Compare commits

..

295 commits

Author SHA1 Message Date
Andreas Schneider
58df5ed52b rpminspect: Don't run annocheck on test binaries
[skip changelog]
2026-01-15 17:21:55 +01:00
Andreas Schneider
1f4ee5276f Remove duplicate libdsdb-module-private-samba.so 2026-01-14 16:36:45 +01:00
Andreas Schneider
dca7b1cb88 Move Obsoletes to ndr-package which more or less was common-libs
[skip changelog]
2026-01-14 16:36:45 +01:00
Andreas Schneider
6af45b81d3 Add /usr/bin/nmbd to rpminspect.yml
/usr/sbin/nmbd is a symlink to /usr/bin/nmbd on Fedora.

[skip changelog]
2026-01-14 16:36:45 +01:00
Andreas Schneider
da7dc3fa61 Add missing tmt files
[skip changelog]
2026-01-14 14:30:40 +01:00
Andreas Schneider
dab569ad71 Create a samba-ndr-libs package and drop samba-common-libs
This should help sssd to reduce some of its dependencies.
2026-01-14 13:36:05 +01:00
Andreas Schneider
baa9e6f8c0 Move libraries from samba-client-libs to samba-libs 2026-01-14 12:23:39 +01:00
Andreas Schneider
fcd8668e55 Add gating test to detect dependency changes in samba libraries
[skip changelog]
2026-01-14 11:43:34 +01:00
Andreas Schneider
b8395d93a7 Create a core-libs sub-package to split up library dependencies 2026-01-14 11:42:08 +01:00
Andreas Schneider
4a23ce5b7a Remove unneeded dependency to samba-common-libs 2026-01-14 08:01:17 +01:00
Andreas Schneider
a170fadc8d Do not redeclare cmocka functions
This might cause issues when compiling with newer cmocka versions.
2026-01-12 10:05:53 +01:00
Günther Deschner
8c46386794 Update to Samba 4.23.4
- resolves: #2421764

Guenther
2025-12-12 17:04:18 +01:00
Andreas Schneider
fb14cf225b Add hint that we bundle ngtcp2 if not provided by the system 2025-11-14 19:12:12 +01:00
Andreas Schneider
4af6273371 Update gitignore
[skip changelog]
2025-11-14 19:12:12 +01:00
Günther Deschner
80c8f32211 Update to Samba 4.23.3
- resolves: #2413362

Guenther
2025-11-07 17:15:53 +01:00
Andreas Schneider
efaa5fdc6d Fix --with testsuite
[skip changelog]
2025-10-22 13:42:11 +02:00
Günther Deschner
c05bf06122 Update to Samba 4.23.2
- resolves: rhbz#2404204
- resolves: rhbz#2391698 - Security fix for CVE-2025-9640
- resolves: rhbz#2394377 - Security fix for CVE-2025-10230

Guenther
2025-10-17 20:41:14 +02:00
Günther Deschner
4e3699d8b5 Update to Samba 4.23.1
- resolves: #2399755

Guenther
2025-09-29 14:16:25 +02:00
Alexander Bokovoy
07953f426e Fix DLZ crash on unconfigured Samba AD system and rebuild against Python 3.14.0rc3
- Resolves: rhbz#2396621
 - Resolves: rhbz#2397242

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2025-09-23 11:42:46 +03:00
Andreas Schneider
b40a7310d3 Build with systemd-userdb support 2025-09-15 10:43:55 +02:00
Andreas Schneider
54c3bbd3f1 Fix building ctdb with PCP 7.0.0 2025-09-12 18:04:02 +02:00
Andreas Schneider
0bc0416ee8 Remove smb3 unix extensions = yes from smb.conf
This is enabled by default now.
2025-09-12 15:03:30 +02:00
Andreas Schneider
86832ccc39 Update to version 4.23.0
- resolves: rhbz#2394791
2025-09-12 14:55:35 +02:00
Günther Deschner
e0762b936f Update to Samba 4.23.0rc4
- resolves: #2393434

Guenther
2025-09-10 10:28:22 +02:00
Alexander Bokovoy
beb6a11089 Restore PCP support
- resolves: rhbz#2392879

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2025-09-04 09:47:08 +03:00
Alexander Bokovoy
5a96c90427 Disable PCP 7.0.0 support
PCP 7.0.0 API has changed, needs more work in ctdb

https://bugzilla.samba.org/show_bug.cgi?id=15904

- resolves: rhbz#2392879

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2025-09-03 16:28:38 +03:00
Alexander Bokovoy
a6119e2bb3 Fix FreeIPA trust to AD
- resolves: rhbz#2392626

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2025-09-03 15:03:44 +03:00
Günther Deschner
83273a97b1 Update to Samba 4.23.0rc3
- resolves: #2387090

Guenther
2025-08-29 23:51:02 +02:00
Günther Deschner
e6a975e422 Update to Samba 4.23.0rc2
- resolves: #2387090

Guenther
2025-08-22 22:06:30 +02:00
Python Maint
c108db5e55 Rebuilt for Python 3.14.0rc2 bytecode 2025-08-18 13:57:35 +02:00
Yaakov Selkowitz
c2bf86b8d2 Move trust_notify module to -dc subpackage
This module is not built in ELN, resulting in a file not found error when
packaging libldb.  Its build conditions are the same as the dns_notify
module already in -dc.
2025-08-17 23:07:18 -04:00
Günther Deschner
052edc4ab6 Update to Samba 4.23.0rc1
- resolves: #2387090

Guenther
2025-08-12 22:09:33 +02:00
František Zatloukal
ad5439e191 Rebuilt for icu 77.1 2025-08-06 09:57:46 +02:00
Fedora Release Engineering
5c93354123 Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild 2025-07-25 17:53:14 +00:00
Günther Deschner
b40f280be5 Fix get_kdc_ip_string handling for secondary KDCs
- resolves: bzso#15881

Guenther
2025-07-10 21:49:52 +02:00
Günther Deschner
d5056e867a Update to Samba 4.22.3
- resolves: #2376873

Guenther
2025-07-08 00:50:43 +02:00
Andreas Schneider
060552411c smb.conf: Remove the '@' for NIX groups, we removed NIS support 2025-06-23 10:14:07 +02:00
Pavel Filipenský
ac5f4a1f4b Move libreplace-private-samba.so to samba-common-libs
Fix this rpmdeps report:

VERIFY Subpackage libldb on x86_64 carries
'Requires: libreplace-private-samba.so()(64bit)' which comes from
subpackage samba-client-libs but does not carry an explicit package
version requirement. Please add 'Requires: samba-client-libs =
%{version}-%{release}' to the spec file to avoid the need to test
interoperability between various combinations of old and new
subpackages.
2025-06-10 14:16:16 +02:00
Pavel Filipenský
64f8b2a484 Install /run/ctdb
Fix following report:

 rpm --verify ctdb-0:4.22.2-3.el9.x86_64

 .M.......  g /run/ctdb

 M Mode differs (includes permissions and file type)
2025-06-10 14:16:16 +02:00
Python Maint
e9a8536578 Rebuilt for Python 3.14 2025-06-06 09:34:20 +02:00
Günther Deschner
eb8dac413e Update to Samba 4.22.2
- resolves: rhbz#2370468
- resolves: rhbz#2370455 - Security fix for CVE-2025-0620

Guenther
2025-06-05 20:34:02 +02:00
Python Maint
b8a889b232 Rebuilt for Python 3.14 2025-06-05 00:08:08 +02:00
Günther Deschner
40bd3a26e8 Update to Samba 4.22.1
- resolves: rhbz#2360776

Guenther
2025-04-18 02:26:37 +02:00
Günther Deschner
b508f2ed7a Turn on SMB 3.1.1 Unix Extensions in vendor smb.conf as well...
Guenther
2025-04-10 09:51:37 +02:00
Günther Deschner
0cb9860a40 Turn on SMB 3.1.1 Unix Extensions in default smb.conf
Guenther
2025-03-07 11:06:39 +01:00
Günther Deschner
30ff8554df Update to Samba 4.22.0
- resolves: rhbz#2350342

Guenther
2025-03-06 16:15:59 +01:00
Andreas Schneider
21e22997d4 Revert "Set samba-tools to noarch"
This reverts commit f00c21e2a8.

We can't set it to noarch as koji complains that "Requires: lmdb" is
present on some arches and not on others.
2025-03-04 14:01:29 +01:00
Andreas Schneider
417731acd0 Use spaces instead of tabs for krb5-printing scripts
Removes rpmlint warnings
2025-03-04 11:06:07 +01:00
Andreas Schneider
8ee5558015 Set ctdb-etcd-mutex to noarch
This only includes python scripts.
2025-03-04 11:03:58 +01:00
Andreas Schneider
e4ac2d5dcb Set samba-gpupdate to noarch
This only includes python scripts.
2025-03-04 11:02:47 +01:00
Andreas Schneider
f00c21e2a8 Set samba-tools to noarch
This only include a python scripts.
2025-03-04 11:01:51 +01:00
Andreas Schneider
e1991f29ec Set samba-usershare to noarch
It only includes configuration files.
2025-03-04 11:00:54 +01:00
Andreas Schneider
1b2e68adff Add missing /run/ctdb dir to files list 2025-03-04 11:00:46 +01:00
Andreas Schneider
7ebad9bdd1 Set version for bundled libreplace 2025-03-04 11:00:46 +01:00
Andrea Bolognani
947b0b72d5 Re-enable mold on riscv64
mold didn't build successfully on riscv64 back when riscv64
support was added to samba, but that has changed since and
today there is no longer any reason not to use it.

Signed-off-by: Andrea Bolognani <abologna@redhat.com>
2025-03-03 14:04:08 +01:00
David Abdurachmanov
6744eb181d Enable lmdb on riscv64
Solves configuration error:

[..]
Checking for a 64-bit host to support lmdb          : ok
Checking for lmdb >= 0.9.16                         : not found
Checking for header lmdb.h                          : no
Checking for lmdb >= 0.9.16 via header check        : not found
Samba AD DC and --enable-selftest requires lmdb 0.9.16 or later
[..]

Signed-off-by: David Abdurachmanov <davidlt@rivosinc.com>
2025-03-03 14:04:08 +01:00
Günther Deschner
c295775181 Update to Samba 4.22.0rc4
- resolves: rhbz#2348758

Guenther
2025-02-27 20:00:34 +01:00
Günther Deschner
c4883ac1e7 Update to Samba 4.22.0rc3
- resolves: rhbz#2346803

Guenther
2025-02-20 18:39:08 +01:00
Andreas Schneider
4e6ca9ecfb Fix libldb built with '--with includelibs' 2025-02-18 14:45:05 +01:00
Andreas Schneider
036c40ef5e Fix the '--with includelibs' build 2025-02-14 19:05:42 +01:00
Andreas Schneider
314544c636 Add LICENSE file of libldb 2025-02-14 14:30:24 +01:00
Andreas Schneider
cb85d85e0f Make %bcond switches easier to understand
This also removes support for building on rhel8.
2025-02-14 12:02:02 +01:00
Günther Deschner
67e7277c75 Update to Samba 4.22.0rc2
- resolves: rhbz#2345547

Guenther
2025-02-13 23:54:53 +01:00
Günther Deschner
f24bbdaf78 Update to version 4.22.0rc1
- resolves: rhbz#2344189

Guenther
2025-02-09 00:59:35 +01:00
Björn Esser
e52328b755
Add explicit BR: libxcrypt-devel
Signed-off-by: Björn Esser <besser82@fedoraproject.org>
2025-02-01 19:57:20 +01:00
Andreas Schneider
7bc49d20ad Fix building with gcc 15 2025-01-22 09:03:43 +01:00
Andreas Schneider
c6899c34b0 Fix stack use after return in new crypt module 2025-01-22 09:00:27 +01:00
Fedora Release Engineering
09d4509590 Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild 2025-01-19 09:54:56 +00:00
Pavel Filipenský
99bcb0cab8 Remove 'Requires: python3-crypt-r' also from samba-tools 2025-01-07 14:28:18 +01:00
Pavel Filipenský
a7c8b51b0f Use upstream Patch instead of python3-crypt-r 2025-01-07 13:52:23 +01:00
Pavel Filipenský
d70953a5ed Update to version 4.21.3
- resolves: rhbz#2335911
2025-01-07 10:42:42 +01:00
Pete Walter
6b05011701 Rebuild for ICU 76 2024-12-08 22:44:21 +00:00
Andreas Schneider
b0f6e67bbc Add missing SAMBA_DCERPCD_DONT_LOG_STDOUT=1 for the testsuite
[skip changelog]
2024-11-29 09:05:13 +01:00
Andreas Schneider
a5688d299c Rework 'with testsuite'
In case we run the testsuite, the %install part will be skipped. Without
the testsuite, the %check section will be skipped.

[skip changelog]
2024-11-29 09:05:10 +01:00
Andreas Schneider
1af6d0aa01 Add missing BuildRequires for running the testsuite
[skip changelog]
2024-11-29 09:05:08 +01:00
Andreas Schneider
e2b080c313 Add python3-crypt-r as requirement for samba-tool 2024-11-26 14:52:12 +01:00
Günther Deschner
438b8a6e95 Update to version 4.21.2
- resolves: rhbz#2328717
2024-11-25 20:16:18 +01:00
Anoop C S
f654bad3bb Remove unused macro samba_requires_eq
This was previously used to force the installation of a matching
libldb version from build time. With libldb now versioned along
with Samba as a public library its usage got removed in d0472882
but the definition remained as a left over.

Signed-off-by: Anoop C S <anoopcs@samba.org>
2024-11-13 11:40:56 +05:30
Pavel Filipenský
667e752f95 Add always to samba-devel: Requires: samba-dc-libs 2024-10-25 19:42:52 +02:00
Richard W.M. Jones
4ae2996e49 Rebuild for Jansson 2.14 (https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org/thread/3PYINSQGKQ4BB25NQUI2A2UCGGLAG5ND/) 2024-10-22 13:42:50 +01:00
Pavel Filipenský
a98899c6d2 Fix samba 4.20 -> 4.21 upgrade for the removed python3-samba-devel 2024-10-22 11:02:58 +02:00
Pavel Filipenský
1caea566a4 Revert "Re-enable linking with mold on i686"
This reverts commit ac58d580e8.

This is to address debuginfo issue reported by rpminspect for i686:
https://bugzilla.redhat.com/show_bug.cgi?id=2318727
2024-10-17 11:39:31 +02:00
Pavel Filipenský
6d5708b5e4 Fix even more rpminspect warnings 2024-10-16 11:32:58 +02:00
Pavel Filipenský
682be9e398 Fix some more rpminspect warnings 2024-10-15 13:20:10 +02:00
Andreas Schneider
a55c2e0445 Fix several rpminspect warnings 2024-10-15 11:58:12 +02:00
Andreas Schneider
16e2ea30c4 rpminspect: Disable inspection of disttag
rpminspect just reads the file an doesn't expand it so it doesn't
understand:

Release: %{samba_release}

[skip changelog]
2024-10-15 11:58:07 +02:00
Pavel Filipenský
2535a64d34 Update to version 4.21.1
- resolves: rhbz#2318518
2024-10-14 15:38:28 +02:00
Andreas Schneider
92d190c9b6 Don't use RTLD_DEEPBIND by default in libldb
- resolves: rhbz#2278016
2024-10-01 14:11:48 +02:00
Pavel Filipenský
8f40e555ff Build with ceph again for ppc64le
This is fixed https://gcc.gnu.org/bugzilla/show_bug.cgi?id=104172
in gcc >= 11.3. It is ok to enable for rhel-9, rhel-10 and f41:

gcc-11.5.0-2.el9
gcc-14.2.1-2.el10
gcc-14.2.1-3.fc41
2024-09-27 13:59:42 +02:00
Yaakov Selkowitz
a4001d23ea Always include libsamba-policy and libsamba-net-private-samba
As of 4.21, these were converted to regular C libraries to which their
respective Python modules depend:

d11b281aef
829b52f99d
2024-09-25 18:11:56 -04:00
Yaakov Selkowitz
6ad6694791 Fix ELN build
libsamba-policy is only built with the AD DC, but the LDB LMDB components
should be built regardless:

https://gitlab.com/samba-team/samba/-/merge_requests/3807
2024-09-24 10:34:22 -04:00
Andreas Schneider
b16ff1f961 Add cert directories to samba-common
Those are created by gpupdate and we need to have them packaged that
selinux can label them correctly.
2024-09-23 12:58:24 +02:00
Alexander Bokovoy
19fdf21ce6 Fix Samba integration with FreeIPA
- resolves: rhbz#2309199

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2024-09-13 16:29:53 +03:00
Günther Deschner
63dc1a2f19 Update required tdb version
- related: rhbz#2309153
2024-09-03 00:19:59 +02:00
Günther Deschner
b363a4cfec Update to version 4.21.0
- resolves: rhbz#2309153
2024-09-02 15:25:28 +02:00
Günther Deschner
11eed52070 Update to version 4.21.0rc4
- resolves: rhbz#2300469
2024-08-28 13:55:38 +02:00
Andreas Schneider
4c2a193110 Fix ldb requires and provides
- related: rhbz#230046
2024-08-21 14:55:13 +02:00
Andreas Schneider
bcb3974e31 Fix manpages for libldb
related: rhbz#230046
2024-08-21 09:29:46 +02:00
Andreas Schneider
49d714c029 Update to version 4.21.0rc3
- related: rhbz#230046
2024-08-21 08:02:37 +02:00
Andreas Schneider
22760e8157 Remove also python-ldb-devel-common
- related: rhbz#230046

This was only used internally.
2024-08-21 07:51:00 +02:00
Günther Deschner
d04728829d Update to Samba 4.21.0rc2
- Package libldb a public library
- resolves: #2300469

Pair-Programmed-With: Andreas Schneider <asn@redhat.com>
2024-08-20 18:33:39 +02:00
Peter Robinson
3dd6bed73b Update to version 4.20.4 2024-08-17 16:16:53 +01:00
Christoph Erhardt
ac58d580e8 Re-enable linking with mold on i686 2024-08-05 08:21:41 +02:00
Fedora Release Engineering
44bb1d4438 Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild 2024-07-20 04:44:46 +00:00
Andreas Schneider
41e97d4a9d Move README.md and WHATSNEW.txt to samba-common 2024-07-01 11:41:48 +02:00
Günther Deschner
4b62d26842 resolves: #2293108 - Move LICENSE file to samba-common
Guenther
2024-06-25 14:30:12 +02:00
Günther Deschner
2588fdd81f resolves: #2293100 - Update to version 4.20.2
Guenther
2024-06-19 19:28:07 +02:00
Python Maint
e5c614494c Rebuilt for Python 3.13 2024-06-10 11:52:50 +02:00
Andreas Schneider
5ae3a0ccb0 Improve setting the version number for pre-releases
[skip changelog]
2024-05-22 09:54:05 +02:00
Andreas Schneider
857301aa5c Convert to %autorelease and %autochangelog
[skip changelog]
2024-05-21 14:17:59 +02:00
Günther Deschner
058c9e46a8 Update to version 4.20.1
resolves: #2279780

Guenther
2024-05-10 22:46:40 +02:00
Pavel Filipenský
a194b836ce rpminspect.yaml: update badfuncs with new library names 2024-04-30 15:56:01 +02:00
Günther Deschner
129e39f982 Update to version 4.20.0
resolves: #2271916

Guenther
2024-03-27 19:02:19 +01:00
Richard W.M. Jones
a5c93245d3 Bump and rebuild package (for riscv64) 2024-03-12 20:39:26 +00:00
David Abdurachmanov
eccf82df8a Add support for riscv64
Signed-off-by: David Abdurachmanov <davidlt@rivosinc.com>
2024-03-12 20:37:00 +00:00
Günther Deschner
05916b6f9c Update to version 4.20.0rc4
resolves: #2269037

Guenther
2024-03-11 19:02:28 +01:00
Andreas Schneider
8fa9d9ff95 Silence warnings when upgrading libwbclient 2024-03-05 13:55:01 +01:00
Günther Deschner
81028e3aa9 Update to version 4.20.0rc3
resolves: #2266039

Guenther
2024-02-26 13:55:19 +01:00
Günther Deschner
9a35124520 Update to version 4.20.0rc2
resolves: #2263874

Guenther
2024-02-12 16:05:52 +01:00
Andreas Schneider
3a7dad4a24 Require cepces-certmonger
This is the package providing cepces-submit required by samba-gpupdate.
It will install all the other required packages.
2024-02-09 16:32:58 +01:00
Andreas Schneider
86c73e995b The AES crypto code has been removed
We use GnuTLS for everything now.
2024-02-09 09:29:46 +01:00
Andreas Schneider
691752e56b Require cepces >= 0.3.8 2024-02-09 09:27:06 +01:00
Pete Walter
885a433df0 Rebuild for ICU 74 2024-02-01 11:15:57 +00:00
Günther Deschner
cd3cf3831b Fix typo
Guenther
2024-02-01 07:59:36 +01:00
Günther Deschner
fc5ba48178 Update to version 4.20.0rc1
resolves: #2260895

Guenther
2024-01-30 10:41:47 +01:00
Fedora Release Engineering
a0149239aa Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild 2024-01-27 02:03:30 +00:00
Andreas Schneider
cbf258a115 Fix samba-gpupdate on Fedora/RHEL 2024-01-16 12:22:50 +01:00
Andreas Schneider
2c97dc253a Remove unused globals libwbc_alternatives_* 2024-01-10 13:16:55 +01:00
Andreas Schneider
368799d573 Bump release number 2024-01-09 13:07:37 +01:00
Andreas Schneider
f245ed7ba2 Create winbind groups using systemd
Also drop creating groups with groupadd entirely.

resolves: rhbz#2256326
2024-01-09 10:52:00 +01:00
Günther Deschner
95272cbe76 Update to version 4.19.4
resolves: #2257287

Guenther
2024-01-08 17:43:06 +01:00
Andreas Schneider
6a716d5e7e Add missing dependencies for samba-gpupdate 2024-01-08 17:30:42 +01:00
Andreas Schneider
448b9a1661 Add missing BuildRequires for cepces
We should install for building what we require during runtime.
2023-12-13 10:01:58 +01:00
Günther Deschner
93059a0a6a Disable ctdb-pcp build for i686 for Fedora
performance-co-pilot is no longer supported on i686 in Fedora Rawhide/40

Guenther
2023-11-28 13:37:54 +01:00
Günther Deschner
9e2c1829db Update to Samba 4.19.3
resolves: #2251766

Guenther
2023-11-27 15:36:02 +01:00
Pavel Filipenský
601c5e7cbb Fix the 'without gpupdate' uninstalled file removal 2023-11-19 12:47:18 +01:00
Andreas Schneider
c92b2eb22b Do not use mold on i686, support for it has been dropped 2023-11-15 14:38:09 +01:00
Andreas Schneider
4f9b479032 Package samba-gpupdate also for RHEL9 2023-11-15 10:37:35 +01:00
Günther Deschner
9996023e42 Update to version 4.19.2
resolves: #2244496

Guenther
2023-10-16 18:00:00 +02:00
Günther Deschner
00b32c4172 When built with testsuite rpcd_echo is built as well
Guenther
2023-10-16 17:34:43 +02:00
Günther Deschner
a1a3c76fb5 Update to version 4.19.1
resolves: #2243073
resolves: #2241881, #2243228: Security fix for CVE-2023-3961
resolves: #2241882, #2243231: Security fix for CVE-2023-4091
resolves: #2241883, #2243230: Security fix for CVE-2023-4154
resolves: #2241884, #2243229: Security fix for CVE-2023-42669
resolves: #2241885, #2243232: Security fix for CVE-2023-42670

Guenther
2023-10-11 13:00:49 +02:00
Günther Deschner
43d90c9175 Update to version 4.19.0
resolves: #2237259

Guenther
2023-09-04 15:55:11 +02:00
Günther Deschner
38db681558 Update to version 4.19.0rc4
resolves: #2232744

Guenther
2023-08-28 18:49:34 +02:00
Günther Deschner
7837b083f2 Update to version 4.19.0rc3
resolves: #2232744

Guenther
2023-08-18 15:27:59 +02:00
Yaakov Selkowitz
070d655da4 Move ad-claims and authn-policy-util to dc-libs
These libraries depend on libdsdb-module and are only built if DC is
enabled (and therefore not for RHEL).
2023-08-16 01:48:58 -04:00
Adam Williamson
dc22ad5bd2 python3-samba-dc requires python3-markdown now 2023-08-15 13:08:22 -07:00
Günther Deschner
9602a07a36 Update to version 4.19.0rc2
resolves: #2227246

Guenther
2023-08-08 12:05:31 +02:00
Günther Deschner
ef6e3a1cfe Update to version 4.19.0rc1
resolves: #2227246

Guenther
2023-08-07 14:00:21 +02:00
Günther Deschner
9ae16cc49b Update to version 4.18.5
resolves: #2224040

Security fix for CVE-2022-2127
resolves: #2222791, #2224254

Security fix for CVE-2023-3347
resolves: #2222792, #2224255

Security fix for CVE-2023-34966
resolves: #2222793, #2224253

Security fix for CVE-2023-34967
resolves: #2222794, #2224252

Security fix for CVE-2023-34968
resolves: #2222795, #2224250

Guenther
2023-07-20 12:19:04 +02:00
Günther Deschner
64ef2ec2d2 Fix netlogon LogonGetCapabilities level 2 error handling
resolves: #2223091

Guenther
2023-07-17 17:22:50 +02:00
František Zatloukal
a38fba0562 Rebuilt for ICU 73.2 2023-07-11 22:21:49 +02:00
Python Maint
3948e24a26 Rebuilt for Python 3.12 2023-07-05 18:27:08 +02:00
Günther Deschner
ac8caa023e Update to version 4.18.4
resolves: #2219799

Guenther
2023-07-05 14:44:37 +02:00
Python Maint
f3b66c42ca Rebuilt for Python 3.12 2023-06-26 12:27:58 +02:00
Adam Williamson
c3a5a6aede Only run libwbclient %pre on upgrade, not fresh install
This seems to be breaking live image build tests because the
script is running before `rm` is installed. I do not know why
it didn't fail the tests run *on the update itself*, but it's
now causing tests of subsequent updates to fail, which is a
problem. Probably an ordering issue.

AFAIK, this script is meant to clean up stuff from earlier
versions of the package, so it's not relevant on fresh installs,
and we can just skip it and avoid any problems in the fresh
install case.
2023-06-26 01:02:08 +02:00
Andreas Schneider
7f3a842050 Fix libwbclient package upgrades
resolves: rhbz#2211577
2023-06-23 10:47:21 +02:00
FeRD (Frank Dana)
efe3dd0ab1 Remove ® symbol from winexe's description 2023-06-17 11:18:44 -04:00
Python Maint
15cfaa7346 Rebuilt for Python 3.12 2023-06-15 13:18:39 +02:00
Andreas Schneider
f5d2701706 Bump baserelease
Forgotten in previous commit.
2023-06-15 12:32:01 +02:00
Andreas Schneider
8210a6cc4c logrotate: Also cover mit_kdc.log
resolves: rhbz#2203539
2023-06-15 10:22:45 +02:00
Günther Deschner
41c4c70006 Update to version 4.18.3
resolves: #2211453

Guenther
2023-06-01 10:45:55 +02:00
Andreas Schneider
a79fd33b58 Fix ccache support 2023-05-05 13:53:47 +02:00
Andreas Schneider
dc949bd3c8 Let samba-winbind just suggest samba-tool 2023-04-20 14:38:04 +02:00
Andreas Schneider
5caa412c6b Add support for mock ccache plugin 2023-04-20 08:12:28 +02:00
Günther Deschner
a6fcf14600 Update to version 4.18.2
resolves: #2187991

Guenther
2023-04-19 14:34:42 +02:00
Günther Deschner
6126e39c51 Update to version 4.18.1
resolves: #2182787 - Update to version 4.18.1
resolves: #2182772, #2182773 - Security fixes for CVE-2023-0225
resolves: #2182774, #2182775 - Security fixes for CVE-2023-0922
resolves: #2182776, #2182777 - Security fixes for CVE-2023-0614

Guenther
2023-03-29 23:42:40 +02:00
Andreas Schneider
8d52163b67 Add missing Requires for bind-utils
samba_dnsupdate uses nsupdate from bind-utils
2023-03-28 09:02:23 +02:00
Andreas Schneider
e5cb35effe Fix ctdb file lists when built with test suite enabled 2023-03-21 15:20:25 +01:00
Andreas Schneider
d336264f64 Fix file list 2023-03-21 11:01:43 +01:00
Kalev Lember
7ffc94f1ba Move libstable-sort-samba4.so to samba-client-libs subpackage
libndr-samba-samba4.so that's already in -client-libs subpackage links
with libstable-sort-samba4.so, which means that we need to put both in
-client-libs to avoid -client-libs suddenly starting to depend on -libs.
2023-03-17 21:08:32 +01:00
Andreas Schneider
32b29ac6e9 Add missing Requires for python3-gpg to samba-tools 2023-03-10 13:01:28 +01:00
Günther Deschner
daa7809342 Update to version 4.18.0
resolves: #2176469

Guenther
2023-03-08 14:22:45 +01:00
Günther Deschner
c7734163fa Update to version 4.18.0rc4
resolves: #2174415

Guenther
2023-03-01 15:38:16 +01:00
Andreas Schneider
b42ebb0a84 Bump baserelease 2023-02-28 07:59:18 +01:00
Andreas Schneider
435e4d9b7b Add missing Requires for glibc-gconv-extra
resolves: #2173619
2023-02-28 07:55:19 +01:00
Pavel Filipenský
1348920d6f SPDX migration 2023-02-23 15:30:48 +01:00
Andreas Schneider
73705701f1 Update License to SPDX expressions
https://fedoraproject.org/wiki/Changes/SPDX_Licenses_Phase_1
2023-02-23 15:15:37 +01:00
Andreas Schneider
101d3c387f Remove obsolete patch 2023-02-21 14:26:16 +01:00
Günther Deschner
90edcb757a Update to version 4.18.0rc3
resolves: #2166416

Guenther
2023-02-16 15:06:55 +01:00
Andreas Schneider
479c5d099f Add missing Requires for samba-tool on samba-dc 2023-02-16 09:14:12 +01:00
Andreas Schneider
b4642ddce5 Fix samba-tool dependencies 2023-02-16 09:14:09 +01:00
Pavel Filipenský
4b6c2a6e52 Add changelog entry 2023-02-13 16:57:39 +01:00
Pavel Filipenský
0a8a75e9d8 Create samba-tools package for samba-tool.
Avoids installation of many python3 pkgs on a simple file server.
2023-02-13 15:25:44 +01:00
Pavel Filipenský
5704b04d69 Fix samba-tool dependencies on non-dc builds
It has two steps:
- Build python3-samba-dc also for non-dc builds
- Require python3-samba-dc from common-tools also for non-dc builds
2023-02-11 13:24:21 +01:00
Günther Deschner
36c4a399ca Update to version 4.18.0rc2
resolves: #2166416

Guenther
2023-02-02 14:47:10 +01:00
Pavel Filipenský
574391dda6 rpminspect: Avoid "Missing: .debug_info"
libdcerpc-samr is a grouping library without .debug_info.
See source4/librpc/wscript_build.
There is an empty source list for bld.SAMBA_LIBRARY('dcerpc-samr'
2023-01-31 22:07:27 +01:00
Andreas Schneider
3937d0fbab Fix typo 2023-01-24 08:59:29 +01:00
Andreas Schneider
6320734465 Add missing python requirements for python3-samba 2023-01-24 08:33:01 +01:00
Andreas Schneider
d5a1366d2a Remove duplicate code 2023-01-24 08:32:19 +01:00
Andreas Schneider
3134f7f1d6 Use python3-dateutil instead of python3-iso8601
We don't have iso8601 in third_party/ anymore.
2023-01-24 08:31:23 +01:00
Andreas Schneider
08e07cb855 Use mold linker on Fedora >= 37
This makes compilation of Samba a lot faster.
2023-01-23 07:25:22 +01:00
Fedora Release Engineering
fe7442c100 Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2023-01-21 02:35:44 +00:00
Günther Deschner
d5d42cde4f Update to version 4.18.0rc1
resolves: #2162097

Guenther
2023-01-19 22:50:04 +01:00
Jitka Plesnikova
127f68766f Remove perl(MODULE_COMPAT), it will be replaced by generators 2023-01-13 21:13:35 +01:00
Pete Walter
c22466881a Rebuild for ICU 72 2022-12-31 03:19:18 +00:00
Pavel Filipenský
c3203becc0 Create package dc-libs also for 'non-dc' build 2022-12-22 17:26:36 +01:00
Pavel Filipenský
5471a3e692 Fix '--without dc' build: delete libauth4-samba4.so 2022-12-20 11:10:25 +01:00
Pavel Filipenský
0f08e77cfc Create a new 'samba-dcerpc' sub-package for DCERPC services 2022-12-19 15:09:46 +01:00
Pavel Filipenský
874e260cc9 Move libpac and libauth4 to dc-libs
This allows us to not install the samba and samba-dc packages. They
are not needed for domain member which just want to have samba-winbind
related packages installed.
2022-12-19 15:06:27 +01:00
Günther Deschner
92dd9596a2 Update to version 4.17.4
resolves: #2153906
resolves: #2154362, #2154363 - Security fixes for CVE-2022-38023
resolves: #2154303, #2154304 - Security fixes for CVE-2022-37966
resolves: #2154320, #2154322 - Security fixes for CVE-2022-37967

Guenther
2022-12-16 18:50:17 +01:00
Alexander Bokovoy
8b52c1b033 Rebuild against krb5 1.20.1
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2022-12-01 18:39:07 +02:00
Florian Weimer
22ec3a0a0d Remove C89-specific language constructs from configure checks
Fix feature detection for major/minor macros.

Related to:

  <https://fedoraproject.org/wiki/Changes/PortingToModernC>
  <https://fedoraproject.org/wiki/Toolchain/PortingToModernC>
2022-11-23 15:20:50 +01:00
Florian Weimer
c7d395b20c Avoid recursive python3_sitearch expansion even if undefined
Fixes an error during SRPM construction if not enough dependencies
are installed (e.g., during the first build stage in mock):

error: /builddir/build/SPECS/samba.spec: line 2478: Too many levels
  of recursion in macro expansion. It is likely caused by recursive
  macro declaration.
2022-11-21 15:45:49 +01:00
Florian Weimer
14cc94aae1 Memoize python3_sitearch for faster RPM spec file processing
This greatly speeds up the creation of source RPMs, among other
things.
2022-11-21 15:29:40 +01:00
Günther Deschner
441bd49ffc Security fixes for CVE-2022-42898
resolves: #2140960, #2143117

Guenther
2022-11-16 11:09:19 +01:00
Günther Deschner
3fcbe364b2 Update to version 4.17.3
resolves: #2142959

Guenther
2022-11-15 18:39:46 +01:00
Pavel Filipenský
cc1c088518 Always add epoch to samba_depver to fix osci.brew-build.rpmdeplint.functional 2022-11-02 15:56:16 +01:00
Andreas Schneider
eaa90f4719 Add missing require for libcmdline from samba-common-libs 2022-10-26 11:31:30 +02:00
Andreas Schneider
9f35dd7b52 Update to version 4.17.2 2022-10-25 14:22:08 +02:00
Andreas Schneider
5175b77178 Add missing dependency for wbinfo used by ctdb scripts 2022-10-24 16:58:29 +02:00
Pavel Filipenský
593cdb5963 Update to version 4.17.1
resolves: rhbz#2127301 - Permission denied calling SMBC_getatr when file not exists
resolves: rhbz#2133818 - rpcclient 4.17.0 unable to resolve server hostname
2022-10-19 16:09:48 +02:00
Andreas Schneider
93ae555a84 Move group creation logic to sysusers.d fragment 2022-10-05 11:40:18 +02:00
Troy Dawson
d54cbd1fbf add BuildRequires: systemd-rpm-macros
Although the spec requires systemd-rpm-macros for macros such as %{_unitdir} it was only getting pulled in as a dependency of other packages.
Dependencies have changed, and systemd-rpm-macros is no longer getting pulled in. Add the BuildRequires so we always get it.

Signed-off-by: Troy Dawson tdawson@redhat.com
2022-09-27 18:18:24 +00:00
Anoop C S
ea9a21adf0 Do not remove ldb-ldap-modules files from buildroot
New sub-package samba-ldb-ldap-modules requires corresponding files
to be present in buildroot irrespective of whether DC components are
enabled or not in the build process. Therefore refrain from removing
those from the buildroot.
2022-09-14 16:12:48 +05:30
Andreas Schneider
473cc2b5a4 Update to version 4.17.0
resolves: rhbz#2118818 - Update to version 4.17.0
resolves: rhbz#2121138 - Fix CVE-2022-32743
resolves: rhbz#2122650 - Fix CVE-2022-1615
2022-09-13 20:46:47 +02:00
Andreas Schneider
ca4228ea9f Add samba-usershare package
resolves: rhbz#2096405
2022-09-13 14:46:17 +02:00
Andreas Schneider
d041102422 Split out libnetapi(-devel) sub-packages
resolves: rhbz#2093656
2022-09-13 14:45:56 +02:00
Günther Deschner
8fd6f2abb9 Update to version 4.17.0rc5
resolves: #2118818

Guenther
2022-09-08 15:34:48 +02:00
Günther Deschner
9497295508 Update to version 4.17.0rc4
resolves: #2118818

Guenther
2022-08-31 10:51:49 +02:00
Adam Williamson
c6f208e111 Rebuild with no changes to fix F37 update grouping 2022-08-25 09:58:00 -07:00
Andreas Schneider
57b6ce7d3c python3-samba package should not require the samba package 2022-08-25 08:17:04 +02:00
Pavel Filipenský
040a14f039 Update to version 4.17.0rc3
resolves: #2118818
2022-08-23 21:10:48 +02:00
Andreas Schneider
b6eef47cea Create a samba-gpupdate sub-package for GPO client support 2022-08-19 12:51:14 +02:00
Andreas Schneider
63377a1809 Split out a samba-ldb-ldap-modules subpackage 2022-08-19 11:28:50 +02:00
Kalev Lember
ffcfd9ef88 Avoid requiring systemd as per updated packaging guidelines
There is no need to require systemd for the systemd scriptlets as
systemd correctly handles reloading depending on the transaction
ordering (even if systemd is installed _after_ the package that installs
the unit file).
2022-08-18 17:11:07 +02:00
Günther Deschner
9f943749c7 Update to version 4.17.0rc2
resolves: #2118818

Guenther
2022-08-17 10:50:48 +02:00
Andreas Schneider
9c22397379 Make sure we detect if SO version numbers of public libraries change. 2022-08-11 16:10:41 +02:00
Andreas Schneider
ce3b414c6d Regroup variables for version definitions 2022-08-10 13:14:01 +02:00
Günther Deschner
8380904ad8 Update to version 4.17.0rc1
resolves: #2116503

Guenther
2022-08-09 14:45:59 +02:00
František Zatloukal
a74bd638b7 Rebuilt for ICU 71.1 2022-08-01 15:10:39 +02:00
Günther Deschner
b41f002876 Update to version 4.16.4
resolves: #2111490
resolves: #2108196, #2111729 - Security fixes for CVE-2022-32742
resolves: #2108205, #2111731 - Security fixes for CVE-2022-32744
resolves: #2108211, #2111732 - Security fixes for CVE-2022-32745
resolves: #2108215, #2111734 - Security fixes for CVE-2022-32746

Guenther
2022-07-29 11:44:10 +02:00
Fedora Release Engineering
8939f84a48 Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2022-07-23 07:57:26 +00:00
Andreas Schneider
9a15eb02f2 Update to version 4.16.3 2022-07-18 17:37:37 +02:00
Andreas Schneider
33e4d19298 Fix BR with includelibs 2022-06-24 07:30:58 +02:00
Python Maint
58b6aadb0f Rebuilt for Python 3.11 2022-06-15 18:06:15 +02:00
Günther Deschner
85e1d4b7c6 Update to Samba 4.16.2
resolves: #2096167

Guenther
2022-06-13 12:42:08 +02:00
Andreas Schneider
dfb88d92d4 Remove weak dependency for logrotate for CentOS/RHEL
resolves: rhbz#2093833
2022-06-08 11:25:43 +02:00
Andreas Schneider
ae63a4dca1 Drop zlib from bundled libraries as we don't have a copy anymore 2022-06-07 15:39:57 +02:00
Jitka Plesnikova
035f4717dd Perl 5.36 rebuild 2022-05-31 08:15:08 +02:00
Pavel Filipenský
8ccc18dc13 Fix rpminspect abidiff
pfilipen
2022-05-13 09:08:24 +02:00
Pavel Filipenský
1d4eb827d1 Fix samba.abignore 2022-05-06 17:05:02 +02:00
Pavel Filipenský
737293fe2b Rename from .abignore to samba.abignore 2022-05-06 14:31:59 +02:00
Pavel Filipenský
0b31575a45 Update requires for packages
pfilipen
2022-05-06 12:19:17 +02:00
Pavel Filipenský
1fa286fd00 rpminspect: ignore inet_ntoa() from /usr/lib*/samba/service/nbtd.so 2022-05-05 19:47:38 +02:00
Andreas Schneider
331fe971e6 Add .abignore file for abidiff
abidiff complains:

abidiff: failed to read input file /usr/lib/libdcerpc-samr.so.0.0.1
abidiff: could not find the debug info

This is a grouping library which doesn't have any source code, so just
ignore it with a suppression file (.abignore).

Example for .abignore:
https://sourceware.org/git/?p=libabigail.git;a=blob;f=default.abignore
2022-05-05 19:45:16 +02:00
Tomas Popela
bec19658c4 Don't require full systemd for tmp file handling in samba-common
Otherwise the full systemd is being pulled into Fedora Flatpak runtime,
but this change benefits other uses as well.
2022-05-05 14:41:46 +02:00
Pavel Filipenský
93ea8c0806 Delete no longer needed comments
pfilipen
2022-05-03 13:10:27 +02:00
Pavel Filipenský
766f1be02d Update to Samba 4.16.1
resolves: #2080915

pfilipen
2022-05-02 13:16:49 +02:00
Andreas Schneider
5533ff7a7c Make sure we do not build Heimdal or crypto code
As we need to rely on GnuTLS for FIPS, remove heimdal and other unused
crypto code to ensure we do not build it!
2022-04-04 11:39:14 +02:00
Sandro Mani
92f6ae3986 Rebuild with mingw-gcc-12 2022-03-25 14:58:37 +01:00
Günther Deschner
d6e74e716f Update to Samba 4.16.0
resolves: #2066290

Guenther
2022-03-22 10:27:37 +01:00
Günther Deschner
da81e5cf5b Update to Samba 4.16.0rc5
resolves: #2042518

Guenther
2022-03-09 15:23:04 +01:00
Pavel Filipenský
48556cdf37 Update to Samba 4.16.0rc4
resolves: #2042518

pfilipen
2022-03-01 12:37:53 +01:00
Andreas Schneider
0d2a366cce Fix samba-tool on builds with samba-dc
resolves: rhbz#2036443
2022-02-23 11:49:53 +01:00
Pavel Filipenský
08f90048f5 Update to Samba 4.16.0rc3
resolves: #2042518

pfilipen
2022-02-15 11:52:16 +01:00
Günther Deschner
626bbcbaac There is no such thing like .el9rhgs
Guenther
2022-02-02 14:41:00 +01:00
Pavel Filipenský
4ee87cc214 Fix missing mdssvc/elasticsearch_mappings.json
pfilipen
2022-02-01 11:13:21 +01:00
Pavel Filipenský
fae36af2f3 Update to Samba 4.16.0rc2
resolves: #2046120, #2048566 - Security fixes for CVE-2021-44141
resolves: #2046146, #2048570 - Security fixes for CVE-2021-44142
resolves: #2046134, #2048568 - Security fixes for CVE-2022-0336
resolves: #2042518

pfilipen
2022-02-01 08:23:36 +01:00
Pavel Filipenský
b935fbcb7d vfs_cephfs on ppc64le is excluded till ceph is fixed on ppc64le 2022-01-26 10:35:36 +01:00
Pavel Filipenský
c8ac21e6f1 Update to Samba 4.16.0rc1 2022-01-25 16:41:03 +01:00
Pavel Filipenský
c1f9bec1db Switch off ld.gold 2022-01-21 11:46:51 +01:00
Pavel Filipenský
6da37eb4ca Update to Samba 4.15.4
resolves: #2009673, #2039034 - Security fixes for CVE-2021-20316
resolves: #2042518

pfilipen
2022-01-20 14:30:55 +01:00
Andreas Schneider
13dfbb0767 Require python3-pyasn1 >= 0.4.8 2022-01-10 15:08:40 +01:00
Pavel Filipenský
8a81633e9a Fix resolv_wrapper with glibc 2.34
resolves: #2019669

pfilipen
2021-12-15 12:33:50 +01:00
Andreas Schneider
3314e8e15a Add missing Requires 2021-12-09 19:11:22 +01:00
Pavel Filipenský
6bc60bb396 Update to Samba 4.15.3
resolves: #2030382

pfilipen
2021-12-08 18:55:07 +01:00
Andreas Schneider
a4093f41f0 Remove unneeded lmdb dependency for samba-tool if we don't have a DC 2021-12-03 13:55:09 +01:00
Andreas Schneider
73757dc8a3 Define _make_verbose in if it doesn't exits
This is needed to build for RHEL8.
2021-11-25 14:58:29 +01:00
Andreas Schneider
6f2c200320 Always build with quota support
We want that the build fails, if we don't have quota support.
2021-11-15 11:14:50 +01:00
Günther Deschner
2ee30bad8f Fix IPA DC schannel support
Guenther
2021-11-13 00:15:32 +01:00
Günther Deschner
2eedc4de19 Fix smbclient -N failures in container setups
Guenther
2021-11-11 18:53:23 +01:00
Günther Deschner
af2d47413b Fix logfile handling
Guenther
2021-11-11 16:02:57 +01:00
Günther Deschner
f0333fc6d6 Fix winbind trusted domain regression
related: #2021716

Guenther
2021-11-11 14:46:42 +01:00
Günther Deschner
56ca6af06a Update to Samba 4.15.2
resolves: #2019660, #2021711 - Security fixes for CVE-2016-2124
resolves: #2019672, #2021716 - Security fixes for CVE-2020-25717
resolves: #2019726, #2021718 - Security fixes for CVE-2020-25718
resolves: #2019732, #2021719 - Security fixes for CVE-2020-25719
resolves: #2021728, #2021729 - Security fixes for CVE-2020-25721
resolves: #2019764, #2021721 - Security fixes for CVE-2020-25722
resolves: #2021726, #2021727 - Security fixes for CVE-2021-3738
resolves: #2019666, #2021715 - Security fixes for CVE-2021-23192
resolves: #2021625

Guenther
2021-11-10 14:12:54 +01:00
Günther Deschner
3c2c163325 Fix winexe core dump
resolves: #2020376

Guenther
2021-11-05 15:01:26 +01:00
Günther Deschner
331ea7c567 Update to Samba 4.15.1
resolves: #2017847

Guenther
2021-10-27 16:33:51 +02:00
Günther Deschner
bc51ea8a5e Update to Samba 4.15.0
resolves: #2005817

Guenther
2021-09-20 12:05:43 +02:00
Günther Deschner
2efb445c94 Update to Samba 4.15.0rc7
resolves: #2003740

Guenther
2021-09-13 17:31:33 +02:00
Günther Deschner
c6ac21963a Update to Samba 4.15.0rc6
resolves: #2002546

Guenther
2021-09-09 11:48:05 +02:00
Günther Deschner
29bd82541a Update to Samba 4.15.0rc5
resolves: #2001827

Guenther
2021-09-07 12:21:08 +02:00
Andreas Schneider
eae8b04784 The testsuite requires lmdb-devel 2021-09-03 09:07:37 +02:00
Andreas Schneider
a7a77b0af0 We need python3-cryptography for krb5 tests 2021-09-03 09:07:20 +02:00
Günther Deschner
0a04de2534 Update to Samba 4.15.0rc4
resolves: #2000079

Guenther
2021-09-01 13:47:44 +02:00
Günther Deschner
a184099345 Update to Samba 4.15.0rc3
resolves: #1998024

Guenther
2021-08-26 13:26:14 +02:00
Günther Deschner
fe6291ff86 Add ceph and etcd mutex helpers for CTDB
Guenther
2021-08-25 17:29:12 +02:00
Anoop C S
6410d154eb Revert "Exclude PyDSDB library files"
This reverts commit cc8c80c04b.
2021-08-16 13:21:01 +05:30
Anoop C S
cffce0ef3e Remove duplicate listing for libdnsserver-common-samba4.so
libdnsserver-common-samba4.so is already getting packaged in samba-libs
sub-package(see 68140d413f) and
samba-dc-libs pulls in samba-libs. Therefore removing it from samba-dc-libs.
2021-08-16 13:16:10 +05:30
Adam Williamson
376ef2f0e0 Fix samba-common-tools dependency
It was literally "python3-%{samba}", which obviously didn't
work.
2021-08-13 09:12:01 -07:00
Andreas Schneider
713db3d972 Add missing Requires in samba-common-tools for samba-tool 2021-08-12 15:02:04 +02:00
Anoop C S
68140d413f Fix inclusion of PyDSDB library files
Commit cc8c80c04b removed the following
PyDSDB library files from buildroot:

* /usr/lib64/python3.9/site-packages/samba/dsdb.cpython-39-x86_64-linux-gnu.so
* /usr/lib64/python3.9/site-packages/samba/dsdb_dns.cpython-39-x86_64-linux-gnu.so

This was done under the impression that their dependency on
libdnsserver-common-samba4.so was not built in a non AD DC
environment. But in reality it was also conditionally removed
from the buildroot.

Apart from including PyDSDB back into python3-samba, we avoid removing
libdnsserver-common-samba4.so from buildroot and subsequently include it
in samba-libs to satisfy all dependencies. Additionally we remove PyDSDB
listing from %files section of python3-samba-dc sub-package.
2021-08-12 17:15:15 +05:30
Andreas Schneider
47c27ed2c1 Document how to build with fedpkg 2021-08-11 10:32:09 +02:00
Andreas Schneider
b904ff11a5 Use more CPUs for re-linking during the install step if possible 2021-08-11 10:32:09 +02:00
Andreas Schneider
58450895a0 Require libs packages to be updated before restarting winbindd 2021-08-11 10:32:09 +02:00
Anoop C S
db523c32da Move samba-tool from samba-dc to samba-common-tools sub-package
samba-tool is now built in a non AD DC environment and has been improved
to prevent crashes due to import errors. See the following commits in
upstream:

* https://git.samba.org/?p=samba.git;a=commit;h=779d0f02718b3812024bafcd5477ec3039c7a0cf
* https://git.samba.org/?p=samba.git;a=commit;h=fb5fe30e824d2d511188053ce04cf797b769727a
* https://git.samba.org/?p=samba.git;a=commit;h=f241fe5d46e8dd2b3265be7eddbd6686a6f920db
* https://git.samba.org/?p=samba.git;a=commit;h=a45ea91cd7e8335319c96ea5bda02014f584df63

related: #1991353
2021-08-11 12:53:03 +05:30
Anoop C S
cc8c80c04b Exclude PyDSDB library files
Following library files are built without AD DC but has dependency on
other components which are only available with DC:

/usr/lib64/python3.9/site-packages/samba/dsdb.cpython-39-x86_64-linux-gnu.so
/usr/lib64/python3.9/site-packages/samba/dsdb_dns.cpython-39-x86_64-linux-gnu.so

Therefore we remove those from buildroot.

resolves: #1991353
2021-08-11 12:18:41 +05:30
21 changed files with 4834 additions and 5159 deletions

1
.fmf/version Normal file
View file

@ -0,0 +1 @@
1

299
.gitignore vendored
View file

@ -1,295 +1,4 @@
samba-3.5.4.tar.gz
samba-3.6.0pre1.tar.gz
/samba-3.6.0pre2.tar.gz
/samba-3.6.0pre3.tar.gz
/samba-3.6.0rc1.tar.gz
/samba-3.6.0rc2.tar.gz
/samba-3.6.0rc3.tar.gz
/samba-3.6.0.tar.gz
/samba-3.6.1.tar.gz
/samba-3.6.3.tar.gz
/samba-3.6.4.tar.gz
/samba-3.6.5.tar.gz
/samba-3.6.6.tar.gz
/samba-3.6.7.tar.gz
/samba-4.0.0rc1.tar.bz2
/samba-4.0.0rc2.tar.bz2
/samba-4.0.0rc3.tar.bz2
/samba-4.0.0rc4.tar.bz2
/samba-4.0.0rc5.tar.bz2
/samba-4.0.0rc6.tar.bz2
/samba-4.0.0.tar.bz2
/samba-4.0.1.tar.bz2
/samba-4.0.2.tar.bz2
/samba-4.0.3.tar.bz2
/samba-4.0.4.tar.bz2
/samba-4.0.5.tar.bz2
/samba-4.0.6.tar.bz2
/samba-4.0.7.tar.xz
/samba-4.1.0rc1.tar.xz
/samba-4.1.0rc2.tar.xz
/samba-4.1.0rc3.tar.xz
/samba-4.1.0rc4.tar.xz
/samba-4.1.0.tar.xz
/samba-4.1.1.tar.xz
/samba-4.1.2.tar.xz
/samba-4.1.3.tar.xz
/samba-4.1.4.tar.xz
/samba-4.1.5.tar.xz
/samba-4.1.6.tar.xz
/samba-4.1.8.tar.xz
/samba-4.1.9.tar.xz
/samba-4.1.11.tar.gz
/samba-4.1.11.tar.xz
/samba-4.1.12.tar.xz
/samba-4.2.0rc2.tar.xz
/samba-4.2.0rc3.tar.xz
/samba-4.2.0rc4.tar.xz
/samba-4.2.0rc5.tar.xz
/samba-4.2.0.tar.xz
/samba-4.2.1.tar.xz
/samba-4.2.2.tar.xz
/samba-4.2.3.tar.xz
/samba-4.3.0rc3.tar.xz
/samba-4.3.0rc4.tar.xz
/samba-4.3.0.tar.xz
/samba-4.3.1.tar.xz
/samba-4.3.2.tar.xz
/samba-4.3.3.tar.xz
/samba-4.3.4.tar.xz
/samba-4.4.0rc1.tar.xz
/samba-4.4.0rc2.tar.xz
/samba-4.4.0rc3.tar.xz
/samba-4.4.0rc4.tar.xz
/samba-4.4.0rc5.tar.xz
/samba-4.4.0.tar.xz
/samba-4.4.2.tar.xz
/samba-4.4.3.tar.xz
/samba-4.4.4.tar.xz
/samba-4.4.5.tar.xz
/samba-4.5.0rc1.tar.xz
/samba-4.5.0rc2.tar.xz
/samba-4.5.0rc3.tar.xz
/samba-4.5.0.tar.xz
/samba-4.5.1.tar.xz
/samba-4.5.2.tar.xz
/samba-4.5.3.tar.xz
/samba-4.6.0rc1.tar.xz
/samba-4.6.0rc2.tar.xz
/samba-4.6.0rc2.tar.asc
/samba-4.6.0rc3.tar.asc
/samba-4.6.0rc3.tar.xz
/samba-4.6.0rc4.tar.xz
/samba-4.6.0rc4.tar.asc
/samba-4.6.0.tar.asc
/samba-4.6.0.tar.xz
/samba-4.6.1.tar.xz
/samba-4.6.1.tar.asc
/samba-4.6.2.tar.xz
/samba-4.6.2.tar.asc
/samba-4.6.3.tar.xz
/samba-4.6.3.tar.asc
/samba-4.6.4.tar.xz
/samba-4.6.4.tar.asc
/samba-4.6.5.tar.xz
/samba-4.6.5.tar.asc
/samba-4.7.0rc1.tar.xz
/samba-4.7.0rc1.tar.asc
/samba-4.7.0rc3.tar.xz
/samba-4.7.0rc3.tar.asc
/samba-4.7.0rc5.tar.xz
/samba-4.7.0rc5.tar.asc
/samba-4.7.0rc6.tar.xz
/samba-4.7.0rc6.tar.asc
/samba-4.7.0.tar.xz
/samba-4.7.0.tar.asc
/samba-4.7.1.tar.xz
/samba-4.7.1.tar.asc
/samba-4.7.2.tar.xz
/samba-4.7.2.tar.asc
/samba-4.7.3.tar.xz
/samba-4.7.3.tar.asc
/samba-4.7.4.tar.xz
/samba-4.7.4.tar.asc
/samba-4.8.0rc1.tar.xz
/samba-4.8.0rc1.tar.asc
/samba-4.8.0rc2.tar.xz
/samba-4.8.0rc2.tar.asc
/samba-4.8.0rc3.tar.xz
/samba-4.8.0rc3.tar.asc
/samba-4.8.0rc4.tar.xz
/samba-4.8.0rc4.tar.asc
/samba-4.8.0.tar.xz
/samba-4.8.0.tar.asc
/samba-4.8.1.tar.xz
/samba-4.8.1.tar.asc
/samba-4.8.2.tar.xz
/samba-4.8.2.tar.asc
/samba-4.8.3.tar.asc
/samba-4.8.3.tar.xz
/samba-4.9.0rc1.tar.xz
/samba-4.9.0rc1.tar.asc
/samba-4.9.0rc2.tar.xz
/samba-4.9.0rc2.tar.asc
/samba-4.9.0rc3.tar.xz
/samba-4.9.0rc3.tar.asc
/samba-4.9.0rc4.tar.xz
/samba-4.9.0rc4.tar.asc
/samba-4.9.0rc5.tar.asc
/samba-4.9.0rc5.tar.xz
/samba-4.9.0.tar.xz
/samba-4.9.0.tar.asc
/samba-4.9.1.tar.asc
/samba-4.9.1.tar.xz
/samba-4.9.2.tar.xz
/samba-4.9.2.tar.asc
/samba-4.9.3.tar.xz
/samba-4.9.3.tar.asc
/samba-4.9.4.tar.xz
/samba-4.9.4.tar.asc
/samba-4.10.0rc1.tar.xz
/samba-4.10.0rc1.tar.asc
/samba-4.10.0rc2.tar.xz
/samba-4.10.0rc2.tar.asc
/samba-4.10.0rc3.tar.xz
/samba-4.10.0rc3.tar.asc
/samba-4.10.0rc4.tar.xz
/samba-4.10.0rc4.tar.asc
/samba-4.10.0.tar.xz
/samba-4.10.0.tar.asc
/samba-4.10.1.tar.xz
/samba-4.10.1.tar.asc
/samba-4.10.2.tar.xz
/samba-4.10.2.tar.asc
/samba-4.10.3.tar.xz
/samba-4.10.3.tar.asc
/samba-4.10.4.tar.xz
/samba-4.10.4.tar.asc
/samba-4.10.5.tar.xz
/samba-4.10.5.tar.asc
/samba-4.10.6.tar.xz
/samba-4.10.6.tar.asc
/samba-4.11.0rc1.tar.xz
/samba-4.11.0rc1.tar.asc
/samba-4.11.0rc2.tar.xz
/samba-4.11.0rc2.tar.asc
/samba-4.11.0rc3.tar.xz
/samba-4.11.0rc3.tar.asc
/samba-4.11.0rc4.tar.xz
/samba-4.11.0rc4.tar.asc
/samba-4.11.0.tar.xz
/samba-4.11.0.tar.asc
/samba-4.11.1.tar.xz
/samba-4.11.1.tar.asc
/samba-4.11.2.tar.xz
/samba-4.11.2.tar.asc
/samba-4.11.3.tar.xz
/samba-4.11.3.tar.asc
/samba-4.11.4.tar.xz
/samba-4.11.4.tar.asc
/samba-4.11.5.tar.xz
/samba-4.11.5.tar.asc
/samba-4.12.0rc1.tar.xz
/samba-4.12.0rc1.tar.asc
/samba-4.12.0rc2.tar.xz
/samba-4.12.0rc2.tar.asc
/samba-4.12.0rc3.tar.xz
/samba-4.12.0rc3.tar.asc
/samba-4.12.0rc4.tar.xz
/samba-4.12.0rc4.tar.asc
/samba-4.12.0.tar.xz
/samba-4.12.0.tar.asc
/samba-4.12.1.tar.xz
/samba-4.12.1.tar.asc
/samba-4.12.2.tar.xz
/samba-4.12.2.tar.asc
/samba-4.12.3.tar.xz
/samba-4.12.3.tar.asc
/samba-4.12.4.tar.xz
/samba-4.12.4.tar.asc
/samba-4.12.5.tar.xz
/samba-4.12.5.tar.asc
/samba-4.13.0rc1.tar.xz
/samba-4.13.0rc1.tar.asc
/samba-4.13.0rc2.tar.xz
/samba-4.13.0rc2.tar.asc
/samba-4.13.0rc3.tar.xz
/samba-4.13.0rc3.tar.asc
/samba-4.13.0rc4.tar.xz
/samba-4.13.0rc4.tar.asc
/samba-4.13.0rc5.tar.xz
/samba-4.13.0rc5.tar.asc
/samba-4.13.0rc6.tar.xz
/samba-4.13.0rc6.tar.asc
/samba-4.13.0.tar.xz
/samba-4.13.0.tar.asc
/samba-4.13.1.tar.xz
/samba-4.13.1.tar.asc
/samba-4.13.2.tar.xz
/samba-4.13.2.tar.asc
/samba-4.13.3.tar.xz
/samba-4.13.3.tar.asc
/samba-4.13.4.tar.xz
/samba-4.13.4.tar.asc
/samba-4.14.0rc1.tar.xz
/samba-4.14.0rc1.tar.asc
/samba-4.14.0rc2.tar.xz
/samba-4.14.0rc2.tar.asc
/samba-4.14.0rc3.tar.xz
/samba-4.14.0rc3.tar.asc
/samba-4.14.0rc4.tar.xz
/samba-4.14.0rc4.tar.asc
/samba-4.14.0.tar.xz
/samba-4.14.0.tar.asc
/samba-4.14.1.tar.xz
/samba-4.14.1.tar.asc
/samba-4.14.2.tar.xz
/samba-4.14.2.tar.asc
/samba-4.14.3.tar.xz
/samba-4.14.3.tar.asc
/samba-4.14.4.tar.xz
/samba-4.14.4.tar.asc
/samba-4.14.5.tar.xz
/samba-4.14.5.tar.asc
/samba-4.14.6.tar.xz
/samba-4.14.6.tar.asc
/samba-4.15.0rc1.tar.xz
/samba-4.15.0rc1.tar.asc
/samba-4.15.0rc2.tar.xz
/samba-4.15.0rc2.tar.asc
/samba-4.15.0rc3.tar.xz
/samba-4.15.0rc3.tar.asc
/samba-4.15.0rc4.tar.xz
/samba-4.15.0rc4.tar.asc
/samba-4.15.0rc5.tar.xz
/samba-4.15.0rc5.tar.asc
/samba-4.15.0rc6.tar.xz
/samba-4.15.0rc6.tar.asc
/samba-4.15.0rc7.tar.xz
/samba-4.15.0rc7.tar.asc
/samba-4.15.0.tar.xz
/samba-4.15.0.tar.asc
/samba-4.15.1.tar.xz
/samba-4.15.1.tar.asc
/samba-4.15.2.tar.xz
/samba-4.15.2.tar.asc
/samba-4.15.3.tar.xz
/samba-4.15.3.tar.asc
/samba-4.15.4.tar.xz
/samba-4.15.4.tar.asc
/samba-4.15.5.tar.xz
/samba-4.15.5.tar.asc
/samba-4.15.6.tar.xz
/samba-4.15.6.tar.asc
/samba-4.15.7.tar.xz
/samba-4.15.7.tar.asc
/samba-4.15.8.tar.xz
/samba-4.15.8.tar.asc
/samba-4.15.9.tar.xz
/samba-4.15.9.tar.asc
/samba-4.15.10.tar.xz
/samba-4.15.10.tar.asc
/samba-4.15.11.tar.xz
/samba-4.15.11.tar.asc
/samba-4.15.12.tar.xz
/samba-4.15.12.tar.asc
/samba-*.tar.xz
/samba-*.tar.asc
/*.rpm
/results_samba

3039
changelog Normal file

File diff suppressed because it is too large Load diff

6
gating.yaml Normal file
View file

@ -0,0 +1,6 @@
--- !Policy
product_versions:
- fedora-*
decision_context: bodhi_update_push_stable
rules:
- !PassingTestCaseRule {test_case_name: fedora-ci.koji-build.tier0.functional}

4
plans.fmf Normal file
View file

@ -0,0 +1,4 @@
discover:
how: fmf
execute:
how: tmt

View file

@ -1,12 +1,17 @@
---
inspections:
disttag: off
badfuncs:
ignore:
- /usr/bin/nmbd
- /usr/bin/nmblookup
- /usr/bin/smbtorture
- /usr/lib*/libndr.so.*
- /usr/lib*/libsmbconf.so.*
- /usr/lib*/samba/libgse-samba4.so
- /usr/lib*/samba/libsamba-sockets-samba4.so
- /usr/lib*/samba/libgse-private-samba.so
- /usr/lib*/samba/libsamba-sockets-private-samba.so
- /usr/lib*/samba/service/nbtd.so
- /usr/libexec/ctdb/smnotify
- /usr/sbin/nmbd
@ -14,3 +19,17 @@ runpath:
allowed_paths:
- /usr/lib/samba
- /usr/lib64/samba
abidiff:
suppression_file: samba.abignore
debuginfo:
ignore:
- /usr/lib*/libdcerpc-samr.so.*
annocheck:
ignore:
- /usr/bin/gentest
- /usr/bin/locktest
- /usr/bin/masktest
- /usr/bin/smbtorture

View file

@ -0,0 +1,38 @@
From b1ec803f420b2c6d3c5c83d70c6875a7f36b15fc Mon Sep 17 00:00:00 2001
From: Andreas Schneider <asn@samba.org>
Date: Fri, 21 Nov 2025 15:33:32 +0100
Subject: [PATCH] s4:dsdb: Do not declare cm_print_error()
This is part of the cmocka.h header file.
Signed-off-by: Andreas Schneider <asn@samba.org>
Reviewed-by: Martin Schwenke <martin@meltin.net>
Reviewed-by: Volker Lendecke <vl@samba.org>
Autobuild-User(master): Volker Lendecke <vl@samba.org>
Autobuild-Date(master): Mon Nov 24 11:28:08 UTC 2025 on atb-devel-224
(cherry picked from commit 5a981663e4f677042ba80191770100aecff2120a)
---
source4/dsdb/samdb/ldb_modules/tests/test_group_audit.c | 5 -----
1 file changed, 5 deletions(-)
diff --git a/source4/dsdb/samdb/ldb_modules/tests/test_group_audit.c b/source4/dsdb/samdb/ldb_modules/tests/test_group_audit.c
index f7075f3485e..12c464b49c7 100644
--- a/source4/dsdb/samdb/ldb_modules/tests/test_group_audit.c
+++ b/source4/dsdb/samdb/ldb_modules/tests/test_group_audit.c
@@ -103,11 +103,6 @@ void audit_message_send(
#define check_group_change_message(m, u, a, e) \
_check_group_change_message(m, u, a, e, __FILE__, __LINE__);
-/*
- * declare the internal cmocka cm_print_error so that we can output messages
- * in sub unit format
- */
-void cm_print_error(const char * const format, ...);
/*
* Validate a group change JSON audit message
--
2.52.0

View file

@ -1,30 +0,0 @@
From 939aed0498269df3c1e012f3b68c314b583f25bd Mon Sep 17 00:00:00 2001
From: Martin Schwenke <martin@meltin.net>
Date: Tue, 27 Apr 2021 15:46:14 +1000
Subject: [PATCH] utils: Use Python 3
Due to the number of flake8 and pylint warnings it is unclear if the
source has Python 3 incompatibilities. These will be cleaned up in
subsequent commits.
Signed-off-by: "L.P.H. van Belle" <belle@bazuin.nl>
Reviewed-by: Martin Schwenke <martin@meltin.net>
Reviewed-by: David Disseldorp <ddiss@samba.org>
Reviewed-by: Jose A. Rivera <jarrpa@samba.org>
---
ctdb/utils/etcd/ctdb_etcd_lock | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/ctdb/utils/etcd/ctdb_etcd_lock b/ctdb/utils/etcd/ctdb_etcd_lock
index 000c6bb7208..7f5194eff0a 100755
--- a/ctdb/utils/etcd/ctdb_etcd_lock
+++ b/ctdb/utils/etcd/ctdb_etcd_lock
@@ -1,4 +1,4 @@
-#!/usr/bin/python
+#!/usr/bin/env python3
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU General Public License as published by
--
2.31.1

View file

@ -1,642 +0,0 @@
From cfdb01091c4ad005654da9b4a64251a6d02ea637 Mon Sep 17 00:00:00 2001
From: Isaac Boukris <iboukris@gmail.com>
Date: Fri, 27 Sep 2019 18:25:03 +0300
Subject: [PATCH 1/3] mit-kdc: add basic loacl realm S4U support
Signed-off-by: Isaac Boukris <iboukris@gmail.com>
Pair-Programmed-With: Andreas Schneider <asn@samba.org>
---
source4/kdc/mit-kdb/kdb_samba_policies.c | 124 +++++++++++------------
source4/kdc/mit_samba.c | 47 ++-------
source4/kdc/mit_samba.h | 6 +-
3 files changed, 71 insertions(+), 106 deletions(-)
diff --git a/source4/kdc/mit-kdb/kdb_samba_policies.c b/source4/kdc/mit-kdb/kdb_samba_policies.c
index dada3b79144..677ec1007c9 100644
--- a/source4/kdc/mit-kdb/kdb_samba_policies.c
+++ b/source4/kdc/mit-kdb/kdb_samba_policies.c
@@ -197,13 +197,17 @@ static krb5_error_code ks_verify_pac(krb5_context context,
krb5_keyblock *krbtgt_key,
krb5_timestamp authtime,
krb5_authdata **tgt_auth_data,
- krb5_pac *pac)
+ krb5_pac *out_pac)
{
struct mit_samba_context *mit_ctx;
krb5_authdata **authdata = NULL;
- krb5_pac ipac = NULL;
- DATA_BLOB logon_data = { NULL, 0 };
+ krb5_keyblock *header_server_key = NULL;
+ krb5_key_data *impersonator_kd = NULL;
+ krb5_keyblock impersonator_key = {0};
krb5_error_code code;
+ krb5_pac pac;
+
+ *out_pac = NULL;
mit_ctx = ks_get_context(context);
if (mit_ctx == NULL) {
@@ -235,41 +239,43 @@ static krb5_error_code ks_verify_pac(krb5_context context,
code = krb5_pac_parse(context,
authdata[0]->contents,
authdata[0]->length,
- &ipac);
+ &pac);
if (code != 0) {
goto done;
}
- /* TODO: verify this is correct
- *
- * In the constrained delegation case, the PAC is from a service
- * ticket rather than a TGT; we must verify the server and KDC
- * signatures to assert that the server did not forge the PAC.
+ /*
+ * For constrained delegation in MIT version < 1.18 we aren't provided
+ * with the 2nd ticket server key to verify the PAC.
+ * We can workaround that by fetching the key from the client db entry,
+ * which is the impersonator account in that version.
+ * TODO: use the provided entry in the new 1.18 version.
*/
if (flags & KRB5_KDB_FLAG_CONSTRAINED_DELEGATION) {
- code = krb5_pac_verify(context,
- ipac,
- authtime,
- client_princ,
- server_key,
- krbtgt_key);
+ /* The impersonator must be local. */
+ if (client == NULL) {
+ code = KRB5KDC_ERR_BADOPTION;
+ goto done;
+ }
+ /* Fetch and decrypt 2nd ticket server's current key. */
+ code = krb5_dbe_find_enctype(context, client, -1, -1, 0,
+ &impersonator_kd);
+ if (code != 0) {
+ goto done;
+ }
+ code = krb5_dbe_decrypt_key_data(context, NULL,
+ impersonator_kd,
+ &impersonator_key, NULL);
+ if (code != 0) {
+ goto done;
+ }
+ header_server_key = &impersonator_key;
} else {
- code = krb5_pac_verify(context,
- ipac,
- authtime,
- client_princ,
- krbtgt_key,
- NULL);
- }
- if (code != 0) {
- goto done;
+ header_server_key = krbtgt_key;
}
- /* check and update PAC */
- code = krb5_pac_parse(context,
- authdata[0]->contents,
- authdata[0]->length,
- pac);
+ code = krb5_pac_verify(context, pac, authtime, client_princ,
+ header_server_key, NULL);
if (code != 0) {
goto done;
}
@@ -277,17 +283,22 @@ static krb5_error_code ks_verify_pac(krb5_context context,
code = mit_samba_reget_pac(mit_ctx,
context,
flags,
- client_princ,
client,
server,
krbtgt,
krbtgt_key,
- pac);
+ &pac);
+ if (code != 0) {
+ goto done;
+ }
+
+ *out_pac = pac;
+ pac = NULL;
done:
+ krb5_free_keyblock_contents(context, &impersonator_key);
krb5_free_authdata(context, authdata);
- krb5_pac_free(context, ipac);
- free(logon_data.data);
+ krb5_pac_free(context, pac);
return code;
}
@@ -316,6 +327,7 @@ krb5_error_code kdb_samba_db_sign_auth_data(krb5_context context,
krb5_authdata **pac_auth_data = NULL;
krb5_authdata **authdata = NULL;
krb5_boolean is_as_req;
+ krb5_const_principal pac_client;
krb5_error_code code;
krb5_pac pac = NULL;
krb5_data pac_data;
@@ -327,11 +339,6 @@ krb5_error_code kdb_samba_db_sign_auth_data(krb5_context context,
krbtgt = krbtgt == NULL ? local_krbtgt : krbtgt;
krbtgt_key = krbtgt_key == NULL ? local_krbtgt_key : krbtgt_key;
- /* FIXME: We don't support S4U yet */
- if (flags & KRB5_KDB_FLAGS_S4U) {
- return KRB5_KDB_DBTYPE_NOSUP;
- }
-
is_as_req = ((flags & KRB5_KDB_FLAG_CLIENT_REFERRALS_ONLY) != 0);
/*
@@ -392,6 +399,16 @@ krb5_error_code kdb_samba_db_sign_auth_data(krb5_context context,
ks_client_princ = client->princ;
}
+ /* In protocol transition, we are currently not provided with the tgt
+ * client name to verify the PAC, we could probably skip the name
+ * verification and just verify the signatures, but since we don't
+ * support cross-realm nor aliases, we can just use server->princ */
+ if (flags & KRB5_KDB_FLAG_PROTOCOL_TRANSITION) {
+ pac_client = server->princ;
+ } else {
+ pac_client = ks_client_princ;
+ }
+
if (client_entry == NULL) {
client_entry = client;
}
@@ -456,7 +473,7 @@ krb5_error_code kdb_samba_db_sign_auth_data(krb5_context context,
code = ks_verify_pac(context,
flags,
- ks_client_princ,
+ pac_client,
client_entry,
server,
krbtgt,
@@ -497,7 +514,7 @@ krb5_error_code kdb_samba_db_sign_auth_data(krb5_context context,
is_as_req ? "AS-REQ" : "TGS-REQ",
client_name);
code = krb5_pac_sign(context, pac, authtime, ks_client_princ,
- server_key, krbtgt_key, &pac_data);
+ server_key, krbtgt_key, &pac_data);
if (code != 0) {
DBG_ERR("krb5_pac_sign failed: %d\n", code);
goto done;
@@ -523,12 +540,6 @@ krb5_error_code kdb_samba_db_sign_auth_data(krb5_context context,
KRB5_AUTHDATA_IF_RELEVANT,
authdata,
signed_auth_data);
- if (code != 0) {
- goto done;
- }
-
- code = 0;
-
done:
if (client_entry != NULL && client_entry != client) {
ks_free_principal(context, client_entry);
@@ -554,32 +565,13 @@ krb5_error_code kdb_samba_db_check_allowed_to_delegate(krb5_context context,
* server; -> delegating service
* proxy; -> target principal
*/
- krb5_db_entry *delegating_service = discard_const_p(krb5_db_entry, server);
-
- char *target_name = NULL;
- bool is_enterprise;
- krb5_error_code code;
mit_ctx = ks_get_context(context);
if (mit_ctx == NULL) {
return KRB5_KDB_DBNOTINITED;
}
- code = krb5_unparse_name(context, proxy, &target_name);
- if (code) {
- goto done;
- }
-
- is_enterprise = (proxy->type == KRB5_NT_ENTERPRISE_PRINCIPAL);
-
- code = mit_samba_check_s4u2proxy(mit_ctx,
- delegating_service,
- target_name,
- is_enterprise);
-
-done:
- free(target_name);
- return code;
+ return mit_samba_check_s4u2proxy(mit_ctx, server, proxy);
}
diff --git a/source4/kdc/mit_samba.c b/source4/kdc/mit_samba.c
index ef4e8c2ed38..962fd05e1ac 100644
--- a/source4/kdc/mit_samba.c
+++ b/source4/kdc/mit_samba.c
@@ -517,7 +517,6 @@ int mit_samba_get_pac(struct mit_samba_context *smb_ctx,
krb5_error_code mit_samba_reget_pac(struct mit_samba_context *ctx,
krb5_context context,
int flags,
- krb5_const_principal client_principal,
krb5_db_entry *client,
krb5_db_entry *server,
krb5_db_entry *krbtgt,
@@ -688,7 +687,7 @@ krb5_error_code mit_samba_reget_pac(struct mit_samba_context *ctx,
context,
*pac,
server->princ,
- discard_const(client_principal),
+ client->princ,
deleg_blob);
if (!NT_STATUS_IS_OK(nt_status)) {
DEBUG(0, ("Update delegation info failed: %s\n",
@@ -1080,41 +1079,17 @@ int mit_samba_check_client_access(struct mit_samba_context *ctx,
}
int mit_samba_check_s4u2proxy(struct mit_samba_context *ctx,
- krb5_db_entry *kentry,
- const char *target_name,
- bool is_nt_enterprise_name)
+ const krb5_db_entry *server,
+ krb5_const_principal target_principal)
{
-#if 1
- /*
- * This is disabled because mit_samba_update_pac_data() does not handle
- * S4U_DELEGATION_INFO
- */
-
- return KRB5KDC_ERR_BADOPTION;
-#else
- krb5_principal target_principal;
- int flags = 0;
- int ret;
-
- if (is_nt_enterprise_name) {
- flags = KRB5_PRINCIPAL_PARSE_ENTERPRISE;
- }
-
- ret = krb5_parse_name_flags(ctx->context, target_name,
- flags, &target_principal);
- if (ret) {
- return ret;
- }
-
- ret = samba_kdc_check_s4u2proxy(ctx->context,
- ctx->db_ctx,
- skdc_entry,
- target_principal);
-
- krb5_free_principal(ctx->context, target_principal);
-
- return ret;
-#endif
+ struct samba_kdc_entry *server_skdc_entry =
+ talloc_get_type_abort(server->e_data,
+ struct samba_kdc_entry);
+
+ return samba_kdc_check_s4u2proxy(ctx->context,
+ ctx->db_ctx,
+ server_skdc_entry,
+ target_principal);
}
static krb5_error_code mit_samba_change_pwd_error(krb5_context context,
diff --git a/source4/kdc/mit_samba.h b/source4/kdc/mit_samba.h
index 4431e82a1b2..9370ab533af 100644
--- a/source4/kdc/mit_samba.h
+++ b/source4/kdc/mit_samba.h
@@ -57,7 +57,6 @@ int mit_samba_get_pac(struct mit_samba_context *smb_ctx,
krb5_error_code mit_samba_reget_pac(struct mit_samba_context *ctx,
krb5_context context,
int flags,
- krb5_const_principal client_principal,
krb5_db_entry *client,
krb5_db_entry *server,
krb5_db_entry *krbtgt,
@@ -74,9 +73,8 @@ int mit_samba_check_client_access(struct mit_samba_context *ctx,
DATA_BLOB *e_data);
int mit_samba_check_s4u2proxy(struct mit_samba_context *ctx,
- krb5_db_entry *kentry,
- const char *target_name,
- bool is_nt_enterprise_name);
+ const krb5_db_entry *server,
+ krb5_const_principal target_principal);
int mit_samba_kpasswd_change_password(struct mit_samba_context *ctx,
char *pwd,
--
2.37.1
From 6e985cf7d5f29292c5f2dd2de75867dd30ef3df6 Mon Sep 17 00:00:00 2001
From: Isaac Boukris <iboukris@gmail.com>
Date: Fri, 27 Sep 2019 18:35:30 +0300
Subject: [PATCH 2/3] krb5-mit: enable S4U client support for MIT build
Signed-off-by: Isaac Boukris <iboukris@gmail.com>
Pair-Programmed-With: Andreas Schneider <asn@samba.org>
---
lib/krb5_wrap/krb5_samba.c | 185 ++++++++++++++++++++++++++
lib/krb5_wrap/krb5_samba.h | 2 -
source4/auth/kerberos/kerberos_util.c | 11 --
3 files changed, 185 insertions(+), 13 deletions(-)
diff --git a/lib/krb5_wrap/krb5_samba.c b/lib/krb5_wrap/krb5_samba.c
index 610efcc9b87..96686147006 100644
--- a/lib/krb5_wrap/krb5_samba.c
+++ b/lib/krb5_wrap/krb5_samba.c
@@ -2697,6 +2697,191 @@ krb5_error_code smb_krb5_kinit_s4u2_ccache(krb5_context ctx,
return 0;
}
+
+#else /* MIT */
+
+static bool princ_compare_no_dollar(krb5_context ctx,
+ krb5_principal a,
+ krb5_principal b)
+{
+ bool cmp;
+ krb5_principal mod = NULL;
+
+ if (a->length == 1 && b->length == 1 &&
+ a->data[0].length != 0 && b->data[0].length != 0 &&
+ a->data[0].data[a->data[0].length -1] !=
+ b->data[0].data[b->data[0].length -1]) {
+ if (a->data[0].data[a->data[0].length -1] == '$') {
+ mod = a;
+ mod->data[0].length--;
+ } else if (b->data[0].data[b->data[0].length -1] == '$') {
+ mod = b;
+ mod->data[0].length--;
+ }
+ }
+
+ cmp = krb5_principal_compare_flags(ctx, a, b,
+ KRB5_PRINCIPAL_COMPARE_CASEFOLD);
+
+ if (mod != NULL) {
+ mod->data[0].length++;
+ }
+
+ return cmp;
+}
+
+krb5_error_code smb_krb5_kinit_s4u2_ccache(krb5_context ctx,
+ krb5_ccache store_cc,
+ krb5_principal init_principal,
+ const char *init_password,
+ krb5_principal impersonate_principal,
+ const char *self_service,
+ const char *target_service,
+ krb5_get_init_creds_opt *krb_options,
+ time_t *expire_time,
+ time_t *kdc_time)
+{
+ krb5_error_code code;
+ krb5_principal self_princ = NULL;
+ krb5_principal target_princ = NULL;
+ krb5_creds *store_creds;
+ krb5_creds *s4u2self_creds = NULL;
+ krb5_creds *s4u2proxy_creds = NULL;
+ krb5_creds init_creds = {0};
+ krb5_creds mcreds = {0};
+ krb5_flags options = KRB5_GC_NO_STORE;
+ krb5_ccache tmp_cc;
+ bool s4u2proxy;
+
+ code = krb5_cc_new_unique(ctx, "MEMORY", NULL, &tmp_cc);
+ if (code != 0) {
+ return code;
+ }
+
+ code = krb5_get_init_creds_password(ctx, &init_creds,
+ init_principal,
+ init_password,
+ NULL, NULL,
+ 0,
+ NULL,
+ krb_options);
+ if (code != 0) {
+ goto done;
+ }
+
+ code = krb5_cc_initialize(ctx, tmp_cc, init_creds.client);
+ if (code != 0) {
+ goto done;
+ }
+
+ code = krb5_cc_store_cred(ctx, tmp_cc, &init_creds);
+ if (code != 0) {
+ goto done;
+ }
+
+ /*
+ * Check if we also need S4U2Proxy or if S4U2Self is
+ * enough in order to get a ticket for the target.
+ */
+ if (target_service == NULL) {
+ s4u2proxy = false;
+ } else if (strcmp(target_service, self_service) == 0) {
+ s4u2proxy = false;
+ } else {
+ s4u2proxy = true;
+ }
+
+ code = krb5_parse_name(ctx, self_service, &self_princ);
+ if (code != 0) {
+ goto done;
+ }
+
+ /* MIT lacks aliases support in S4U, for S4U2Self we require the tgt
+ * client and the request server to be the same principal name. */
+ if (!princ_compare_no_dollar(ctx, init_creds.client, self_princ)) {
+ code = KRB5KDC_ERR_PADATA_TYPE_NOSUPP;
+ goto done;
+ }
+
+ mcreds.client = impersonate_principal;
+ mcreds.server = init_creds.client;
+
+ code = krb5_get_credentials_for_user(ctx, options, tmp_cc, &mcreds,
+ NULL, &s4u2self_creds);
+ if (code != 0) {
+ goto done;
+ }
+
+ if (s4u2proxy) {
+ code = krb5_parse_name(ctx, target_service, &target_princ);
+ if (code != 0) {
+ goto done;
+ }
+
+ mcreds.client = init_creds.client;
+ mcreds.server = target_princ;
+ mcreds.second_ticket = s4u2self_creds->ticket;
+
+ code = krb5_get_credentials(ctx, options |
+ KRB5_GC_CONSTRAINED_DELEGATION,
+ tmp_cc, &mcreds, &s4u2proxy_creds);
+ if (code != 0) {
+ goto done;
+ }
+
+ /* Check KDC support of S4U2Proxy extension */
+ if (!krb5_principal_compare(ctx, s4u2self_creds->client,
+ s4u2proxy_creds->client)) {
+ code = KRB5KDC_ERR_PADATA_TYPE_NOSUPP;
+ goto done;
+ }
+
+ store_creds = s4u2proxy_creds;
+ } else {
+ store_creds = s4u2self_creds;;
+
+ /* We need to save the ticket with the requested server name
+ * or the caller won't be able to find it in cache. */
+ if (!krb5_principal_compare(ctx, self_princ,
+ store_creds->server)) {
+ krb5_free_principal(ctx, store_creds->server);
+ store_creds->server = NULL;
+ code = krb5_copy_principal(ctx, self_princ,
+ &store_creds->server);
+ if (code != 0) {
+ goto done;
+ }
+ }
+ }
+
+ code = krb5_cc_initialize(ctx, store_cc, store_creds->client);
+ if (code != 0) {
+ goto done;
+ }
+
+ code = krb5_cc_store_cred(ctx, store_cc, store_creds);
+ if (code != 0) {
+ goto done;
+ }
+
+ if (expire_time) {
+ *expire_time = (time_t) store_creds->times.endtime;
+ }
+
+ if (kdc_time) {
+ *kdc_time = (time_t) store_creds->times.starttime;
+ }
+
+done:
+ krb5_cc_destroy(ctx, tmp_cc);
+ krb5_free_cred_contents(ctx, &init_creds);
+ krb5_free_creds(ctx, s4u2self_creds);
+ krb5_free_creds(ctx, s4u2proxy_creds);
+ krb5_free_principal(ctx, self_princ);
+ krb5_free_principal(ctx, target_princ);
+
+ return code;
+}
#endif
#if !defined(HAVE_KRB5_MAKE_PRINCIPAL) && defined(HAVE_KRB5_BUILD_PRINCIPAL_ALLOC_VA)
diff --git a/lib/krb5_wrap/krb5_samba.h b/lib/krb5_wrap/krb5_samba.h
index eab67f6d969..b5385c69a33 100644
--- a/lib/krb5_wrap/krb5_samba.h
+++ b/lib/krb5_wrap/krb5_samba.h
@@ -252,7 +252,6 @@ krb5_error_code smb_krb5_kinit_password_ccache(krb5_context ctx,
krb5_get_init_creds_opt *krb_options,
time_t *expire_time,
time_t *kdc_time);
-#ifdef SAMBA4_USES_HEIMDAL
krb5_error_code smb_krb5_kinit_s4u2_ccache(krb5_context ctx,
krb5_ccache store_cc,
krb5_principal init_principal,
@@ -263,7 +262,6 @@ krb5_error_code smb_krb5_kinit_s4u2_ccache(krb5_context ctx,
krb5_get_init_creds_opt *krb_options,
time_t *expire_time,
time_t *kdc_time);
-#endif
#if defined(HAVE_KRB5_MAKE_PRINCIPAL)
#define smb_krb5_make_principal krb5_make_principal
diff --git a/source4/auth/kerberos/kerberos_util.c b/source4/auth/kerberos/kerberos_util.c
index 544d9d853cc..c14d8c72d8c 100644
--- a/source4/auth/kerberos/kerberos_util.c
+++ b/source4/auth/kerberos/kerberos_util.c
@@ -234,9 +234,7 @@ done:
{
krb5_error_code ret;
const char *password;
-#ifdef SAMBA4_USES_HEIMDAL
const char *self_service;
-#endif
const char *target_service;
time_t kdc_time = 0;
krb5_principal princ;
@@ -268,9 +266,7 @@ done:
return ret;
}
-#ifdef SAMBA4_USES_HEIMDAL
self_service = cli_credentials_get_self_service(credentials);
-#endif
target_service = cli_credentials_get_target_service(credentials);
password = cli_credentials_get_password(credentials);
@@ -331,7 +327,6 @@ done:
#endif
if (password) {
if (impersonate_principal) {
-#ifdef SAMBA4_USES_HEIMDAL
ret = smb_krb5_kinit_s4u2_ccache(smb_krb5_context->krb5_context,
ccache,
princ,
@@ -342,12 +337,6 @@ done:
krb_options,
NULL,
&kdc_time);
-#else
- talloc_free(mem_ctx);
- (*error_string) = "INTERNAL error: s4u2 ops "
- "are not supported with MIT build yet";
- return EINVAL;
-#endif
} else {
ret = smb_krb5_kinit_password_ccache(smb_krb5_context->krb5_context,
ccache,
--
2.37.1
From 3a9c224f229128451c878b262a716d48cb9f75d6 Mon Sep 17 00:00:00 2001
From: Isaac Boukris <iboukris@gmail.com>
Date: Sat, 19 Sep 2020 14:16:20 +0200
Subject: [PATCH 3/3] wip: for canonicalization with new MIT kdc code
---
source4/kdc/mit_samba.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/source4/kdc/mit_samba.c b/source4/kdc/mit_samba.c
index 962fd05e1ac..9dc1bdf870b 100644
--- a/source4/kdc/mit_samba.c
+++ b/source4/kdc/mit_samba.c
@@ -232,6 +232,9 @@ int mit_samba_get_principal(struct mit_samba_context *ctx,
if (kflags & KRB5_KDB_FLAG_CANONICALIZE) {
sflags |= SDB_F_CANON;
}
+#if KRB5_KDB_API_VERSION >= 10
+ sflags |= SDB_F_FORCE_CANON;
+#endif
if (kflags & (KRB5_KDB_FLAG_CLIENT_REFERRALS_ONLY |
KRB5_KDB_FLAG_INCLUDE_PAC)) {
/*
--
2.37.1

View file

@ -0,0 +1,2 @@
#Type Name ID
g printadmin -

View file

@ -0,0 +1,2 @@
#Type Name ID
g usershares -

View file

@ -0,0 +1,2 @@
#Type Name ID
g wbpriv 88

5
samba.abignore Normal file
View file

@ -0,0 +1,5 @@
#################################################
# This is a grouping library without any code
#################################################
[suppress_file]
file_name_regexp=.*libdcerpc-samr\\.so.*

View file

@ -1,4 +1,4 @@
/var/log/samba/log.* {
/var/log/samba/*log* {
compress
dateext
maxage 365

5687
samba.spec

File diff suppressed because it is too large Load diff

View file

@ -269,6 +269,13 @@
; map system = no
; store dos attributes = yes
# Turn on SMB 3.1.1 Unix Extensions by default
#
# Note: The Linux Kernel SMB3 client will negotiate unix extensions by default,
# find more info in man mount.smb3(8). Linux 6.13 will finally support special
# filetypes and symlink handling.
smb3 unix extensions = yes
#============================ Share Definitions ==============================

View file

@ -18,6 +18,9 @@
load printers = yes
cups options = raw
# Install samba-usershares package for support
include = /etc/samba/usershares.conf
[homes]
comment = Home Directories
valid users = %S, %D%w%S
@ -35,7 +38,8 @@
[print$]
comment = Printer Drivers
path = /var/lib/samba/drivers
write list = @printadmin root
force group = @printadmin
# printadmin is a local group
write list = printadmin root
force group = printadmin
create mask = 0664
directory mask = 0775

View file

@ -1,2 +1,2 @@
SHA512 (samba-4.15.12.tar.xz) = c3d678944828f718a589630cf19998c8c917d8e93041fc46c07946ecd98ba8656086ca5b8881a1ab7c5a8d8ab4a66c7953e86bd99d67aeac2760e4151ffc0de2
SHA512 (samba-4.15.12.tar.asc) = ac841370c230d0132c5e3ec8c0c1c87f9ba863fd45f6e48f191d50069c8a77cb924ace4166c5f594eda40f8b56f07b0c0501dbf92e38ee3455ccb5c88fa23fb6
SHA512 (samba-4.23.4.tar.xz) = 58979aa8a83e8210918f4f1adbcadff329e57a9cd25d7aba98d18f54a2e790a7ef3cc6b9fb3303d492d33d67f4a135849a419c95644d14e53a39654736d486ac
SHA512 (samba-4.23.4.tar.asc) = 0981ce6a43202953cdc7ceae77fa0e3b4ab853991430dde4df6daa163984de6c7ca3f3a3037376659d3bdaedcc108cdd7a77ce0ac24d0a1add56c7103fca7dce

22
tests/deps-check.fmf Normal file
View file

@ -0,0 +1,22 @@
summary: Check samba package dependency structure
description: |
Verify that samba library packages maintain correct dependency hierarchy:
- samba-core-libs has no samba-*-libs dependencies
- samba-ndr-libs depends on samba-core-libs (not samba-client-libs or samba-libs)
- samba-client-libs depends on core-libs + ndr-libs (not samba-libs)
- samba-client depends on samba-client-libs (not samba-libs)
- samba-libs does not depend on samba-dc-libs
- libsmbclient depends on samba-client-libs (not samba-libs)
- libwbclient has no samba-*-libs dependencies
- libldb has no samba-*-libs dependencies
test: ./deps-check.sh
framework: shell
require:
- samba-core-libs
- samba-ndr-libs
- samba-client-libs
- samba-libs
- samba-client
- libwbclient
- libsmbclient
- libldb

167
tests/deps-check.sh Executable file
View file

@ -0,0 +1,167 @@
#!/bin/bash
#
# Samba package dependency structure verification
#
# This test ensures that the samba library package dependencies don't regress.
# The expected hierarchy is:
#
# samba-core-libs (no samba-*-libs dependencies)
# ^
# |
# samba-ndr-libs (depends on samba-core-libs only)
# ^
# |
# samba-client-libs (depends on samba-core-libs + samba-ndr-libs)
#
# libwbclient (no samba-*-libs dependencies - only links to libc)
#
# samba-client (depends on samba-client-libs, NOT samba-libs)
# libsmbclient (depends on samba-client-libs, NOT samba-libs)
#
# NOTE: This test checks RESOLVED dependencies, not just explicit Requires.
# A library requirement like 'libfoo.so' is resolved to the package that
# provides it, ensuring we catch indirect dependencies.
#
set -e
ERRORS=0
# Get all packages that a package depends on (resolved)
# This resolves library deps like 'libfoo.so' to actual package names
get_resolved_deps() {
local pkg="$1"
rpm --query --requires "$pkg" 2>/dev/null | while read -r req; do
# Skip rpmlib and config requirements
[[ "$req" =~ ^rpmlib ]] && continue
[[ "$req" =~ ^config ]] && continue
[[ "$req" =~ ^/ ]] && continue
# Get the package that provides this requirement
provider=$(rpm --query --whatprovides "$req" 2>/dev/null | head -1)
if [ -n "$provider" ] && [ "$provider" != "no package provides $req" ]; then
# Extract just the package name (remove version-release.arch)
echo "${provider%%-[0-9]*}"
fi
done | sort -u
}
# Check that a package does NOT depend on packages matching a pattern
# This checks RESOLVED dependencies (what packages actually get pulled in)
check_no_resolved_dep() {
local pkg="$1"
local pattern="$2"
local description="$3"
if ! rpm --query "$pkg" &>/dev/null; then
echo "SKIP: $pkg not installed"
return 0
fi
local bad_deps
# Exclude the package itself from the check
bad_deps=$(get_resolved_deps "$pkg" | grep -v "^${pkg}$" | grep -E "$pattern" || true)
if [ -n "$bad_deps" ]; then
echo "FAIL: $pkg depends on $description"
echo " Found: $bad_deps"
ERRORS=$((ERRORS + 1))
return 1
fi
echo "PASS: $pkg does not depend on $description"
return 0
}
# Check that a package DOES depend on a specific package
check_has_resolved_dep() {
local pkg="$1"
local expected="$2"
if ! rpm --query "$pkg" &>/dev/null; then
echo "SKIP: $pkg not installed"
return 0
fi
if get_resolved_deps "$pkg" | grep -qF "$expected"; then
echo "PASS: $pkg depends on $expected"
return 0
fi
echo "FAIL: $pkg does not depend on $expected"
ERRORS=$((ERRORS + 1))
return 1
}
echo "=== Samba Package Dependency Checks ==="
echo ""
echo "Checking resolved dependencies (library deps resolved to packages)"
echo ""
# 1. samba-core-libs must NOT depend on any samba-*-libs packages
echo "--- samba-core-libs ---"
check_no_resolved_dep samba-core-libs "^samba-.*-libs$" "any samba*-libs package"
echo ""
# 2. samba-ndr-libs must depend on samba-core-libs
# but NOT samba-client-libs or samba-libs
echo "--- samba-ndr-libs ---"
check_has_resolved_dep samba-ndr-libs "samba-core-libs"
check_no_resolved_dep samba-ndr-libs "^samba-client-libs$" "samba-client-libs"
check_no_resolved_dep samba-ndr-libs "^samba-libs$" "samba-libs"
echo ""
# 3. samba-client-libs must depend on samba-core-libs and samba-ndr-libs
# but NOT samba-libs
echo "--- samba-client-libs ---"
check_has_resolved_dep samba-client-libs "samba-core-libs"
check_has_resolved_dep samba-client-libs "samba-ndr-libs"
check_no_resolved_dep samba-client-libs "^samba-libs$" "samba-libs"
echo ""
# 4. libwbclient must NOT depend on any samba-*-libs packages
echo "--- libwbclient ---"
check_no_resolved_dep libwbclient "^samba-.*-libs$" "any samba*-libs package"
echo ""
# 5. samba-client must depend on samba-client-libs but NOT samba-libs
# (client tools should not pull in server libraries)
echo "--- samba-client ---"
check_has_resolved_dep samba-client "samba-client-libs"
check_no_resolved_dep samba-client "^samba-libs$" "samba-libs"
echo ""
# 6. libsmbclient must depend on samba-client-libs but NOT samba-libs
# (SMB client library should not pull in server libraries)
echo "--- libsmbclient ---"
check_has_resolved_dep libsmbclient "samba-client-libs"
check_no_resolved_dep libsmbclient "^samba-libs$" "samba-libs"
echo ""
# 7. libldb must NOT depend on any samba-*-libs packages
# (libldb is a standalone database library)
echo "--- libldb ---"
check_no_resolved_dep libldb "^samba-.*-libs$" "any samba*-libs package"
echo ""
# 8. samba-libs must NOT depend on samba-dc-libs
# (server libraries should not pull in DC-specific libraries)
echo "--- samba-libs ---"
check_no_resolved_dep samba-libs "^samba-dc-libs$" "samba-dc-libs"
echo ""
echo "=== Summary ==="
if [ $ERRORS -gt 0 ]; then
echo "FAILED: $ERRORS dependency check(s) failed"
exit 1
fi
echo "All dependency checks passed"
exit 0

3
usershares.conf.vendor Normal file
View file

@ -0,0 +1,3 @@
[global]
usershare max shares = 100
usershare allow guests = yes