 Andreas Schneider - 2:4.0.4-2 -- resolves: #923765 - Improve packaging of README files. - -* Wed Mar 20 2013 Andreas Schneider - 2:4.0.4-1 -- Update to Samba 4.0.4. - -* Mon Mar 11 2013 Andreas Schneider - 2:4.0.3-4 -- resolves: #919333 - Create /run/samba too. - -* Mon Mar 04 2013 Andreas Schneider - 2:4.0.3-3 -- Fix the cache dir to be /var/lib/samba to support upgrades. - -* Thu Feb 14 2013 Andreas Schneider - 2:4.0.3-2 -- resolves: #907915 - libreplace.so => not found - -* Thu Feb 07 2013 Andreas Schneider - 2:4.0.3-1 -- Update to Samba 4.0.3. -- resolves: #907544 - Add unowned directory /usr/lib64/samba. -- resolves: #906517 - Fix pidl code generation with gcc 4.8. -- resolves: #908353 - Fix passdb backend ldapsam as module. - -* Wed Jan 30 2013 Andreas Schneider - 2:4.0.2-1 -- Update to Samba 4.0.2. -- Fixes CVE-2013-0213. -- Fixes CVE-2013-0214. -- resolves: #906002 -- resolves: #905700 -- resolves: #905704 -- Fix conn->share_access which is reset between user switches. -- resolves: #903806 -- Add missing example and make sure we don't introduce perl dependencies. -- resolves: #639470 - -* Wed Jan 16 2013 Andreas Schneider - 2:4.0.1-1 -- Update to Samba 4.0.1. -- Fixes CVE-2013-0172. - -* Mon Dec 17 2012 Andreas Schneider - 2:4.0.0-174 -- Fix typo in winbind-krb-locator post uninstall script. - -* Tue Dec 11 2012 Andreas Schneider - 2:4.0.0-173 -- Update to Samba 4.0.0. - -* Thu Dec 06 2012 Andreas Schneider - 2:4.0.0-171.rc6 -- Fix typo in winbind-krb-locator post uninstall script. - -* Tue Dec 04 2012 Andreas Schneider - 2:4.0.0-170.rc6 -- Update to Samba 4.0.0rc6. -- Add /etc/pam.d/samba for swat to work correctly. -- resolves #882700 - -* Fri Nov 23 2012 Guenther Deschner - 2:4.0.0-169.rc5 -- Make sure ncacn_ip_tcp client code looks for NBT_NAME_SERVER name types. - -* Thu Nov 15 2012 Andreas Schneider - 2:4.0.0-168.rc5 -- Reduce dependencies of samba-devel and create samba-test-devel package. - -* Tue Nov 13 2012 Andreas Schneider - 2:4.0.0-167.rc5 -- Use workaround for winbind default domain only when set. -- Build with old ctdb support. - -* Tue Nov 13 2012 Andreas Schneider - 2:4.0.0-166.rc5 -- Update to Samba 4.0.0rc5. - -* Mon Nov 05 2012 Andreas Schneider - 2:4.0.0-165.rc4 -- Fix library dependencies of libnetapi. - -* Mon Nov 05 2012 Andreas Schneider - 2:4.0.0-164.rc4 -- resolves: #872818 - Fix perl dependencies. - -* Tue Oct 30 2012 Andreas Schneider - 2:4.0.0-163.rc4 -- Update to Samba 4.0.0rc4. - -* Mon Oct 29 2012 Andreas Schneider - 2:4.0.0-162.rc3 -- resolves: #870630 - Fix scriptlets interpeting a comment as argument. - -* Fri Oct 26 2012 Andreas Schneider - 2:4.0.0-161.rc3 -- Add missing Requries for python modules. -- Add NetworkManager dispatcher script for winbind. - -* Fri Oct 19 2012 Andreas Schneider - 2:4.0.0-160.rc3 -- resolves: #867893 - Move /var/log/samba to samba-common package for - winbind which requires it. - -* Thu Oct 18 2012 Andreas Schneider - 2:4.0.0-159.rc3 -- Compile default auth methods into smbd. - -* Tue Oct 16 2012 Andreas Schneider - 2:4.0.0-158.rc3 -- Move pam_winbind.conf and the manpages to the right package. - -* Tue Oct 16 2012 Andreas Schneider - 2:4.0.0-157.rc3 -* resolves: #866959 - Build auth_builtin as static module. - -* Tue Oct 16 2012 Andreas Schneider - 2:4.0.0-156.rc3 -- Update systemd Requires to reflect latest packaging guidelines. - -* Tue Oct 16 2012 Andreas Schneider - 2:4.0.0-155.rc3 -- Add back the AES patches which didn't make it in rc3. - -* Tue Oct 16 2012 Andreas Schneider - 2:4.0.0-154.rc3 -- Update to 4.0.0rc3. -- resolves: #805562 - Unable to share print queues. -- resolves: #863388 - Unable to reload smbd configuration with systemctl. - -* Wed Oct 10 2012 Alexander Bokovoy - 2:4.0.0-153.rc2 -- Use alternatives to configure winbind_krb5_locator.so -- Fix Requires for winbind. - -* Thu Oct 04 2012 Andreas Schneider - 2:4.0.0-152.rc2 -- Add kerberos AES support. -- Fix printing initialization. - -* Tue Oct 02 2012 Andreas Schneider - 2:4.0.0-151.rc2 -- Update to 4.0.0rc2. - -* Wed Sep 26 2012 Andreas Schneider - 2:4.0.0-150.rc1 -- Fix Obsoletes/Provides for update from samba4. -- Bump release number to be bigger than samba4. - -* Wed Sep 26 2012 Andreas Schneider - 2:4.0.0-96.rc1 -- Package smbprint again. - -* Wed Sep 26 2012 Andreas Schneider - 2:4.0.0-95.rc1 -- Update to 4.0.0rc1. - -* Mon Aug 20 2012 Guenther Deschner - 2:3.6.7-94.2 -- Update to 3.6.7 - -* Sat Jul 21 2012 Fedora Release Engineering - 2:3.6.6-93.2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild - -* Thu Jul 19 2012 Guenther Deschner - 2:3.6.6-93 -- Fix printing tdb upgrade for 3.6.6 -- resolves: #841609 - -* Sun Jul 15 2012 Ville Skyttä - 2:3.6.6-92 -- Call ldconfig at libwbclient and -winbind-clients post(un)install time. -- Fix empty localization files, use %%find_lang to find and %%lang-mark them. -- Escape macros in %%changelog. -- Fix source tarball URL. - -* Tue Jun 26 2012 Guenther Deschner - 2:3.6.6-91 -- Update to 3.6.6 - -* Thu Jun 21 2012 Andreas Schneider - 2:3.6.5-90 -- Fix ldonfig. -- Require systemd for samba-common package. -- resolves: #829197 - -* Mon Jun 18 2012 Andreas Schneider - 2:3.6.5-89 -- Fix usrmove paths. -- resolves: #829197 - -* Tue May 15 2012 Andreas Schneider - 2:3.6.5-88 -- Move tmpfiles.d config to common package as it is needed for smbd and - winbind. -- Make sure tmpfiles get created after installation. - -* Wed May 09 2012 Guenther Deschner - 2:3.6.5-87 -- Correctly use system iniparser library - -* Fri May 04 2012 Andreas Schneider - 2:3.6.5-86 -- Bump Epoch to fix a problem with a Samba4 update in testing. - -* Mon Apr 30 2012 Guenther Deschner - 1:3.6.5-85 -- Security Release, fixes CVE-2012-2111 -- resolves: #817551 - -* Mon Apr 23 2012 Andreas Schneider - 1:3.6.4-84 -- Fix creation of /var/run/samba. -- resolves: #751625 - -* Fri Apr 20 2012 Guenther Deschner - 1:3.6.4-83 -- Avoid private krb5_locate_kdc usage -- resolves: #754783 - -* Thu Apr 12 2012 Jon Ciesla - 1:3.6.4-82 -- Update to 3.6.4 -- Fixes CVE-2012-1182 - -* Mon Mar 19 2012 Andreas Schneider - 1:3.6.3-81 -- Fix provides for of libwclient-devel for samba-winbind-devel. - -* Thu Feb 23 2012 Andreas Schneider - 1:3.6.3-80 -- Add commented out 'max protocol' to the default config. - -* Mon Feb 13 2012 Andreas Schneider - 1:3.6.3-79 -- Create a libwbclient package. -- Replace winbind-devel with libwbclient-devel package. - -* Mon Jan 30 2012 Andreas Schneider - 1:3.6.3-78 -- Update to 3.6.3 -- Fixes CVE-2012-0817 - -* Sat Jan 14 2012 Fedora Release Engineering - 1:3.6.1-77.1 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild - -* Mon Dec 05 2011 Andreas Schneider - 1:3.6.1-77 -- Fix winbind cache upgrade. -- resolves: #760137 - -* Fri Nov 18 2011 Andreas Schneider - 1:3.6.1-76 -- Fix piddir to match with systemd files. -- Fix crash bug in the debug system. -- resolves: #754525 - -* Fri Nov 04 2011 Andreas Schneider - 1:3.6.1-75 -- Fix systemd dependencies -- resolves: #751397 - -* Wed Oct 26 2011 Andreas Schneider - 1:3.6.1-74 -- Update to 3.6.1 - -* Tue Oct 04 2011 Guenther Deschner - 1:3.6.0-73 -- Fix nmbd startup -- resolves: #741630 - -* Tue Sep 20 2011 Tom Callaway - 1:3.6.0-72 -- convert to systemd -- restore epoch from f15 - -* Sat Aug 13 2011 Guenther Deschner - 3.6.0-71 -- Update to 3.6.0 final - -* Sun Jul 31 2011 Guenther Deschner - 3.6.0rc3-70 -- Update to 3.6.0rc3 - -* Tue Jun 07 2011 Guenther Deschner - 3.6.0rc2-69 -- Update to 3.6.0rc2 - -* Tue May 17 2011 Guenther Deschner - 3.6.0rc1-68 -- Update to 3.6.0rc1 - -* Wed Apr 27 2011 Guenther Deschner - 3.6.0pre3-67 -- Update to 3.6.0pre3 - -* Wed Apr 13 2011 Guenther Deschner - 3.6.0pre2-66 -- Update to 3.6.0pre2 - -* Fri Mar 11 2011 Guenther Deschner - 3.6.0pre1-65 -- Enable quota support - -* Wed Feb 09 2011 Fedora Release Engineering - 0:3.6.0-64pre1.1 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild - -* Wed Nov 24 2010 Guenther Deschner - 3.6.0pre1-64 -- Add %%ghost entry for /var/run using tmpfs -- resolves: #656685 - -* Thu Aug 26 2010 Guenther Deschner - 3.6.0pre1-63 -- Put winbind krb5 locator plugin into a separate rpm -- resolves: #627181 - -* Tue Aug 03 2010 Guenther Deschner - 3.6.0pre1-62 -- Update to 3.6.0pre1 - -* Wed Jun 23 2010 Guenther Deschner - 3.5.4-61 -- Update to 3.5.4 - -* Wed May 19 2010 Guenther Deschner - 3.5.3-60 -- Update to 3.5.3 -- Make sure nmb and smb initscripts return LSB compliant return codes -- Fix winbind over ipv6 - -* Wed Apr 07 2010 Guenther Deschner - 3.5.2-59 -- Update to 3.5.2 - -* Mon Mar 08 2010 Simo Sorce - 3.5.1-58 -- Security update to 3.5.1 -- Fixes CVE-2010-0728 - -* Mon Mar 08 2010 Guenther Deschner - 3.5.0-57 -- Remove cifs.upcall and mount.cifs entirely - -* Mon Mar 01 2010 Guenther Deschner - 3.5.0-56 -- Update to 3.5.0 - -* Fri Feb 19 2010 Guenther Deschner - 3.5.0rc3-55 -- Update to 3.5.0rc3 - -* Tue Jan 26 2010 Guenther Deschner - 3.5.0rc2-54 -- Update to 3.5.0rc2 - -* Fri Jan 15 2010 Jeff Layton - 3.5.0rc1-53 -- separate out CIFS tools into cifs-utils package - -* Fri Jan 08 2010 Guenther Deschner - 3.5.0rc1-52 -- Update to 3.5.0rc1 - -* Tue Dec 15 2009 Guenther Deschner - 3.5.0pre2-51 -- Update to 3.5.0pre2 -- Remove umount.cifs - -* Wed Nov 25 2009 Guenther Deschner - 3.4.3-49 -- Various updates to inline documentation in default smb.conf file -- resolves: #483703 - -* Thu Oct 29 2009 Guenther Deschner - 3.4.3-48 -- Update to 3.4.3 - -* Fri Oct 09 2009 Simo Sorce - 3.4.2-47 -- Spec file cleanup -- Fix sources upstream location -- Remove conditionals to build talloc and tdb, now they are completely indepent - packages in Fedora -- Add defattr() where missing -- Turn all tabs into 4 spaces -- Remove unused migration script -- Split winbind-clients out of main winbind package to avoid multilib to include - huge packages for no good reason - -* Thu Oct 01 2009 Guenther Deschner - 3.4.2-0.46 -- Update to 3.4.2 -- Security Release, fixes CVE-2009-2813, CVE-2009-2948 and CVE-2009-2906 - -* Wed Sep 16 2009 Tomas Mraz - 3.4.1-0.45 -- Use password-auth common PAM configuration instead of system-auth - -* Wed Sep 09 2009 Guenther Deschner - 3.4.1-0.44 -- Update to 3.4.1 - -* Thu Aug 20 2009 Guenther Deschner - 3.4.0-0.43 -- Fix cli_read() -- resolves: #516165 - -* Thu Aug 06 2009 Guenther Deschner - 3.4.0-0.42 -- Fix required talloc version number -- resolves: #516086 - -* Sun Jul 26 2009 Fedora Release Engineering - 0:3.4.0-0.41.1 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild - -* Fri Jul 17 2009 Guenther Deschner - 3.4.0-0.41 -- Fix Bug #6551 (vuid and tid not set in sessionsetupX and tconX) -- Specify required talloc and tdb version for BuildRequires - -* Fri Jul 03 2009 Guenther Deschner - 3.4.0-0.40 -- Update to 3.4.0 - -* Fri Jun 19 2009 Guenther Deschner - 3.4.0rc1-0.39 -- Update to 3.4.0rc1 - -* Mon Jun 08 2009 Guenther Deschner - 3.4.0pre2-0.38 -- Update to 3.4.0pre2 - -* Thu Apr 30 2009 Guenther Deschner - 3.4.0pre1-0.37 -- Update to 3.4.0pre1 - -* Wed Apr 29 2009 Guenther Deschner - 3.3.4-0.36 -- Update to 3.3.4 - -* Mon Apr 20 2009 Guenther Deschner - 3.3.3-0.35 -- Enable build of idmap_tdb2 for clustered setups - -* Wed Apr 1 2009 Guenther Deschner - 3.3.3-0.34 -- Update to 3.3.3 - -* Thu Mar 26 2009 Simo Sorce - 3.3.2-0.33 -- Fix nmbd init script nmbd reload was causing smbd not nmbd to reload the - configuration -- Fix upstream bug 6224, nmbd was waiting 5+ minutes before running elections on - startup, causing your own machine not to show up in the network for 5 minutes - if it was the only client in that workgroup (fix committed upstream) - -* Thu Mar 12 2009 Guenther Deschner - 3.3.2-0.31 -- Update to 3.3.2 -- resolves: #489547 - -* Thu Mar 5 2009 Guenther Deschner - 3.3.1-0.30 -- Add libcap-devel to requires list (resolves: #488559) - -* Tue Mar 3 2009 Simo Sorce - 3.3.1-0.29 -- Make the talloc and ldb packages optionsl and disable their build within - the samba3 package, they are now built as part of the samba4 package - until they will both be released as independent packages. - -* Wed Feb 25 2009 Guenther Deschner - 3.3.1-0.28 -- Enable cluster support - -* Tue Feb 24 2009 Guenther Deschner - 3.3.1-0.27 -- Update to 3.3.1 - -* Sat Feb 21 2009 Simo Sorce - 3.3.0-0.26 -- Rename ldb* tools to ldb3* to avoid conflicts with newer ldb releases - -* Tue Feb 3 2009 Guenther Deschner - 3.3.0-0.25 -- Update to 3.3.0 final -- Add upstream fix for ldap connections to AD (Bug #6073) -- Remove bogus perl dependencies (resolves: #473051) - -* Fri Nov 28 2008 Guenther Deschner - 3.3.0-0rc1.24 -- Update to 3.3.0rc1 - -* Thu Nov 27 2008 Simo Sorce - 3.2.5-0.23 -- Security Release, fixes CVE-2008-4314 - -* Thu Sep 18 2008 Guenther Deschner - 3.2.4-0.22 -- Update to 3.2.4 -- resolves: #456889 -- move cifs.upcall to /usr/sbin - -* Wed Aug 27 2008 Guenther Deschner - 3.2.3-0.21 -- Security fix for CVE-2008-3789 - -* Mon Aug 25 2008 Guenther Deschner - 3.2.2-0.20 -- Update to 3.2.2 - -* Mon Aug 11 2008 Simo Sorce - 3.2.1-0.19 -- Add fix for CUPS problem, fixes bug #453951 - -* Wed Aug 6 2008 Simo Sorce - 3.2.1-0.18 -- Update to 3.2.1 - -* Tue Jul 1 2008 Guenther Deschner - 3.2.0-2.17 -- Update to 3.2.0 final -- resolves: #452622 - -* Tue Jun 10 2008 Guenther Deschner - 3.2.0-1.rc2.16 -- Update to 3.2.0rc2 -- resolves: #449522 -- resolves: #448107 - -* Fri May 30 2008 Guenther Deschner - 3.2.0-1.rc1.15 -- Fix security=server -- resolves: #449038, #449039 - -* Wed May 28 2008 Guenther Deschner - 3.2.0-1.rc1.14 -- Add fix for CVE-2008-1105 -- resolves: #446724 - -* Fri May 23 2008 Guenther Deschner - 3.2.0-1.rc1.13 -- Update to 3.2.0rc1 - -* Wed May 21 2008 Simo Sorce - 3.2.0-1.pre3.12 -- make it possible to print against Vista and XP SP3 as servers -- resolves: #439154 - -* Thu May 15 2008 Guenther Deschner - 3.2.0-1.pre3.11 -- Add "net ads join createcomputer=ou1/ou2/ou3" fix (BZO #5465) - -* Fri May 09 2008 Guenther Deschner - 3.2.0-1.pre3.10 -- Add smbclient fix (BZO #5452) - -* Fri Apr 25 2008 Guenther Deschner - 3.2.0-1.pre3.9 -- Update to 3.2.0pre3 - -* Tue Mar 18 2008 Guenther Deschner - 3.2.0-1.pre2.8 -- Add fixes for libsmbclient and support for r/o relocations - -* Mon Mar 10 2008 Guenther Deschner - 3.2.0-1.pre2.7 -- Fix libnetconf, libnetapi and msrpc DSSETUP call - -* Thu Mar 06 2008 Guenther Deschner - 3.2.0-1.pre2.6 -- Create separate packages for samba-winbind and samba-winbind-devel -- Add cifs.spnego helper - -* Wed Mar 05 2008 Guenther Deschner - 3.2.0-1.pre2.3 -- Update to 3.2.0pre2 -- Add talloc and tdb lib and devel packages -- Add domainjoin-gui package - -* Fri Feb 22 2008 Simo Sorce - 3.2.0-0.pre1.3 -- Try to fix GCC 4.3 build -- Add --with-dnsupdate flag and also make sure other flags are required just to - be sure the features are included without relying on autodetection to be - successful - -* Tue Feb 19 2008 Fedora Release Engineering - 0:3.2.0-1.pre1.2 -- Autorebuild for GCC 4.3 - -* Tue Dec 04 2007 Release Engineering - 3.2.0-0.pre1.2 -- Rebuild for openldap bump - -* Thu Oct 18 2007 Guenther Deschner 3.2.0-0.pre1.1.fc9 -- 32/64bit padding fix (affects multilib installations) - -* Mon Oct 8 2007 Simo Sorce 3.2.0-0.pre1.fc9 -- New major relase, minor switched from 0 to 2 -- License change, the code is now GPLv3+ -- Numerous improvements and bugfixes included -- package libsmbsharemodes too -- remove smbldap-tools as they are already packaged separately in Fedora -- Fix bug 245506 - -* Tue Oct 2 2007 Simo Sorce 3.0.26a-1.fc8 -- rebuild with AD DNS Update support - -* Tue Sep 11 2007 Simo Sorce 3.0.26a-0.fc8 -- upgrade to the latest upstream realease -- includes security fixes released today in 3.0.26 - -* Fri Aug 24 2007 Simo Sorce 3.0.25c-4.fc8 -- add fix reported upstream for heavy idmap_ldap memleak - -* Tue Aug 21 2007 Simo Sorce 3.0.25c-3.fc8 -- fix a few places were "open" is used an interfere with the new glibc - -* Tue Aug 21 2007 Simo Sorce 3.0.25c-2.fc8 -- remove old source -- add patch to fix samba bugzilla 4772 - -* Tue Aug 21 2007 Guenther Deschner 3.0.25c-0.fc8 -- update to 3.0.25c - -* Fri Jun 29 2007 Simo Sorce 3.0.25b-3.fc8 -- handle cases defined in #243766 - -* Tue Jun 26 2007 Simo Sorce 3.0.25b-2.fc8 -- update to 3.0.25b -- better error codes for init scripts: #244823 - -* Tue May 29 2007 Günther Deschner -- fix pam_smbpass patch. - -* Fri May 25 2007 Simo Sorce -- update to 3.0.25a as it contains many fixes -- add a fix for pam_smbpass made by Günther but committed upstream after 3.0.25a was cut. - -* Mon May 14 2007 Simo Sorce -- final 3.0.25 -- includes security fixes for CVE-2007-2444,CVE-2007-2446,CVE-2007-2447 - -* Mon Apr 30 2007 Günther Deschner -- move to 3.0.25rc3 - -* Thu Apr 19 2007 Simo Sorce -- fixes in the spec file -- moved to 3.0.25rc1 -- addedd patches (merged upstream so they will be removed in 3.0.25rc2) - -* Wed Apr 4 2007 Simo Sorce 3.0.24-12.fc7 -- fixes in smb.conf -- advice in smb.conf to put scripts in /var/lib/samba/scripts -- create /var/lib/samba/scripts so that selinux can be happy -- fix Vista problems with msdfs errors - -* Tue Apr 03 2007 Guenther Deschner 3.0.24-11.fc7 -- enable PAM and NSS dlopen checks during build -- fix unresolved symbols in libnss_wins.so (bug #198230) - -* Fri Mar 30 2007 Simo Sorce 3.0.24-10.fc7 -- set passdb backend = tdbsam as default in smb.conf -- remove samba-docs dependency from swat, that was a mistake -- put back COPYING and other files in samba-common -- put examples in samba not in samba-docs -- leave only stuff under docs/ in samba-doc - -* Thu Mar 29 2007 Simo Sorce 3.0.24-9.fc7 -- integrate most of merge review proposed changes (bug #226387) -- remove libsmbclient-devel-static and simply stop shipping the - static version of smbclient as it seem this is deprecated and - actively discouraged - -* Wed Mar 28 2007 Simo Sorce 3.0.24-8.fc7 -- fix for bug #176649 - -* Mon Mar 26 2007 Simo Sorce -- remove patch for bug 106483 as it introduces a new bug that prevents - the use of a credentials file with the smbclient tar command -- move the samba private dir from being the same as the config dir - (/etc/samba) to /var/lib/samba/private - -* Mon Mar 26 2007 Simo Sorce 3.0.24-7.fc7 -- make winbindd start earlier in the init process, at the same time - ypbind is usually started as well -- add a sepoarate init script for nmbd called nmb, we need to be able - to restart nmbd without dropping al smbd connections unnecessarily - -* Fri Mar 23 2007 Simo Sorce -- add samba.schema to /etc/openldap/schema - -* Thu Mar 22 2007 Florian La Roche -- adjust the Requires: for the scripts, add "chkconfig --add smb" - -* Tue Mar 20 2007 Simo Sorce 3.0.24-6.fc7 -- do not put comments inline on smb.conf options, they may be read - as part of the value (for example log files names) - -* Mon Mar 19 2007 Simo Sorce 3.0.24-5.fc7 -- actually use the correct samba.pamd file not the old samba.pamd.stack file -- fix logifles and use upstream convention of log.* instead of our old *.log - Winbindd creates its own log.* files anyway so we will be more consistent -- install our own (enhanced) default smb.conf file -- Fix pam_winbind acct_mgmt PAM result code (prevented local users from - logging in). Fixed by Guenther. -- move some files from samba to samba-common as they are used with winbindd - as well - -* Fri Mar 16 2007 Guenther Deschner 3.0.24-4.fc7 -- fix arch macro which reported Vista to Samba clients. - -* Thu Mar 15 2007 Simo Sorce 3.0.24-3.fc7 -- Directories reorg, tdb files must go to /var/lib, not - to /var/cache, add migration script in %%post common -- Split out libsmbclient, devel and doc packages -- Remove libmsrpc.[h|so] for now as they are not really usable -- Remove kill -HUP from rotate, samba use -HUP for other things - noit to reopen logs - -* Tue Feb 20 2007 Simo Sorce 3.0.24-2.fc7 -- New upstream release -- Fix packaging issue wrt idmap modules used only by smbd -- Addedd Vista Patchset for compatibility with Windows Vista -- Change default of "msdfs root", it seem to cause problems with - some applications and it has been proposed to change it for - 3.0.25 upstream - -* Fri Sep 1 2006 Jay Fenlason 3.0.23c-2 -- New upstream release. - -* Tue Aug 8 2006 Jay Fenlason 3.0.23b-2 -- New upstream release. - -* Mon Jul 24 2006 Jay Fenlason 3.0.23a-3 -- Fix the -logfiles patch to close - bz#199607 Samba compiled with wrong log path. - bz#199206 smb.conf has incorrect log file path - -* Mon Jul 24 2006 Jay Fenlason 3.0.23a-2 -- Upgrade to new upstream 3.0.23a -- include upstream samr_alias patch - -* Tue Jul 11 2006 Jay Fenlason 3.0.23-2 -- New upstream release. -- Use modified filter-requires-samba.sh from packaging/RHEL/setup/ - to get rid of bogus dependency on perl(Unicode::MapUTF8) -- Update the -logfiles and -smb.conf patches to work with 3.0.23 - -* Thu Jul 6 2006 Jay Fenlason 3.0.23-0.RC3 -- New upstream RC release. -- Update the -logfiles, and -passwd patches for - 3.0.23rc3 -- Include the change to smb.init from Bastien Nocera ) - to close - bz#182560 Wrong retval for initscript when smbd is dead -- Update this spec file to build with 3.0.23rc3 -- Remove the -install.mount.smbfs patch, since we don't install - mount.smbfs any more. - -* Wed Jun 14 2006 Tomas Mraz - 2.0.21c-3 -- rebuilt with new gnutls - -* Fri Mar 17 2006 Jay Fenlason 2.0.21c-2 -- New upstream version. - -* Mon Feb 13 2006 Jay Fenlason 3.0.21b-2 -- New upstream version. -- Since the rawhide kernel has dropped support for smbfs, remove smbmount - and smbumount. Users should use mount.cifs instead. -- Upgrade to 3.0.21b - -* Fri Feb 10 2006 Jesse Keating - 0:3.0.20b-2.1.1 -- bump again for double-long bug on ppc(64) - -* Fri Dec 09 2005 Jesse Keating -- rebuilt - -* Sun Nov 13 2005 Jay Fenlason 3.0.20b-2 -- turn on -DLDAP_DEPRECATED to allow access to ldap functions that have - been depricated in 2.3.11, but which don't have well-documented - replacements (ldap_simple_bind_s(), for example). -- Upgrade to 3.0.20b, which includes all the previous upstream patches. -- Updated the -warnings patch for 3.0.20a. -- Include --with-shared-modules=idmap_ad,idmap_rid to close - bz#156810 --with-shared-modules=idmap_ad,idmap_rid -- Include the new samba.pamd from Tomas Mraz (tmraz@redhat.com) to close - bz#170259 pam_stack is deprecated - -* Sun Nov 13 2005 Warren Togami 3.0.20-3 -- epochs from deps, req exact release -- rebuild against new openssl - -* Mon Aug 22 2005 Jay Fenlason 3.0.20-2 -- New upstream release - Includes five upstream patches -bug3010_v1, -groupname_enumeration_v3, - -regcreatekey_winxp_v1, -usrmgr_groups_v1, and -winbindd_v1 - This obsoletes the -pie and -delim patches - the -warning and -gcc4 patches are obsolete too - The -man, -passwd, and -smbspool patches were updated to match 3.0.20pre1 - Also, the -quoting patch was implemented differently upstream - There is now a umount.cifs executable and manpage - We run autogen.sh as part of the build phase - The testprns command is now gone - libsmbclient now has a man page -- Include -bug106483 patch to close - bz#106483 smbclient: -N negates the provided password, despite documentation -- Added the -warnings patch to quiet some compiler warnings. -- Removed many obsolete patches from CVS. - -* Mon May 2 2005 Jay Fenlason 3.0.14a-2 -- New upstream release. -- the -64bit-timestamps, -clitar, -establish_trust, user_rights_v1, - winbind_find_dc_v2 patches are now obsolete. - -* Thu Apr 7 2005 Jay Fenlason 3.0.13-2 -- New upstream release -- add my -quoting patch, to fix swat with strings that contain - html meta-characters, and to use correct quote characters in - lists, closing bz#134310 -- include the upstream winbindd_2k3sp1 patch -- include the -smbclient patch. -- include the -hang patch from upstream. - -* Thu Mar 24 2005 Florian La Roche -- add a "exit 0" to the postun of the main samba package - -* Wed Mar 2 2005 Tomas Mraz 3.0.11-5 -- rebuild with openssl-0.9.7e - -* Thu Feb 24 2005 Jay Fenlason 3.0.11-4 -- Use the updated filter-requires-samba.sh file, so we don't accidentally - pick up a dependency on perl(Crypt::SmbHash) - -* Fri Feb 18 2005 Jay Fenlason 3.0.11-3 -- add -gcc4 patch to compile with gcc 4. -- remove the now obsolete -smbclient-kerberos.patch -- Include four upstream patches from - http://samba.org/~jerry/patches/post-3.0.11/ - (Slightly modified the winbind_find_dc_v2 patch to apply easily with - rpmbuild). - -* Fri Feb 4 2005 Jay Fenlason 3.0.11-2 -- include -smbspool patch to close bz#104136 - -* Wed Jan 12 2005 Jay Fenlason 3.0.10-4 -- Update the -man patch to fix ntlm_auth.1 too. -- Move pam_smbpass.so to the -common package, so both the 32 - and 64-bit versions will be installed on multiarch platforms. - This closes bz#143617 -- Added new -delim patch to fix mount.cifs so it can accept - passwords with commas in them (via environment or credentials - file) to close bz#144198 - -* Wed Jan 12 2005 Tim Waugh 3.0.10-3 -- Rebuilt for new readline. - -* Fri Dec 17 2004 Jay Fenlason 3.0.10-2 -- New upstream release that closes CAN-2004-1154 bz#142544 -- Include the -64bit patch from Nalin. This closes bz#142873 -- Update the -logfiles patch to work with 3.0.10 -- Create /var/run/winbindd and make it part of the -common rpm to close - bz#142242 - -* Mon Nov 22 2004 Jay Fenlason 3.0.9-2 -- New upstream release. This obsoletes the -secret patch. - Include my changetrustpw patch to make "net ads changetrustpw" stop - aborting. This closes #134694 -- Remove obsolete triggers for ancient samba versions. -- Move /var/log/samba to the -common rpm. This closes #76628 -- Remove the hack needed to get around the bad docs files in the - 3.0.8 tarball. -- Change the comment in winbind.init to point at the correct pidfile. - This closes #76641 - -* Mon Nov 22 2004 Than Ngo 3.0.8-4 -- fix unresolved symbols in libsmbclient which caused applications - such as KDE's konqueror to fail when accessing smb:// URLs. #139894 - -* Thu Nov 11 2004 Jay Fenlason 3.0.8-3.1 -- Rescue the install.mount.smbfs patch from Juanjo Villaplana - (villapla@si.uji.es) to prevent building the srpm from trashing your - installed /usr/bin/smbmount - -* Tue Nov 9 2004 Jay Fenlason 3.0.8-3 -- Include the corrected docs tarball, and use it instead of the - obsolete docs from the upstream 3.0.8 tarball. -- Update the logfiles patch to work with the updated docs. - -* Mon Nov 8 2004 Jay Fenlason 3.0.8-2 -- New upstream version fixes CAN-2004-0930. This obsoletes the - disable-sendfile, salt, signing-shortkey and fqdn patches. -- Add my ugly non-ascii-domain patch. -- Updated the pie patch for 3.0.8. -- Updated the logfiles patch for 3.0.8. - -* Tue Oct 26 2004 Jay Fenlason 3.0.8-0.pre2 -- New upstream version -- Add Nalin's signing-shortkey patch. - -* Tue Oct 19 2004 Jay Fenlason 3.0.8-0.pre1.3 -- disable the -salt patch, because it causes undefined references in - libsmbclient that prevent gnome-vfs from building. - -* Fri Oct 15 2004 Jay Fenlason 3.0.8-0.pre1.2 -- Re-enable the x_fclose patch that was accidentally disabled - in 3.0.8-0.pre1.1. This closes #135832 -- include Nalin's -fqdn and -salt patches. - -* Wed Oct 13 2004 Jay Fenlason 3.0.8-0.pre1.1 -- Include disable-sendfile patch to default "use sendfile" to "no". - This closes #132779 - -* Wed Oct 6 2004 Jay Fenlason -- Include patch from Steven Lawrance (slawrance@yahoo.com) that modifies - smbmnt to work with 32-bit uids. - -* Mon Sep 27 2004 Jay Fenlason 3.0.8-0.pre1 -- new upstream release. This obsoletes the ldapsam_compat patches. - -* Wed Sep 15 2004 Jay Fenlason 3.0.7-4 -- Update docs section to not carryover the docs/manpages directory - This moved many files from /usr/share/doc/samba-3.0.7/docs/* to - /usr/share/doc/samba-3.0.7/* -- Modify spec file as suggested by Rex Dieter (rdieter@math.unl.edu) - to correctly create libsmbclient.so.0 and to use %%_initrddir instead - of rolling our own. This closes #132642 -- Add patch to default "use sendfile" to no, since sendfile appears to - be broken -- Add patch from Volker Lendecke to help make - ldapsam_compat work again. -- Add patch from "Vince Brimhall" for ldapsam_compat - These two patches close bugzilla #132169 - -* Mon Sep 13 2004 Jay Fenlason 3.0.7-3 -- Upgrade to 3.0.7, which fixes CAN-2004-0807 CAN-2004-0808 - This obsoletes the 3.0.6-schema patch. -- Update BuildRequires line to include openldap-devel openssl-devel - and cups-devel - -* Mon Aug 16 2004 Jay Fenlason 3.0.6-3 -- New upstream version. -- Include post 3.0.6 patch from "Gerald (Jerry) Carter" - to fix a duplicate in the LDAP schema. -- Include 64-bit timestamp patch from Ravikumar (rkumar@hp.com) - to allow correct timestamp handling on 64-bit platforms and fix #126109. -- reenable the -pie patch. Samba is too widely used, and too vulnerable - to potential security holes to disable an important security feature - like -pie. The correct fix is to have the toolchain not create broken - executables when programs compiled -pie are stripped. -- Remove obsolete patches. -- Modify this spec file to put libsmbclient.{a,so} in the right place on - x86_64 machines. - -* Thu Aug 5 2004 Jason Vas Dias 3.0.5-3 -- Removed '-pie' patch - 3.0.5 uses -fPIC/-PIC, and the combination -- resulted in executables getting corrupt stacks, causing smbmnt to -- get a SIGBUS in the mount() call (bug 127420). - -* Fri Jul 30 2004 Jay Fenlason 3.0.5-2 -- Upgrade to 3.0.5, which is a regression from 3.0.5pre1 for a - security fix. -- Include the 3.0.4-backport patch from the 3E branch. This restores - some of the 3.0.5pre1 and 3.0.5rc1 functionality. - -* Tue Jul 20 2004 Jay Fenlason 3.0.5-0.pre1.1 -- Backport base64_decode patche to close CAN-2004-0500 -- Backport hash patch to close CAN-2004-0686 -- use_authtok patch from Nalin Dahyabhai -- smbclient-kerberos patch from Alexander Larsson -- passwd patch uses "*" instead of "x" for "hashed" passwords for - accounts created by winbind. "x" means "password is in /etc/shadow" to - brain-damaged pam_unix module. - -* Fri Jul 2 2004 Jay Fenlason 3.0.5.0pre1.0 -- New upstream version -- use %% { SOURCE1 } instead of a hardcoded path -- include -winbind patch from Gerald (Jerry) Carter (jerry@samba.org) - https://bugzilla.samba.org/show_bug.cgi?id=1315 - to make winbindd work against Windows versions that do not have - 128 bit encryption enabled. -- Moved %%{_bindir}/net to the -common package, so that folks who just - want to use winbind, etc don't have to install -client in order to - "net join" their domain. -- New upstream version obsoletes the patches added in 3.0.3-5 -- Remove smbgetrc.5 man page, since we don't ship smbget. - -* Tue Jun 15 2004 Elliot Lee -- rebuilt - -* Tue May 4 2004 Jay Fenlason 3.0.3-5 -- Patch to allow password changes from machines patched with - Microsoft hotfix MS04-011. -- Include patches for https://bugzilla.samba.org/show_bug.cgi?id=1302 - and https://bugzilla.samba.org/show_bug.cgi?id=1309 - -* Thu Apr 29 2004 Jay Fenlason 3.0.3-4 -- Samba 3.0.3 released. - -* Wed Apr 21 2004 jay Fenlason 3.0.3-3.rc1 -- New upstream version -- updated spec file to make libsmbclient.so executable. This closes - bugzilla #121356 - -* Mon Apr 5 2004 Jay Fenlason 3.0.3-2.pre2 -- New upstream version -- Updated configure line to remove --with-fhs and to explicitly set all - the directories that --with-fhs was setting. We were overriding most of - them anyway. This closes #118598 - -* Mon Mar 15 2004 Jay Fenlason 3.0.3-1.pre1 -- New upstream version. -- Updated -pie and -logfiles patches for 3.0.3pre1 -- add krb5-devel to buildrequires, fixes #116560 -- Add patch from Miloslav Trmac (mitr@volny.cz) to allow non-root to run - "service smb status". This fixes #116559 - -* Tue Mar 02 2004 Elliot Lee -- rebuilt - -* Mon Feb 16 2004 Jay Fenlason 3.0.2a-1 -- Upgrade to 3.0.2a - -* Mon Feb 16 2004 Karsten Hopp 3.0.2-7 -- fix ownership in -common package - -* Fri Feb 13 2004 Elliot Lee -- rebuilt - -* Fri Feb 13 2004 Jay Fenlason -- Change all requires lines to list an explicit epoch. Closes #102715 -- Add an explicit Epoch so that %%{epoch} is defined. - -* Mon Feb 9 2004 Jay Fenlason 3.0.2-5 -- New upstream version: 3.0.2 final includes security fix for #114995 - (CAN-2004-0082) -- Edit postun script for the -common package to restart winbind when - appropriate. Fixes bugzilla #114051. - -* Mon Feb 2 2004 Jay Fenlason 3.0.2-3rc2 -- add %%dir entries for %%{_libdir}/samba and %%{_libdir}/samba/charset -- Upgrade to new upstream version -- build mount.cifs for the new cifs filesystem in the 2.6 kernel. - -* Mon Jan 19 2004 Jay Fenlason 3.0.2-1rc1 -- Upgrade to new upstream version - -* Wed Dec 17 2003 Felipe Alfaro Solana 3.0.1-1 -- Update to 3.0.1 -- Removed testparm patch as it's already merged -- Removed Samba.7* man pages -- Fixed .buildroot patch -- Fixed .pie patch -- Added new /usr/bin/tdbdump file - -* Thu Sep 25 2003 Jay Fenlason 3.0.0-15 -- New 3.0.0 final release -- merge nmbd-netbiosname and testparm patches from 3E branch -- updated the -logfiles patch to work against 3.0.0 -- updated the pie patch -- update the VERSION file during build -- use make -j if avaliable -- merge the winbindd_privileged change from 3E -- merge the "rm /usr/lib" patch that allows Samba to build on 64-bit - platforms despite the broken Makefile - -* Mon Aug 18 2003 Jay Fenlason -- Merge from samba-3E-branch after samba-3.0.0rc1 was released - -* Wed Jul 23 2003 Jay Fenlason 3.0.0-3beta3 -- Merge from 3.0.0-2beta3.3E -- (Correct log file names (#100981).) -- (Fix pidfile directory in samab.log) -- (Remove obsolete samba-3.0.0beta2.tar.bz2.md5 file) -- (Move libsmbclient to the -common package (#99449)) - -* Sun Jun 22 2003 Nalin Dahyabhai 2.2.8a-4 -- rebuild - -* Wed Jun 04 2003 Elliot Lee -- rebuilt - -* Wed May 28 2003 Jay Fenlason 2.2.8a-2 -- add libsmbclient.so for gnome-vfs-extras -- Edit specfile to specify /var/run for pid files -- Move /tmp/.winbindd/socket to /var/run/winbindd/socket - -* Wed May 14 2003 Florian La Roche -- add proper ldconfig calls - -* Thu Apr 24 2003 Jay Fenlason 2.2.8a-1 -- upgrade to 2.2.8a -- remove old .md5 files -- add "pid directory = /var/run" to the smb.conf file. Fixes #88495 -- Patch from jra@dp.samba.org to fix a delete-on-close regression - -* Mon Mar 24 2003 Jay Fenlason 2.2.8-0 -- Upgrade to 2.2.8 -- removed commented out patches. -- removed old patches and .md5 files from the repository. -- remove duplicate /sbin/chkconfig --del winbind which causes - warnings when removing samba. -- Fixed minor bug in smbprint that causes it to fail when called with - more than 10 parameters: the accounting file (and spool directory - derived from it) were being set wrong due to missing {}. This closes - bug #86473. -- updated smb.conf patch, includes new defaults to close bug #84822. - -* Mon Feb 24 2003 Elliot Lee -- rebuilt - -* Thu Feb 20 2003 Jonathan Blandford 2.2.7a-5 -- remove swat.desktop file - -* Thu Feb 20 2003 Nalin Dahyabhai 2.2.7a-4 -- relink libnss_wins.so with SHLD="%%{__cc} -lnsl" to force libnss_wins.so to - link with libnsl, avoiding unresolved symbol errors on functions in libnsl - -* Mon Feb 10 2003 Jay Fenlason 2.2.7a-3 -- edited spec file to put .so files in the correct directories - on 64-bit platforms that have 32-bit compatability issues - (sparc64, x86_64, etc). This fixes bugzilla #83782. -- Added samba-2.2.7a-error.patch from twaugh. This fixes - bugzilla #82454. - -* Wed Jan 22 2003 Tim Powers -- rebuilt - -* Thu Jan 9 2003 Jay Fenlason 2.2.7a-1 -- Update to 2.2.7a -- Change default printing system to CUPS -- Turn on pam_smbpass -- Turn on msdfs - -* Sat Jan 4 2003 Jeff Johnson 2.2.7-5 -- use internal dep generator. - -* Sat Dec 14 2002 Tim Powers 2.2.7-4 -- don't use rpms internal dep generator - -* Mon Dec 02 2002 Elliot Lee 2.2.7-3 -- Fix missing doc files. -- Fix multilib issues - -* Wed Nov 20 2002 Bill Nottingham 2.2.7-2 -- update to 2.2.7 -- add patch for LFS in smbclient () - -* Wed Aug 28 2002 Trond Eivind Glomsød 2.2.5-10 -- logrotate fixes (#65007) - -* Mon Aug 26 2002 Trond Eivind Glomsrød 2.2.5-9 -- /usr/lib was used in place of %%{_libdir} in three locations (#72554) - -* Mon Aug 5 2002 Trond Eivind Glomsrød 2.2.5-8 -- Initscript fix (#70720) - -* Fri Jul 26 2002 Trond Eivind Glomsrød 2.2.5-7 -- Enable VFS support and compile the "recycling" module (#69796) -- more selective includes of the examples dir - -* Tue Jul 23 2002 Trond Eivind Glomsrød 2.2.5-6 -- Fix the lpq parser for better handling of LPRng systems (#69352) - -* Tue Jul 23 2002 Trond Eivind Glomsrød 2.2.5-5 -- desktop file fixes (#69505) - -* Wed Jun 26 2002 Trond Eivind Glomsrød 2.2.5-4 -- Enable ACLs - -* Tue Jun 25 2002 Trond Eivind Glomsrød 2.2.5-3 -- Make it not depend on Net::LDAP - those are doc files and examples - -* Fri Jun 21 2002 Tim Powers -- automated rebuild - -* Thu Jun 20 2002 Trond Eivind Glomsrød 2.2.5-1 -- 2.2.5 - -* Fri Jun 14 2002 Trond Eivind Glomsrød 2.2.4-5 -- Move the post/preun of winbind into the -common subpackage, - where the script is (#66128) - -* Tue Jun 4 2002 Trond Eivind Glomsrød 2.2.4-4 -- Fix pidfile locations so it runs properly again (2.2.4 - added a new directtive - #65007) - -* Thu May 23 2002 Tim Powers -- automated rebuild - -* Tue May 14 2002 Trond Eivind Glomsrød 2.2.4-2 -- Fix #64804 - -* Thu May 9 2002 Trond Eivind Glomsrød 2.2.4-1 -- 2.2.4 -- Removed some zero-length and CVS internal files -- Make it build - -* Wed Apr 10 2002 Trond Eivind Glomsrød 2.2.3a-6 -- Don't use /etc/samba.d in smbadduser, it should be /etc/samba - -* Thu Apr 4 2002 Trond Eivind Glomsrød 2.2.3a-5 -- Add libsmbclient.a w/headerfile for KDE (#62202) - -* Tue Mar 26 2002 Trond Eivind Glomsrød 2.2.3a-4 -- Make the logrotate script look the correct place for the pid files - -* Thu Mar 14 2002 Nalin Dahyabhai 2.2.3a-3 -- include interfaces.o in pam_smbpass.so, which needs symbols from interfaces.o - (patch posted to samba-list by Ilia Chipitsine) - -* Thu Feb 21 2002 Trond Eivind Glomsrød 2.2.3a-2 -- Rebuild - -* Thu Feb 7 2002 Trond Eivind Glomsrød 2.2.3a-1 -- 2.2.3a - -* Mon Feb 4 2002 Trond Eivind Glomsrød 2.2.3-1 -- 2.2.3 - -* Thu Nov 29 2001 Trond Eivind Glomsrød 2.2.2-8 -- New pam configuration file for samba - -* Tue Nov 27 2001 Trond Eivind Glomsrød 2.2.2-7 -- Enable PAM session controll and password sync - -* Tue Nov 13 2001 Trond Eivind Glomsrød 2.2.2-6 -- Move winbind files to samba-common. Add separate initscript for - winbind -- Fixes for winbind - protect global variables with mutex, use - more secure getenv - -* Thu Nov 8 2001 Trond Eivind Glomsrød 2.2.2-5 -- Teach smbadduser about "getent passwd" -- Fix more pid-file references -- Add (conditional) winbindd startup to the initscript, configured in - /etc/sysconfig/samba - -* Wed Nov 7 2001 Trond Eivind Glomsrød 2.2.2-4 -- Fix pid-file reference in logrotate script -- include pam and nss modules for winbind - -* Mon Nov 5 2001 Trond Eivind Glomsrød 2.2.2-3 -- Add "--with-utmp" to configure options (#55372) -- Include winbind, pam_smbpass.so, rpcclient and smbcacls -- start using /var/cache/samba, we need to keep state and there is - more than just locks involved - -* Sat Nov 03 2001 Florian La Roche 2.2.2-2 -- add "reload" to the usage string in the startup script - -* Mon Oct 15 2001 Trond Eivind Glomsrød 2.2.2-1 -- 2.2.2 - -* Tue Sep 18 2001 Trond Eivind Glomsrød 2.2.1a-5 -- Add patch from Jeremy Allison to fix IA64 alignment problems (#51497) - -* Mon Aug 13 2001 Trond Eivind Glomsrød -- Don't include smbpasswd in samba, it's in samba-common (#51598) -- Add a disabled "obey pam restrictions" statement - it's not - active, as we use encrypted passwords, but if the admin turns - encrypted passwords off the choice is available. (#31351) - -* Wed Aug 8 2001 Trond Eivind Glomsrød -- Use /var/cache/samba instead of /var/lock/samba -- Remove "domain controller" keyword from smb.conf, it's - deprecated (from #13704) -- Sync some examples with smb.conf.default -- Fix password synchronization (#16987) - -* Fri Jul 20 2001 Trond Eivind Glomsrød -- Tweaks of BuildRequires (#49581) - -* Wed Jul 11 2001 Trond Eivind Glomsrød -- 2.2.1a bugfix release - -* Tue Jul 10 2001 Trond Eivind Glomsrød -- 2.2.1, which should work better for XP - -* Sat Jun 23 2001 Trond Eivind Glomsrød -- 2.2.0a security fix -- Mark lograte and pam configuration files as noreplace - -* Fri Jun 22 2001 Trond Eivind Glomsrød -- Add the /etc/samba directory to samba-common - -* Thu Jun 21 2001 Trond Eivind Glomsrød -- Add improvements to the smb.conf as suggested in #16931 - -* Tue Jun 19 2001 Trond Eivind Glomsrød -- (these changes are from the non-head version) -- Don't include /usr/sbin/samba, it's the same as the initscript -- unset TMPDIR, as samba can't write into a TMPDIR owned - by root (#41193) -- Add pidfile: lines for smbd and nmbd and a config: line - in the initscript (#15343) -- don't use make -j -- explicitly include /usr/share/samba, not just the files in it - -* Tue Jun 19 2001 Bill Nottingham -- mount.smb/mount.smbfs go in /sbin, *not* %%{_sbindir} - -* Fri Jun 8 2001 Preston Brown -- enable encypted passwords by default - -* Thu Jun 7 2001 Helge Deller -- build as 2.2.0-1 release -- skip the documentation-directories docbook, manpages and yodldocs -- don't include *.sgml documentation in package -- moved codepage-directory to /usr/share/samba/codepages -- make it compile with glibc-2.2.3-10 and kernel-headers-2.4.2-2 - -* Mon May 21 2001 Helge Deller -- updated to samba 2.2.0 -- moved codepages to %%{_datadir}/samba/codepages -- use all available CPUs for building rpm packages -- use %%{_xxx} defines at most places in spec-file -- "License:" replaces "Copyright:" -- dropped excludearch sparc -- de-activated japanese patches 100 and 200 for now - (they need to be fixed and tested wth 2.2.0) -- separated swat.desktop file from spec-file and added - german translations -- moved /etc/sysconfig/samba to a separate source-file -- use htmlview instead of direct call to netscape in - swat.desktop-file - -* Mon May 7 2001 Bill Nottingham -- device-remove security fix again () - -* Fri Apr 20 2001 Bill Nottingham -- fix tempfile security problems, officially () -- update to 2.0.8 - -* Sun Apr 8 2001 Bill Nottingham -- turn of SSL, kerberos - -* Thu Apr 5 2001 Bill Nottingham -- fix tempfile security problems (patch from ) - -* Thu Mar 29 2001 Bill Nottingham -- fix quota support, and quotas with the 2.4 kernel (#31362, #33915) - -* Mon Mar 26 2001 Nalin Dahyabhai -- tweak the PAM code some more to try to do a setcred() after initgroups() -- pull in all of the optflags on i386 and sparc -- don't explicitly enable Kerberos support -- it's only used for password - checking, and if PAM is enabled it's a no-op anyway - -* Mon Mar 5 2001 Tim Waugh -- exit successfully from preun script (bug #30644). - -* Fri Mar 2 2001 Nalin Dahyabhai -- rebuild in new environment - -* Wed Feb 14 2001 Bill Nottingham -- updated japanese stuff (#27683) - -* Fri Feb 9 2001 Bill Nottingham -- fix trigger (#26859) - -* Wed Feb 7 2001 Bill Nottingham -- add i18n support, japanese patch (#26253) - -* Wed Feb 7 2001 Trond Eivind Glomsrød -- i18n improvements in initscript (#26537) - -* Wed Jan 31 2001 Bill Nottingham -- put smbpasswd in samba-common (#25429) - -* Wed Jan 24 2001 Bill Nottingham -- new i18n stuff - -* Sun Jan 21 2001 Bill Nottingham -- rebuild - -* Thu Jan 18 2001 Bill Nottingham -- i18n-ize initscript -- add a sysconfig file for daemon options (#23550) -- clarify smbpasswd man page (#23370) -- build with LFS support (#22388) -- avoid extraneous pam error messages (#10666) -- add Urban Widmark's bug fixes for smbmount (#19623) -- fix setgid directory modes (#11911) -- split swat into subpackage (#19706) - -* Wed Oct 25 2000 Nalin Dahyabhai -- set a default CA certificate path in smb.conf (#19010) -- require openssl >= 0.9.5a-20 to make sure we have a ca-bundle.crt file - -* Mon Oct 16 2000 Bill Nottingham -- fix swat only_from line (#18726, others) -- fix attempt to write outside buildroot on install (#17943) - -* Mon Aug 14 2000 Bill Nottingham -- add smbspool back in (#15827) -- fix absolute symlinks (#16125) - -* Sun Aug 6 2000 Philipp Knirsch -- bugfix for smbadduser script (#15148) - -* Mon Jul 31 2000 Matt Wilson -- patch configure.ing (patch11) to disable cups test -- turn off swat by default - -* Fri Jul 28 2000 Bill Nottingham -- fix condrestart stuff - -* Fri Jul 21 2000 Bill Nottingham -- add copytruncate to logrotate file (#14360) -- fix init script (#13708) - -* Sat Jul 15 2000 Bill Nottingham -- move initscript back -- remove 'Using Samba' book from %%doc -- move stuff to /etc/samba (#13708) -- default configuration tweaks (#13704) -- some logrotate tweaks - -* Wed Jul 12 2000 Prospector -- automatic rebuild - -* Tue Jul 11 2000 Bill Nottingham -- fix logrotate script (#13698) - -* Thu Jul 6 2000 Bill Nottingham -- fix initscripts req (prereq /etc/init.d) - -* Wed Jul 5 2000 Than Ngo -- add initdir macro to handle the initscript directory -- add a new macro to handle /etc/pam.d/system-auth - -* Thu Jun 29 2000 Nalin Dahyabhai -- enable Kerberos 5 and SSL support -- patch for duplicate profile.h headers - -* Thu Jun 29 2000 Bill Nottingham -- fix init script - -* Tue Jun 27 2000 Bill Nottingham -- rename samba logs (#11606) - -* Mon Jun 26 2000 Bill Nottingham -- initscript munging - -* Fri Jun 16 2000 Bill Nottingham -- configure the swat stuff usefully -- re-integrate some specfile tweaks that got lost somewhere - -* Thu Jun 15 2000 Bill Nottingham -- rebuild to get rid of cups dependency - -* Wed Jun 14 2000 Nalin Dahyabhai -- tweak logrotate configurations to use the PID file in /var/lock/samba - -* Sun Jun 11 2000 Bill Nottingham -- rebuild in new environment - -* Thu Jun 1 2000 Nalin Dahyabhai -- change PAM setup to use system-auth - -* Mon May 8 2000 Bill Nottingham -- fixes for ia64 - -* Sat May 6 2000 Bill Nottingham -- switch to %%configure - -* Wed Apr 26 2000 Nils Philippsen -- version 2.0.7 - -* Sun Mar 26 2000 Florian La Roche -- simplify preun - -* Thu Mar 16 2000 Bill Nottingham -- fix yp_get_default_domain in autoconf -- only link against readline for smbclient -- fix log rotation (#9909) - -* Fri Feb 25 2000 Bill Nottingham -- fix trigger, again. - -* Mon Feb 7 2000 Bill Nottingham -- fix trigger. - -* Fri Feb 4 2000 Bill Nottingham -- turn on quota support - -* Mon Jan 31 2000 Cristian Gafton -- rebuild to fox dependencies -- man pages are compressed - -* Fri Jan 21 2000 Bill Nottingham -- munge post scripts slightly - -* Wed Jan 19 2000 Bill Nottingham -- turn on mmap again. Wheee. -- ship smbmount on alpha - -* Mon Dec 6 1999 Bill Nottingham -- turn off mmap. ;) - -* Wed Dec 1 1999 Bill Nottingham -- change /var/log/samba to 0700 -- turn on mmap support - -* Thu Nov 11 1999 Bill Nottingham -- update to 2.0.6 - -* Fri Oct 29 1999 Bill Nottingham -- add a %%defattr for -common - -* Tue Oct 5 1999 Bill Nottingham -- shift some files into -client -- remove /home/samba from package. - -* Tue Sep 28 1999 Bill Nottingham -- initscript oopsie. killproc -HUP, not other way around. - -* Sun Sep 26 1999 Bill Nottingham -- script cleanups. Again. - -* Wed Sep 22 1999 Bill Nottingham -- add a patch to fix dropped reconnection attempts - -* Mon Sep 6 1999 Jeff Johnson -- use cp rather than mv to preserve /etc/services perms (#4938 et al). -- use mktemp to generate /etc/tmp.XXXXXX file name. -- add prereqs on sed/mktemp/killall (need to move killall to /bin). -- fix trigger syntax (i.e. "samba < 1.9.18p7" not "samba < samba-1.9.18p7") - -* Mon Aug 30 1999 Bill Nottingham -- sed "s|nawk|gawk|" /usr/bin/convert_smbpasswd - -* Sat Aug 21 1999 Bill Nottingham -- fix typo in mount.smb - -* Fri Aug 20 1999 Bill Nottingham -- add a %%trigger to work around (sort of) broken scripts in - previous releases - -* Mon Aug 16 1999 Bill Nottingham -- initscript munging - -* Mon Aug 9 1999 Bill Nottingham -- add domain parsing to mount.smb - -* Fri Aug 6 1999 Bill Nottingham -- add a -common package, shuffle files around. - -* Fri Jul 23 1999 Bill Nottingham -- add a chmod in %%postun so /etc/services & inetd.conf don't become unreadable - -* Wed Jul 21 1999 Bill Nottingham -- update to 2.0.5 -- fix mount.smb - smbmount options changed again......... -- fix postun. oops. -- update some stuff from the samba team's spec file. - -* Fri Jun 18 1999 Bill Nottingham -- split off clients into separate package -- don't run samba by default - -* Mon Jun 14 1999 Bill Nottingham -- fix one problem with mount.smb script -- fix smbpasswd on sparc with a really ugly kludge - -* Thu Jun 10 1999 Dale Lovelace -- fixed logrotate script - -* Tue May 25 1999 Bill Nottingham -- turn of 64-bit locking on 32-bit platforms - -* Thu May 20 1999 Bill Nottingham -- so many releases, so little time -- explicitly uncomment 'printing = bsd' in sample config - -* Tue May 18 1999 Bill Nottingham -- update to 2.0.4a -- fix mount.smb arg ordering - -* Fri Apr 16 1999 Bill Nottingham -- go back to stop/start for restart (-HUP didn't work in testing) - -* Fri Mar 26 1999 Bill Nottingham -- add a mount.smb to make smb mounting a little easier. -- smb filesystems apparently don't work on alpha. Oops. - -* Thu Mar 25 1999 Bill Nottingham -- always create codepages - -* Tue Mar 23 1999 Bill Nottingham -- logrotate changes - -* Sun Mar 21 1999 Cristian Gafton -- auto rebuild in the new build environment (release 3) - -* Fri Mar 19 1999 Preston Brown -- updated init script to use graceful restart (not stop/start) - -* Tue Mar 9 1999 Bill Nottingham -- update to 2.0.3 - -* Thu Feb 18 1999 Bill Nottingham -- update to 2.0.2 - -* Mon Feb 15 1999 Bill Nottingham -- swat swat - -* Tue Feb 9 1999 Bill Nottingham -- fix bash2 breakage in post script - -* Fri Feb 5 1999 Bill Nottingham -- update to 2.0.0 - -* Mon Oct 12 1998 Cristian Gafton -- make sure all binaries are stripped - -* Thu Sep 17 1998 Jeff Johnson -- update to 1.9.18p10. -- fix %%triggerpostun. - -* Tue Jul 07 1998 Erik Troan -- updated postun triggerscript to check $0 -- clear /etc/codepages from %%preun instead of %%postun - -* Mon Jun 08 1998 Erik Troan -- made the %%postun script a tad less agressive; no reason to remove - the logs or lock file (after all, if the lock file is still there, - samba is still running) -- the %%postun and %%preun should only exectute if this is the final - removal -- migrated %%triggerpostun from Red Hat's samba package to work around - packaging problems in some Red Hat samba releases - -* Sun Apr 26 1998 John H Terpstra -- minor tidy up in preparation for release of 1.9.18p5 -- added findsmb utility from SGI package - -* Wed Mar 18 1998 John H Terpstra -- Updated version and codepage info. -- Release to test name resolve order - -* Sat Jan 24 1998 John H Terpstra -- Many optimisations (some suggested by Manoj Kasichainula -- Use of chkconfig in place of individual symlinks to /etc/rc.d/init/smb -- Compounded make line -- Updated smb.init restart mechanism -- Use compound mkdir -p line instead of individual calls to mkdir -- Fixed smb.conf file path for log files -- Fixed smb.conf file path for incoming smb print spool directory -- Added a number of options to smb.conf file -- Added smbadduser command (missed from all previous RPMs) - Doooh! -- Added smbuser file and smb.conf file updates for username map - +%autochangelog diff --git a/smb.conf.example b/smb.conf.example index e672ce9..271f13b 100644 --- a/smb.conf.example +++ b/smb.conf.example @@ -269,6 +269,13 @@ ; map system = no ; store dos attributes = yes +# Turn on SMB 3.1.1 Unix Extensions by default +# +# Note: The Linux Kernel SMB3 client will negotiate unix extensions by default, +# find more info in man mount.smb3(8). Linux 6.13 will finally support special +# filetypes and symlink handling. + + smb3 unix extensions = yes #============================ Share Definitions ============================== @@ -281,7 +288,7 @@ [printers] comment = All Printers - path = /var/spool/samba + path = /var/tmp browseable = no guest ok = no writable = no diff --git a/smb.conf.vendor b/smb.conf.vendor index 32441aa..f237c86 100644 --- a/smb.conf.vendor +++ b/smb.conf.vendor @@ -18,6 +18,9 @@ load printers = yes cups options = raw + # Install samba-usershares package for support + include = /etc/samba/usershares.conf + [homes] comment = Home Directories valid users = %S, %D%w%S @@ -35,7 +38,8 @@ [print$] comment = Printer Drivers path = /var/lib/samba/drivers - write list = @printadmin root - force group = @printadmin + # printadmin is a local group + write list = printadmin root + force group = printadmin create mask = 0664 directory mask = 0775 diff --git a/sources b/sources index 8d0552d..01648ec 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (samba-4.13.14.tar.xz) = 9df1de1ef80010e83ac36239d4af7958fe4f44a0cad4c68cdde71d63d502372767dfe4e01f4743e3ab1d23fe3b65ac7571c14ef9614a3b6feba53c2295a7f28e -SHA512 (samba-4.13.14.tar.asc) = 525f0d8087076e39db3205d878a2aba8242ef79927bca253963b2df7f181439dc825efd5ed457103a06251f2870fda68811ed1395a6cb7a995630e8f193153e7 +SHA512 (samba-4.23.4.tar.xz) = 58979aa8a83e8210918f4f1adbcadff329e57a9cd25d7aba98d18f54a2e790a7ef3cc6b9fb3303d492d33d67f4a135849a419c95644d14e53a39654736d486ac +SHA512 (samba-4.23.4.tar.asc) = 0981ce6a43202953cdc7ceae77fa0e3b4ab853991430dde4df6daa163984de6c7ca3f3a3037376659d3bdaedcc108cdd7a77ce0ac24d0a1add56c7103fca7dce diff --git a/tests/deps-check.fmf b/tests/deps-check.fmf new file mode 100644 index 0000000..c1452d0 --- /dev/null +++ b/tests/deps-check.fmf @@ -0,0 +1,22 @@ +summary: Check samba package dependency structure +description: | + Verify that samba library packages maintain correct dependency hierarchy: + - samba-core-libs has no samba-*-libs dependencies + - samba-ndr-libs depends on samba-core-libs (not samba-client-libs or samba-libs) + - samba-client-libs depends on core-libs + ndr-libs (not samba-libs) + - samba-client depends on samba-client-libs (not samba-libs) + - samba-libs does not depend on samba-dc-libs + - libsmbclient depends on samba-client-libs (not samba-libs) + - libwbclient has no samba-*-libs dependencies + - libldb has no samba-*-libs dependencies +test: ./deps-check.sh +framework: shell +require: + - samba-core-libs + - samba-ndr-libs + - samba-client-libs + - samba-libs + - samba-client + - libwbclient + - libsmbclient + - libldb diff --git a/tests/deps-check.sh b/tests/deps-check.sh new file mode 100755 index 0000000..ce49074 --- /dev/null +++ b/tests/deps-check.sh @@ -0,0 +1,167 @@ +#!/bin/bash +# +# Samba package dependency structure verification +# +# This test ensures that the samba library package dependencies don't regress. +# The expected hierarchy is: +# +# samba-core-libs (no samba-*-libs dependencies) +# ^ +# | +# samba-ndr-libs (depends on samba-core-libs only) +# ^ +# | +# samba-client-libs (depends on samba-core-libs + samba-ndr-libs) +# +# libwbclient (no samba-*-libs dependencies - only links to libc) +# +# samba-client (depends on samba-client-libs, NOT samba-libs) +# libsmbclient (depends on samba-client-libs, NOT samba-libs) +# +# NOTE: This test checks RESOLVED dependencies, not just explicit Requires. +# A library requirement like 'libfoo.so' is resolved to the package that +# provides it, ensuring we catch indirect dependencies. +# + +set -e + +ERRORS=0 + +# Get all packages that a package depends on (resolved) +# This resolves library deps like 'libfoo.so' to actual package names +get_resolved_deps() { + local pkg="$1" + + rpm --query --requires "$pkg" 2>/dev/null | while read -r req; do + # Skip rpmlib and config requirements + [[ "$req" =~ ^rpmlib ]] && continue + [[ "$req" =~ ^config ]] && continue + [[ "$req" =~ ^/ ]] && continue + + # Get the package that provides this requirement + provider=$(rpm --query --whatprovides "$req" 2>/dev/null | head -1) + if [ -n "$provider" ] && [ "$provider" != "no package provides $req" ]; then + # Extract just the package name (remove version-release.arch) + echo "${provider%%-[0-9]*}" + fi + done | sort -u +} + +# Check that a package does NOT depend on packages matching a pattern +# This checks RESOLVED dependencies (what packages actually get pulled in) +check_no_resolved_dep() { + local pkg="$1" + local pattern="$2" + local description="$3" + + if ! rpm --query "$pkg" &>/dev/null; then + echo "SKIP: $pkg not installed" + return 0 + fi + + local bad_deps + # Exclude the package itself from the check + bad_deps=$(get_resolved_deps "$pkg" | grep -v "^${pkg}$" | grep -E "$pattern" || true) + + if [ -n "$bad_deps" ]; then + echo "FAIL: $pkg depends on $description" + echo " Found: $bad_deps" + ERRORS=$((ERRORS + 1)) + return 1 + fi + echo "PASS: $pkg does not depend on $description" + return 0 +} + +# Check that a package DOES depend on a specific package +check_has_resolved_dep() { + local pkg="$1" + local expected="$2" + + if ! rpm --query "$pkg" &>/dev/null; then + echo "SKIP: $pkg not installed" + return 0 + fi + + if get_resolved_deps "$pkg" | grep -qF "$expected"; then + echo "PASS: $pkg depends on $expected" + return 0 + fi + echo "FAIL: $pkg does not depend on $expected" + ERRORS=$((ERRORS + 1)) + return 1 +} + +echo "=== Samba Package Dependency Checks ===" +echo "" +echo "Checking resolved dependencies (library deps resolved to packages)" +echo "" + +# 1. samba-core-libs must NOT depend on any samba-*-libs packages +echo "--- samba-core-libs ---" +check_no_resolved_dep samba-core-libs "^samba-.*-libs$" "any samba*-libs package" + +echo "" + +# 2. samba-ndr-libs must depend on samba-core-libs +# but NOT samba-client-libs or samba-libs +echo "--- samba-ndr-libs ---" +check_has_resolved_dep samba-ndr-libs "samba-core-libs" +check_no_resolved_dep samba-ndr-libs "^samba-client-libs$" "samba-client-libs" +check_no_resolved_dep samba-ndr-libs "^samba-libs$" "samba-libs" + +echo "" + +# 3. samba-client-libs must depend on samba-core-libs and samba-ndr-libs +# but NOT samba-libs +echo "--- samba-client-libs ---" +check_has_resolved_dep samba-client-libs "samba-core-libs" +check_has_resolved_dep samba-client-libs "samba-ndr-libs" +check_no_resolved_dep samba-client-libs "^samba-libs$" "samba-libs" + +echo "" + +# 4. libwbclient must NOT depend on any samba-*-libs packages +echo "--- libwbclient ---" +check_no_resolved_dep libwbclient "^samba-.*-libs$" "any samba*-libs package" + +echo "" + +# 5. samba-client must depend on samba-client-libs but NOT samba-libs +# (client tools should not pull in server libraries) +echo "--- samba-client ---" +check_has_resolved_dep samba-client "samba-client-libs" +check_no_resolved_dep samba-client "^samba-libs$" "samba-libs" + +echo "" + +# 6. libsmbclient must depend on samba-client-libs but NOT samba-libs +# (SMB client library should not pull in server libraries) +echo "--- libsmbclient ---" +check_has_resolved_dep libsmbclient "samba-client-libs" +check_no_resolved_dep libsmbclient "^samba-libs$" "samba-libs" + +echo "" + +# 7. libldb must NOT depend on any samba-*-libs packages +# (libldb is a standalone database library) +echo "--- libldb ---" +check_no_resolved_dep libldb "^samba-.*-libs$" "any samba*-libs package" + +echo "" + +# 8. samba-libs must NOT depend on samba-dc-libs +# (server libraries should not pull in DC-specific libraries) +echo "--- samba-libs ---" +check_no_resolved_dep samba-libs "^samba-dc-libs$" "samba-dc-libs" + +echo "" +echo "=== Summary ===" + +if [ $ERRORS -gt 0 ]; then + echo "FAILED: $ERRORS dependency check(s) failed" + exit 1 +fi + +echo "All dependency checks passed" +exit 0 diff --git a/usershares.conf.vendor b/usershares.conf.vendor new file mode 100644 index 0000000..38a7885 --- /dev/null +++ b/usershares.conf.vendor @@ -0,0 +1,3 @@ +[global] + usershare max shares = 100 + usershare allow guests = yes