Commit graph

57 commits

Author SHA1 Message Date
Patrick J Volkerding
ffef56590d Mon May 18 19:17:21 UTC 2020
Greetings! After three months in /testing, the PAM merge into the main tree
is now complete. When updating, be sure to install the new pam, cracklib, and
libpwquality packages or you may find yourself locked out of your machine.
Otherwise, these changes should be completely transparent and you shouldn't
notice any obvious operational differences. Be careful if you make any changes
in /etc/pam.d/ - leaving an extra console logged in while testing PAM config
changes is a recommended standard procedure. Thanks again to Robby Workman,
Vincent Batts, Phantom X, and ivandi for help implementing this. It's not
done yet and there will be more fine-tuning of the config files, but now we
can move on to build some other updates. Enjoy!
a/cracklib-2.9.7-x86_64-1.txz:  Added.
a/kernel-firmware-20200517_f8d32e4-noarch-1.txz:  Upgraded.
a/libcgroup-0.41-x86_64-7.txz:  Rebuilt.
  Rebuilt to add PAM support.
a/libpwquality-1.4.2-x86_64-1.txz:  Added.
a/lilo-24.2-x86_64-9.txz:  Rebuilt.
  Enable the "compact" option by default.
  liloconfig: correctly set the root partition.
a/pam-1.3.1-x86_64-1.txz:  Added.
a/shadow-4.8.1-x86_64-7.txz:  Rebuilt.
  Rebuilt to add PAM support.
a/utempter-1.2.0-x86_64-1.txz:  Upgraded.
a/util-linux-2.35.1-x86_64-6.txz:  Rebuilt.
  Rebuilt to add PAM support.
a/xfsprogs-5.6.0-x86_64-2.txz:  Rebuilt.
  Recompiled against icu4c-67.1.
ap/at-3.2.1-x86_64-2.txz:  Rebuilt.
  Rebuilt to add PAM support.
ap/cups-2.3.3-x86_64-2.txz:  Rebuilt.
  Rebuilt to add PAM support.
ap/hplip-3.20.5-x86_64-2.txz:  Rebuilt.
  Rebuilt to add PAM support.
ap/mariadb-10.4.13-x86_64-2.txz:  Rebuilt.
  Rebuilt to add PAM support.
ap/screen-4.8.0-x86_64-2.txz:  Rebuilt.
  Rebuilt to add PAM support.
ap/soma-3.3.0-noarch-1.txz:  Upgraded.
  Thanks to David Woodfall.
ap/sqlite-3.31.1-x86_64-2.txz:  Rebuilt.
  Recompiled against icu4c-67.1.
ap/sudo-1.9.0-x86_64-2.txz:  Rebuilt.
  Rebuilt to add PAM support.
ap/vim-8.2.0788-x86_64-1.txz:  Upgraded.
d/bison-3.6.2-x86_64-1.txz:  Upgraded.
d/meson-0.54.2-x86_64-1.txz:  Upgraded.
d/python-setuptools-46.4.0-x86_64-1.txz:  Upgraded.
d/vala-0.48.6-x86_64-1.txz:  Upgraded.
kde/calligra-2.9.11-x86_64-36.txz:  Rebuilt.
  Recompiled against icu4c-67.1.
kde/kde-workspace-4.11.22-x86_64-7.txz:  Rebuilt.
  Rebuilt to add PAM support.
l/ConsoleKit2-1.2.1-x86_64-4.txz:  Rebuilt.
  Rebuilt to add PAM support.
l/boost-1.73.0-x86_64-2.txz:  Rebuilt.
  Recompiled against icu4c-67.1.
l/gnome-keyring-3.36.0-x86_64-2.txz:  Rebuilt.
  Rebuilt to add PAM support.
l/harfbuzz-2.6.6-x86_64-2.txz:  Rebuilt.
  Recompiled against icu4c-67.1.
l/icu4c-67.1-x86_64-1.txz:  Upgraded.
  Shared library .so-version bump.
l/imagemagick-7.0.10_13-x86_64-1.txz:  Upgraded.
l/libcap-2.34-x86_64-2.txz:  Rebuilt.
  Rebuilt to add PAM support.
l/libical-3.0.8-x86_64-2.txz:  Rebuilt.
  Recompiled against icu4c-67.1.
l/libuv-1.38.0-x86_64-1.txz:  Upgraded.
l/libvisio-0.1.7-x86_64-3.txz:  Rebuilt.
  Recompiled against icu4c-67.1.
l/polkit-0.116-x86_64-3.txz:  Rebuilt.
  Rebuilt to add PAM support.
l/qt-4.8.7-x86_64-16.txz:  Rebuilt.
  Recompiled against icu4c-67.1.
l/qt5-5.13.2-x86_64-4.txz:  Rebuilt.
  Recompiled against icu4c-67.1.
l/qt5-webkit-5.212.0_alpha4-x86_64-2.txz:  Rebuilt.
  Recompiled against icu4c-67.1.
l/raptor2-2.0.15-x86_64-9.txz:  Rebuilt.
  Recompiled against icu4c-67.1.
l/system-config-printer-1.5.12-x86_64-4.txz:  Rebuilt.
  Rebuilt to add PAM support.
l/vte-0.60.2-x86_64-2.txz:  Rebuilt.
  Recompiled against icu4c-67.1.
n/cifs-utils-6.10-x86_64-4.txz:  Rebuilt.
  Rebuilt to add PAM support.
n/cyrus-sasl-2.1.27-x86_64-4.txz:  Rebuilt.
  Rebuilt to add PAM support.
n/dovecot-2.3.10.1-x86_64-1.txz:  Upgraded.
  Rebuilt to add PAM support.
  Compiled against icu4c-67.1.
  This update fixes several denial-of-service vulnerabilities.
  For more information, see:
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10957
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10958
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10967
  (* Security fix *)
n/mutt-1.14.1-x86_64-1.txz:  Upgraded.
n/netatalk-3.1.12-x86_64-3.txz:  Rebuilt.
  Rebuilt to add PAM support.
n/netkit-rsh-0.17-x86_64-3.txz:  Rebuilt.
  Rebuilt to add PAM support.
n/nss-pam-ldapd-0.9.11-x86_64-1.txz:  Added.
n/openssh-8.2p1-x86_64-3.txz:  Rebuilt.
  Rebuilt to add PAM support.
n/openvpn-2.4.9-x86_64-2.txz:  Rebuilt.
  Rebuilt to add PAM support.
n/pam-krb5-4.9-x86_64-1.txz:  Added.
n/php-7.4.6-x86_64-2.txz:  Rebuilt.
  Recompiled against icu4c-67.1.
n/popa3d-1.0.3-x86_64-4.txz:  Rebuilt.
  Rebuilt to add PAM support.
n/postfix-3.5.2-x86_64-1.txz:  Upgraded.
  Compiled against icu4c-67.1.
n/ppp-2.4.8-x86_64-2.txz:  Rebuilt.
  Rebuilt to add PAM support.
n/proftpd-1.3.6c-x86_64-2.txz:  Rebuilt.
  Rebuilt to add PAM support.
n/samba-4.12.2-x86_64-2.txz:  Rebuilt.
  Rebuilt to add PAM support.
  Recompiled against icu4c-67.1.
n/tin-2.4.4-x86_64-2.txz:  Rebuilt.
  Recompiled against icu4c-67.1.
n/vsftpd-3.0.3-x86_64-6.txz:  Rebuilt.
  Rebuilt to add PAM support.
t/texlive-2019.190626-x86_64-4.txz:  Rebuilt.
  Recompiled against icu4c-67.1.
x/vulkan-sdk-1.2.135.0-x86_64-1.txz:  Upgraded.
x/xdm-1.1.11-x86_64-10.txz:  Rebuilt.
  Rebuilt to add PAM support.
x/xisxwayland-1-x86_64-1.txz:  Added.
xap/sane-1.0.30-x86_64-1.txz:  Upgraded.
  This update fixes several security issues.
  For more information, see:
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12867
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12862
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12863
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12865
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12866
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12861
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12864
  (* Security fix *)
xap/vim-gvim-8.2.0788-x86_64-1.txz:  Upgraded.
xap/xlockmore-5.63-x86_64-2.txz:  Rebuilt.
  Rebuilt to add PAM support.
xap/xscreensaver-5.44-x86_64-2.txz:  Rebuilt.
  Rebuilt to add PAM support.
extra/brltty/brltty-6.1-x86_64-2.txz:  Rebuilt.
  Recompiled against icu4c-67.1.
extra/pure-alsa-system/qt5-5.13.2-x86_64-4_alsa.txz:  Rebuilt.
  Recompiled against icu4c-67.1.
isolinux/initrd.img:  Rebuilt.
  Added PAM libraries, security modules, and config files.
usb-and-pxe-installers/usbboot.img:  Rebuilt.
  Added PAM libraries, security modules, and config files.
2020-05-18 23:25:14 +02:00
Patrick J Volkerding
f845c97d2d Sat Mar 28 05:48:42 UTC 2020
a/lvm2-2.03.09-x86_64-1.txz:  Upgraded.
d/guile-3.0.2-x86_64-1.txz:  Upgraded.
l/glib-networking-2.64.1-x86_64-1.txz:  Upgraded.
l/gtk+3-3.24.16-x86_64-1.txz:  Upgraded.
l/gvfs-1.44.1-x86_64-1.txz:  Upgraded.
l/librsvg-2.48.1-x86_64-1.txz:  Upgraded.
l/vte-0.60.1-x86_64-1.txz:  Upgraded.
xap/audacious-4.0-x86_64-3.txz:  Rebuilt.
  Also support GTK+ interface, including a .desktop file for it.
xap/audacious-plugins-4.0-x86_64-3.txz:  Rebuilt.
  Rebuilt with --enable-gtk.
extra/pure-alsa-system/audacious-plugins-4.0-x86_64-3_alsa.txz:  Rebuilt.
  Rebuilt with --enable-gtk.
extra/pure-alsa-system/qt5-5.13.2-x86_64-3_alsa.txz:  Added.
2020-03-28 17:59:48 +01:00
Patrick J Volkerding
f1c067fa42 Wed Mar 25 22:53:06 UTC 2020
a/e2fsprogs-1.45.6-x86_64-2.txz:  Rebuilt.
  Fixed RELEASE-NOTES dangling symlink.
a/kernel-generic-5.4.28-x86_64-1.txz:  Upgraded.
a/kernel-huge-5.4.28-x86_64-1.txz:  Upgraded.
a/kernel-modules-5.4.28-x86_64-1.txz:  Upgraded.
ap/nano-4.9-x86_64-1.txz:  Upgraded.
d/kernel-headers-5.4.28-x86-1.txz:  Upgraded.
d/llvm-10.0.0-x86_64-1.txz:  Upgraded.
  Shared library .so-version bump.
d/rust-1.42.0-x86_64-2.txz:  Rebuilt.
  Recompiled against llvm-10.0.0.
d/scons-3.1.2-x86_64-3.txz:  Rebuilt.
  Fixed shebangs for python3, removed useless .bat files.
  Thanks to teeemcee and ponce.
d/vala-0.48.2-x86_64-1.txz:  Upgraded.
k/kernel-source-5.4.28-noarch-1.txz:  Upgraded.
l/libgsf-1.14.47-x86_64-1.txz:  Upgraded.
l/neon-0.31.0-x86_64-1.txz:  Upgraded.
l/netpbm-10.89.03-x86_64-1.txz:  Upgraded.
l/qt5-5.13.2-x86_64-3.txz:  Rebuilt.
  Recompiled against llvm-10.0.0.
x/mesa-20.0.2-x86_64-2.txz:  Rebuilt.
  Recompiled against llvm-10.0.0.
xfce/thunar-1.8.14-x86_64-1.txz:  Upgraded.
isolinux/initrd.img:  Rebuilt.
kernels/*:  Upgraded.
usb-and-pxe-installers/usbboot.img:  Rebuilt.
2020-03-26 08:59:49 +01:00
Patrick J Volkerding
7ca677f34e Thu Feb 20 23:40:12 UTC 2020
a/ed-1.16-x86_64-1.txz:  Upgraded.
l/gtk+3-3.24.14-x86_64-3.txz:  Rebuilt.
  Rebuilt to add wayland backend.
l/libuv-1.34.2-x86_64-1.txz:  Added.
  This is needed by bind-9.16.0.
l/qt5-5.13.2-x86_64-2.txz:  Rebuilt.
  Rebuilt to add wayland support.
  Use the system ffmpeg, not the bundled one.
n/bind-9.16.0-x86_64-1.txz:  Upgraded.
  rc.bind: don't change file ownerships in /var/named. Thanks to voegelas.
n/proftpd-1.3.6c-x86_64-1.txz:  Upgraded.
  No CVEs assigned, but this sure looks like a security issue:
  Use-after-free vulnerability in memory pools during data transfer.
  (* Security fix *)
x/libinput-1.15.2-x86_64-1.txz:  Upgraded.
x/xkbcomp-1.4.3-x86_64-1.txz:  Upgraded.
testing/packages/PAM/proftpd-1.3.6c-x86_64-1_pam.txz:  Upgraded.
  No CVEs assigned, but this sure looks like a security issue:
  Use-after-free vulnerability in memory pools during data transfer.
  (* Security fix *)
2020-02-21 08:59:49 +01:00
Patrick J Volkerding
8ea9f1e02e Mon Feb 17 06:03:43 UTC 2020
ap/ksh93-20200131_e4fea8c5-x86_64-1.txz:  Upgraded.
ap/zsh-5.8-x86_64-1.txz:  Upgraded.
l/brotli-1.0.7-x86_64-1.txz:  Added.
l/gmime-3.2.6-x86_64-1.txz:  Upgraded.
l/hyphen-2.8.8-x86_64-1.txz:  Added.
l/openal-soft-1.20.1-x86_64-1.txz:  Upgraded.
  Thanks to Skaendo and Willy Sudiarto Raharjo.
l/qt5-webkit-5.212.0_alpha3-x86_64-1.txz:  Added.
  Thanks to alienBOB.
l/woff2-20180531_a0d0ed7-x86_64-1.txz:  Added.
n/bluez-5.53-x86_64-1.txz:  Upgraded.
n/mutt-1.13.4-x86_64-1.txz:  Upgraded.
n/samba-4.11.6-x86_64-3.txz:  Rebuilt.
n/socat-1.7.3.4-x86_64-1.txz:  Added.
n/whois-5.5.6-x86_64-1.txz:  Upgraded.
testing/packages/PAM/samba-4.11.6-x86_64-3_pam.txz:  Rebuilt.
  Added patches to fix joining a DC when using krb5. Looks like the patches are
  already upstreamed in the latest 4.12.0-rc. Thanks to camerabambai.
2020-02-17 17:59:51 +01:00
Patrick J Volkerding
6087aff6ca Sat Feb 15 22:57:25 UTC 2020
a/libcgroup-0.41-x86_64-6.txz:  Rebuilt.
ap/mariadb-10.4.12-x86_64-2.txz:  Rebuilt.
d/Cython-0.29.15-x86_64-1.txz:  Upgraded.
d/cmake-3.16.4-x86_64-2.txz:  Rebuilt.
  Recompiled against qt5-5.13.2.
d/doxygen-1.8.17-x86_64-2.txz:  Rebuilt.
  Recompiled against qt5-5.13.2.
l/ConsoleKit2-1.2.1-x86_64-3.txz:  Rebuilt.
l/gnome-keyring-3.34.0-x86_64-2.txz:  Rebuilt.
l/imagemagick-7.0.9_23-x86_64-1.txz:  Upgraded.
l/polkit-0.116-x86_64-2.txz:  Rebuilt.
l/python-future-0.18.2-x86_64-1.txz:  Added.
  This is needed by fetchmailconf and will probably see additional use as
  projects jump off of the sinking Python 2 ship.
l/v4l-utils-1.18.0-x86_64-2.txz:  Rebuilt.
  Recompiled against qt5-5.13.2.
n/cifs-utils-6.10-x86_64-3.txz:  Rebuilt.
n/fetchmail-6.4.2-x86_64-1.txz:  Upgraded.
n/pinentry-1.1.0-x86_64-3.txz:  Rebuilt.
  Recompiled against qt5-5.13.2.
n/samba-4.11.6-x86_64-2.txz:  Rebuilt.
n/wpa_supplicant-2.9-x86_64-2.txz:  Rebuilt.
  Recompiled against qt5-5.13.2.
xap/xpdf-4.02-x86_64-3.txz:  Rebuilt.
  Recompiled against qt5-5.13.2.
testing/packages/PAM/ConsoleKit2-1.2.1-x86_64-3_pam.txz:  Rebuilt.
  Put the pam security modules in /lib${LIBDIRSUFFIX}/security.
  Remove .la files in /lib${LIBDIRSUFFIX}/security.
testing/packages/PAM/cifs-utils-6.10-x86_64-3_pam.txz:  Rebuilt.
  Put the pam security modules in /lib${LIBDIRSUFFIX}/security.
testing/packages/PAM/gnome-keyring-3.34.0-x86_64-2_pam.txz:  Rebuilt.
  Put the pam security modules in /lib${LIBDIRSUFFIX}/security.
  Remove .la files in /lib${LIBDIRSUFFIX}/security.
testing/packages/PAM/libcgroup-0.41-x86_64-6_pam.txz:  Rebuilt.
  Put the pam security modules in /lib${LIBDIRSUFFIX}/security.
  Remove .la files in /lib${LIBDIRSUFFIX}/security.
testing/packages/PAM/libpwquality-1.4.2-x86_64-2_pam.txz:  Rebuilt.
  Put the pam security modules in /lib${LIBDIRSUFFIX}/security.
  Remove .la files in /lib${LIBDIRSUFFIX}/security.
testing/packages/PAM/mariadb-10.4.12-x86_64-2_pam.txz:  Rebuilt.
  Put the pam security modules in /lib${LIBDIRSUFFIX}/security.
testing/packages/PAM/pam-1.3.1-x86_64-2_pam.txz:  Rebuilt.
  Put the pam security modules in /lib${LIBDIRSUFFIX}/security to support
  multilib. Thanks to GazL.
testing/packages/PAM/polkit-0.116-x86_64-2_pam.txz:  Rebuilt.
  Rebuilt using --with-pam-module-dir=/lib${LIBDIRSUFFIX}/security.
testing/packages/PAM/samba-4.11.6-x86_64-2_pam.txz:  Rebuilt.
  Put the pam security modules in /lib${LIBDIRSUFFIX}/security.
2020-02-16 08:59:47 +01:00
Patrick J Volkerding
7cde3ca9e7 Sat Feb 15 02:42:28 UTC 2020
a/kernel-generic-5.4.20-x86_64-1.txz:  Upgraded.
a/kernel-huge-5.4.20-x86_64-1.txz:  Upgraded.
a/kernel-modules-5.4.20-x86_64-1.txz:  Upgraded.
a/shadow-4.8.1-x86_64-3.txz:  Rebuilt.
a/util-linux-2.35.1-x86_64-3.txz:  Rebuilt.
d/kernel-headers-5.4.20-x86-1.txz:  Upgraded.
k/kernel-source-5.4.20-noarch-1.txz:  Upgraded.
l/ConsoleKit2-1.2.1-x86_64-2.txz:  Rebuilt.
l/dconf-editor-3.34.4-x86_64-1.txz:  Upgraded.
l/libxkbcommon-0.10.0-x86_64-1.txz:  Added.
l/openal-soft-1.19.1-x86_64-1.txz:  Added.
l/qt5-5.13.2-x86_64-1.txz:  Added.
  Thanks to alienBOB.
n/openssh-8.2p1-x86_64-1.txz:  Upgraded.
  Potentially incompatible changes:
  * ssh(1), sshd(8): the removal of "ssh-rsa" from the accepted
    CASignatureAlgorithms list.
  * ssh(1), sshd(8): this release removes diffie-hellman-group14-sha1
    from the default key exchange proposal for both the client and
    server.
  * ssh-keygen(1): the command-line options related to the generation
    and screening of safe prime numbers used by the
    diffie-hellman-group-exchange-* key exchange algorithms have
    changed. Most options have been folded under the -O flag.
  * sshd(8): the sshd listener process title visible to ps(1) has
    changed to include information about the number of connections that
    are currently attempting authentication and the limits configured
    by MaxStartups.
x/mesa-19.3.4-x86_64-2.txz:  Rebuilt.
  Reverted "[PATCH] swr: Fix GCC 4.9 checks." which makes X fail to start with
  an illegal instruction on some hardware.
isolinux/initrd.img:  Rebuilt.
kernels/*:  Upgraded.
testing/packages/PAM/ConsoleKit2-1.2.1-x86_64-2_pam.txz:  Rebuilt.
  Rebuilt with --disable-libcgmanager to fix setting limits on PAM.
  Thanks to gattocarlo.
testing/packages/PAM/openssh-8.2p1-x86_64-1_pam.txz:  Upgraded.
testing/packages/PAM/shadow-4.8.1-x86_64-3_pam.txz:  Rebuilt.
  Moved some of the /etc/pam.d/ file to the util-linux package where they
  more properly belong.
testing/packages/PAM/util-linux-2.35.1-x86_64-3_pam.txz:  Rebuilt.
  Added some /etc/pam.d/ files previously in the shadow package.
  Changed /etc/pam.d/{chfn,chsh} and made chfn/chsh setuid root to fix them.
  Added /etc/pam.d/{runuser,runuser-l}.
usb-and-pxe-installers/usbboot.img:  Rebuilt.
2020-02-15 08:59:47 +01:00