[ubuntu/yakkety-proposed] ntp 1:4.2.8p8+dfsg-1ubuntu1 (Accepted)
Christian Ehrhardt
christian.ehrhardt at canonical.com
Fri Jul 29 13:34:16 UTC 2016
ntp (1:4.2.8p8+dfsg-1ubuntu1) yakkety; urgency=medium
[ Christian Ehrhardt ]
* Merge from Debian testing. Remaining changes:
+ debian/rules: enable debugging. Asked debian to add this in bug #643954.
+ debian/rules, debian/ntp.dirs, debian/source_ntp.py: Add apport hook.
+ debian/control: Add Suggests on apparmor.
+ debian/source_ntp.py: Add filter on AppArmor profile names to prevent
false positives from denials originating in other packages
+ debian/ntpdate.if-up: Fix interaction with openntpd. Stop ntp before
running ntpdate when an interface comes up, then start again afterwards.
+ debian/ntp.init, debian/rules: Only stop when entering single user mode,
don't use /var/lib/ntp/ntp.conf.dhcp if /etc/ntp.conf is newer - it can
get stale. Patch by Simon Déziel.
+ debian/ntp.conf, debian/ntpdate.default: Change default server to
ntp.ubuntu.com.
+ debian/control: Add bison to Build-Depends (for ntpd/ntp_parser.y).
+ Extend PPS support
- debian/README.Debian: Add a PPS section to the README.Debian
- debian/ntp.conf: Add some configuration examples from the offical
documentation.
+ SECURITY UPDATE: NTP statsdir cleanup cronjob insecure (LP: #1528050)
- debian/ntp.cron.daily: fix security issues, patch thanks to halfdog!
- CVE-2016-0727
+ Merge also contains an upstream fix that solves (LP: #1567540)
* Added changes
+ match Ubuntu packages now that Debian has ntp apparmor accepted in
d/control for Apparmor conflicts/replaces
+ d/apparmor-profile add samba winbindd pipe (LP: #1582767)
* Drop Changes:
+ Add enforcing AppArmor profile (accepted in Debian):
- debian/control: Add Conflicts/Replaces on apparmor-profiles.
- debian/control: Add Suggests on apparmor.
- debian/control: Build-Depends on dh-apparmor.
- add debian/apparmor-profile*.
- debian/ntp.dirs: Add apparmor directories.
- debian/rules: Install apparmor-profile and apparmor-profile.tunable.
- debian/source_ntp.py: Add filter on AppArmor profile names to prevent
false positives from denials originating in other packages.
- debian/README.Debian: Add note on AppArmor.
+ Add PPS support (accepted in Debian)
- debian/control: Add Build-Depends on pps-tools
+ debian/apparmor-profile: allow 'rw' access to /dev/pps[0-9]* devices.
+ d/p/fix_local_sync.patch: fix local clock sync (fixed upstream)
+ debian/patches/ntpdate-fix-lp1526264.patch (fixed upstream):
- Add Alfonso Sanchez-Beato's patch for fixing the cannot correct dates in
the future bug
+ debian/apparmor-profile: adjust to handle AF_UNSPEC with dgram and stream
+ dropping previous ubuntu security patches/fixes that have been upstreamed
in 4.2.8p6: CVE-2015-7973, CVE-2015-7975, CVE-2015-7976, CVE-2015-7977,
CVE-2015-7978, CVE-2015-7979, CVE-2015-8138, CVE-2015-8158
+ dropping previous ubuntu security patches/fixes that have been upstreamed
in 4.2.8p7: CVE-2016-1548, CVE-2016-1550, CVE-2016-2516, CVE-2016-2518,
CVE-2015-7974, CVE-2016-1547
[ Robie Basak ]
* Restore AppArmor entries in debian/ntp.dirs.
ntp (1:4.2.8p8+dfsg-1) unstable; urgency=high
* New usptream version
- Fixes security issues
ntp (1:4.2.8p7+dfsg-4) unstable; urgency=high
* Update apparmor-profiles-extra again now we now in which version they
removed it.
* Call dh_apparmor. Add build-depends on dh-apparmor. (Closes: #824767)
ntp (1:4.2.8p7+dfsg-3) unstable; urgency=medium
[ Hideki Yamane ]
* Properly enable Apparmor profile from Ubuntu (Closes: #823024)
Patch from Hideki Yamane <henrich at debian.or.jp>
* Update replace/breaks versions of apparmor-profiles-extra
(Closes: #805183)
ntp (1:4.2.8p7+dfsg-2) unstable; urgency=medium
* Only build-depend on pps-tools on Linux
ntp (1:4.2.8p7+dfsg-1) unstable; urgency=medium
* New upstream version
This might fix a few CVEs.
* Drop CVE-2015-5300.patch and CVE-2015-7704.patch now claimed to
be fixed upstream.
* Remove Bdale from uploaders (Closes: #804377)
* Remove section about patching the kernel for PPS support, it's already
included in the kernel (Closes: #811171)
* Pass --build and --host to configure. (Closes: #315935)
Patch from Helmut Grohne <helmut at subdivi.de>
* Missing Build-Depends libopts25-dev (which is not implicit in autogen,
because autogen is M-A:foreign).
Patch from Helmut Grohne <helmut at subdivi.de>
* Fix ntp.dhcp to also check for pool and better handle spaces and tabs.
(Closes: #809344, #806676)
* Change watch file to use https (Closes: #793926)
* Hook into NetworkManager to update ntp servers from dhcp. (Closes:
#778415). Patch from Helmut Grohne <helmut at subdivi.de>
* Build Depend on pps-tools (Closes: #691672)
* Don't run ntpdate when method is none. Patch from
Dmitry Borisyuk <q1werty at i.com.ua>
* Also use flock to in the ntp init script, and update the lock file
location. (Closes: #806556)
* Move apparmor profile from apparmor-profiles-extra. Add Breaks/Replaces.
(Closes: #805183)
Date: Fri, 29 Jul 2016 12:42:43 +0200
Changed-By: Christian Ehrhardt <christian.ehrhardt at canonical.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Signed-By: Robie Basak <robie.basak at canonical.com>
https://launchpad.net/ubuntu/+source/ntp/1:4.2.8p8+dfsg-1ubuntu1
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 29 Jul 2016 12:42:43 +0200
Source: ntp
Binary: ntp ntpdate ntp-doc
Architecture: source
Version: 1:4.2.8p8+dfsg-1ubuntu1
Distribution: yakkety
Urgency: high
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Christian Ehrhardt <christian.ehrhardt at canonical.com>
Description:
ntp - Network Time Protocol daemon and utility programs
ntp-doc - Network Time Protocol documentation
ntpdate - client for setting system time from NTP servers
Closes: 315935 691672 778415 793926 804377 805183 806556 806676 809344 811171 823024 824767
Launchpad-Bugs-Fixed: 1528050 1567540 1582767
Changes:
ntp (1:4.2.8p8+dfsg-1ubuntu1) yakkety; urgency=medium
.
[ Christian Ehrhardt ]
* Merge from Debian testing. Remaining changes:
+ debian/rules: enable debugging. Asked debian to add this in bug #643954.
+ debian/rules, debian/ntp.dirs, debian/source_ntp.py: Add apport hook.
+ debian/control: Add Suggests on apparmor.
+ debian/source_ntp.py: Add filter on AppArmor profile names to prevent
false positives from denials originating in other packages
+ debian/ntpdate.if-up: Fix interaction with openntpd. Stop ntp before
running ntpdate when an interface comes up, then start again afterwards.
+ debian/ntp.init, debian/rules: Only stop when entering single user mode,
don't use /var/lib/ntp/ntp.conf.dhcp if /etc/ntp.conf is newer - it can
get stale. Patch by Simon Déziel.
+ debian/ntp.conf, debian/ntpdate.default: Change default server to
ntp.ubuntu.com.
+ debian/control: Add bison to Build-Depends (for ntpd/ntp_parser.y).
+ Extend PPS support
- debian/README.Debian: Add a PPS section to the README.Debian
- debian/ntp.conf: Add some configuration examples from the offical
documentation.
+ SECURITY UPDATE: NTP statsdir cleanup cronjob insecure (LP: #1528050)
- debian/ntp.cron.daily: fix security issues, patch thanks to halfdog!
- CVE-2016-0727
+ Merge also contains an upstream fix that solves (LP: #1567540)
* Added changes
+ match Ubuntu packages now that Debian has ntp apparmor accepted in
d/control for Apparmor conflicts/replaces
+ d/apparmor-profile add samba winbindd pipe (LP: #1582767)
* Drop Changes:
+ Add enforcing AppArmor profile (accepted in Debian):
- debian/control: Add Conflicts/Replaces on apparmor-profiles.
- debian/control: Add Suggests on apparmor.
- debian/control: Build-Depends on dh-apparmor.
- add debian/apparmor-profile*.
- debian/ntp.dirs: Add apparmor directories.
- debian/rules: Install apparmor-profile and apparmor-profile.tunable.
- debian/source_ntp.py: Add filter on AppArmor profile names to prevent
false positives from denials originating in other packages.
- debian/README.Debian: Add note on AppArmor.
+ Add PPS support (accepted in Debian)
- debian/control: Add Build-Depends on pps-tools
+ debian/apparmor-profile: allow 'rw' access to /dev/pps[0-9]* devices.
+ d/p/fix_local_sync.patch: fix local clock sync (fixed upstream)
+ debian/patches/ntpdate-fix-lp1526264.patch (fixed upstream):
- Add Alfonso Sanchez-Beato's patch for fixing the cannot correct dates in
the future bug
+ debian/apparmor-profile: adjust to handle AF_UNSPEC with dgram and stream
+ dropping previous ubuntu security patches/fixes that have been upstreamed
in 4.2.8p6: CVE-2015-7973, CVE-2015-7975, CVE-2015-7976, CVE-2015-7977,
CVE-2015-7978, CVE-2015-7979, CVE-2015-8138, CVE-2015-8158
+ dropping previous ubuntu security patches/fixes that have been upstreamed
in 4.2.8p7: CVE-2016-1548, CVE-2016-1550, CVE-2016-2516, CVE-2016-2518,
CVE-2015-7974, CVE-2016-1547
.
[ Robie Basak ]
* Restore AppArmor entries in debian/ntp.dirs.
.
ntp (1:4.2.8p8+dfsg-1) unstable; urgency=high
.
* New usptream version
- Fixes security issues
.
ntp (1:4.2.8p7+dfsg-4) unstable; urgency=high
.
* Update apparmor-profiles-extra again now we now in which version they
removed it.
* Call dh_apparmor. Add build-depends on dh-apparmor. (Closes: #824767)
.
ntp (1:4.2.8p7+dfsg-3) unstable; urgency=medium
.
[ Hideki Yamane ]
* Properly enable Apparmor profile from Ubuntu (Closes: #823024)
Patch from Hideki Yamane <henrich at debian.or.jp>
* Update replace/breaks versions of apparmor-profiles-extra
(Closes: #805183)
.
ntp (1:4.2.8p7+dfsg-2) unstable; urgency=medium
.
* Only build-depend on pps-tools on Linux
.
ntp (1:4.2.8p7+dfsg-1) unstable; urgency=medium
.
* New upstream version
This might fix a few CVEs.
* Drop CVE-2015-5300.patch and CVE-2015-7704.patch now claimed to
be fixed upstream.
* Remove Bdale from uploaders (Closes: #804377)
* Remove section about patching the kernel for PPS support, it's already
included in the kernel (Closes: #811171)
* Pass --build and --host to configure. (Closes: #315935)
Patch from Helmut Grohne <helmut at subdivi.de>
* Missing Build-Depends libopts25-dev (which is not implicit in autogen,
because autogen is M-A:foreign).
Patch from Helmut Grohne <helmut at subdivi.de>
* Fix ntp.dhcp to also check for pool and better handle spaces and tabs.
(Closes: #809344, #806676)
* Change watch file to use https (Closes: #793926)
* Hook into NetworkManager to update ntp servers from dhcp. (Closes:
#778415). Patch from Helmut Grohne <helmut at subdivi.de>
* Build Depend on pps-tools (Closes: #691672)
* Don't run ntpdate when method is none. Patch from
Dmitry Borisyuk <q1werty at i.com.ua>
* Also use flock to in the ntp init script, and update the lock file
location. (Closes: #806556)
* Move apparmor profile from apparmor-profiles-extra. Add Breaks/Replaces.
(Closes: #805183)
Checksums-Sha1:
174ebda8a8bbd0c182a9f469306d830154547a7b 2359 ntp_4.2.8p8+dfsg-1ubuntu1.dsc
3c2565a01aed586c4ff60e6c6961919895a8ad35 4214004 ntp_4.2.8p8+dfsg.orig.tar.xz
32e963e509f65245883393caa3685c5bb4950288 62076 ntp_4.2.8p8+dfsg-1ubuntu1.debian.tar.xz
Checksums-Sha256:
7ede6ce3ad937aaaa8363496f0575dfd0e050557629ef6975d74a286c1d5a9df 2359 ntp_4.2.8p8+dfsg-1ubuntu1.dsc
73e19507784300c5ea24fddeb9779c9a5056e42b40457759a69549e1030a3894 4214004 ntp_4.2.8p8+dfsg.orig.tar.xz
5319cf32fab5d0c4dc511004b6c1e088b2d61dc7b5cf44f54e92a977a7c1e5b8 62076 ntp_4.2.8p8+dfsg-1ubuntu1.debian.tar.xz
Files:
05c7e9ab00bd5f5cd988167b4849ade1 2359 net optional ntp_4.2.8p8+dfsg-1ubuntu1.dsc
87d57e42f6ce32c66b9d3a96561e7166 4214004 net optional ntp_4.2.8p8+dfsg.orig.tar.xz
ba292b6822faa01040809fb508a7b412 62076 net optional ntp_4.2.8p8+dfsg-1ubuntu1.debian.tar.xz
Original-Maintainer: Debian NTP Team <pkg-ntp-maintainers at lists.alioth.debian.org>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJXm1sPAAoJEOVkucJ1vdUu0s0P/jpPLqS7rCOTbOrsY9y3zMC7
iVYyjIv+uwNka4TPQ8rBrvKcwMr3oscQOaj9rB5lKkn29+atB98XdbFvflf3BtRl
JZBTijoWGeq1UYOfvDq6GFdMboL/k4/maa68NpRnr6oN2YHPmqFApkMnHOHQV1iY
qVZo4z2otGmkNsdnHREP6FlysBdMvXghMA7QngK0IDDjuFwEo8JSY/05s0JcV4Hv
VN9WiTCsNm/N+igfqwB4G1/sqggiiVqytTVapqQVcdtEo10zROjDM1xqR8x6uj90
DXJ8NfHNwkUH1DlBJDh4NeXtEriP4EyYGB8VxeiPKIiA/ZoHnr/LyzWAU+151gBJ
QGCxFs6PWuPIiShUhbtMtCiHQNsOc+fSpkmKFLlVMucuLNhjWCyyETZnucHfynS3
G7FK63qySc4Fah3szMfq/ZqSSL87qYN+qiLfx59KNC9iAVBujlZE8EwfL2IOED47
63GN+XNAvzJk+h2vp1+CrsVkTPHM4inTSZxTt7EncOGmobnR89FIXvOPNDuNLee3
76Zc6qK/E8xDIf9gxLQkuyT5RCTX2I5/rpde5K8ahsPYNDRgKQPAeObfZZT0gTqQ
ETjKbprQhhIynw13JU/GoZGeqn6JVXXb90ZU4lw/9uCsOH83C1kQDxOJG1cS1mCc
GLWhj8urJaviKSwQh6l6
=sqrl
-----END PGP SIGNATURE-----
More information about the Yakkety-changes
mailing list