Compare commits

...
Sign in to create a new pull request.

101 commits

Author SHA1 Message Date
Andreas Schneider
58df5ed52b rpminspect: Don't run annocheck on test binaries
[skip changelog]
2026-01-15 17:21:55 +01:00
Andreas Schneider
1f4ee5276f Remove duplicate libdsdb-module-private-samba.so 2026-01-14 16:36:45 +01:00
Andreas Schneider
dca7b1cb88 Move Obsoletes to ndr-package which more or less was common-libs
[skip changelog]
2026-01-14 16:36:45 +01:00
Andreas Schneider
6af45b81d3 Add /usr/bin/nmbd to rpminspect.yml
/usr/sbin/nmbd is a symlink to /usr/bin/nmbd on Fedora.

[skip changelog]
2026-01-14 16:36:45 +01:00
Andreas Schneider
da7dc3fa61 Add missing tmt files
[skip changelog]
2026-01-14 14:30:40 +01:00
Andreas Schneider
dab569ad71 Create a samba-ndr-libs package and drop samba-common-libs
This should help sssd to reduce some of its dependencies.
2026-01-14 13:36:05 +01:00
Andreas Schneider
baa9e6f8c0 Move libraries from samba-client-libs to samba-libs 2026-01-14 12:23:39 +01:00
Andreas Schneider
fcd8668e55 Add gating test to detect dependency changes in samba libraries
[skip changelog]
2026-01-14 11:43:34 +01:00
Andreas Schneider
b8395d93a7 Create a core-libs sub-package to split up library dependencies 2026-01-14 11:42:08 +01:00
Andreas Schneider
4a23ce5b7a Remove unneeded dependency to samba-common-libs 2026-01-14 08:01:17 +01:00
Andreas Schneider
a170fadc8d Do not redeclare cmocka functions
This might cause issues when compiling with newer cmocka versions.
2026-01-12 10:05:53 +01:00
Günther Deschner
8c46386794 Update to Samba 4.23.4
- resolves: #2421764

Guenther
2025-12-12 17:04:18 +01:00
Andreas Schneider
fb14cf225b Add hint that we bundle ngtcp2 if not provided by the system 2025-11-14 19:12:12 +01:00
Andreas Schneider
4af6273371 Update gitignore
[skip changelog]
2025-11-14 19:12:12 +01:00
Günther Deschner
80c8f32211 Update to Samba 4.23.3
- resolves: #2413362

Guenther
2025-11-07 17:15:53 +01:00
Andreas Schneider
efaa5fdc6d Fix --with testsuite
[skip changelog]
2025-10-22 13:42:11 +02:00
Günther Deschner
c05bf06122 Update to Samba 4.23.2
- resolves: rhbz#2404204
- resolves: rhbz#2391698 - Security fix for CVE-2025-9640
- resolves: rhbz#2394377 - Security fix for CVE-2025-10230

Guenther
2025-10-17 20:41:14 +02:00
Günther Deschner
4e3699d8b5 Update to Samba 4.23.1
- resolves: #2399755

Guenther
2025-09-29 14:16:25 +02:00
Alexander Bokovoy
07953f426e Fix DLZ crash on unconfigured Samba AD system and rebuild against Python 3.14.0rc3
- Resolves: rhbz#2396621
 - Resolves: rhbz#2397242

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2025-09-23 11:42:46 +03:00
Andreas Schneider
b40a7310d3 Build with systemd-userdb support 2025-09-15 10:43:55 +02:00
Andreas Schneider
54c3bbd3f1 Fix building ctdb with PCP 7.0.0 2025-09-12 18:04:02 +02:00
Andreas Schneider
0bc0416ee8 Remove smb3 unix extensions = yes from smb.conf
This is enabled by default now.
2025-09-12 15:03:30 +02:00
Andreas Schneider
86832ccc39 Update to version 4.23.0
- resolves: rhbz#2394791
2025-09-12 14:55:35 +02:00
Günther Deschner
e0762b936f Update to Samba 4.23.0rc4
- resolves: #2393434

Guenther
2025-09-10 10:28:22 +02:00
Alexander Bokovoy
beb6a11089 Restore PCP support
- resolves: rhbz#2392879

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2025-09-04 09:47:08 +03:00
Alexander Bokovoy
5a96c90427 Disable PCP 7.0.0 support
PCP 7.0.0 API has changed, needs more work in ctdb

https://bugzilla.samba.org/show_bug.cgi?id=15904

- resolves: rhbz#2392879

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2025-09-03 16:28:38 +03:00
Alexander Bokovoy
a6119e2bb3 Fix FreeIPA trust to AD
- resolves: rhbz#2392626

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2025-09-03 15:03:44 +03:00
Günther Deschner
83273a97b1 Update to Samba 4.23.0rc3
- resolves: #2387090

Guenther
2025-08-29 23:51:02 +02:00
Günther Deschner
e6a975e422 Update to Samba 4.23.0rc2
- resolves: #2387090

Guenther
2025-08-22 22:06:30 +02:00
Python Maint
c108db5e55 Rebuilt for Python 3.14.0rc2 bytecode 2025-08-18 13:57:35 +02:00
Yaakov Selkowitz
c2bf86b8d2 Move trust_notify module to -dc subpackage
This module is not built in ELN, resulting in a file not found error when
packaging libldb.  Its build conditions are the same as the dns_notify
module already in -dc.
2025-08-17 23:07:18 -04:00
Günther Deschner
052edc4ab6 Update to Samba 4.23.0rc1
- resolves: #2387090

Guenther
2025-08-12 22:09:33 +02:00
František Zatloukal
ad5439e191 Rebuilt for icu 77.1 2025-08-06 09:57:46 +02:00
Fedora Release Engineering
5c93354123 Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild 2025-07-25 17:53:14 +00:00
Günther Deschner
b40f280be5 Fix get_kdc_ip_string handling for secondary KDCs
- resolves: bzso#15881

Guenther
2025-07-10 21:49:52 +02:00
Günther Deschner
d5056e867a Update to Samba 4.22.3
- resolves: #2376873

Guenther
2025-07-08 00:50:43 +02:00
Andreas Schneider
060552411c smb.conf: Remove the '@' for NIX groups, we removed NIS support 2025-06-23 10:14:07 +02:00
Pavel Filipenský
ac5f4a1f4b Move libreplace-private-samba.so to samba-common-libs
Fix this rpmdeps report:

VERIFY Subpackage libldb on x86_64 carries
'Requires: libreplace-private-samba.so()(64bit)' which comes from
subpackage samba-client-libs but does not carry an explicit package
version requirement. Please add 'Requires: samba-client-libs =
%{version}-%{release}' to the spec file to avoid the need to test
interoperability between various combinations of old and new
subpackages.
2025-06-10 14:16:16 +02:00
Pavel Filipenský
64f8b2a484 Install /run/ctdb
Fix following report:

 rpm --verify ctdb-0:4.22.2-3.el9.x86_64

 .M.......  g /run/ctdb

 M Mode differs (includes permissions and file type)
2025-06-10 14:16:16 +02:00
Python Maint
e9a8536578 Rebuilt for Python 3.14 2025-06-06 09:34:20 +02:00
Günther Deschner
eb8dac413e Update to Samba 4.22.2
- resolves: rhbz#2370468
- resolves: rhbz#2370455 - Security fix for CVE-2025-0620

Guenther
2025-06-05 20:34:02 +02:00
Python Maint
b8a889b232 Rebuilt for Python 3.14 2025-06-05 00:08:08 +02:00
Günther Deschner
40bd3a26e8 Update to Samba 4.22.1
- resolves: rhbz#2360776

Guenther
2025-04-18 02:26:37 +02:00
Günther Deschner
b508f2ed7a Turn on SMB 3.1.1 Unix Extensions in vendor smb.conf as well...
Guenther
2025-04-10 09:51:37 +02:00
Günther Deschner
0cb9860a40 Turn on SMB 3.1.1 Unix Extensions in default smb.conf
Guenther
2025-03-07 11:06:39 +01:00
Günther Deschner
30ff8554df Update to Samba 4.22.0
- resolves: rhbz#2350342

Guenther
2025-03-06 16:15:59 +01:00
Andreas Schneider
21e22997d4 Revert "Set samba-tools to noarch"
This reverts commit f00c21e2a8.

We can't set it to noarch as koji complains that "Requires: lmdb" is
present on some arches and not on others.
2025-03-04 14:01:29 +01:00
Andreas Schneider
417731acd0 Use spaces instead of tabs for krb5-printing scripts
Removes rpmlint warnings
2025-03-04 11:06:07 +01:00
Andreas Schneider
8ee5558015 Set ctdb-etcd-mutex to noarch
This only includes python scripts.
2025-03-04 11:03:58 +01:00
Andreas Schneider
e4ac2d5dcb Set samba-gpupdate to noarch
This only includes python scripts.
2025-03-04 11:02:47 +01:00
Andreas Schneider
f00c21e2a8 Set samba-tools to noarch
This only include a python scripts.
2025-03-04 11:01:51 +01:00
Andreas Schneider
e1991f29ec Set samba-usershare to noarch
It only includes configuration files.
2025-03-04 11:00:54 +01:00
Andreas Schneider
1b2e68adff Add missing /run/ctdb dir to files list 2025-03-04 11:00:46 +01:00
Andreas Schneider
7ebad9bdd1 Set version for bundled libreplace 2025-03-04 11:00:46 +01:00
Andrea Bolognani
947b0b72d5 Re-enable mold on riscv64
mold didn't build successfully on riscv64 back when riscv64
support was added to samba, but that has changed since and
today there is no longer any reason not to use it.

Signed-off-by: Andrea Bolognani <abologna@redhat.com>
2025-03-03 14:04:08 +01:00
David Abdurachmanov
6744eb181d Enable lmdb on riscv64
Solves configuration error:

[..]
Checking for a 64-bit host to support lmdb          : ok
Checking for lmdb >= 0.9.16                         : not found
Checking for header lmdb.h                          : no
Checking for lmdb >= 0.9.16 via header check        : not found
Samba AD DC and --enable-selftest requires lmdb 0.9.16 or later
[..]

Signed-off-by: David Abdurachmanov <davidlt@rivosinc.com>
2025-03-03 14:04:08 +01:00
Günther Deschner
c295775181 Update to Samba 4.22.0rc4
- resolves: rhbz#2348758

Guenther
2025-02-27 20:00:34 +01:00
Günther Deschner
c4883ac1e7 Update to Samba 4.22.0rc3
- resolves: rhbz#2346803

Guenther
2025-02-20 18:39:08 +01:00
Andreas Schneider
4e6ca9ecfb Fix libldb built with '--with includelibs' 2025-02-18 14:45:05 +01:00
Andreas Schneider
036c40ef5e Fix the '--with includelibs' build 2025-02-14 19:05:42 +01:00
Andreas Schneider
314544c636 Add LICENSE file of libldb 2025-02-14 14:30:24 +01:00
Andreas Schneider
cb85d85e0f Make %bcond switches easier to understand
This also removes support for building on rhel8.
2025-02-14 12:02:02 +01:00
Günther Deschner
67e7277c75 Update to Samba 4.22.0rc2
- resolves: rhbz#2345547

Guenther
2025-02-13 23:54:53 +01:00
Günther Deschner
f24bbdaf78 Update to version 4.22.0rc1
- resolves: rhbz#2344189

Guenther
2025-02-09 00:59:35 +01:00
Björn Esser
e52328b755
Add explicit BR: libxcrypt-devel
Signed-off-by: Björn Esser <besser82@fedoraproject.org>
2025-02-01 19:57:20 +01:00
Andreas Schneider
7bc49d20ad Fix building with gcc 15 2025-01-22 09:03:43 +01:00
Andreas Schneider
c6899c34b0 Fix stack use after return in new crypt module 2025-01-22 09:00:27 +01:00
Fedora Release Engineering
09d4509590 Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild 2025-01-19 09:54:56 +00:00
Pavel Filipenský
99bcb0cab8 Remove 'Requires: python3-crypt-r' also from samba-tools 2025-01-07 14:28:18 +01:00
Pavel Filipenský
a7c8b51b0f Use upstream Patch instead of python3-crypt-r 2025-01-07 13:52:23 +01:00
Pavel Filipenský
d70953a5ed Update to version 4.21.3
- resolves: rhbz#2335911
2025-01-07 10:42:42 +01:00
Pete Walter
6b05011701 Rebuild for ICU 76 2024-12-08 22:44:21 +00:00
Andreas Schneider
b0f6e67bbc Add missing SAMBA_DCERPCD_DONT_LOG_STDOUT=1 for the testsuite
[skip changelog]
2024-11-29 09:05:13 +01:00
Andreas Schneider
a5688d299c Rework 'with testsuite'
In case we run the testsuite, the %install part will be skipped. Without
the testsuite, the %check section will be skipped.

[skip changelog]
2024-11-29 09:05:10 +01:00
Andreas Schneider
1af6d0aa01 Add missing BuildRequires for running the testsuite
[skip changelog]
2024-11-29 09:05:08 +01:00
Andreas Schneider
e2b080c313 Add python3-crypt-r as requirement for samba-tool 2024-11-26 14:52:12 +01:00
Günther Deschner
438b8a6e95 Update to version 4.21.2
- resolves: rhbz#2328717
2024-11-25 20:16:18 +01:00
Anoop C S
f654bad3bb Remove unused macro samba_requires_eq
This was previously used to force the installation of a matching
libldb version from build time. With libldb now versioned along
with Samba as a public library its usage got removed in d0472882
but the definition remained as a left over.

Signed-off-by: Anoop C S <anoopcs@samba.org>
2024-11-13 11:40:56 +05:30
Pavel Filipenský
667e752f95 Add always to samba-devel: Requires: samba-dc-libs 2024-10-25 19:42:52 +02:00
Richard W.M. Jones
4ae2996e49 Rebuild for Jansson 2.14 (https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org/thread/3PYINSQGKQ4BB25NQUI2A2UCGGLAG5ND/) 2024-10-22 13:42:50 +01:00
Pavel Filipenský
a98899c6d2 Fix samba 4.20 -> 4.21 upgrade for the removed python3-samba-devel 2024-10-22 11:02:58 +02:00
Pavel Filipenský
1caea566a4 Revert "Re-enable linking with mold on i686"
This reverts commit ac58d580e8.

This is to address debuginfo issue reported by rpminspect for i686:
https://bugzilla.redhat.com/show_bug.cgi?id=2318727
2024-10-17 11:39:31 +02:00
Pavel Filipenský
6d5708b5e4 Fix even more rpminspect warnings 2024-10-16 11:32:58 +02:00
Pavel Filipenský
682be9e398 Fix some more rpminspect warnings 2024-10-15 13:20:10 +02:00
Andreas Schneider
a55c2e0445 Fix several rpminspect warnings 2024-10-15 11:58:12 +02:00
Andreas Schneider
16e2ea30c4 rpminspect: Disable inspection of disttag
rpminspect just reads the file an doesn't expand it so it doesn't
understand:

Release: %{samba_release}

[skip changelog]
2024-10-15 11:58:07 +02:00
Pavel Filipenský
2535a64d34 Update to version 4.21.1
- resolves: rhbz#2318518
2024-10-14 15:38:28 +02:00
Andreas Schneider
92d190c9b6 Don't use RTLD_DEEPBIND by default in libldb
- resolves: rhbz#2278016
2024-10-01 14:11:48 +02:00
Pavel Filipenský
8f40e555ff Build with ceph again for ppc64le
This is fixed https://gcc.gnu.org/bugzilla/show_bug.cgi?id=104172
in gcc >= 11.3. It is ok to enable for rhel-9, rhel-10 and f41:

gcc-11.5.0-2.el9
gcc-14.2.1-2.el10
gcc-14.2.1-3.fc41
2024-09-27 13:59:42 +02:00
Yaakov Selkowitz
a4001d23ea Always include libsamba-policy and libsamba-net-private-samba
As of 4.21, these were converted to regular C libraries to which their
respective Python modules depend:

d11b281aef
829b52f99d
2024-09-25 18:11:56 -04:00
Yaakov Selkowitz
6ad6694791 Fix ELN build
libsamba-policy is only built with the AD DC, but the LDB LMDB components
should be built regardless:

https://gitlab.com/samba-team/samba/-/merge_requests/3807
2024-09-24 10:34:22 -04:00
Andreas Schneider
b16ff1f961 Add cert directories to samba-common
Those are created by gpupdate and we need to have them packaged that
selinux can label them correctly.
2024-09-23 12:58:24 +02:00
Alexander Bokovoy
19fdf21ce6 Fix Samba integration with FreeIPA
- resolves: rhbz#2309199

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2024-09-13 16:29:53 +03:00
Günther Deschner
63dc1a2f19 Update required tdb version
- related: rhbz#2309153
2024-09-03 00:19:59 +02:00
Günther Deschner
b363a4cfec Update to version 4.21.0
- resolves: rhbz#2309153
2024-09-02 15:25:28 +02:00
Günther Deschner
11eed52070 Update to version 4.21.0rc4
- resolves: rhbz#2300469
2024-08-28 13:55:38 +02:00
Andreas Schneider
4c2a193110 Fix ldb requires and provides
- related: rhbz#230046
2024-08-21 14:55:13 +02:00
Andreas Schneider
bcb3974e31 Fix manpages for libldb
related: rhbz#230046
2024-08-21 09:29:46 +02:00
Andreas Schneider
49d714c029 Update to version 4.21.0rc3
- related: rhbz#230046
2024-08-21 08:02:37 +02:00
Andreas Schneider
22760e8157 Remove also python-ldb-devel-common
- related: rhbz#230046

This was only used internally.
2024-08-21 07:51:00 +02:00
Günther Deschner
d04728829d Update to Samba 4.21.0rc2
- Package libldb a public library
- resolves: #2300469

Pair-Programmed-With: Andreas Schneider <asn@redhat.com>
2024-08-20 18:33:39 +02:00
12 changed files with 1030 additions and 1209 deletions

1
.fmf/version Normal file
View file

@ -0,0 +1 @@
1

2
.gitignore vendored
View file

@ -1,2 +1,4 @@
/samba-*.tar.xz
/samba-*.tar.asc
/*.rpm
/results_samba

6
gating.yaml Normal file
View file

@ -0,0 +1,6 @@
--- !Policy
product_versions:
- fedora-*
decision_context: bodhi_update_push_stable
rules:
- !PassingTestCaseRule {test_case_name: fedora-ci.koji-build.tier0.functional}

4
plans.fmf Normal file
View file

@ -0,0 +1,4 @@
discover:
how: fmf
execute:
how: tmt

View file

@ -1,6 +1,10 @@
---
inspections:
disttag: off
badfuncs:
ignore:
- /usr/bin/nmbd
- /usr/bin/nmblookup
- /usr/bin/smbtorture
- /usr/lib*/libndr.so.*
@ -22,3 +26,10 @@ abidiff:
debuginfo:
ignore:
- /usr/lib*/libdcerpc-samr.so.*
annocheck:
ignore:
- /usr/bin/gentest
- /usr/bin/locktest
- /usr/bin/masktest
- /usr/bin/smbtorture

View file

@ -0,0 +1,38 @@
From b1ec803f420b2c6d3c5c83d70c6875a7f36b15fc Mon Sep 17 00:00:00 2001
From: Andreas Schneider <asn@samba.org>
Date: Fri, 21 Nov 2025 15:33:32 +0100
Subject: [PATCH] s4:dsdb: Do not declare cm_print_error()
This is part of the cmocka.h header file.
Signed-off-by: Andreas Schneider <asn@samba.org>
Reviewed-by: Martin Schwenke <martin@meltin.net>
Reviewed-by: Volker Lendecke <vl@samba.org>
Autobuild-User(master): Volker Lendecke <vl@samba.org>
Autobuild-Date(master): Mon Nov 24 11:28:08 UTC 2025 on atb-devel-224
(cherry picked from commit 5a981663e4f677042ba80191770100aecff2120a)
---
source4/dsdb/samdb/ldb_modules/tests/test_group_audit.c | 5 -----
1 file changed, 5 deletions(-)
diff --git a/source4/dsdb/samdb/ldb_modules/tests/test_group_audit.c b/source4/dsdb/samdb/ldb_modules/tests/test_group_audit.c
index f7075f3485e..12c464b49c7 100644
--- a/source4/dsdb/samdb/ldb_modules/tests/test_group_audit.c
+++ b/source4/dsdb/samdb/ldb_modules/tests/test_group_audit.c
@@ -103,11 +103,6 @@ void audit_message_send(
#define check_group_change_message(m, u, a, e) \
_check_group_change_message(m, u, a, e, __FILE__, __LINE__);
-/*
- * declare the internal cmocka cm_print_error so that we can output messages
- * in sub unit format
- */
-void cm_print_error(const char * const format, ...);
/*
* Validate a group change JSON audit message
--
2.52.0

1972
samba.spec

File diff suppressed because it is too large Load diff

View file

@ -269,6 +269,13 @@
; map system = no
; store dos attributes = yes
# Turn on SMB 3.1.1 Unix Extensions by default
#
# Note: The Linux Kernel SMB3 client will negotiate unix extensions by default,
# find more info in man mount.smb3(8). Linux 6.13 will finally support special
# filetypes and symlink handling.
smb3 unix extensions = yes
#============================ Share Definitions ==============================

View file

@ -38,7 +38,8 @@
[print$]
comment = Printer Drivers
path = /var/lib/samba/drivers
write list = @printadmin root
force group = @printadmin
# printadmin is a local group
write list = printadmin root
force group = printadmin
create mask = 0664
directory mask = 0775

View file

@ -1,2 +1,2 @@
SHA512 (samba-4.20.4.tar.xz) = 390805d006c380e83f0a0f6f0c00cd6605c32c937f4cf11e7ac5b177abd4538b0be40c505d72c500855f28a625f60aaa007c4466c316c3f93bfb5baa583f384f
SHA512 (samba-4.20.4.tar.asc) = ff8369bf307e56fe842a101b05dcbf382779a3812763e67b573449412195777fce25864ca4e0d89c126bc46cf3a2d359c5d5bda68b60af8849cd91f9d418ee98
SHA512 (samba-4.23.4.tar.xz) = 58979aa8a83e8210918f4f1adbcadff329e57a9cd25d7aba98d18f54a2e790a7ef3cc6b9fb3303d492d33d67f4a135849a419c95644d14e53a39654736d486ac
SHA512 (samba-4.23.4.tar.asc) = 0981ce6a43202953cdc7ceae77fa0e3b4ab853991430dde4df6daa163984de6c7ca3f3a3037376659d3bdaedcc108cdd7a77ce0ac24d0a1add56c7103fca7dce

22
tests/deps-check.fmf Normal file
View file

@ -0,0 +1,22 @@
summary: Check samba package dependency structure
description: |
Verify that samba library packages maintain correct dependency hierarchy:
- samba-core-libs has no samba-*-libs dependencies
- samba-ndr-libs depends on samba-core-libs (not samba-client-libs or samba-libs)
- samba-client-libs depends on core-libs + ndr-libs (not samba-libs)
- samba-client depends on samba-client-libs (not samba-libs)
- samba-libs does not depend on samba-dc-libs
- libsmbclient depends on samba-client-libs (not samba-libs)
- libwbclient has no samba-*-libs dependencies
- libldb has no samba-*-libs dependencies
test: ./deps-check.sh
framework: shell
require:
- samba-core-libs
- samba-ndr-libs
- samba-client-libs
- samba-libs
- samba-client
- libwbclient
- libsmbclient
- libldb

167
tests/deps-check.sh Executable file
View file

@ -0,0 +1,167 @@
#!/bin/bash
#
# Samba package dependency structure verification
#
# This test ensures that the samba library package dependencies don't regress.
# The expected hierarchy is:
#
# samba-core-libs (no samba-*-libs dependencies)
# ^
# |
# samba-ndr-libs (depends on samba-core-libs only)
# ^
# |
# samba-client-libs (depends on samba-core-libs + samba-ndr-libs)
#
# libwbclient (no samba-*-libs dependencies - only links to libc)
#
# samba-client (depends on samba-client-libs, NOT samba-libs)
# libsmbclient (depends on samba-client-libs, NOT samba-libs)
#
# NOTE: This test checks RESOLVED dependencies, not just explicit Requires.
# A library requirement like 'libfoo.so' is resolved to the package that
# provides it, ensuring we catch indirect dependencies.
#
set -e
ERRORS=0
# Get all packages that a package depends on (resolved)
# This resolves library deps like 'libfoo.so' to actual package names
get_resolved_deps() {
local pkg="$1"
rpm --query --requires "$pkg" 2>/dev/null | while read -r req; do
# Skip rpmlib and config requirements
[[ "$req" =~ ^rpmlib ]] && continue
[[ "$req" =~ ^config ]] && continue
[[ "$req" =~ ^/ ]] && continue
# Get the package that provides this requirement
provider=$(rpm --query --whatprovides "$req" 2>/dev/null | head -1)
if [ -n "$provider" ] && [ "$provider" != "no package provides $req" ]; then
# Extract just the package name (remove version-release.arch)
echo "${provider%%-[0-9]*}"
fi
done | sort -u
}
# Check that a package does NOT depend on packages matching a pattern
# This checks RESOLVED dependencies (what packages actually get pulled in)
check_no_resolved_dep() {
local pkg="$1"
local pattern="$2"
local description="$3"
if ! rpm --query "$pkg" &>/dev/null; then
echo "SKIP: $pkg not installed"
return 0
fi
local bad_deps
# Exclude the package itself from the check
bad_deps=$(get_resolved_deps "$pkg" | grep -v "^${pkg}$" | grep -E "$pattern" || true)
if [ -n "$bad_deps" ]; then
echo "FAIL: $pkg depends on $description"
echo " Found: $bad_deps"
ERRORS=$((ERRORS + 1))
return 1
fi
echo "PASS: $pkg does not depend on $description"
return 0
}
# Check that a package DOES depend on a specific package
check_has_resolved_dep() {
local pkg="$1"
local expected="$2"
if ! rpm --query "$pkg" &>/dev/null; then
echo "SKIP: $pkg not installed"
return 0
fi
if get_resolved_deps "$pkg" | grep -qF "$expected"; then
echo "PASS: $pkg depends on $expected"
return 0
fi
echo "FAIL: $pkg does not depend on $expected"
ERRORS=$((ERRORS + 1))
return 1
}
echo "=== Samba Package Dependency Checks ==="
echo ""
echo "Checking resolved dependencies (library deps resolved to packages)"
echo ""
# 1. samba-core-libs must NOT depend on any samba-*-libs packages
echo "--- samba-core-libs ---"
check_no_resolved_dep samba-core-libs "^samba-.*-libs$" "any samba*-libs package"
echo ""
# 2. samba-ndr-libs must depend on samba-core-libs
# but NOT samba-client-libs or samba-libs
echo "--- samba-ndr-libs ---"
check_has_resolved_dep samba-ndr-libs "samba-core-libs"
check_no_resolved_dep samba-ndr-libs "^samba-client-libs$" "samba-client-libs"
check_no_resolved_dep samba-ndr-libs "^samba-libs$" "samba-libs"
echo ""
# 3. samba-client-libs must depend on samba-core-libs and samba-ndr-libs
# but NOT samba-libs
echo "--- samba-client-libs ---"
check_has_resolved_dep samba-client-libs "samba-core-libs"
check_has_resolved_dep samba-client-libs "samba-ndr-libs"
check_no_resolved_dep samba-client-libs "^samba-libs$" "samba-libs"
echo ""
# 4. libwbclient must NOT depend on any samba-*-libs packages
echo "--- libwbclient ---"
check_no_resolved_dep libwbclient "^samba-.*-libs$" "any samba*-libs package"
echo ""
# 5. samba-client must depend on samba-client-libs but NOT samba-libs
# (client tools should not pull in server libraries)
echo "--- samba-client ---"
check_has_resolved_dep samba-client "samba-client-libs"
check_no_resolved_dep samba-client "^samba-libs$" "samba-libs"
echo ""
# 6. libsmbclient must depend on samba-client-libs but NOT samba-libs
# (SMB client library should not pull in server libraries)
echo "--- libsmbclient ---"
check_has_resolved_dep libsmbclient "samba-client-libs"
check_no_resolved_dep libsmbclient "^samba-libs$" "samba-libs"
echo ""
# 7. libldb must NOT depend on any samba-*-libs packages
# (libldb is a standalone database library)
echo "--- libldb ---"
check_no_resolved_dep libldb "^samba-.*-libs$" "any samba*-libs package"
echo ""
# 8. samba-libs must NOT depend on samba-dc-libs
# (server libraries should not pull in DC-specific libraries)
echo "--- samba-libs ---"
check_no_resolved_dep samba-libs "^samba-dc-libs$" "samba-dc-libs"
echo ""
echo "=== Summary ==="
if [ $ERRORS -gt 0 ]; then
echo "FAILED: $ERRORS dependency check(s) failed"
exit 1
fi
echo "All dependency checks passed"
exit 0