Accepted systemd 234-2~bpo9+1 (source amd64) into stretch-backports, stretch-backports

Hash: SHA256

Format: 1.8
Date: Tue, 08 Aug 2017 23:44:17 +0200
Source: systemd
Binary: systemd systemd-sysv systemd-container systemd-journal-remote systemd-coredump systemd-tests libpam-systemd libnss-myhostname libnss-mymachines libnss-resolve libnss-systemd libsystemd0 libsystemd-dev udev libudev1 libudev-dev udev-udeb libudev1-udeb
Architecture: source amd64
Version: 234-2~bpo9+1
Distribution: stretch-backports
Urgency: medium
Maintainer: Debian systemd Maintainers <pkg-systemd-maintainers@lists.alioth.debian.org>
Changed-By: Michael Biebl <biebl@debian.org>
 libnss-myhostname - nss module providing fallback resolution for the current hostname
 libnss-mymachines - nss module to resolve hostnames for local container instances
 libnss-resolve - nss module to resolve names via systemd-resolved
 libnss-systemd - nss module providing dynamic user and group name resolution
 libpam-systemd - system and service manager - PAM module
 libsystemd-dev - systemd utility library - development files
 libsystemd0 - systemd utility library
 libudev-dev - libudev development files
 libudev1   - libudev shared library
 libudev1-udeb - libudev shared library (udeb)
 systemd    - system and service manager
 systemd-container - systemd container/nspawn tools
 systemd-coredump - tools for storing and retrieving coredumps
 systemd-journal-remote - tools for sending and receiving remote journal logs
 systemd-sysv - system and service manager - SysV links
 systemd-tests - tests for systemd
 udev       - /dev/ and hotplug management daemon
 udev-udeb  - /dev/ and hotplug management daemon (udeb)
Closes: 758279 791944 805785 824532 835810 837893 839291 845442 849316 851438 851933 856306 856337 857270 858014 859152 859941 861157 861158 861171 861769 862062 862292 863111 863277 865449 866147 866313 866579 868002 868695
 systemd (234-2~bpo9+1) stretch-backports; urgency=medium
   * Rebuild for stretch-backports.
   * Switch debian-branch to stretch-backports
   * Don't rely on the debhelper meson build system support.
     This requires a newer debhelper which is not availabe in stretch (yet).
 systemd (234-2) unstable; urgency=medium
   [ Martin Pitt ]
   * udev README.Debian: Fix name of example *.link file
   [ Felipe Sateler ]
   * test-condition: Don't assume that all non-root users are normal users.
     Automated builders may run under a dedicated system user, and this test
     would fail that.
   [ Michael Biebl ]
   * Revert "units: Tell login to preserve environment"
     Environment=LANG= LANGUAGE= LC_CTYPE= ... as used in the getty units is
     not unsetting the variables but instead sets it to an empty var. Passing
     that environment to login messes up the system locale settings and
     breaks programs like gpg-agent.
     (Closes: #868695)
 systemd (234-1) unstable; urgency=medium
   [ Michael Biebl ]
   * New upstream version 234
     - tmpfiles: Create /var/log/lastlog if it does not exist.
       (Closes: #866313)
     - network: Bridge vlan without PVID. (Closes: #859941)
   * Rebase patches
   * Switch build system from autotools to meson.
     Update the Build-Depends accordingly.
   * Update fsckd patch for meson
   * udev autopkgtest: no longer install test-udev binary manually.
     This is now done by the upstream build system.
   * Update symbols file for libsystemd0
   * Update lintian override for systemd-tests.
     Upstream now installs manual and unsafe tests in subdirectories of
     /usr/lib/systemd/tests/, so ignore those as well.
   * Bump Standards-Version to 4.0.0
   * Change priority of libnss-* packages from extra to optional.
   * Use UTF-8 locale when building the package.
     Otherwise meson will be pretty unhappy when trying to process files with
     unicode characters. Use C.UTF-8 as this locale is pretty much guaranteed
     to be available everywhere.
   * Mark test-timesync as manual.
     The test tries to setup inotify watches for /run/systemd/netif/links
     which fails in a buildd environment where systemd is not active.
   * Do not link udev against libsystemd-shared.
     We ship udev in a separate binary package, so can't use
     libsystemd-shared, which is part of the systemd binary package.
   * Avoid requiring a "kvm" system group.
     This group is not universally available and as a result generates a
     warning during boot. As kvm is only really useful if the qemu package is
     installed and this package already takes care of setting up the proper
     permissions for /dev/kvm, drop this rule from 50-udev-default.rules.
   [ Martin Pitt ]
   * udev README.Debian: Update transitional rules and mention *.link files.
     - 01-mac-for-usb.link got replaced with 73-usb-net-by-mac.rules
     - /etc/systemd/network/50-virtio-kernel-names.link is an upgrade
       transition for VMs with virtio
     - Describe *.link files as a simpler/less error prone (but also less
       flexible) way of customizing interface names. (Closes: #868002)
 systemd (233-10) unstable; urgency=medium
   [ Martin Pitt ]
   * Adjust var-lib-machines.mount target.
     Upstream PR #6095 changed the location to
     {remote-fs,machines}.target.wants, so just install all available ones.
   [ Dimitri John Ledkov ]
   * Fix out-of-bounds write in systemd-resolved.
     CVE-2017-9445 (Closes: #866147, LP: #1695546)
   [ Michael Biebl ]
   * Be truly quiet in systemctl -q is-enabled (Closes: #866579)
   * Improve RLIMIT_NOFILE handling.
     Use /proc/sys/fs/nr_open to find the current limit of open files
     compiled into the kernel instead of using a hard-coded value of 65536
     for RLIMIT_NOFILE. (Closes: #865449)
   [ Nicolas Braud-Santoni ]
   * debian/extra/rules: Use updated U2F ruleset.
     This ruleset comes from Yubico's libu2f-host. (Closes: #824532)
 systemd (233-9) unstable; urgency=medium
   * hwdb: Use path_join() to generate the hwdb_bin path.
     This ensures /lib/udev/hwdb.bin gets the correct SELinux context. Having
     double slashes in the path makes selabel_lookup_raw() return the wrong
     context. (Closes: #851933)
   * Drop no longer needed Breaks against usb-modeswitch
   * Drop Breaks for packages shipping rcS init scripts.
     This transition was completed in stretch.
 systemd (233-8) experimental; urgency=medium
   * Bump debhelper compatibility level to 10
   * Drop versioned Build-Depends on dpkg-dev.
     It's no longer necessary as even Jessie ships a new enough version.
   * timesyncd: don't use compiled-in list if FallbackNTP has been configured
     explicitly (Closes: #861769)
   * resolved: fix null pointer p->question dereferencing.
     This fixes a bug which allowed a remote DoS (daemon crash) via a crafted
     DNS response with an empty question section.
     Fixes: CVE-2017-9217 (Closes: #863277)
 systemd (233-7) experimental; urgency=medium
   [ Michael Biebl ]
   * basic/journal-importer: Fix unaligned access in get_data_size()
     (Closes: #862062)
   * ima: Ensure policy exists before asking the kernel to load it
     (Closes: #863111)
   * Add Depends: procps to systemd.
     It's required by /usr/lib/systemd/user/systemd-exit.service which calls
     /bin/kill to stop the systemd --user instance. (Closes: #862292)
   * service: Serialize information about currently executing command
     (Closes: #861157)
   * seccomp: Add clone syscall definitions for mips (Closes: #861171)
   [ Dimitri John Ledkov ]
   * ubuntu: disable dnssec on any ubuntu releases (LP: #1690605)
   [ Felipe Sateler ]
   * Specify nobody user and group.
     Otherwise nss-systemd will translate to group 'nobody', which doesn't
     exist on debian systems.
 systemd (233-6) experimental; urgency=medium
   [ Felipe Sateler ]
   * Backport upstream PR #5531.
     This delays opening the mdns and llmnr sockets until a network has enabled
     them. This silences annoying messages when networkd receives such packets
     without expecting them: Got mDNS UDP packet on unknown scope.
   [ Martin Pitt ]
   * resolved: Disable DNSSEC by default on stretch and zesty.
     Both Debian stretch and Ubuntu zesty are close to releasing, switch to
     DNSSEC=off by default for those. Users can still turn it back on with
     DNSSEC=allow-downgrade (or even "yes").
   [ Michael Biebl ]
   * Add Conflicts against hal.
     Since v183, udev no longer supports RUN+="socket:". This feature is
     still used by hal, but now generates vast amounts of errors in the
     journal. Thus force the removal of hal by adding a Conflicts to the udev
     package. This is safe, as hal is long dead and no longer useful.
   * Drop systemd-ui Suggests
     systemd-ui is unmaintained upstream and not particularly useful anymore.
   * journal: fix up syslog facility when forwarding native messages.
     Native journal messages (_TRANSPORT=journal) typically don't have a
     syslog facility attached to it. As a result when forwarding the
     messages to syslog they ended up with facility 0 (LOG_KERN).
     Apply syslog_fixup_facility() so we use LOG_USER instead.
     (Closes: #837893)
   * Split upstream tests into systemd-tests binary package (Closes: #859152)
   * Get PACKAGE_VERSION from config.h.
     This also works with meson and is not autotools specific.
   [ Sjoerd Simons ]
   * init-functions Only call daemon-reload when planning to redirect
     systemctl daemon-reload is a quite a heavy operation, it will re-parse
     all configuration and re-run all generators. This should only be done
     when strictly needed. (Closes: #861158)
 systemd (233-5) experimental; urgency=medium
   * Do not throw a warning in emergency and rescue mode if plymouth is not
     Ideally, plymouth should only be referenced via dependencies, not
     ExecStartPre. This at least avoids the confusing error message on
     minimal installations that do not carry plymouth.
   * rules: Allow SPARC vdisk devices when identifying CD drives
     (Closes: #858014)
 systemd (233-4) experimental; urgency=medium
   [ Martin Pitt ]
   * udev autopkgtest: Drop obsolete sys.tar.xz fallback.
     This was only necessary for supporting 232 as well.
   * root-unittest: Drop obsolete FIXME comment.
   * Add libpolkit-gobject-1-dev build dep for polkit version detection.
   * Move systemd.link(5) to udev package.
     .link files are being handled by udev, so it should ship the
     corresponding manpage. Bump Breaks/Replaces accordingly. (Closes: #857270)
   [ Michael Biebl ]
   * Restart journald on upgrades (Closes: #851438)
   * Avoid strict DM API versioning.
     Compiling against the dm-ioctl.h header as provided by the Linux kernel
     will embed the DM interface version number. Running an older kernel can
     lead to errors on shutdown when trying to detach DM devices.
     As a workaround, build against a local copy of dm-ioctl.h based on 3.13,
     which is the minimum required version to support DM_DEFERRED_REMOVE.
     (Closes: #856337)
 systemd (233-3) experimental; urgency=medium
   [ Michael Biebl ]
   * Install D-Bus policy files in /usr
   * Drop no longer needed maintainer scripts migration code and simplify
     various version checks
   * Fix location of installed tests
   * Override package-name-doesnt-match-sonames lintian warning for libnss-*
   * Don't ship any symlinks in /etc/systemd/system.
     Those should be created dynamically via "systemctl enable".
   [ Martin Pitt ]
   * root-unittests autopkgtest: Skip test-udev.
     It has its own autopkgtest and needs some special preparation. At some
     point that should be merged into root-unittests, but let's quickfix this
     to unbreak upstream CI.
 systemd (233-2) experimental; urgency=medium
   * test: skip instead of fail if crypto kmods are not available.
     The Debian buildds have module loading disabled, thus AF_ALG sockets are
     not available during build. Skip the tests that cover those (khash and
     id128) instead of failing them in this case.
 systemd (233-1) experimental; urgency=medium
   [ Martin Pitt ]
   * New upstream release 233:
     - udev: Remove /run/udev/control on stop to avoid sendsigs to kill
       udevd. (Closes: #791944)
     - nspawn: Handle container directory symlinks. (Closes: #805785)
     - Fix mount units to not become "active" when NFS mounts time out.
       (Closes: #835810)
     - hwdb: Rework path/priority comparison when loading files from /etc/
       vs. /lib. (Closes: #845442)
     - machinectl: Fix "list" command when failing to determine OS version.
       (Closes: #849316)
     - Support tilegx architecture. (Closes: #856306)
     - systemd-sleep(8): Point out inhibitor interface as better alternative
       for suspend integration. (Closes: #758279)
     - journalctl: Improve error message wording when specifying boot
       offset with ephemeral journal. (Closes: #839291)
   * Install new systemd-umount and /usr/lib/environment.d/
   * Use "make install-tests" for shipped unit tests
   * Switch back to gold linker on mips*
     Bug #851736 got fixed now.
   * debian/rules: Drop obsolete SETCAP path
   [ Michael Biebl ]
   * Drop upstart jobs for udev
   * Drop /sbin/udevadm compat symlink from udev-udeb and initramfs
   * Drop Breaks and Replaces from pre-jessie
