7zip (24.05+dfsg-3) unstable; urgency=medium . * Use DEP5 license name 7zip (24.05+dfsg-2) unstable; urgency=medium . * Add license text for Zstandard code * Extend years * Use canonical license identifier 7zip (24.05+dfsg-1) unstable; urgency=medium . * New upstream version 24.05+dfsg * Rediff patches * Reorder sequence of d/control fields by cme (routine-update) * Restore Breaks and Replaces line * Renumber patches 7zip-rar (24.05+ds-2) unstable; urgency=medium . * Use DEP5 license name 7zip-rar (24.05+ds-1) unstable; urgency=medium . * Typo fix * Add repack option to force repack upstream tarballs * Add suffix to repacked tarball * New upstream version 24.05+ds * Rediff patches * Add license text for Zstandard code * Extend years * Use canonical license identifier * Renumber patches * Standards-Version: 4.7.0 (routine-update) * Remove trailing whitespace in debian/copyright (routine-update) apprise (1.8.0-1) unstable; urgency=medium . * New upstream version 1.8.0 apt (2.9.3) unstable; urgency=medium . [ Julian Andres Klode ] * Initial implementation ("alpha") of the 3.0 solver: This new solver is available using the --solver 3.0 option. Highlights: - Fully backtracking solver, think DPLL without pure literal elimination - Manually installed packages are not offered up for removal - New --no-strict-pinning option allows APT to fallback to non-candidate versions, e.g. apt install --no-strict-pinning foo/experimental installs foo from experimental and will switch dependencies where needed. - Autoremove is more aggressive and only keeps the strongest automatically installed package. For example, gcc- will now be offered for removal and no longer kept around due libtool Depends: gcc | c-compiler and gcc- Provides: c-compiler, as `gcc` is already satisfied. Caveats right now: - Test suite is not yet passing - The list of automatically removable packages is not displayed when automatically installed packages are not removed - Error information gets lost on backtracking (see Debug::APT::Solver=2) - Error information is just rendered as A -> B implication graphs, with some nodes perhaps containing a "not". - The logic for replacing obsolete manually installed packages with new replacement packages (think Conflits/Replaces/Provides) is not yet implemented. - Conflict-driven clause learning is not implemented, so backtracking is technically pretty inefficient. * Solver3 integration fixes: - test: Ignore progress output in comparing output.. - test-allow-scores-for-all-dependency-types: Adjust for solver3 - EDSP: Add "solver3" alias for apt-internal-solver * UI work: - Highlight essential removals with action::remove color - The text of notices and audits shall not be bold - Separate columns by 2 spaces in lists (Closes: #1070064) * Support src:name shortcuts in showsrc, source, build-dep commands . [ David Kalnischkies ] * Do not ignore if a cmake execute_process fails * Avoid figuring which kept pkgs are phased if we don't display it * Match version constraints before saving garbage packages * Do not upgrade rev-deps ear-marked for removal * Drop sudo-related envvars in testing framework * Add test for dealing with unsat Suggests promoted to Recommends * Allow parsing an empty Provides line (Closes: #1069874) . [ Frans Spiesschaert ] * Dutch program translation update (Closes: #1070142) * Dutch manpages translation update (Closes: #1070143) astc-encoder (4.8.0+ds-1) unstable; urgency=medium . * New upstream version 4.8.0+ds * Update d/copyright * Bump Standards-Version to 4.7.0 * Refresh patches (no functional changes) * Build-depend on pkgconf instead of pkg-config biometryd (0.3.1-4) unstable; urgency=medium . * debian/watch: + Update for new GitLab tags page. * debian/control: + Bump Standards-Version to 4.7.0. No changes needed. bpfcc (0.29.1+ds-1.1) unstable; urgency=medium . * Non-maintainer upload. * [46b1ef4] Drop ppc64el from supported architectures (Closes: #1070768) bpfcc (0.29.1+ds-1) unstable; urgency=medium . * [28e32b6] New upstream version 0.29.1+ds bpfcc (0.28.0+ds-1) unstable; urgency=medium . * [0d35817] New upstream version 0.28.0+ds * [6ff6592] Add python3-setuptools build-dep * [59ea134] Add build-dep on zip needed by tests * [cb250ee] Bump S-V to 4.6.2, no changes to package * [7115e7c] Mark patch 2003 forwarded as not-needed bpfcc (0.26.0+ds-2~experimental2) experimental; urgency=medium . * [0e31111] Set architectures to linux-any bpfcc (0.26.0+ds-2~experimental1) experimental; urgency=medium . * [ab623bb] Enable all available architecture builds (Closes: #1030657) bpfcc (0.26.0+ds-1) unstable; urgency=medium . * [b4a876d] New upstream version 0.26.0+ds * [90d7771] Refresh patch 2003 for new release bpfcc (0.25.0+ds-2) unstable; urgency=medium . * [9fe5665] Cleanup existing temporary kernel headers path. Thanks to Jakub Wilk (Closes: 1028479) bpfcc (0.25.0+ds-1) unstable; urgency=medium . [ Debian Janitor ] * [09c55f4] Remove constraints unnecessary since buster . [ Vasudev Kamath ] * [8e5006c] New upstream version 0.25.0+ds * [ed6ed86] Drop patch 0001 which-tools-include-blk-mq.h. * [ceb5677] Refresh patch 2003-libbpf-tools-debian bpfcc (0.24.0+ds-1) unstable; urgency=medium . * [25e9441] New upstream version 0.24.0+ds. Closes: bug#1002291, Thanks to Sudip Mukherjee. + Support for kernel up to 5.16 + bcc tools: update for trace.py, sslsniff.py, tcptop.py, hardirqs.py, etc. + new libbpf tools: bashreadline + allow specify wakeup_events for perf buffer + support BPF_MAP_TYPE_{INODE, TASK}_STORAGE maps + remove all deprecated libbpf function usage + remove P4/B language support + major test infra change, using github actions now + doc update, bug fixes and other tools improvement * [c2634bc] Refresh patch 2003 for upstream release 0.24.0 * [25e9441] New upstream version 0.24.0+ds * [c2634bc] Refresh patch 2003 for upstream release 0.24.0 * [a6dfe80] Add patch 0001 to fix the issue in bio tools. * [25e9441] New upstream version 0.24.0+ds * [c2634bc] Refresh patch 2003 for upstream release 0.24.0 * [22f934a] Add patch 0001-tools-include-blk-mq.h-in-bio-tools.patch bpfcc (0.23.0+ds-1) unstable; urgency=medium . * [7e2f83e] New upstream version 0.23.0+ds * [f32279a] Refresh patch 2003 with new release of bcc. bpfcc (0.22.0+ds-2) unstable; urgency=medium . * Upload to unstable. bpfcc (0.22.0+ds-1) experimental; urgency=medium . * [75dc27e] New upstream version 0.22.0+ds + Support for kernel up to 5.14 + add ipv4/ipv6 filter support for tcp trace tools + add python interface to attach raw perf events + fix tcpstates for incorrect display of dport + new options for bcc tools runqslower, argdist + new libbpf-tools: filetop, exitsnoop, tcprtt + doc update, bug fixes and other tools improvement * [37970c9] Drop patch which is merged upstream 0001-libbpf-tools-readahead-don-t-mark-struct-hist-as-sta.patch. bpfcc (0.21.0+ds-7) unstable; urgency=medium . * Upload to unstable . [ Debian Janitor ] * [6b6bd08] Apply multi-arch hints. + libbpfcc, libbpfcc-dev: Add Multi-Arch: same. bpfcc (0.21.0+ds-6) experimental; urgency=medium . * [1329347] Drop s390x from Architectures list of libbpf-tools. bpfcc (0.21.0+ds-5) experimental; urgency=medium . * [61bbc17] Fence the clean target for libbpf-tools behind architecture check. bpfcc (0.21.0+ds-4) experimental; urgency=medium . * [7e2e5e6] Build libbpfcc-dev also on s390x and armhf similar to libbpfcc. * [32e3f0d] Build libbpf-tools only on supported architecture. bpfcc (0.21.0+ds-3) experimental; urgency=medium . * [a26969e] Use DEB_HOST_GNU_TYPE for getting system specific libbpf.a bpfcc (0.21.0+ds-2) experimental; urgency=medium . * [67ae45f] Restrict architecture for libbpf-tools to amd64 arm64 ppc64el and s390x. * [974eab1] Refresh patch 2003 for compiling libbpf-tools. Remove instruction to build libbpf.a which is only relevant when embedded copy of libbpf is used * [6095fd6] Remove compatibility definitions added to support 5.10 kernel. * [fedf9de] Introduce patch to fix readahead libbpf-tools from upstream. bpfcc (0.21.0+ds-1) experimental; urgency=medium . * [4ac8de7] New upstream version 0.21.0+ds * [fe4539e] Delete patches merged upstream * [25ecc88] Refresh 2001_fix_path_todeadloc.c.patch to work with new changes * [5fe4cc3] Refresh 0004-compat-defs.patch to add more definitions. * [312ec64] Refresh 0004-compat-defs.patch add more kernel compat definitions * [076f67a] swapin_example has been renamed to swapin * [c48b72d] Add support for building libbpf-tools package Closes: bug#978727, Thanks to Michael Prokop. * [abec541] Bump version of libbpf-dev to >= 0.4.0, needed by libbpf-tools * [55fe1cb] Add lintian override for missing man pages in libbpf-tools bpfcc (0.18.0+ds-2) unstable; urgency=medium . * [a328ab5] Do not rename the files under tools/lib to have -bpfcc suffix. Thanks to Salvatore Bonaccorso (Closes: #980296) bpfcc (0.18.0+ds-1) unstable; urgency=medium . [ Vasudev Kamath ] * [ac15aec] New upstream version 0.18.0+ds . [ Luca Boccassi ] * [f56181a] Refresh patches for upstream 0.18.0 release * [0ca71bd] Add 0004-compat-defs.patch to fix build without kernel 5.11 bpfcc (0.17.0+ds-1) unstable; urgency=medium . [ Luca Boccassi ] * [25bd1bf] New upstream version 0.17.0+ds * [9cfd50f] Backport patches to allow unvendoring of libbpf * [80cdd1a] Backport patch to allow dynamic linking against libclang-cpp * [aab402c] Add patch to remove no-libbpf library flavour * [9821776] Build-depend on libclang-cpp-dev to dynamically link against clang libraries. (Closes: #979015) * [4fc0af4] Build-depend on libbpf-dev, set the CMake variable to use it (Closes: #979016, #942290) * [8f07801] Remove bundling of libbpf, use packaged version bpfcc (0.17.0-9) unstable; urgency=medium . * [76dc661] Build with -DENABLE_LLVM_SHARED=on. Thanks to Vincent Bernat (Closes: 977629) bpfcc (0.17.0-8) unstable; urgency=medium . * [bb4e5c5] Drop the symbols file for libbpfcc library. Thanks to Adrian Bunk (Closes: #976596) bpfcc (0.17.0-7) unstable; urgency=medium . * [f62f9e8] Really update armhf symbols, batchpatch did not consider all symbols bpfcc (0.17.0-6) unstable; urgency=medium . * [955a3d8] Update symbol file for armhf architecture bpfcc (0.17.0-5) unstable; urgency=medium . * Upload to unstable bpfcc (0.17.0-4) experimental; urgency=medium . * [baeaa5c] Update symbols file for armhf architecture. bpfcc (0.17.0-3) experimental; urgency=medium . * [5065456] Enable build on armhf and s390x these arch are supported by upstream bpfcc (0.17.0-2) unstable; urgency=medium . * Upload to unstable bpfcc (0.17.0-1) experimental; urgency=medium . * [9406b6d] New upstream version 0.17.0 * [e034148] Update copyright hints file. * [9695968] Introduce patch to fix path of netqtop.c in netqtop-bpfcc. * [9d6bc84] Update symbols file for 0.17.0 release in amd64 * [07948f9] Move swapin example file to doc folder and remove exec permission. bpfcc (0.16.0-3) unstable; urgency=medium . * [b56af1b] Update symbols file for arm64. Thanks to Graham Inggs for the bug report. (Closes: #972416) bpfcc (0.16.0-2) unstable; urgency=medium . * Upload to unstable. * [bb5fe10] Update symbols file for arm64, ppc64 and ppc64el bpfcc (0.16.0-1) experimental; urgency=medium . * [91d874e] New upstream version 0.16.0 * [5b11f74] copyright-check: mine license from jpg and jpeg files * [87d34e2] Updated copyright_hints for 0.16.0 * [4feea7e] Updated symbols file for 0.16.0 release. * [54b5c8f] Move deadlock.c to /usr/share/bpfcc-tools and patch deadlock-bpfcc * [f528e72] For now drop --no-parallel if something breaks will revert. bpfcc (0.14.0-3) unstable; urgency=medium . * Upload to unstable bpfcc (0.14.0-2) experimental; urgency=medium . * [717e7c2] Update symbols file for arm64, ppc64 and ppc64el architecture bpfcc (0.14.0-1) unstable; urgency=medium . [ Debian Janitor ] * [2c8337d] Add missing build dependency on dh addon. * [663d385] Set upstream metadata fields: Bug-Database, Bug-Submit, Repository, Repository-Browse. * [89e8416] Update standards version to 4.5.0, no changes needed. . [ Vasudev Kamath ] * [fc1a4b7] Add component = libbpf in debian/gbp.conf * [b9cd982] New upstream version 0.14.0 * [faaab4e] Delete fix-ppc64.patch, it has been merged to upstream code. * [71e0883] Install the bpf introspection tool as part of bpfcc-tool * [a0239d1] Only install versioned libraries as part of libbpfcc * [708ca35] Install static libraries as part of libbpfcc-dev package. * [c7dc429] Rename libbpfcc to libbcc-bpf0 and libbpfcc-dev to libbcc-bpf-dev * [4991bf0] Add myself as the Uploader * [8b106fc] Generate symbols file using pkg-kde-symbols package * [f198242] Reformat the Build-Depends in control file * [ce63c32] Reformat the rules file and introduce hardening=+all * [f13fa19] Move BPF introspection too bps to bpfcc-introspection package * [62e313f] Install bpfcc-tools man page using manpages file * [e542371] Make sure all tools in bpfcc-tools has -bpfcc suffix * [93de5f4] Separate hardening from DEB_BUILD_MAINT_OPTIONS * [209ed76] Revert the package renaming of libbpfcc and libbpfcc-dev * [04406f4] Bump debhelper-compat to 13 * [0f5c9fc] Add source of libbpf-tools/bin/bpftool to debian/missing-sources * [60722cc] Introduce copyright-check and copyright_hints file * [7da6b60] Update license of embedded libbpf * [781baf1] Add Copyright section for libbpf * [b0fca8a] Updated symbols file . [ Ritesh Raj Sarraf ] * [01e615b] Refresh patch with gbp pq workflow * [cadf75d] Fix exception in trace-bpfcc. Thanks to Philipp Marek (Closes: #965188) bpfcc (0.12.0-2) unstable; urgency=medium . [ Frédéric Bonnard ] * [17d0441] Import upstream patch : fix test_map_in_map.cc compilation error bpfcc (0.12.0-1) unstable; urgency=medium . * [250799a] New upstream version 0.12.0 * [281b66f] Add example import commands into d/README.source * [184d93c] Fix installation of some tools in standard path bpfcc (0.11.0-1) unstable; urgency=medium . * [52cfb06] New upstream version 0.11.0 (Closes: #941753) * [a7af29e] Multiple sources are used to build bpfcc * [4d67dd6] Update d/copyright reflecting about new sources * [040e9cc] Drop python2 support * [5f5de07] Instruct dh_python3 to explicitly set shebang * [fc28e57] Bump debhelper compatibility to 12 * [cb25f1d] Add Rules-Requires-Root stanza in d/control * [b266b16] Use canonical URI * [83e6674] Bump Standards Version to 4.4.1 * [c471de9] Ship libs for libbcc_bpf.so * [e3195c0] Add details about license * [d144eba] Use DEB_BUILD_MAINT_OPTIONS to skip tests bpfcc (0.8.0-4) unstable; urgency=medium . * [6bb6080] Fix .so and its symlink in their respective pacakges. Thanks to Vincent Bernat bpfcc (0.8.0-3) unstable; urgency=medium . * [ae23e3f] Restrict architectures to what is currently buildable bpfcc (0.8.0-2) unstable; urgency=medium . * [b8a9b76] Add .pc and .so files in -dev package. Thanks to Vincent Bernat (Closes: #921188) * [c1424ff] Set architecture dependent for the development package bpfcc (0.8.0-1) unstable; urgency=medium . * [5228c2f] Add debian/watch file. Thanks to Michael Prokop * [1f9bead] Add debian/gbp.conf file * [b172968] New upstream version 0.8.0 * [ad863b4] Drop patch fix-uint128-build-failure.patch Not needed anymore bpfcc (0.7.0-2) unstable; urgency=medium . * Disable parallel builds. Thanks to Adrian Bunk and Bernhard Schmidt (Closes: #913609) bpfcc (0.7.0-1) unstable; urgency=medium . [ Ondřej Nový ] * d/copyright: Use https protocol in Format field * d/changelog: Remove trailing whitespaces . [ Ritesh Raj Sarraf ] * New upstream version 0.7.0 * Drop the (now)unnecessary --parallel argument bpfcc (0.6.0-2) unstable; urgency=medium . * Drop patch force-using-clang-4.0.diff (Closes: #906974) bpfcc (0.6.0-1) unstable; urgency=medium . * Bump to debhelper compatibility 11 * Install files to all packages * Switch packaging repository to Salsa * New upstream version 0.6.0 * Drop patch build-for-multiple-python-installations.diff. Merged upstream bpfcc (0.5.0-5) unstable; urgency=medium . * Add python3 bpfcc package. Thanks to Andreas Gerstmayr * Add python3-distutils to build dependency (Closes: #893434) * Add missing debian documents (Closes: #891035) bpfcc (0.5.0-4) unstable; urgency=medium . * Check for file type before renaming (Closes: #890686) bpfcc (0.5.0-3) unstable; urgency=medium . * Extend libbpfcc to ppc64 too. And restrict bpfcc-lua to amd64 only bpfcc (0.5.0-2) unstable; urgency=medium . * Really enable some 64bit architectures. We'll extend to other architectures only when upstream has readiness bpfcc (0.5.0-1) unstable; urgency=medium . * New upstream version 0.5.0 * Drop architecture support to 64bit common architectures only (Closes: #882344) bpfcc (0.4.0-1) unstable; urgency=medium . [ Edward Betts ] * correct spelling mistake . [ Ritesh Raj Sarraf ] * Fix FTBFS with clang 4.0. Thanks to Sylvestre Ledru (Closes: 882160) * New upstream version 0.4.0 * Disable User-level Statically Defined Tracing * Fix patches * Revert "Disable User-level Statically Defined Tracing" * Check manpage file's existence. For now, this will only honor regular manpages, and not symlinks bpfcc (0.3.0-4) unstable; urgency=medium . * Add dependency on library for the development package. Thanks to Alexander Kurtz (Closes: #878922) * Revert "Add depends on linux headers package, which is a dependency for JIT" * Update README.Debian with details about dependency on running kernel development headers and debug package. Thanks to Alexander Kurtz (Closes: #878935) bpfcc (0.3.0-3) unstable; urgency=medium . * Drop netperf from build dependency. It is a non-free package * Don't parse debian/changelog. Instead rely on dpkg for it bpfcc (0.3.0-2) unstable; urgency=medium . * Add depends on linux headers package, which is a dependency for JIT compilation. Thanks to Damien R. (Closes: #877925) * Add some more build deps * Add patches to fix Lua library detection. Thanks to Damien R. (Closes: #873322) bpfcc (0.3.0-1) unstable; urgency=medium . * Restrict Lua dev package to supported architectures * New upstream version 0.3.0 bpfcc (0.2.0+git0.02884a026-2) unstable; urgency=medium . * Restrict architecture support for Lua (Closes: 864724) * Run wrap-and-sort bpfcc (0.2.0+git0.02884a026-1) unstable; urgency=medium . * [06cde45] Add Vcs URLs * [d315114] New upstream version 0.2.0+git0.02884a026 * [a82a0d3] Add a debian/README.source file * [71ecdd8] Refresh patch debian/patches/fix-install-path.patch * [b907f40] Don't ship cpp binaries. debian/patches/disable-massive-cpp-binaries.patch bpfcc (0.2.0-3) experimental; urgency=medium . * [06cde45] Add Vcs URLs * [68431db] Bump build dependency to fix build dependency on some architectures. Thanks to Breno Leitao (Closes: #853888) * [b6da2f9] Override Experimental's gcc bpfcc (0.2.0-2) unstable; urgency=medium . * [d33527e] Add libfl-dev to build dependency * [f6c75f8] Drop llvm from build deps. Doesn't need explicit mention * [b1cb3d1] Add patch to fix uint128 build failure on 32bit systems * [4ed5b02] Drop conflict on perf-tools-unstable. With the binary filenames suffixed, both packages can and should co-exist * [0321e23] Educate bpfcc build about linux-headers package split. Thanks to George Kargiotakis (Closes: #849747) * [67afd61] Change all executable filenames. Suffix names with '-bpfcc' * [ffc625a] Drop shlibs:Depends. Not needed here * [f6470d2] Document the binary name suffixes in NEWS and README.Debian bpfcc (0.2.0-1) unstable; urgency=medium . * Initial Release (Closes: #846366) Picked many of the initial packaging bits from upstream repository. Thanks. * [8cf1070] Drop shlibs depends and add python-netaddr to Depends * [a6a9fb4] Add details about files licensed under BSL * [ded0a33] Add Boost License Snippet changeme (1.2.3-4) unstable; urgency=medium . * Team Upload. . [ Debian Janitor ] * Update standards version to 4.6.2, no changes needed. . [ Sophie Brun ] * Remove useless dep python3-nose (Closes: #1070294) chromium (125.0.6422.60-1) unstable; urgency=high . * New upstream stable release. - CVE-2024-4947: Type Confusion in V8. Reported by Vasily Berdnikov (@vaber_b) and Boris Larin (@oct0xor) of Kaspersky. - CVE-2024-4948: Use after free in Dawn. Reported by wgslfuzz. - CVE-2024-4949: Use after free in V8. Reported by Ganjiang Zhou(@refrain_areu) of ChaMd5-H1 team. - CVE-2024-4950: Inappropriate implementation in Downloads. Reported by Shaheen Fazim. * d/copyright: fix instrumented_libs deletion; upstream renamed it. * d/scripts/unbundle: bundle new requirement absl_crc (which is unavailable in bookworm). * d/patches: - upstream/uint-includes.patch: drop,merged upstream. - upstream/fps-optional.patch: drop, merged upstream. - upstream/span-optional.patch: drop, merged upstream. - upstream/extractor-bitset.patch: drop, merged upstream. - upstream/atomic.patch: drop, merged upstream. - upstream/webgpu-optional.patch: drop, merged upstream. - disable/catapult.patch: refresh. - i386/angle-lockfree.patch: drop, I _think_ it's no longer needed. - upstream/ruy-include.patch: add header build fix. - upstream/vulkan-include.patch: add header build fix. - upstream/mojo-bindings-include.patch: add header build fix. - upstream/appservice-include.patch: add header build fix. - upstream/no-vector-consts.patch: add build fix; gnu libstdc++ doesn't allow const types inside vectors. - upstream/lens-include.patch: add header build fix. - bookworm/nvt2.patch: drop (replace with a better non-revert patch). - bookworm/v8-wrappable.patch: add nvt2.patch build fix replacement that just defines a single struct member. - upstream/ninja.patch: add build fix for failure triggered by ninja-1.12 (closes: #1071197). - fixes/bad-font-gc00000.patch: add formatting patch revert to make other patches easier to apply. - fixes/bad-font-gc2.patch: add a build failure fix & refresh. - fixes/bad-font-gc11.patch: add a build failure fix & refresh. . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/0001-Add-PPC64-support-for-boringssl.patch: Modify for upstream changes - third_party/0002-Add-PPC64-generated-files-for-boringssl.patch: Add pregenerated configuration for ppc64el support in BoringSSL - third_party/0002-third-party-boringssl-add-generated-files.patch: Rename to third_party/0002-Add-PPC64-generated-files-for-boringssl.patch - workarounds/HACK-debian-clang-disable-skia-musttail.patch: Refresh for upstream changes - third_party/skia-vsx-instructions.patch: Refresh for upstream changes - ffmpeg/0001-Add-support-for-ppc64.patch: Refresh for upstream changes chromium (124.0.6367.207-1) unstable; urgency=high . * New upstream security release. - CVE-2024-4761: Out of bounds write in V8. Reported by Anonymous. chromium (124.0.6367.201-1) unstable; urgency=high . * New upstream security release. - CVE-2024-4671: Use after free in Visuals. Reported by Anonymous. chromium (124.0.6367.155-1) unstable; urgency=high . * New upstream security release. - CVE-2024-4558: Use after free in ANGLE. Reported by gelatin dessert. - CVE-2024-4559: Heap buffer overflow in WebAudio. Reported by Cassidy Kim(@cassidy6564). * d/control: replace libu2f-udev recommends with udev (closes: #1070283). . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/skia-vsx-instructions.patch: fix various issues. cpulimit (3.1-1) unstable; urgency=medium . * Import upstream version 3.1. * Update years of packaging copyright. * Declare compliance with Debian Policy 4.7.0. deviceinfo (0.2.2-2) unstable; urgency=medium . * debian/control: + In B-D:, drop systemd and B-D on systemd-dev [linux-any]. (Closes: #1060537). + Bump Standards-Version to 4.7.0. No changes needed. * debian/watch: + Update file for recent GitLab changes of the tags overview page. distrobox (1.7.2.1-1) unstable; urgency=medium . * New upstream version 1.7.2.1 evince (46.1-1) unstable; urgency=medium . * New upstream release ft2-clone (1.84+ds-1) unstable; urgency=medium . * New upstream version. galvani (0.35-1) unstable; urgency=medium . * New upstream version. gdk-pixbuf (2.42.12+dfsg-1) unstable; urgency=high . * Team upload * New upstream release - Reject malformed .ani files, including one category that can cause memory corruption (CVE-2022-48622) * d/rules: Keep .ani, .bmp, .icns, .ico, .pnm, .qtif, .tga, .xbm, .xpm loaders enabled for now. They are weakly maintained, and no longer enabled by default upstream to reduce security exposure, but disabling them would be a feature regression, which we shouldn't do in the same upload as a security fix. * d/rules: Disable miscellaneous loaders for the udeb, which as far as we know only needs PNG support * d/copyright: Pre-generated HTML documentation no longer needs excluding * Set high urgency for security fix gmenuharness (0.1.4-7) unstable; urgency=medium . * debian/watch: + Update file for recent GitLab changes of the tags overview page. * debian/control: + Bump Standards-Version to 4.7.0. No changes needed. gnome-maps (46.11-1) unstable; urgency=medium . * New upstream release gnome-text-editor (46.3-1) unstable; urgency=medium . * New upstream release golang-github-iovisor-gobpf (0.2.0-6) unstable; urgency=medium . * Update d/copyright. (Closes: #1052916) * Update standards version to 4.6.2, no changes needed. * Update lintian overrides. golang-github-iovisor-gobpf (0.2.0-5) unstable; urgency=medium . * Backport support-for-new-bcc_func_load-signature.patch from upstream for handling bpfcc > 0.24.0. golang-github-iovisor-gobpf (0.2.0-4) unstable; urgency=medium . * Fix golang-github-iovisor-gobpf-dev depends: - add libbpfcc-dev golang-github-iovisor-gobpf (0.2.0-3) unstable; urgency=medium . * Fix configuration of autopkgtest architectures restriction. golang-github-iovisor-gobpf (0.2.0-2) unstable; urgency=medium . * Restrict autopkgtest architectures to those where libbpfcc-dev is available. * lintian: ignore tests/dummy*.o files. * Install examples. * Update standards version to 4.6.1, no changes needed. golang-github-iovisor-gobpf (0.2.0-1) unstable; urgency=medium . * Initial release (Closes: #1014634). * Update copyrights. golang-github-lucas-clemente-quic-go (0.38.2-2) unstable; urgency=medium . * Team Upload * Backport patch to fix loop variable for Go 1.22 (Closes: #1066780) golang-github-pborman-getopt (2.1.0-1) unstable; urgency=medium . * d/control: Bump standards version to 4.7.0 (no change). * New upstream version 2.1.0 iniparser (4.2.1-1) unstable; urgency=medium . * New upstream version 4.2.1 * debian/control: Homepage: Reflect upstream move to gitlab * debian/copyright: Source: Reflect upstream move to gitlab * debian/u/metadata: Reflect upstream move to gitlab * debian/watch: Move watch URL to gitlab.com hosting releases * Mark cmake support patach as forwarded upstream jgit (6.7.0-1) unstable; urgency=medium . * Team upload * New upstream version 6.7.0: - Fixes CVE-2023-4759 (Closes: #1055853) * Refreshing patches * Raising Standards version to 4.7.0 (no change) * Updating build-dependencies and Maven rules * Updating the list of pom.xml files to ignore * Building the package with javac instead of the eclipse compiler * Setting the versions of the Debian-packaged Maven plugins for the build * Skipping the generation of unneeded artifacts with maven-antrun-plugin * Trim trailing whitespace in d/control langtable (0.0.66-1) unstable; urgency=medium . * Team upload. * New upstream release. libauthen-webauthn-perl (0.003-1) unstable; urgency=medium . * Import upstream version 0.003. * Update debian/copyright * Declare compliance with policy 4.7.0 * Drop spelling-error patch libcompress-snappy-perl (0.25+ds-1) unstable; urgency=medium . * New upstream version 0.25+ds * Bump copyright years. libeconf (0.6.3+dfsg1-1) unstable; urgency=medium . * New upstream release. * List static library in debian/not-installed libhdr-histogram (0.11.8-1) unstable; urgency=medium . * Initial release (Closes: #1070643) libmina-sshd-java (2.12.1-2) unstable; urgency=medium . * Source-only upload to unstable libmina-sshd-java (2.12.1-1) experimental; urgency=medium . * Initial release (Closes: #683639) libnet-kafka-perl (1.06-2) unstable; urgency=medium . * No-change source-only re-upload. libnet-kafka-perl (1.06-1) unstable; urgency=low . * Initial release (closes: #1071228). libpdl-ccs-perl (1.23.23-1) unstable; urgency=medium . * Team upload. * New upstream release. * Use dh-sequence-pdl for dh_pdl. * Enable Salsa CI. * Update copyright file. libsecp256k1 (0.5.0-2) unstable; urgency=medium . * Team upload * Move to pkgconf libsecp256k1 (0.5.0-1) experimental; urgency=medium . * Team upload * New upstream version 0.5.0 (Closes: #1065745) libstatistics-r-perl (0.34-2) unstable; urgency=medium . * Team upload. * debian/watch: use uscan version 4. * Fix maintainer address. * Don't install README (duplicate of POD and manpage). * Mark package as autopkgtest-able. * Declare compliance with Debian Policy 4.7.0. * Set Rules-Requires-Root: no. * Bump debhelper-compat to 13. * Annotate test-only build dependencies with . * Refresh debian/copyright formatting. * Update CPAN URLs in debian/*. * Add more test and runtime dependencies. log4cxx (1.2.0-1) unstable; urgency=medium . * New upstream release. * Do not load the doxygen logo from the Internet when viewing the documentation -- avoiding a privacy issue for the user. * Bump SV to 4.7.0 - no changes required. * Suggest pkgconf instead of pkg-config for the -dev package. lomiri-wallpapers (20.04.0-4) unstable; urgency=medium . * debian/watch: + Update file for recent GitLab changes of the tags overview page. * debian/control: + Bump Standards-Version to 4.7.0. No changes needed. lomiri-weather-app (5.13.5-2) unstable; urgency=medium . * Re-upload source-only as is. lomiri-weather-app (5.13.5-1) unstable; urgency=medium . * Initial release to Debian. (Closes: #1070400). luma.core (2.4.2-1) unstable; urgency=medium . * [a613a30] New upstream version 2.4.2. (Closes: #1069393) * [a79ca78] Update patch * [147c9c2] Trim trailing whitespace. mdit-py-plugins (0.4.1-1) unstable; urgency=medium . * New upstream version * Standards-Version: 4.7.0 (routine-update) * d/control: Update my contact information. meshsdfilter (1.0+1gitb81411-2) unstable; urgency=medium . * Rebuild against new ABI for libopenmesh-dev node-caniuse-db (1.0.30001620-1) unstable; urgency=medium . * Team upload * New upstream version 1.0.30001620 node-nouislider (15.7.2+ds-1) unstable; urgency=medium . * New upstream release. * debian/control - Bump Standards-Version to 4.7.0. * debian/copyright - Update my copyright years. nova (2:29.0.1-6) unstable; urgency=medium . * Add genisoimage to python3-nova depends. nova (2:29.0.1-5) unstable; urgency=medium . * Removed depends on python3-amqplib. nova (2:29.0.1-4) unstable; urgency=medium . * Restrict autopkgtest to Architecture: amd64 arm64 ppc64el. nova (2:29.0.1-3) unstable; urgency=medium . * Updated es.po debconf template, thanks to Camaleón (Closes: #1029028). nova (2:29.0.1-2) unstable; urgency=medium . * Removed (build-)depends on python3-os-win. nova (2:29.0.1-1) unstable; urgency=medium . * New upstream release. * Uploading to unstable. nova (2:29.0.0~rc1-1) experimental; urgency=medium . * New upstream release. * Fixed (build-)depends for this release. * Rebased remove-svg-converter-from-doc-conf.py.patch. * Removed removed-actdiag-from-doc.patch. * Blacklist TestObjectVersions.test_versions as hashes changed. nova (2:28.0.0-2) unstable; urgency=medium . * Add oslo.db and os_vif namespaces when generating nova.conf. nova (2:28.0.0-1) unstable; urgency=medium . * New upstream release. * Uploading to unstable. nova (2:28.0.0~rc1-1) experimental; urgency=medium . * New upstream release. * Fixed (build-)depends for this release. * Removed CVE-2023-2088 patch applied upstream. * Cleans better. nova (2:27.0.0-6) unstable; urgency=medium . * Added graphviz as build-depends. * Dump sphinxdoc build error. * Add removed-actdiag-from-doc.patch. nova (2:27.0.0-5) unstable; urgency=medium . * Uploading to unstable. nova (2:27.0.0-4) experimental; urgency=medium . * Closing the correct bug and fix patch header (Closes: #1035981). nova (2:27.0.0-3) experimental; urgency=medium . * Remove deprecated / removed options from nova-compute-ironic.conf. * CVE-2023-2088: Unauthorized volume access through deleted volume attachments. Applied upstream patch: Add force to os-brick disconnect. (Closes: #1035978). nova (2:27.0.0-2) experimental; urgency=medium . * Build-depends on openstack-pkg-tools (>= 123~). nova (2:27.0.0-1) experimental; urgency=medium . * New upstream release. nova (2:27.0.0~rc1-1) experimental; urgency=medium . * New upstream release. * Removed (build-)depends versions when satisfied in Bookworm. * Removed breaks / replaces not relevant after Bookworm. * Removed lsb-base depends. * Fixed (build-)depends for this release. nova (2:26.1.0-4) unstable; urgency=high . * Remove deprecated / removed options from nova-compute-ironic.conf. * CVE-2023-2088: Unauthorized volume access through deleted volume attachments. Applied upstream patch: Add force to os-brick disconnect. (Closes: #1035981). nova (2:26.1.0-2) unstable; urgency=medium . * Build-depends on openstack-pkg-tools (>= 123~). nova (2:26.1.0-1) unstable; urgency=medium . * New upstream release. * Removed cve-2022-47951-nova-stable-zed.patch applied upstream. nova (2:26.0.0-6) unstable; urgency=high . * CVE-2022-47951: By supplying a specially created VMDK flat image which references a specific backing file path, an authenticated user may convince systems to return a copy of that file's contents from the server resulting in unauthorized access to potentially sensitive data. Add upstream patch cve-2022-47951-glance-stable-zed.patch (Closes: #1029561). nova (2:26.0.0-5) unstable; urgency=medium . * Kill the nova-volume transition package. nova (2:26.0.0-4) unstable; urgency=medium . * Removed python3-pypowervm as (build-)depends. nova (2:26.0.0-2) unstable; urgency=medium . * Black list a unit test that gets stuck (Closes: #1022733): - SupportDirectIOTestCase.test_supports_direct_io_with_exception_in_open - SupportDirectIOTestCase.test_supports_direct_io_with_exception_in_write nova (2:26.0.0-1.1) unstable; urgency=medium . * Non-maintainer upload. * No source change upload to rebuild with debhelper 13.10. nova (2:26.0.0-1) unstable; urgency=medium . * New upstream release. nova (2:26.0.0~rc1-3) unstable; urgency=medium . * Uploading to unstable. nova (2:26.0.0~rc1-2) experimental; urgency=medium . * Add --namespace oslo.limit when generating nova.conf. nova (2:26.0.0~rc1-1) experimental; urgency=medium . * New upstream release. * Fixed (build-)depends for this release. * Removed remove-crashing-blockdiag-doc-line.patch: not needed anymore. * Rebased Add-a-healtcheck-url.patch. * Removed remove-dataclasses-requirements.txt.patch not needed anymore. * Removed Make_test_wait_for_instance_event_test_time_independent.patch applied upstream. * Removed Add_a_proper_schema_version_to_network_data.json.patch applied upstream. * Removed debian/patches/Fix_compatibility_with_jsonschema_4.x.patch applied upstream. nova (2:25.0.1-3) unstable; urgency=medium . * Also skip open redirect tests in autopkgtest. nova (2:25.0.1-2) unstable; urgency=medium . * Skip open redirect tests, as this is affected by a change in the Python 3.10.6 standard library. Note I reported the issue upstream in launchpad with the ID 1986545 (Closes: #1017217). nova (2:25.0.1-1) unstable; urgency=medium . * New upstream release. nova (2:25.0.0-6) unstable; urgency=medium . * Add Add_a_proper_schema_version_to_network_data.json.patch. * Add Fix_compatibility_with_jsonschema_4.x.patch. nova (2:25.0.0-5) unstable; urgency=medium . * Add swtpm as dependency of nova-compute-{kvm,qemu}. * Add Make_test_wait_for_instance_event_test_time_independent.patch (Closes: #1013410). nova (2:25.0.0-4) unstable; urgency=medium . * Autopkgtest: also blacklist test that fails on s390x: - LibvirtISERVolumeDriverTestCase\.test_get_transport nova (2:25.0.0-3) unstable; urgency=medium . * Autopkgtest: blacklist some unit tests that are failing. nova (2:25.0.0-2) unstable; urgency=medium . * Fix autopkgtest Depends:. nova (2:25.0.0-1) unstable; urgency=medium . * New upstream release. nova (2:25.0.0~rc1-2) unstable; urgency=medium . * Uploading to unstable. nova (2:25.0.0~rc1-1) experimental; urgency=medium . * New upstream release. * Fixed (build-)depends for this release. * nova-compute: add depends on ovmf, to support UEFI in instances. * d/control: remove all trances of nova-compute-uml, as it's now only in oldoldoldstable. * Add autopkgtest. * Refreshed remove-dataclasses-requirements.txt.patch. nova (2:24.0.0-2) unstable; urgency=medium . * Blacklist test_temporary_chown which is expected to fail under a packaging environement (Closes: #1002426). * Add remove-dataclasses-requirements.txt.patch. nova (2:24.0.0-1) unstable; urgency=medium . * New upstream release. nova (2:24.0.0~rc1-4) unstable; urgency=medium . * Uploading to unstable. nova (2:24.0.0~rc1-3) experimental; urgency=medium . * Comment out deprecated policies, otherwise, Nova doesn't work. nova (2:24.0.0~rc1-2) experimental; urgency=medium . * Fixed MANIFEST.in not including migrate.cfg. nova (2:24.0.0~rc1-1) experimental; urgency=medium . * New upstream release. * Fixed (build-)depends for this release. * Fixed oslo.config namespaces when generating config file. * Do touch nova/db/api/__init__.py in d/rules until https://review.opendev.org/c/openstack/nova/+/809980 is merged. * Do not manually copy nova/db/sqlalchemy/migrate_repo/migrate.cfg as upstream switched to Alembic. nova (2:23.0.2-3) unstable; urgency=medium . * Do not maintain glance_api_servers through debconf (as the default of reading its URL in the Keystone catalogue is better). * Upload to unstable. nova (2:23.0.2-1) experimental; urgency=medium . * New upstream release. nova (2:23.0.1-1) experimental; urgency=medium . * New upstream version nova (2:23.0.0-1) experimental; urgency=medium . * Do not set [glance]/api_servers http://localhost:9292 as default. * New upstream release. * Fixed (build-)depends for this release. nova (2:23.0.0~rc1-1) experimental; urgency=medium . * Tune nova-api-{,metadata-}uwsgi.ini for performance. * New upstream release. * Removed (build-)depends versions when satisfied in Bullseye. * Fixed (build-)depends for this release. * Removed clean-up-build_requests-table-on-upgrades.patch. nova (2:22.0.1-2) unstable; urgency=medium . * Add depend on python3-q-text-as-data (Closes: #990705). * Do not set [glance]/api_servers http://localhost:9292 as default: let Nova figure it out from the Keystone catalogue. nova (2:22.0.1-1) unstable; urgency=medium . * New upstream point release. nova (2:22.0.0-3) unstable; urgency=medium . * Exclude a number of tests which are failing under non-i386 buildd (Closes: #976590, #976954). See LP bug: 1909972. nova (2:22.0.0-2) unstable; urgency=medium . * Rename old policy.json instead of deleting it. * Set DEB_BUILD_OPTIONS: nocheck DEB_BUILD_PROFILES: nocheck in the debian/salsa-ci.yml file. * Do not package /etc/nova/policy.json. nova (2:22.0.0-1) unstable; urgency=medium . * New upstream release. * Fix version depends on qemu (as Nova requires min 4.0 now). * Uploading to unstable. * Fixed debian/watch. * Add a debian/salsa-ci.yml. nova (2:22.0.0~rc1-1) experimental; urgency=medium . * New upstream release. * Fixed (build-)depends for this release. * Removed fix-requirements.txt.patch. * Switched to yaml policy file. nova (2:21.1.0-2) unstable; urgency=medium . * Add dosfstools as depends to nova-compute, needed for ephemeral storage. nova (2:21.1.0-1) unstable; urgency=medium . * Replaced Suggests: python3-pygresql by python3-psycopg2 (Closes: #964473). * Runtime depends on qemu-system instead of just qemu (Closes: #966264). * New upstream release. nova (2:21.0.0-3) unstable; urgency=medium . * Blacklist NovaProxyRequestHandlerTestCase.test_tcp_rst_no_compute_rpcapi(). Note the other unit test were repaired by the oslo.utils 4.1.1-4. (Closes: #963339). nova (2:21.0.0-2) unstable; urgency=medium . * Add missing --namespace oslo.privsep when generating nova.conf. nova (2:21.0.0-1) unstable; urgency=medium . * New upstream release. nova (2:21.0.0~rc2-1) unstable; urgency=medium . * Also generate a policy.yaml example. * Add Add-a-healtcheck-url.patch. * New upstream release. * Uploading to unstable. nova (2:21.0.0~rc1-3) experimental; urgency=medium . * Add cgroup-tools as depends for nova-compute to allow Cinder QoS. * Correctly install systemd .service units. nova (2:21.0.0~rc1-2) experimental; urgency=medium . * Build-Depends on python3-oslotest >= 4.2.0, as building with 4.1.0 fails. nova (2:21.0.0~rc1-1) experimental; urgency=medium . * New upstream release. * Fixed (build-)depends for this release. * Rebased remove-svg-converter-from-doc-conf.py.patch. * Removed --with systemd from debian/rules. * Kill the xenvnc console proxy from nova-consoleproxy, and the nova-console package, as these are gone from upstream. * Kill some remainings of nova-network. * Removed installation of etc/nova/rootwrap.d/api-metadata.filters, as file doesn't exist anymore (probably switched to privsep). nova (2:20.1.1-1) unstable; urgency=medium . * New upstream point release. * Ran debconf-updatepo. nova (2:20.0.0-5) unstable; urgency=medium . * Do not fail nova-common.config when searching for DEFROUTE_IP and none is found. nova (2:20.0.0-4) unstable; urgency=medium . * Updated nl.po debconf translations (Closes: #945027). * Fallback to using hostname -i when searching for my-ip, as if using a network setup with BGP, searching for default if doesn't work. nova (2:20.0.0-3) unstable; urgency=medium . * Fix nova-xenvncproxy.init.in - Missing Should-start - Missing Should-stop - Caused service unit file was generated incorrect nova (2:20.0.0-2) unstable; urgency=medium . [ Ondřej Nový ] * Run wrap-and-sort -bastk. * Bump Standards-Version to 4.4.1. . [ Thomas Goirand ] * Uploading to unstable. nova (2:20.0.0-1) experimental; urgency=medium . [ Thomas Goirand ] * Updated de.po debconf translation (Closes: #940260). * Updated da.po debconf translation (Closes: #923121). . [ Michal Arbet ] * New upstream version . [ Svein-Erik Skjelbred ] * Local changes to remedy errors/weknesses in nova-common.postinst.in and nova-common.prerm (Closes: #930999). nova (2:20.0.0~rc1-3) experimental; urgency=medium . * Remove bpython, ipython and git build-depends (Closes: #939014). nova (2:20.0.0~rc1-2) experimental; urgency=medium . * Do not attempt to copy placement-policy.json in postinst. nova (2:20.0.0~rc1-1) experimental; urgency=medium . * New upstream release. * Fixed (build-)depends for this release. * Refreshed remove-crashing-blockdiag-doc-line.patch. * Add fix-requirements.txt.patch. * Temporarily removed python3-sphinxcontrib.svg2pdfconverter, as it depends on inkscape which is currently broken in Experimental. Also patch the conf.py to remove that dependency. * Removed nova-placement-api package. This is gone upstream in the favor of the separate placement service. * Removed the nova-cells package, init script and /usr/bin service, as the Nova Cells v1 is now removed from Nova. * Removed the nova-consoleauth package, init script and /usr/bin service, as this is also removed from Nova in Train. nova (2:19.0.2-4) unstable; urgency=medium . * Set dmidecode as recommends only, because it's not available on all platforms. nova (2:19.0.2-3) unstable; urgency=medium . * Switch nova-api and nova-api-metadata to uwsgi. - Add 2 ini files for uwsgi. - Nova-api now carries 2 .init.in files. - Removed debconf template for API selections. - add more dh_installinit overrides. - add python3-pastescript and uwsgi-plugin-python3 as depends. - Remove enabled API management from maintainer scripts. nova (2:19.0.2-2) unstable; urgency=medium . * Black list these until the launchpad bug 1841667 is fixed: - LibvirtDriverTestCase.test_get_disk_xml - LibvirtConnTestCase.test_detach_volume_with_vir_domain_affect_live_flag - LibvirtConnTestCase.test_update_volume_xml nova (2:19.0.2-1) unstable; urgency=medium . * New upstream version * Remove upstream applied patches: - CVE-2019-14433_Replace_non-nova_server_fault_message.patch - fix-python3-compatibility-ceph.patch * Fix lintian syntax-error-in-debconf-template templates nova (2:19.0.1-1) unstable; urgency=medium . [ Ondřej Nový ] * Use debhelper-compat instead of debian/compat. * Bump Standards-Version to 4.4.0. . [ Michal Arbet ] * Fix bug when package was installed noninteractive and auth_url in placement/neutron section was changed * Update pofiles * New upstream version * Remove upstream applied patch - debian/patches/Workaround_missing_RequestSpec.instance_group.uuid.patch nova (2:19.0.0-4) unstable; urgency=medium . * Uploading to unstable. nova (2:19.0.0-3) experimental; urgency=medium . * Add upstream patch to fix broken request_spec, which in certain cases lead to breaking instance migration: - Workaround_missing_RequestSpec.instance_group.uuid.patch nova (2:19.0.0-2) experimental; urgency=medium . * d/control: - Bump openstack-pkg-tools to version 99 * d/copyright: Update year for my line nova (2:19.0.0-1) experimental; urgency=medium . * New upstream release. nova (2:19.0.0~rc1-1) experimental; urgency=medium . * New upstream release. * Fixed (build-)depends for this release. * Removed revert-restore-async-keyword.patch, not needed anymore. * Refreshed other patches. * Do not call python3-oslo*, but directly the installed binary. nova (2:18.1.0-6) unstable; urgency=medium . * Add upstream patch to fix broken request_spec, which in certain cases lead to breaking instance migration: - Workaround_missing_RequestSpec.instance_group.uuid.patch nova (2:18.1.0-5) unstable; urgency=medium . * Revert using uwsgi for nova-api: this breaks the metadata server. nova (2:18.1.0-4) unstable; urgency=medium . * Use uwsgi for nova-api. nova (2:18.1.0-2) unstable; urgency=medium . * Add fix-python3-compatibility-ceph.patch * Update debconf template translations, with thanks to: - German: Helge Kreutzmann (Closes: #919423) - Dutch: Frans Spiesschaert (Closes: #920430) nova (2:18.1.0-1) unstable; urgency=medium . * New upstream release. nova (2:18.0.3-5) unstable; urgency=medium . * Update debconf template translations, with thanks to: - French: Alban Vidal (Closes: #915285). - Dutch: Frans Spiesschaert (Closes: #914535). - Portuguese: Traduz PT (Closes: #914427). - German: Chris Leick (Closes: #914385). nova (2:18.0.3-4) unstable; urgency=medium . * d/control: Bump openstack-pkg-tools 89 * d/control: Add python3-openstackclient dependency nova (2:18.0.3-3) unstable; urgency=medium . * d/rules: - Create NOVA_CONF variable to reduce a code - Add some placement defaults * d/nova-common.config.in: d/nova-common.postinst.in: - Add placement configuration - Add placement user creation (Closes: #913478) * d/nova-common.templates.in: Add placement questions * Update po files nova (2:18.0.3-2) unstable; urgency=medium . * d/rules: Change neutron auth_url port default to 5000 * d/nova-common.config.in d/nova-common.postinst.in d/nova-common.templates.in - Fix glance api_servers config by debconf (Closes: #913126) - Fix neutron auth_url point to ksat-public-ip (Closes: #913127) nova (2:18.0.3-1) unstable; urgency=medium . * Add debconf config for cinder os_region_name * d/rules: make regionOne default value for os_region_name * d/copyright: Add me to copyright file * Update pofiles * New upstream version nova (2:18.0.1-2) unstable; urgency=medium . [ Michal Arbet ] * d/nova-api-postinst.in: - Add calling nova-common's trigger nova-common-db-sync * - Add calling "nova-manage cell_v2 map_cell0" * - Add calling "nova-manage cell_v2 create_cell --name=cell1" * d/nova-api.postrm: - Redesigned to nova-api.postrm.in * d/nova-api.prerm: - Add deletion of nova_api database * d/nova-common.postinst.in - Add function run_db_sync - Add function create_cell0_database if configured via dbconfig-common - Changed postinst to call create_cell0_database and after that run_db_sync - Add if clause triggered which calls nova-common-db-sync * d/nova-common.postrm.in: - Add deletion of /etc/nova/placement-policy.json (Closes: #909115) - Add deletion of nova_cell0 database if configured * d/nova-common.triggers: - Add nova-common-db-sync trigger * d/nova-placement-api.config.in - Add creation of placement db which is currently not required in rocky, but now it is possible to do it with dbconfig-common * d/nova-placement-api.postrm.in - Add purging dbc config * d/nova-placement-api.prerm - Add deletion of placement database * d/rules: - Add deletion of __pychache__ in dh_clean - Add pkgos-merge-templates of nova-placement-api nova (2:18.0.1-1) unstable; urgency=medium . * New upstream release. * Remove Dont_persist_zero_allocation_ratios_in_ResourceTracker.patch applied upstream. * Add revert-restore-async-keyword.patch. * (build-)depends on oslo.db to ensure we have async removal. nova (2:18.0.0-1) unstable; urgency=medium . [ Thomas Goirand ] * New upstream release. * Add --namespace osprofiler when generating nova.conf. * Also generate placement-policy.json and install it in postinst. * Add Add_debug_logs_for_when_provider_inventory_changes.patch. * Add Log_the_operation_when_updating_generation_in_ProviderTree.patch. * Add Avoid-spurious-ComputeNode.save-during-update_available_resource.patch. * Add python3-ceph runtime depends. Note: this is for the moment incompatible with Sid that doesn't have it. * Fixed (build-)depends for this release. * Removed patches applied upstream, refresh others: - Fix_PatternPropertiesTestCase_for_py3.6.patch - fix-async-as-keyword.patch - make-nova-reproducible.patch * Add Dont_persist_zero_allocation_ratios_in_ResourceTracker.patch. * Blacklist all XenAPI and hacking tests, as some are failing. See launchpad bugs #1790850 and #1790849. * Diabled PatternPropertiesTestCase.test_validate_patternProperties_fails() and CreateInstanceTypeTest.test_name_with_non_printable_characters() as it fails as well and is unlikely to have an impact in production. See launchpad bug https://bugs.launchpad.net/nova/+bug/1790847. . [ Ondřej Nový ] * d/control: Use team+openstack@tracker.debian.org as maintainer nova (2:17.0.3-13) unstable; urgency=medium . * Fixed init script description. * Add fix-async-as-keyword.patch, fix fails to install with Python 3.7 because of async keyword (Closes: #904587). nova (2:17.0.3-12) unstable; urgency=medium . * Refreshed patches. * Add make-nova-reproducible.patch (Closes: #892420). nova (2:17.0.3-11) unstable; urgency=medium . * Add missin rights in nova-common.sudoers: - nova ALL = (root) NOPASSWD: /usr/bin/privsep-helper * nova (2:17.0.3-10) unstable; urgency=medium . * Removed euca2ools from build-depends. * Do not call dh_auto_clean, use python3 setup.py clean. nova (2:17.0.3-9) unstable; urgency=medium . * Fixed startup description. * Switched to openstack-pkg-tools >= 80~ UWSGI handling, adding ipv6 support. nova (2:17.0.3-8) unstable; urgency=medium . * Fix again nova-placement-api init script. nova (2:17.0.3-7) unstable; urgency=medium . [ Michal Arbet & Thomas Goirand ] * Enable SSL support for nova-placement-api, and use a uwsgi .ini file, which is a way more convenient for deployer to use rather than editing /etc/init.d/nova-placement-api. nova (2:17.0.3-6) unstable; urgency=medium . * Add qemu-block-extra as runtime depends to nova-compute-{qemu,kvm}. nova (2:17.0.3-5) unstable; urgency=medium . * Switch to Type=notify for nova-{api,cells,compute,consoleauth,scheduler}. nova (2:17.0.3-4) unstable; urgency=medium . * nova-placement-api runtime depends on uwsgi-python3, not python 2. nova (2:17.0.3-3) unstable; urgency=medium . * Add dmidecode as runtime depends, needed by compute node for libvirt. nova (2:17.0.3-2) unstable; urgency=medium . * Add --rem-header Content-Lenght when starting the nova-placement-api uwsgi daemon, as otherwise, we get a 104 error (connection reset by peer). nova (2:17.0.0-4) unstable; urgency=medium . * Better default values for [neutron] section. * Correctly read/write [neutron] config. * Fixed dbc postrm. nova (2:17.0.0-2) unstable; urgency=medium . * Fixed nova-placement-api must use uwsgi_python3 not uwsgi_python. nova (2:17.0.0-1) unstable; urgency=medium . * New upstream release. * Fix keystone_authtoken defaults. * Removed double-defined override_dh_python3. * Switched to openstack-pkg-tools >= 70~ provided debconf templates. * Using policy.json generated with --format json. * Add Breaks:+Replaces: python-nova (Closes: #891681). nova (2:17.0.0~rc1-2) unstable; urgency=medium . * Uploading to unstable. nova (2:17.0.0~rc1-1) experimental; urgency=medium . [ Ondřej Nový ] * d/control: Set Vcs-* to salsa.debian.org . [ Thomas Goirand ] * New upstream release. * Fixed (build-)depends for this release. * Removed patches applied upstream: - Add_nova-idmapshift_to_rootwrap_filters.patch - Fix_quobyte_test_validate_volume_no_mtab_entry.patch - CVE-2017-16239_Refined_fix_for_validating_image_on_rebuild.patch - CVE-2017-17051_Fix_doubling_allocations_on_rebuild.patch * Using pkgos-dh_auto_test. * Removed usr/bin/nova-idmapshift (removed in Queens). * Removing debian/tmp/usr/etc after setup.py install. * Generates policy.yaml using oslopolicy-sample-generator. * Standards-Version is now 4.1.3. * Some clean-up in debian/rules. * Switched to Python 3. * Make sure service files are generated for consoleproxi daemons. * nova-common.config: do not use /sbin/route, cat in /proc instead. nova (2:16.0.3-10) unstable; urgency=medium . * Add explicit dependency on e2fsprogs (Closes: #887212, #887188). * Updated / added debconf templates translations: - nl.po (Closes: #882650). - de.po (Closes: #885161). - fr.po (Closes: #886208). nova (2:16.0.3-9) unstable; urgency=medium . * Fixed [neutron]/tenant_name. nova (2:16.0.3-8) unstable; urgency=medium . * Rebuilt with openstack-pkg-tools >= 60~. nova (2:16.0.3-7) unstable; urgency=medium . * Rebuilt with openstack-pkg-tools >= 59~, to make sure we're using allocated UID/GID from #884178. nova (2:16.0.3-6) unstable; urgency=high . * CVE-2017-17051 / OSSA-2017-006: Nova FilterScheduler doubles resource allocations during rebuild with new image. Applied upstream patch: Fix doubling allocations on rebuild (Closes: 883621). Note: previous upload was in fact only refining the patch for addressing CVE-2017-16239, not CVE-2017-17051. This upload really fixes the bug for CVE-2017-17051. nova (2:16.0.3-5) unstable; urgency=high . * CVE-2017-17051/OSSA-2017-005.1 (errata for CVE-2017-16239/OSSA-2017-005): Nova Filter Scheduler bypass through rebuild action. Apply upstream patch: Refined fix for validating image on rebuild (Closes: #883621). nova (2:16.0.3-4) unstable; urgency=medium . * Using --paste-logger when starting uwsgi for placement-api, and runtime depends on python-pastescript. nova (2:16.0.3-3) unstable; urgency=medium . * Fixed default_floating_pool option to ext-net. * 4 workers by default for nova-placement-api. * Rebuilt with openstack-pkg-tools >= 56. * Removed dh-systemd build-depends. * Standards-Version is now 4.1.1. nova (2:16.0.3-2) unstable; urgency=medium . * Fixed arguments for nova-placement-api's uwsgi_python. nova (2:16.0.3-1) unstable; urgency=high . * New upstream release. Includes: - CVE-2017-16239 / OSSA-2017-005: Nova Filter Scheduler bypass through rebuild action. Applied upstream patch: Validate new image via scheduler during rebuild (Closes: #882009). * Add Fix_quobyte_test_validate_volume_no_mtab_entry.patch. nova (2:16.0.1-3) unstable; urgency=medium . * Add missing source of debconf script in nova-placement-api.postinst. nova (2:16.0.1-2) unstable; urgency=medium . * Fixed nova-xenvncproxy init script syntax (Closes: #863165). * Using uwsgi-plugin-python to run the placement-api (Closes: #875712). * Now setting-up nova-placement-api automatically with debconf. * The nova-compute daemon now runtime depends on fdisk (Closes: #872135). * Update pt.po (Closes: #873173). * Update fr.po (Closes: #874103). * Replaces nova-api endpoint /v2/'%(tenant_id)s' by /v2.1 as per upstream installation doc. * Uploading to unstable. nova (2:16.0.1-1) experimental; urgency=medium . [ Daniel Baumann ] * Updating vcs fields. * Updating copyright format url. * Updating maintainer field. * Running wrap-and-sort -bast. * Updating standards version to 4.0.0. * Removing gbp.conf, not used anymore or should be specified in the developers dotfiles. * Correcting permissions in debian packaging files. * Updating standards version to 4.0.1. * Deprecating priority extra as per policy 4.0.1. * Updating standards version to 4.1.0. . [ Thomas Goirand ] * New upstream release. * Removed nova-network. * Fixed (build-)depends for this release. * Rebased some patch, delete others. * Blacklist all nova.tests.unit.test_wsgi.TestWSGIServerWithSSL* tests. * Fix namespaces for nova.conf generation. * Generating /etc/nova/policy.yaml. * Removed nova-cert, which is also removed upstream. * Fixed mssing binaries in nova-common.install. nova (2:14.0.0-4) unstable; urgency=medium . [ David Rabel ] * Team upload. * Bump build dependency on openstack-pkg-tools (Closes: #858708, #858710). . [ Thomas Goirand ] * CVE-2017-7214: apply upstream patch (Closes: 858568). nova (2:14.0.0-3) unstable; urgency=medium . [ Ondřej Nový ] * Bumped debhelper compat version to 10 . [ Thomas Goirand ] * Allow using SQLAlchemy >= 1.1. * Fix bug that prevented generating nova-spicehtml5proxy and nova-xenvncproxy .service files. nova (2:14.0.0-1) unstable; urgency=medium . * New upstream release. nova (2:14.0.0~rc1-2) unstable; urgency=medium . [ Ondřej Nový ] * d/s/options: extend-diff-ignore of .gitreview * d/control: Use correct branch in Vcs-* fields . [ Thomas Goirand ] * Uploading to unstable. * Fixed oslotest EPOCH. nova (2:14.0.0~rc1-1) experimental; urgency=medium . * New upstream release. * Fixed (build-)depends for this release. * Using OpenStack's Gerrit as VCS URLs. * Points .gitreview to OpenStack's Gerrit packaging-deb. * Fixed nova.conf generation. * Blacklist failing test: - virt.libvirt.test_driver.LibvirtConnTestCase.test_spawn_with_config_drive * Added a nova-placement-api package & daemon. * Package /usr/bin/nova-policy in nova-common. * Added --parallel when running unit tests. * Revised debian/copyright holder list. nova (2:14.0.0~b2-2) experimental; urgency=medium . * Team upload. * Added python-pep8 to build depends (Closes: #834134) * (Build-)Depends on python-websockify instead of websockify nova (2:14.0.0~b2-1) experimental; urgency=medium . * New upstream release. * Fixed (build-)depends for this release. * Updated Danish translation of the debconf (Closes: #830630). nova (2:14.0.0~b1-2) experimental; urgency=medium . * Fixed correct path for $pybasedir. * Fixed bindir to /usr/bin. * Fixed use_neutron to True by default. * Fixed api_servers to http://localhost:9292 by default. * Rebuilt with openstack-pkg-tools >= 52~ to ensure ALTER TABLE is done correctly with backquotes for the db name. nova (2:14.0.0~b1-1) experimental; urgency=medium . * New upstream release. * Fixed (build-)depends for this release. * Update the namespace list when generating nova.conf. * Adds fix-requirements.txt.patch. nova (2:13.1.0-4) unstable; urgency=medium . * Team upload. * Added python-pep8 to build depends (Closes: #834134) nova (2:13.1.0-3) unstable; urgency=medium . * Added upstream patch (Closes: #832158): Fix_NoSuchOptError_when_referring_to_conf.neutron.auth_plugin.patch nova (2:13.1.0-2) unstable; urgency=medium . * Rebuilt with openstack-pkg-tools to ensure the ALTER DATABASE is made with quotes, which is important for nova-api that has a dash by default in the db name (Closes: #827317). nova (2:13.1.0-1) unstable; urgency=medium . * New upstream release. * Add support-all-paramiko-versions.patch so that Nova continues to work with python-paramiko (>= 2). * Build-Depends: python-oslo.concurrency should be >= 3.7.1 for this release, even though upstream advertises otherwise. * Do not run broken unit test with Paramiko 2.x: test_crypto.KeyPairTest.test_generate_key_pair_mocked_private_key nova (2:13.0.0-4) unstable; urgency=medium . * Fix pybasedir to a correct value. (Closes: #827179). nova (2:13.0.0-3) unstable; urgency=medium . [ Thomas Goirand ] * Updated Japanese debconf templates translation update (Closes: #820768). * Updated Dutch debconf templates translation (Closes: #822887). * Updated Brazilian Portuguese debconf templates (Closes: #824336). . [ Ondřej Nový ] * Added Documentation to systemd units nova (2:13.0.0-2) unstable; urgency=medium . [ Ondřej Nový ] * Use /bin/sh as su shell in postinst script explicitly * Standards-Version is 3.9.8 now (no change) * Use /bin/sh as default shell for "nova" user nova (2:13.0.0-1) unstable; urgency=medium . * New upstream release. nova (2:13.0.0~rc3-1) unstable; urgency=medium . * New upstream release. * Uploading to unstable. * Updated ja.po debconf translations (Closes: #815955). nova (2:13.0.0~rc1-4) experimental; urgency=medium . * Standards-Version: 3.9.7 (no change) * Do not use keystone admin auth token anymore (and therefore, build-depends on openstack-pkg-tools >= 40~). nova (2:13.0.0~rc1-3) experimental; urgency=medium . * Fixed netron -> neutron in nova-common.postinst.in. nova (2:13.0.0~rc1-2) experimental; urgency=medium . * Added dbconfig-common management of the novaapi db. nova (2:13.0.0~rc1-1) experimental; urgency=medium . [ Ivan Udovichenko ] * d/patches: Add Install-missed-files.patch file. * d/patches/series: Remove outdated entry and add the new one. . [ Thomas Goirand ] * New upstream release. * Fix [neutron]/auth_plugin -> [neutron]/auth_type fixup, to follow the changes in upstream generated config file. * Fixed (build-)depends for this release. nova (2:13.0.0~b3-1) experimental; urgency=medium . [ Ondřej Nový ] * Fixed VCS URLs (https). . [ Thomas Goirand ] * New upstream release. * Fixed (build-)depends for this release. * Fix namespace list for generating nova.conf. nova (2:13.0.0~b2-2) experimental; urgency=medium . [ Ivan Udovichenko ] * d/rules: Binary for nova-objectstore service is not generated anymore. . [ Thomas Goirand ] * Do not use -S flag of dpkg-parsechangelog: incompatible with Trusty. * Add build-depends-indep in Git to avoid crash during sphinx doc build. * Bump EPOCH to align with Ubuntu. * Stop using hand-crafted config file, and use the generated one. * Removed ec2 from possible API activation (support for that doesn't exist anymore). nova (1:13.0.0~b2-1) experimental; urgency=medium . * New upstream release. * Fixed (build-)depends for this release. * Do not delete nova-api-ec2 (it's gone upstream...). * Fixed debian/copyright. * Using testr directly for unit tests, as run_tests.sh is now deprecated. nova (1:12.0.0-4) unstable; urgency=medium . * Added q-text-as-data as depends of nova-api. nova (1:12.0.0-3) unstable; urgency=medium . * Rebuilt with openstack-pkg-tools 37 to use Keystone API v3. nova (1:12.0.0-2) unstable; urgency=medium . * Uploading to unstable. nova (1:12.0.0-1) experimental; urgency=medium . * New upstream release. * Updated the Danish translation of the debconf templates thanks to Joe Dalton (Closes: #800397). * Updated Dutch translation of debconf messages thanks to Frans Spiesschaert (Closes: #797349). * Added rsync as a dependency for nova-compute (Closes: #801579). nova (1:12.0.0~rc1-1) experimental; urgency=medium . * New upstream release. * Now nova-api depends on python-openstackclient. * Fixed missing migrate.cfg file, preventing SQL migration to work. * Fixed (build-)depends for this release. nova (1:12.0.0~b3-1) experimental; urgency=medium . * New upstream release. * Fixed (build-)depends for this release. * Refreshed patches, deleted obsolete ones. * Fixed install of nova/locale. * Fixed install of usr/bin/nova-rootwrap-daemon. nova (1:12.0.0~b2-1) experimental; urgency=medium . * New upstream release. * Reviewed (build-)depends for this release. * Using oslo-config-generator to build the sample config file. nova (1:12.0.0~b1-1) experimental; urgency=medium . * New upstream release. * Reviewed (build-)depends for this release. * Rebased patches and removed those applied upstream. * Fixed export OSLO_PACKAGE_VERSION to not give PBR the ~ char. nova (2015.1.0-8) unstable; urgency=medium . * Allow running with SQLA 1.0.6. nova (2015.1.0-7) unstable; urgency=medium . * Still needs Breaks: + Replaces: of nova-compute-uml in nova-compute-ironic, as per Andreas Beckmann advice (Closes: #788992). nova (2015.1.0-6) unstable; urgency=medium . * Removes nova-compute-uml (is there anyone using it?). nova (2015.1.0-5) unstable; urgency=medium . * Renames service_neutron_metadata_proxy as service_metadata_proxy, as per upstream deprecation. Thanks to Mathieu Rohon for the bug report (Closes: #788815). nova (2015.1.0-4) unstable; urgency=medium . * Added hotfix from upstream: - Fix_loading_things_in_instance_extra_for_old_instances.patch - Create-instance_extra-entry-if-it-doesn_t-update.patch - Fix-max_number-for-migrate_flavor-data.patch nova (2015.1.0-3) unstable; urgency=medium . [ gustavo panizzo ] * Add a missing rootwrap filter, needed to use unprivileged lxc. . [ Thomas Goirand ] * Added bridge-utils dependency in nova-common (Closes: #786488). * Updated fr.po thanks to Julien Patriarca (Closes: #786497). nova (2015.1.0-2) unstable; urgency=medium . * Added conflicts: nova-baremetal for the nova-compute-ironic (Closes: #784294). nova (2015.1.0-1) unstable; urgency=medium . * New upstream release. nova (2015.1~rc2-1) unstable; urgency=medium . * New upstream release. * Uploading to unstable. * Reviewed (build-)depends for this release. * Removed the nova-baremetal package, since there's now Ironic. * Added a nova-conmpute-ironic package. nova (2014.2.2-4) experimental; urgency=medium . * Using port 5000 for the keystone authtoken. nova (2014.2.2-3) experimental; urgency=medium . * CVE-2015-0259: Websocket Hijacking Vulnerability in Nova VNC Server. Applied upstream patch (Closes: #780250): Websocket_Proxy_should_verify_Origin_header_juno.patch nova (2014.2.2-1) experimental; urgency=medium . * New upstream point release. nova (2014.2.1-3) experimental; urgency=medium . * Build-depends on dh-python and openstack-pkg-tools >= 22~. nova (2014.2.1-2) experimental; urgency=medium . * Now build-depends on openstack-pkg-tools (>= 20~). nova (2014.2.1-1) experimental; urgency=medium . * New upstream release. * CVE-2014-3708_Fixes_DOS_issue_in_instance_list_ip_filter_juno.patch has been applied upstream, removing it. * Added patch for removing ssl.PROTOCOL_SSLv3 from openstack/common. nova (2014.2-4) experimental; urgency=medium . * Added CVE-2014-3708_Fixes_DOS_issue_in_instance_list_ip_filter_juno.patch. nova (2014.2-3) experimental; urgency=medium . * Reworked the default nova.conf to use the new section and clean the deprecated ones. nova (2014.2-2) experimental; urgency=medium . * Added conntrack as Depends: for nova-compute. nova (2014.2-1) experimental; urgency=medium . * New upstream release. nova (2014.2~rc2-1) experimental; urgency=medium . * Fixed correct de.po (Closes: #763682). * Mangling upstream rc and beta versions in watch file. * Now using a single logrotate file in nova-common. nova (2014.2~rc1-1) experimental; urgency=medium . * New upstream release. * Added pt_BR.po Brazilian Portuguese debconf templates translation thanks to Adriano Rafael Gomes (Closes: #762472). * nova-xenvncproxy init script provides itself now. * Updated (build-)depends for this release. * Removed no-intersphinx patch (it's removed upstream). nova (2014.2~b3-1) experimental; urgency=medium . * New upstream release. * New (build-)depends for this release. * Removed nova-clear-rabbit-queues from nova-scheduler (gone from upstream). * Also package nova-serialproxy. . [ gustavo panizzo ] * Support to run nova daemons under systemd. nova (2014.1.3-11) unstable; urgency=high . * CVE-2015-0259: Websocket Hijacking Vulnerability in Nova VNC Server. Done a rebase of upstream patch, so that it can be applied on top of the websockify 0.6 support patch. The resulting patch is a mix of the Icehouse and Juno patch. (Closes: #780250). nova (2014.1.3-10) unstable; urgency=medium . * Now calling read_neutron_config() in the postinst, for some reason, it was never called. nova (2014.1.3-9) unstable; urgency=medium . * Rebuilt with openstack-pkg-tools (>= 22~): starts daemons on first install. nova (2014.1.3-8) unstable; urgency=medium . * Rebuilt with openstack-pkg-tools (>= 21~). nova (2014.1.3-7) unstable; urgency=medium . * Now init scripts depends on libvirtd and not libvirt-bin, as this has been renamed in the libvirt-daemon-system package (Closes: #772699). * Do not touch the database directive if user doesn't want to use dbconfig-common (Closes: #770941). * Updated de.po German debconf translation (Closes: #771409). * Added patch for CVE-2014-8333: Fix VM leak when deletion of VM during resizing. * Ensure we have the systemd fixes by build-depending on openstack-pkg-tools (>= 20~). * Only calls pkgos_dbc_postinst if the user asked for dbconf-common management. nova (2014.1.3-6) unstable; urgency=high . [ Mehdi Abaakouk ] * Fix a issue into fix-live-migraton-nfs.patch. . [ Thomas Goirand ] * CVE-2014-3708: Nova network DoS through API filtering. Applied upstream patch: Fixes_DOS_issue_in_instance_list_ip_filter (Closes: #769163). nova (2014.1.3-5) unstable; urgency=high . * CVE-2014-7230 & CVE-2014-7231: Potential leak of passwords into log files. Added CVE-2014-7230_CVE-2014-7231_Sync_process_utils_from_oslo.patch from upstream (Closes: #765714). nova (2014.1.3-4) unstable; urgency=medium . * Removed debian/*.init and debian/*.upstart.in from sources. nova (2014.1.3-2) unstable; urgency=medium . * Updated patchset for CEPH, thanks to Dmitry Borodaenko . * Removed contrib/boto_v6/* in debian/copyright, replaced bin/nova-manage by nova/cmd/{baremetal_,}manage.py. * Mangling upstream rc and beta versions in watch file. * Added 9990_update_german_programm_messages.patch, thanks to Helge Kreutzmann . * Fixed correct de.po (Closes: #763682). * Added nl.po initial Debconf translation, thanks to Frans Spiesschaert (Closes: #764125). * Standards-Version is now 3.9.6 (no change). nova (2014.1.3-1) unstable; urgency=medium . * New upstream release. * Rebased/refreshed patches. Some where applied upstream, so got removed. nova (2014.1.2-7) unstable; urgency=medium . * Added fix-live-migraton-nfs.patch. * Added pt_BR.po Brazilian Portuguese debconf templates translation thanks to Adriano Rafael Gomes (Closes: #762472). * nova-xenvncproxy init script provides itself now. nova (2014.1.2-6) unstable; urgency=medium . * Switching to libvirt-daemon-system instead of libvirt-bin because the libvirt package changed (Closes: #757548). nova (2014.1.2-5) unstable; urgency=medium . * Updated it.po italian Debconf template, thanks to Beatrice Torracca (Closes: #758305). * Reduced the number of lintian warnings (only cosmetic changes). nova (2014.1.2-4) unstable; urgency=medium . * Cleans the .testrepository. nova (2014.1.2-3) unstable; urgency=medium . [ Thomas Goirand ] * Added new patch for Ceph, thanks to Roman Podoliaka: 0012_CEPH_Fix_instance_boot_when_Ceph_is_used_for_ephemeral_storage.patch . [ Mehdi Abaakouk ] * Added two new fix for configdrive and ceph 0013_CEPH_uses_correct_imagebackend_for_configdrive.patch 0014_CEPH_reworks_configdrive_creation.patch nova (2014.1.2-2) unstable; urgency=medium . [ Thomas Goirand ] * Added new Ceph patch backport from Dmitry Borodaenko: 0010_CEPH_Rename_rbb.py_to_rbd_utils.py_in_libvirt_driver_directory.patch . [ Mehdi Abaakouk ] * Added new Ceph patch backport from myself patches/0011_CEPH_fix_live_migration_with_configdrive.patch nova (2014.1.2-1) unstable; urgency=medium . [ Gustavo Panizzo ] * New upstream release. * Patches refreshed. * Patch for CVE-2014-3517 removed, it was applied upstream. * Patch added to fix regression. https://review.openstack.org/#/c/112750/ . [ Thomas Goirand ] * Added new patchset from Dmitry Borodaenko to better support Ceph and NFS as backend storages. These are backports from Juno. Thanks for his work! nova (2014.1.1-8) unstable; urgency=medium . * CVE-2014-3517: analyzing response times to requests for instance metadata, an attacker may be able to guess a valid instance ID signature. Included upstream patch form the OpenStack security team, which introduces a constant time function to avoid leak (Closes: #755042). nova (2014.1.1-7) unstable; urgency=medium . * Refreshed libvirt_convert_cpu_features_attribute_from_list_to_a_set.patch. * Added spiceproxy_config_startup.patch, thanks to Gaudenz Steinlin (Closes: #754346). nova (2014.1.1-6) unstable; urgency=medium . * Updated the Danish debconf template translation, thanks to Joe Dalton (Closes: #753974). nova (2014.1.1-5) unstable; urgency=high . * Added a backport of https://review.openstack.org/#/c/91663/ to allow Nova to work with Websockify 0.6 (Closes: #752454). nova (2014.1.1-4) unstable; urgency=high . * CVE-2013-1068: Fixed sudoers file (Closes: 753579). nova (2014.1.1-1) unstable; urgency=medium . * New upstream release. * Removed both CVE-2014-2573 patches applied upstream. * Refreshed Ceph patches. nova (2014.1-10) unstable; urgency=medium . * Now build-depends on opesntack-pkg-tools >= 0.12~. nova (2014.1-9) unstable; urgency=high . * CVE-2014-2573: Nova VMWare driver leaks rescued images. Applied 2 patches from upstream (Closes: #750144). nova (2014.1-8) unstable; urgency=medium . * Switched to copytruncate instead of restart daemons for logrotate. nova (2014.1-7) unstable; urgency=medium . * Removed useless python-support Build-Depends. nova (2014.1-4) unstable; urgency=medium . * Test if /sbin/route is present before using it (Closes: #737052). nova (2014.1-3) unstable; urgency=medium . * Fixes regression in nova template wording (Closes: #745277). * Added German translation for debconf templates, thanks to Pfannenstein Erik (Closes: #745445). nova (2014.1-2) unstable; urgency=low . * Added 5 Ceph support patches. * Switched to [DEFAULT]/sql_connection to [database]/connection in the config and postinst scripts of nova-common (Close: #745551). * Added an example generated nova.conf.example file. nova (2014.1-1) unstable; urgency=medium . * New upstream release. * Uploading to unstable. nova (2014.1~rc2-1) experimental; urgency=low . * New upstream pre-release. * Fixed new configuration that goes now in the [libvirt] section. * Allow selecting log destination for Openstack daemons. * Fixed nova.conf for Icehouse. * Updated Russian debconf translation, thanks to Yuri Kozlov (Closes: #743423). nova (2014.1~rc1-1) experimental; urgency=low . [ Thomas Goirand ] * New upstream release. * Reviewed (build-)dependencies. . [ Gustavo Panizzo ] * Change the default VIF driver for kvm compute nodes. nova (2014.1~b3-1) experimental; urgency=low . * New upstream release (Icehouse beta 1). * Removed CVE-2013-4463_CVE-2013-4469 now applied upstream. nova (2013.2.3-1) unstable; urgency=medium . * New upstream release. * Removed patch applied upstream for CVE-2014-0134. * Rebase of the Ceph support patch. * CVE-2014-0167: RBAC policy not properly enforced in Nova EC2 API. Applied upstream patch: Add_RBAC_policy_for_ec2_API_security_groups_calls.patch (Closes: #744051). nova (2013.2.2-4) unstable; urgency=high . * CVE-2014-0134: Nova host data leak to vm instance in rescue mode. Applied upstream patch: CVE-2014-0134_Persist_image_format_to_a_file.patch (Closes: #742712). nova (2013.2.2-3) unstable; urgency=medium . * Rebuilt for SQLA 0.9.x. * Updated Debconf translation, with thanks to: - French, Julien Patriarca (Closes: #740224). - Danish, Joe Dalton (Closes: #739754). nova (2013.2.2-2) unstable; urgency=medium . * Rebuilt using openstack-pkg-tools >= 9~. nova (2013.2.2-1) unstable; urgency=high . [ Thomas Goirand ] * New upstream point release (Closes: #736926, #736465). * Added gustavo panizzo as uploader. * Standards-Version: is now 3.9.5. * Refreshed Ceph backport patch. . [ gustavo panizzo ] * nova-manage db sync failure is not fatal in nova-common.postinst nova (2013.2.1-6) unstable; urgency=medium . * Fix broken template given by Christian PERRIER (Closes: #738271). nova (2013.2.1-5) unstable; urgency=medium . * Updated debconf template thanks to the intl team. (Closes: #737819) nova (2013.2.1-4) unstable; urgency=medium . * Configures Neutron credentials through Debconf. * Adds a backport of Ceph support into Nova. * Restarts daemons after logrotate. nova (2013.2.1-2) unstable; urgency=medium . [ Gonéri Le Bouder ] * Add myself in Uploaders * nova-compute-kvm directly depends on qemu-kvm since kvm package doesn't exist anymore. We keep an alternative dependency on kvm to simplify backports. * build_sphinx: pass target dir as an argument to avoid the following issue with sphinx 1.2 https://bitbucket.org/birkenfeld/sphinx/pull-request/193 http://lists.openstack.org/pipermail/openstack-dev/2013-December/021863.html . [ Thomas Goirand ] * Killed the DEFAULTS_FILE feature in init scripts and template. * Updated debconf template translation, with thanks to: - Swedish: Martin Bagge (Closes: #734621). - German: Chris Leick (Closes: #735335). nova (2013.2.1-1) unstable; urgency=high . * New upstream release (Closes: #732022). This fixes: CVE-2013-7048: Nova live snapshots use an insecure local directory and CVE-2013-6419: Metadata queries from Neutron to Nova are not restricted by tenant. * Added | cut -d" " -f1 when searching for the default gateway interface, in the nova-common.config script that tries to guess the "my_ip" address, just in case there's more than one interface in use (in which case it may fail in non-interactive mode). * Updates the French debconf translation which was broken, thanks to our cheesemaster for the update (Closes: #732267). * Updates the Spanish debconf translation, thanks to jathan for this update (Closes: #732206). * Fixes requirement.txt patch (upstream now includes the python-six fix). * Removes patch applied upstream: CVE-2013-4463_CVE-2013-4469_ensure_we_dont_boot_oversized_image.patch * Fix typoe in libvirt_vif_driver (had Hybird instead of Hybrid). * Updates (build-)depends version of python-six (>= 1.4.1) and python-iso8601 (>= 0.1.8). * Removed python-argparse from python-nova depends. nova (2013.2-3) unstable; urgency=high . * Moved python-mysqldb from Recommends to Depends in python-nova. * CVE-2013-4463 & CVE-2013-4469: ensure we don't boot oversized images, applied upstream patch (Closes: #728605). * Update of some debconf translations, with warm thanks to: - French, Julien Patriarca (Closes: #728765). - Russian, Yuri Kozlov (Closes: #729711). - German, Chris Leick (Closes: #730453). nova (2013.2-2) unstable; urgency=low . * Added some Provides: for the nova-consoleproxy so that it is in line with what Ubuntu does. * Adds --log-file= for each daemons. nova (2013.2-1) unstable; urgency=low . * New upstream release. * Uploading to unstable. nova (2013.2~rc2-1) experimental; urgency=low . * New upstream release. nova (2013.2~rc1-1) experimental; urgency=low . * New upstream release. nova (2013.1.3-2) unstable; urgency=low . * Removes XCP support to allow Ocaml transition to testing until XCP is fixed and updated. * Updated fr and it Debconf translations (Closes: #721333, #722425). nova (2013.1.3-1) unstable; urgency=low . * New upstream point release. * Fixed wrong chown in upstart script (sed s/Root/root/). * Adds new debconf template translations: - Brazilian Portuguese, thanks to Adriano Rafael Gomes (Closes: #718710). - Japanese, thanks to victory (Closes: #718924). * Debconf translation updates: - Danish, thanks to Joe Dalton (Closes: #720005). - Portuguese, thanks to the Traduz team (Closes: #720315). - Czech, thanks to Michal Šimůnek (Closes: #721039). - Russian, thanks to Yuri Kozlov (Closes: #721259). * Adds iproute to nova-common depends (Closes: #719138). * Removes Make-nova-api-use-servicegroup.API.service_is_up.patch applied upstream. * Removes CVE-2013-2256_Make_flavors_is_public_option_actually_work.patch now applied upstream. * Removes CVE-2013-4185_Use_cached_nwinfo_for_secgroup_rules.patch now applied upstream. * CVE-2013-4278: Applies upstream patch (Closes: #720602). * Added patch to fix Nova networking. * Removes the nova-xcp-plugins package until we have a working XCP again in testing. nova (2013.1.2-3) unstable; urgency=low . [ Julien Cristau ] * Add logrotate configuration for nova-manage.log. . [ Thomas Goirand ] * Added some logic to purge /etc/init.d/nova-xcp-network if it's there, and have upgrade working (Closes: #718965). Thanks to Andreas Beckmann for his bug report. * CVE-2013-2256: fixes ACL on public flavors (Closes: #718905). * CVE-2013-4185: stops a potential DOS with source security groups by using cached nwinfo for secgroup rules (Closes: #718907). * Added missing nova-common pre-depends: net-tools. * Fixed upgrade of nova-xcp-network to nova-xcp-plugins (Closes: #718965). nova (2013.1.2-2) unstable; urgency=low . * Uploading to unstable (Closes: #710157, #711326, #711541, #707600). * New upstream release. * Added Should-Start/stop: postgresql mysql in init scripts (Closes: #706013) thanks to Julien Cristau for reporting. * Fixed logrotate scripts for nova-xvpvncproxy and nova-consoleauth (Closes: #706011). Thanks to Julien Cristau for reporting. * Adds memcache_convert_host_value_from_unicode_to_a_string.patch * CVE-2013-2030: Remove insecure default for signing_dir option from the api-paste.ini (Closes: #707600). * Removes memcache_convert_host_value_from_unicode_to_a_string.patch which is now applied upstream. * Moves Suggests: as Depends: for novnc and websockify for nova-novncproxy. * Merged nova-xcp* into a single binary package. * Merged NoVNC, XVP and SPICE console into a single binary package. * Now using a single log file for all types of console proxy, and logrotate that (Closes: #706011). * Ran wrap-and-sort. * Added Make nova-api use servicegroup.API.service_is_up() patch, so that nova can work with multiple redundant memecached using heartbeat. * Killed the nova-objectstore package. * testrepository build-depends is now version >= 0.0.14 * Reviewed a bit the init scripts boot dependencies, and added a few Should-Start / Should-Stop to make sure mysql, postgress and keystone are up and running. * Removed debian/python-nova.postinst, as update-python-modules --post-install is managed by dh_python2. * Added missing nova-compute dependencies in the nova-compute- packages. * Sets default security_group_api = quantum. * Starts nova after rabbit and ntp. nova (2013.1.2-1) unstable; urgency=low . * Uploading to unstable. * New upstream release. * Added Should-Start/stop: postgresql mysql in init scripts (Closes: #706013) thanks to Julien Cristau for reporting. * Fixed logrotate scripts for nova-xvpvncproxy and nova-consoleauth (Closes: #706011). Thanks to Julien Cristau for reporting. * Adds memcache_convert_host_value_from_unicode_to_a_string.patch * CVE-2013-2030: Remove insecure default for signing_dir option from the api-paste.ini (Closes: #707600). * Removes memcache_convert_host_value_from_unicode_to_a_string.patch which is now applied upstream. * Moves Suggests: as Depends: for novnc and websockify for nova-novncproxy. * Merged nova-xcp* into a single binary package. * Merged NoVNC, XVP and SPICE console into a single binary package. * Now using a single log file for all types of console proxy, and logrotate that (Closes: #706011). * Ran wrap-and-sort. * Added Make nova-api use servicegroup.API.service_is_up() patch, so that nova can work with multiple redundant memecached using heartbeat. * Killed the nova-objectstore package. * testrepository build-depends is now version >= 0.0.14 * Reviewed a bit the init scripts boot dependencies, and added a few Should-Start / Should-Stop to make sure mysql, postgress and keystone are up and running. * Removed debian/python-nova.postinst, as update-python-modules --post-install is managed by dh_python2. * Added missing nova-compute dependencies in the nova-compute- packages. * Sets default security_group_api = quantum. * Starts nova after rabbit and ntp. nova (2013.1-1) experimental; urgency=low . * New upstream version. * Removes fix-ini-syntax patch. * Rewrote the pkgos_* calls to match the new parameter order. nova (2012.2.3-3) experimental; urgency=low . * CVE-2013-1838: Nova DoS by allocating all Fixed IPs (Closes: #703064). * Added || true in the unit testing. nova (2012.2.3-2) experimental; urgency=low . * CVE-2013-0335: VNC proxy can connect to the wrong VM (Closes: #701773). nova (2012.2.3-1) experimental; urgency=low . [ Thomas Goirand ] * New upstream release. * Removed CVE-2013-0208 patch now applied upstream. * Removed useless dependency python-quantum (-quantumclient is enough). * CVE-2013-0280: Information leak and Denial of Service using XML entities (Closes: #700949). . [ Mehdi Abaakouk ] * Add build-depends on python-pastedeploy, python-migrate nova (2012.2.2-1) experimental; urgency=low . [ Mehdi Abaakouk ] * New upstream version. * New upstream version * Add patches: fix-ubuntu-tests.patch fix-docs-build-without-network.patch * Removed patches included by upstream: nova-manage_flagfile_location.patch CVE-2012-3360_CVE-2012-3361.patch stable_essex_20120710.patch iscsiadm_path.patch CVE-2012-3371.patch CVE-2012-3447_compute-node-file-injection.patch . [ Thomas Goirand ] * Ordered debian/control build-depends and python-nova depends by alpha order. * Added new dependency to python-babel. * Now uses setup.py to install python-nova. * Switched to using pkgos_func functions. * Sets compat level to 9. * Now using xz compression level 9 for all debs. * Configuring Keystone endpoint for nova-api. . [ Roland Mas ] * No more build-dependency on python-glance (only -glanceclient). * Stop providing the Volume service by default (now handled by Cinder). Note: manual database migration required. nova (2012.1.1-18) unstable; urgency=low . * nova-common isn't anymore using /usr/share/doc to store configuration files used in the postinst, thanks to Ansgar for reporting it (Closes: #705117). nova (2012.1.1-17) unstable; urgency=low . * Fixes wrong default file in postinst (Closes: #704544). nova (2012.1.1-16) unstable; urgency=low . * Fixes console auth after security fix (Closes: #703242). * Fixes a typo in debian/nova-common.postinst when activating NOVA_ENABLE. * Fixes the DNS in the case of PGSQL: now it really is postgresql:// and not qgsql://. nova (2012.1.1-15) unstable; urgency=low . * CVE-2013-1838: Nova DoS by allocating all Fixed IPs (Closes: #703064). nova (2012.1.1-14) unstable; urgency=high . * CVE-2013-0335: VNC proxy can connect to the wrong VM (Closes: #701773). nova (2012.1.1-13) unstable; urgency=high . * CVE-2013-0280: Information leak and Denial of Service using XML entities (Closes: #700949). nova (2012.1.1-12) unstable; urgency=high . * CVE-2013-0208: Fixes boot from volume allows access to random volumes, with special thanks to TTX for making sure I was aware of it (Closes: #699266). nova (2012.1.1-11) unstable; urgency=low . * Fixes some wrong path to binaries in the rootwrap config (Closes: #695791). nova (2012.1.1-10) unstable; urgency=low . * Fixes capitalization in debian/po/es.po (Nova vs nova) (Closes: #687000). * Fixes some spaces in debian/po/zh_CN.po. nova (2012.1.1-9) unstable; urgency=low . [ Thomas Goirand ] * Added Debconf Chinese translation thanks to ben . . [ Loic Dachary (OuoU) ] * revert to using --flagfile instead of --config-file in nova-compute.init because --flagfile supports both configuration file formats. Using --config-file forces to use the newest configuration file format and is not backward compatible. If upgrading from nova-compute-2012.1.1-4 to all versions until nova-compute-2012.1.1-8 when using the old format in nova.conf, nova-compute will no longer run. It will silently fail to parse the older format and abort. nova (2012.1.1-8) unstable; urgency=low . * Corrected wrong encoding in the it.po (Closes: #685576). nova (2012.1.1-7) unstable; urgency=low . * Updated Spanish debconf translation thanks to Jathan (Closes: #678479). * Added Italian debconf translation thanks to Beatrice Torracca (Closes: #681250). * Added missing [DEFAULT] in nova-compute.conf for xen. nova (2012.1.1-6) unstable; urgency=high * CVE-2012-3447: file injection writing to host filesystem (Closes: #684256). nova (2012.1.1-5) unstable; urgency=high * Fix CVE-2012-3371. Closes: #681301 nova (2012.1.1-4) unstable; urgency=low * fix the iscsiadm path (Closes: #681175). nova (2012.1.1-3) unstable; urgency=low * Added a display-po-stats target in debian/rules * Added a call-for-po-trans target in debian/rules * Updated debconf translations thanks to: - de.po: Pfannenstein Erik (Closes: #680558). - pl.po: "Michał Kułach" (Closes: #680524). - da.po: Joe Dalton (Closes: #680354). - ru.po: Yuri Kozlov (Closes: #680267). * Do not rm -r /var/lib/nova/instances in the nova-compute postrm, because it has files from nova-common. Same with nova-network (Closes: #680642). nova (2012.1.1-2) unstable; urgency=high * Fixes CVE-2012-3360, CVE-2012-3361 (Closes: #680110). * Debconf translation updates with thanks to: - cs.po Michal Simunek (Closes: #679670). - pt.po Miguel Figueiredo (Closes: #679497). - sk.po helix84 (Closes: #679445). - fr.po Julien Patriarca (Closes: #679422). - sv.po Martin Bagge (Closes: #679009). nova (2012.1.1-1) unstable; urgency=low * New upstream release. nova (2012.1-8) unstable; urgency=low [ Thomas Goirand ] * Fixes "Cannot disassociate network from project" critical error 'bool' object has no attribute decode (Closes: #672350). * Added new debconf translations (with thanks to): - es: jathan (Closes: #678479). - de: Pfannenstein Erik (Closes: #678034). - gl: Jorge Barreiro (Closes: #678908). - pt: Traduz (Closes: #678735). - cs: Michal Simunek (Closes: #678667). - ru: Yuri Kozlov (Closes: #678429). - fr: Julien Patriarca (Closes: #678234). - pl: "Michał Kułach" (Closes: #678154). - sk: helix84 (Closes: #677284). [ Ghe Rivero ] * remove extra slash on sql_connection nova.conf nova (2012.1-7) unstable; urgency=low * Fixes "prompting due to modified conffiles" (Closes: #677400). * File /etc/default/nova-common isn't a conffile anymore as well. * Removed libvirt-type flag in nova-compute-xen nova-compute.conf, since we are using XenAPI and not libvirt. * Now configuring XenAPI URL, user and password through Debconf. * Makes replacements in nova.conf accept spaces, dashes and tabs. * Added initial Swedish debconf translation thanks to Martin Bagge (Closes: #677031). * Added initial Dutch debconf translation thanks to Jeroen Schot (Closes: #677364). * Added initial Danish debconf translation thanks to Joe Dalton (Closes: #677798). * Applied debian/control and debian/*.templates from debian-l10n-english (Closes: #675136). nova (2012.1-6) unstable; urgency=low [ Thomas Goirand ] * Now depends on sqlite3 (Closes: #674510). * nova-compute-{hypervisor} are now conflicting each others. * Fixed URL to the format 1.0 for the debian/copyright file. * nova-api is now split into multiple nova-api-* packages. [ Mehdi Abaakouk ] * Add nodocs support in DEB_BUILD_OPTIONS. * Do not use dbconfig if configure_db is false. Closes: #675271 * Fixed CVE-2012-2654. (Closes: #676465) [ Loic Dachary (OuoU) ] * Fix broken init file for nova-bojectstore (Closes: #676638) * Add Loic Dachary in uploaders nova (2012.1-5) unstable; urgency=low [ Ghe Rivero ] * Not start daemons from init by default. Added /etc/default/nova file * Added some new packages: api-os-compute, api-os-volume, api-ec2, compute-qemu, api-metadata * Instal api-paste.ini from nova-common nova (2012.1-4) unstable; urgency=low [ Ghe Rivero ] * Properly use dbconfig postrm at nova-common. Closes: #673986 * Added python db modules to suggests. Closes: #672888 [ Mehdi Abaakou ] * Remove obsolete volume_group option in nova-volume init script. Closes: #674030 nova (2012.1-3) unstable; urgency=low * 3 files are moved from python-nova to nova-compute, nova-network and nova-volumes, add Replaces and Breaks statements to enable smooth upgrade of version in testing. Closes: #665375 * Call dbconfig postrm script and remove nova-manage log. Closes: #670435 * Remove doc/sourc/api on dh_autoclean * Purge nova-* log files nova (2012.1-2) unstable; urgency=low * Fixed CVE-2012-2101. Closes: #670637 nova (2012.1-1) unstable; urgency=low * New upstream release nova (2012.1~rc3-1) unstable; urgency=low * New upstream release nova (2012.1~rc1-1) unstable; urgency=low [ Ghe Rivero ] * Use nova-rootwrap instead of sudo [ Thomas Goirand ] * nova-xcp-network.init now has a Required-Start: xcp-networkd, as otherwise, the boot process is simply stuck. * Added a chmod +x of all Nova XCP plugins in the postinst: otherwise, there's a XENAPI_PLUGIN_FAILURE when starting nova-compute, and the Git seems to have wrong Unix rights. [ Julien Danjou ] * Add dbconfig support * Bump standard version * Add logrotate entry for nova-dhcpbridge.log in nova-network * Add nova-cert package, providing the nova-cert daemon nova (2012.1~e4-1) unstable; urgency=low * New upstream version [ Julien Danjou ] * nova-api recommends python-keystone * Allow nova group members to read logs and configuration file. nova (2012.1~e3-4) unstable; urgency=low * Added init script to nova-consoleauth * Added init script to nova-xvpvncproxy nova (2012.1~e3-3) unstable; urgency=low * nova-compute- now depends on nova-common (Closes: #657569) * Added nova-consoleauth to nova-console nova (2012.1~e3-2) unstable; urgency=low * Fixed compute-xen postinst (Closes: #657569) * Minor fix in gbp.conf * Added policy.json * Added connection_type flag to nova.conf * Fixed funtions names in nova-xcp-networkt.init nova (2012.1~e3-1) unstable; urgency=low * New upstream version nova (2012.1~e2+git757-g62cf887-3) experimental; urgency=low * Added nova-xvpvncproxy binary package nova (2012.1~e2+git757-g62cf887-2) experimental; urgency=low * Fixed git debian/experimental merging * Added adduser depends to nova-compute-{lxc,xen,kvm,uml} nova (2012.1~e2+git757-g62cf887-1) experimental; urgency=low * New snapshot release * Removed nova-vncproxy binary package nova (2012.1~e2+git548-g6f0ef42-1) experimental; urgency=low * New snapshot release nova (2012.1~e2+git508-gcff2ddc-1) experimental; urgency=low * New snapshot release nova (2012.1~e2-3) unstable; urgency=low [ Thomas Goirand ] * nova-compute-xen shouldn't depends on the Xen hypervisor: it can be installed in a domU for example. [ Ghe Rivero ] * Lintian clean of empty packages * Added ovs-ofctl to nova_sudoers * Clean rules files moving nova-doc linking to nova-doc.links * Remove verbose logging in nova.conf * Sync nova database only if using it by default. nova (2012.1~e2-2) unstable; urgency=low * Do not fail postinst if the database upgrade fails (Closes: #648282) * Add missing files in debian/copyright (Closes: #633600) nova (2012.1~e2-1) unstable; urgency=low * New upstream release nova (2012.1~e1+git354-g1b4a0f8-2) experimental; urgency=low * Fix build-depends nova (2012.1~e1+git354-g1b4a0f8-1) experimental; urgency=low * New snapshot-release nova (2012.1~e1+git332-gaa7ca15-1) experimental; urgency=low [ Ghe Rivero ] * New snapshot release nova (2012.1~e1+git256-g022295e) experimental; urgency=low * New snapshot release * Refreshed patches to new upstream nova (2012.1~e1-4) unstable; urgency=high * Added security patch. CVE-2011-4596 nova (2012.1~e1-3) unstable; urgency=low [ Ghe Rivero ] * Create lock dirs on init files [ Julien Danjou ] * Add LOCK_DIR creation on all init files * Use NOVA_USER variable * Create pidfile nova (2012.1~e1-2) unstable; urgency=low [ Julien Danjou ] * Set real build-dependencies * Fix Vcs URLs * Fix Maintainer and Uploaders fields * Fix copyright file format * Enhance short description of python-nova. * Remove Ubuntu related stuff * Remove get-orig-source target * Fix clean and build-deps for test * Disabled tests on build * Fix typo in nova-doc description * Fix typo in copyright file * Fix build-dependency on novaclient * Add missing depends on adduser * Use libjs-underscore in doc * Stop making hypervisors packages conflicting * Rewrite init scripts and add missing nova-vnc-proxy.init [ Ghe Rivero ] * Resolved circular Depends on nova-compute. (Closes: #649379) * Some build-depends cleanup * Fixed brctl path in sudo file. (Closes: #631830) [ Thomas Goirand ] * Added a small debian/gbp.conf * Added missing python-netaddr build-depends. * Added missing build-depends on python-gflags * Added version (eg: >= 2.6.7-1) for build-depends on python-novaclient nova (2012.1~e1-1) unstable; urgency=low * [de01249] Imported Upstream version 2012.1~e1 * [216fb9a] Synced with ubuntu package nova (2011.2-1) unstable; urgency=low * Removes embedded jquery.js from nova-doc package. * Added some manpages stubs to make package lintian clean. * Adds a nova-volume.default where the admin can decide what VG to use. * debian/nova-objectstore.logrotate working in Debian. * Do not have debian/*.upstart files in Debian. Using debian/*.upstart.in and copying them as .upstart only if building in Ubuntu. * Nova init files reviewed so that they are working in Debian. * Initscripts of nova-compute now has a Should-Start: libvirt-bin * nova-compute.postinst working with libvirt group in Debian. * Reviewed the package descriptions. * Reviewed some dependencies in debian/control (added some adduser and lsb-base depends). * Added missing binary Depends: (nova-manage must depends on python-amqplib unless failing puiparts tests, nova-compute is pretty usless without qemu-utils) * Removes .gitignore files from binaries. * Don't package nova-manage.1 man page if we aren't building docs. * Packages correctly: nova-manage.1 and not novamanage.1 !!! odr-audioenc (3.4.0-2) unstable; urgency=low . * Fix Vcs-Browser and Vcs-Git fields in d/control * Bump Standards-Version to 4.7.0 in d/control onnxruntime (1.13.1+dfsg-1) unstable; urgency=medium . [ Mo Zhou ] * Initial release. (Closes: #933354, #1035081) . [ Andre Moreira Magalhaes ] * Import new upstream release . [ Dylan Aïssi ] * Finalize packaging openmesh (10.0.0-2) unstable; urgency=medium . * Added missing #includes to fix FTBFS (Closes: #1067954) openmesh (10.0.0-1) unstable; urgency=medium . * New upstream release * Package ABI bump openmm (8.1.1+dfsg-1) unstable; urgency=medium . * New upstream version 8.1.1+dfsg * Bump copyright years. opensnitch (1.5.8.1-1) unstable; urgency=medium . * New upstream release. * Upload sponsored by Petter Reinholdtsen. opensnitch (1.5.8-2) unstable; urgency=medium . * Upload to unstable. * Upload sponsored by Petter Reinholdtsen. opensnitch (1.5.8-1) experimental; urgency=medium . * New upstream release. . [ Gustavo Iñiguez Goia ] * ui: added 64x64 icon. * Added missing entry for GUI manual page. * Updated appstream Summary field. * Removed ftrace dependency from d/control. * ui: updated appstream Summary field. * Updated d/control Description. . [ Petter Reinholdtsen ] * Added appstream content rating, no restrictions. * Corrected appstream icon name. * Documented appstream metadata license in d/copyright. * Place manual pages in correct packages. . * Upload sponsored by Petter Reinholdtsen. opensnitch (1.5.7-3) experimental; urgency=medium . [ Gustavo Iñiguez Goia ] * fixed /etc/xdg/autostart/ link . * Upload sponsored by Petter Reinholdtsen. opensnitch (1.5.7-2) experimental; urgency=medium . [ Gustavo Iñiguez Goia ] * added opensnitchd manual page * added new manual page, updated opensnitchd.1 * improved debian/tests/ . * Upload sponsored by Petter Reinholdtsen. opensnitch (1.5.7-1) unstable; urgency=medium . * New upstream release . [ Gustavo Iñiguez Goia ] * Set test-fw-rules.sh as flaky. * Make test-fw-rules.sh more verbose. . [ Petter Reinholdtsen ] * Fixed typo in nb comment of desktop file. * Added appstream desktop category to metadata XML. . * Upload sponsored by Petter Reinholdtsen. opensnitch (1.5.6-1) unstable; urgency=medium . * New upstream release . [ Gustavo Iñiguez Goia ] * tests: removed Architecture: restriction * changed Maintainer: field to team+pkg-go * added new test * added Uploaders field * updated Vcs* fields . [ Petter Reinholdtsen ] * Added Debian package relation between opensnitch and python3-opensnitch-ui. * Handle autopkgtest scripts differently, as they have different requirements. . * Upload sponsored by Petter Reinholdtsen. opensnitch (1.5.5-1) unstable; urgency=medium . * New upstream release. * Bump Standards-Version to 4.6.2. * Upload sponsored by Petter Reinholdtsen. opensnitch (1.5.4-1) unstable; urgency=high . * New upstream release. (Closes: #1030115) * debian/control: - Updated packages description. - Removed debconf and whiptail|dialog dependencies. - Added xdg-user-dirs, gtk-update-icon-cache dependencies. - Point Vcs-Git field to the 1.5.0 branch. * debian/postinst: - Fixed opensnitch_ui.desktop installation. - Fixed updating icons cache. * debian/postrm: - Fixed removing opensnitch_ui.desktop * debian/tests/: - Added autopkgtests. * Upload sponsored by Petter Reinholdtsen. opensnitch (1.5.3-1) unstable; urgency=medium . * Added debian/upstream/metadata. * Updated Homepage url. * Updated Copyright years. opensnitch (1.5.2.1-1) unstable; urgency=medium . * Initial release. (Closes: #909567) openstack-cluster-installer (42.3.9) unstable; urgency=medium . * [662335a] oci-build-data-vg: Remove double-implementation of realpath. * [a9e0bbf] controller.pp: fix bug: set $allowed_intern_only before using it. * [ab4c537] ocicli: cluster-install in hyperconverged mode really waits for 2nd pass puppet run. * [575872a] Add smartmontools as depends for oci-common. * [dbc64d0] oci-poc-provision: use machine-show to fetch cl3-ctrl-1,2,3 IPs to avoid fetching the VIP IP. * [a6300b0] tempest.pp: fixed syntax when setting-up region names. * [a9abd9a] Correct image name for Tempest. * [53dd0bd] Fix ext-floating1 as external network name for tempest. * [56c4da4] oci-poc-install-cluster-bgp: Use CEPH_1 as default volume type. * [55d5bb1] tempest.pp: Restrict tests. openstack-cluster-installer (42.3.8) unstable; urgency=medium . [ Thomas Goirand ] * [bce1962] exclude.conf: blacklist stacks_stack_list\.test_request * [ab0f913] Blacklist failint tests in Wallaby. * [e5c5934] Document using ikvswitch with the OCI-PoC * [2a3f2fd] controller.pp: also create the key-manager:service-admin role (needed for tempest). * [2e84088] Add load-balancer_observer role as well. * [f640d89] Add a new ocicli machine-ipmi-adopt command, useful when IPMI is using dhcp. * [215e6a3] Fix ocicli machine-ipmi-adopt. * [1f8a426] Another machine-ipmi-adopt fix. * [525eb65] oci-hdd-maint -l: Display firmware version of HDD with MegaRAID devices. * [77b4b3d] hardware_profile.php: also search for storcli64 (as top priority before others). * [473562a] oci-hdd-maint -l: use /usr/bin/storcli64 or /usr/bin/storcli_x64 when available. * [523499e] oci-hdd-maint: use /usr/bin/storcli64 when evailable, order -pdlist and -vdlist by slot num. * [c97580d] oci-hdd-maint: report State and Spun with storcli64. * [1bb0751] Add a swift_df_report, so we can later on tweak /etc/rsyncd.conf depending on remaining space. * [0f8d15d] oci-hdd-maint: -vdlist: fix DG if it is == "-" * [130159a] oci-block-device-udev-sorting: revert R740xd patch, as something broke. * [8a667f4] Fix back 20-swift.conf as per the package: separate log file for each process. * [a8f4853] Fix + update the basic OCI install doc. * [4f79158] Added support for multiple time servers * [12f3079] Missing mkdir -p config/hooks/live when installing the install-kernel-from-backports.hook.chroot * [61184fd] For the moment, restrict filebeat to amd64 only (as we don't have arm64 packages for it yet). * [6ed88c0] openstack-cluster-installer-live-image-builder: add missing openstack-pkg-tools depends. * [57551b9] openstack-cluster-installer-build-live-image: Install firmware-qlogic when arch is not aarch64. * [75308dd] oci-agent: use ["port"]["id"]["value"] if ["port"]["descr"] doesn't start with en or swp. * [785305b] auto-racking: produce an error when product description isn't in auto-racking.json. * [5082760] auto-racking: report error when no LLDP info. * [511b66c] Better error message when product name not found. * [357c997] Add bash-completion for the --filter option. * [105cfae] openstack-cluster-installer-utils: add missing q-text-as-data depends, needed by oci-hdd-maint. * [59cbb86] oci-hdd-maint -vdlist: display missing slot num for JBOD drives. * [5a8a520] oci-block-device-udev-sorting: better ProLiant DL365 Gen11 support. * [e8bff56] Relax IPMI username that can be set (use safe_password instead of safe_fqdn). * [ffcb0c5] Include drive-full-checker in swift's rsyslog config. * [4acf6ce] report.php: do not apply automations like RAID and so on if the server isn't in status=live. * [129f0b0] Fix sql syntax of previous commit. . [ Olivier Chaze ] * [332b31b] adding haproxy rate limit . [ Thomas Goirand ] * [c600d38] Fix merge-on-all-branches for the new release. * [db1bc3f] Set close-on-exec and close-on-exec2 on all uwsgi API services. * [bc064cb] Add disk-full prevention using swift-disk-full-checker and fallocate_reserve. * [b761ec8] swift: Use log_name_per_daemon=true. * [97ec1e8] poc-bin/oci-poc-install-cluster-bgp: set swift reserved space. * [73cf774] Fix rsyslog config for swiftproxy. . [ Jim Scadden ] * [6cb1846] Don't listen for SSH on ceph-cluster IPs * [4a841b6] New OCI role type 'radosgw' * When radosgw node(s) are present additional PGs and users are created in Ceph * When there is no 'swift proxy hostname' defined, a swift frontend+backend is created in haproxy on the controller(s) and pointed to radosgw nodes (if there are swiftproxy nodes present then the backend will point to those instead). * When 'swift proxy hostname' is defined a haproxy frontend+backend is created on the radosgw nodes. If there are both swiftproxy and radosgw nodes present then it is up to administrator to ensure end user traffic is only sent to one of groups of nodes. . [ Axel Jaquet ] * [6a30ca6] Add support for network agent zoning . [ Thomas Goirand ] * PoC: configure 47 VMs, with a Keystone cluster and a hyper-converged compute-only cluster. * [632a92a] controller.pp: do firewall purge if not used as network node. * [b401067] volume.pp: populate /etc/keystone/puppet.conf instead of /etc/openstack/puppet/admin-clouds.yaml for xena and down. * [2aa3b7c] ocicli: use "--snifflimit 0 -d ," when using csvlook to avoid warning message. * [9ae005a] swiftproxy_haproxy.pp: fix calling of template for /etc/haproxy/custom_delay.lua * [ddc6c80] swiftproxy: Implement delay if rate is too high for some Swift accounts / containers. * [bc9905f] Fix typo in oci-hdd-maint HDD disposition output. * [a266bc5] compute.pp: fix using it with external keystone. * [95d4375] Add a --force-frr option for servers. * [24a3c46] Make ocicli also work with hostnames and encode the password when sending it, so we can accept + in the pass. * [5f26d33] machine-ipmi-adopt: Redirect stderr to /dev/null to avoid ugliness. * [c2e915b] PoC & keystone only cluster: make it possible to not install Barbican, Heat & Rabbit. . [ Olivier Chaze ] * [4ce2769] Send absolute values rather than rate and interval 60 to match default graphite . [ Thomas Goirand ] * [acc0bcf] Fix nova api microversion for Caracal. * [bc8251f] Add a 3rd interface to the OCI VM for IPMI. . [ Simeon Gourlin ] * [07687ea] Adding error messages to monitoring plugin code . [ Thomas Goirand ] * [8b704a3] messaging.pp & controller.pp: ::cloudkitty::processor doesn't have max_workers param in Yoga and up. fix typoe: brabican -> barbican. * [8b544b1] enc.php: Get swiftproxy.pp haproxy.cfg to order other swiftproxy hostname in correct numerical order. * [1fe3290] controller.pp: fix typo in barbican See merge request openstack-team/debian/openstack-cluster-installer!50 * [3616a64] swiftcommon.pp: requires => Package['swift'] when creating /var/log/swift with swift as owner. * [7652f89] db_sync.php: Fix ALTER TABLE missing the $con variable. * [d8b508a] Fix-up installing OSD on compute nodes. * [cbf1f53] swift diskfull scenarios prevention: differentiate rsync and fallocate reserve. * [a16c446] PoC: implements swiftstore/swiftproxy reserved space . [ Axel Jacquet ] * [2b6a64c] Add option to limit admin access to API based on source IP. . [ Thomas Goirand ] * [64edd72] Add options for forcefrr and fix calling oci-first-boot from install-status.php * [151c3a0] oci-first-boot: now using /dev/disk/oci-sort when parsing /etc/oci/data-disk for formating CephOSD. * [38ca3cf] tempest.pp: Fix caracal microversion. * [26f9828] tempest.pp: Support external keystone See merge request openstack-team/debian/openstack-cluster-installer!53 * [888e4a3] Add support for onboard ethernet interfaces See merge request openstack-team/debian/openstack-cluster-installer!52 * [c182327] Manage dnsmasq_dns_servers option in /etc/neutron/dhcp_agent.ini in OCI. See merge request openstack-team/debian/openstack-cluster-installer!48 * [d6e5658] controller.pp: do not set Keystone notification URL if there's no rabbitmq. * [c3812d5] oci-block-device-udev-sorting: more target for LinuxKVM + qemu-oci. * [d533711] oci-build-data-vg: use /dev/disk/oci-sort if available. * [2605631] tempest.pp: support up to Caracal. * [ed93fa7] tempest.pp: set region= whenever needed, which is mandatory for multi-region clusters. * [579a220] Increase RAM of network nodes to 8GB (instead of 5). * [dc8f17b] Updated regex for identifying switchport name See merge request openstack-team/debian/openstack-cluster-installer!54 * [767577b] tempest.pp: fix img_file to use full path of image. * [ebc5d51] reset-lenovo-ipmi-password-age: check if ocicli and q are present, exit 0 if not (Closes: #1057083). openstack-cluster-installer (42.3.7) unstable; urgency=medium . * [3258401] oci-live: mkdir -p, not mkdir /p * [ccd5a21] openstack-cluster-installer-agent: use descr field instead of PortID value, so it works with ikvswitch. * [e61dbd6] More ikvswitch compat. * [b830bcf] auto-racking.json: define defaults values that work with ikvswitch. * [823d1e7] Set auto_rack_machines_info=yes by default. * [27566f5] Add "qemu-oci": { "num-u": 1 } in auto-racking.json * [d1a97f7] oci-poc-vms: new templates for servers, so it uses ikvswitch. * [062dc32] Add IPMI login / pass / ip saving to the vault / OpenBao through plugins. * [1d614f3] Add a --filter option to ocicli machine-list. * [39e7e2d] Add missing require_once("inc/plugin_ipmi_pass.php"); in src/install-status.php * [46ffdab] enable auto-racking in the PoC, since we're now using BGP-2-host. * [25aa16d] openstack-cluster-installer-poc now depends on ikvswitch. * [22dea5c] Kill the oci-poc-virtual-network init/service script, in the favor of ikvswitch. * [6939b46] Fix some typos. * [24598e2] poc-bin/oci-poc-install-cluster-bgp: Some fix-ups for network nodes. * [b899739] src/inc/slave_actions.php: correctly pass-in VLAN number if not using bonding. * [08ac350] Add puppet-module-rally as depends. * [36e4371] poc-bin/oci-poc-install-cluster-bgp: provision messaging VIP, use BGP. * [1d81310] Workaround a bug where /etc/oci/system-serial is sometimes empty. * [5af5111] controller.pp: fix username param called twice when calling ::neutron::server::placement * [0951763] oci-poc: Fully provision a culster using BGP-2-host setup using oci-poc-provision in the host. * [01a76f0] tempest: do not use admin_domain_scope * [913442e] tempest: use use_dynamic_credentials=true * [b3a9f25] tempest: compute/volume_device_name=sdb, compute/min_compute_nodes=2 * [a90198f] tempest: Use only ext-floating1, not ext-net1 * [2b2117a] utils/usr/bin/oci-poc-provision-network: uncomment the BGP internal network (aka: ext-net1). * [3b234da] Add oci-poc-ci. * [b300aff] octavia-openrc and swift-openrc: use region-postfixed usernames if needed. * [93a1678] Added octavia support in the PoC. * [21aa619] 6 more compute nodes. * [d114f49] utils/usr/bin/oci-poc-provision-octavia-network: fix syntax error. * [4e32b26] 38 VMs by default. * [a14d0d9] ocicli: do not install tempest servers by default when doing cluster-install, because they need provisionning of OpenStack frist. * [4803cab] PoC: provision flavors and az * [a8bf9eb] oci-poc-provision-network is to be run on CTL1 * [dc7d63b] Fixup for oci-poc-provision-az. * [9622e55] oci-poc-provision: provision the tempest node automatically as well. * [a37b59b] Use 2 different flavors, and enable resize_available. * [27317d4] tempest: remove compute-feature-enabled/xenapi_apis * [0c3d974] Set --swift-public-cloud-middlewares yes. * [e2a5c54] tempest: set cinder_backup_available and neutron_dr_available. * [c24888e] tempest: set volume/backend_names (to: CEPH_1) and volume/storage_protocol (to: rbd). * [664245a] Copy /root/debian.qcow2 in the tempest server to enable scenario testing with it. * [f1bd126] Set compute VMs with 8 vCPUs. * [d6f5e42] Run tempest at end of oci-poc-provision, and use tempest exclude.conf * [58ea482] Correctly set poc's VMs vcpu num. * [edd4618] * ocicli/ocicli: display num of core and sockets * poc: compute with 8 VCPU. * [fd5aa2f] poc-bin/oci-poc-install-cluster-bgp: Add --swift-public-cloud-middlewares yes * [b3f2d6a] Remove set-x in poc-bin/oci-poc-ci * [dec6c92] Run tempest only once. * [20235f4] poc-bin/oci-poc-provision: get tempest node IP *after* it's installed. * [afabcb9] tempest.pp: set Cinder min/max API microversion. * [16082c1] oci-poc-ci: call oci-poc-setup before installing. * [7a5acf1] rework exclude.conf * [dbd1061] More excluded tests. * [b597f4d] controller.pp: fix heat and magnum domain user. * [b2ee18b] Upgrade tempest nodes when upgrading release. * [fb3feb5] More tests in exclude list. * [fbaaf07] Exclude the 10 slowest tests. * [3092df8] neutron-uwsgi: only one thread, to avoid "greenlet.error: cannot switch to a different thread" * [6d596a5] swift container: set replicator_node_timeout => 120. * [f37f660] Merge branch 'bugfix/assign-ceph-ips' into 'debian/bobcat' Fix: Assign ceph IPs to cephmon and compute_is_cephosd nodes See merge request openstack-team/debian/openstack-cluster-installer!43 openstack-cluster-installer (42.3.6) unstable; urgency=medium . * Re-upload source-only. openstack-cluster-installer (42.3.5) unstable; urgency=medium . * Misc fixes: * [02ed695] Do not clean-up /var/spool/cron/crontabs/keystone that is later re-added by Cron[oci-fernet-keys-rotate]. * [3cfe6e6] fix doubled-defined orchestrator/coordination_url in messaging.pp * [a163754] add poc-bin/oci-poc-haproxy to setup haproxy in the virtualized PoC * [6195ab5] Add puppet-module-puppet as depends . * bin/oci-cluster-upgrade-openstack-release: * [cc42e1b] Fix ::ceilometer::agent::auth uses auth_user, not username as param. * [f36711a] Fix swift_store_user for region-postfixed users. * [a8d69e6] Fix: always specify username in authtokens in case of region-name postfixed user. * [205b56a] Some more fixes for the same trouble. * [db4701a] oci-cluster-upgrade-openstack-release: include messaging nodes * [94f7eef] controller.pp: class Ceilometer::Agent::Auth is Ceilometer::Agent::Service_Credential starting with wallaby, not xena. * [3fb1b2d] Revert "Change indexer_url to local ip instead of database VIP" This reverts commit dd6f570ebd1b67e4702b24c2921317464f75e9d0. * [1945a7a] Lots of fixes in oci-cluster-upgrade-openstack-release * [a73a209] gnocchi database_connection uses $machine_ip instead of $sql_host. * [a48a968] messaging.pp: fix cloudkitty setup under Xena. * [4d8c945] Add cluster_check_status * [f504d64] Add haproxy-cmd on all hosts using haproxy. * [b46db6b] Huge enhancements on the cluster-upgrade script. :P * [182df40] Add wallaby -> xena dependency list. * [b7f8954] Also upgrade python3-neutron-dynamic-routing if exists. * [32492fb] Do not run puppet before everything is upgraded fully. * [0c86859] depends list for yoga * [97539d0] Fix xena -> yoga upgrade of deps in controllers. * [558063c] messaging.pp: fix, shouldn't manually set cloudkitty_config { orchestrator/max_threads in yoga. * [77682d5] In Yoga and up, ::ceilometer::cache is included from ::ceilometer, so we should call it first. * [3af43ae] depends list for yoga->zed upgrade. * [5c5b46f] never touches CEPH nodes, correctly upgrade horizon plugins when doing yoga -> zed. * [44b0b01] Fix ALL_NODES_BUT_CEPH. * [e717c06] Do initial-cluster-setup during xena -> yoga upgrade. * [4aae596] fix syntax error. * [a5b8d9a] Do not do initial-cluster-setup=yes. * [42e8255] Run nova-manage db online_data_migrations in loops until done. * [acf7339] Escape $RET properly when doing nova-manage db online_data_migrations * [83bf7d7] do the db-sync before enabling services. . * hardware support: * [9565107] Use baseboard-serial-number as serial for GIGABYTE MZ01-CE1-00 motherboards. * [655137e] Use a more generic way to report serial number. * [b7dad20] Report MZ01-CE1-00 GIGABYTE as Dataforge hydra-f * [580a590] oci-block-device-udev-sorting: Add Dataforge Hydra-F support * [9094290] common/usr/bin/oci-block-device-udev-sorting: correctly detect Dataforge drive order. * [5233429] Correctly support hydra-f HDDs scanning. * [7c746e3] oci-block-device-udev-sorting: Remove spaces after port number definition. * [e2cbe92] Do not install ilorest-chif on arm64. * [09e6eed] Avoid installing non-x86_64 stuff on other arch. * [e695021] use osbpo for non amd64 arch. . * live-image-builder: * [70ecfbb] make it work under arm64. * [bdaa466] More arm64 support. * [59a943d] More code for arm64 live image handling, move openstack-cluster-installer-build-live-image into a separate binary, so it can be installed on a satelite server in order to build for foreign arch. * [a9ee6ec] Add oci-live to build the live image locally and remotely with multi-arch. openstack-cluster-installer (42.3.4) unstable; urgency=medium . * [67f291a] Display cpu_vendor and cpu_model_name when doing "ocicli machine-list -h" * [7d43101] Add reset-lenovo-ipmi-password-age to avoid IPMI password expiration on Lenovo hosts. * [d16ba43] Add TOTP support in Keystone + Horizon. * [6a68e46] Fix wrong admin password if not using external keystone. Also repair designate-central validation. openstack-cluster-installer (42.3.3) unstable; urgency=medium . [ Olivier Chaze ] * [dd6f570] Change indexer_url to local ip instead of database VIP . [ Thomas Goirand ] * [377a8b8] Add multi-region support. openstack-cluster-installer (42.3.2) unstable; urgency=medium . [ Thomas Goirand ] * [4d920f8] openstack-cluster-installer-utils: depends on gnupg, not gnupg2 (Closes: #1055405). . [ Olivier Chaze ] * [d245a2d] Haproxy admin socket and reload haproxy instead of restart. * [1e2c431] Reload haproxy command misplaced. . [ Philippe Seraphin ] * [77b00f0] Update oci-hdd-maint for calling disk-firmware-installer. . [ Jim Scadden ] * [86783ee] Fix /etc/network/interfaces NIC names set to Array (Closes: #1054600). * [9370179] Support for custom repository package signing key (Closes: #1028481). * [eb18316] Fix puppet fails to determine cephnet IP address (Closes: #1054648). * [13c99f3] Factorize non-system block device list, fixing "Block device list can be incorrect when using NVMe drives and/or RAID" (Closes: #1054649). * [d2ea19c] ocicli: machine-guess-racking returns error when no match found (Closes: #1054593). * [afed002] Reduce PHP warnings in apache log (Closes: #1054598). * [5368c5a] Regex updates for Dell OS10 switches & BroadCom NXE NICs (Closes: #1054603). openstack-cluster-installer (42.3.1) unstable; urgency=medium . [ Thomas Goirand ] * [3a5d30c] Set min firmware version for ST20000NM002D (20TB Exos) as E004, since we need that on HPE DL345. * [d9095e0] Add oci-foreman. * [3d5b074] Fix serial detection fallback to system-uuid. . [ Olivier Chaze ] * [c6151ad] increasing mon osd down out interval to avoid rebalancing data too soon . [ Thomas Goirand ] * [c23ab3c] Add oci-swift-upgrade-hdd-firmware, using the disk-firmware-updater binary. * [0fb890e] filebeat: use systemd::dropin_file instead of just the file resource. . [ Theo Gindre ] * [e4acf39] Delete monitoring and dns records when machine-destroy is called . [ Thomas Goirand ] * [8b579a9] Do not use ::cloudkitty auth_section param if >= yoga. * [1998fee] Do not call keystone::client in bobcat and up. * [779f69f] Do not call neutron::client in bobcat and up. * [99f0676] Speed-up collecting machine list when doing cluster-install. * [b9394b1] Do not call ::nova::client on bobcat and up. * [6510713] CVE-2023-2088/OSSA-2023-003 and bobcat support: configure ::nova::keystone::service_user and ::cinder::keystone::service_user * [322a616] Fix cpu_model_real for Bobcat's puppet-nova. openstack-cluster-installer (42.3.0) unstable; urgency=medium . [ Thomas Goirand ] * Use a new field for the Designate ptr_zone_email. * Disable amphora logging in Octavia. * Depends on default-mysql-server | mariadb-server, not just default-mysql-server. * openstack-cluster-installer-build-live-image: do not attempt to install megactl, megamgr and dellmgr when installing megacli in the live image. * openstack-cluster-installer-agent: use first RAID controller (head -n 1). * oci-block-device-udev-sorting: Add ProLiant DL365 Gen10 Plus support. * Add support for using storcli instead of megacli. * Set keystone_authtoken/service_type in cinder.conf. * Add support for puppet-openstack Antelope. * network.pp: rotate /var/log/conntrackd-stats.log daily. * Fix: new compute not being discovered automatically (because of a not defined $clusterid in a MySQL query). * New ocicli feature to re-assign the IPMI address of a server. * Add support for HPE ProLiant DL345 Gen11. * Swiftstores: do not attempt to XFS format nvme0n1 if nvme0 is the system disk. * lldpd: list existing NICs instead of just eth*, which doesn't work with BIOS names. * Agent: report version of MegaRAID 12GSAS/PCIe Secure SAS39xx controller. * Fix handling of CPU model extra flags params. * Add oci-poc-virtual-network.service (Closes: #1039302). * Increased the size of the BIOS version field to 64 chars (Closes: #1028457). * Correctly transmit "$self_signed_api_cert" to messaging nodes. * Applied patches sent by Jim Scadden to the Debian BTS. Thanks a lot to him for his bugfix contributions: - fix ocicli machine-guess-racking returns error when no match found (Closes: #1053506). - fix 500 error on oci agent first report (Closes: #1053507). - fix puppetserver sign command needs updating for puppet 7 (Closes: #1053510). - Use "dmidecode -s system-uuid" on QEMU VMs in some cases (Closes: #1053513). - Bugfix for handling NICs which do not report a speed (Closes: #1053514). * Cleans better. . [ Axel Jacquet ] * Use a new field for managed_resource_tenant_id. * Add deployment of MySQL server + rally in the Tempest role. openstack-cluster-installer (42.2.5) unstable; urgency=medium . * Fix in Zed: swift-proxy delete_concurrency. openstack-cluster-installer (42.2.4) unstable; urgency=medium . * Add a default designate_policy.json in Horizon enforcing dnsmember requirement to display the DNS panel. * Add Bookworm support: - Add support for the new non-free-firmware in bookworm and up. - Fix idna_convert.class.php to support PHP 8.2. - Fix implode() call wrong param order in ssh.php's send_ssh_cmd(). - Do not install netcat in --postinstall-packages, as it's gone from bookworm, and openstack-cluster-installer-common already depends on netcat-traditional. - oci-hdd-maint: add ThinkSystem SR665 HDD disposition. - Fixups for Puppet >= 7. - Add puppet-module-puppetlabs-sshkeys-core as Depends. - Depends on puppetserver | puppet-master. - oci-poc: add [master] section if missing from puppet.conf. - Mount /var/log, /var/lib/automysqlbackup on a data disk on messaging nodes (if such disk exists). - Add missing depends: puppet-module-puppetlabs-cron-core. - PoC: fix the vip interface name to be ens5, instead of eth1. Also, allow more flexibility (ie: any eth name) for network interface selection in the OCI's IPAM. - Add puppet-module-puppetlabs-mount-core as depends (needed for swift). - src/api.php: Also fix NIC string check for network_add. - Volume nodes: build the lvm.conf filter AFTER building the vg. openstack-cluster-installer (42.2.3) unstable; urgency=medium . * openstack-cluster-installer-poc: do not depends on grub-efi-amd64-signed, not available in arm64, suggests: it instead. openstack-cluster-installer (42.2.2) unstable; urgency=medium . * Add call to ::cinder::nova in compute.pp when having OSDs in the cluster. * Add call to ::cinder::nova in volume.pp. * Only suggests grub-efi-{amd64,arm64}-signed, because OCI is arch:all and can't depends on grub-efi-amd64-signed. Only copy grub / shim to the tftp folder if it's available. openstack-cluster-installer (42.2.1) unstable; urgency=medium . * Fix filter:tempurl/prefix_path -> filter:tempurl/path_prefix in swiftproxy.pp. * Increase net.core.somaxconn to 65536 on all nodes. * Make oci-build-nova-instances-vg do bind mounts for /var/lib/{libvirt,nova,cinder} instead of just /var/lib/nova/instances. This better fits setup with Ceph. * Added DSS 1510 support in oci-block-device-udev-sorting. * Make Designate work. * Make it possible to customize VXLAN VNI ranges per clusters. * Add support for Yoga. * Setup an additional VG in controllers if a data disk exists, and use it for Glance image upload temp dir in Horizon. * swift: add rsync bandwidth limiting for rsync (very useful when doing rebalance). * Install also by default a few firmware: - firmware-linux-free - firmware-misc-nonfree (contains intel NICs) - firmware-qlogic * Add --order/-o option to ocicli machine-list. * horizon: set $password_retrieve = true by default (inconditionally) to enable password retrieval from metadata (encrypted with the user SSH public key). That's mandatory for Windows install. * Use the new rsync_module_per_device puppet-swift feature. * controller+messaging MariaDB: set innodb_buffer_pool_size to total_ram / 8 plus add innodb_flush_log_at_trx_commit = 2. * Implement client/server PKI auth for VNC. * Octavia: disable bad cypher by default. * Barbican: install barbican-worker by default in the controllers. * Add UEFI support. * Add designate-tlds support, and documentation. * Fix live image autologin (Closes: #1027800). * Removed puppet-master dependency as the server is currently removed from Debian until Puppet 6 or 7 is packaged. openstack-cluster-installer (42.1.0+nmu1) unstable; urgency=medium . * Non-maintainer upload. * No source change upload to rebuild with debhelper 13.10. openstack-cluster-installer (42.1.0) unstable; urgency=medium . * Fix haproxy rate which was 10 times too low. openstack-cluster-installer (42.0.0) unstable; urgency=medium . [ Kevin Allioli ] * Added swift erasure coding support. * Correct the list of allowed methods for ::swift::proxy::tempurl, also set filter:tempurl/prefix_path. * Tweaks for designate integration. . [ Thomas Goirand ] * Set nova::api max_limit to 10000. * Add a install_cloudkitty_dashboard flag. * Add oci-ilorest wrapper. * Correctly check for Horizon availability on haproxy. * Lower the privileges of the backup user used for Galera replications. * Fix ceilometer for floating ips polling. * Fix unix rights of /var/log/swift/*.log files using puppet. * Configure heat_api/heat_api_root. * Make it possible to skip installation of Telemetry completely. * Fix the puppet stuff for Xena. * Make Octavia installation optional. * Use ilorest to configure ProLiant DL385 Gen10 Plus boot device (add ilorest as depends). * ::ceilometer::keystone::auth': do not pass the parameter configure_endpoint when >= victoria. * Fix collector_gnocchi/region_name call goes in cloudkitty::processor when >= xena. * Correctly install OCI root CAs in the target systems. * Configure Nova + Libvirt to do live migration over libvirt native TLS. * Add the possibility to add a --fixed-ip parameter when doing machine-add. * Restart MySQL in case of start failures on controller + messaging. * Add OpenStack deployment over OpenStack VMs CI script. * tempest.pp: increase ssh and image build timeout, and handle microversion min and max for both Placement and Nova. * utils/usr/bin/oci-build-cinder-volume-vg: handle /dev/disk/oci-sort. * openstack-cluster-installer-common: add racadm bash-completion script. * oci-hdd-maint: make sure the script is ran as root, exit 1 otherwise. * Implement radius auth using php-dapphp-radius if php-radius is not available (php-radius is removed from bookworm because it doesn't build against PHP 8.x). Set depends to php-dapphp-radius | php-radius. . [ Cyril de Bourgues ] * use the new way for external healthcheck & add dontlognull. . [ Simeon Gourlin ] * Modify disk install parameter for hardware raid setup. openstack-cluster-installer (41) unstable; urgency=medium . [ Thomas Goirand ] * Fix poc-bin/oci-poc-install-cluster-swift with the new VM layout. * Add udev rule and sort script to restore sanity in drive orders on HP DL385, Qemu and others. * Handle region_name per cluster. * Set net.ipv4.ip_nonlocal_bind on all servers, needed if we set LocalAddress in sshd + bgp-to-the-host. * Cloudkitty: use keystone as fetcher_backend. * Fix rabbit URL for ceilometer notifications in the controller. * Add ceilometermiddleware support for swiftproxy. * Call ::nova::cinder for any OpenStack release >= train, in both the controller and compute classes. * Add support for Ceilometer dynamic pollsters. * Make Nova's reserved_host_memory_mb configurable, and set default to 16GB. * Add optional activation of tempurl, symlink and staticweb swiftproxy middlewares on swiftproxy nodes. * Move cloudkitty & gnocchi dbs to the messaging nodes, on a new Galera cluster for billing. * Automatically write /etc/ceilometer/gnocchi_resources.yaml from /etc/openstack-cluster-installer/gnocchi_resources.yaml. Same with /etc/cloudkitty/metrics.yml for the processor. * Rate limit the API to a customizable value, at the iptables level (default: 100 queries/s connection max per /24), and haproxy (default: 20 concurrent sockets), with no limit for cluster internal use. * Increased memcached max_connections to 16k (instead of 8k). * Only keep 7 days of haproxy logs instead of the default which is 52. * controller: also install python3-pankoclient. * Configure by default the number of keystone uwsgi workers. * Added filebeat support. * Add missing pciutils depends in the openstack-cluster-installer-common package (the agent uses it). * Manage the number of API workers with $::os_workers and the new classes foo::wsgi::uwsgi contributed to puppet-openstack. * Add code to force a debian suite name for the MegaCli repo. * Setup postfix with correct relayhost in all machines of clusters. * Use "ceph-volume lvm batch --osds-per-device 2" instead of calling the ceph::osd class to create the OSDs. * Allow overriding the debian suite name for the HPE repo. * Add support for installing PERCCLI. * Fix swiftproxy.pp haproxy setup for Bullseye (ie: haproxy >= 2.1). * Add missing call to class { '::octavia::housekeeping': } in controllers. * Transmit all of the PKIs through the ENC, so there's no need to use a script to update them. Administartors can simply edit the SSL key materials on the OCI machine under /var/lib/oci/ssl/slave-nodes. The puppet manifests are now taking care of updating the certs, and restarting daemons appropriately. * Fix-up correct rights and location for PKI materials in the cluster. * Addresses OSSN-0088: disable glance metadef for non-admins. * Fix compute node setup in case there's no data disk. * Set enable_new_services => false when calling nova::conductor, to have new compute nodes appear disabled by default, which is better for production. * oci-poc: added support for AMD virtualization, and added modprobe.d options to enable nested virtualization. * Add an option to not provision CephOSD automatically. * Optionnaly, OCI can set an HTTP proxy in the aodh-notifier's service environment, which is very useful if the controller have no internet access (this way, aodh-notifier can notify any URL). * Do not attempt to setup swiftstore disks if they appear commented out in the fstab. * Add an option to install Panko or not (do not install by default). * Set correct collect_statistics_interval and cluster_partition_handling. * If using victoria and up, do not use SSL for Glance, as the package has changed to not use UWSGI, and therefore, lost SSL support. * Added support for Manila (share as a service). * Add VRRP auth password (for Neutron L3 routers in HA). * Make it possible to select available Horizon themes. * Report and display machine block device controller and ethernet driver, with their firmware driver version. * Add a custom oci_facts.yaml in each nodes in /etc/facter/facts.d, maintained by both puppet and at provisionning time. This is helpful for anyone willing to customize his puppet environment depending on node role and this type of info, directly in puppet or hiera. * Depends on qemu-system, not just qemu (Closes: #992951). . [ Axel Jacquet ] * Added rate limit for swift proxies. openstack-cluster-installer (40.1) unstable; urgency=medium . * Fix swiftproxy.pp haproxy setup for Bullseye (ie: haproxy >= 2.1). openstack-cluster-installer (40) unstable; urgency=medium . * Fix compute.pp, volume.pp, swiftproxy.pp and network.pp not having the $all_rabbits_ips parameter and failing to apply. * Fix calling auto-join-rabbit-cluster in messaging nodes. * openstack-cluster-installer-build-live-image: do not modify config/build if the file doesn't exist. * Correctly schedule keystone bootstraping before doing the roles. * ocicli cluster-install: display VOLUME, SWIFTPROXY and SWIFTSTORE when installing them. * oci-poc: correctly bridge 192.168.105.1/24 to the ocibr1 (ie: the bridge connected to the eth1 of all VMs) instead of eth0, correcting the floating IP connection to the VMs. * oci-poc: allow using .raw images for glance upload. openstack-cluster-installer (39) unstable; urgency=medium . * Add -y flag when installing HPE tools. openstack-cluster-installer (38) unstable; urgency=medium . * Correctly generate passwords for service='bill'. * Switch to netcat-traditional instead of netcat (Closes: #981499). * Allow setting-up gnocchi-api on messaging+bill{mon,osd} separate nodes to enable better scalling. openstack-cluster-installer (37) unstable; urgency=medium . [ Thomas Goirand ] * oci-fixup-compute-node: Do not perform libvirt hack if not in stretch or buster. * Add HPE non-free tools installation support (hponcfg, storcli, ssacli), and automatically activate IPMI over LAN on them. * Fix typo when selecting ceph or swift backend for Glance. * Use roundrobbin (instead of source) for nova-api HAProxy backend. * oci-hdd-maint: reports correctly the serial numbers of HPE SmartArray connected HDD/SSD. . [ Cyril de Bourgues ] * Add 3 swift ring management utilities. openstack-cluster-installer (36) unstable; urgency=medium . * Fix galera_package_name when installing the Galera cluster. openstack-cluster-installer (35) unstable; urgency=medium . * oci-poc: restart isc-dhcp-server after starting VMs. * Add billmon and billosd roles, to have an independent Ceph for Telemetry. * Install chrony by default in target machines, not ntp. * Fix corosync setup with the Bullseye 3.1.x version. * Fix haproxy >= 2.1 incompatibility with reqrep / rspirep. openstack-cluster-installer (34) unstable; urgency=medium . * Upgrade IPMI before BIOS (as that's what Dell server needs). Also correctly report r420/r620 lifecycle version. * Fixed reporting phys block device size when MegaCli returns SECTOR_SIZE=0. * Report r420 / r620 Lifecycle version correctly. * Add ceph_osd_initial_setup to stop provisionning Ceph OSD once the cluster is in production. * Add force_no_bgp2host to make it possible to setup a compute cluster using bgp-to-the-host, but forcing Network nodes to use L2 connectivity. * Allow using non-DVR setup, with central network nodes (though using DVR for east-west traffic). * Fix distribution names inside the live image for the new version of live-build. openstack-cluster-installer (32) unstable; urgency=medium . * Removed the oci-poc-vms init script, and make it a normal shell script. * Fixed oci-poc-install-cluster-full to run with the new oci-poc-vms. * It's now possible to set %%COMPUTE_AGGREGATE%% in the "machine-set": of hardware-profile.json, and it will be replaced by whatever is set as compute-aggregate in auto-racking.json. * Add a new machine-renew-ipmi-password command to ocicli. * Setup kvm_intel / kvm_amd nested=0/1 at provision time, so it's not needed to reboot compute nodes after install to enable nested virt. Also support nested virt for amd processors. * Add a cluster option nova_scheduler_prefers_hosts_with_more_ram, controlling the ram_weight_multiplier (-1 / 1) of the Nova Scheduler. * Add messaging nodes for separate, dedicated, notification bus, which is increase the reliability if using notifications (no risk to overload the central rabbitmq service with the notification messages). * When there's both Ceph and Swift available, make it possible to select which type of backend to use for Ceph. * Made installing magnum optional. * Switch to using ceph-volume from the puppet-ceph class. openstack-cluster-installer (31) unstable; urgency=medium . * Agent: fix MegaRAID detection. * report.php: allow dots in HDD models and size. * Commands machine-megacli-apply and machine-check-megacli-applied can be used without a hardware profile name. * Add machine-guess-racking and machine-auto-rack, for filling-up the racking information automatically looking-up LLDP information against the /etc/openstack-cluster-installer/auto-racking.json configuration file. * Deny public access to SMTP, Keystone, Heat CFN and Aodh API on the VIP. * Add API calls to record hosts in DNS, add hosts to monitoring, and change plus record host root passwords. All of this using plugins in the form of customizable shell scripts. * Cinder-volume: allow one backend per disk. * Run ipmitool lan set 1 cipher_privs Xaaaaaaaaaaaaaa on R410/R610. * Add puppet-module-etcddiscovery as depends of puppet-module-oci. * Set the chassis/system serial as hostname in the live image, so that LLDP and dhclient uses it to advertize and broadcast a more meaningful hostname than just "debian". * Add "ocicli machine-auto-add" which adds a machine automatically to a cluster defined in openstack-cluster-installer.conf, using the role matched by the hardware-profiles.json, and the location defined in the auto-racking.json configuration file. * Add the possibility to completely automate: - megacli profiles. - racking info (ie: data center and rack position auto-fill). - adding machine to clusters. - installing the OS. This effectively makes it possible to automatically auto-provision servers in a "hand-free" mode as soon as they are plugged and booted. * Add --blockdevs / -b option to ocicli machine-list to display block devices. * Add an option to set the initial drive weight for swift. * Fixed VIP hostname in /etc/hosts if it was customized. * Add hdparm as runtime depends of -utils. * Also copy {account,container,object}.builder files when installing swift store and proxy nodes. * Install numactl and numad, and start numad on compute nodes. * Increases buffer for net.ipv6.neigh.default.gc_thresh{1,2,3} (previously done only for IPv4). * Do not include :443 in the keystone endpoint. * Stop generating /root/openrc. * Create all necessary Keystone roles, only in the first master, and only if the service is installed. * swiftproxy: set other proxies as backup in haproxy. * ocicli machine-list: sort machines by a much more natural order, which works in both cases where a machine has been added to a cluster or not: - .role,(.hostname|length),.hostname,.product_name,.serial * Add support for CephOSD on compute machines (ie: hyperconverged). openstack-cluster-installer (30) unstable; urgency=medium . * Better output for drives with MegaCLI in oci-hdd-maint. * Allow for on-the-fly change of machines IPMI network (can be needed if the IPMI network list and DHCP configuration has changed). * Switch all of the VMs of the oci-poc to virtio-scsi by default (instead of virtio-blk) so that we can test trim/discard. * oci-cluster-upgrade-openstack-release: Only perform OVS upgrades if the package openvswitch-common, and apt-cache policy shows it will upgrade. * Add installation of anacron in generic.pp (ie: all nodes). * Added oci-cluster-upgrade-old-swift-oci, to be run on the OCI machine, to upgrade from the older type of Galera setup that OCI was doing in the OCI released in Buster. * Make it possible to use Ceph from official Debian backports. * Live image: use by default a text-mode syslinux, so that it works over serial console. Also set the default timeout to 20 seconds. * Add a machine-wipe command to wipe the HDD when the machine is in live. * Add a cluster-reset, to reset all machines into live. * Fix cluster-install, so it really works now. * Add cluster-rolecounts-list / cluster-rolecounts-set commands. * Add -y and -u options in oci-hdd-maint. * Generate a root ssh key on all machines, and allow ssh as root from one volume note to another, to make backups of LVM over ssh possible. * Agent: do not report what lsblk reports as trans:iscsi. * Add racadm get BIOS.BiosBootSettings.HddFailover Enabled for r740xd. * Default to max_stacks_per_tenant=5000 (upstream default is 100). * Do not manage Octavia Amphora flavor in nova if not in initial cluster setup mode, in order to speed-up the run. * Allow renaming of the external network names, per compute/network node. * Activate enable_proxy_headers_parsing when available. * Small fix for per-machine libvirt extra CPU flags. * Use networks instead of each individual machines to do the swiftstore firewalling. Also firewall swiftproxies, which can also be stores. * Allow to use hostnames instead of chassis serial in many API calls. * Add an option for LVM volume nodes to configure reserved_percentage and max_over_subscription_ratio. * Remove options for LVM volume nodes max_luns_per_storage_group and check_max_pool_luns_threshold as it is specific to VNX driver. * Add a per (compute|network) node option to install Neutron BGP dragent. * Allow Dell Lifecycle automatic upgrades within the Agent. * Report and display all block devices handled by MegaCli (ie: LSI RAID controllers). * Automate building megacli RAID devices. * Use DEFAULT/default_ephemeral_format=ext4 in Nova. openstack-cluster-installer (29) unstable; urgency=medium . * Add the setup of a tempest node. * Write a correct oci-write-lvm-filter to be used in compute and volume nodes at first boot: it lists devices present in /etc/oci/data-disks only. * Fix enc not sending Gnocchi's statsd UUID. * Make cinder-api run on uwsgi, not Apache, if using >= Train. * Add Ussuri support in controller.pp & compute.pp. * Add -f flag in oci-hdd-maint when formating an XFS partition. * Add oci-cluster-upgrade-openstack-release to enable scripted upgrades from one OpenStack release to the next. * Switched cinder-api to uwsgi even in Stein. * Add oci-poc-provision-cloud in -utils, so it's easier to setup the PoC. * Add configuration of Nova's limit_tenants_to_placement_aggregate. * Send racadm command to set boot device for r740xd machines. * Configure /etc/ssh/sshd_config so that servers don't have the ssh listening on public IPs. We're listing ssh host key certs using a custom puppet fact. * The cluster values in variables.conf are now automatically transmited to the nodes matching the roles: of the matching entry. * Added initial and experimental support for Designate. * Improved oci-hdd-maint to show correctly the RAID slots, size, model and serial of HDDs. * Removed the dependency on approx. openstack-cluster-installer (28) unstable; urgency=medium . * Do not use StrictHostKeyChecking=no when rsyncing fernet tokens, as we have signed ssh host keys. * Add missing authors from d/copyright. * Add an option for LVM volume nodes to configure volume_copy_bps_limit. * ocicli: use csvlook from csvkit instead of column by default. * Fixup volume backup backend in volume.pp * Make it possible choose ceph or swift for cinder-backup. * Add oci-puppet to lauch puppet -t more easily. * Fix ports for Ceph OSDs so that they are each 4, not each 3 ports. * oci-make-osd: Fix calculating DEFROUTE_IP if using BGP 2 host. * Prioritize Swift over Ceph as a backend for cinder-backup and Glance. * Load kernel and ramdisk over http instead of tftp (much faster). * Make Glance swift-backend works if we're using a local swift and a non-rocky setup. * Fix generating the scp-ring script so it doesn't scp to IPMI IPs. * Fix swift ring building so it wont add IPMI IPs. * Add a new oci-cluster-upgrade-stretch-to-buster. * Set arp_responder to True everywhere. * Fix ipxe.php to chain to any IP address that runs on the PXE server, not just hardcoded 192.168.100.2. * Fix Glance over Ceph when >= train. * Add filters to lvm.conf to avoid nested LVM issues. * Add a new oci-cluster-upgrade-stretch-to-buster script to minimize downtime when upgrading from stretch. * Automatically add new cluster's SSH CA key into OCI's /etc/ssh/ssh_known_hosts * Configure ocicli within the PoC's PXE server. * Add a PoC oci-poc-{save,restore} to be able to save a cluster state. * Add sync-oci-code script. * Make neutron's global_physnet_mtu and path_mtu tweakable cluster variables. * octavia::worker: base image now uses 4GB HDD. * Add oci-cluster-upgrade-stretch-to-buster script (currently PoC) * Allow controllers configuration for Cinder storage_availability_zone and default_volume_type * Do not manage policy-rc.d for keystone if not using Rocky. * Redirect output of oci-fernet-keys-rotate to /dev/null to avoid cron job to spam. * Fix ENC regarding non-master-controller IPs. * Do not use StrictHostKeyChecking=no when rsyncing fernet tokens, as we have signed ssh host keys. * Add a --first-master option to ocicli cluster-set, so one can change who's the first master in the cluster. * Fix-up volume.pp to allow using ceph as backend for cinder-backup. openstack-cluster-installer (27) unstable; urgency=medium . * Automatically call "nova-manage cell_v2 discover_hosts" when an hypervisor is finished to install with puppet. * Fixed wrong parameter definition in swift{store,proxy}.pp classes. * Add --notes to ocicli. * Also report and display Dell's Lifecycle controller version. * Apply Dell racadm serial configuration by default when setting-up IPMI. * Add a "machine-apply-ipmi" command to ocicli, so that IPMI config can be re-applied with the current db configuration. * Add IPMI value settings in ocicli machine-set (doesn't commit). * Add configuration of IPMI VLANs. * Use escapeshellarg() for the username and pass when calling ipmitool. * Add an ocicli check-all-ipmi command. * Enhanced a lot machine-list, now has options to display whatever the user needs to be output, so that it may fit on a normal screen. * Also install syscfg on machines using iDRAC6 or 7. * Fix "ocicli cluster-list" when no cluster is defined. * Cannot delete a location if a network is using it. * Cannot delete a region if some locations are using it. * Cannot delete a cluster if some networks or machines are using it. * Add the concept of first and last IP of a subnet, and rework the IP allocation logic. * Correctly schedule the Galera cluster, so that the first Galera node will start first, then other controllers will wait for its SQL Galera to be up before attempting to join the new Galera cluster. * Fixed a bug in enc_get_mon_nodes() which was always using cluster_id='1', so failing if the cluster had a different ID. * Do not attempt db_sync for services if the node is not first_master, or if initial_cluster_setup is set to no. * Add a system to sign SSH host keys, so that the cluster can trust itself, and nova can safely scp disk images when migrating VMs. * Get the LLDPD info for each nic, store that in the db, and display with "ocicli machine-list -h". * Fix serial number fetch by the OCI agent on Supermicro machines. * Review the boot processs, and now correctly wait for networking to be up, plus package every binaries of the installed server in a -utils package. * Also automatically sign the live image host keys, and trust it. * Really disable notifications if disabled (by setting noop driver). openstack-cluster-installer (25) unstable; urgency=medium . * oci-agent: Add missing Breaks+Replaces (<< 24~) (Closes: #947385). openstack-cluster-installer (24) unstable; urgency=medium . * Also delete /var/lib/openstack-cluster-installer-poc on purge (Closes: #905516). * Add chmod after copy function for ssh private key on controllers * Set defaults_options max_conn to 40960 in swiftproxy.pp * Set swift_proxy_config DEFAULT/max_clients to 2048 on all proxy servers. * Add haproxy stats in the haproxy of swiftproxies. * Add the object-expirer daemon in *one* swiftproxy (because it's 1 per cluster). * Define ::nova::pci *before* ::nova::compute. * Set /etc/default/openvswitch-switch. * Now support setting-up CPU model at cluster and individual single compute node level. * Setup and use apparmor on libvirt in compute nodes (mandatory for live-migration to work in Buster). * Add oci-update-cluster-certs to update the cluster's API certs and internal cluster PKI automatically (and restart services). * Manage /etc/systemd/system/puppet.service.d/oci-ca-cert.conf with puppet. * Enable puppet if the 2nd run is a success. * Also setup neutron-metadata + haproxy server on network nodes. * Enable anti-affinity for Octavia's amphoraes. * Remove the use of spare_amphorae_pool_size, as it doesn't work with anti-affinity. * Make it possible to select, for each swift store and proxy, if they are storing accounts, containers, or objects. * Glance haproxy always verify TLS. * Make it possible to use an external swift as a backend for Glance and Cinder-backup. * Add a --hostname option to machine-set. * Package the openstack-cluster-installer-agent separately. * Use /usr/sbin/iptables-legacy and /usr/sbin/ip6tables-legacy if != stretch, runtime depends on puppet-module-voxpupuli-alternatives to do so. * Add more doc in README.md, especially a table of content in it. * Fix for iPXE not detecting the correct machine: there's now a db column to record the DHCP IP of machines. * Add missing option httpchk in the galera backend definition. * Make it possible to add custom parameters for machines & clusters simply by editing a variables.json configuration file, auto-generating the OCI REST API, ocicli and ocicli bash completion. * Add new parameters for swiftstore and swiftproxy: --server-per-port, --disk-chunk-size and --network-chunk-size. * Also setup etcd and etcd-discovery if setting-up Magnum. Now OCI runtime depends on puppet-module-cristifalcas-etcd. * Make it possible to automatically assign IPMI IP addresses of slave machines. * Add automatic BIOS upgrade throught the OCI agent when running live. openstack-cluster-installer (23) unstable; urgency=medium . [ Thomas Goirand ] * Install intel-microcode and smartmontools in nodes by default. * Add full installation and support for Magnum. * haproxy: correctly check SSL certificate of each service. * SSL certificate with -addext "subjectAltName = DNS:${SLAVE_NODE_HOSTNAME}" to avoid warnings. * Add a debmirror machine type. * Correctly generate the ec2 credential keys for Keystone. * Switch Octavia to ACTIVE_STANDBY by default. * Automatically format /dev/sdb as XFS over a volume group and mount it in /var/lib/nova/instances. * Automatically install megacli if requested in config file. * Fix CephOSD nodes when using NVME disks. * Allow using a Ceph cluster network and configure CephOSD nodes the correct way for it. * Always transmit an up-to-date /etc/hosts to all nodes throught the ENC. * Differenciate API root CA and OCI root CA. * Add a cluster option to use self signed certs or not. * Manage /etc/systemd/system/puppet.service.d/oci-ca-cert.conf with puppet. * Lots of fixes for OpenStack rocky. * Enable or disable nested virtualization on cluster or machine level. * Added an oci-update-cluster-certs script, so one can published updated certs in a whole cluster. * Optionnaly, a cluster can use an external swift cluster for Glance and Cinder backups. . [ Ondřej Nový ] * Running wrap-and-sort -bast. * Use debhelper-compat instead of debian/compat. openstack-cluster-installer (22) experimental; urgency=medium . [ Thomas Goirand ] * Add role-add, role-create, role-delete API and ocicli. * Add bash-completion script for ocicli. * Enhance ocicli network-list, add a network-set command. * Allow setting-up multiple external bridges for flat networks. * List all bridge setup with OCI in neutron's config, allowing a virtually unlimited number of bridges. * Fix service_credentials/cafile in ceilometer. * Add option to perform ipmitool settings in the target image when running on the slave image. * Add option to show the calculated IPMI console command. * Add some sysctl customization (low swappiness, higher conntrack, etc.). * Provision ssh public / private keypair between nova nodes in the /var/lib/nova/.ssh folder, to allow (live) migration using ssh / scp. * Switch to a db migration system with the schema saved in PHP format. * Add a cluster-show command. * Add the setup of chrony on all machines, with customization of time server host for the clock source. * Add the nf_conntrack module by default in /etc/modules. * Make sure python-keystonemiddleware is installed on swift-proxy nodes. * Firewall swift's container, account and object servers. * Empty DEFAULT/external_network_bridge by default, as this prevent using more than one external network. * Libvirt configuration on compute nodes (ie: /etc/default/libvirt-guests): - PARALLEL_SHUTDOWN=8 - SHUTDOWN_TIMEOUT=120 - START_DELAY=4 * Add qemu monitor on port 550XX for each VMs in the PoC. * Copy swift_fstab_dev_list.sh when provisionning. * Set Neutron's global_physnet_mtu and ml2's path_mtu if the VM net network has mtu != 0, allowing to set (for example) mtu = 9000. * Use wget to install openstack-backports-archive-keyring_0.1_all.deb instead of using apt-get update / apt-get install --allow-unauthenticated (which method doesn't work anymore in Buster). * Set haproxy's nbproc to 4 by default for swiftproxy, compute and controller nodes. * Copy the backport repository key file inside the targets instead of using the openstack-backports-archive-keyring package, which doesn't work anymore if using Buster. * Also install gnupg2 in the installed machines of the cluster. * Add support for Stein's separated placement. * Adapt puppet manifests so that they also work with Stein's puppet-openstack. * Add the feature to setup any machine with software RAID. * Using system serial number, and not chassis anymore. * Fully working Octavia support. . [ Oliver Chaze ] * swift: do not log in syslog general logs * increase default haproxy server timeout openstack-cluster-installer (21) unstable; urgency=medium . * Bugfix release for Buster which includes: - Fixed reserve_ip_to_all_slaves_of_network() call in network_add API call. - Correctly check for $mgmt_net["iface2"] and not $onenet when calculating --static-iface. - Fix block device list for swiftstore (statsd hostname was breaking it, ordering was broken). - Correctly set the erlang_cookie for rabbitmq as a random value. - Correctly use a a real random key for heat's encryption key. - Correct swift pipeline order when using encryption. - Correctly set unix rights of drives in /srv/node. openstack-cluster-installer (20) unstable; urgency=medium . * Set allow_resize_to_same_host to True on all nova nodes. * Set dhcp_domain to '' in nova.conf, to avoid .novalocal or .openstacklocal postfixed to hostname by DHCP. * Set important rabbitmq production parameters (the most important one is the autoheal, to avoid split-brain breakage). * Randomize the rabbitmq host list in transport_url, to avoid having all services connecting always to the same host. * Add support for Cinder volume over Ceph. * Provision Ceph OSD using bluestore. * Fix poc-bin/oci-poc-setup-bodi-hook motd. * Make Ceph optional on compute nodes: - Add a machine-show to show machine properties. - Add a machine-set, to select /var/lib/nova/instances on Ceph or not. - Modify the ENC to transmit the use_ceph_if_available variable. - Modify compute manifest to use the use_ceph_if_available and possibly use Ceph or not for /var/lib/nova/instances. * Better Octavia defaults. * Fix dns_domain of neutron.conf to the domain name of the deployed cloud. * Enable optional statsd logging for swiftstores. * Using uwsgi instead of Apache for heat-api, heat-api-cfn, nova-api, barbican-api and aodh-api. openstack-cluster-installer (19) unstable; urgency=medium . * Set all services to use RabbitMQ HA queues. * Explicitely choose the firewall type for Neutron agents. * Setup ceilometer::agent::central on controller nodes. * Setup cloudkitty-processor on multiple controllers using coordination URL. * Fix Ceilometer redis connection URLs. * Set resume_guests_state_on_host_boot in compute's nova.conf. * Rewrite the Location: headers coming from nova & heat, so that microversion redirections (ie: 302 redirect) can work. This repair listing instances in Horizon. * Correctly binds instance VNC servers to 0.0.0.0 on compute hosts. * Make the NoVNC console work. * Add rsync of glance images from first controller to the others. * Add script to add machines in the ring. * Fix Glance-api public_endpoint URL to correct HAProxy URL. openstack-cluster-installer (18) unstable; urgency=medium . * Fix cloudkitty's keystone_fetcher and gnocchi_fetcher cafile=. * Fix cloudkitty's rabbitmq amqp_sasl_mechanisms and login. * Setup correct database/connection for Gnocchi. * Setup redis for Gnocchi. * Live image: iomem=relaxed console=tty0, install plymouth (so that systemd prints on all consoles). * Add Panko and Ceilometer services. * New style of networking options for openstack-debian-images. * Add e2fsprogs to the slaves. * fernet_replace_keys => false by default, and also do not attempt to isntall fernet key "1" on each puppet run. * Nova default config on compute: - DEFAULT/use_cow_images = False. - preallocate_images = 'space'. - remove_unused_original_minimum_age_seconds = 604800 (one week). * Neutron default config: - service_plugins: add segments. - network_vlan_ranges = external (so, we use br-ex for the VLANs). * Do not chown swift:swift /srv/node/X if X isn't mounted (which may be the case if there's a borken drive in a swift cluster). * Add firewalling of Octavia API on the VIP. * Install default openstack-cluster-installer.conf for Buster. openstack-cluster-installer (17) unstable; urgency=medium . * Use host CPU model for VMs in the -poc. * Fix starting-up VMs with 3 drives in the PoC. * Run gnocchi-api using uwsgi rather than Apache to avoid port bind conflict. * Fix neutron.conf [database]/connection to be empty on compute nodes. * Fix puppet scheduling of swiftproxy install. * Fixed machines table with default SQL values. * Do not use INSERT with '' as value for IDs, just omit it, so it works with mariadb 10.3. * Remove the nobarrier option from Ceph OSD fstab, as it doesn't work anymore in Sid/Buster. * Do not use roundrobin for glancebe in haproxy, but source, else it wouldn't work properly. * Add ccze to all installed computers. openstack-cluster-installer (16) unstable; urgency=medium . * Add Gnocchi, Aodh, Cloudkitty and Octavia deployment. openstack-cluster-installer (15) unstable; urgency=medium . * Add Compute, Volume and Ceph support. * Correctly purges /etc/openstack-cluster-installer and /var/lib/oci. (Closes: #915781). openstack-cluster-installer (14) unstable; urgency=medium . * Add the possibility to customize the motd of installed machines. * Switch Heat API URL from /orchestration to /orchestration-api to avoid any clash with /orchestration-cfn. * Fixed rabbitmq SSL setup, and made heat work. * Add the setup of openstack-dashboard (aka: Horizon). * Add the setup of Barbican. * Add Swift encryption using a secret key stored in Barbican. * Add puppet-module-puppetlabs-firewall, and firewall the public IP. openstack-cluster-installer (13) unstable; urgency=medium . * Fix path of chown in swiftstore.pp. openstack-cluster-installer (12) unstable; urgency=medium . * Use Exec in puppet to change unix right of /srv/node/* folders in all swift store nodes, do not do that in rc.local anymore. openstack-cluster-installer (11) unstable; urgency=medium . * Fixed $machine_ip for the listen of memcache in swiftproxy nodes, so that it works with puppet 5. openstack-cluster-installer (10) unstable; urgency=medium . * Do not install openstack-backports-archive-keyring when setting-up buildd Debian repository. * Overrides epmd.socket to make sure epmd binds on all interfaces. openstack-cluster-installer (9) unstable; urgency=medium . * Automatically remove space in "connection = " in config file. * Add option to include incoming buildd, so it's easier to test in Sid. openstack-cluster-installer (8) unstable; urgency=medium . * Fixed Source URL in debian/copyright. * Some more fixups for OCI to work with Sid/Buster without additional repo. openstack-cluster-installer (7) unstable; urgency=medium . * Remove qemu-kvm from depends of openstack-cluster-installer, made the -poc package to use only qemu, suggesting qemu-kvm. This should ease transition to Testing. openstack-cluster-installer (6) unstable; urgency=high . * Add authentication system. * Switch to rocky when using backports. * Add lots of middleware in the default Swift pipeline. * Make it possible to expose the swift proxy-server directly without using the controller's haproxy. * Add read/write affinity. * Lots of minor tweaks and debugs. openstack-cluster-installer (5) unstable; urgency=medium . [ Ondřej Nový ] * Running wrap-and-sort -bast * Delete /var/lib/openstack-cluster-installer-poc on purge (Closes: #905516). . [ Thomas Goirand ] * Add swift deployment capability. * Add a CLI API client. openstack-cluster-installer (4) unstable; urgency=medium . * Add a glance cluster. openstack-cluster-installer (3) unstable; urgency=medium . [ Thomas Goirand ] * Setup a Keystone cluster with Haproxy and a VIP. . [ Ondřej Nový ] * Running wrap-and-sort -bast * d/control: Use team+openstack@tracker.debian.org as maintainer openstack-cluster-installer (2) unstable; urgency=medium . * Add openstack-cluster-installer-poc and puppet packages. * Add full network/ip manager. * Add automatic slave node cert management. * Automatically setup a galera cluster on slave controller nodes. openstack-cluster-installer (1) unstable; urgency=medium . * Initial release. openstack-meta-packages (0.35) unstable; urgency=medium . * Removed obsolete packages from depends. openstack-meta-packages (0.34) unstable; urgency=medium . * Removed python3-congressclient from openstack-clients package. openstack-meta-packages (0.33) unstable; urgency=medium . * Removed python3-ceilometerclient from openstack-clients depends. openstack-meta-packages (0.32) unstable; urgency=medium . * Fixed package homepage (Closes: #994768). * Add magnum, placement and tempest puppet module depends. openstack-meta-packages (0.31) unstable; urgency=medium . * Use stable-security from bullseye and on (Closes: #972745). * Use debhelper-compat = 11. openstack-meta-packages (0.30) unstable; urgency=medium . * Removed nova-consoleauth from depends (doesn't exist anymore). openstack-meta-packages (0.29) unstable; urgency=medium . * openstack-tempest-ci-live-booter: removed dependency on approx. openstack-meta-packages (0.28) unstable; urgency=medium . * Apply fix from Svein-Erik Skjelbred (Closes: #930992). openstack-meta-packages (0.27) unstable; urgency=high . * Replaced nova-placement-api by placement-api. openstack-meta-packages (0.26) unstable; urgency=medium . [ Ondřej Nový ] * Use debhelper-compat instead of debian/compat. . [ Thomas Goirand ] * Fix dependency on keystoneclient (Closes: #934644). openstack-meta-packages (0.25) unstable; urgency=medium . * Add puppet-module-panko to openstack-puppet-modules. openstack-meta-packages (0.24) unstable; urgency=medium . * Add puppet-module-octavia to openstack-puppet-modules plus a few more. * Add a number of clients to the openstack-clients metapackage. openstack-meta-packages (0.23) unstable; urgency=medium . [ Ondřej Nový ] * Running wrap-and-sort -bast . [ Thomas Goirand ] * Removed puppet-module-theforeman-dns from dependencies. openstack-meta-packages (0.22) unstable; urgency=medium . [ Ondřej Nový ] * Running wrap-and-sort -bast * d/control: Use team+openstack@tracker.debian.org as maintainer . [ Thomas Goirand ] * Added lots of new dependencies for openstack-puppet-modules. * Fixed minimum version of puppet-module-puppetlabs-apache. * Add puppet-module-puppetlabs-haproxy as depends. openstack-meta-packages (0.21) unstable; urgency=medium . [ Ondřej Nový ] * d/control: Set Vcs-* to salsa.debian.org * Running wrap-and-sort -bast . [ Thomas Goirand ] * Fixed preseed-lib to work with the new style of debconf templates from openstack-pkg-tools >= 70~. * Removed ceilometer-api and heat-api-cloudwatch from depends, as these don't exist anymore. * Added more dependencies in openstack-clients, and switch to using Python 3 version of clients. * Also remove ceilometer-collector from depends, also gone upstream. (Closes: #895120) * Add a new openstack-puppet-modules metapackage. openstack-meta-packages (0.20) unstable; urgency=medium . * Removed mongodb since it's not used by Telemetry anymore. openstack-meta-packages (0.19) unstable; urgency=medium . * Switch back to nova-compute-qemu, the -kvm doesn't work even with the nested virtualization turned on. * Removed apt-get install linux-image-amd64 since live-tools bug is fixed. * openstack-deploy runtime depends on e2fsprogs, xfsprogs (Closes: #887256). openstack-meta-packages (0.18) unstable; urgency=medium . [ Thomas Goirand ] * Restart swift services properly. * Set nova-placement-api as runtime depends for the proxy node. * Remove debian/openstack-tempest-ci.postinst that was installing the openstack.list file in /etc/tempest-ci. * live-booter depends on lsb-base. * Add bridge and iface config in live-booter init script. . [ Ondřej Nový ] * Update Swift configuration for Pike * Use deb.debian.org as Debian mirror openstack-meta-packages (0.17) unstable; urgency=medium . * Add new package: openstack-tempest-ci-live-booter. * openstack-deploy: Fix default package name for mysql-server to be mariadb-server. * Add preseed of the nova-placement-api in preseed lib. * Lots of rework in openstack-tempest-ci. * Add Debian live configurator package and scripts. openstack-meta-packages (0.16) unstable; urgency=medium . * Updated VCS fields. * Updated copyright format URL. * Ran wrap-and-sort -bast. * Updated maintainer field. * Standards-Version: 4.1.1. * Removed gbp.conf. * Deprecating priority extra as per policy 4.0.1. * openstack-tempest-ci with more parameters. * Removed nova-cert from openstack-compute-node, as nova-cert is gone. openstack-meta-packages (0.15) unstable; urgency=medium . [ Ondřej Nový ] * d/s/options: extend-diff-ignore of .gitreview * d/control: Using OpenStack's Gerrit as VCS URLs. . [ Thomas Goirand ] * Runtime depends on default-mysql-* (Closes: #848445, #848446). openstack-meta-packages (0.14) unstable; urgency=medium . [ Thomas Goirand ] * Update to mitaka instead of liberty. * Generating /etc/openstack-tempest-ci/openstack-ci.list dynamically to pickup Debian and OpenStack release names from pkgos.conf if it exists. * Removed activation of ec2 lib in preseed, as it's gone away from upstream code in Nova. * Added 14 new python-*client in the openstack-clients metapackage. * Added support for IPMI Debian Live provisionning of Tempest CI. * Added the automatic installation of: designate, barbican, manila, mistral, trove, congress, sahara, murano. * Also handling novaapi db. * Correctly use KEYSTONE_ADMIN_PASS and not AUTH_TOKEN anymore when preseeding endpoints. * DEBIAN_FRONTEND=noninteractive in osinstall_install_if_not_installed. * Adds missing mkdir -p /etc/openstack-tempest-ci in the openstack-tempest-ci package. * Adds Depends: ipmitool for openstack-tempest-ci. * Added some tweaks to make it work with Newton b1 as well (compatible with Mitaka though...). * Added openstack-tempest-merge-repo. * Fixed --shared option when deploying proxy network. * Fixed ssh user for cirros in openstack-deploy-tempest. * Switched to using liberty instead of Kilo. * Also setting OS_PROJECT_NAME in openrc.sh. * Fixed --is-public=True -> --visibility public when adding a new image. * Using openstackclient instead of keystoneclient cli when creating the testme user and project. * Defines the alt user and tenant correctly. * Fixed compute image_ssh_user. * Do not set public_router_id at all (this adds failures). * Added the setup of swift. * Standards-Version is now 3.9.8 (no change). . [ Ondřej Nový ] * Fixed VCS URLs (https). * Fixed tempest.api.object_storage.test_crossdomain.CrossdomainTest .test_get_crossdomain_policy . [ gustavo panizzo ] * openstack-deploy: Ignore errors preseeding man-db * openstack-deply: Determine the MySQL server version automatically * openstack-deploy: now it can be used in sid openstack-meta-packages (0.13) unstable; urgency=medium . * Removed openvswitch-datapath-dkms from recommends. openstack-meta-packages (0.12) unstable; urgency=medium . * Added scripts to do automatic network configuration of the proxy node. * Fixed os_preseed_set_dbconfig_conf to also write the MySQL root pass. openstack-meta-packages (0.10) unstable; urgency=medium . * Downgraded openvswitch-datapath-dkms and memcached from depends to recommends: mostly everything is in the mainstream kernel now. * Downgraded memcached from depends to recommends, as it's not available in some arch (Closes: #763539). * Added ceilometer and trove clients in the openstack-clients package. * Standards-Version is now 3.9.6. openstack-meta-packages (0.8) unstable; urgency=medium . * Uploading to unstable. openstack-meta-packages (0.7) experimental; urgency=medium . * Added missing python-heatclient dependency. * Adds ceilometer-alarm-evaluator & ceilometer-alarm-notifier to the openstack-proxy-node package. * Added mongodb-10gen-unstable, mongodb-nightly, mongodb-stable, mongodb-unstable and mongodb-10gen as possible candidates to replace mongodb. * Added a new openstack-deploy package. Note that currently, only the all-in-one setup has been tested. openstack-meta-packages (0.6) unstable; urgency=low . * Removed nova-api from the openstack-compute-node package, since the way to run the metadata service is now through quantum. * Now using Quantum as stronger Depends and not just Recommends:. * Added Heat in the proxy node. * Ran wrap-and-sort. * Fixed the nova-consoleproxy dependency. * Removed nova-console and added nova-consoleauth from -proxy-node. * Removed cinder-api and cinder-scheduler from the -proxy-node. * Bumped Standard-Version to 3.9.4. openstack-meta-packages (0.4) unstable; urgency=low . * Really uploading to unstable. openstack-meta-packages (0.3) experimental; urgency=low . * Uploading to unstable. * Fix typo in Vcs-Git (Closes: #705496). openstack-meta-packages (0.2) experimental; urgency=low . * Added Depends: nova-conductor in the openstack-proxy-node package. * Moved Depends: nova-xvpvncproxy to the openstack-compute-node package. openstack-meta-packages (0.1) experimental; urgency=low . * Initial release. pastebinit (1.7.0-1) unstable; urgency=medium . * New upstream release (1.7.0). * d/pastebinit.docs: Update documentation path for markdown change in upstream README file. pathspider (2.0.1-4) unstable; urgency=medium . * QA upload. * Avoid generating a runtime-dep on python3-nose perdition (2.2-3.4) unstable; urgency=medium . [ Andreas Beckmann ] * Non-maintainer upload. * Drop hardcoded library dependency. (Closes: #1068419) * Update (Build-)Depends on transitional packages. * The ldconfig trigger is already generated by debhelper. * Whitespace cleanup. . [ Michael Hudson-Doyle ] * d/patches/remove-strcasestr.patch: remove implementation of strcasestr that conflicts with that provided by glibc. (Closes: #1067403) perdition (2.2-3.3) unstable; urgency=medium . * Non-maintainer upload. * Add libnsl-dev to Build-Depends (Closes: #1065109, #1066417) perdition (2.2-3.2) unstable; urgency=medium . * Non-maintainer upload. * Add exit code true after invoke-rc.d in the files below (Closes: #999659). Thanks to Sergey Spiridonov. - perdition-ldap.postinst - perdition-ldap.prerm - perdition-mysql.postinst - perdition-mysql.prerm - perdition-odbc.postinst - perdition-odbc.prerm - perdition-postgresql.postinst - perdition-postgresql.prerm - perdition.postinst - perdition.preinst - perdition.prerm perdition (2.2-3.1) unstable; urgency=medium . * Non-maintainer upload. * Add missing include (Closes: #889289) . [ Helmut Grohne ] * Address FTCBFS: Let dh_auto_configure pass --host to ./configure. (Closes: #929978) perdition (2.2-3) unstable; urgency=high . * Correct syntax of ldconfig trigger (closes: #http://bugs.debian.org/847214) perdition (2.2-2) unstable; urgency=medium . * Switch to build depend on the metapackage default-libmysqlclient-dev (closes: #845889) * Update from standards version 3.9.6 to 3.9.8 * Update from compat level 7 to 9 perdition (2.2-1) unstable; urgency=medium . * New Upstream * Add support for forward secrecy (closes: #765867) * Make builds reproducible (closes: #787998) * Allow compilation against OpenSSL 1.1 (closes: #828494) * Update standards version to 3.9.6 perdition (2.1-2) unstable; urgency=medium . * Add missing call to dh_autoreconf perdition (2.1-1) unstable; urgency=low . * New Upstream Release (closes: #751430) * Fix for CVE-2013-4584 . Perdition fails to apply the administrator's specified ciphersuite preferences when making outbound connections to IMAP and POP servers using STARTTLS. For these outbound connections, it applies the administrator's listening ciphersuite preferences, which in many cases may be significantly weaker. . This is not a critical vulnerability (it can be mitigated, for example, by enforcing a strict minimalist ciphersuite on the backend server), but in the absence of any such mitigation, it may cause the connections between the proxy server and the backend server to negotiate a weaker ciphersuite than the administrator's stated intent. . (closes: #729028) * Versioned build dependency on dpkg-dev (>=1.16.1) (closes: #680086) * Use 1.0 as Managesieve version (closes: #726175) * Use autoreconf (closes: #737666) * Harden build flags * Build verbosely * Update standards version to 3.9.5 perdition (2.0-1) unstable; urgency=low . * New upstream release perdition (1.19~rc5-1) unstable; urgency=low * Use hardened build flags (closes: #655412) * Fix segmentation fault in strcasestr() (closes: #660735) * Added homepage to control file (closes: #594026) * Do not include .la files from binary packages (closes: #633184) * Set package format to 3.0 (quilt) perdition (1.19~rc4-4) unstable; urgency=low * Move local changes into patches (closes: 643242) perdition (1.19~rc4-3) unstable; urgency=low * Handle IPv6 address literals in --bind-address - Upstream patch http://hg.vergenet.net/perdition/perdition/rev/06e0c2cdb64f * managesieve: Fix handling of long authentication hashes - Upstream patch http://hg.vergenet.net/perdition/perdition/rev/6544c58ec144 - (closes: 630499) perdition (1.19~rc4-2) unstable; urgency=low * Clean up use of 4/8 byte types on architectures such as amd64 where ssize_t and long are 8 bytes white but int is only 4 bytes wide. - Fix possible premature connection closure. - Fix possible stack corruption in odbc module. - Critical portions of upstream patch http://hg.vergenet.net/perdition/perdition/rev/57268f4aaa94 - (closes: 59791) perdition (1.19~rc4-1) unstable; urgency=low * New Upstream * There is a typo in the changelog for 1.19~rc3-2 "libvanessa-logger-dev (>= 0.0.12)" should be "libvanessa-socket-dev (>= 0.0.12)". perdition (1.19~rc3-2) unstable; urgency=low * BuildDepend on libvanessa-logger-dev (>= 0.0.12) instead of (>= 0.0.10). (closes: #592459) * Update standards version from 3.9.0 to 3.9.1 perdition (1.19~rc3-1) unstable; urgency=low * New upstream perdition (1.19~rc2-1) unstable; urgency=low * New Upstream perdition (1.19~rc1-1) unstable; urgency=low * New Upstream - Separate pop_capability and imap_capability configuration parameters (closes: #564164) - Use "." as the delimiter for pop_capability (closes: #564164) perdition (1.18-2) unstable; urgency=low * Don't check for pid files after starting daemons in init script. They legitimately may not exist yet. * ssl: honour timeout during setup (closes: #561885) perdition (1.18-1) unstable; urgency=low * New Upstream perdition (1.18~rc3-1) unstable; urgency=low * New Upstream perdition (1.18~rc2-1) unstable; urgency=low * don't call make from perdition prerm script - make may not be installed - unnecessary clean up of user-generated files * Fix ldap module return values (closes: #548054) perdition (1.18~rc1-2) unstable; urgency=low * Update build dependency on libvanessa-socket-dev to 0.0.8. - Perdition 1.18~rc1 requires symbols that are new in vanessa-socket 0.0.8. (closes: #544876) perdition (1.18~rc1-1) unstable; urgency=low * New Upstream - Pass include '\0' in the length passed to yp_match() in the NIS module Thanks to Robert Edmonds (closes: #412151) - Use ca_path and ca_file for incoming connections Thanks to Sven Hartge (closes: #380390) - Fix buffer overflow in options logging code that caused perdition to segfault on start-up if the ssl_mode string supplied was greater than 26 characters long. Thanks to Laurent Licour for the fix. (closes: #395408) - Refer to libperditiondb_postgresql.so.0 in POSTGRESQL of perditiondb(5) (closes: #507414) - Don't accept STARTTLS command in imap4 mode if it hasn't been enabled in the configuration. (closes: #500554) - Process subjectAltName fields (closes: #513461) - Support ldap v3 (closes: #473570) - Support ldaps (closes: #477159) perdition (1.17-8) unstable; urgency=low * Change build-dependancy from libdb4.3-dev to libdb-dev, which currently depends on libdb4.6-dev. This is to allow libdb4.3 to be removed from the archive. (closes: #442663) perdition (1.17-7) unstable; urgency=low * Remove the unneccesary Build-Depends on automake as part of automake transition. http://wiki.debian.org/AutomakeTransition (closes: #376643) * Fix documentation of map_library. Thanks to Anand Kumria. (closes: #354527) * Add suggests perdition-ldap, perdition-mysql, perdition-odbc, perdition-postgresql to perdition * Update from standards version 3.6.1 to 3.7.2 perdition (1.17-5) unstable; urgency=low * Rebuild, as i386 upload was missing depenancies on vanessa libraries. This was caused by a ~/.magic in the build environment that had very unexpected side affects. Primarily causing file to return "data" instead of "ELF" on ELF executables, and thus causing all executables to be skipped by dh_shlibdeps. (closes: #344797) * Tell dh_shlibdeps that base libraries are in the perdition package and found in debian/perdition/usr/lib perdition (1.17-4) unstable; urgency=low * Update MySQL build dependancy to libmysqlclient15-dev (closes: 343790) perdition (1.17-3) unstable; urgency=low * Revert to using ldap_init() instead of ldap_initialize() which seems to be broken on debian's ldap, 2.1.30. I am not sure what version it works for, if any. http://www.openldap.org/lists/openldap-software/200406/msg00688.html perdition (1.17-2) unstable; urgency=low * Build packet code for daemon modules as a shared module, else it brakes the build on smoe arches. This is an attempt at a more permanant solution to this problem, rather than the band-aid solution included in 1.15-5. Thanks to Kurt Roeckx (closes: Bug#315771) * Forcibly disable build of ldap documentation. * Change build-dependancies on virtual packages to non-virtual packages - libdb-dev -> libdb4.3-dev - libmysqlclient-dev -> libmysqlclient14-dev Thanks to Kurt Roeckx perdition (1.17-1) unstable; urgency=low * Update postgresql-dev build dependancy to libpq-dev * New Upstream perdition (1.15-5) unstable; urgency=low * Don't build packet code for deamon module as a staticly linked object, as introduced in 1.15-4, as this breaks building on some architectures. Instead, just omit building the sample client and server program, which are never installed anyway. (closes: Bug#291132) perdition (1.15-4) unstable; urgency=low * Rebuilt with correct libary dependancies. It turns out that when 1.15-3 (and possibly other releases) were built the vanessa libraries were present in a local directory, as well /usr/lib, which caused some dependancies to be omitted. (closes: Bug#290794) * Move shared packet code for deamon module into a staticly linked library as having multiple objects link against packet.o breaks the build sometimes. perdition (1.15-3) unstable; urgency=low * Fixed problem with SSL+inetd mode not working if debug was enabled. (Roberto Suarez Soto) (closes: Bug#287017) * Fixed compile gcc-4.0 compile problem. (Andreas Jochens) (closes: Bug#287911) perdition (1.15-2) unstable; urgency=low * Removed ldap (latex) documentation as it can no longer be built on debian. (closes: Bug#266067) perdition (1.15-1) unstable; urgency=low * Fixed a bug in the forming of the return string from an LDAP lookup. (closes: Bug#243898) * Use compat 4 * Removed half-broken depends perdition (1.14release-1) unstable; urgency=low * Ldap filter parsing code has been completely rewritten and should now allow substitutions in any part of the URL. (Actually this was fixed in 1.10, but I missed closing the bug report.) (closes: Bug#203734) perdition (1.13-1) unstable; urgency=low * New Upstream perdition (1.12release-1) unstable; urgency=low * New Upstream perdition (1.11release-3) unstable; urgency=low * Child processes don't delete the pid file (closes: Bug#222181) perdition (1.11release-2) unstable; urgency=low * Added PID file support (closes: Bug#219248) Code has been incoporated into CVS for the next release Thanks to Roland Rosenfeld perdition (1.11release-1) unstable; urgency=low * New Upstream perdition (1.11beta8-7) unstable; urgency=low * Build dependancy against new libgdbm-dev package instead of libgdbm1-dev. Also rebuilt against libgdbm2. As advised via email bu James Troup. @ New starndards version. 5.3.10 perdition (1.11beta8-6) unstable; urgency=low * New standards version. * Removed spurious multi-line string constant from perdition_verify_result() which seems to cause compile problems on at least Debian HPPA. (closes: Bug#193857) perdition (1.11beta8-5) unstable; urgency=low * Fixed typo in init script. (closes: Bug#193673) * Also from previous package release. (closes: Bug#192479) perdition (1.11beta8-3) unstable; urgency=low * Fix so perdition can build against libdb4.1-dev (closes: Bug#191032) perdition (1.11beta8-2) unstable; urgency=low * Updated versioned dependancies on libvanessa-adt-dev, libvanessa-socket-dev and libvanessa-logger-dev perdition (1.11beta8-1) unstable; urgency=low * Imap subfolders should work correctly. Actually this was fixed a long time ago. (closes: Bug#171558) * Not a bug. Use the domain delimiter configuration parameter. (closes: #171080) * Compile aggainst mysqlclient12. Oooh, I so love changing crap like that. * Moved back out of non-US. Where is the smart money on when it will have move yet again because of some dependancy? I say 2 years. pgmodeler (1.1.3-1) unstable; urgency=medium . * New upstream version 1.1.3. phoc (0.39.0+ds-1) unstable; urgency=medium . * New upstream release * d/control: Use shared gmobile * Install new phoc.gsettings manual page phosh-tour (0.39.0-1) unstable; urgency=medium . * New upstream release * d/control: Use shared gmobile php-codesniffer (3.9.2-1) unstable; urgency=medium . [ jrfnl ] * Changelog for the 3.9.2 release . [ David Prévot ] * Update repository source * Adjust package to composer source * Update copyright (years) * Update manpages * Adaptations for debci php-mockery (1.6.12-1) unstable; urgency=medium . [ Nathanael Esayeas ] * Fix mocking anonymous classes (#1415) * Changelog v1.6.12 (#1418) . [ Rolands Usāns ] * Fix PHP Doc Comments (#1410) . [ David Prévot ] * Don’t import upstream tools/ * Update Standards-Version to 4.7.0 playmidi (2.4debian-15) unstable; urgency=medium . * QA upload. . * Added d/gbp.conf to describe branch layout. * Updated vcs in d/control to Salsa. * Updated d/gbp.conf to enforce the use of pristine-tar. * Updated Standards-Version from 3.9.3 to 4.7.0. * Use wrap-and-sort -at for debian control files * Trim trailing whitespace. * debian/copyright: use spaces rather than tabs to start continuation lines. * debian/rules: Use dh_prep rather than "dh_clean -k". * Use set -e rather than passing -e on the shebang-line. * Bump debhelper from deprecated 7 to 13. * Set debhelper-compat version in Build-Depends. * Corrected formatting and content of d/copyright. * Updated d/control, d/copyright with new home page location and added d/watch. * Moved some d/rules setup to individual files. * Flagged in d/control that no root build is needed. puppet-module-tempest (24.0.0-3) unstable; urgency=medium . * Fix tempest.conf path in revert-workspace-patch.patch. puppet-module-tempest (24.0.0-2) unstable; urgency=medium . * Fix doubled-defined tempest_config_file in init.pp. pycrc (0.10.0-3) unstable; urgency=medium . * Delete src/__init__.py, it isn’t useful and ends up installed as /usr/lib/python3/dist-packages/__init__.py which isn’t appropriate. Closes: #1071060. * Standards-Version 4.7.0, no change required. * Fix the upstream URL in debian/copyright. python-autoray (0.6.12-1) unstable; urgency=medium . * Updated to new upstream version 0.6.12. * Updated 002-fix-for-test-file.patch to fit new upstream version. python-binary-memcached (0.31.2+dfsg1-2) unstable; urgency=medium . * Removed python3-m2r build-depends (Closes: #1071074). python-colormap (1.1.0-1) unstable; urgency=medium . * Team upload. * New upstream release. * debian/control: Update build-dependencies. * debian/rules: Remove useless override to dh_fixperms. python-json-log-formatter (1.0.0-1) unstable; urgency=medium . * Team upload. * New upstream release. python-samsung-mdc (1.12.2-2) unstable; urgency=medium . * Source-only upload for migration to testing. python-samsung-mdc (1.12.2-1) unstable; urgency=medium . * Initial release. (Closes: #1069829) python-tenacity (8.3.0-1) unstable; urgency=medium . * Team upload. . [ Ondřej Nový ] * Remove myself from Uploaders. . [ Colin Watson ] * New upstream release. * Use pybuild-plugin-pyproject. python-typing-extensions (4.11.0-1) unstable; urgency=medium . * Team upload. * New upstream release. python-vitrageclient (5.0.0-3) unstable; urgency=medium . * Add support-networkx-3.patch. r-cran-cmstatr (0.9.3-1) unstable; urgency=medium . * Team upload. * New upstream version * Standards-Version: 4.7.0 (routine-update) * Set upstream metadata fields: Bug-Database, Bug-Submit, Repository, Repository-Browse. r-cran-htmltools (0.5.8.1-1) unstable; urgency=medium . * New upstream version * Standards-Version: 4.7.0 (routine-update) * dh-update-R to update Build-Depends (routine-update) * Remove constraints unnecessary since bullseye (oldstable): + Build-Depends: Drop versioned constraint on r-cran-fastmap (>= 1.1.0). r-cran-promises (1.3.0+dfsg-1) unstable; urgency=medium . * Team upload. * New upstream version * Standards-Version: 4.7.0 (routine-update) * dh-update-R to update Build-Depends (routine-update) * Remove constraints unnecessary since bullseye (oldstable): + Build-Depends: Drop versioned constraint on r-cran-fastmap (>= 1.1.0). r-cran-sass (0.4.9+dfsg-1) unstable; urgency=medium . * New upstream version * Standards-Version: 4.7.0 (routine-update) * dh-update-R to update Build-Depends (routine-update) * Remove constraints unnecessary since bullseye (oldstable): + Build-Depends: Drop versioned constraint on r-cran-htmltools (>= 0.5.1). * Set LANG=C in autopkgtest relational (3.2-1) unstable; urgency=low . * New upstream release * Moved from github to codeberg * Add Vcs-* fields to d/control * Change email to the debian one requests (2.31.0+dfsg-2) unstable; urgency=medium . * Team upload. * Fix FTBFS with pytest 8 (Closes: #1063985) rtl-ais (0.3+git20240507+ds-1) unstable; urgency=medium . * Initial release. (Closes: #1070697) rust-ahash-0.7 (0.7.8-2) unstable; urgency=medium . * relax to build-depend unversioned on dh-cargo * declare compliance with Debian Policy 4.7.0 * update copyright info: fix file path * tidy patches 2001_* rust-asahi-bless (0.2.0-1) unstable; urgency=medium . * Package asahi-bless 0.2.0 from crates.io using debcargo 2.6.0 (See #1055634) rust-asahi-btsync (0.2.0-1) unstable; urgency=medium . * Package asahi-btsync 0.2.0 from crates.io using debcargo 2.6.0 (See #1055634) rust-asahi-nvram (0.2.0-1) unstable; urgency=medium . * Package asahi-nvram 0.2.0 from crates.io using debcargo 2.6.0 (Closes: #1055634) rust-asahi-wifisync (0.2.0-1) unstable; urgency=medium . * Package asahi-wifisync 0.2.0 from crates.io using debcargo 2.6.0 (See #1055634) rust-roadmap (0.6.0-3) unstable; urgency=medium . * add patch 1001 to accept newer branch of crate serde_yaml; relax (build-)dependencies for crate serde_yaml; closes: bug#1071212, thanks to Peter Green * update copyright info: fix file path * declare compliance with Debian Policy 4.7.0 rust-selinux-sys (0.6.7-3) unstable; urgency=medium . * Team upload. * Package selinux-sys 0.6.7 from crates.io using debcargo 2.6.1 * Tighten bindgen dependency. rust-selinux-sys (0.6.7-2) unstable; urgency=medium . * Team upload. * Package selinux-sys 0.6.7 from crates.io using debcargo 2.6.1 * Workaround missing type error when building on 32-bite architectures with time64 rustc (1.71.1+dfsg1-2) unstable; urgency=medium . * d/control: fix package names in B+R (Closes: #1071242) rustc (1.71.1+dfsg1-1) unstable; urgency=medium . * upload to unstable rustc (1.71.1+dfsg1-1~exp2) experimental; urgency=medium . * d/control: properly B+R old rustc packages (Closes: #1071005) rustc (1.71.1+dfsg1-1~exp1) experimental; urgency=medium . [ Fabian Grünbichler ] * New upstream release (Closes: #1069019) * d/control: tighten cargo versions (Closes: #1029007) * d/control: remove B-D on cmake-3 (Closes: #1067109) * d/control: re-enable git-using tests * rust-doc: fix references to cargo-doc (Closes: #969210, #1063390) * rust-src: ship Cargo.lock (Closes: #1057736) * d/control: add libssl and prefer curl with openssl (Closes: #962508) * d/control: move LLVM symlinks to own package (Closes: #1021868) . [ Rob Shearman ] * Support finding llvm-profdata & llvm-cov with cargo-binutils sane-backends (1.3.0-1) unstable; urgency=medium . * New upstream release. - debian/sane-utils.install: Install new saned.install.md. - Refresh patches. * debian/control: - Replace obsolete pkg-config with pkgconf. * New debian/patches/0610-fix_groff_font_warnings.patch: - Fix missing font messages. * Install saned.service mask symlink into /usr (Closes: #1059186). - Thanks to Chris Hofstaedtler . * debian/copyright: - Add 2024 to myself. - New po/zh_CN.po. sendmail (8.18.1-3) unstable; urgency=medium . * QA upload * Enable _FFR_REJECT_NUL_BYTE for rejecting mail that include NUL byte * By default enable rejecting mail that include NUL byte. set confREJECT_NUL to 'true' by default . User could disable by setting confREJECT_NUL to false. (Closes: #1070190). Close a variant of CVE-2023-51765 aka SMTP smuggling. snd (24.4-1) unstable; urgency=medium . * New upstream version 24.4 + Update d/upstream-changelog * Bump standards version to 4.7.0 sucrack (1.2.3-7) unstable; urgency=medium . [ Debian Janitor ] * Update standards version to 4.6.1, no changes needed. . [ Sophie Brun ] * Refresh patches * Add missing include (Closes: #1066503) * Bump Standards-Version to 4.7.0 sucrack (1.2.3-6) unstable; urgency=medium . * Team Upload . [ Samuel Henrique ] * Bump DH to 13 * Bump Standards-Version to 4.5.1 * Add salsa-ci.yml * Configure git-buildpackage for Debian * d/control: Add 'Rules-Requires-Root: no' . [ Debian Janitor ] * Set debhelper-compat version in Build-Depends. * Drop unnecessary dependency on dh-autoreconf. sucrack (1.2.3-5) unstable; urgency=medium . * Team upload. [ Raphaël Hertzog ] * d/control: - Update Vcs-Git and Vcs-Browser for the move to salsa.debian.org - Update team maintainer address to Debian Security Tools . [ SZ Lin (林上智) ] * Add upstream metadata file * d/control: - Bump debhelper version to 11 - Bump Standards-Version to 4.2.1 - Replace "extra" with "optional" in priority field - Remove dh-autoreconf for Build-Depends: since it is enabled by default now - Remove trailing space * d/compat: - Bump compat version to 11 * d/copyright: - Fix license declaration inconsistency issue (Closes: #908634) - Fix violation of DEP-5 format * d/rules: - Add override_dh_missing target (--fail-missing) sucrack (1.2.3-4) unstable; urgency=medium . * Team upload. . [ Marcos Fouces ] * Updated watch file. * Fix typo in control file. * Delete dirs file. No need for it sucrack (1.2.3-3) unstable; urgency=medium . [ Raphaël Hertzog ] * Team upload. * Updated watch file. Thanks to Marcos Fouces for the patch (Closes: #826517) * Bumd Standards-Version to 3.9.8. . [ Sophie Brun ] * Add a patch to fix FTBFS with ld --as-needed. Thanks to Gianfranco Costamagna and Logan Rosen sucrack (1.2.3-2) unstable; urgency=medium . * Take over the package in the pkg-security team with the permission of Eva Ramon * Use debhelper 9 * Use dh-autoreconf (Closes: #744519, #727978) * Add a patch to fix a typo error in sucrack sucrack (1.2.3-1) unstable; urgency=low . * Non-maintainer upload * Compile with --enable-statistics (Closes: #687836) sucrack (1.2.3-0.9) unstable; urgency=low * Non-maintainer upload * Fixed lintian warning: hardening-no-stackprotector * Fixed lintian warning: hardening-no-relro * Lintian override for warning: hardening-no-fortify sucrack (1.2.3-0.7) unstable; urgency=low * Non-maintainer upload * Fix Ubuntu FTBFS with ld --as-needed, build with -pthread (Closes: #641433) * Upload sponsored by Philipp Hug ** Added Eva Ramon to Uploaders sucrack (1.2.3-0.5) unstable; urgency=low * Non-maintainer upload + Last update by the mantainer was five years ago * New upstream release * New Standards Version 3.9.3 * Clean lintian errors * Clean lintian warnings * Quilt 3.0 format applied to package source * Remove restoring of config.sub and config.guess in clean target * Added watch file * Upload sponsored by Philipp Hug ** Current maintainer is MIA, he was also sponsored by me sucrack (1.2.2-2) unstable; urgency=low * Upstream release without new version * Upload sponsored by Philipp Hug sucrack (1.1-3) unstable; urgency=low * Patched to link dynamically * Upload sponsored by Philipp Hug sucrack (1.1-2) unstable; urgency=low * Moved to main suru-icon-theme (2024.02.1-2) unstable; urgency=medium . * debian/control: + Bump Standards-Version to 4.7.0. No changes needed. * debian/watch: + Update file for recent GitLab changes of the tags overview page. uim (1:1.8.8-9.4) unstable; urgency=medium . * Non-maintainer upload. . [ Andreas Metzler ] * Ignore internal symbols in debian/libuim8.symbols. Closes: #1070389 unrar-free (1:0.3.0-0.1) unstable; urgency=medium . * Non-maintainer upload. * d/watch: Scan using git mode. * New upstream release. (Closes: #453891, #270751) * d/copyright: Drop info that was removed upstream. (Closes: #1023405) * Description: Drop outdated sentence about newer RAR formats. * Move from B-D: pkg-config to pkgconf. vip-manager2 (2.5.0-1) unstable; urgency=medium . * New upstream version 2.5.0. * debian/tests: Use dashes in test names. vulture (2.11-1) unstable; urgency=medium . * Team upload. * New upstream release. * Use pybuild-plugin-pyproject. webkit2gtk (2.44.2-1) unstable; urgency=high . * New upstream release. * debian/upstream/signing-key.asc: - Replace Carlos Garcia's DSA key with the new RSA one. wireshark (4.2.5-1) unstable; urgency=medium . * New upstream version: - security fixes: - MONGO and ZigBee TLV dissector infinite loops (CVE-2024-4854) - The editcap command line utility could crash when chopping bytes from the beginning of a packet. (CVE-2024-4853) - The editcap command line utility could crash when injecting secrets while writing multiple files (CVE-2024-4855) * debian/patches: Drop cherry picked patch already integrated upstream * Update symbols files wlc (1.14-1) unstable; urgency=medium . * Team upload. * New upstream version 1.14. * d/watch: Bump version from 3 to 4, no changes needed. * d/control: - Change build dependencies indentation. - Build-Depend on pybuild-plugin-pyproject. - Set field Rules-Requires-Root:no. - Bump Standards-Version to 4.7.0, no changes needed. - Update Description field with latest upstream information. * d/wlc.1: - Removed font C since it cannot be selected. - Remove upstream specific installation step. - Fix typos. - Added myself in the copyright section. xarray-safe-s1 (2024.05.16-1) unstable; urgency=medium . * New upstream release. xsar (2024.05.15-1) unstable; urgency=medium . * New upstream release. * debian/control: - Recommend python3-xarray-safe-rcm, python3-xarray-safe-s1, and python3-xradarsat2. zarr (2.18.1+ds-1) unstable; urgency=medium . * New upstream release. zfs-linux (2.2.4-1) unstable; urgency=medium . * New upstream version 2.2.4 * d/patches: remove patches already applied by upstream * libzpool: update symbol list * d/tests: skip some flaky tests in zfs-test-suite-{1,2} * d/control: update python3 dependency of zfs-dkms * d/symbols: remove unreferenced libspl symbols (closes: #1070899)