head	1.64;
access;
symbols
	pkgsrc-2026Q1:1.63.0.2
	pkgsrc-2026Q1-base:1.63
	pkgsrc-2025Q4:1.62.0.6
	pkgsrc-2025Q4-base:1.62
	pkgsrc-2025Q3:1.62.0.4
	pkgsrc-2025Q3-base:1.62
	pkgsrc-2025Q2:1.62.0.2
	pkgsrc-2025Q2-base:1.62
	pkgsrc-2025Q1:1.59.0.4
	pkgsrc-2025Q1-base:1.59
	pkgsrc-2024Q4:1.59.0.2
	pkgsrc-2024Q4-base:1.59
	pkgsrc-2024Q3:1.57.0.2
	pkgsrc-2024Q3-base:1.57
	pkgsrc-2024Q2:1.56.0.2
	pkgsrc-2024Q2-base:1.56
	pkgsrc-2024Q1:1.54.0.4
	pkgsrc-2024Q1-base:1.54
	pkgsrc-2023Q4:1.54.0.2
	pkgsrc-2023Q4-base:1.54
	pkgsrc-2023Q3:1.51.0.4
	pkgsrc-2023Q3-base:1.51
	pkgsrc-2023Q2:1.51.0.2
	pkgsrc-2023Q2-base:1.51
	pkgsrc-2023Q1:1.50.0.2
	pkgsrc-2023Q1-base:1.50
	pkgsrc-2022Q4:1.48.0.2
	pkgsrc-2022Q4-base:1.48
	pkgsrc-2022Q3:1.46.0.2
	pkgsrc-2022Q3-base:1.46
	pkgsrc-2022Q2:1.43.0.4
	pkgsrc-2022Q2-base:1.43
	pkgsrc-2022Q1:1.43.0.2
	pkgsrc-2022Q1-base:1.43
	pkgsrc-2021Q4:1.41.0.2
	pkgsrc-2021Q4-base:1.41
	pkgsrc-2021Q3:1.38.0.4
	pkgsrc-2021Q3-base:1.38
	pkgsrc-2021Q2:1.38.0.2
	pkgsrc-2021Q2-base:1.38
	pkgsrc-2021Q1:1.35.0.2
	pkgsrc-2021Q1-base:1.35
	pkgsrc-2020Q4:1.34.0.2
	pkgsrc-2020Q4-base:1.34
	pkgsrc-2020Q3:1.33.0.2
	pkgsrc-2020Q3-base:1.33
	pkgsrc-2020Q2:1.30.0.2
	pkgsrc-2020Q2-base:1.30
	pkgsrc-2020Q1:1.27.0.2
	pkgsrc-2020Q1-base:1.27
	pkgsrc-2019Q4:1.24.0.4
	pkgsrc-2019Q4-base:1.24
	pkgsrc-2019Q3:1.23.0.2
	pkgsrc-2019Q3-base:1.23
	pkgsrc-2019Q2:1.22.0.2
	pkgsrc-2019Q2-base:1.22
	pkgsrc-2019Q1:1.21.0.2
	pkgsrc-2019Q1-base:1.21
	pkgsrc-2018Q4:1.18.0.2
	pkgsrc-2018Q4-base:1.18
	pkgsrc-2018Q3:1.13.0.6
	pkgsrc-2018Q3-base:1.13
	pkgsrc-2018Q2:1.13.0.4
	pkgsrc-2018Q2-base:1.13
	pkgsrc-2018Q1:1.13.0.2
	pkgsrc-2018Q1-base:1.13
	pkgsrc-2017Q4:1.12.0.8
	pkgsrc-2017Q4-base:1.12
	pkgsrc-2017Q3:1.12.0.6
	pkgsrc-2017Q3-base:1.12
	pkgsrc-2017Q2:1.12.0.2
	pkgsrc-2017Q2-base:1.12
	pkgsrc-2017Q1:1.10.0.6
	pkgsrc-2017Q1-base:1.10
	pkgsrc-2016Q4:1.10.0.4
	pkgsrc-2016Q4-base:1.10
	pkgsrc-2016Q3:1.10.0.2
	pkgsrc-2016Q3-base:1.10
	pkgsrc-2016Q2:1.7.0.2
	pkgsrc-2016Q2-base:1.7
	pkgsrc-2016Q1:1.5.0.2
	pkgsrc-2016Q1-base:1.5
	pkgsrc-2015Q4:1.4.0.2
	pkgsrc-2015Q4-base:1.4
	pkgsrc-2015Q3:1.2.0.4
	pkgsrc-2015Q3-base:1.2
	pkgsrc-2015Q2:1.2.0.2
	pkgsrc-2015Q2-base:1.2;
locks; strict;
comment	@# @;


1.64
date	2026.04.17.08.35.42;	author adam;	state Exp;
branches;
next	1.63;
commitid	nb8GzjS8LPllYhCG;

1.63
date	2025.12.28.10.07.56;	author adam;	state Exp;
branches;
next	1.62;
commitid	5s54PVYKc6JA1aoG;

1.62
date	2025.06.04.14.43.09;	author taca;	state Exp;
branches;
next	1.61;
commitid	0pBm488TcsMFcAXF;

1.61
date	2025.05.06.12.07.35;	author wiz;	state Exp;
branches;
next	1.60;
commitid	XKZsX38e3wO0hQTF;

1.60
date	2025.04.06.16.15.43;	author tsutsui;	state Exp;
branches;
next	1.59;
commitid	H96kKFbSHwH2C0QF;

1.59
date	2024.11.26.11.38.09;	author adam;	state Exp;
branches;
next	1.58;
commitid	AhoJBUGFiFFNh9zF;

1.58
date	2024.10.24.17.23.43;	author adam;	state Exp;
branches;
next	1.57;
commitid	VLjwgrvvvGeQfWuF;

1.57
date	2024.06.27.09.50.27;	author adam;	state Exp;
branches;
next	1.56;
commitid	UpTY7cNf8xOMzBfF;

1.56
date	2024.05.08.15.54.54;	author adam;	state Exp;
branches;
next	1.55;
commitid	dIJedmBJZnUmcd9F;

1.55
date	2024.04.15.07.16.38;	author adam;	state Exp;
branches;
next	1.54;
commitid	wjVrGMTRzgWo4d6F;

1.54
date	2023.11.16.16.37.31;	author dogcow;	state Exp;
branches;
next	1.53;
commitid	vxooyt1dvhBR1RME;

1.53
date	2023.11.15.18.54.43;	author wiz;	state Exp;
branches;
next	1.52;
commitid	fiF0sOo1KnyBOJME;

1.52
date	2023.10.10.16.05.01;	author taca;	state Exp;
branches;
next	1.51;
commitid	nBrLwNKe7U9t26IE;

1.51
date	2023.04.29.08.01.06;	author wiz;	state Exp;
branches
	1.51.4.1;
next	1.50;
commitid	8eZ9Hjsd0f4iDYmE;

1.50
date	2023.01.10.02.12.40;	author tnn;	state Exp;
branches;
next	1.49;
commitid	omdXPheiFrxXcW8E;

1.49
date	2023.01.03.15.27.23;	author wiz;	state Exp;
branches;
next	1.48;
commitid	pOhinCxJWnAAP68E;

1.48
date	2022.11.29.13.20.23;	author jperkin;	state Exp;
branches
	1.48.2.1;
next	1.47;
commitid	1MgzZVvg3NwpeB3E;

1.47
date	2022.10.25.07.46.11;	author wiz;	state Exp;
branches;
next	1.46;
commitid	iWIi5gW2mTzOw4ZD;

1.46
date	2022.08.09.17.56.09;	author adam;	state Exp;
branches;
next	1.45;
commitid	UG8yI4LpGtWsnePD;

1.45
date	2022.07.29.20.33.38;	author jperkin;	state Exp;
branches;
next	1.44;
commitid	WeTUApJ2bWL7APND;

1.44
date	2022.07.21.09.35.19;	author adam;	state Exp;
branches;
next	1.43;
commitid	bda48AXwIwz7dKMD;

1.43
date	2022.03.20.21.53.53;	author adam;	state Exp;
branches
	1.43.4.1;
next	1.42;
commitid	tN1dj2ZKMuoWf0xD;

1.42
date	2022.03.07.21.40.37;	author thor;	state Exp;
branches;
next	1.41;
commitid	lThpKNoRM9eEAkvD;

1.41
date	2021.12.25.03.36.01;	author taca;	state Exp;
branches;
next	1.40;
commitid	AsvoxLsFx7SIUYlD;

1.40
date	2021.11.10.13.33.20;	author adam;	state Exp;
branches;
next	1.39;
commitid	tniNhZdUEpOaFfgD;

1.39
date	2021.10.08.13.20.34;	author adam;	state Exp;
branches;
next	1.38;
commitid	daqB6l6mkFfEE0cD;

1.38
date	2021.06.22.09.36.41;	author nia;	state Exp;
branches
	1.38.4.1;
next	1.37;
commitid	XB9IvSIzuWBgT6YC;

1.37
date	2021.05.30.20.02.31;	author thor;	state Exp;
branches;
next	1.36;
commitid	PCS2ZOr0y6Va5dVC;

1.36
date	2021.04.14.19.11.20;	author adam;	state Exp;
branches;
next	1.35;
commitid	eEYvwmWgAe7lhiPC;

1.35
date	2021.01.28.13.17.16;	author adam;	state Exp;
branches;
next	1.34;
commitid	gFfmlER35nyXLuFC;

1.34
date	2020.11.12.06.37.18;	author adam;	state Exp;
branches;
next	1.33;
commitid	N2EOSSOe0GDw1zvC;

1.33
date	2020.08.18.07.39.31;	author adam;	state Exp;
branches;
next	1.32;
commitid	wWpUAnL1IgYT8wkC;

1.32
date	2020.07.28.01.11.10;	author christos;	state Exp;
branches;
next	1.31;
commitid	mS3u22H48ziMDMhC;

1.31
date	2020.07.06.14.38.06;	author adam;	state Exp;
branches;
next	1.30;
commitid	PeoO8iGiep9BP1fC;

1.30
date	2020.05.19.12.13.51;	author hauke;	state Exp;
branches
	1.30.2.1;
next	1.29;
commitid	tSTpodiBIt8lzQ8C;

1.29
date	2020.04.29.10.01.18;	author adam;	state Exp;
branches;
next	1.28;
commitid	jsE7RvvZYDyFug6C;

1.28
date	2020.04.02.11.21.41;	author adam;	state Exp;
branches;
next	1.27;
commitid	Wa63wLmymJoRNN2C;

1.27
date	2020.03.08.12.39.27;	author tnn;	state Exp;
branches;
next	1.26;
commitid	iUgnZ5bTW30w2BZB;

1.26
date	2020.01.29.12.44.14;	author adam;	state Exp;
branches;
next	1.25;
commitid	Ft9rRscMTD1TjAUB;

1.25
date	2019.12.30.13.58.35;	author adam;	state Exp;
branches;
next	1.24;
commitid	jBv9BqAlUqK8HJQB;

1.24
date	2019.11.10.17.01.58;	author adam;	state Exp;
branches
	1.24.4.1;
next	1.23;
commitid	RfZ7NLoOHs32jkKB;

1.23
date	2019.08.03.06.54.39;	author adam;	state Exp;
branches;
next	1.22;
commitid	zdQ1HJfb8rWs8yxB;

1.22
date	2019.04.08.18.35.58;	author adam;	state Exp;
branches
	1.22.2.1;
next	1.21;
commitid	MBFzI2jtBlScMziB;

1.21
date	2019.03.20.19.09.10;	author adam;	state Exp;
branches
	1.21.2.1;
next	1.20;
commitid	6hMtylCUPtqDz8gB;

1.20
date	2019.03.13.18.02.31;	author adam;	state Exp;
branches;
next	1.19;
commitid	DyVu5DbUUsQRqefB;

1.19
date	2019.01.03.19.36.45;	author adam;	state Exp;
branches;
next	1.18;
commitid	5FDFuS5hsFpMan6B;

1.18
date	2018.12.22.01.13.52;	author adam;	state Exp;
branches;
next	1.17;
commitid	O1rUV8UEulLrrJ4B;

1.17
date	2018.12.10.14.42.45;	author ryoon;	state Exp;
branches;
next	1.16;
commitid	7IfiRGY7ZGzBjg3B;

1.16
date	2018.12.09.14.48.03;	author ryoon;	state Exp;
branches;
next	1.15;
commitid	ETCjQUnxSmrxn83B;

1.15
date	2018.12.03.13.51.52;	author mlelstv;	state Exp;
branches;
next	1.14;
commitid	1XhCqFW1igX6gm2B;

1.14
date	2018.11.23.07.30.02;	author ryoon;	state Exp;
branches;
next	1.13;
commitid	lXbvlXjrqhr9t21B;

1.13
date	2018.02.28.03.38.49;	author nonaka;	state Exp;
branches;
next	1.12;
commitid	G7Lp2mj4lXupNzsA;

1.12
date	2017.05.24.15.51.32;	author he;	state Exp;
branches;
next	1.11;
commitid	5IOOcMdr6ubgRESz;

1.11
date	2017.04.08.08.56.27;	author ryoon;	state Exp;
branches;
next	1.10;
commitid	3lgBE7lbcfxA2IMz;

1.10
date	2016.08.15.12.05.24;	author richard;	state Exp;
branches
	1.10.6.1;
next	1.9;
commitid	xB5qKE9EUAYIFoiz;

1.9
date	2016.07.11.12.28.17;	author wiz;	state Exp;
branches;
next	1.8;
commitid	ausKjgBBOlFaVTdz;

1.8
date	2016.07.07.16.44.14;	author taca;	state Exp;
branches;
next	1.7;
commitid	fvo7xor6AT6xspdz;

1.7
date	2016.05.07.03.09.33;	author taca;	state Exp;
branches
	1.7.2.1;
next	1.6;
commitid	rzBHOqkZO1U1Vu5z;

1.6
date	2016.04.13.08.26.10;	author manu;	state Exp;
branches;
next	1.5;
commitid	b2ePpkM5ydbBor2z;

1.5
date	2016.01.31.20.28.23;	author ryoon;	state Exp;
branches
	1.5.2.1;
next	1.4;
commitid	1kXukBWnXZkSM7Ty;

1.4
date	2015.12.13.08.48.36;	author wiz;	state Exp;
branches;
next	1.3;
commitid	ofwX9taBOYGquLMy;

1.3
date	2015.09.28.17.37.04;	author ryoon;	state Exp;
branches;
next	1.2;
commitid	QJCLUHHtJXo9R2Dy;

1.2
date	2015.06.26.16.09.49;	author jperkin;	state Exp;
branches;
next	1.1;
commitid	Cc8Xam97HYwDmXqy;

1.1
date	2015.05.12.12.19.52;	author ryoon;	state Exp;
branches;
next	;
commitid	4reC5lBSgnPrz9ly;

1.51.4.1
date	2023.10.12.15.59.15;	author bsiegert;	state Exp;
branches;
next	;
commitid	B2Gn1WZtGvDxWlIE;

1.48.2.1
date	2023.02.12.19.23.21;	author spz;	state Exp;
branches;
next	;
commitid	fPBawgR5jaPPQgdE;

1.43.4.1
date	2022.08.28.08.13.40;	author spz;	state Exp;
branches;
next	;
commitid	ZKj34OE4h4QTxCRD;

1.38.4.1
date	2021.11.24.12.45.47;	author tm;	state Exp;
branches;
next	;
commitid	zSasPyPOfE7iX2iD;

1.30.2.1
date	2020.07.29.20.15.59;	author bsiegert;	state Exp;
branches;
next	;
commitid	T9NABfw8xjjjY0iC;

1.24.4.1
date	2020.01.29.13.13.05;	author bsiegert;	state Exp;
branches;
next	;
commitid	Cn2dZW2VUDoWtAUB;

1.22.2.1
date	2019.09.15.09.11.02;	author bsiegert;	state Exp;
branches;
next	;
commitid	OqJr2FM5oHHVv5DB;

1.21.2.1
date	2019.04.10.10.27.05;	author bsiegert;	state Exp;
branches;
next	;
commitid	9s1bv2ozkN2U0NiB;

1.10.6.1
date	2017.05.27.19.01.15;	author bsiegert;	state Exp;
branches;
next	;
commitid	L4aF9F0XhIvrO3Tz;

1.7.2.1
date	2016.07.20.18.52.47;	author spz;	state Exp;
branches;
next	;
commitid	4EWM6pWzPyjjL5fz;

1.5.2.1
date	2016.04.15.07.25.11;	author bsiegert;	state Exp;
branches;
next	1.5.2.2;
commitid	ZamU0dLDbaUK2H2z;

1.5.2.2
date	2016.05.13.14.49.20;	author bsiegert;	state Exp;
branches;
next	;
commitid	G7SkCJ55TBdkBk6z;


desc
@@


1.64
log
@samba4: updated to 4.24.1

Changes since 4.24.0

* BUG 16057: autobuild fails if /proc/version contains trailing space
* BUG 16035: use after free in streams_xattr_connect()
* BUG 16042: rpc workers with long living clients grow server  memory keytab
* BUG 16058: vfs_snapper failing to access or enumerate files in subfolders
* BUG 16040: Samba is not build with FORTIFY_SOURCE
* BUG 16055: Fix tests with MIT Kerberos 1.22.x

4.24.0

NEW FEATURES/CHANGES
* Authentication information audit support
* vfs_streams_xattr can hold larger streams
* Support for remote password management (Entra ID SSPR, Keycloak)
* Kerberos PKINIT KeyTrust logon support
* msDS-KeyCredentialLink validation
* Kerberos PKINIT strong/flexible key mappings
* Kerberos PKINIT SID extension
* KDC includes PAC by default
* KDC can insist clients request canonicalization
* KDC can avoid potentially confusing canonicalization
* KDC provides Kerberos acceptors with canonical client names
@
text
@@@comment $NetBSD: PLIST,v 1.63 2025/12/28 10:07:56 adam Exp $
bin/cifsdd
bin/dbwrap_tool
bin/dumpmscat
bin/gentest
bin/ldbadd
bin/ldbdel
bin/ldbedit
bin/ldbmodify
bin/ldbrename
bin/ldbsearch
bin/locktest
bin/masktest
bin/mdsearch
bin/mvxattr
bin/ndrdump
bin/net
bin/nmblookup
bin/ntlm_auth
bin/oLschema2ldif
bin/pdbedit
bin/profiles
bin/regdiff
bin/regpatch
bin/regshell
bin/regtree
bin/rpcclient
bin/samba-log-parser
${PLIST.ads}bin/samba-tool
bin/sharesec
bin/smbcacls
bin/smbclient
bin/smbcontrol
bin/smbcquotas
bin/smbget
bin/smbpasswd
bin/smbspool
bin/smbstatus
bin/smbtar
bin/smbtorture
bin/smbtree
bin/testparm
bin/wbinfo
bin/wspsearch
include/charset.h
include/core/doserr.h
include/core/error.h
include/core/hresult.h
include/core/ntstatus.h
include/core/ntstatus_gen.h
include/core/werror.h
include/core/werror_gen.h
include/dcesrv_core.h
include/domain_credentials.h
include/gen_ndr/atsvc.h
include/gen_ndr/auth.h
include/gen_ndr/claims.h
include/gen_ndr/dcerpc.h
include/gen_ndr/drsblobs.h
include/gen_ndr/drsuapi.h
include/gen_ndr/krb5pac.h
include/gen_ndr/lsa.h
include/gen_ndr/misc.h
include/gen_ndr/nbt.h
include/gen_ndr/ndr_atsvc.h
include/gen_ndr/ndr_dcerpc.h
include/gen_ndr/ndr_drsblobs.h
include/gen_ndr/ndr_drsuapi.h
include/gen_ndr/ndr_krb5pac.h
include/gen_ndr/ndr_misc.h
include/gen_ndr/ndr_nbt.h
include/gen_ndr/ndr_samr.h
include/gen_ndr/ndr_svcctl.h
include/gen_ndr/ndr_svcctl_c.h
include/gen_ndr/netlogon.h
include/gen_ndr/samr.h
include/gen_ndr/security.h
include/gen_ndr/server_id.h
include/gen_ndr/svcctl.h
include/ldb_wrap.h
include/libsmbclient.h
include/lookup_sid.h
include/machine_sid.h
include/ndr.h
include/ndr/ndr_dcerpc.h
include/ndr/ndr_drsblobs.h
include/ndr/ndr_drsuapi.h
include/ndr/ndr_krb5pac.h
include/ndr/ndr_nbt.h
include/ndr/ndr_svcctl.h
include/netapi.h
include/passdb.h
include/rpc_common.h
include/samba/session.h
include/samba/version.h
include/share.h
include/smb2_lease_struct.h
include/smb3posix.h
${PLIST.ldap}include/smb_ldap.h
include/smbconf.h
${PLIST.ldap}include/smbldap.h
include/tdr.h
include/tsocket.h
include/tsocket_internal.h
include/util/attr.h
include/util/blocking.h
include/util/data_blob.h
include/util/debug.h
include/util/discard.h
include/util/fault.h
include/util/genrand.h
include/util/idtree.h
include/util/idtree_random.h
include/util/signal.h
include/util/substitute.h
include/util/talloc_keep_secret.h
include/util/tfork.h
include/util/time.h
include/util_ldb.h
include/wbclient.h
lib/libdcerpc-binding.so
lib/libdcerpc-binding.so.0
lib/libdcerpc-binding.so.0.0.1
lib/libdcerpc-server-core.so
lib/libdcerpc-server-core.so.0
lib/libdcerpc-server-core.so.0.0.1
lib/libndr-krb5pac.so
lib/libndr-krb5pac.so.0
lib/libndr-krb5pac.so.0.0.1
lib/libndr-nbt.so
lib/libndr-nbt.so.0
lib/libndr-nbt.so.0.0.1
lib/libndr-standard.so
lib/libndr-standard.so.0
lib/libndr-standard.so.0.0.1
lib/libndr.so
lib/libndr.so.6
lib/libndr.so.6.0.0
lib/libnetapi.so
lib/libnetapi.so.1
lib/libnetapi.so.1.0.0
lib/libnss_winbind.so
lib/libsamba-errors.so
lib/libsamba-errors.so.1
lib/libsamba-errors.so.1.0.0
lib/libsamba-passdb.so
lib/libsamba-passdb.so.0
lib/libsamba-passdb.so.0.30.0
lib/libsamba-util.so
lib/libsamba-util.so.0
lib/libsamba-util.so.0.0.1
lib/libsmbclient.so
lib/libsmbclient.so.0
lib/libsmbclient.so.0.8.1
lib/libsmbconf.so
lib/libsmbconf.so.0
lib/libsmbconf.so.0.0.1
${PLIST.ldap}lib/libsmbldap.so
${PLIST.ldap}lib/libsmbldap.so.2
${PLIST.ldap}lib/libsmbldap.so.2.1.0
lib/libwbclient.so
lib/libwbclient.so.0
lib/libwbclient.so.0.16
lib/pkgconfig/ndr.pc
lib/pkgconfig/ndr_krb5pac.pc
lib/pkgconfig/ndr_nbt.pc
lib/pkgconfig/ndr_standard.pc
lib/pkgconfig/netapi.pc
lib/pkgconfig/samba-util.pc
lib/pkgconfig/smbclient.pc
lib/pkgconfig/wbclient.pc
${PYSITELIB}/_ldb_text.py
${PYSITELIB}/ldb.so
${PYSITELIB}/samba/__init__.py
${PYSITELIB}/samba/_glue.so
${PYSITELIB}/samba/_ldb.so
${PYSITELIB}/samba/asn1.py
${PYSITELIB}/samba/auth.so
${PYSITELIB}/samba/auth_util.py
${PYSITELIB}/samba/colour.py
${PYSITELIB}/samba/common.py
${PYSITELIB}/samba/compression.so
${PYSITELIB}/samba/credentials.so
${PYSITELIB}/samba/crypto.so
${PYSITELIB}/samba/dbchecker.py
${PYSITELIB}/samba/dcerpc/__init__.py
${PYSITELIB}/samba/dcerpc/atsvc.so
${PYSITELIB}/samba/dcerpc/auth.so
${PYSITELIB}/samba/dcerpc/base.so
${PYSITELIB}/samba/dcerpc/bcrypt_rsakey_blob.so
${PYSITELIB}/samba/dcerpc/claims.so
${PYSITELIB}/samba/dcerpc/conditional_ace.so
${PYSITELIB}/samba/dcerpc/dcerpc.so
${PYSITELIB}/samba/dcerpc/dfs.so
${PYSITELIB}/samba/dcerpc/dns.so
${PYSITELIB}/samba/dcerpc/dnsp.so
${PYSITELIB}/samba/dcerpc/dnsserver.so
${PYSITELIB}/samba/dcerpc/drsblobs.so
${PYSITELIB}/samba/dcerpc/drsuapi.so
${PYSITELIB}/samba/dcerpc/echo.so
${PYSITELIB}/samba/dcerpc/epmapper.so
${PYSITELIB}/samba/dcerpc/gkdi.so
${PYSITELIB}/samba/dcerpc/gmsa.so
${PYSITELIB}/samba/dcerpc/idmap.so
${PYSITELIB}/samba/dcerpc/initshutdown.so
${PYSITELIB}/samba/dcerpc/irpc.so
${PYSITELIB}/samba/dcerpc/keycredlink.so
${PYSITELIB}/samba/dcerpc/krb5ccache.so
${PYSITELIB}/samba/dcerpc/krb5pac.so
${PYSITELIB}/samba/dcerpc/lsa.so
${PYSITELIB}/samba/dcerpc/mdssvc.so
${PYSITELIB}/samba/dcerpc/messaging.so
${PYSITELIB}/samba/dcerpc/mgmt.so
${PYSITELIB}/samba/dcerpc/misc.so
${PYSITELIB}/samba/dcerpc/nbt.so
${PYSITELIB}/samba/dcerpc/netlogon.so
${PYSITELIB}/samba/dcerpc/ntlmssp.so
${PYSITELIB}/samba/dcerpc/preg.so
${PYSITELIB}/samba/dcerpc/samr.so
${PYSITELIB}/samba/dcerpc/schannel.so
${PYSITELIB}/samba/dcerpc/security.so
${PYSITELIB}/samba/dcerpc/server_id.so
${PYSITELIB}/samba/dcerpc/smb3posix.so
${PYSITELIB}/samba/dcerpc/smbXsrv.so
${PYSITELIB}/samba/dcerpc/smb_acl.so
${PYSITELIB}/samba/dcerpc/spoolss.so
${PYSITELIB}/samba/dcerpc/srvsvc.so
${PYSITELIB}/samba/dcerpc/svcctl.so
${PYSITELIB}/samba/dcerpc/tpm20_rsakey_blob.so
${PYSITELIB}/samba/dcerpc/unixinfo.so
${PYSITELIB}/samba/dcerpc/winbind.so
${PYSITELIB}/samba/dcerpc/windows_event_ids.so
${PYSITELIB}/samba/dcerpc/winreg.so
${PYSITELIB}/samba/dcerpc/winspool.so
${PYSITELIB}/samba/dcerpc/witness.so
${PYSITELIB}/samba/dcerpc/wkssvc.so
${PYSITELIB}/samba/dcerpc/xattr.so
${PLIST.ads}${PYSITELIB}/samba/dckeytab.so
${PYSITELIB}/samba/descriptor.py
${PYSITELIB}/samba/dnsresolver.py
${PYSITELIB}/samba/dnsserver.py
${PYSITELIB}/samba/domain/__init__.py
${PYSITELIB}/samba/domain/models/__init__.py
${PYSITELIB}/samba/domain/models/auth_policy.py
${PYSITELIB}/samba/domain/models/auth_silo.py
${PYSITELIB}/samba/domain/models/claim_type.py
${PYSITELIB}/samba/domain/models/computer.py
${PYSITELIB}/samba/domain/models/constants.py
${PYSITELIB}/samba/domain/models/container.py
${PYSITELIB}/samba/domain/models/exceptions.py
${PYSITELIB}/samba/domain/models/fields.py
${PYSITELIB}/samba/domain/models/gmsa.py
${PYSITELIB}/samba/domain/models/group.py
${PYSITELIB}/samba/domain/models/model.py
${PYSITELIB}/samba/domain/models/org.py
${PYSITELIB}/samba/domain/models/person.py
${PYSITELIB}/samba/domain/models/query.py
${PYSITELIB}/samba/domain/models/registry.py
${PYSITELIB}/samba/domain/models/schema.py
${PYSITELIB}/samba/domain/models/site.py
${PYSITELIB}/samba/domain/models/subnet.py
${PYSITELIB}/samba/domain/models/types.py
${PYSITELIB}/samba/domain/models/user.py
${PYSITELIB}/samba/domain/models/value_type.py
${PYSITELIB}/samba/domain_update.py
${PYSITELIB}/samba/drs_utils.py
${PYSITELIB}/samba/dsdb.so
${PYSITELIB}/samba/dsdb_dns.so
${PYSITELIB}/samba/emulate/__init__.py
${PYSITELIB}/samba/emulate/traffic.py
${PYSITELIB}/samba/emulate/traffic_packets.py
${PYSITELIB}/samba/forest_update.py
${PYSITELIB}/samba/functional_level.py
${PYSITELIB}/samba/generate_csr.py
${PYSITELIB}/samba/gensec.so
${PYSITELIB}/samba/getopt.py
${PYSITELIB}/samba/gkdi.py
${PYSITELIB}/samba/gp/__init__.py
${PYSITELIB}/samba/gp/gp_centrify_crontab_ext.py
${PYSITELIB}/samba/gp/gp_centrify_sudoers_ext.py
${PYSITELIB}/samba/gp/gp_cert_auto_enroll_ext.py
${PYSITELIB}/samba/gp/gp_chromium_ext.py
${PYSITELIB}/samba/gp/gp_drive_maps_ext.py
${PYSITELIB}/samba/gp/gp_ext_loader.py
${PYSITELIB}/samba/gp/gp_firefox_ext.py
${PYSITELIB}/samba/gp/gp_firewalld_ext.py
${PYSITELIB}/samba/gp/gp_gnome_settings_ext.py
${PYSITELIB}/samba/gp/gp_msgs_ext.py
${PYSITELIB}/samba/gp/gp_scripts_ext.py
${PYSITELIB}/samba/gp/gp_sec_ext.py
${PYSITELIB}/samba/gp/gp_smb_conf_ext.py
${PYSITELIB}/samba/gp/gp_sudoers_ext.py
${PYSITELIB}/samba/gp/gpclass.py
${PYSITELIB}/samba/gp/util/logging.py
${PYSITELIB}/samba/gp/vgp_access_ext.py
${PYSITELIB}/samba/gp/vgp_files_ext.py
${PYSITELIB}/samba/gp/vgp_issue_ext.py
${PYSITELIB}/samba/gp/vgp_motd_ext.py
${PYSITELIB}/samba/gp/vgp_openssh_ext.py
${PYSITELIB}/samba/gp/vgp_startup_scripts_ext.py
${PYSITELIB}/samba/gp/vgp_sudoers_ext.py
${PYSITELIB}/samba/gp/vgp_symlink_ext.py
${PYSITELIB}/samba/gp_parse/__init__.py
${PYSITELIB}/samba/gp_parse/gp_aas.py
${PYSITELIB}/samba/gp_parse/gp_csv.py
${PYSITELIB}/samba/gp_parse/gp_inf.py
${PYSITELIB}/samba/gp_parse/gp_ini.py
${PYSITELIB}/samba/gp_parse/gp_pol.py
${PYSITELIB}/samba/gpo.so
${PYSITELIB}/samba/graph.py
${PYSITELIB}/samba/hostconfig.py
${PYSITELIB}/samba/hresult.so
${PYSITELIB}/samba/idmap.py
${PYSITELIB}/samba/join.py
${PYSITELIB}/samba/kcc/__init__.py
${PYSITELIB}/samba/kcc/debug.py
${PYSITELIB}/samba/kcc/graph.py
${PYSITELIB}/samba/kcc/graph_utils.py
${PYSITELIB}/samba/kcc/kcc_utils.py
${PYSITELIB}/samba/kcc/ldif_import_export.py
${PYSITELIB}/samba/key_credential_link.py
${PYSITELIB}/samba/logger.py
${PYSITELIB}/samba/lsa_utils.py
${PYSITELIB}/samba/mdb_util.py
${PYSITELIB}/samba/messaging.so
${PYSITELIB}/samba/ms_display_specifiers.py
${PYSITELIB}/samba/ms_forest_updates_markdown.py
${PYSITELIB}/samba/ms_schema.py
${PYSITELIB}/samba/ms_schema_markdown.py
${PYSITELIB}/samba/ndr.py
${PYSITELIB}/samba/net.so
${PYSITELIB}/samba/net_s3.so
${PYSITELIB}/samba/netbios.so
${PYSITELIB}/samba/netcmd/__init__.py
${PYSITELIB}/samba/netcmd/common.py
${PYSITELIB}/samba/netcmd/computer.py
${PYSITELIB}/samba/netcmd/computer_generate_csr.py
${PYSITELIB}/samba/netcmd/computer_keytrust.py
${PYSITELIB}/samba/netcmd/contact.py
${PYSITELIB}/samba/netcmd/dbcheck.py
${PYSITELIB}/samba/netcmd/delegation.py
${PYSITELIB}/samba/netcmd/dns.py
${PYSITELIB}/samba/netcmd/domain/__init__.py
${PYSITELIB}/samba/netcmd/domain/auth/__init__.py
${PYSITELIB}/samba/netcmd/domain/auth/policy/__init__.py
${PYSITELIB}/samba/netcmd/domain/auth/policy/computer_allowed_to_authenticate_to.py
${PYSITELIB}/samba/netcmd/domain/auth/policy/policy.py
${PYSITELIB}/samba/netcmd/domain/auth/policy/service_allowed_to_authenticate_from.py
${PYSITELIB}/samba/netcmd/domain/auth/policy/service_allowed_to_authenticate_to.py
${PYSITELIB}/samba/netcmd/domain/auth/policy/user_allowed_to_authenticate_from.py
${PYSITELIB}/samba/netcmd/domain/auth/policy/user_allowed_to_authenticate_to.py
${PYSITELIB}/samba/netcmd/domain/auth/silo/__init__.py
${PYSITELIB}/samba/netcmd/domain/auth/silo/member.py
${PYSITELIB}/samba/netcmd/domain/auth/silo/silo.py
${PYSITELIB}/samba/netcmd/domain/backup.py
${PYSITELIB}/samba/netcmd/domain/claim/__init__.py
${PYSITELIB}/samba/netcmd/domain/claim/claim_type.py
${PYSITELIB}/samba/netcmd/domain/claim/value_type.py
${PYSITELIB}/samba/netcmd/domain/classicupgrade.py
${PYSITELIB}/samba/netcmd/domain/common.py
${PYSITELIB}/samba/netcmd/domain/dcpromo.py
${PYSITELIB}/samba/netcmd/domain/demote.py
${PYSITELIB}/samba/netcmd/domain/functional_prep.py
${PYSITELIB}/samba/netcmd/domain/info.py
${PYSITELIB}/samba/netcmd/domain/join.py
${PYSITELIB}/samba/netcmd/domain/kds/__init__.py
${PYSITELIB}/samba/netcmd/domain/kds/root_key.py
${PYSITELIB}/samba/netcmd/domain/keytab.py
${PYSITELIB}/samba/netcmd/domain/leave.py
${PYSITELIB}/samba/netcmd/domain/level.py
${PYSITELIB}/samba/netcmd/domain/passwordsettings.py
${PYSITELIB}/samba/netcmd/domain/provision.py
${PYSITELIB}/samba/netcmd/domain/samba3upgrade.py
${PYSITELIB}/samba/netcmd/domain/schemaupgrade.py
${PYSITELIB}/samba/netcmd/domain/tombstones.py
${PYSITELIB}/samba/netcmd/domain/trust.py
${PYSITELIB}/samba/netcmd/drs.py
${PYSITELIB}/samba/netcmd/dsacl.py
${PYSITELIB}/samba/netcmd/encoders.py
${PYSITELIB}/samba/netcmd/forest.py
${PYSITELIB}/samba/netcmd/fsmo.py
${PYSITELIB}/samba/netcmd/gpcommon.py
${PYSITELIB}/samba/netcmd/gpo.py
${PYSITELIB}/samba/netcmd/group.py
${PYSITELIB}/samba/netcmd/ldapcmp.py
${PYSITELIB}/samba/netcmd/main.py
${PYSITELIB}/samba/netcmd/nettime.py
${PYSITELIB}/samba/netcmd/ntacl.py
${PYSITELIB}/samba/netcmd/ou.py
${PYSITELIB}/samba/netcmd/processes.py
${PYSITELIB}/samba/netcmd/pso.py
${PYSITELIB}/samba/netcmd/rodc.py
${PYSITELIB}/samba/netcmd/schema.py
${PYSITELIB}/samba/netcmd/service_account/__init__.py
${PYSITELIB}/samba/netcmd/service_account/group_msa_membership.py
${PYSITELIB}/samba/netcmd/service_account/service_account.py
${PYSITELIB}/samba/netcmd/shell.py
${PYSITELIB}/samba/netcmd/sites.py
${PYSITELIB}/samba/netcmd/spn.py
${PYSITELIB}/samba/netcmd/testparm.py
${PYSITELIB}/samba/netcmd/user/__init__.py
${PYSITELIB}/samba/netcmd/user/add.py
${PYSITELIB}/samba/netcmd/user/add_unix_attrs.py
${PYSITELIB}/samba/netcmd/user/auth/__init__.py
${PYSITELIB}/samba/netcmd/user/auth/policy.py
${PYSITELIB}/samba/netcmd/user/auth/silo.py
${PYSITELIB}/samba/netcmd/user/delete.py
${PYSITELIB}/samba/netcmd/user/disable.py
${PYSITELIB}/samba/netcmd/user/edit.py
${PYSITELIB}/samba/netcmd/user/enable.py
${PYSITELIB}/samba/netcmd/user/generate_csr.py
${PYSITELIB}/samba/netcmd/user/getgroups.py
${PYSITELIB}/samba/netcmd/user/keytrust.py
${PYSITELIB}/samba/netcmd/user/list.py
${PYSITELIB}/samba/netcmd/user/move.py
${PYSITELIB}/samba/netcmd/user/password.py
${PYSITELIB}/samba/netcmd/user/readpasswords/__init__.py
${PYSITELIB}/samba/netcmd/user/readpasswords/common.py
${PYSITELIB}/samba/netcmd/user/readpasswords/get_kerberos_ticket.py
${PYSITELIB}/samba/netcmd/user/readpasswords/getpassword.py
${PYSITELIB}/samba/netcmd/user/readpasswords/show.py
${PYSITELIB}/samba/netcmd/user/readpasswords/syncpasswords.py
${PYSITELIB}/samba/netcmd/user/rename.py
${PYSITELIB}/samba/netcmd/user/sensitive.py
${PYSITELIB}/samba/netcmd/user/setexpiry.py
${PYSITELIB}/samba/netcmd/user/setpassword.py
${PYSITELIB}/samba/netcmd/user/setprimarygroup.py
${PYSITELIB}/samba/netcmd/user/unlock.py
${PYSITELIB}/samba/netcmd/validators.py
${PYSITELIB}/samba/netcmd/visualize.py
${PYSITELIB}/samba/nt_time.py
${PYSITELIB}/samba/ntacls.py
${PYSITELIB}/samba/ntstatus.so
${PYSITELIB}/samba/param.so
${PYSITELIB}/samba/policies.py
${PYSITELIB}/samba/policy.so
${PYSITELIB}/samba/posix_eadb.so
${PYSITELIB}/samba/provision/__init__.py
${PYSITELIB}/samba/provision/backend.py
${PYSITELIB}/samba/provision/common.py
${PYSITELIB}/samba/provision/kerberos.py
${PYSITELIB}/samba/provision/kerberos_implementation.py
${PYSITELIB}/samba/provision/sambadns.py
${PYSITELIB}/samba/registry.so
${PYSITELIB}/samba/remove_dc.py
${PYSITELIB}/samba/reparse_symlink.so
${PYSITELIB}/samba/safe_tarfile.py
${PYSITELIB}/samba/samba3/__init__.py
${PYSITELIB}/samba/samba3/libsmb_samba_cwrapper.so
${PYSITELIB}/samba/samba3/libsmb_samba_internal.py
${PYSITELIB}/samba/samba3/mdscli.so
${PYSITELIB}/samba/samba3/param.so
${PYSITELIB}/samba/samba3/passdb.so
${PYSITELIB}/samba/samba3/smbconf.so
${PYSITELIB}/samba/samba3/smbd.so
${PYSITELIB}/samba/samdb.py
${PYSITELIB}/samba/schema.py
${PYSITELIB}/samba/sd_utils.py
${PYSITELIB}/samba/security.so
${PYSITELIB}/samba/sites.py
${PYSITELIB}/samba/smbconf.so
${PYSITELIB}/samba/subnets.py
${PYSITELIB}/samba/subunit/__init__.py
${PYSITELIB}/samba/subunit/run.py
${PYSITELIB}/samba/tdb_util.py
${PYSITELIB}/samba/tests/__init__.py
${PYSITELIB}/samba/tests/audit_log_base.py
${PYSITELIB}/samba/tests/audit_log_dsdb.py
${PYSITELIB}/samba/tests/audit_log_pass_change.py
${PYSITELIB}/samba/tests/auth.py
${PYSITELIB}/samba/tests/auth_log.py
${PYSITELIB}/samba/tests/auth_log_base.py
${PYSITELIB}/samba/tests/auth_log_ncalrpc.py
${PYSITELIB}/samba/tests/auth_log_netlogon.py
${PYSITELIB}/samba/tests/auth_log_netlogon_bad_creds.py
${PYSITELIB}/samba/tests/auth_log_pass_change.py
${PYSITELIB}/samba/tests/auth_log_samlogon.py
${PYSITELIB}/samba/tests/auth_log_winbind.py
${PYSITELIB}/samba/tests/bcrypt_rsakey_blob.py
${PYSITELIB}/samba/tests/blackbox/__init__.py
${PYSITELIB}/samba/tests/blackbox/bug13653.py
${PYSITELIB}/samba/tests/blackbox/check_output.py
${PYSITELIB}/samba/tests/blackbox/claims.py
${PYSITELIB}/samba/tests/blackbox/downgradedatabase.py
${PYSITELIB}/samba/tests/blackbox/gmsa.py
${PYSITELIB}/samba/tests/blackbox/http_chunk.py
${PYSITELIB}/samba/tests/blackbox/http_content.py
${PYSITELIB}/samba/tests/blackbox/mdsearch.py
${PYSITELIB}/samba/tests/blackbox/misc_dfs_widelink.py
${PYSITELIB}/samba/tests/blackbox/ndrdump.py
${PYSITELIB}/samba/tests/blackbox/netads_dns.py
${PYSITELIB}/samba/tests/blackbox/netads_json.py
${PYSITELIB}/samba/tests/blackbox/rpcd_witness_samba_only.py
${PYSITELIB}/samba/tests/blackbox/samba_dnsupdate.py
${PYSITELIB}/samba/tests/blackbox/smbcacls.py
${PYSITELIB}/samba/tests/blackbox/smbcacls_basic.py
${PYSITELIB}/samba/tests/blackbox/smbcacls_dfs_propagate_inherit.py
${PYSITELIB}/samba/tests/blackbox/smbcacls_propagate_inhertance.py
${PYSITELIB}/samba/tests/blackbox/smbcacls_save_restore.py
${PYSITELIB}/samba/tests/blackbox/smbcontrol.py
${PYSITELIB}/samba/tests/blackbox/smbcontrol_process.py
${PYSITELIB}/samba/tests/blackbox/traffic_learner.py
${PYSITELIB}/samba/tests/blackbox/traffic_replay.py
${PYSITELIB}/samba/tests/blackbox/traffic_summary.py
${PYSITELIB}/samba/tests/common.py
${PYSITELIB}/samba/tests/complex_expressions.py
${PYSITELIB}/samba/tests/compression.py
${PYSITELIB}/samba/tests/conditional_ace_assembler.py
${PYSITELIB}/samba/tests/conditional_ace_bytes.py
${PYSITELIB}/samba/tests/conditional_ace_claims.py
${PYSITELIB}/samba/tests/core.py
${PYSITELIB}/samba/tests/cred_opt.py
${PYSITELIB}/samba/tests/credentials.py
${PYSITELIB}/samba/tests/dcerpc/__init__.py
${PYSITELIB}/samba/tests/dcerpc/array.py
${PYSITELIB}/samba/tests/dcerpc/bare.py
${PYSITELIB}/samba/tests/dcerpc/binding.py
${PYSITELIB}/samba/tests/dcerpc/dfs.py
${PYSITELIB}/samba/tests/dcerpc/dnsserver.py
${PYSITELIB}/samba/tests/dcerpc/integer.py
${PYSITELIB}/samba/tests/dcerpc/lsa.py
${PYSITELIB}/samba/tests/dcerpc/lsa_utils.py
${PYSITELIB}/samba/tests/dcerpc/mdssvc.py
${PYSITELIB}/samba/tests/dcerpc/misc.py
${PYSITELIB}/samba/tests/dcerpc/raw_protocol.py
${PYSITELIB}/samba/tests/dcerpc/raw_testcase.py
${PYSITELIB}/samba/tests/dcerpc/registry.py
${PYSITELIB}/samba/tests/dcerpc/rpc_talloc.py
${PYSITELIB}/samba/tests/dcerpc/rpcecho.py
${PYSITELIB}/samba/tests/dcerpc/sam.py
${PYSITELIB}/samba/tests/dcerpc/samr_change_password.py
${PYSITELIB}/samba/tests/dcerpc/srvsvc.py
${PYSITELIB}/samba/tests/dcerpc/string_tests.py
${PYSITELIB}/samba/tests/dcerpc/testrpc.py
${PYSITELIB}/samba/tests/dcerpc/unix.py
${PYSITELIB}/samba/tests/dckeytab.py
${PYSITELIB}/samba/tests/dns.py
${PYSITELIB}/samba/tests/dns_aging.py
${PYSITELIB}/samba/tests/dns_base.py
${PYSITELIB}/samba/tests/dns_forwarder.py
${PYSITELIB}/samba/tests/dns_forwarder_helpers/server.py
${PYSITELIB}/samba/tests/dns_invalid.py
${PYSITELIB}/samba/tests/dns_packet.py
${PYSITELIB}/samba/tests/dns_tkey.py
${PYSITELIB}/samba/tests/dns_wildcard.py
${PYSITELIB}/samba/tests/docs.py
${PYSITELIB}/samba/tests/domain_backup.py
${PYSITELIB}/samba/tests/domain_backup_offline.py
${PYSITELIB}/samba/tests/dsdb.py
${PYSITELIB}/samba/tests/dsdb_api.py
${PYSITELIB}/samba/tests/dsdb_dn.py
${PYSITELIB}/samba/tests/dsdb_dns.py
${PYSITELIB}/samba/tests/dsdb_lock.py
${PYSITELIB}/samba/tests/dsdb_quiet_env_tests.py
${PYSITELIB}/samba/tests/dsdb_quiet_provision_tests.py
${PYSITELIB}/samba/tests/dsdb_schema_attributes.py
${PYSITELIB}/samba/tests/emulate/__init__.py
${PYSITELIB}/samba/tests/emulate/traffic.py
${PYSITELIB}/samba/tests/emulate/traffic_packet.py
${PYSITELIB}/samba/tests/encrypted_secrets.py
${PYSITELIB}/samba/tests/gensec.py
${PYSITELIB}/samba/tests/get_opt.py
${PYSITELIB}/samba/tests/getdcname.py
${PYSITELIB}/samba/tests/gkdi.py
${PYSITELIB}/samba/tests/glue.py
${PYSITELIB}/samba/tests/gpo.py
${PYSITELIB}/samba/tests/gpo_member.py
${PYSITELIB}/samba/tests/graph.py
${PYSITELIB}/samba/tests/group_audit.py
${PYSITELIB}/samba/tests/hostconfig.py
${PYSITELIB}/samba/tests/imports.py
${PYSITELIB}/samba/tests/join.py
${PYSITELIB}/samba/tests/kcc/__init__.py
${PYSITELIB}/samba/tests/kcc/graph.py
${PYSITELIB}/samba/tests/kcc/graph_utils.py
${PYSITELIB}/samba/tests/kcc/kcc_utils.py
${PYSITELIB}/samba/tests/kcc/ldif_import_export.py
${PYSITELIB}/samba/tests/key_credential_link.py
${PYSITELIB}/samba/tests/key_credential_link_samdb.py
${PYSITELIB}/samba/tests/krb5/alias_tests.py
${PYSITELIB}/samba/tests/krb5/as_canonicalization_tests.py
${PYSITELIB}/samba/tests/krb5/as_req_tests.py
${PYSITELIB}/samba/tests/krb5/authn_policy_tests.py
${PYSITELIB}/samba/tests/krb5/claims_in_pac.py
${PYSITELIB}/samba/tests/krb5/claims_tests.py
${PYSITELIB}/samba/tests/krb5/compatability_tests.py
${PYSITELIB}/samba/tests/krb5/conditional_ace_tests.py
${PYSITELIB}/samba/tests/krb5/device_tests.py
${PYSITELIB}/samba/tests/krb5/etype_tests.py
${PYSITELIB}/samba/tests/krb5/fast_tests.py
${PYSITELIB}/samba/tests/krb5/gkdi_tests.py
${PYSITELIB}/samba/tests/krb5/gmsa_tests.py
${PYSITELIB}/samba/tests/krb5/group_tests.py
${PYSITELIB}/samba/tests/krb5/kcrypto.py
${PYSITELIB}/samba/tests/krb5/kdc_base_test.py
${PYSITELIB}/samba/tests/krb5/kdc_tests.py
${PYSITELIB}/samba/tests/krb5/kdc_tgs_tests.py
${PYSITELIB}/samba/tests/krb5/kdc_tgt_tests.py
${PYSITELIB}/samba/tests/krb5/key_trust_tests.py
${PYSITELIB}/samba/tests/krb5/kpasswd_tests.py
${PYSITELIB}/samba/tests/krb5/lockout_tests.py
${PYSITELIB}/samba/tests/krb5/ms_kile_client_principal_lookup_tests.py
${PYSITELIB}/samba/tests/krb5/netlogon.py
${PYSITELIB}/samba/tests/krb5/nt_hash_tests.py
${PYSITELIB}/samba/tests/krb5/pac_align_tests.py
${PYSITELIB}/samba/tests/krb5/pkinit_certificate_mapping_tests.py
${PYSITELIB}/samba/tests/krb5/pkinit_tests.py
${PYSITELIB}/samba/tests/krb5/protected_users_tests.py
${PYSITELIB}/samba/tests/krb5/raw_testcase.py
${PYSITELIB}/samba/tests/krb5/rfc4120_constants.py
${PYSITELIB}/samba/tests/krb5/rfc4120_pyasn1.py
${PYSITELIB}/samba/tests/krb5/rfc4120_pyasn1_generated.py
${PYSITELIB}/samba/tests/krb5/rodc_tests.py
${PYSITELIB}/samba/tests/krb5/s4u_tests.py
${PYSITELIB}/samba/tests/krb5/salt_tests.py
${PYSITELIB}/samba/tests/krb5/simple_tests.py
${PYSITELIB}/samba/tests/krb5/spn_tests.py
${PYSITELIB}/samba/tests/krb5/test_ccache.py
${PYSITELIB}/samba/tests/krb5/test_idmap_nss.py
${PYSITELIB}/samba/tests/krb5/test_ldap.py
${PYSITELIB}/samba/tests/krb5/test_min_domain_uid.py
${PYSITELIB}/samba/tests/krb5/test_rpc.py
${PYSITELIB}/samba/tests/krb5/test_smb.py
${PYSITELIB}/samba/tests/krb5/xrealm_tests.py
${PYSITELIB}/samba/tests/krb5_credentials.py
${PYSITELIB}/samba/tests/ldap_raw.py
${PYSITELIB}/samba/tests/ldap_referrals.py
${PYSITELIB}/samba/tests/ldap_spn.py
${PYSITELIB}/samba/tests/ldap_upn_sam_account.py
${PYSITELIB}/samba/tests/ldap_whoami.py
${PYSITELIB}/samba/tests/libsmb-basic.py
${PYSITELIB}/samba/tests/libsmb.py
${PYSITELIB}/samba/tests/loadparm.py
${PYSITELIB}/samba/tests/logfiles.py
${PYSITELIB}/samba/tests/lsa_string.py
${PYSITELIB}/samba/tests/messaging.py
${PYSITELIB}/samba/tests/ndr/gkdi.py
${PYSITELIB}/samba/tests/ndr/gmsa.py
${PYSITELIB}/samba/tests/ndr/sd.py
${PYSITELIB}/samba/tests/ndr/wbint.py
${PYSITELIB}/samba/tests/net_join.py
${PYSITELIB}/samba/tests/net_join_no_spnego.py
${PYSITELIB}/samba/tests/netbios.py
${PYSITELIB}/samba/tests/netcmd.py
${PYSITELIB}/samba/tests/netlogonsvc.py
${PYSITELIB}/samba/tests/nss/base.py
${PYSITELIB}/samba/tests/nss/group.py
${PYSITELIB}/samba/tests/ntacls.py
${PYSITELIB}/samba/tests/ntacls_backup.py
${PYSITELIB}/samba/tests/ntlm_auth.py
${PYSITELIB}/samba/tests/ntlm_auth_base.py
${PYSITELIB}/samba/tests/ntlm_auth_krb5.py
${PYSITELIB}/samba/tests/ntlmdisabled.py
${PYSITELIB}/samba/tests/pam_winbind.py
${PYSITELIB}/samba/tests/pam_winbind_chauthtok.py
${PYSITELIB}/samba/tests/pam_winbind_setcred.py
${PYSITELIB}/samba/tests/pam_winbind_warn_pwd_expire.py
${PYSITELIB}/samba/tests/param.py
${PYSITELIB}/samba/tests/password_hash.py
${PYSITELIB}/samba/tests/password_hash_fl2003.py
${PYSITELIB}/samba/tests/password_hash_fl2008.py
${PYSITELIB}/samba/tests/password_hash_gpgme.py
${PYSITELIB}/samba/tests/password_hash_ldap.py
${PYSITELIB}/samba/tests/password_quality.py
${PYSITELIB}/samba/tests/password_test.py
${PYSITELIB}/samba/tests/policy.py
${PYSITELIB}/samba/tests/posixacl.py
${PYSITELIB}/samba/tests/prefork_restart.py
${PYSITELIB}/samba/tests/process_limits.py
${PYSITELIB}/samba/tests/provision.py
${PYSITELIB}/samba/tests/pso.py
${PYSITELIB}/samba/tests/py_credentials.py
${PYSITELIB}/samba/tests/registry.py
${PYSITELIB}/samba/tests/reparsepoints.py
${PYSITELIB}/samba/tests/rust.py
${PYSITELIB}/samba/tests/s3_net_join.py
${PYSITELIB}/samba/tests/s3idmapdb.py
${PYSITELIB}/samba/tests/s3param.py
${PYSITELIB}/samba/tests/s3passdb.py
${PYSITELIB}/samba/tests/s3registry.py
${PYSITELIB}/samba/tests/s3windb.py
${PYSITELIB}/samba/tests/safe_tarfile.py
${PYSITELIB}/samba/tests/samba3sam.py
${PYSITELIB}/samba/tests/samba_startup_fl_change.py
${PYSITELIB}/samba/tests/samba_tool/__init__.py
${PYSITELIB}/samba/tests/samba_tool/base.py
${PYSITELIB}/samba/tests/samba_tool/computer.py
${PYSITELIB}/samba/tests/samba_tool/contact.py
${PYSITELIB}/samba/tests/samba_tool/demote.py
${PYSITELIB}/samba/tests/samba_tool/dnscmd.py
${PYSITELIB}/samba/tests/samba_tool/domain_auth_policy.py
${PYSITELIB}/samba/tests/samba_tool/domain_auth_silo.py
${PYSITELIB}/samba/tests/samba_tool/domain_claim.py
${PYSITELIB}/samba/tests/samba_tool/domain_kds_root_key.py
${PYSITELIB}/samba/tests/samba_tool/domain_models.py
${PYSITELIB}/samba/tests/samba_tool/drs_clone_dc_data_lmdb_size.py
${PYSITELIB}/samba/tests/samba_tool/dsacl.py
${PYSITELIB}/samba/tests/samba_tool/forest.py
${PYSITELIB}/samba/tests/samba_tool/fsmo.py
${PYSITELIB}/samba/tests/samba_tool/gpo.py
${PYSITELIB}/samba/tests/samba_tool/gpo_exts.py
${PYSITELIB}/samba/tests/samba_tool/group.py
${PYSITELIB}/samba/tests/samba_tool/help.py
${PYSITELIB}/samba/tests/samba_tool/join.py
${PYSITELIB}/samba/tests/samba_tool/join_lmdb_size.py
${PYSITELIB}/samba/tests/samba_tool/join_member.py
${PYSITELIB}/samba/tests/samba_tool/ntacl.py
${PYSITELIB}/samba/tests/samba_tool/ou.py
${PYSITELIB}/samba/tests/samba_tool/passwordsettings.py
${PYSITELIB}/samba/tests/samba_tool/processes.py
${PYSITELIB}/samba/tests/samba_tool/promote_dc_lmdb_size.py
${PYSITELIB}/samba/tests/samba_tool/provision_lmdb_size.py
${PYSITELIB}/samba/tests/samba_tool/provision_password_check.py
${PYSITELIB}/samba/tests/samba_tool/provision_userPassword_crypt.py
${PYSITELIB}/samba/tests/samba_tool/rodc.py
${PYSITELIB}/samba/tests/samba_tool/schema.py
${PYSITELIB}/samba/tests/samba_tool/service_account.py
${PYSITELIB}/samba/tests/samba_tool/silo_base.py
${PYSITELIB}/samba/tests/samba_tool/sites.py
${PYSITELIB}/samba/tests/samba_tool/timecmd.py
${PYSITELIB}/samba/tests/samba_tool/user.py
${PYSITELIB}/samba/tests/samba_tool/user_auth_policy.py
${PYSITELIB}/samba/tests/samba_tool/user_auth_silo.py
${PYSITELIB}/samba/tests/samba_tool/user_check_password_script.py
${PYSITELIB}/samba/tests/samba_tool/user_generate_csr.py
${PYSITELIB}/samba/tests/samba_tool/user_get_kerberos_ticket.py
${PYSITELIB}/samba/tests/samba_tool/user_getpassword_gmsa.py
${PYSITELIB}/samba/tests/samba_tool/user_keytrust.py
${PYSITELIB}/samba/tests/samba_tool/user_virtualCryptSHA.py
${PYSITELIB}/samba/tests/samba_tool/user_virtualCryptSHA_base.py
${PYSITELIB}/samba/tests/samba_tool/user_virtualCryptSHA_gpg.py
${PYSITELIB}/samba/tests/samba_tool/user_virtualCryptSHA_userPassword.py
${PYSITELIB}/samba/tests/samba_tool/user_wdigest.py
${PYSITELIB}/samba/tests/samba_tool/visualize.py
${PYSITELIB}/samba/tests/samba_tool/visualize_drs.py
${PYSITELIB}/samba/tests/samba_upgradedns_lmdb.py
${PYSITELIB}/samba/tests/samdb.py
${PYSITELIB}/samba/tests/samdb_api.py
${PYSITELIB}/samba/tests/sddl.py
${PYSITELIB}/samba/tests/sddl_conditional_ace.py
${PYSITELIB}/samba/tests/security.py
${PYSITELIB}/samba/tests/security_descriptors.py
${PYSITELIB}/samba/tests/segfault.py
${PYSITELIB}/samba/tests/sid_strings.py
${PYSITELIB}/samba/tests/smb-notify.py
${PYSITELIB}/samba/tests/smb.py
${PYSITELIB}/samba/tests/smb1posix.py
${PYSITELIB}/samba/tests/smb2symlink.py
${PYSITELIB}/samba/tests/smb3unix.py
${PYSITELIB}/samba/tests/smbconf.py
${PYSITELIB}/samba/tests/smbd_base.py
${PYSITELIB}/samba/tests/smbd_fuzztest.py
${PYSITELIB}/samba/tests/source.py
${PYSITELIB}/samba/tests/source_chars.py
${PYSITELIB}/samba/tests/strings.py
${PYSITELIB}/samba/tests/subunitrun.py
${PYSITELIB}/samba/tests/tdb_util.py
${PYSITELIB}/samba/tests/token_factory.py
${PYSITELIB}/samba/tests/tpm20_rsakey_blob.py
${PYSITELIB}/samba/tests/upgrade.py
${PYSITELIB}/samba/tests/upgradeprovision.py
${PYSITELIB}/samba/tests/upgradeprovisionneeddc.py
${PYSITELIB}/samba/tests/usage.py
${PYSITELIB}/samba/tests/varlink/base.py
${PYSITELIB}/samba/tests/varlink/getgrouprecord.py
${PYSITELIB}/samba/tests/varlink/getmemberships.py
${PYSITELIB}/samba/tests/varlink/getuserrecord.py
${PYSITELIB}/samba/tests/xattr.py
${PYSITELIB}/samba/upgrade.py
${PYSITELIB}/samba/upgradehelpers.py
${PYSITELIB}/samba/uptodateness.py
${PYSITELIB}/samba/werror.so
${PYSITELIB}/samba/xattr.py
${PYSITELIB}/samba/xattr_native.so
${PYSITELIB}/samba/xattr_tdb.so
${PLIST.ads}lib/samba/bind9/dlz_bind9_10.${SHLIB_EXT}
${PLIST.ads}lib/samba/bind9/dlz_bind9_11.${SHLIB_EXT}
${PLIST.ads}lib/samba/bind9/dlz_bind9_12.${SHLIB_EXT}
${PLIST.ads}lib/samba/bind9/dlz_bind9_14.${SHLIB_EXT}
${PLIST.ads}lib/samba/bind9/dlz_bind9_16.${SHLIB_EXT}
${PLIST.ads}lib/samba/bind9/dlz_bind9_18.${SHLIB_EXT}
${PLIST.ads}lib/samba/idmap/ad.${SHLIB_EXT}
lib/samba/idmap/autorid.${SHLIB_EXT}
lib/samba/idmap/hash.${SHLIB_EXT}
${PLIST.ads}lib/samba/idmap/rfc2307.${SHLIB_EXT}
lib/samba/idmap/rid.${SHLIB_EXT}
lib/samba/idmap/script.${SHLIB_EXT}
lib/samba/idmap/tdb2.${SHLIB_EXT}
lib/samba/krb5/async_dns_krb5_locator.${SHLIB_EXT}
lib/samba/krb5/winbind_krb5_locator.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/acl.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/aclread.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/anr.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/asq.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/audit_log.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/count_attrs.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/descriptor.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/dirsync.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/dns_notify.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/dsdb_notification.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/encrypted_secrets.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/extended_dn_in.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/extended_dn_out.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/extended_dn_store.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/group_audit_log.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/ildap.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/instancetype.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/lazy_commit.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/ldap.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/ldb.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/ldbsamba_extensions.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/linked_attributes.${SHLIB_EXT}
${PLIST.ads}${PLIST.mdb}lib/samba/ldb/mdb.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/new_partition.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/objectclass.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/objectclass_attrs.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/objectguid.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/operational.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/paged_results.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/paged_searches.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/partition.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/password_hash.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/ranged_results.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/rdn_name.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/repl_meta_data.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/resolve_oids.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/rootdse.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/samba3sam.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/samba3sid.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/samba_dsdb.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/samba_secrets.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/samldb.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/sample.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/schema_data.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/schema_load.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/secrets_tdb_sync.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/server_sort.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/show_deleted.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/skel.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/subtree_delete.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/subtree_rename.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/tdb.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/tombstone_reanimate.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/trust_notify.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/unique_object_sids.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/update_keytab.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/vlv.${SHLIB_EXT}
${PLIST.ads}lib/samba/ldb/wins_ldb.${SHLIB_EXT}
${PLIST.ads}lib/samba/nss_info/hash.${SHLIB_EXT}
${PLIST.ads}lib/samba/nss_info/rfc2307.${SHLIB_EXT}
${PLIST.ads}lib/samba/nss_info/sfu.${SHLIB_EXT}
${PLIST.ads}lib/samba/nss_info/sfu20.${SHLIB_EXT}
lib/samba/private/libCHARSET3-private-samba.so
lib/samba/private/libHDB-SAMBA4-private-samba.so
lib/samba/private/libLIBWBCLIENT-OLD-private-samba.so
lib/samba/private/libMESSAGING-SEND-private-samba.so
lib/samba/private/libMESSAGING-private-samba.so
lib/samba/private/libREG-FULL-private-samba.so
lib/samba/private/libRPC-SERVER-LOOP-private-samba.so
lib/samba/private/libRPC-WORKER-private-samba.so
lib/samba/private/libad-claims-private-samba.so
lib/samba/private/libaddns-private-samba.so
lib/samba/private/libads-private-samba.so
lib/samba/private/libasn1-private-samba.so
lib/samba/private/libasn1util-private-samba.so
lib/samba/private/libauth-private-samba.so
lib/samba/private/libauth-unix-token-private-samba.so
lib/samba/private/libauth4-private-samba.so
lib/samba/private/libauthkrb5-private-samba.so
lib/samba/private/libauthn-policy-util-private-samba.so
lib/samba/private/libcli-cldap-private-samba.so
lib/samba/private/libcli-ldap-common-private-samba.so
lib/samba/private/libcli-ldap-private-samba.so
lib/samba/private/libcli-nbt-private-samba.so
lib/samba/private/libcli-smb-common-private-samba.so
lib/samba/private/libcli-spoolss-private-samba.so
lib/samba/private/libcliauth-private-samba.so
lib/samba/private/libclidns-private-samba.so
lib/samba/private/libcluster-private-samba.so
lib/samba/private/libcmdline-contexts-private-samba.so
lib/samba/private/libcmdline-private-samba.so
lib/samba/private/libcom-err-private-samba.so
lib/samba/private/libcommon-auth-private-samba.so
lib/samba/private/libdb-glue-private-samba.so
lib/samba/private/libdbwrap-private-samba.so
lib/samba/private/libdcerpc-pkt-auth-private-samba.so
lib/samba/private/libdcerpc-private-samba.so
lib/samba/private/libdcerpc-samba-private-samba.so
lib/samba/private/libdcerpc-samba4-private-samba.so
lib/samba/private/libdcerpc-samr-private-samba.so
lib/samba/private/libdcerpc-server-private-samba.so
lib/samba/private/libdfs-server-ad-private-samba.so
lib/samba/private/libdlz-bind9-for-torture-private-samba.so
lib/samba/private/libdnsserver-common-private-samba.so
lib/samba/private/libdsdb-garbage-collect-tombstones-private-samba.so
lib/samba/private/libdsdb-module-private-samba.so
lib/samba/private/libevents-private-samba.so
lib/samba/private/libflag-mapping-private-samba.so
lib/samba/private/libgenrand-private-samba.so
lib/samba/private/libgensec-private-samba.so
lib/samba/private/libgpext-private-samba.so
lib/samba/private/libgpo-private-samba.so
lib/samba/private/libgse-private-samba.so
lib/samba/private/libgss-preauth-private-samba.so
lib/samba/private/libgssapi-private-samba.so
lib/samba/private/libhcrypto-private-samba.so
lib/samba/private/libhdb-private-samba.so
lib/samba/private/libheimbase-private-samba.so
lib/samba/private/libheimntlm-private-samba.so
lib/samba/private/libhttp-private-samba.so
lib/samba/private/libhx509-private-samba.so
lib/samba/private/libidmap-private-samba.so
lib/samba/private/libinterfaces-private-samba.so
lib/samba/private/libiov-buf-private-samba.so
lib/samba/private/libkdc-private-samba.so
lib/samba/private/libkrb5-private-samba.so
lib/samba/private/libkrb5samba-private-samba.so
lib/samba/private/libldb-cmdline-private-samba.so
lib/samba/private/libldb-key-value-private-samba.so
${PLIST.mdb}lib/samba/private/libldb-mdb-int-private-samba.so
lib/samba/private/libldb-private-samba.so
lib/samba/private/libldb-tdb-err-map-private-samba.so
lib/samba/private/libldb-tdb-int-private-samba.so
lib/samba/private/libldbsamba-private-samba.so
lib/samba/private/liblibcli-lsa3-private-samba.so
lib/samba/private/liblibcli-netlogon3-private-samba.so
lib/samba/private/liblibsmb-private-samba.so
lib/samba/private/libmessages-dgm-private-samba.so
lib/samba/private/libmessages-util-private-samba.so
lib/samba/private/libmscat-private-samba.so
lib/samba/private/libmsghdr-private-samba.so
lib/samba/private/libmsrpc3-private-samba.so
lib/samba/private/libndr-samba-private-samba.so
lib/samba/private/libndr-samba4-private-samba.so
lib/samba/private/libnet-keytab-private-samba.so
lib/samba/private/libnetif-private-samba.so
lib/samba/private/libnpa-tstream-private-samba.so
lib/samba/private/libnss-info-private-samba.so
lib/samba/private/libpac-private-samba.so
lib/samba/private/libposix-eadb-private-samba.so
lib/samba/private/libprinter-driver-private-samba.so
lib/samba/private/libprinting-migrate-private-samba.so
lib/samba/private/libprocess-model-private-samba.so
lib/samba/private/libpyldb-util-private-samba.so
lib/samba/private/libregistry-private-samba.so
lib/samba/private/libreplace-private-samba.so
lib/samba/private/libroken-private-samba.so
lib/samba/private/libsamba-cluster-support-private-samba.so
lib/samba/private/libsamba-credentials-private-samba.so
lib/samba/private/libsamba-debug-private-samba.so
lib/samba/private/libsamba-hostconfig-private-samba.so
lib/samba/private/libsamba-modules-private-samba.so
lib/samba/private/libsamba-net-join-private-samba.so
lib/samba/private/libsamba-net-private-samba.so
lib/samba/private/libsamba-policy-private-samba.so
lib/samba/private/libsamba-python-private-samba.so
lib/samba/private/libsamba-security-private-samba.so
lib/samba/private/libsamba-security-trusts-private-samba.so
lib/samba/private/libsamba-sockets-private-samba.so
lib/samba/private/libsamba3-util-private-samba.so
lib/samba/private/libsamdb-common-private-samba.so
lib/samba/private/libsamdb-private-samba.so
lib/samba/private/libscavenge-dns-records-private-samba.so
lib/samba/private/libsecrets3-private-samba.so
lib/samba/private/libserver-id-db-private-samba.so
lib/samba/private/libserver-role-private-samba.so
lib/samba/private/libservice-private-samba.so
lib/samba/private/libshares-private-samba.so
lib/samba/private/libsmbclient-raw-private-samba.so
lib/samba/private/libsmbd-base-private-samba.so
lib/samba/private/libsmbd-shim-private-samba.so
lib/samba/private/libsmbldaphelper-private-samba.so
lib/samba/private/libsmbpasswdparser-private-samba.so
lib/samba/private/libsocket-blocking-private-samba.so
lib/samba/private/libstable-sort-private-samba.so
lib/samba/private/libsys-rw-private-samba.so
lib/samba/private/libtalloc-report-printf-private-samba.so
lib/samba/private/libtalloc-report-private-samba.so
lib/samba/private/libtdb-wrap-private-samba.so
lib/samba/private/libtevent-util-private-samba.so
lib/samba/private/libtime-basic-private-samba.so
lib/samba/private/libtorture-private-samba.so
lib/samba/private/libutil-crypt-private-samba.so
lib/samba/private/libutil-reg-private-samba.so
lib/samba/private/libutil-setid-private-samba.so
lib/samba/private/libutil-tdb-private-samba.so
lib/samba/private/libwind-private-samba.so
lib/samba/private/libxattr-tdb-private-samba.so
${PLIST.ads}lib/samba/process_model/prefork.${SHLIB_EXT}
${PLIST.ads}lib/samba/process_model/standard.${SHLIB_EXT}
${PLIST.pam}lib/samba/security/pam_winbind.${SHLIB_EXT}
${PLIST.ads}lib/samba/service/cldap.${SHLIB_EXT}
${PLIST.ads}lib/samba/service/dcerpc.${SHLIB_EXT}
${PLIST.ads}lib/samba/service/dns.${SHLIB_EXT}
${PLIST.ads}lib/samba/service/dns_update.${SHLIB_EXT}
${PLIST.ads}lib/samba/service/drepl.${SHLIB_EXT}
${PLIST.ads}lib/samba/service/ft_scanner.${SHLIB_EXT}
${PLIST.ads}lib/samba/service/kcc.${SHLIB_EXT}
${PLIST.ads}lib/samba/service/kdc.${SHLIB_EXT}
${PLIST.ads}lib/samba/service/ldap.${SHLIB_EXT}
${PLIST.ads}lib/samba/service/nbtd.${SHLIB_EXT}
${PLIST.ads}lib/samba/service/ntp_signd.${SHLIB_EXT}
${PLIST.ads}lib/samba/service/s3fs.${SHLIB_EXT}
${PLIST.ads}lib/samba/service/winbindd.${SHLIB_EXT}
${PLIST.ads}lib/samba/service/wrepl.${SHLIB_EXT}
lib/samba/vfs/acl_tdb.${SHLIB_EXT}
lib/samba/vfs/acl_xattr.${SHLIB_EXT}
lib/samba/vfs/aio_fork.${SHLIB_EXT}
lib/samba/vfs/aio_pthread.${SHLIB_EXT}
lib/samba/vfs/aio_ratelimit.${SHLIB_EXT}
lib/samba/vfs/audit.${SHLIB_EXT}
lib/samba/vfs/cap.${SHLIB_EXT}
lib/samba/vfs/catia.${SHLIB_EXT}
lib/samba/vfs/commit.${SHLIB_EXT}
lib/samba/vfs/crossrename.${SHLIB_EXT}
lib/samba/vfs/default_quota.${SHLIB_EXT}
lib/samba/vfs/dirsort.${SHLIB_EXT}
lib/samba/vfs/expand_msdfs.${SHLIB_EXT}
lib/samba/vfs/extd_audit.${SHLIB_EXT}
lib/samba/vfs/fake_perms.${SHLIB_EXT}
lib/samba/vfs/fruit.${SHLIB_EXT}
lib/samba/vfs/full_audit.${SHLIB_EXT}
lib/samba/vfs/linux_xfs_sgid.${SHLIB_EXT}
lib/samba/vfs/media_harmony.${SHLIB_EXT}
lib/samba/vfs/offline.${SHLIB_EXT}
${PLIST.ads}lib/samba/vfs/posix_eadb.${SHLIB_EXT}
lib/samba/vfs/preopen.${SHLIB_EXT}
lib/samba/vfs/readahead.${SHLIB_EXT}
lib/samba/vfs/readonly.${SHLIB_EXT}
lib/samba/vfs/recycle.${SHLIB_EXT}
lib/samba/vfs/shadow_copy.${SHLIB_EXT}
lib/samba/vfs/shadow_copy2.${SHLIB_EXT}
lib/samba/vfs/shell_snap.${SHLIB_EXT}
${PLIST.snapper}lib/samba/vfs/snapper.${SHLIB_EXT}
lib/samba/vfs/streams_depot.${SHLIB_EXT}
lib/samba/vfs/streams_xattr.${SHLIB_EXT}
lib/samba/vfs/syncops.${SHLIB_EXT}
lib/samba/vfs/time_audit.${SHLIB_EXT}
lib/samba/vfs/unityed_media.${SHLIB_EXT}
lib/samba/vfs/virusfilter.${SHLIB_EXT}
lib/samba/vfs/widelinks.${SHLIB_EXT}
lib/samba/vfs/worm.${SHLIB_EXT}
lib/samba/vfs/xattr_tdb.${SHLIB_EXT}
libexec/samba/rpcd_classic
libexec/samba/rpcd_epmapper
libexec/samba/rpcd_fsrvp
libexec/samba/rpcd_lsad
libexec/samba/rpcd_mdssvc
libexec/samba/rpcd_spoolss
libexec/samba/rpcd_winreg
libexec/samba/samba-bgqd
libexec/samba/samba-dcerpcd
${PLIST.cups}libexec/samba/smbspool_krb5_wrapper
man/man1/dbwrap_tool.1
man/man1/gentest.1
man/man1/ldbadd.1
man/man1/ldbdel.1
man/man1/ldbedit.1
man/man1/ldbmodify.1
man/man1/ldbrename.1
man/man1/ldbsearch.1
man/man1/locktest.1
man/man1/log2pcap.1
man/man1/masktest.1
man/man1/mdsearch.1
man/man1/mvxattr.1
man/man1/ndrdump.1
man/man1/nmblookup.1
man/man1/ntlm_auth.1
man/man1/oLschema2ldif.1
man/man1/profiles.1
man/man1/regdiff.1
man/man1/regpatch.1
man/man1/regshell.1
man/man1/regtree.1
man/man1/rpcclient.1
man/man1/samba-log-parser.1
man/man1/sharesec.1
man/man1/smbcacls.1
man/man1/smbclient.1
man/man1/smbcontrol.1
man/man1/smbcquotas.1
man/man1/smbget.1
man/man1/smbstatus.1
man/man1/smbtar.1
man/man1/smbtorture.1
man/man1/smbtree.1
man/man1/testparm.1
man/man1/wbinfo.1
man/man1/wspsearch.1
man/man3/ldb.3
man/man5/lmhosts.5
${PLIST.pam}man/man5/pam_winbind.conf.5
man/man5/smb.conf.5
man/man5/smbpasswd.5
man/man7/libsmbclient.7
man/man7/samba.7
man/man7/traffic_learner.7
man/man7/traffic_replay.7
man/man8/cifsdd.8
man/man8/eventlogadm.8
man/man8/idmap_ad.8
man/man8/idmap_autorid.8
man/man8/idmap_hash.8
man/man8/idmap_ldap.8
man/man8/idmap_nss.8
man/man8/idmap_rfc2307.8
man/man8/idmap_rid.8
man/man8/idmap_script.8
man/man8/idmap_tdb.8
man/man8/idmap_tdb2.8
man/man8/net.8
man/man8/nmbd.8
${PLIST.pam}man/man8/pam_winbind.8
man/man8/pdbedit.8
man/man8/samba-bgqd.8
man/man8/samba-dcerpcd.8
man/man8/samba-gpupdate.8
man/man8/samba-regedit.8
man/man8/samba-tool.8
man/man8/samba.8
man/man8/samba_downgrade_db.8
man/man8/smbd.8
man/man8/smbpasswd.8
man/man8/smbspool.8
man/man8/smbspool_krb5_wrapper.8
man/man8/vfs_acl_tdb.8
man/man8/vfs_acl_xattr.8
man/man8/vfs_aio_fork.8
man/man8/vfs_aio_pthread.8
man/man8/vfs_aio_ratelimit.8
man/man8/vfs_audit.8
man/man8/vfs_cap.8
man/man8/vfs_catia.8
man/man8/vfs_commit.8
man/man8/vfs_crossrename.8
man/man8/vfs_default_quota.8
man/man8/vfs_dirsort.8
man/man8/vfs_expand_msdfs.8
man/man8/vfs_extd_audit.8
man/man8/vfs_fake_perms.8
man/man8/vfs_fruit.8
man/man8/vfs_full_audit.8
man/man8/vfs_linux_xfs_sgid.8
man/man8/vfs_media_harmony.8
man/man8/vfs_offline.8
man/man8/vfs_preopen.8
man/man8/vfs_readahead.8
man/man8/vfs_readonly.8
man/man8/vfs_recycle.8
man/man8/vfs_shadow_copy.8
man/man8/vfs_shadow_copy2.8
man/man8/vfs_shell_snap.8
${PLIST.snapper}man/man8/vfs_snapper.8
man/man8/vfs_streams_depot.8
man/man8/vfs_streams_xattr.8
man/man8/vfs_syncops.8
man/man8/vfs_time_audit.8
man/man8/vfs_unityed_media.8
man/man8/vfs_virusfilter.8
man/man8/vfs_widelinks.8
man/man8/vfs_worm.8
man/man8/vfs_xattr_tdb.8
man/man8/winbind_krb5_locator.8
man/man8/winbindd.8
sbin/eventlogadm
sbin/nmbd
${PLIST.ads}sbin/samba
sbin/samba-gpupdate
${PLIST.ads}sbin/samba_dnsupdate
${PLIST.ads}sbin/samba_downgrade_db
${PLIST.ads}sbin/samba_kcc
${PLIST.ads}sbin/samba_spnupdate
${PLIST.ads}sbin/samba_upgradedns
sbin/smbd
${PLIST.winbind}sbin/winbindd
share/doc/samba/NT4-Locking.reg
share/doc/samba/NT4_PlainPassword.reg
share/doc/samba/Win-2Kx-XPP-DeleteCachedProfiles.reg
share/doc/samba/Win-2Kx-XPP-ForceLocalProfile.reg
share/doc/samba/Win-NT-DeleteRoamingProfile.reg
share/doc/samba/Win2000_PlainPassword.reg
share/doc/samba/Win7_Samba3DomainMember.reg
share/doc/samba/Win95_PlainPassword.reg
share/doc/samba/Win98_PlainPassword.reg
share/doc/samba/Win9X-CacheHandling.reg
share/doc/samba/WinME_PlainPassword.reg
share/doc/samba/WinXP_PlainPassword.reg
share/doc/samba/WindowsTerminalServer.reg
share/examples/samba/adduser.sh
share/examples/samba/deluser.sh
@@pkgdir share/examples/samba/pam_smbpass
share/examples/samba/samba.schema
share/examples/samba/smb.conf.default
share/locale/ar/LC_MESSAGES/pam_winbind.mo
share/locale/cs/LC_MESSAGES/pam_winbind.mo
share/locale/da/LC_MESSAGES/pam_winbind.mo
share/locale/de/LC_MESSAGES/net.mo
share/locale/de/LC_MESSAGES/pam_winbind.mo
share/locale/es/LC_MESSAGES/pam_winbind.mo
share/locale/fi/LC_MESSAGES/pam_winbind.mo
share/locale/fr/LC_MESSAGES/pam_winbind.mo
share/locale/hu/LC_MESSAGES/pam_winbind.mo
share/locale/it/LC_MESSAGES/pam_winbind.mo
share/locale/ja/LC_MESSAGES/pam_winbind.mo
share/locale/ka/LC_MESSAGES/net.mo
share/locale/ka/LC_MESSAGES/pam_winbind.mo
share/locale/ko/LC_MESSAGES/pam_winbind.mo
share/locale/nb/LC_MESSAGES/pam_winbind.mo
share/locale/nl/LC_MESSAGES/pam_winbind.mo
share/locale/pl/LC_MESSAGES/pam_winbind.mo
share/locale/pt_BR/LC_MESSAGES/pam_winbind.mo
share/locale/ru/LC_MESSAGES/pam_winbind.mo
share/locale/sv/LC_MESSAGES/pam_winbind.mo
share/locale/tr/LC_MESSAGES/pam_winbind.mo
share/locale/zh_CN/LC_MESSAGES/pam_winbind.mo
share/locale/zh_TW/LC_MESSAGES/pam_winbind.mo
${PLIST.ads}share/samba/samba/admx/GNOME_Settings.admx
${PLIST.ads}share/samba/samba/admx/en-US/GNOME_Settings.adml
${PLIST.ads}share/samba/samba/admx/en-US/samba.adml
${PLIST.ads}share/samba/samba/admx/ru-RU/GNOME_Settings.adml
${PLIST.ads}share/samba/samba/admx/samba.admx
${PLIST.ads}share/samba/setup/ad-schema/AD_DS_Attributes_Windows_Server_v1903.ldf
${PLIST.ads}share/samba/setup/ad-schema/AD_DS_Attributes__Windows_Server_2012_R2.ldf
${PLIST.ads}share/samba/setup/ad-schema/AD_DS_Attributes__Windows_Server_2016.ldf
${PLIST.ads}share/samba/setup/ad-schema/AD_DS_Attributes__Windows_Server_v1803.ldf
${PLIST.ads}share/samba/setup/ad-schema/AD_DS_Classes_Windows_Server_v1903.ldf
${PLIST.ads}share/samba/setup/ad-schema/AD_DS_Classes__Windows_Server_2012_R2.ldf
${PLIST.ads}share/samba/setup/ad-schema/AD_DS_Classes__Windows_Server_2016.ldf
${PLIST.ads}share/samba/setup/ad-schema/AD_DS_Classes__Windows_Server_v1803.ldf
${PLIST.ads}share/samba/setup/ad-schema/Attributes_for_AD_DS__Windows_Server_2008_R2.ldf
${PLIST.ads}share/samba/setup/ad-schema/Attributes_for_AD_DS__Windows_Server_2012.ldf
${PLIST.ads}share/samba/setup/ad-schema/Classes_for_AD_DS__Windows_Server_2008_R2.ldf
${PLIST.ads}share/samba/setup/ad-schema/Classes_for_AD_DS__Windows_Server_2012.ldf
${PLIST.ads}share/samba/setup/ad-schema/MS-AD_Schema_2K8_Attributes.txt
${PLIST.ads}share/samba/setup/ad-schema/MS-AD_Schema_2K8_Classes.txt
${PLIST.ads}share/samba/setup/ad-schema/MS-AD_Schema_2K8_R2_Attributes.txt
${PLIST.ads}share/samba/setup/ad-schema/MS-AD_Schema_2K8_R2_Classes.txt
${PLIST.ads}share/samba/setup/ad-schema/licence.txt
${PLIST.ads}share/samba/setup/adprep/WindowsServerDocs/Forest-Wide-Updates.md
${PLIST.ads}share/samba/setup/adprep/WindowsServerDocs/Sch49.ldf.diff
${PLIST.ads}share/samba/setup/adprep/WindowsServerDocs/Sch50.ldf.diff
${PLIST.ads}share/samba/setup/adprep/WindowsServerDocs/Sch51.ldf.diff
${PLIST.ads}share/samba/setup/adprep/WindowsServerDocs/Sch57.ldf.diff
${PLIST.ads}share/samba/setup/adprep/WindowsServerDocs/Sch59.ldf.diff
${PLIST.ads}share/samba/setup/adprep/WindowsServerDocs/Schema-Updates.md
${PLIST.ads}share/samba/setup/adprep/fix-forest-rev.ldf
${PLIST.ads}share/samba/setup/aggregate_schema.ldif
${PLIST.ads}share/samba/setup/display-specifiers/DisplaySpecifiers-Win2k0.txt
${PLIST.ads}share/samba/setup/display-specifiers/DisplaySpecifiers-Win2k3.txt
${PLIST.ads}share/samba/setup/display-specifiers/DisplaySpecifiers-Win2k3R2.txt
${PLIST.ads}share/samba/setup/display-specifiers/DisplaySpecifiers-Win2k8.txt
${PLIST.ads}share/samba/setup/display-specifiers/DisplaySpecifiers-Win2k8R2.txt
${PLIST.ads}share/samba/setup/dns_update_list
${PLIST.ads}share/samba/setup/extended-rights.ldif
${PLIST.ads}share/samba/setup/idmap_init.ldif
${PLIST.ads}share/samba/setup/krb5.conf
${PLIST.ads}share/samba/setup/named.conf
${PLIST.ads}share/samba/setup/named.conf.dlz
${PLIST.ads}share/samba/setup/named.conf.update
${PLIST.ads}share/samba/setup/named.txt
${PLIST.ads}share/samba/setup/prefixMap.txt
${PLIST.ads}share/samba/setup/provision.ldif
${PLIST.ads}share/samba/setup/provision.reg
${PLIST.ads}share/samba/setup/provision.zone
${PLIST.ads}share/samba/setup/provision_basedn.ldif
${PLIST.ads}share/samba/setup/provision_basedn_modify.ldif
${PLIST.ads}share/samba/setup/provision_basedn_options.ldif
${PLIST.ads}share/samba/setup/provision_basedn_references.ldif
${PLIST.ads}share/samba/setup/provision_computers_add.ldif
${PLIST.ads}share/samba/setup/provision_computers_modify.ldif
${PLIST.ads}share/samba/setup/provision_configuration.ldif
${PLIST.ads}share/samba/setup/provision_configuration_basedn.ldif
${PLIST.ads}share/samba/setup/provision_configuration_modify.ldif
${PLIST.ads}share/samba/setup/provision_configuration_references.ldif
${PLIST.ads}share/samba/setup/provision_dns_accounts_add.ldif
${PLIST.ads}share/samba/setup/provision_dns_add_samba.ldif
${PLIST.ads}share/samba/setup/provision_dnszones_add.ldif
${PLIST.ads}share/samba/setup/provision_dnszones_modify.ldif
${PLIST.ads}share/samba/setup/provision_dnszones_partitions.ldif
${PLIST.ads}share/samba/setup/provision_group_policy.ldif
${PLIST.ads}share/samba/setup/provision_init.ldif
${PLIST.ads}share/samba/setup/provision_partitions.ldif
${PLIST.ads}share/samba/setup/provision_privilege.ldif
${PLIST.ads}share/samba/setup/provision_rootdse_add.ldif
${PLIST.ads}share/samba/setup/provision_rootdse_modify.ldif
${PLIST.ads}share/samba/setup/provision_schema_basedn.ldif
${PLIST.ads}share/samba/setup/provision_schema_basedn_modify.ldif
${PLIST.ads}share/samba/setup/provision_self_join.ldif
${PLIST.ads}share/samba/setup/provision_self_join_config.ldif
${PLIST.ads}share/samba/setup/provision_self_join_modify.ldif
${PLIST.ads}share/samba/setup/provision_self_join_modify_config.ldif
${PLIST.ads}share/samba/setup/provision_self_join_modify_schema.ldif
${PLIST.ads}share/samba/setup/provision_users.ldif
${PLIST.ads}share/samba/setup/provision_users_add.ldif
${PLIST.ads}share/samba/setup/provision_users_modify.ldif
${PLIST.ads}share/samba/setup/provision_well_known_sec_princ.ldif
${PLIST.ads}share/samba/setup/schema_samba4.ldif
${PLIST.ads}share/samba/setup/secrets.ldif
${PLIST.ads}share/samba/setup/secrets_dns.ldif
${PLIST.ads}share/samba/setup/secrets_init.ldif
${PLIST.ads}share/samba/setup/share.ldif
${PLIST.ads}share/samba/setup/spn_update_list
${PLIST.ads}share/samba/setup/ypServ30.ldif
@


1.63
log
@samba4: updated to 4.23.4

Changes since 4.23.3
* BUG 15926: Samba 4.22 breaks Time Machine
* BUG 15947: mdssvc doesn't support $time.iso dates before 1970
* BUG 15963: Fix winbind cache consistency
* BUG 15897: Assert failed: (dirfd != -1) || (smb_fname->base_name[0] == '/')
  in vfswrap_openat
* BUG 15950: ctdb can crash with inconsistent cluster lock configuration
* BUG 15897: Assert failed: (dirfd != -1) || (smb_fname->base_name[0] == '/')
  in vfswrap_openat
* BUG 15809: samba-bgqd: rework man page
* BUG 15936: samba-bgqd can't find [printers] share
* BUG 15955: Winbind can hang forever in gssapi if there are network issues.
* BUG 15961: libldb requires linking libreplace on Linux
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.62 2025/06/04 14:43:09 taca Exp $
d116 1
d177 1
d274 1
d321 1
d337 2
d411 1
d413 1
d551 1
d579 1
d599 1
d606 1
d725 1
d728 1
d1010 1
d1131 1
d1206 2
@


1.62
log
@net/samba4: update to 4.21.6

Samba 4.21.6 (2025-06-03)

This is the latest stable release of the Samba 4.21 release series.
It contains the security-relevant bugfix CVE-2025-0620:

    smbd doesn't pick up group membership changes
    when re-authenticating an expired SMB session:
    https://www.samba.org/samba/security/CVE-2025-0620.html


For more detail and changes with 4.21.4 and 4.21.5 please refer:
<https://www.samba.org/samba/history/>.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.61 2025/05/06 12:07:35 wiz Exp $
d136 2
a137 2
lib/libndr.so.5
lib/libndr.so.5.0.0
d147 1
a147 1
lib/libsamba-passdb.so.0.29.0
d153 1
a153 1
lib/libsmbclient.so.0.8.0
d188 1
d205 1
d227 1
d471 1
d510 1
d569 1
d592 1
d634 2
d663 1
d745 1
d750 4
d830 1
d944 1
a954 1
lib/samba/private/libsmb-transport-private-samba.so
d983 1
d1179 21
@


1.61
log
@*: SOEXT -> SHLIB_EXT
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.60 2025/04/06 16:15:43 tsutsui Exp $
d620 1
d953 1
@


1.60
log
@samba4: fix build failure on NetBSD/i386 (and other non-LP64 environments).

Ok'ed by wiz@@ and closes PR pkg/58947.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.59 2024/11/26 11:38:09 adam Exp $
d746 76
a821 76
${PLIST.ads}lib/samba/bind9/dlz_bind9_10.${SOEXT}
${PLIST.ads}lib/samba/bind9/dlz_bind9_11.${SOEXT}
${PLIST.ads}lib/samba/bind9/dlz_bind9_12.${SOEXT}
${PLIST.ads}lib/samba/bind9/dlz_bind9_14.${SOEXT}
${PLIST.ads}lib/samba/bind9/dlz_bind9_16.${SOEXT}
${PLIST.ads}lib/samba/bind9/dlz_bind9_18.${SOEXT}
${PLIST.ads}lib/samba/idmap/ad.${SOEXT}
lib/samba/idmap/autorid.${SOEXT}
lib/samba/idmap/hash.${SOEXT}
${PLIST.ads}lib/samba/idmap/rfc2307.${SOEXT}
lib/samba/idmap/rid.${SOEXT}
lib/samba/idmap/script.${SOEXT}
lib/samba/idmap/tdb2.${SOEXT}
lib/samba/krb5/async_dns_krb5_locator.${SOEXT}
lib/samba/krb5/winbind_krb5_locator.${SOEXT}
${PLIST.ads}lib/samba/ldb/acl.${SOEXT}
${PLIST.ads}lib/samba/ldb/aclread.${SOEXT}
${PLIST.ads}lib/samba/ldb/anr.${SOEXT}
${PLIST.ads}lib/samba/ldb/asq.${SOEXT}
${PLIST.ads}lib/samba/ldb/audit_log.${SOEXT}
${PLIST.ads}lib/samba/ldb/count_attrs.${SOEXT}
${PLIST.ads}lib/samba/ldb/descriptor.${SOEXT}
${PLIST.ads}lib/samba/ldb/dirsync.${SOEXT}
${PLIST.ads}lib/samba/ldb/dns_notify.${SOEXT}
${PLIST.ads}lib/samba/ldb/dsdb_notification.${SOEXT}
${PLIST.ads}lib/samba/ldb/encrypted_secrets.${SOEXT}
${PLIST.ads}lib/samba/ldb/extended_dn_in.${SOEXT}
${PLIST.ads}lib/samba/ldb/extended_dn_out.${SOEXT}
${PLIST.ads}lib/samba/ldb/extended_dn_store.${SOEXT}
${PLIST.ads}lib/samba/ldb/group_audit_log.${SOEXT}
${PLIST.ads}lib/samba/ldb/ildap.${SOEXT}
${PLIST.ads}lib/samba/ldb/instancetype.${SOEXT}
${PLIST.ads}lib/samba/ldb/lazy_commit.${SOEXT}
${PLIST.ads}lib/samba/ldb/ldap.${SOEXT}
${PLIST.ads}lib/samba/ldb/ldb.${SOEXT}
${PLIST.ads}lib/samba/ldb/ldbsamba_extensions.${SOEXT}
${PLIST.ads}lib/samba/ldb/linked_attributes.${SOEXT}
${PLIST.ads}${PLIST.mdb}lib/samba/ldb/mdb.${SOEXT}
${PLIST.ads}lib/samba/ldb/new_partition.${SOEXT}
${PLIST.ads}lib/samba/ldb/objectclass.${SOEXT}
${PLIST.ads}lib/samba/ldb/objectclass_attrs.${SOEXT}
${PLIST.ads}lib/samba/ldb/objectguid.${SOEXT}
${PLIST.ads}lib/samba/ldb/operational.${SOEXT}
${PLIST.ads}lib/samba/ldb/paged_results.${SOEXT}
${PLIST.ads}lib/samba/ldb/paged_searches.${SOEXT}
${PLIST.ads}lib/samba/ldb/partition.${SOEXT}
${PLIST.ads}lib/samba/ldb/password_hash.${SOEXT}
${PLIST.ads}lib/samba/ldb/ranged_results.${SOEXT}
${PLIST.ads}lib/samba/ldb/rdn_name.${SOEXT}
${PLIST.ads}lib/samba/ldb/repl_meta_data.${SOEXT}
${PLIST.ads}lib/samba/ldb/resolve_oids.${SOEXT}
${PLIST.ads}lib/samba/ldb/rootdse.${SOEXT}
${PLIST.ads}lib/samba/ldb/samba3sam.${SOEXT}
${PLIST.ads}lib/samba/ldb/samba3sid.${SOEXT}
${PLIST.ads}lib/samba/ldb/samba_dsdb.${SOEXT}
${PLIST.ads}lib/samba/ldb/samba_secrets.${SOEXT}
${PLIST.ads}lib/samba/ldb/samldb.${SOEXT}
${PLIST.ads}lib/samba/ldb/sample.${SOEXT}
${PLIST.ads}lib/samba/ldb/schema_data.${SOEXT}
${PLIST.ads}lib/samba/ldb/schema_load.${SOEXT}
${PLIST.ads}lib/samba/ldb/secrets_tdb_sync.${SOEXT}
${PLIST.ads}lib/samba/ldb/server_sort.${SOEXT}
${PLIST.ads}lib/samba/ldb/show_deleted.${SOEXT}
${PLIST.ads}lib/samba/ldb/skel.${SOEXT}
${PLIST.ads}lib/samba/ldb/subtree_delete.${SOEXT}
${PLIST.ads}lib/samba/ldb/subtree_rename.${SOEXT}
${PLIST.ads}lib/samba/ldb/tdb.${SOEXT}
${PLIST.ads}lib/samba/ldb/tombstone_reanimate.${SOEXT}
${PLIST.ads}lib/samba/ldb/unique_object_sids.${SOEXT}
${PLIST.ads}lib/samba/ldb/update_keytab.${SOEXT}
${PLIST.ads}lib/samba/ldb/vlv.${SOEXT}
${PLIST.ads}lib/samba/ldb/wins_ldb.${SOEXT}
${PLIST.ads}lib/samba/nss_info/hash.${SOEXT}
${PLIST.ads}lib/samba/nss_info/rfc2307.${SOEXT}
${PLIST.ads}lib/samba/nss_info/sfu.${SOEXT}
${PLIST.ads}lib/samba/nss_info/sfu20.${SOEXT}
d957 53
a1009 53
${PLIST.ads}lib/samba/process_model/prefork.${SOEXT}
${PLIST.ads}lib/samba/process_model/standard.${SOEXT}
${PLIST.pam}lib/samba/security/pam_winbind.${SOEXT}
${PLIST.ads}lib/samba/service/cldap.${SOEXT}
${PLIST.ads}lib/samba/service/dcerpc.${SOEXT}
${PLIST.ads}lib/samba/service/dns.${SOEXT}
${PLIST.ads}lib/samba/service/dns_update.${SOEXT}
${PLIST.ads}lib/samba/service/drepl.${SOEXT}
${PLIST.ads}lib/samba/service/kcc.${SOEXT}
${PLIST.ads}lib/samba/service/kdc.${SOEXT}
${PLIST.ads}lib/samba/service/ldap.${SOEXT}
${PLIST.ads}lib/samba/service/nbtd.${SOEXT}
${PLIST.ads}lib/samba/service/ntp_signd.${SOEXT}
${PLIST.ads}lib/samba/service/s3fs.${SOEXT}
${PLIST.ads}lib/samba/service/winbindd.${SOEXT}
${PLIST.ads}lib/samba/service/wrepl.${SOEXT}
lib/samba/vfs/acl_tdb.${SOEXT}
lib/samba/vfs/acl_xattr.${SOEXT}
lib/samba/vfs/aio_fork.${SOEXT}
lib/samba/vfs/aio_pthread.${SOEXT}
lib/samba/vfs/audit.${SOEXT}
lib/samba/vfs/cap.${SOEXT}
lib/samba/vfs/catia.${SOEXT}
lib/samba/vfs/commit.${SOEXT}
lib/samba/vfs/crossrename.${SOEXT}
lib/samba/vfs/default_quota.${SOEXT}
lib/samba/vfs/dirsort.${SOEXT}
lib/samba/vfs/expand_msdfs.${SOEXT}
lib/samba/vfs/extd_audit.${SOEXT}
lib/samba/vfs/fake_perms.${SOEXT}
lib/samba/vfs/fruit.${SOEXT}
lib/samba/vfs/full_audit.${SOEXT}
lib/samba/vfs/linux_xfs_sgid.${SOEXT}
lib/samba/vfs/media_harmony.${SOEXT}
lib/samba/vfs/offline.${SOEXT}
${PLIST.ads}lib/samba/vfs/posix_eadb.${SOEXT}
lib/samba/vfs/preopen.${SOEXT}
lib/samba/vfs/readahead.${SOEXT}
lib/samba/vfs/readonly.${SOEXT}
lib/samba/vfs/recycle.${SOEXT}
lib/samba/vfs/shadow_copy.${SOEXT}
lib/samba/vfs/shadow_copy2.${SOEXT}
lib/samba/vfs/shell_snap.${SOEXT}
${PLIST.snapper}lib/samba/vfs/snapper.${SOEXT}
lib/samba/vfs/streams_depot.${SOEXT}
lib/samba/vfs/streams_xattr.${SOEXT}
lib/samba/vfs/syncops.${SOEXT}
lib/samba/vfs/time_audit.${SOEXT}
lib/samba/vfs/unityed_media.${SOEXT}
lib/samba/vfs/virusfilter.${SOEXT}
lib/samba/vfs/widelinks.${SOEXT}
lib/samba/vfs/worm.${SOEXT}
lib/samba/vfs/xattr_tdb.${SOEXT}
@


1.59
log
@samba4: updated to 4.21.2

Changes since 4.21.1
--------------------

o  Ralph Boehme <slow@@samba.org>
   * BUG 15732: smbd fails to correctly check sharemode against OVERWRITE
     dispositions.
   * BUG 15754: Panic in close_directory.

o  Pavel Filipenský <pfilipensky@@samba.org>
   * BUG 15752: winexe no longer works with samba 4.21.

o  Stefan Metzmacher <metze@@samba.org>
   * BUG 14356: protocol error - Unclear debug message "pad length mismatch" for
     invalid bind packet.
   * BUG 15425: NetrGetLogonCapabilities QueryLevel 2 needs to be implemented.
   * BUG 15740: gss_accept_sec_context() from Heimdal does not imply
     GSS_C_MUTUAL_FLAG with GSS_C_DCE_STYLE.
   * BUG 15749: winbindd should call process_set_title() for locator child.

o  Martin Schwenke <mschwenke@@ddn.com>
   * BUG 15320: Update CTDB to track all TCP connections to public IP addresses.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.58 2024/10/24 17:23:43 adam Exp $
d783 1
a783 1
${PLIST.ads}lib/samba/ldb/mdb.${SOEXT}
d889 1
a889 1
lib/samba/private/libldb-mdb-int-private-samba.so
@


1.58
log
@samba4: updated to 4.21.1

Changes since 4.21.0

o  Ralph Boehme <slow@@samba.org>
   * BUG 15624: DH reconnect error handling can lead to stale sharemode entries.
   * BUG 15695: "inherit permissions = yes" triggers assert() in vfs_default
     when creating a stream.

o  Alexander Bokovoy <ab@@samba.org>
   * BUG 15715: Samba 4.21.0 broke FreeIPA domain member integration.

o  Andréas Leroux <aleroux@@tranquil.it>
   * BUG 15692: Missing conversion for msDS-UserTGTLifetime, msDS-
     ComputerTGTLifetime and msDS-ServiceTGTLifetime on "samba-tool
     domain auth policy modify".

o  Stefan Metzmacher <metze@@samba.org>
   * BUG 15280: irpc_destructor may crash during shutdown.
   * BUG 15624: DH reconnect error handling can lead to stale sharemode entries.
   * BUG 15649: Durable handle is not granted when a previous OPEN exists with
     NoOplock.
   * BUG 15651: Durable handle is granted but reconnect fails.
   * BUG 15708: Disconnected durable handles with RH lease should not be purged
     by a new non conflicting open.
   * BUG 15714: net ads testjoin and other commands use the wrong secrets.tdb in
     a cluster.
   * BUG 15726: 4.21 using --with-system-mitkrb5 requires MIT krb5 1.16 as rfc
     8009 etypes are used.

o  Christof Schmitt <cs@@samba.org>
   * BUG 15730: VFS_OPEN_HOW_WITH_BACKUP_INTENT breaks shadow_copy2.

o  Andreas Schneider <asn@@samba.org>
   * BUG 15643: Samba 4.20.0 DLZ module crashes BIND on startup.
   * BUG 15721: Cannot build libldb lmdb backend on a build without AD DC.

o  Jones Syue <jonessyue@@qnap.com>
   * BUG 15706: Consistent log level for sighup handler.

4.21.0
https://www.samba.org/samba/history/samba-4.21.0.html
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.57 2024/06/27 09:50:27 adam Exp $
d216 1
@


1.57
log
@samba4: updated to 4.20.2

Changes since 4.20.1
--------------------

o  Jeremy Allison <jra@@samba.org>
   * BUG 15662: vfs_widelinks with DFS shares breaks case insensitivity.

o  Douglas Bagnall <douglas.bagnall@@catalyst.net.nz>
   * BUG 13213: Samba build is not reproducible.
   * BUG 15569: ldb qsort might r/w out of bounds with an intransitive compare
     function.
   * BUG 15625: Many qsort() comparison functions are non-transitive, which can
     lead to out-of-bounds access in some circumstances.

o  Andrew Bartlett <abartlet@@samba.org>
   * BUG 15638: Need to change gitlab-ci.yml tags in all branches to avoid CI
     bill.
   * BUG 15654: We have added new options --vendor-name and --vendor-patch-
     revision arguments to ./configure to allow distributions and packagers to
     put their name in the Samba version string so that when debugging Samba the
     source of the binary is obvious.

o  Günther Deschner <gd@@samba.org>
   * BUG 15665: CTDB RADOS mutex helper misses namespace support.

o  Stefan Metzmacher <metze@@samba.org>
   * BUG 13019: Dynamic DNS updates with the internal DNS are not working.
   * BUG 14981: netr_LogonSamLogonEx returns NR_STATUS_ACCESS_DENIED with
     SysvolReady=0.
   * BUG 15412: Anonymous smb3 signing/encryption should be allowed (similar to
     Windows Server 2022).
   * BUG 15573: Panic in dreplsrv_op_pull_source_apply_changes_trigger.
   * BUG 15620: s4:nbt_server: does not provide unexpected handling, so winbindd
     can't use nmb requests instead cldap.
   * BUG 15642: winbindd, net ads join and other things don't work on an ipv6
     only host.
   * BUG 15659: Segmentation fault when deleting files in vfs_recycle.
   * BUG 15664: Panic in vfs_offload_token_db_fetch_fsp().
   * BUG 15666: "client use kerberos" and --use-kerberos is ignored for the
     machine account.

o  Noel Power <noel.power@@suse.com>
   * BUG 15435: Regression DFS not working with widelinks = true.

o  Andreas Schneider <asn@@samba.org>
   * BUG 15633: samba-gpupdate - Invalid NtVer in netlogon_samlogon_response.
   * BUG 15653: idmap_ad creates an incorrect local krb5.conf in case of trusted
     domain lookups.
   * BUG 15660: The images don't build after the git security release and CentOS
     8 Stream is EOL.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.56 2024/05/08 15:54:54 adam Exp $
d6 6
a52 3
include/credentials.h
include/dcerpc.h
${PLIST.ads}include/dcerpc_server.h
a72 1
include/gen_ndr/ndr_samr_c.h
a91 1
include/param.h
a92 1
include/policy.h
a115 3
include/util/tevent_ntstatus.h
include/util/tevent_unix.h
include/util/tevent_werror.h
a122 3
lib/libdcerpc-samr.so
lib/libdcerpc-samr.so.0
lib/libdcerpc-samr.so.0.0.1
a125 6
${PLIST.ads}lib/libdcerpc-server.so
${PLIST.ads}lib/libdcerpc-server.so.0
${PLIST.ads}lib/libdcerpc-server.so.0.0.1
lib/libdcerpc.so
lib/libdcerpc.so.0
lib/libdcerpc.so.0.0.1
d136 2
a137 2
lib/libndr.so.4
lib/libndr.so.4.0.0
a141 3
lib/libsamba-credentials.so
lib/libsamba-credentials.so.1
lib/libsamba-credentials.so.1.0.0
a144 3
lib/libsamba-hostconfig.so
lib/libsamba-hostconfig.so.0
lib/libsamba-hostconfig.so.0.0.1
d147 1
a147 4
lib/libsamba-passdb.so.0.28.0
lib/libsamba-policy.so
lib/libsamba-policy.so.0
lib/libsamba-policy.so.0.0.1
a150 3
lib/libsamdb.so
lib/libsamdb.so.0
lib/libsamdb.so.0.0.1
a159 3
lib/libtevent-util.so
lib/libtevent-util.so.0
lib/libtevent-util.so.0.0.1
a162 3
lib/pkgconfig/dcerpc.pc
lib/pkgconfig/dcerpc_samr.pc
${PLIST.ads}lib/pkgconfig/dcerpc_server.pc
a167 3
lib/pkgconfig/samba-credentials.pc
lib/pkgconfig/samba-hostconfig.pc
lib/pkgconfig/samba-policy.pc
a168 1
lib/pkgconfig/samdb.pc
d171 2
d236 23
d315 1
d335 10
a344 3
${PYSITELIB}/samba/netcmd/domain/auth/policy.py
${PYSITELIB}/samba/netcmd/domain/auth/silo.py
${PYSITELIB}/samba/netcmd/domain/auth/silo_member.py
d356 2
a360 14
${PYSITELIB}/samba/netcmd/domain/models/__init__.py
${PYSITELIB}/samba/netcmd/domain/models/auth_policy.py
${PYSITELIB}/samba/netcmd/domain/models/auth_silo.py
${PYSITELIB}/samba/netcmd/domain/models/claim_type.py
${PYSITELIB}/samba/netcmd/domain/models/exceptions.py
${PYSITELIB}/samba/netcmd/domain/models/fields.py
${PYSITELIB}/samba/netcmd/domain/models/group.py
${PYSITELIB}/samba/netcmd/domain/models/model.py
${PYSITELIB}/samba/netcmd/domain/models/query.py
${PYSITELIB}/samba/netcmd/domain/models/schema.py
${PYSITELIB}/samba/netcmd/domain/models/site.py
${PYSITELIB}/samba/netcmd/domain/models/subnet.py
${PYSITELIB}/samba/netcmd/domain/models/user.py
${PYSITELIB}/samba/netcmd/domain/models/value_type.py
d384 3
d472 1
a504 1
${PYSITELIB}/samba/tests/dcerpc/createtrustrelax.py
d508 1
d539 2
d575 1
d670 1
d693 1
a737 1
${PYSITELIB}/samba/trust_utils.py
d763 1
d775 1
a775 1
lib/samba/ldb/ildap.${SOEXT}
d778 3
a780 1
lib/samba/ldb/ldbsamba_extensions.${SOEXT}
d782 1
d789 1
d793 1
d802 1
d806 1
d808 1
d811 1
d817 1
a817 1
lib/samba/nss_info/hash.${SOEXT}
d855 1
d858 2
d886 6
d912 1
d917 1
d919 1
d921 1
d923 1
d929 1
d948 1
a950 1
lib/samba/private/libtrusts-util-private-samba.so
d1021 6
d1056 1
@


1.56
log
@samba4: updated to 4.20.1

Changes since 4.20.0

* BUG 15630: dns update debug message is too noisy.
* BUG 15635: Do not fail PAC validation for RFC8009 checksums types.
* BUG 15605: Improve performance of lookup_groupmem() in idmap_ad.
* BUG 15636: Smbcacls incorrectly propagates inheritance with Inherit-Only
  flag.
* BUG 15611: http library doesn't support 'chunked transfer encoding'.
* BUG 15600: Provide a systemd service file for the background queue daemon.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.55 2024/04/15 07:16:38 adam Exp $
d485 1
@


1.55
log
@samba4: updated to 4.20.0

Samba 4.20.0

NEW FEATURES/CHANGES
====================

New Minimum MIT Krb5 version for Samba AD Domain Controller
-----------------------------------------------------------

Samba now requires MIT 1.21 when built against a system MIT Krb5 and
acting as an Active Directory DC.  This addresses the issues that were
fixed in CVE-2022-37967 (KrbtgtFullPacSignature) and ensures that
Samba builds against the MIT version that allows us to avoid that
attack.

Removed dependency on Perl JSON module
--------------------------------------

Distributions are advised that the Perl JSON package is no longer
required by Samba builds that use the imported Heimdal.  The build
instead uses Perl's JSON::PP built into recent perl5 versions.

Current lists of packages required by Samba for major distributions
are found in the bootstrap/generated-dists/ directory of a Samba
source tree.  While there will be some differences - due to features
chosen by packagers - comparing these lists with the build dependencies
in a package may locate other dependencies we no longer require.

samba-tool user getpassword / syncpasswords ;rounds= change
-----------------------------------------------------------

The password access tool "samba-tool user getpassword" and the
password sync tool "samba-tool user syncpasswords" allow attributes to
be chosen for output, and accept parameters like
pwdLastSet;format=GeneralizedTime

These attributes then appear, in the same format, as the attributes in
the LDIF output.  This was not the case for the ;rounds= parameter of
virtualCryptSHA256 and virtualCryptSHA512, for example as
--attributes="virtualCryptSHA256;rounds=50000"

This release makes the behaviour consistent between these two
features.  Installations using GPG-encrypted passwords (or plaintext
storage) and the rounds= option, will find the output has changed

from:
virtualCryptSHA256: {CRYPT}$5$rounds=2561$hXem.M9onhM9Vuix$dFdSBwF

to:
virtualCryptSHA256;rounds=2561: {CRYPT}$5$rounds=2561$hXem.M9onhM9Vuix$dFdSBwF

Group Managed service account client-side features
--------------------------------------------------

samba-tool has been extended to provide client-side support for Group
Managed Service accounts.  These accounts have passwords that change
automatically, giving the advantages of service isolation without risk
of poor, unchanging passwords.

Where possible, Samba's existing samba-tool password handling
commands, which in the past have only operated against the local
sam.ldb have been extended to permit operation against a remote server
with authenticated access to "-H ldap://$DCNAME"

Supported operations include:
 - reading the current and previous gMSA password via
   "samba-tool user getpassword"
 - writing a Kerberos Ticket Granting Ticket (TGT) to a local
   credentials cache with a new command
   "samba-tool user get-kerberos-ticket"

New Windows Search Protocol Client
----------------------------------

Samba now by default builds new experimental Windows Search Protocol (WSP)
command line client "wspsearch"

The "wspsearch" cmd-line utility allows a WSP search request to be sent
to a server (such as a windows server) that has the (WSP)
Windows Search Protocol service configured and enabled.

For more details see the wspsearch man page.

Allow 'smbcacls' to save/restore DACLs to file
--------------------------------------------

'smbcacls' has been extended to allow DACLs to be saved and restored
to/from a file. This feature mimics the functionality that windows cmd
line tool 'icacls.exe' provides. Additionally files created either
by 'smbcalcs' or 'icacls.exe' are interchangeable and can be used by
either tool as the same file format is used.

New options added are:
 - '--save savefile'    Saves DACLs in sddl format to file
 - '--recurse'          Performs the '--save' operation above on directory
                        and all files/directories below.
 - '--restore savefile' Restores the stored DACLS to files in directory

Samba-tool extensions for AD Claims, Authentication Policies and Silos
----------------------------------------------------------------------

samba-tool now allows users to be associated with claims.  In the
Samba AD DC, claims derive from Active Directory attributes mapped
into specific names.  These claims can be used in rules, which are
conditional ACEs in a security descriptor, that decide if a user is
restricted by an authentication policy.

samba-tool also allows the creation and management of authentication
policies, which are rules about where a user may authenticate from,
if NTLM is permitted, and what services a user may authenticate to.

Finally, support is added for the creation and management of
authentication silos, which are helpful in defining network boundaries
by grouping users and the services they connect to.

Please note: The command line syntax for these tools is not final, and
may change before the next release, as we gain user feedback.  The
syntax will be locked in once Samba offers 2016 AD Functional Level as
a default.

AD DC support for Authentication Silos and Authentication Policies
------------------------------------------------------------------

The Samba AD DC now also honours any existing claims, authentication
policy and authentication silo configuration previously created (eg
from an import of a Microsoft AD), as well as new configurations
created with samba-tool.  The use of Microsoft's Powershell based
client tools is not expected to work.

To use this feature, the functional level must be set to 2012_R2 or
later with:

 ad dc functional level = 2016

in the smb.conf.

The smb.conf file on each DC must have 'ad dc functional level = 2016'
set to have the partially complete feature available.  This will also,
at first startup, update the server's own AD entry with the configured
functional level.

For new domains, add these parameters to 'samba-tool provision'

--option="ad dc functional level = 2016" --function-level=2016

The second option, setting the overall domain functional level
indicates that all DCs should be at this functional level.

To raise the domain functional level of an existing domain, after
updating the smb.conf and restarting Samba run
samba-tool domain schemaupgrade --schema=2019
samba-tool domain functionalprep --function-level=2016
samba-tool domain level raise --domain-level=2016 --forest-level=2016

This support is still new, so is not enabled by default in this
release.  The above instructions are set at 2016, which while not
complete, matches what our testing environment validates.

Conditional ACEs and Resource Attribute ACEs
--------------------------------------------

Ordinary Access Control Entries (ACEs) unconditionally allow or deny
access to a given user or group. Conditional ACEs have an additional
section that describes conditions under which the ACE applies. If the
conditional expression is true, the ACE works like an ordinary ACE,
otherwise it is ignored. The condition terms can refer to claims,
group memberships, and attributes on the object itself. These
attributes are described in Resource Attribute ACEs that occur in the
object's System Access Control List (SACL). Conditional ACEs are
described in Microsoft documentation.

Conditional ACE evaluation is controlled by the "acl claims
evaluation" smb.conf option. The default value is "AD DC only" which
enables them in AD DC settings. The other option is "never", which
disables them altogether. There is currently no option to enable them
on the file server (this is likely to change in future releases).

The Security Descriptor Definition Language has extensions for
conditional ACEs and resource attribute ACEs; these are now supported
by Samba.

Service Witness Protocol [MS-SWN]
---------------------------------

In a ctdb cluster it is now possible to provide
the SMB witness service that allows clients to
monitor their current smb connection to cluster
node A by asking cluster node B to notify the
client if the ip address from node A or the
whole node A becomes unavailable.

For disk shares in a ctdb cluster
SMB2_SHARE_CAP_SCALEOUT is now always returned
for SMB3 tree connect responses.

If the witness service is active
SMB2_SHARE_CAP_CLUSTER is now also returned.

In order to activate the witness service
"rpc start on demand helpers = no" needs to
be configured in the global section.
At the same time the 'samba-dcerpcd' service
needs to be started explicitly, typically
with the '--libexec-rpcds' option in order
to make all available services usable.
One important aspect is that tcp ports
135 (for the endpoint mapper) and various
ports in the 'rpc server dynamic port range'
will be used to provide the witness service
(rpcd_witness).

ctdb provides a '47.samba-dcerpcd.script' in order
to manage the samba-dcerpcd.service.
Typically as systemd service, but that's up
to the packager and/or admin.

Please note that current windows client
requires SMB2_SHARE_CAP_CONTINUOUS_AVAILABILITY
in addition to SMB2_SHARE_CAP_CLUSTER in order
to make use of the witness service.
But SMB2_SHARE_CAP_CONTINUOUS_AVAILABILITY implies
the windows clients always ask for persistent handle
(which are not implemented in samba yet), so
that every open generates a warning in the
windows smb client event log.
That's why SMB2_SHARE_CAP_CONTINUOUS_AVAILABILITY
is not returned by default.
An explicit 'smb3 share cap:CONTINUOUS AVAILABILITY = yes'
is needed.

There are also new 'net witness' commands in order
to let the admin list active client registrations
or ask specific clients to move their smb connection
to another cluster node. These are available:

 net witness list
 net witness client-move
 net witness share-move
 net witness force-unregister
 net witness force-response

Consult 'man net' or 'net witness help' for further details.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.54 2023/11/16 16:37:31 dogcow Exp $
d482 2
@


1.54
log
@fix "-ads" option build
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.53 2023/11/15 18:54:43 wiz Exp $
d38 1
d98 1
d148 2
a149 2
lib/libndr.so.3
lib/libndr.so.3.0.1
d177 1
a177 1
lib/libsmbclient.so.0.7.0
d221 1
d231 2
d250 2
d279 1
d285 1
d314 1
d366 1
d368 1
d397 1
d401 26
a426 1
${PYSITELIB}/samba/netcmd/user.py
d429 1
d480 1
d486 1
d492 1
d501 3
d553 1
d574 1
d578 1
d584 1
d595 1
d620 3
a622 1
${PYSITELIB}/samba/tests/ndr.py
a669 1
${PYSITELIB}/samba/tests/samba_tool/domain_auth_base.py
d695 1
d699 2
d702 2
d715 1
d717 1
d733 1
d813 120
a932 120
lib/samba/private/libCHARSET3-samba4.so
${PLIST.ads}lib/samba/private/libHDB-SAMBA4-samba4.so
lib/samba/private/libLIBWBCLIENT-OLD-samba4.so
lib/samba/private/libMESSAGING-SEND-samba4.so
lib/samba/private/libMESSAGING-samba4.so
lib/samba/private/libREG-FULL-samba4.so
lib/samba/private/libRPC-SERVER-LOOP-samba4.so
lib/samba/private/libRPC-WORKER-samba4.so
${PLIST.ads}lib/samba/private/libad-claims-samba4.so
lib/samba/private/libaddns-samba4.so
lib/samba/private/libads-samba4.so
lib/samba/private/libasn1-samba4.so
lib/samba/private/libasn1util-samba4.so
lib/samba/private/libauth-samba4.so
lib/samba/private/libauth-unix-token-samba4.so
lib/samba/private/libauth4-samba4.so
lib/samba/private/libauthkrb5-samba4.so
${PLIST.ads}lib/samba/private/libauthn-policy-util-samba4.so
lib/samba/private/libcli-cldap-samba4.so
lib/samba/private/libcli-ldap-common-samba4.so
lib/samba/private/libcli-ldap-samba4.so
lib/samba/private/libcli-nbt-samba4.so
lib/samba/private/libcli-smb-common-samba4.so
lib/samba/private/libcli-spoolss-samba4.so
lib/samba/private/libcliauth-samba4.so
lib/samba/private/libclidns-samba4.so
lib/samba/private/libcluster-samba4.so
lib/samba/private/libcmdline-contexts-samba4.so
lib/samba/private/libcmdline-samba4.so
lib/samba/private/libcom-err-samba4.so
lib/samba/private/libcommon-auth-samba4.so
${PLIST.ads}lib/samba/private/libdb-glue-samba4.so
lib/samba/private/libdbwrap-samba4.so
lib/samba/private/libdcerpc-pkt-auth-samba4.so
lib/samba/private/libdcerpc-samba-samba4.so
lib/samba/private/libdcerpc-samba4.so
${PLIST.ads}lib/samba/private/libdfs-server-ad-samba4.so
${PLIST.ads}lib/samba/private/libdlz-bind9-for-torture-samba4.so
lib/samba/private/libdnsserver-common-samba4.so
${PLIST.ads}lib/samba/private/libdsdb-garbage-collect-tombstones-samba4.so
lib/samba/private/libdsdb-module-samba4.so
lib/samba/private/libevents-samba4.so
lib/samba/private/libflag-mapping-samba4.so
lib/samba/private/libgenrand-samba4.so
lib/samba/private/libgensec-samba4.so
lib/samba/private/libgpext-samba4.so
lib/samba/private/libgpo-samba4.so
lib/samba/private/libgse-samba4.so
lib/samba/private/libgss-preauth-samba4.so
lib/samba/private/libgssapi-samba4.so
lib/samba/private/libhcrypto-samba4.so
lib/samba/private/libhdb-samba4.so
lib/samba/private/libheimbase-samba4.so
lib/samba/private/libheimntlm-samba4.so
lib/samba/private/libhttp-samba4.so
lib/samba/private/libhx509-samba4.so
lib/samba/private/libidmap-samba4.so
lib/samba/private/libinterfaces-samba4.so
lib/samba/private/libiov-buf-samba4.so
lib/samba/private/libkdc-samba4.so
lib/samba/private/libkrb5-samba4.so
lib/samba/private/libkrb5samba-samba4.so
lib/samba/private/libldbsamba-samba4.so
lib/samba/private/liblibcli-lsa3-samba4.so
lib/samba/private/liblibcli-netlogon3-samba4.so
lib/samba/private/liblibsmb-samba4.so
lib/samba/private/libmessages-dgm-samba4.so
lib/samba/private/libmessages-util-samba4.so
lib/samba/private/libmscat-samba4.so
lib/samba/private/libmsghdr-samba4.so
lib/samba/private/libmsrpc3-samba4.so
lib/samba/private/libndr-samba-samba4.so
lib/samba/private/libndr-samba4.so
lib/samba/private/libnet-keytab-samba4.so
lib/samba/private/libnetif-samba4.so
lib/samba/private/libnpa-tstream-samba4.so
lib/samba/private/libnss-info-samba4.so
${PLIST.ads}lib/samba/private/libpac-samba4.so
lib/samba/private/libposix-eadb-samba4.so
lib/samba/private/libprinter-driver-samba4.so
lib/samba/private/libprinting-migrate-samba4.so
${PLIST.ads}lib/samba/private/libprocess-model-samba4.so
lib/samba/private/libregistry-samba4.so
lib/samba/private/libreplace-samba4.so
lib/samba/private/libroken-samba4.so
lib/samba/private/libsamba-cluster-support-samba4.so
lib/samba/private/libsamba-debug-samba4.so
lib/samba/private/libsamba-modules-samba4.so
lib/samba/private/libsamba-net-samba4.so
lib/samba/private/libsamba-python-samba4.so
lib/samba/private/libsamba-security-samba4.so
lib/samba/private/libsamba-sockets-samba4.so
lib/samba/private/libsamba3-util-samba4.so
lib/samba/private/libsamdb-common-samba4.so
${PLIST.ads}lib/samba/private/libscavenge-dns-records-samba4.so
lib/samba/private/libsecrets3-samba4.so
lib/samba/private/libserver-id-db-samba4.so
lib/samba/private/libserver-role-samba4.so
${PLIST.ads}lib/samba/private/libservice-samba4.so
lib/samba/private/libshares-samba4.so
lib/samba/private/libsmb-transport-samba4.so
lib/samba/private/libsmbclient-raw-samba4.so
lib/samba/private/libsmbd-base-samba4.so
lib/samba/private/libsmbd-shim-samba4.so
${PLIST.ldap}lib/samba/private/libsmbldaphelper-samba4.so
lib/samba/private/libsmbpasswdparser-samba4.so
lib/samba/private/libsocket-blocking-samba4.so
lib/samba/private/libstable-sort-samba4.so
lib/samba/private/libsys-rw-samba4.so
lib/samba/private/libtalloc-report-printf-samba4.so
lib/samba/private/libtalloc-report-samba4.so
lib/samba/private/libtdb-wrap-samba4.so
lib/samba/private/libtime-basic-samba4.so
lib/samba/private/libtorture-samba4.so
lib/samba/private/libtrusts-util-samba4.so
lib/samba/private/libutil-reg-samba4.so
lib/samba/private/libutil-setid-samba4.so
lib/samba/private/libutil-tdb-samba4.so
lib/samba/private/libwind-samba4.so
lib/samba/private/libxattr-tdb-samba4.so
d1026 1
@


1.53
log
@samba: update to 4.19.2.

This is the first stable release of the Samba 4.19 release series.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.52 2023/10/10 16:05:01 taca Exp $
d762 1
a762 1
lib/samba/private/libad-claims-samba4.so
d771 1
a771 1
lib/samba/private/libauthn-policy-util-samba4.so
@


1.52
log
@net/samba4: update to 4.18.8

                   ==============================
                   Release Notes for Samba 4.18.8
                          October 10, 2023
                   ==============================


This is a security release in order to address the following defects:


o CVE-2023-3961:  Unsanitized pipe names allow SMB clients to connect as root to
                  existing unix domain sockets on the file system.
                  https://www.samba.org/samba/security/CVE-2023-3961.html

o CVE-2023-4091:  SMB client can truncate files to 0 bytes by opening files with
                  OVERWRITE disposition when using the acl_xattr Samba VFS
                  module with the smb.conf setting
                  "acl_xattr:ignore system acls = yes"
                  https://www.samba.org/samba/security/CVE-2023-4091.html

o CVE-2023-4154:  An RODC and a user with the GET_CHANGES right can view all
                  attributes, including secrets and passwords.  Additionally,
                  the access check fails open on error conditions.
                  https://www.samba.org/samba/security/CVE-2023-4154.html

o CVE-2023-42669: Calls to the rpcecho server on the AD DC can request that the
                  server block for a user-defined amount of time, denying
                  service.
                  https://www.samba.org/samba/security/CVE-2023-42669.html

o CVE-2023-42670: Samba can be made to start multiple incompatible RPC
                  listeners, disrupting service on the AD DC.
                  https://www.samba.org/samba/security/CVE-2023-42670.html
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.51 2023/04/29 08:01:06 wiz Exp $
d22 1
d147 1
a147 1
lib/libndr.so.3.0.0
d269 1
d272 1
d331 37
a367 2
${PYSITELIB}/samba/netcmd/domain.py
${PYSITELIB}/samba/netcmd/domain_backup.py
d370 1
d373 1
d389 1
d394 1
d524 2
d528 1
d541 1
d563 1
d611 1
d618 5
d762 1
d771 1
d954 1
a969 1
man/man5/smbgetrc.5
d1074 1
d1077 2
d1081 1
@


1.51
log
@samba: update to 4.18.2.

4.18.2

Changes since 4.18.1
--------------------

o  Jeremy Allison <jra@@samba.org>
   * BUG 15302: Log flood: smbd_calculate_access_mask_fsp: Access denied:
     message level should be lower.
   * BUG 15306: Floating point exception (FPE) via cli_pull_send at
     source3/libsmb/clireadwrite.c.

o  Andrew Bartlett <abartlet@@samba.org>
   * BUG 15328: test_tstream_more_tcp_user_timeout_spin fails intermittently on
     Rackspace GitLab runners.
   * BUG 15329: Reduce flapping of ridalloc test.
   * BUG 15351: large_ldap test is unreliable.

o  Ralph Boehme <slow@@samba.org>
   * BUG 15143: New filename parser doesn't check veto files smb.conf parameter.
   * BUG 15354: mdssvc may crash when initializing.

o  Volker Lendecke <vl@@samba.org>
   * BUG 15313: large directory optimization broken for non-lcomp path elements.
   * BUG 15357: streams_depot fails to create streams.
   * BUG 15358: shadow_copy2 and streams_depot don't play well together.

o  Rob van der Linde <rob@@catalyst.net.nz>
   * BUG 15316: Flapping tests in samba_tool_drs_show_repl.py.

o  Stefan Metzmacher <metze@@samba.org>
   * BUG 15317: winbindd idmap child contacts the domain controller without a
     need.
   * BUG 15318: idmap_autorid may fail to map sids of trusted domains for the
     first time.
   * BUG 15319: idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings.
   * BUG 15323: net ads search -P doesn't work against servers in other domains.
   * BUG 15353: Temporary smbXsrv_tcon_global.tdb can't be parsed.

o  Joseph Sutton <josephsutton@@catalyst.net.nz>
   * BUG 15316: Flapping tests in samba_tool_drs_show_repl.py.
   * BUG 15343: Tests use depricated and removed methods like
     assertRegexpMatches.

4.18.1

This is a security release in order to address the following defects:

o CVE-2023-0225: An incomplete access check on dnsHostName allows authenticated
                 but otherwise unprivileged users to delete this attribute from
                 any object in the directory.
                 https://www.samba.org/samba/security/CVE-2023-0225.html

o CVE-2023-0922: The Samba AD DC administration tool, when operating against a
                 remote LDAP server, will by default send new or reset
                 passwords over a signed-only connection.
                 https://www.samba.org/samba/security/CVE-2023-0922.html

o CVE-2023-0614: The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919
                 Confidential attribute disclosure via LDAP filters was
                 insufficient and an attacker may be able to obtain
                 confidential BitLocker recovery keys from a Samba AD DC.
                 Installations with such secrets in their Samba AD should
                 assume they have been obtained and need replacing.
                 https://www.samba.org/samba/security/CVE-2023-0614.html


Changes since 4.18.0
--------------------

o  Douglas Bagnall <douglas.bagnall@@catalyst.net.nz>
   * BUG 15276: CVE-2023-0225.

o  Andrew Bartlett <abartlet@@samba.org>
   * BUG 15270: CVE-2023-0614.
   * BUG 15331: ldb wildcard matching makes excessive allocations.
   * BUG 15332: large_ldap test is inefficient.

o  Rob van der Linde <rob@@catalyst.net.nz>
   * BUG 15315: CVE-2023-0922.

o  Joseph Sutton <josephsutton@@catalyst.net.nz>
   * BUG 15270: CVE-2023-0614.
   * BUG 15276: CVE-2023-0225.

4.18.0

This is the first stable release of the Samba 4.18 release series.
Please read the release notes carefully before upgrading.

NEW FEATURES/CHANGES
====================

SMB Server performance improvements
-----------------------------------

The security improvements in recent releases
(4.13, 4.14, 4.15, 4.16), mainly as protection against symlink races,
caused performance regressions for metadata heavy workloads.

While 4.17 already improved the situation quite a lot,
with 4.18 the locking overhead for contended path based operations
is reduced by an additional factor of ~ 3 compared to 4.17.
It means the throughput of open/close
operations reached the level of 4.12 again.

More succinct samba-tool error messages
---------------------------------------

Historically samba-tool has reported user error or misconfiguration by
means of a Python traceback, showing you where in its code it noticed
something was wrong, but not always exactly what is amiss. Now it
tries harder to identify the true cause and restrict its output to
describing that. Particular cases include:

 * a username or password is incorrect
 * an ldb database filename is wrong (including in smb.conf)
 * samba-tool dns: various zones or records do not exist
 * samba-tool ntacl: certain files are missing
 * the network seems to be down
 * bad --realm or --debug arguments

Accessing the old samba-tool messages
-------------------------------------

This is not new, but users are reminded they can get the full Python
stack trace, along with other noise, by using the argument '-d3'.
This may be useful when searching the web.

The intention is that when samba-tool encounters an unrecognised
problem (especially a bug), it will still output a Python traceback.
If you encounter a problem that has been incorrectly identified by
samba-tool, please report it on https://bugzilla.samba.org.

Colour output with samba-tool --color
-------------------------------------

For some time a few samba-tool commands have had a --color=yes|no|auto
option, which determines whether the command outputs ANSI colour
codes. Now all samba-tool commands support this option, which now also
accepts 'always' and 'force' for 'yes', 'never' and 'none' for 'no',
and 'tty' and 'if-tty' for 'auto' (this more closely matches
convention). With --color=auto, or when --color is omitted, colour
codes are only used when output is directed to a terminal.

Most commands have very little colour in any case. For those that
already used it, the defaults have changed slightly.

 * samba-tool drs showrepl: default is now 'auto', not 'no'

 * samba-tool visualize: the interactions between --color-scheme,
   --color, and --output have changed slightly. When --color-scheme is
   set it overrides --color for the purpose of the output diagram, but
   not for other output like error messages.

New samba-tool dsacl subcommand for deleting ACES
-------------------------------------------------

The samba-tool dsacl tool can now delete entries in directory access
control lists. The interface for 'samba-tool dsacl delete' is similar
to that of 'samba-tool dsacl set', with the difference being that the
ACEs described by the --sddl argument are deleted rather than added.

No colour with NO_COLOR environment variable
--------------------------------------------

With both samba-tool --color=auto (see above) and some other places
where we use ANSI colour codes, the NO_COLOR environment variable will
disable colour output. See https://no-color.org/ for a description of
this variable. `samba-tool --color=always` will use colour regardless
of NO_COLOR.

New wbinfo option --change-secret-at
------------------------------------

The wbinfo command has a new option, --change-secret-at=<DOMAIN CONTROLLER>
which forces the trust account password to be changed at a specified domain
controller. If the specified domain controller cannot be contacted the
password change fails rather than trying other DCs.

New option to change the NT ACL default location
------------------------------------------------

Usually the NT ACLs are stored in the security.NTACL extended
attribute (xattr) of files and directories. The new
"acl_xattr:security_acl_name" option allows to redefine the default
location. The default "security.NTACL" is a protected location, which
means the content of the security.NTACL attribute is not accessible
from normal users outside of Samba. When this option is set to use a
user-defined value, e.g. user.NTACL then any user can potentially
access and overwrite this information. The module prevents access to
this xattr over SMB, but the xattr may still be accessed by other
means (eg local access, SSH, NFS). This option must only be used when
this consequence is clearly understood and when specific precautions
are taken to avoid compromising the ACL content.

Azure Active Directory / Office365 synchronisation improvements
--------------------------------------------------------------

Use of the Azure AD Connect cloud sync tool is now supported for
password hash synchronisation, allowing Samba AD Domains to synchronise
passwords with this popular cloud environment.

REMOVED FEATURES
================


smb.conf changes
================

  Parameter Name                          Description     Default
  --------------                          -----------     -------
  acl_xattr:security_acl_name             New             security.NTACL
  server addresses                        New


CHANGES SINCE 4.18.0rc4
=======================

o  Jeremy Allison <jra@@samba.org>
   * BUG 15314: streams_xattr is creating unexpected locks on folders.

o  Volker Lendecke <vl@@samba.org>
   * BUG 15310: New samba-dcerpc architecture does not scale gracefully.


CHANGES SINCE 4.18.0rc3
=======================

o  Andreas Schneider <asn@@samba.org>
   * BUG 15308: Avoid that tests fail because other tests didn't do cleanup on
     failure.

o  baixiangcpp <baixiangcpp@@gmail.com>
   * BUG 15311: fd_load() function implicitly closes the fd where it should not.


CHANGES SINCE 4.18.0rc2
=======================

o  Jeremy Allison <jra@@samba.org>
   * BUG 15301: Improve file_modtime() and issues around smb3 unix test.

o  Ralph Boehme <slow@@samba.org>
   * BUG 15299: Spotlight doesn't work with latest macOS Ventura.

o  Stefan Metzmacher <metze@@samba.org>
   * BUG 15298: Build failure on solaris with tevent 0.14.0 (and ldb 2.7.0).
     (tevent 0.14.1 and ldb 2.7.1 are already released...)

o  John Mulligan <jmulligan@@redhat.com>
   * BUG 15307: vfs_ceph incorrectly uses fsp_get_io_fd() instead of
     fsp_get_pathref_fd() in close and fstat.

o  Andreas Schneider <asn@@samba.org>
   * BUG 15291: test_chdir_cache.sh doesn't work with SMBD_DONT_LOG_STDOUT=1.
   * BUG 15301: Improve file_modtime() and issues around smb3 unix test.


CHANGES SINCE 4.18.0rc1
=======================

o  Andrew Bartlett <abartlet@@samba.org>
   * BUG 10635: Office365 azure Password Sync not working.

o  Stefan Metzmacher <metze@@samba.org>
   * BUG 15286: auth3_generate_session_info_pac leaks wbcAuthUserInfo.

o  Noel Power <noel.power@@suse.com>
   * BUG 15293: With clustering enabled samba-bgqd can core dump due to use
     after free.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.50 2023/01/10 02:12:40 tnn Exp $
a876 1
libexec/samba/rpcd_rpcecho
@


1.51.4.1
log
@Pullup ticket #6808 - requested by taca
net/samba4: security fix

Revisions pulled up:
- net/samba4/Makefile                                           1.170-1.171
- net/samba4/PLIST                                              1.52
- net/samba4/distinfo                                           1.97-1.98

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Wed Sep 27 12:02:48 UTC 2023

   Modified Files:
   	pkgsrc/net/samba4: Makefile distinfo

   Log Message:
   net/samba4: update to 4.18.7

                     ==============================
                     Release Notes for Samba 4.18.7
                           September 27, 2023
                     ==============================

   This is the latest stable release of the Samba 4.18 release series.

   Changes since 4.18.6
   --------------------

   o  Jeremy Allison <jra@@samba.org>
     * BUG 15419: Weird filename can cause assert to fail in
       openat_pathref_fsp_nosymlink().
     * BUG 15423: use-after-free in aio_del_req_from_fsp during smbd shutdown
       after failed IPC FSCTL_PIPE_TRANSCEIVE.
     * BUG 15432: TREE_CONNECT without SETUP causes smbd to use uninitialized
       pointer.

   o  Andrew Bartlett <abartlet@@samba.org>
     * BUG 15401: Avoid infinite loop in initial user sync with Azure AD Connect.
     * BUG 15407: Samba replication logs show (null) DN.

   o  Ralph Boehme <slow@@samba.org>
     * BUG 15463: macOS mdfind returns only 50 results.

   o  Remi Collet <rcollet@@redhat.com>
     * BUG 14808: smbc_getxattr() return value is incorrect.

   o  Volker Lendecke <vl@@samba.org>
     * BUG 15481: GETREALFILENAME_CACHE can modify incoming new filename with
       previous cache entry value.

   o  Stefan Metzmacher <metze@@samba.org>
     * BUG 15464: libnss_winbind causes memory corruption since samba-4.18,
       impacts sendmail, zabbix, potentially more.

   o  MikeLiu <mikeliu@@qnap.com>
     * BUG 15453: File doesn't show when user doesn't have permission if
       aio_pthread is loaded.

   o  Martin Schwenke <mschwenke@@ddn.com>
     * BUG 15451: ctdb_killtcp fails to work with --enable-pcap and libpcap ≥
       1.9.1.

   o  Joseph Sutton <josephsutton@@catalyst.net.nz>
     * BUG 15476: The KDC in 4.18 (and older) is not able to accept tickets with
       empty claims pac blobs (from Samba 4.19 or Windows).
     * BUG 15477: The heimdal KDC doesn't detect s4u2self correctly when fast is
       in use.

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Tue Oct 10 16:05:01 UTC 2023

   Modified Files:
   	pkgsrc/net/samba4: Makefile PLIST distinfo

   Log Message:
   net/samba4: update to 4.18.8

                     ==============================
                     Release Notes for Samba 4.18.8
                            October 10, 2023
                     ==============================

   This is a security release in order to address the following defects:

   o CVE-2023-3961:  Unsanitized pipe names allow SMB clients to connect as root to
                    existing unix domain sockets on the file system.
                    https://www.samba.org/samba/security/CVE-2023-3961.html

   o CVE-2023-4091:  SMB client can truncate files to 0 bytes by opening files with
                    OVERWRITE disposition when using the acl_xattr Samba VFS
                    module with the smb.conf setting
                    "acl_xattr:ignore system acls = yes"
                    https://www.samba.org/samba/security/CVE-2023-4091.html

   o CVE-2023-4154:  An RODC and a user with the GET_CHANGES right can view all
                    attributes, including secrets and passwords.  Additionally,
                    the access check fails open on error conditions.
                    https://www.samba.org/samba/security/CVE-2023-4154.html

   o CVE-2023-42669: Calls to the rpcecho server on the AD DC can request that the
                    server block for a user-defined amount of time, denying
                    service.
                    https://www.samba.org/samba/security/CVE-2023-42669.html

   o CVE-2023-42670: Samba can be made to start multiple incompatible RPC
                    listeners, disrupting service on the AD DC.
                    https://www.samba.org/samba/security/CVE-2023-42670.html
@
text
@d1 1
a1 1
@@comment $NetBSD$
d877 1
@


1.50
log
@samba4: fix PLIST error when option ads is off
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.49 2023/01/03 15:27:23 wiz Exp $
a36 2
@@pkgdir bind-dns
@@pkgdir etc/samba
d52 1
d186 1
a186 1
lib/libwbclient.so.0.15
d209 1
d217 1
d363 2
d416 1
d482 1
d486 1
d517 1
d555 1
d562 1
d611 3
d806 1
d1015 2
d1018 1
@


1.49
log
@samba: update to 4.17.4.

This is the latest stable release of the Samba 4.17 release series.
It also contains security changes in order to address the following defects:


o CVE-2022-37966: This is the Samba CVE for the Windows Kerberos
                  RC4-HMAC Elevation of Privilege Vulnerability
                  disclosed by Microsoft on Nov 8 2022.

                  A Samba Active Directory DC will issue weak rc4-hmac
                  session keys for use between modern clients and servers
                  despite all modern Kerberos implementations supporting
                  the aes256-cts-hmac-sha1-96 cipher.

                  On Samba Active Directory DCs and members
                  'kerberos encryption types = legacy' would force
                  rc4-hmac as a client even if the server supports
                  aes128-cts-hmac-sha1-96 and/or aes256-cts-hmac-sha1-96.

                  https://www.samba.org/samba/security/CVE-2022-37966.html

o CVE-2022-37967: This is the Samba CVE for the Windows
                  Kerberos Elevation of Privilege Vulnerability
                  disclosed by Microsoft on Nov 8 2022.

                  A service account with the special constrained
                  delegation permission could forge a more powerful
                  ticket than the one it was presented with.

                  https://www.samba.org/samba/security/CVE-2022-37967.html

o CVE-2022-38023: The "RC4" protection of the NetLogon Secure channel uses the
                  same algorithms as rc4-hmac cryptography in Kerberos,
                  and so must also be assumed to be weak.

                  https://www.samba.org/samba/security/CVE-2022-38023.html

Note that there are several important behavior changes
included in this release, which may cause compatibility problems
interacting with system still expecting the former behavior.
Please read the advisories of CVE-2022-37966,
CVE-2022-37967 and CVE-2022-38023 carefully!

samba-tool got a new 'domain trust modify' subcommand
-----------------------------------------------------

This allows "msDS-SupportedEncryptionTypes" to be changed
on trustedDomain objects. Even against remote DCs (including Windows)
using the --local-dc-ipaddress= (and other --local-dc-* options).
See 'samba-tool domain trust modify --help' for further details.

smb.conf changes
----------------

  Parameter Name                               Description             Default
  --------------                               -----------             -------
  allow nt4 crypto                             Deprecated              no
  allow nt4 crypto:COMPUTERACCOUNT             New
  kdc default domain supported enctypes        New (see manpage)
  kdc supported enctypes                       New (see manpage)
  kdc force enable rc4 weak session keys       New                     No
  reject md5 clients                           New Default, Deprecated Yes
  reject md5 servers                           New Default, Deprecated Yes
  server schannel                              Deprecated              Yes
  server schannel require seal                 New, Deprecated         Yes
  server schannel require seal:COMPUTERACCOUNT New
  winbind sealed pipes                         Deprecated              Yes

Changes since 4.17.3
--------------------

o  Jeremy Allison <jra@@samba.org>
   * BUG 15224: pam_winbind uses time_t and pointers assuming they are of the
     same size.

o  Andrew Bartlett <abartlet@@samba.org>
   * BUG 14929: CVE-2022-44640 [SECURITY] Upstream Heimdal free of
     user-controlled pointer in FAST.
   * BUG 15219: Heimdal session key selection in AS-REQ examines wrong entry.
   * BUG 15237: CVE-2022-37966.
   * BUG 15258: filter-subunit is inefficient with large numbers of knownfails.

o  Ralph Boehme <slow@@samba.org>
   * BUG 15240: CVE-2022-38023.
   * BUG 15252: smbd allows setting FILE_ATTRIBUTE_TEMPORARY on directories.

o  Stefan Metzmacher <metze@@samba.org>
   * BUG 13135: The KDC logic arround msDs-supportedEncryptionTypes differs from
     Windows.
   * BUG 14611: CVE-2021-20251 [SECURITY] Bad password count not incremented
     atomically.
   * BUG 15203: CVE-2022-42898 [SECURITY] krb5_pac_parse() buffer parsing
     vulnerability.
   * BUG 15206: libnet: change_password() doesn't work with
     dcerpc_samr_ChangePasswordUser4().
   * BUG 15219: Heimdal session key selection in AS-REQ examines wrong entry.
   * BUG 15230: Memory leak in snprintf replacement functions.
   * BUG 15237: CVE-2022-37966.
   * BUG 15240: CVE-2022-38023.
   * BUG 15253: RODC doesn't reset badPwdCount reliable via an RWDC
     (CVE-2021-20251 regression).

o  Noel Power <noel.power@@suse.com>
   * BUG 15224: pam_winbind uses time_t and pointers assuming they are of the
     same size.

o  Anoop C S <anoopcs@@samba.org>
   * BUG 15198: Prevent EBADF errors with vfs_glusterfs.

o  Andreas Schneider <asn@@samba.org>
   * BUG 15237: CVE-2022-37966.
   * BUG 15243: %U for include directive doesn't work for share listing
     (netshareenum).
   * BUG 15257: Stack smashing in net offlinejoin requestodj.

o  Joseph Sutton <josephsutton@@catalyst.net.nz>
   * BUG 15197: Windows 11 22H2 and Samba-AD 4.15 Kerberos login issue.
   * BUG 15219: Heimdal session key selection in AS-REQ examines wrong entry.
   * BUG 15231: CVE-2022-37967.
   * BUG 15237: CVE-2022-37966.

o  Nicolas Williams <nico@@twosigma.com>
   * BUG 14929: CVE-2022-44640 [SECURITY] Upstream Heimdal free of
     user-controlled pointer in FAST.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.48 2022/11/29 13:20:23 jperkin Exp $
d699 1
a699 1
${PLIST.ads}lib/samba/private/libasn1-samba4.so
d716 1
a716 1
${PLIST.ads}lib/samba/private/libcom-err-samba4.so
d735 6
a740 6
${PLIST.ads}lib/samba/private/libgss-preauth-samba4.so
${PLIST.ads}lib/samba/private/libgssapi-samba4.so
${PLIST.ads}lib/samba/private/libhcrypto-samba4.so
${PLIST.ads}lib/samba/private/libhdb-samba4.so
${PLIST.ads}lib/samba/private/libheimbase-samba4.so
${PLIST.ads}lib/samba/private/libheimntlm-samba4.so
d742 1
a742 1
${PLIST.ads}lib/samba/private/libhx509-samba4.so
d746 2
a747 2
${PLIST.ads}lib/samba/private/libkdc-samba4.so
${PLIST.ads}lib/samba/private/libkrb5-samba4.so
d771 1
a771 1
${PLIST.ads}lib/samba/private/libroken-samba4.so
d804 1
a804 1
${PLIST.ads}lib/samba/private/libwind-samba4.so
@


1.48
log
@samba4: Build krb5.so module statically.

Avoids issues when building on systems that have a native libkrb5.so.  Samba
libraries that try to link against krb5.so, which during the build phase is
named libgensec_module_krb5.so, end up with incorrect library dependencies,
likely due to wrapper interactions.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.47 2022/10/25 07:46:11 wiz Exp $
d479 1
a1081 3
@@pkgdir var/db/samba4/private
@@pkgdir var/log
@@pkgdir var/run
@


1.48.2.1
log
@Pullup ticket #6728 - requested by taca
net/samba4: security update

Revisions pulled up:
- net/samba4/Makefile                                           1.155,1.157-1.159
- net/samba4/PLIST                                              1.49-1.50
- net/samba4/distinfo                                           1.88-1.89
- net/samba4/options.mk                                         1.18

-------------------------------------------------------------------
   Module Name:	pkgsrc
   Committed By:	wiz
   Date:		Tue Jan  3 15:27:23 UTC 2023

   Modified Files:
   	pkgsrc/net/samba4: Makefile PLIST distinfo options.mk

   Log Message:
   samba: update to 4.17.4.

   This is the latest stable release of the Samba 4.17 release series.
   It also contains security changes in order to address the following defects:

   o CVE-2022-37966: This is the Samba CVE for the Windows Kerberos
                     RC4-HMAC Elevation of Privilege Vulnerability
                     disclosed by Microsoft on Nov 8 2022.

                     A Samba Active Directory DC will issue weak rc4-hmac
                     session keys for use between modern clients and servers
                     despite all modern Kerberos implementations supporting
                     the aes256-cts-hmac-sha1-96 cipher.

                     On Samba Active Directory DCs and members
                     'kerberos encryption types = legacy' would force
                     rc4-hmac as a client even if the server supports
                     aes128-cts-hmac-sha1-96 and/or aes256-cts-hmac-sha1-96.

                     https://www.samba.org/samba/security/CVE-2022-37966.html

   o CVE-2022-37967: This is the Samba CVE for the Windows
                     Kerberos Elevation of Privilege Vulnerability
                     disclosed by Microsoft on Nov 8 2022.

                     A service account with the special constrained
                     delegation permission could forge a more powerful
                     ticket than the one it was presented with.

                     https://www.samba.org/samba/security/CVE-2022-37967.html

   o CVE-2022-38023: The "RC4" protection of the NetLogon Secure channel uses the
                     same algorithms as rc4-hmac cryptography in Kerberos,
                     and so must also be assumed to be weak.

                     https://www.samba.org/samba/security/CVE-2022-38023.html

   Note that there are several important behavior changes
   included in this release, which may cause compatibility problems
   interacting with system still expecting the former behavior.
   Please read the advisories of CVE-2022-37966,
   CVE-2022-37967 and CVE-2022-38023 carefully!

   samba-tool got a new 'domain trust modify' subcommand
   -----------------------------------------------------

   This allows "msDS-SupportedEncryptionTypes" to be changed
   on trustedDomain objects. Even against remote DCs (including Windows)
   using the --local-dc-ipaddress= (and other --local-dc-* options).
   See 'samba-tool domain trust modify --help' for further details.

   smb.conf changes
   ----------------

     Parameter Name                               Description             Default
     --------------                               -----------             -------
     allow nt4 crypto                             Deprecated              no
     allow nt4 crypto:COMPUTERACCOUNT             New
     kdc default domain supported enctypes        New (see manpage)
     kdc supported enctypes                       New (see manpage)
     kdc force enable rc4 weak session keys       New                     No
     reject md5 clients                           New Default, Deprecated Yes
     reject md5 servers                           New Default, Deprecated Yes
     server schannel                              Deprecated              Yes
     server schannel require seal                 New, Deprecated         Yes
     server schannel require seal:COMPUTERACCOUNT New
     winbind sealed pipes                         Deprecated              Yes

   Changes since 4.17.3
   --------------------

   o  Jeremy Allison <jra@@samba.org>
      * BUG 15224: pam_winbind uses time_t and pointers assuming they are of the
        same size.

   o  Andrew Bartlett <abartlet@@samba.org>
      * BUG 14929: CVE-2022-44640 [SECURITY] Upstream Heimdal free of
        user-controlled pointer in FAST.
      * BUG 15219: Heimdal session key selection in AS-REQ examines wrong entry.
      * BUG 15237: CVE-2022-37966.
      * BUG 15258: filter-subunit is inefficient with large numbers of knownfails.

   o  Ralph Boehme <slow@@samba.org>
      * BUG 15240: CVE-2022-38023.
      * BUG 15252: smbd allows setting FILE_ATTRIBUTE_TEMPORARY on directories.

   o  Stefan Metzmacher <metze@@samba.org>
      * BUG 13135: The KDC logic arround msDs-supportedEncryptionTypes differs from
        Windows.
      * BUG 14611: CVE-2021-20251 [SECURITY] Bad password count not incremented
        atomically.
      * BUG 15203: CVE-2022-42898 [SECURITY] krb5_pac_parse() buffer parsing
        vulnerability.
      * BUG 15206: libnet: change_password() doesn't work with
        dcerpc_samr_ChangePasswordUser4().
      * BUG 15219: Heimdal session key selection in AS-REQ examines wrong entry.
      * BUG 15230: Memory leak in snprintf replacement functions.
      * BUG 15237: CVE-2022-37966.
      * BUG 15240: CVE-2022-38023.
      * BUG 15253: RODC doesn't reset badPwdCount reliable via an RWDC
        (CVE-2021-20251 regression).

   o  Noel Power <noel.power@@suse.com>
      * BUG 15224: pam_winbind uses time_t and pointers assuming they are of the
        same size.

   o  Anoop C S <anoopcs@@samba.org>
      * BUG 15198: Prevent EBADF errors with vfs_glusterfs.

   o  Andreas Schneider <asn@@samba.org>
      * BUG 15237: CVE-2022-37966.
      * BUG 15243: %U for include directive doesn't work for share listing
        (netshareenum).
      * BUG 15257: Stack smashing in net offlinejoin requestodj.

   o  Joseph Sutton <josephsutton@@catalyst.net.nz>
      * BUG 15197: Windows 11 22H2 and Samba-AD 4.15 Kerberos login issue.
      * BUG 15219: Heimdal session key selection in AS-REQ examines wrong entry.
      * BUG 15231: CVE-2022-37967.
      * BUG 15237: CVE-2022-37966.

   o  Nicolas Williams <nico@@twosigma.com>
      * BUG 14929: CVE-2022-44640 [SECURITY] Upstream Heimdal free of
        user-controlled pointer in FAST.


   To generate a diff of this commit:
   cvs rdiff -u -r1.154 -r1.155 pkgsrc/net/samba4/Makefile
   cvs rdiff -u -r1.48 -r1.49 pkgsrc/net/samba4/PLIST
   cvs rdiff -u -r1.87 -r1.88 pkgsrc/net/samba4/distinfo
   cvs rdiff -u -r1.17 -r1.18 pkgsrc/net/samba4/options.mk

-------------------------------------------------------------------
   Module Name:	pkgsrc
   Committed By:	tnn
   Date:		Tue Jan 10 02:12:40 UTC 2023

   Modified Files:
   	pkgsrc/net/samba4: PLIST

   Log Message:
   samba4: fix PLIST error when option ads is off


   To generate a diff of this commit:
   cvs rdiff -u -r1.49 -r1.50 pkgsrc/net/samba4/PLIST

-------------------------------------------------------------------
   Module Name:	pkgsrc
   Committed By:	hauke
   Date:		Thu Jan 19 16:32:54 UTC 2023

   Modified Files:
   	pkgsrc/net/samba4: Makefile

   Log Message:
   Un-break FreeBSD build - it does not define ENODATA.

   See also this thread
   <https://mail-index.netbsd.org/tech-kern/2012/04/30/msg013090.html>.


   To generate a diff of this commit:
   cvs rdiff -u -r1.156 -r1.157 pkgsrc/net/samba4/Makefile

-------------------------------------------------------------------
   Module Name:	pkgsrc
   Committed By:	wiz
   Date:		Mon Jan 23 09:13:52 UTC 2023

   Modified Files:
   	pkgsrc/net/samba4: Makefile

   Log Message:
   samba4: add upper bound for ldb and remove reference to non-existent file


   To generate a diff of this commit:
   cvs rdiff -u -r1.157 -r1.158 pkgsrc/net/samba4/Makefile

-------------------------------------------------------------------
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Sat Jan 28 13:52:03 UTC 2023

   Modified Files:
   	pkgsrc/net/samba4: Makefile distinfo

   Log Message:
   net/samba4: update to 4.17.5

                      ===============
                      Release Notes for Samba 4.17.5
                             January 26, 2023
                      ===============

   This is the latest stable release of the Samba 4.17 release series.

   Changes since 4.17.4
   --------------------

   o  Jeremy Allison <jra@@samba.org>
      * BUG 14808: smbc_getxattr() return value is incorrect.
      * BUG 15172: Compound SMB2 FLUSH+CLOSE requests from MacOSX are not handled
        correctly.
      * BUG 15210: synthetic_pathref AFP_AfpInfo failed errors.
      * BUG 15226: samba-tool gpo listall fails IPv6 only - finddcs() fails to find
        DC when there is only an AAAA record for the DC in DNS.
      * BUG 15236: smbd crashes if an FSCTL request is done on a stream handle.
      * BUG 15277: DFS links don't work anymore on Mac clients since 4.17.
      * BUG 15283: vfs_virusfilter segfault on access, directory edgecase
        (accessing NULL value).

   o  Samuel Cabrero <scabrero@@samba.org>
      * BUG 15240: CVE-2022-38023 [SECURITY] Samba should refuse RC4 (aka md5)
        based SChannel on NETLOGON (additional changes).

   o  Volker Lendecke <vl@@samba.org>
      * BUG 15243: %U for include directive doesn't work for share listing
        (netshareenum).
      * BUG 15266: Shares missing from netshareenum response in samba 4.17.4.
      * BUG 15269: ctdb: use-after-free in run_proc.

   o  Stefan Metzmacher <metze@@samba.org>
      * BUG 15243: %U for include directive doesn't work for share listing
        (netshareenum).
      * BUG 15266: Shares missing from netshareenum response in samba 4.17.4.
      * BUG 15280: irpc_destructor may crash during shutdown.
      * BUG 15286: auth3_generate_session_info_pac leaks wbcAuthUserInfo.

   o  Andreas Schneider <asn@@samba.org>
      * BUG 15268: smbclient segfaults with use after free on an optimized build.

   o  Jones Syue <jonessyue@@qnap.com>
      * BUG 15282: smbstatus leaking files in msg.sock and msg.lock.

   o  Andrew Walker <awalker@@ixsystems.com>
      * BUG 15164: Leak in wbcCtxPingDc2.
      * BUG 15265: Access based share enum does not work in Samba 4.16+.
      * BUG 15267: Crash during share enumeration.
      * BUG 15271: rep_listxattr on FreeBSD does not properly check for reads off
        end of returned buffer.

   o  Florian Weimer <fweimer@@redhat.com>
      * BUG 15281: Avoid relying on C89 features in a few places.


   To generate a diff of this commit:
   cvs rdiff -u -r1.158 -r1.159 pkgsrc/net/samba4/Makefile
   cvs rdiff -u -r1.88 -r1.89 pkgsrc/net/samba4/distinfo
@
text
@d1 1
a1 1
@@comment $NetBSD$
a478 1
${PYSITELIB}/samba/tests/krb5/etype_tests.py
d698 1
a698 1
lib/samba/private/libasn1-samba4.so
d715 1
a715 1
lib/samba/private/libcom-err-samba4.so
d734 6
a739 6
lib/samba/private/libgss-preauth-samba4.so
lib/samba/private/libgssapi-samba4.so
lib/samba/private/libhcrypto-samba4.so
lib/samba/private/libhdb-samba4.so
lib/samba/private/libheimbase-samba4.so
lib/samba/private/libheimntlm-samba4.so
d741 1
a741 1
lib/samba/private/libhx509-samba4.so
d745 2
a746 2
lib/samba/private/libkdc-samba4.so
lib/samba/private/libkrb5-samba4.so
d770 1
a770 1
lib/samba/private/libroken-samba4.so
d803 1
a803 1
lib/samba/private/libwind-samba4.so
d1081 3
@


1.47
log
@samba: update to 4.17.1.

Changes since 4.17.0
--------------------

o  Jeremy Allison <jra@@samba.org>
   * BUG 14611: CVE-2021-20251 [SECURITY] Bad password count not incremented
     atomically.
   * BUG 15174: smbXsrv_connection_shutdown_send result leaked.
   * BUG 15182: Flush on a named stream never completes.
   * BUG 15195: Permission denied calling SMBC_getatr when file not exists.

o  Douglas Bagnall <douglas.bagnall@@catalyst.net.nz>
   * BUG 15189: Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later
     over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC.
   * BUG 15191: pytest: add file removal helpers for TestCaseInTempDir.

o  Andrew Bartlett <abartlet@@samba.org>
   * BUG 14611: CVE-2021-20251 [SECURITY] Bad password count not incremented
     atomically.
   * BUG 15189: Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later.
     over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC.

o  Ralph Boehme <slow@@samba.org>
   * BUG 15182: Flush on a named stream never completes.

o  Volker Lendecke <vl@@samba.org>
   * BUG 15151: vfs_gpfs silently garbles timestamps > year 2106.

o  Gary Lockyer <gary@@catalyst.net.nz>
   * BUG 14611: CVE-2021-20251 [SECURITY] Bad password count not incremented
     atomically.

o  Stefan Metzmacher <metze@@samba.org>
   * BUG 15200: multi-channel socket passing may hit a race if one of the
     involved processes already existed.
   * BUG 15201: memory leak on temporary of struct imessaging_post_state and
     struct tevent_immediate on struct imessaging_context (in
     rpcd_spoolss and maybe others).

o  Noel Power <noel.power@@suse.com>
   * BUG 15205: Since popt1.19 various use after free errors using result of
     poptGetArg are now exposed.

o  Anoop C S <anoopcs@@samba.org>
   * BUG 15192: Remove special case for O_CREAT in SMB_VFS_OPENAT from
     vfs_glusterfs.

o  Andreas Schneider <asn@@samba.org>
   * BUG 15169: GETPWSID in memory cache grows indefinetly with each NTLM auth.

o  Joseph Sutton <josephsutton@@catalyst.net.nz>
   * BUG 14611: CVE-2021-20251 [SECURITY] Bad password count not incremented
     atomically.

                   ==============================
                   Release Notes for Samba 4.17.0
                         September 13, 2022
                   ==============================


This is the first stable release of the Samba 4.17 release series.
Please read the release notes carefully before upgrading.


NEW FEATURES/CHANGES
====================

SMB Server performance improvements
-----------------------------------

The security improvements in recent releases
(4.13, 4.14, 4.15, 4.16), mainly as protection against symlink races,
caused performance regressions for meta data heavy workloads.

With 4.17 the situation improved a lot again:

- Pathnames given by a client are devided into dirname and basename.
  The amount of syscalls to validate dirnames is reduced to 2 syscalls
  (openat, close) per component. On modern Linux kernels (>= 5.6) smbd
  makes use of the openat2() syscall with RESOLVE_NO_SYMLINKS,
  in order to just use 2 syscalls (openat2, close) for the whole dirname.

- Contended path based operations used to generate a lot of unsolicited
  wakeup events causing thundering herd problems, which lead to masive
  latencies for some clients. These events are now avoided in order
  to provide stable latencies and much higher throughput of open/close
  operations.

Configure without the SMB1 Server
---------------------------------

It is now possible to configure Samba without support for
the SMB1 protocol in smbd. This can be selected at configure
time with either of the options:

--with-smb1-server
--without-smb1-server

By default (without either of these options set) Samba
is configured to include SMB1 support (i.e. --with-smb1-server
is the default). When Samba is configured without SMB1 support,
none of the SMB1 code is included inside smbd except the minimal
stub code needed to allow a client to connect as SMB1 and immediately
negotiate the selected protocol into SMB2 (as a Windows server also
allows).

None of the SMB1-only smb.conf parameters are removed when
configured without SMB1, but these parameters are ignored by
the smbd server. This allows deployment without having to change
an existing smb.conf file.

This option allows sites, OEMs and integrators to configure Samba
to remove the old and insecure SMB1 protocol from their products.

Note that the Samba client libraries still support SMB1 connections
even when Samba is configured as --without-smb1-server. This is
to ensure maximum compatibility with environments containing old
SMB1 servers.

Bronze bit and S4U support now also with MIT Kerberos 1.20
----------------------------------------------------------

In 2020 Microsoft Security Response Team received another Kerberos-related
report. Eventually, that led to a security update of the CVE-2020-17049,
Kerberos KDC Security Feature Bypass Vulnerability, also known as a ‘Bronze
Bit’. With this vulnerability, a compromised service that is configured to use
Kerberos constrained delegation feature could tamper with a service ticket that
is not valid for delegation to force the KDC to accept it.

With the release of MIT Kerberos 1.20, Samba AD DC is able able to mitigate the
‘Bronze Bit’ attack. MIT Kerberos KDC's KDB (Kerberos Database Driver) API was
changed to allow passing more details between KDC and KDB components. When built
against MIT Kerberos, Samba AD DC supports MIT Kerberos 1.19 and 1.20 versions
but 'Bronze Bit' mitigation is provided only with MIT Kerberos 1.20.

In addition to fixing the ‘Bronze Bit’ issue, Samba AD DC now fully supports
S4U2Self and S4U2Proxy Kerberos extensions.

Note the default (Heimdal-based) KDC was already fixed in 2021,
see https://bugzilla.samba.org/show_bug.cgi?id=14642

Resource Based Constrained Delegation (RBCD) support
----------------------------------------------------

Samba AD DC built with MIT Kerberos 1.20 offers RBCD support now. With MIT
Kerberos 1.20 we have complete RBCD support passing Sambas S4U testsuite.

samba-tool delegation got the 'add-principal' and 'del-principal' subcommands
in order to manage RBCD.

To complete RBCD support and make it useful to Administrators we added the
Asserted Identity [1] SID into the PAC for constrained delegation. This is
available for Samba AD compiled with MIT Kerberos 1.20.

Note the default (Heimdal-based) KDC does not support RBCD yet.

[1] https://docs.microsoft.com/en-us/windows-server/security/kerberos/kerberos-constrained-delegation-overview

Customizable DNS listening port
-------------------------------

It is now possible to set a custom listening port for the builtin DNS service,
making easy to host another DNS on the same system that would bind to the
default port and forward the domain-specific queries to Samba using the custom
port. This is the opposite configuration of setting a forwarder in Samba.

It makes possible to use another DNS server as a front and forward to Samba.

Dynamic DNS updates may not be proxied by the front DNS server when forwarding
to Samba. Dynamic DNS update proxying depends on the features of the other DNS
server used as a front.

CTDB changes
------------

* When Samba is configured with both --with-cluster-support and
  --systemd-install-services then a systemd service file for CTDB will
  be installed.

* ctdbd_wrapper has been removed.  ctdbd is now started directly from
  a systemd service file or init script.

* The syntax for the ctdb.tunables configuration file has been
  relaxed.  However, trailing garbage after the value, including
  comments, is no longer permitted.  Please see ctdb-tunables(7) for
  more details.

Operation without the (unsalted) NT password hash
-------------------------------------------------

When Samba is configured with 'nt hash store = never' then Samba will
no longer store the (unsalted) NT password hash for users in Active
Directory.  (Trust accounts, like computers, domain controllers and
inter-domain trusts are not impacted).

In the next version of Samba the default for 'nt hash store' will
change from 'always' to 'auto', where it will follow (behave as 'nt
hash store = never' when 'ntlm auth = disabled' is set.

Security-focused deployments of Samba that have eliminated NTLM from
their networks will find setting 'ntlm auth = disabled' with 'nt hash
store = always' as a useful way to improve compliance with
best-practice guidance on password storage (which is to always use an
interated hash).

Note that when 'nt hash store = never' is set, then arcfour-hmac-md5
Kerberos keys will not be available for users who subsequently change
their password, as these keys derive their values from NT hashes.  AES
keys are stored by default for all deployments of Samba with Domain
Functional Level 2008 or later, are supported by all modern clients,
and are much more secure.

Finally, also note that password history in Active Directory is stored
in nTPwdHistory using a series of NT hash values.  Therefore the full
password history feature is not available in this mode.

To provide some protection against password re-use previous Kerberos
hash values (the current, old and older values are already stored) are
used, providing a history length of 3.

There is one small limitation of this workaround: Changing the
sAMAccountName, userAccountControl or userPrincipalName of an account
can cause the Kerberos password salt to change.  This means that after
*both* an account rename and a password change, only the current
password will be recognised for password history purposes.

Python API for smbconf
----------------------

Samba's smbconf library provides a generic frontend to various
configuration backends (plain text file, registry) as a C library. A
new Python wrapper, importable as 'samba.smbconf' is available.  An
additional module, 'samba.samba3.smbconf', is also available to enable
registry backend support. These libraries allow Python programs to
read, and optionally write, Samba configuration natively.

JSON support for smbstatus
--------------------------

It is now possible to print detailed information in JSON format in
the smbstatus program using the new option --json. The JSON output
covers all the existing text output including sessions, connections,
open files, byte-range locks, notifies and profile data with all
low-level information maintained by Samba in the respective databases.

Protected Users security group
------------------------------

Samba AD DC now includes support for the Protected Users security
group introduced in Windows Server 2012 R2. The feature reduces the
attack surface of user accounts by preventing the use of weak
encryption types. It also mitigates the effects of credential theft by
limiting credential lifetime and scope.

The protections are intended for user accounts only, and service or
computer accounts should not be added to the Protected Users
group. User accounts added to the group are granted the following
security protections:

   * NTLM authentication is disabled.
   * Kerberos ticket-granting tickets (TGTs) encrypted with RC4 are
     not issued to or accepted from affected principals. Tickets
     encrypted with AES, and service tickets encrypted with RC4, are
     not affected by this restriction.
   * The lifetime of Kerberos TGTs is restricted to a maximum of four
     hours.
   * Kerberos constrained and unconstrained delegation is disabled.

If the Protected Users group is not already present in the domain, it
can be created with 'samba-tool group add'. The new '--special'
parameter must be specified, with 'Protected Users' as the name of the
group. An example command invocation is:

samba-tool group add 'Protected Users' --special

or against a remote server:

samba-tool group add 'Protected Users' --special -H ldap://dc1.example.com -U Administrator

The Protected Users group is identified in the domain by its having a
RID of 525. Thus, it should only be created with samba-tool and the
'--special' parameter, as above, so that it has the required RID
to function correctly.


REMOVED FEATURES
================

LanMan Authentication and password storage removed from the AD DC
-----------------------------------------------------------------

The storage and authentication with LanMan passwords has been entirely
removed from the Samba AD DC, even when "lanman auth = yes" is set.


smb.conf changes
================

  Parameter Name                          Description     Default
  --------------                          -----------     -------
  dns port                                New default     53
  fruit:zero_file_id                      New default     yes
  nt hash store                           New parameter   always
  smb1 unix extensions                    Replaces "unix extensions"
  volume serial number                    New parameter   -1
  winbind debug traceid                   New parameter   no
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.46 2022/08/09 17:56:09 adam Exp $
a627 1
${PLIST.ads}lib/samba/gensec/krb5.${SOEXT}
@


1.46
log
@samba4: updated to 4.16.4

Release Notes for Samba 4.16.4

This is a security release in order to address the following defects:

o CVE-2022-2031:  Samba AD users can bypass certain restrictions associated with
                  changing passwords.
                  https://www.samba.org/samba/security/CVE-2022-2031.html

o CVE-2022-32744: Samba AD users can forge password change requests for any user.
                  https://www.samba.org/samba/security/CVE-2022-32744.html

o CVE-2022-32745: Samba AD users can crash the server process with an LDAP add
                  or modify request.
                  https://www.samba.org/samba/security/CVE-2022-32745.html

o CVE-2022-32746: Samba AD users can induce a use-after-free in the server
                  process with an LDAP add or modify request.
                  https://www.samba.org/samba/security/CVE-2022-32746.html

o CVE-2022-32742: Server memory information leak via SMB1.
                  https://www.samba.org/samba/security/CVE-2022-32742.html
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.45 2022/07/29 20:33:38 jperkin Exp $
d146 2
a147 2
lib/libndr.so.2
lib/libndr.so.2.0.0
d157 1
d269 23
a291 7
${PYSITELIB}/samba/gp_cert_auto_enroll_ext.py
${PYSITELIB}/samba/gp_chromium_ext.py
${PYSITELIB}/samba/gp_ext_loader.py
${PYSITELIB}/samba/gp_firefox_ext.py
${PYSITELIB}/samba/gp_firewalld_ext.py
${PYSITELIB}/samba/gp_gnome_settings_ext.py
${PYSITELIB}/samba/gp_msgs_ext.py
a297 5
${PYSITELIB}/samba/gp_scripts_ext.py
${PYSITELIB}/samba/gp_sec_ext.py
${PYSITELIB}/samba/gp_smb_conf_ext.py
${PYSITELIB}/samba/gp_sudoers_ext.py
${PYSITELIB}/samba/gpclass.py
d368 1
d375 1
d399 1
d485 1
d487 1
d489 1
d512 1
d529 1
d598 1
d601 1
a617 8
${PYSITELIB}/samba/vgp_access_ext.py
${PYSITELIB}/samba/vgp_files_ext.py
${PYSITELIB}/samba/vgp_issue_ext.py
${PYSITELIB}/samba/vgp_motd_ext.py
${PYSITELIB}/samba/vgp_openssh_ext.py
${PYSITELIB}/samba/vgp_startup_scripts_ext.py
${PYSITELIB}/samba/vgp_sudoers_ext.py
${PYSITELIB}/samba/vgp_symlink_ext.py
@


1.45
log
@samba4: Add support for mit-krb5.

The builtin heimdal no longer builds and it's unclear how it can possibly
work as it uses functions that do not exist anywhere.  Also fix some SunOS
build issues.

I'm not convinced this won't break builds that use heimdal but will keep an
eye out for failures.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.44 2022/07/21 09:35:19 adam Exp $
d469 1
d676 1
d685 1
d702 1
d721 6
d728 1
d732 2
d757 1
d790 1
@


1.44
log
@samba4: updated to 4.16.3

Changes since 4.16.2
--------------------
* BUG 15099: Using vfs_streams_xattr and deleting a file causes a panic.
* BUG 14986: Add support for bind 9.18.
* BUG 15076: logging dsdb audit to specific files does not work.
* BUG 14979: Problem when winbind renews Kerberos.
* BUG 15095: Samba with new lorikeet-heimdal fails to build on gcc 12.1 in
  developer mode.
* BUG 15105: Crash in streams_xattr because fsp->base_fsp->fsp_name is NULL.
* BUG 15118: Crash in rpcd_classic - NULL pointer deference in
  mangle_is_mangled().
* BUG 15100: smbclient commands del & deltree fail with
  NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS.
* BUG 15120: Fix check for chown when processing NFSv4 ACL.
* BUG 15082: The pcap background queue process should not be stopped.
* BUG 15097: testparm: Fix typo in idmap rangesize check.
* BUG 15106: net ads info returns LDAP server and LDAP server name as null.
* BUG 15108: ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link.
* BUG 15090: CTDB child process logging does not work as expected.

Changes since 4.16.1
--------------------
* BUG 15042: Use pathref fd instead of io fd in vfs_default_durable_cookie.
* BUG 15069: vfs_gpfs with vfs_shadowcopy2 fail to restore file if original
  file had been deleted.
* BUG 15087: netgroups support removed.
* BUG 14674: net ads info shows LDAP Server: 0.0.0.0 depending on contacted
  server.
* BUG 15062: Update from 4.15  to 4.16 breaks discovery of [homes] on
  standalone server from Win and IOS.
* BUG 15071: waf produces incorrect names for python extensions with Python
  3.11.
* BUG 15075: smbclient -E doesn't work as advertised.
* BUG 15071: waf produces incorrect names for python extensions with Python
  3.11.
* BUG 15081: The samba background daemon doesn't refresh the printcap cache
  on startup.
* BUG 14443: Out-by-4 error in smbd read reply max_send clamp..

Changes since 4.16.0
--------------------
* BUG 14831: Share and server swapped in smbget password prompt.
* BUG 15022: Durable handles won't reconnect if the leased file is written
  to.
* BUG 15023: rmdir silently fails if directory contains unreadable files and
  hide unreadable is yes.
* BUG 15038: SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on
  renamed file handle.
* BUG 8731: Need to describe --builtin-libraries= better (compare with
 --bundled-libraries).
* BUG 14957: vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback.
* BUG 15035: shadow_copy2 fails listing snapshotted dirs with
  shadow:fixinodes.
* BUG 15046: PAM Kerberos authentication incorrectly fails with a clock skew
  error.
* BUG 15041: Username map - samba erroneously applies unix group memberships
  to user account entries.
* BUG 14951: KVNO off by 100000.
* BUG 15027: Uninitialized litemask in variable in vfs_gpfs module.
* BUG 15055: vfs_gpfs recalls=no option prevents listing files.
* BUG 15054: smbd doesn't handle UPNs for looking up names.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.43 2022/03/20 21:53:53 adam Exp $
a674 1
${PLIST.ads}lib/samba/private/libHDB-SAMBA4-samba4.so
a682 1
lib/samba/private/libasn1-samba4.so
a698 1
lib/samba/private/libcom-err-samba4.so
a716 6
lib/samba/private/libgss-preauth-samba4.so
lib/samba/private/libgssapi-samba4.so
lib/samba/private/libhcrypto-samba4.so
lib/samba/private/libhdb-samba4.so
lib/samba/private/libheimbase-samba4.so
lib/samba/private/libheimntlm-samba4.so
a717 1
lib/samba/private/libhx509-samba4.so
a720 2
lib/samba/private/libkdc-samba4.so
lib/samba/private/libkrb5-samba4.so
a743 1
lib/samba/private/libroken-samba4.so
a775 1
lib/samba/private/libwind-samba4.so
@


1.43
log
@samba4: updated to 4.15.6

Changes since 4.15.5
--------------------
* BUG 14169: Renaming file on DFS root fails with
  NT_STATUS_OBJECT_PATH_NOT_FOUND.
* BUG 14737: Samba does not response STATUS_INVALID_PARAMETER when opening 2
  objects with same lease key.
* BUG 14938: NT error code is not set when overwriting a file during rename
  in libsmbclient.
* BUG 14996: Fix ldap simple bind with TLS auditing.
* BUG 14674: net ads info shows LDAP Server: 0.0.0.0 depending on contacted
  server.
* BUG 14979: Problem when winbind renews Kerberos.
* BUG 8691: pam_winbind will not allow gdm login if password about to expire.
* BUG 14971: virusfilter_vfs_openat: Not scanned: Directory or special file.
* BUG 13631: DFS fix for AIX broken.
* BUG 14974: Solaris and AIX acl modules: wrong function arguments.
* BUG 7239: Function aixacl_sys_acl_get_file not declared / coredump.
* BUG 14900: Regression: Samba 4.15.2 on macOS segfaults intermittently
  during strcpy in tdbsam_getsampwnam.
* BUG 14989: Fix a use-after-free in SMB1 server.
* BUG 14968: smb2_signing_decrypt_pdu() may not decrypt with
  gnutls_aead_cipher_decrypt() from gnutls before 3.5.2.
* BUG 14984: changing the machine password against an RODC likely destroys
  the domain join.
* BUG 14993: authsam_make_user_info_dc() steals memory from its struct
  ldb_message *msg argument.
* BUG 14995: Use Heimdal 8.0 (pre) rather than an earlier snapshot.
* BUG 14967: Samba autorid fails to map AD users if id rangesize fits in the
  id range only once.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.42 2022/03/07 21:40:37 thor Exp $
d177 1
d268 2
d271 2
d470 1
d549 1
d582 1
d612 1
d679 3
d684 1
a684 2
lib/samba/private/libasn1-samba4.so.8
lib/samba/private/libasn1-samba4.so.8.0.0
d701 1
a701 2
lib/samba/private/libcom_err-samba4.so.0
lib/samba/private/libcom_err-samba4.so.0.25
d720 6
a725 10
lib/samba/private/libgssapi-samba4.so.2
lib/samba/private/libgssapi-samba4.so.2.0.0
lib/samba/private/libhcrypto-samba4.so.5
lib/samba/private/libhcrypto-samba4.so.5.0.1
lib/samba/private/libhdb-samba4.so.11
lib/samba/private/libhdb-samba4.so.11.0.2
lib/samba/private/libheimbase-samba4.so.1
lib/samba/private/libheimbase-samba4.so.1.0.0
lib/samba/private/libheimntlm-samba4.so.1
lib/samba/private/libheimntlm-samba4.so.1.0.1
d727 1
a727 2
lib/samba/private/libhx509-samba4.so.5
lib/samba/private/libhx509-samba4.so.5.0.0
d731 2
a732 4
lib/samba/private/libkdc-samba4.so.2
lib/samba/private/libkdc-samba4.so.2.0.0
lib/samba/private/libkrb5-samba4.so.26
lib/samba/private/libkrb5-samba4.so.26.0.0
d756 1
a756 2
lib/samba/private/libroken-samba4.so.19
lib/samba/private/libroken-samba4.so.19.0.1
d789 1
a789 3
lib/samba/private/libwinbind-client-samba4.so
lib/samba/private/libwind-samba4.so.0
lib/samba/private/libwind-samba4.so.0.0.0
d844 8
d853 1
a882 1
man/man1/vfstest.1
d910 1
d931 1
@


1.43.4.1
log
@Pullup tickets #6664 #6669 - requested by taca
net/samba4: security update
databases/ldb: dependency update

Update net/samba4 to 4.15.9 from samba-4.15.6 by patch,
since HEAD is on a later minor.
Update databases/ldb to 2.4.4 from 2.4.2 because samba-4.15.9 requires it.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.43 2022/03/20 21:53:53 adam Exp $
a176 1
lib/libsmbconf.so.0.0.1
a463 1
${PYSITELIB}/samba/tests/krb5/kpasswd_tests.py
a603 1
${PLIST.ads}lib/samba/bind9/dlz_bind9_18.${SOEXT}
a1059 1

@


1.42
log
@net/samba4: version 4.15.4

This includes a patch (already posted upstream) to fix updated Samba on
NetBSD's /proc, so the upgrade is not blocked anymore.

Release notes for 4.15:

EW FEATURES/CHANGES
====================

VFS
---

The effort to modernize Samba's VFS interface is complete and Samba 4.15.0 ships
with a modernized VFS designed for the post SMB1 world.

For details please refer to the documentation at source3/modules/The_New_VFS.txt
or visit the <https://wiki.samba.org/index.php/The_New_VFS>.


Bind DLZ: add the ability to set allow/deny lists for zone transfer clients
---------------------------------------------------------------------------

Up to now, any client could use a DNS zone transfer request to the
bind server, and get an answer from Samba. Now the default behaviour
will be to deny those request. Two new options have been added to
manage the list of authorized/denied clients for zone transfer
requests. In order to be accepted, the request must be issued by a
client that is in the allow list and NOT in the deny list.


"server multi channel support" no longer experimental
-----------------------------------------------------

This option is enabled by default starting with 4.15 (on Linux and FreeBSD).
Due to dependencies on kernel APIs of Linux or FreeBSD, it's only possible
to use this feature on Linux and FreeBSD for now.


samba-tool available without the ad-dc
--------------------------------------

The 'samba-tool' command is now available when samba is configured
"--without-ad-dc". Not all features will work, and some ad-dc specific options
have been disabled. The 'samba-tool domain' options, for example, are limited
when no ad-dc is present. Samba must still be built with ads in order to enable
'samba-tool'.


Improved command line user experience
-------------------------------------

Samba utilities did not consistently implement their command line interface. A
number of options were requiring to specify values in one tool and not in the
other, some options meant different in different tools.

These should be stories of the past now. A new command line parser has been
implemented with sanity checking. Also the command line interface has been
simplified and provides better control for encryption, signing and kerberos.

Previously many tools silently ignored unknown options. To prevent unexpected
behaviour all tools will now consistently reject unknown options.

Also several command line options have a smb.conf variable to control the
default now.

All tools are now logging to stderr by default. You can use "--debug-stdout" to
change the behavior. All servers will log to stderr at early startup until logging
is setup to go to a file by default.

### Common parser:

Options added:
--client-protection=off|sign|encrypt

Options renamed:
--kerberos       ->    --use-kerberos=required|desired|off
--krb5-ccache    ->    --use-krb5-ccache=CCACHE
--scope          ->    --netbios-scope=SCOPE
--use-ccache     ->    --use-winbind-ccache

Options removed:
-e|--encrypt
-C removed from --use-winbind-ccache
-i removed from --netbios-scope
-S|--signing


### Duplicates in command line utils

ldbadd/ldbdel/ldbedit/ldbmodify/ldbrename/ldbsearch:
-e is still available as an alias for --editor,
   as it used to be.
-s is no longer reported as an alias for --configfile,
   it never worked that way as it was shadowed by '-s' for '--scope'.

ndrdump:
-l is not available for --load-dso anymore

net:
-l is not available for --long anymore

sharesec:
-V is not available for --viewsddl anymore

smbcquotas:
--user        ->    --quota-user

nmbd:
--log-stdout  ->    --debug-stdout

smbd:
--log-stdout  ->    --debug-stdout

winbindd:
--log-stdout  ->    --debug-stdout


Scanning of trusted domains and enterprise principals
-----------------------------------------------------

As an artifact from the NT4 times, we still scanned the list of trusted domains
on winbindd startup. This is wrong as we never can get a full picture in Active
Directory. It is time to change the default value to "No". Also with this change
we always use enterprise principals for Kerberos so that the DC will be able
to redirect ticket requests to the right DC. This is e.g. needed for one way
trusts. The options `winbind use krb5 enterprise principals` and
`winbind scan trusted domains` will be deprecated in one of the next releases.


Support for Offline Domain Join (ODJ)
-------------------------------------

The net utility is now able to support the offline domain join feature
as known from the Windows djoin.exe command for many years. Samba's
implementation is accessible via the 'net offlinejoin' subcommand. It
can provision computers and request offline joining for both Windows
and Unix machines. It is also possible to provision computers from
Windows (using djoin.exe) and use the generated data in Samba's 'net'
utility. The existing options for the provisioning and joining steps
are documented in the net(8) manpage.


'samba-tool dns zoneoptions' for aging control
----------------------------------------------

The 'samba-tool dns zoneoptions' command can be used to turn aging on
and off, alter the refresh and no-refresh periods, and manipulate the
timestamps of existing records.

To turn aging on for a zone, you can use something like this:

  samba-tool dns zoneoptions --aging=1 --refreshinterval=306600

which turns on aging and ensures no records less than five years old
are aged out and scavenged. After aging has been on for sufficient
time for records to be renewed, the command

  samba-tool dns zoneoptions --refreshinterval=168

will set the refresh period to the standard seven days. Using this two
step process will help prevent the temporary loss of dynamic records
if scavenging happens before their first renewal.


Marking old records as static or dynamic with 'samba-tool'
----------------------------------------------------------

A bug in Samba versions prior to 4.9 meant records that were meant to
be static were marked as dynamic and vice versa. To fix the timestamps
in these domains, it is possible to use the following options,
preferably before turning aging on.

   --mark-old-records-static
   --mark-records-dynamic-regex
   --mark-records-static-regex

The "--mark-old-records-static" option will make records older than the
specified date static (that is, with a zero timestamp). For example,
if you upgraded to Samba 4.9 in November 2018, you could use ensure no
old records will be mistakenly interpreted as dynamic using the
following option:

  samba-tool dns zoneoptions --mark-old-records-static=2018-11-30

Then, if you know that that will have marked some records as static
that should be dynamic, and you know which those are due to your
naming scheme, you can use commands like:

  samba-tool dns zoneoptions --mark-records-dynamic-regex='\w+-desktop'

where '\w+-desktop' is a perl-compatible regular expression that will
match 'bob-desktop', 'alice-desktop', and so on.

These options are deliberately long and cumbersome to type, so people
have a chance to think before they get to the end. You can make a
mess if you get it wrong.

All 'samba-tool dns zoneoptions' modes can be given a "--dry-run/-n"
argument that allows you to inspect the likely results before going
ahead.

NOTE: for aging to work, you need to have "dns zone scavenging = yes"
set in the smb.conf of at least one server.


DNS tombstones are now deleted as appropriate
---------------------------------------------

When all the records for a DNS name have been deleted, the node is put
in a tombstoned state (separate from general AD object tombstoning,
which deleted nodes also go through). These tombstones should be
cleaned up periodically. Due to a conflation of scavenging and
tombstoning, we have only been deleting tombstones when aging is
enabled.

If you have a lot of tombstoned DNS nodes (that is, DNS names for
which you have removed all the records), cleaning up these DNS
tombstones may take a noticeable time.


DNS tombstones use a consistent timestamp format
------------------------------------------------

DNS records use an hours-since-1601 timestamp format except for in the
case of tombstone records where a 100-nanosecond-intervals-since-1601
format is used (this latter format being the most common in Windows).
We had mixed that up, which might have had strange effects in zones
where aging was enabled (and hence tombstone timestamps were used).


samba-tool dns update and RPC changes
-------------------------------------

The dnsserver DCERPC pipe can be used by 'samba-tool' and Windows tools
to manipulate dns records on the remote server. A bug in Samba meant
it was not possible to update an existing DNS record to change the
TTL. The general behaviour of RPC updates is now closer to that of
Windows.

'samba-tool dns update' is now a bit more careful in rejecting and
warning you about malformed IPv4 and IPv6 addresses.

CVE-2021-3671: Crash in Heimdal KDC and updated security release policy
-----------------------------------------------------------------------

An unuthenticated user can crash the AD DC KDC by omitting the server
name in a TGS-REQ.  Per Samba's updated security process a specific
security release was not made for this issue as it is a recoverable
Denial Of Service.

See https://wiki.samba.org/index.php/Samba_Security_Proces

samba-tool domain backup offline with the LMDB backend
------------------------------------------------------

samba-tool domain backup offline, when operating with the LMDB backend
now correctly takes out locks against concurrent modification of the
database during the backup.  If you use this tool on a Samba AD DC
using LMDB, you should upgrade to this release for safer backups.

REMOVED FEATURES
================

Tru64 ACL support has been removed from this release. The last
supported release of Tru64 UNIX was in 2012.

NIS support has been removed from this release. This is not
available in Linux distributions anymore.

The DLZ DNS plugin is no longer built for Bind versions 9.8 and 9.9,
which have been out of support since 2018.


smb.conf changes
================

  Parameter Name                          Description     Default
  --------------                          -----------     -------
  client use kerberos                     New             desired
  client max protocol                     Values Removed
  client min protocol                     Values Removed
  client protection                       New             default
  client smb3 signing algorithms          New             see man smb.conf
  client smb3 encryption algorithms       New             see man smb.conf
  preopen:posix-basic-regex               New             No
  preopen:nomatch_log_level               New             5
  preopen:match_log_level                 New             5
  preopen:nodigits_log_level              New             1
  preopen:founddigits_log_level           New             3
  preopen:reset_log_level                 New             5
  preopen:push_log_level                  New             3
  preopen:queue_log_level                 New             10
  server max protocol                     Values Removed
  server min protocol                     Values Removed
  server multi channel support            Changed         Yes (on Linux and FreeBSD)
  server smb3 signing algorithms          New             see man smb.conf
  server smb3 encryption algorithms       New             see man smb.conf
  winbind use krb5 enterprise principals  Changed         Yes
  winbind scan trusted domains            Changed         No


Release notes for 4.14:

NEW FEATURES/CHANGES
====================

Here is a copy of a clarification note added to the Samba code
in the file: VFS-License-clarification.txt.
--------------------------------------------------------------

A clarification of our GNU GPL License enforcement boundary within the Samba
Virtual File System (VFS) layer.

Samba is licensed under the GNU GPL. All code committed to the Samba
project or that creates a "modified version" or software "based on" Samba must
be either licensed under the GNU GPL or a compatible license.

Samba has several plug-in interfaces where external code may be called
from Samba GNU GPL licensed code. The most important of these is the
Samba VFS layer.

Samba VFS modules are intimately connected by header files and API
definitions to the part of the Samba code that provides file services,
and as such, code that implements a plug-in Samba VFS module must be
licensed under the GNU GPL or a compatible license.

However, Samba VFS modules may themselves call third-party external
libraries that are not part of the Samba project and are externally
developed and maintained.

As long as these third-party external libraries do not use any of the
Samba internal structure, APIs or interface definitions created by the
Samba project (to the extent that they would be considered subject to the GNU
GPL), then the Samba Team will not consider such third-party external
libraries called from Samba VFS modules as "based on" and/or creating a
"modified version" of the Samba code for the purposes of GNU GPL.
Accordingly, we do not require such libraries be licensed under the GNU GPL
or a GNU GPL compatible license.

VFS
---

The effort to modernize Samba's VFS interface has reached a major milestone with
the next release Samba 4.14.

For details please refer to the documentation at source3/modules/The_New_VFS.txt or
visit the <https://wiki.samba.org/index.php/The_New_VFS>.

Printing
--------

Publishing printers in AD is more reliable and more printer features are
added to the published information in AD. Samba now also supports Windows
drivers for the ARM64 architecture.

Client Group Policy
-------------------
This release extends Samba to support Group Policy functionality for Winbind
clients. Active Directory Administrators can set policies that apply Sudoers
configuration, and cron jobs to run hourly, daily, weekly or monthly.

To enable the application of Group Policies on a client, set the global
smb.conf option 'apply group policies' to 'yes'. Policies are applied on an
interval of every 90 minutes, plus a random offset between 0 and 30 minutes.

Policies applied by Samba are 'non-tattooing', meaning that changes can be
reverted by executing the `samba-gpupdate --unapply` command. Policies can be
re-applied using the `samba-gpupdate --force` command.
To view what policies have been or will be applied to a system, use the
`samba-gpupdate --rsop` command.

Administration of Samba policy requires that a Samba ADMX template be uploaded
to the SYSVOL share. The samba-tool command `samba-tool gpo admxload` is
provided as a convenient method for adding this policy. Once uploaded, policies
can be modified in the Group Policy Management Editor under Computer
Configuration/Policies/Administrative Templates. Alternatively, Samba policy
may be managed using the `samba-tool gpo manage` command. This tool does not
require the admx templates to be installed.

Python 3.6 or later required
----------------------------

Samba's minimum runtime requirement for python was raised to Python
3.6 with samba 4.13.  Samba 4.14 raises this minimum version to Python
3.6 also to build Samba. It is no longer possible to build Samba
(even just the file server) with Python versions 2.6 and 2.7.

As Python 2.7 has been End Of Life upstream since April 2020, Samba
is dropping ALL Python 2.x support in this release.

Miscellaneous samba-tool changes
--------------------------------

The 'samba-tool' subcommands to manage AD objects (e.g. users, computers and
groups) now consistently use the "add" command when adding a new object to
the AD. The previous deprecation warnings when using the 'add' commands
have been removed. For compatibility reasons, both the 'add' and 'create'
commands can be used now.

Users, groups and contacts can now be renamed with the respective rename
commands.

Locked users can be unlocked with the new 'samba-tool user unlock' command.

The 'samba-tool user list' and 'samba-tool group listmembers' commands
provide additional options to hide expired and disabled user accounts
(--hide-expired and --hide-disabled).


CTDB CHANGES
============

* The NAT gateway and LVS features now uses the term "leader" to refer
  to the main node in a group through which traffic is routed and
  "follower" for other members of a group.  The command for
  determining the leader has changed to "ctdb natgw leader" (from
  "ctdb natgw master").  The configuration keyword for indicating that
  a node can not be the leader of a group has changed to
  "follower-only" (from "slave-only").  Identical changes were made
  for LVS.

* Remove "ctdb isnotrecmaster" command.  It isn't used by CTDB's
  scripts and can be checked by users with "ctdb pnn" and "ctdb
  recmaster".


smb.conf changes
================

  Parameter Name                     Description                Default
  --------------                     -----------                -------
  smb encrypt                        Removed
  async dns timeout                  New                        10
  client smb encrypt                 New                        default
  honor change notify privilege      New                        No
  smbd force process locks           New                        No
  server smb encrypt                 New                        default
@
text
@d1 1
a1 1
@@comment $NetBSD$
d37 2
d599 66
a664 66
${PLIST.ads}lib/samba/bind9/dlz_bind9_10.so
${PLIST.ads}lib/samba/bind9/dlz_bind9_11.so
${PLIST.ads}lib/samba/bind9/dlz_bind9_12.so
${PLIST.ads}lib/samba/bind9/dlz_bind9_14.so
${PLIST.ads}lib/samba/bind9/dlz_bind9_16.so
${PLIST.ads}lib/samba/gensec/krb5.so
${PLIST.ads}lib/samba/idmap/ad.so
lib/samba/idmap/autorid.so
lib/samba/idmap/hash.so
${PLIST.ads}lib/samba/idmap/rfc2307.so
lib/samba/idmap/rid.so
lib/samba/idmap/script.so
lib/samba/idmap/tdb2.so
lib/samba/krb5/async_dns_krb5_locator.so
lib/samba/krb5/winbind_krb5_locator.so
${PLIST.ads}lib/samba/ldb/acl.so
${PLIST.ads}lib/samba/ldb/aclread.so
${PLIST.ads}lib/samba/ldb/anr.so
${PLIST.ads}lib/samba/ldb/audit_log.so
${PLIST.ads}lib/samba/ldb/count_attrs.so
${PLIST.ads}lib/samba/ldb/descriptor.so
${PLIST.ads}lib/samba/ldb/dirsync.so
${PLIST.ads}lib/samba/ldb/dns_notify.so
${PLIST.ads}lib/samba/ldb/dsdb_notification.so
${PLIST.ads}lib/samba/ldb/encrypted_secrets.so
${PLIST.ads}lib/samba/ldb/extended_dn_in.so
${PLIST.ads}lib/samba/ldb/extended_dn_out.so
${PLIST.ads}lib/samba/ldb/extended_dn_store.so
${PLIST.ads}lib/samba/ldb/group_audit_log.so
lib/samba/ldb/ildap.so
${PLIST.ads}lib/samba/ldb/instancetype.so
${PLIST.ads}lib/samba/ldb/lazy_commit.so
lib/samba/ldb/ldbsamba_extensions.so
${PLIST.ads}lib/samba/ldb/linked_attributes.so
${PLIST.ads}lib/samba/ldb/new_partition.so
${PLIST.ads}lib/samba/ldb/objectclass.so
${PLIST.ads}lib/samba/ldb/objectclass_attrs.so
${PLIST.ads}lib/samba/ldb/objectguid.so
${PLIST.ads}lib/samba/ldb/operational.so
${PLIST.ads}lib/samba/ldb/paged_results.so
${PLIST.ads}lib/samba/ldb/partition.so
${PLIST.ads}lib/samba/ldb/password_hash.so
${PLIST.ads}lib/samba/ldb/ranged_results.so
${PLIST.ads}lib/samba/ldb/repl_meta_data.so
${PLIST.ads}lib/samba/ldb/resolve_oids.so
${PLIST.ads}lib/samba/ldb/rootdse.so
${PLIST.ads}lib/samba/ldb/samba3sam.so
${PLIST.ads}lib/samba/ldb/samba3sid.so
${PLIST.ads}lib/samba/ldb/samba_dsdb.so
${PLIST.ads}lib/samba/ldb/samba_secrets.so
${PLIST.ads}lib/samba/ldb/samldb.so
${PLIST.ads}lib/samba/ldb/schema_data.so
${PLIST.ads}lib/samba/ldb/schema_load.so
${PLIST.ads}lib/samba/ldb/secrets_tdb_sync.so
${PLIST.ads}lib/samba/ldb/show_deleted.so
${PLIST.ads}lib/samba/ldb/subtree_delete.so
${PLIST.ads}lib/samba/ldb/subtree_rename.so
${PLIST.ads}lib/samba/ldb/tombstone_reanimate.so
${PLIST.ads}lib/samba/ldb/unique_object_sids.so
${PLIST.ads}lib/samba/ldb/update_keytab.so
${PLIST.ads}lib/samba/ldb/vlv.so
${PLIST.ads}lib/samba/ldb/wins_ldb.so
lib/samba/nss_info/hash.so
${PLIST.ads}lib/samba/nss_info/rfc2307.so
${PLIST.ads}lib/samba/nss_info/sfu.so
${PLIST.ads}lib/samba/nss_info/sfu20.so
d791 53
a843 53
${PLIST.ads}lib/samba/process_model/prefork.so
${PLIST.ads}lib/samba/process_model/standard.so
${PLIST.pam}lib/samba/security/pam_winbind.so
${PLIST.ads}lib/samba/service/cldap.so
${PLIST.ads}lib/samba/service/dcerpc.so
${PLIST.ads}lib/samba/service/dns.so
${PLIST.ads}lib/samba/service/dns_update.so
${PLIST.ads}lib/samba/service/drepl.so
${PLIST.ads}lib/samba/service/kcc.so
${PLIST.ads}lib/samba/service/kdc.so
${PLIST.ads}lib/samba/service/ldap.so
${PLIST.ads}lib/samba/service/nbtd.so
${PLIST.ads}lib/samba/service/ntp_signd.so
${PLIST.ads}lib/samba/service/s3fs.so
${PLIST.ads}lib/samba/service/winbindd.so
${PLIST.ads}lib/samba/service/wrepl.so
lib/samba/vfs/acl_tdb.so
lib/samba/vfs/acl_xattr.so
lib/samba/vfs/aio_fork.so
lib/samba/vfs/aio_pthread.so
lib/samba/vfs/audit.so
lib/samba/vfs/cap.so
lib/samba/vfs/catia.so
lib/samba/vfs/commit.so
lib/samba/vfs/crossrename.so
lib/samba/vfs/default_quota.so
lib/samba/vfs/dirsort.so
lib/samba/vfs/expand_msdfs.so
lib/samba/vfs/extd_audit.so
lib/samba/vfs/fake_perms.so
lib/samba/vfs/fruit.so
lib/samba/vfs/full_audit.so
lib/samba/vfs/linux_xfs_sgid.so
lib/samba/vfs/media_harmony.so
lib/samba/vfs/offline.so
${PLIST.ads}lib/samba/vfs/posix_eadb.so
lib/samba/vfs/preopen.so
lib/samba/vfs/readahead.so
lib/samba/vfs/readonly.so
lib/samba/vfs/recycle.so
lib/samba/vfs/shadow_copy.so
lib/samba/vfs/shadow_copy2.so
lib/samba/vfs/shell_snap.so
${PLIST.snapper}lib/samba/vfs/snapper.so
lib/samba/vfs/streams_depot.so
lib/samba/vfs/streams_xattr.so
lib/samba/vfs/syncops.so
lib/samba/vfs/time_audit.so
lib/samba/vfs/unityed_media.so
lib/samba/vfs/virusfilter.so
lib/samba/vfs/widelinks.so
lib/samba/vfs/worm.so
lib/samba/vfs/xattr_tdb.so
d974 1
d1057 2
a1059 5
@@pkgdir var/log
@@pkgdir var/db/samba4/private
@@pkgdir share/examples/samba/pam_smbpass
@@pkgdir etc/samba
@@pkgdir bind-dns
@


1.41
log
@net/samba4: update to 4.13.15

This release contain security fixes.


                   ===============================
                   Release Notes for Samba 4.13.15
                          December 15, 2021
                   ===============================


This is the latest stable release of the Samba 4.13 release series.

Important Notes
===============

There have been a few regressions in the security release 4.13.14:

o CVE-2020-25717: A user on the domain can become root on domain members.
                  https://www.samba.org/samba/security/CVE-2020-25717.html
                  PLEASE [RE-]READ!
                  The instructions have been updated and some workarounds
                  initially adviced for 4.13.14 are no longer required and
                  should be reverted in most cases.

o BUG-14902: User with multiple spaces (eg Fred<space><space>Nurk) become
             un-deletable. While this release should fix this bug, it is
             adviced to have a look at the bug report for more detailed
             information, see https://bugzilla.samba.org/show_bug.cgi?id=14902.

Changes since 4.13.14
---------------------

o  Andrew Bartlett <abartlet@@samba.org>
   * BUG 14656: Spaces incorrectly collapsed in ldb attributes.
   * BUG 14901: The CVE-2020-25717 username map [script] advice has undesired
     side effects for the local nt token.
   * BUG 14902: User with multiple spaces (eg Fred<space><space>Nurk) become un-
     deletable.

o  Ralph Boehme <slow@@samba.org>
   * BUG 14922: Kerberos authentication on standalone server in MIT realm
     broken.

o  Alexander Bokovoy <ab@@samba.org>
   * BUG 14903: Support for ROLE_IPA_DC is incomplete.

o  Stefan Metzmacher <metze@@samba.org>
   * BUG 14899: winbindd doesn't start when "allow trusted domains" is off.
   * BUG 14901: The CVE-2020-25717 username map [script] advice has undesired
     side effects for the local nt token.

o  Joseph Sutton <josephsutton@@catalyst.net.nz>
   * BUG 14901: The CVE-2020-25717 username map [script] advice has undesired
     side effects for the local nt token.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.40 2021/11/10 13:33:20 adam Exp $
a4 1
bin/findsmb
d8 1
a8 1
bin/mdfind
d22 1
a22 1
bin/samba-tool
a36 2
@@pkgdir bind-dns
@@pkgdir etc/samba
d47 1
a47 1
include/dcerpc_server.h
a110 1
include/util/string_wrappers.h
d128 3
a130 3
lib/libdcerpc-server.so
lib/libdcerpc-server.so.0
lib/libdcerpc-server.so.0.0.1
d144 2
a145 2
lib/libndr.so.1
lib/libndr.so.1.0.0
d147 2
a148 1
lib/libnetapi.so.0
d151 2
a152 2
lib/libsamba-credentials.so.0
lib/libsamba-credentials.so.0.0.1
d172 1
a172 1
lib/libsmbclient.so.0.6.0
d177 1
d186 1
a186 1
lib/pkgconfig/dcerpc_server.pc
a205 1
${PYSITELIB}/samba/compat.py
d251 1
a251 1
${PYSITELIB}/samba/dckeytab.so
d266 2
d276 2
d299 1
d344 2
a345 1
${PYSITELIB}/samba/samba3/libsmb_samba_internal.so
d376 1
a376 1
${PYSITELIB}/samba/tests/blackbox/mdfind.py
d382 2
d392 1
d397 2
d410 1
d417 1
d430 1
d442 1
d446 1
d487 1
d518 1
d536 1
d548 1
d565 1
d568 1
d581 1
a581 1
${PYSITELIB}/samba/third_party/__init__.py
d585 8
d597 66
a662 67
lib/samba/bind9/dlz_bind9.${SOEXT}
lib/samba/bind9/dlz_bind9_10.${SOEXT}
lib/samba/bind9/dlz_bind9_11.${SOEXT}
lib/samba/bind9/dlz_bind9_12.${SOEXT}
lib/samba/bind9/dlz_bind9_14.${SOEXT}
lib/samba/bind9/dlz_bind9_16.${SOEXT}
lib/samba/bind9/dlz_bind9_9.${SOEXT}
lib/samba/gensec/krb5.${SOEXT}
${PLIST.ads}lib/samba/idmap/ad.${SOEXT}
lib/samba/idmap/autorid.${SOEXT}
lib/samba/idmap/hash.${SOEXT}
${PLIST.ads}lib/samba/idmap/rfc2307.${SOEXT}
lib/samba/idmap/rid.${SOEXT}
lib/samba/idmap/script.${SOEXT}
lib/samba/idmap/tdb2.${SOEXT}
lib/samba/krb5/winbind_krb5_locator.${SOEXT}
lib/samba/ldb/acl.${SOEXT}
lib/samba/ldb/aclread.${SOEXT}
lib/samba/ldb/anr.${SOEXT}
lib/samba/ldb/audit_log.${SOEXT}
lib/samba/ldb/count_attrs.${SOEXT}
lib/samba/ldb/descriptor.${SOEXT}
lib/samba/ldb/dirsync.${SOEXT}
lib/samba/ldb/dns_notify.${SOEXT}
lib/samba/ldb/dsdb_notification.${SOEXT}
lib/samba/ldb/encrypted_secrets.${SOEXT}
lib/samba/ldb/extended_dn_in.${SOEXT}
lib/samba/ldb/extended_dn_out.${SOEXT}
lib/samba/ldb/extended_dn_store.${SOEXT}
lib/samba/ldb/group_audit_log.${SOEXT}
lib/samba/ldb/ildap.${SOEXT}
lib/samba/ldb/instancetype.${SOEXT}
lib/samba/ldb/lazy_commit.${SOEXT}
lib/samba/ldb/ldbsamba_extensions.${SOEXT}
lib/samba/ldb/linked_attributes.${SOEXT}
lib/samba/ldb/new_partition.${SOEXT}
lib/samba/ldb/objectclass.${SOEXT}
lib/samba/ldb/objectclass_attrs.${SOEXT}
lib/samba/ldb/objectguid.${SOEXT}
lib/samba/ldb/operational.${SOEXT}
lib/samba/ldb/paged_results.${SOEXT}
lib/samba/ldb/partition.${SOEXT}
lib/samba/ldb/password_hash.${SOEXT}
lib/samba/ldb/ranged_results.${SOEXT}
lib/samba/ldb/repl_meta_data.${SOEXT}
lib/samba/ldb/resolve_oids.${SOEXT}
lib/samba/ldb/rootdse.${SOEXT}
lib/samba/ldb/samba3sam.${SOEXT}
lib/samba/ldb/samba3sid.${SOEXT}
lib/samba/ldb/samba_dsdb.${SOEXT}
lib/samba/ldb/samba_secrets.${SOEXT}
lib/samba/ldb/samldb.${SOEXT}
lib/samba/ldb/schema_data.${SOEXT}
lib/samba/ldb/schema_load.${SOEXT}
lib/samba/ldb/secrets_tdb_sync.${SOEXT}
lib/samba/ldb/show_deleted.${SOEXT}
lib/samba/ldb/subtree_delete.${SOEXT}
lib/samba/ldb/subtree_rename.${SOEXT}
lib/samba/ldb/tombstone_reanimate.${SOEXT}
lib/samba/ldb/unique_object_sids.${SOEXT}
lib/samba/ldb/update_keytab.${SOEXT}
lib/samba/ldb/vlv.${SOEXT}
lib/samba/ldb/wins_ldb.${SOEXT}
lib/samba/nss_info/hash.${SOEXT}
${PLIST.ads}lib/samba/nss_info/rfc2307.${SOEXT}
${PLIST.ads}lib/samba/nss_info/sfu.${SOEXT}
${PLIST.ads}lib/samba/nss_info/sfu20.${SOEXT}
d664 1
a664 1
lib/samba/private/libHDB-SAMBA4-samba4.so
d687 1
a687 1
lib/samba/private/libcmdline-credentials-samba4.so
d691 1
a691 1
lib/samba/private/libdb-glue-samba4.so
d696 2
a697 2
lib/samba/private/libdfs-server-ad-samba4.so
lib/samba/private/libdlz-bind9-for-torture-samba4.so
d699 1
a699 1
lib/samba/private/libdsdb-garbage-collect-tombstones-samba4.so
d744 1
a744 3
lib/samba/private/libpac-samba4.so
lib/samba/private/libpopt-samba3-cmdline-samba4.so
lib/samba/private/libpopt-samba3-samba4.so
d748 1
a748 1
lib/samba/private/libprocess-model-samba4.so
d762 1
a762 1
lib/samba/private/libscavenge-dns-records-samba4.so
d766 1
a766 1
lib/samba/private/libservice-samba4.so
a781 1
lib/samba/private/libutil-cmdline-samba4.so
d789 55
a843 53
lib/samba/process_model/prefork.${SOEXT}
lib/samba/process_model/standard.${SOEXT}
${PLIST.pam}lib/samba/security/pam_winbind.${SOEXT}
lib/samba/service/cldap.${SOEXT}
lib/samba/service/dcerpc.${SOEXT}
lib/samba/service/dns.${SOEXT}
lib/samba/service/dns_update.${SOEXT}
lib/samba/service/drepl.${SOEXT}
lib/samba/service/kcc.${SOEXT}
lib/samba/service/kdc.${SOEXT}
lib/samba/service/ldap.${SOEXT}
lib/samba/service/nbtd.${SOEXT}
lib/samba/service/ntp_signd.${SOEXT}
lib/samba/service/s3fs.${SOEXT}
lib/samba/service/winbindd.${SOEXT}
lib/samba/service/wrepl.${SOEXT}
lib/samba/vfs/acl_tdb.${SOEXT}
lib/samba/vfs/acl_xattr.${SOEXT}
lib/samba/vfs/aio_fork.${SOEXT}
lib/samba/vfs/aio_pthread.${SOEXT}
lib/samba/vfs/audit.${SOEXT}
lib/samba/vfs/cap.${SOEXT}
lib/samba/vfs/catia.${SOEXT}
lib/samba/vfs/commit.${SOEXT}
lib/samba/vfs/crossrename.${SOEXT}
lib/samba/vfs/default_quota.${SOEXT}
lib/samba/vfs/dirsort.${SOEXT}
lib/samba/vfs/expand_msdfs.${SOEXT}
lib/samba/vfs/extd_audit.${SOEXT}
lib/samba/vfs/fake_perms.${SOEXT}
lib/samba/vfs/fruit.${SOEXT}
lib/samba/vfs/full_audit.${SOEXT}
lib/samba/vfs/linux_xfs_sgid.${SOEXT}
lib/samba/vfs/media_harmony.${SOEXT}
lib/samba/vfs/offline.${SOEXT}
lib/samba/vfs/posix_eadb.${SOEXT}
lib/samba/vfs/preopen.${SOEXT}
lib/samba/vfs/readahead.${SOEXT}
lib/samba/vfs/readonly.${SOEXT}
lib/samba/vfs/recycle.${SOEXT}
lib/samba/vfs/shadow_copy.${SOEXT}
lib/samba/vfs/shadow_copy2.${SOEXT}
lib/samba/vfs/shell_snap.${SOEXT}
${PLIST.snapper}lib/samba/vfs/snapper.${SOEXT}
lib/samba/vfs/streams_depot.${SOEXT}
lib/samba/vfs/streams_xattr.${SOEXT}
lib/samba/vfs/syncops.${SOEXT}
lib/samba/vfs/time_audit.${SOEXT}
lib/samba/vfs/unityed_media.${SOEXT}
lib/samba/vfs/virusfilter.${SOEXT}
lib/samba/vfs/widelinks.${SOEXT}
lib/samba/vfs/worm.${SOEXT}
lib/samba/vfs/xattr_tdb.${SOEXT}
a844 1
man/man1/findsmb.1
d849 1
a849 1
man/man1/mdfind.1
d875 1
a875 1
man/man5/pam_winbind.conf.5
d897 1
a897 1
man/man8/pam_winbind.8
d899 1
d948 1
a948 1
sbin/samba
d950 5
a954 5
sbin/samba_dnsupdate
sbin/samba_downgrade_db
sbin/samba_kcc
sbin/samba_spnupdate
sbin/samba_upgradedns
a971 1
@@pkgdir share/examples/samba/pam_smbpass
d974 86
a1059 81
share/samba/samba/admx/en-US/samba.adml
share/samba/samba/admx/samba.admx
share/samba/setup/ad-schema/AD_DS_Attributes__Windows_Server_2012_R2.ldf
share/samba/setup/ad-schema/AD_DS_Attributes__Windows_Server_2016.ldf
share/samba/setup/ad-schema/AD_DS_Classes__Windows_Server_2012_R2.ldf
share/samba/setup/ad-schema/AD_DS_Classes__Windows_Server_2016.ldf
share/samba/setup/ad-schema/Attributes_for_AD_DS__Windows_Server_2008_R2.ldf
share/samba/setup/ad-schema/Attributes_for_AD_DS__Windows_Server_2012.ldf
share/samba/setup/ad-schema/Classes_for_AD_DS__Windows_Server_2008_R2.ldf
share/samba/setup/ad-schema/Classes_for_AD_DS__Windows_Server_2012.ldf
share/samba/setup/ad-schema/MS-AD_Schema_2K8_Attributes.txt
share/samba/setup/ad-schema/MS-AD_Schema_2K8_Classes.txt
share/samba/setup/ad-schema/MS-AD_Schema_2K8_R2_Attributes.txt
share/samba/setup/ad-schema/MS-AD_Schema_2K8_R2_Classes.txt
share/samba/setup/ad-schema/licence.txt
share/samba/setup/adprep/WindowsServerDocs/Forest-Wide-Updates.md
share/samba/setup/adprep/WindowsServerDocs/Sch49.ldf.diff
share/samba/setup/adprep/WindowsServerDocs/Sch50.ldf.diff
share/samba/setup/adprep/WindowsServerDocs/Sch51.ldf.diff
share/samba/setup/adprep/WindowsServerDocs/Sch57.ldf.diff
share/samba/setup/adprep/WindowsServerDocs/Sch59.ldf.diff
share/samba/setup/adprep/WindowsServerDocs/Schema-Updates.md
share/samba/setup/adprep/fix-forest-rev.ldf
share/samba/setup/aggregate_schema.ldif
share/samba/setup/display-specifiers/DisplaySpecifiers-Win2k0.txt
share/samba/setup/display-specifiers/DisplaySpecifiers-Win2k3.txt
share/samba/setup/display-specifiers/DisplaySpecifiers-Win2k3R2.txt
share/samba/setup/display-specifiers/DisplaySpecifiers-Win2k8.txt
share/samba/setup/display-specifiers/DisplaySpecifiers-Win2k8R2.txt
share/samba/setup/dns_update_list
share/samba/setup/extended-rights.ldif
share/samba/setup/idmap_init.ldif
share/samba/setup/krb5.conf
share/samba/setup/named.conf
share/samba/setup/named.conf.dlz
share/samba/setup/named.conf.update
share/samba/setup/named.txt
share/samba/setup/prefixMap.txt
share/samba/setup/provision.ldif
share/samba/setup/provision.reg
share/samba/setup/provision.zone
share/samba/setup/provision_basedn.ldif
share/samba/setup/provision_basedn_modify.ldif
share/samba/setup/provision_basedn_options.ldif
share/samba/setup/provision_basedn_references.ldif
share/samba/setup/provision_computers_add.ldif
share/samba/setup/provision_computers_modify.ldif
share/samba/setup/provision_configuration.ldif
share/samba/setup/provision_configuration_basedn.ldif
share/samba/setup/provision_configuration_modify.ldif
share/samba/setup/provision_configuration_references.ldif
share/samba/setup/provision_dns_accounts_add.ldif
share/samba/setup/provision_dns_add_samba.ldif
share/samba/setup/provision_dnszones_add.ldif
share/samba/setup/provision_dnszones_modify.ldif
share/samba/setup/provision_dnszones_partitions.ldif
share/samba/setup/provision_group_policy.ldif
share/samba/setup/provision_init.ldif
share/samba/setup/provision_partitions.ldif
share/samba/setup/provision_privilege.ldif
share/samba/setup/provision_rootdse_add.ldif
share/samba/setup/provision_rootdse_modify.ldif
share/samba/setup/provision_schema_basedn.ldif
share/samba/setup/provision_schema_basedn_modify.ldif
share/samba/setup/provision_self_join.ldif
share/samba/setup/provision_self_join_config.ldif
share/samba/setup/provision_self_join_modify.ldif
share/samba/setup/provision_self_join_modify_config.ldif
share/samba/setup/provision_self_join_modify_schema.ldif
share/samba/setup/provision_users.ldif
share/samba/setup/provision_users_add.ldif
share/samba/setup/provision_users_modify.ldif
share/samba/setup/provision_well_known_sec_princ.ldif
share/samba/setup/schema_samba4.ldif
share/samba/setup/secrets.ldif
share/samba/setup/secrets_dns.ldif
share/samba/setup/secrets_init.ldif
share/samba/setup/share.ldif
share/samba/setup/spn_update_list
share/samba/setup/ypServ30.ldif
@@pkgdir var/db/samba4
@


1.40
log
@samba4: updated to 4.13.14

Changes since 4.13.13
---------------------

o  Douglas Bagnall <douglas.bagnall@@catalyst.net.nz>
   * CVE-2020-25722

o  Andrew Bartlett <abartlet@@samba.org>
   * CVE-2020-25718
   * CVE-2020-25719
   * CVE-2020-25721
   * CVE-2020-25722

o  Ralph Boehme <slow@@samba.org>
   * CVE-2020-25717

o  Alexander Bokovoy <ab@@samba.org>
   * CVE-2020-25717

o  Samuel Cabrero <scabrero@@samba.org>
   * CVE-2020-25717

o  Nadezhda Ivanova <nivanova@@symas.com>
   * CVE-2020-25722

o  Stefan Metzmacher <metze@@samba.org>
   * CVE-2016-2124
   * CVE-2020-25717
   * CVE-2020-25719
   * CVE-2020-25722
   * CVE-2021-23192
   * CVE-2021-3738
   * ldb: version 2.2.3

o  Andreas Schneider <asn@@samba.org>
   * CVE-2020-25719

o  Joseph Sutton <josephsutton@@catalyst.net.nz>
   * CVE-2020-17049
   * CVE-2020-25718
   * CVE-2020-25719
   * CVE-2020-25721
   * CVE-2020-25722
   * MS CVE-2020-17049

Changes since 4.13.12
---------------------

o  Douglas Bagnall <douglas.bagnall@@catalyst.net.nz>
   * BUG 14868: rodc_rwdc test flaps.
   * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

o  Andrew Bartlett <abartlet@@samba.org>
   * BUG 14642: Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze
     bit' S4U2Proxy Constrained Delegation bypass in Samba with
     embedded Heimdal.
   * BUG 14836: Python ldb.msg_diff() memory handling failure.
   * BUG 14845: "in" operator on ldb.Message is case sensitive.
   * BUG 14848: Release LDB 2.3.1 for Samba 4.14.9.
   * BUG 14871: Fix Samba support for UF_NO_AUTH_DATA_REQUIRED.
   * BUG 14874: Allow special chars like "@@" in samAccountName when generating
     the salt.
   * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

o  Isaac Boukris <iboukris@@gmail.com>
   * BUG 14642: Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze
     bit' S4U2Proxy Constrained Delegation bypass in Samba with
     embedded Heimdal.
   * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

o  Viktor Dukhovni <viktor@@twosigma.com>
   * BUG 12998: Fix transit path validation.
   * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

o  Luke Howard <lukeh@@padl.com>
   * BUG 14642: Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze
     bit' S4U2Proxy Constrained Delegation bypass in Samba with
     embedded Heimdal.
   * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

o  Stefan Metzmacher <metze@@samba.org>
   * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

o  David Mulder <dmulder@@suse.com>
   * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

o  Andreas Schneider <asn@@samba.org>
   * BUG 14870: Prepare to operate with MIT krb5 >= 1.20.
   * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

o  Joseph Sutton <josephsutton@@catalyst.net.nz>
   * BUG 14642: Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze
     bit' S4U2Proxy Constrained Delegation bypass in Samba with
     embedded Heimdal.
   * BUG 14645: rpcclient NetFileEnum and net rpc file both cause lock order
     violation: brlock.tdb, share_entries.tdb.
   * BUG 14836: Python ldb.msg_diff() memory handling failure.
   * BUG 14845: "in" operator on ldb.Message is case sensitive.
   * BUG 14848: Release LDB 2.3.1 for Samba 4.14.9.
   * BUG 14868: rodc_rwdc test flaps.
   * BUG 14871: Fix Samba support for UF_NO_AUTH_DATA_REQUIRED.
   * BUG 14874: Allow special chars like "@@" in samAccountName when generating
     the salt.
   * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

o  Nicolas Williams <nico@@twosigma.com>
   * BUG 14642: Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze
     bit' S4U2Proxy Constrained Delegation bypass in Samba with
     embedded Heimdal.
   * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.39 2021/10/08 13:20:34 adam Exp $
d459 1
@


1.39
log
@samba4: updated to 4.13.12

Changes since 4.13.11
---------------------
* BUG 14806: Address a signifcant performance regression in database access
  in the AD DC since Samba 4.12.
* BUG 14807: Fix performance regression in lsa_LookupSids3/LookupNames4 since
  Samba 4.9 by using an explicit database handle cache.
* BUG 14817: An unuthenticated user can crash the AD DC KDC by omitting the
  server name in a TGS-REQ.
* BUG 14818: Address flapping samba_tool_drs_showrepl test.
* BUG 14819: Address flapping dsdb_schema_attributes test.
* BUG 14817: An unuthenticated user can crash the AD DC KDC by omitting the
  server name in a TGS-REQ
* BUG 14817: An unuthenticated user can crash the AD DC KDC by omitting the
  server name in a TGS-REQ.
* BUG 14817: An unuthenticated user can crash the AD DC KDC by omitting the
  server name in a TGS-REQ.
* BUG 14817: An unuthenticated user can crash the AD DC KDC by omitting the
  server name in a TGS-REQ.
* BUG 14817: An unuthenticated user can crash the AD DC KDC by omitting the
  server name in a TGS-REQ.
* BUG 14817: An unuthenticated user can crash the AD DC KDC by omitting the
  server name in a TGS-REQ.
* BUG 14784: Fix CTDB flag/status update race conditions.
* BUG 14817: An unuthenticated user can crash the AD DC KDC by omitting the
  server name in a TGS-REQ.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.38 2021/06/22 09:36:41 nia Exp $
d419 1
d440 1
d453 1
d455 1
d457 1
d460 1
d467 2
d666 1
@


1.38
log
@samba4: downgrade to 4.13.9, as discussed on netbsd-users@@
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.35 2021/01/28 13:17:16 adam Exp $
d228 1
d393 1
d439 4
d444 4
d449 1
d453 4
@


1.38.4.1
log
@Pullup ticket #6537 - requested by taca
net/samba4: security fix

Revisions pulled up:
- net/samba4/Makefile                                           1.130-1.132
- net/samba4/PLIST                                              1.39-1.40
- net/samba4/distinfo                                           1.67,1.69

---
   Module Name:	pkgsrc
   Committed By:	adam
   Date:		Wed Sep 29 19:01:31 UTC 2021

   Modified Files:
   	pkgsrc/archivers/ark: Makefile
   	pkgsrc/archivers/innoextract: Makefile
   	pkgsrc/archivers/libcomprex: Makefile buildlink3.mk
   	pkgsrc/archivers/libzip: Makefile buildlink3.mk
   	pkgsrc/archivers/php-pecl-zip: Makefile
   	pkgsrc/archivers/php-zip: Makefile
   	pkgsrc/audio/ardour: Makefile
   	pkgsrc/audio/ario: Makefile
   	pkgsrc/audio/audacious-plugins: Makefile
   	pkgsrc/audio/bmp-scrobbler: Makefile
   	pkgsrc/audio/cmusfm: Makefile
   	pkgsrc/audio/csound6: Makefile
   	pkgsrc/audio/din: Makefile
   	pkgsrc/audio/flactag: Makefile
   	pkgsrc/audio/forked-daapd: Makefile
   	pkgsrc/audio/gbemol: Makefile
   	pkgsrc/audio/glyr: Makefile buildlink3.mk
   	pkgsrc/audio/grip: Makefile
   	pkgsrc/audio/herrie: Makefile
   	pkgsrc/audio/hydrogen: Makefile
   	pkgsrc/audio/icecast: Makefile
   	pkgsrc/audio/jack-rack: Makefile
   	pkgsrc/audio/libmusicbrainz: Makefile buildlink3.mk
   	pkgsrc/audio/libmusicbrainz5: Makefile buildlink3.mk
   	pkgsrc/audio/libofa: Makefile
   	pkgsrc/audio/mad123: Makefile
   	pkgsrc/audio/moc: Makefile
   	pkgsrc/audio/mp3diags: Makefile
   	pkgsrc/audio/mpdas: Makefile
   	pkgsrc/audio/musicpd: Makefile
   	pkgsrc/audio/ncmpcpp: Makefile
   	pkgsrc/audio/pianobar: Makefile
   	pkgsrc/audio/pragha: Makefile
   	pkgsrc/audio/qmmp: Makefile
   	pkgsrc/audio/sound-juicer: Makefile
   	pkgsrc/audio/strawberry: Makefile
   	pkgsrc/audio/streamtuner: Makefile buildlink3.mk
   	pkgsrc/audio/terminatorx: Makefile
   	pkgsrc/audio/tremor-tools: Makefile
   	pkgsrc/audio/vimpc: Makefile
   	pkgsrc/audio/vorbis-tools: Makefile
   	pkgsrc/biology/canu: Makefile
   	pkgsrc/biology/coordgenlibs: Makefile buildlink3.mk
   	pkgsrc/biology/htslib: Makefile
   	pkgsrc/biology/maeparser: Makefile buildlink3.mk
   	pkgsrc/biology/ncbi-blast+: Makefile
   	pkgsrc/biology/openbabel: Makefile
   	pkgsrc/cad/kicad: Makefile
   	pkgsrc/cad/librecad: Makefile
   	pkgsrc/cad/openscad: Makefile
   	pkgsrc/chat/anope: Makefile
   	pkgsrc/chat/bitlbee: Makefile
   	pkgsrc/chat/centerim: Makefile
   	pkgsrc/chat/ctrlproxy: Makefile
   	pkgsrc/chat/ekg: Makefile
   	pkgsrc/chat/farstream: Makefile
   	pkgsrc/chat/gloox: Makefile
   	pkgsrc/chat/ircd-hybrid: Makefile
   	pkgsrc/chat/konversation: Makefile
   	pkgsrc/chat/ktp-accounts-kcm: Makefile
   	pkgsrc/chat/ktp-approver: Makefile
   	pkgsrc/chat/ktp-auth-handler: Makefile
   	pkgsrc/chat/ktp-common-internals: Makefile buildlink3.mk
   	pkgsrc/chat/ktp-contact-list: Makefile
   	pkgsrc/chat/ktp-contact-runner: Makefile
   	pkgsrc/chat/ktp-desktop-applets: Makefile
   	pkgsrc/chat/ktp-filetransfer-handler: Makefile
   	pkgsrc/chat/ktp-kded-integration-module: Makefile
   	pkgsrc/chat/ktp-send-file: Makefile
   	pkgsrc/chat/ktp-text-ui: Makefile
   	pkgsrc/chat/libgadu: Makefile buildlink3.mk
   	pkgsrc/chat/libpurple: Makefile
   	pkgsrc/chat/mumble: Makefile
   	pkgsrc/chat/profanity: Makefile
   	pkgsrc/chat/scrollz: Makefile
   	pkgsrc/chat/spectrum: Makefile
   	pkgsrc/chat/swift: Makefile
   	pkgsrc/chat/telepathy-gabble: Makefile
   	pkgsrc/chat/unrealircd: Makefile
   	pkgsrc/chat/weechat: Makefile
   	pkgsrc/chat/znc: Makefile
   	pkgsrc/comms/asterisk13: Makefile
   	pkgsrc/comms/asterisk16: Makefile
   	pkgsrc/comms/asterisk18: Makefile
   	pkgsrc/comms/gammu: Makefile
   	pkgsrc/converters/libabw: Makefile buildlink3.mk
   	pkgsrc/converters/libcdr: Makefile buildlink3.mk
   	pkgsrc/converters/libe-book: Makefile buildlink3.mk
   	pkgsrc/converters/libepubgen: Makefile buildlink3.mk
   	pkgsrc/converters/libetonyek: Makefile buildlink3.mk
   	pkgsrc/converters/libfreehand: Makefile buildlink3.mk
   	pkgsrc/converters/libmspub: Makefile buildlink3.mk
   	pkgsrc/converters/libmwaw: Makefile buildlink3.mk
   	pkgsrc/converters/libpagemaker: Makefile buildlink3.mk
   	pkgsrc/converters/libqxp: Makefile buildlink3.mk
   	pkgsrc/converters/librevenge: Makefile buildlink3.mk
   	pkgsrc/converters/libstaroffice: Makefile
   	pkgsrc/converters/libvisio: Makefile buildlink3.mk
   	pkgsrc/converters/libwpd: Makefile buildlink3.mk
   	pkgsrc/converters/libwpg: Makefile buildlink3.mk
   	pkgsrc/converters/libwps: Makefile buildlink3.mk
   	pkgsrc/converters/libzmf: Makefile
   	pkgsrc/converters/orcus: Makefile
   	pkgsrc/converters/rss2html: Makefile
   	pkgsrc/databases/couchdb: Makefile
   	pkgsrc/databases/freetds: Makefile buildlink3.mk
   	pkgsrc/databases/libcassandra: Makefile
   	pkgsrc/databases/mariadb104-client: Makefile
   	pkgsrc/databases/mariadb104-server: Makefile
   	pkgsrc/databases/mariadb105-client: Makefile
   	pkgsrc/databases/mariadb105-server: Makefile
   	pkgsrc/databases/mariadb106-client: Makefile
   	pkgsrc/databases/mariadb106-server: Makefile
   	pkgsrc/databases/mongodb: Makefile
   	pkgsrc/databases/mongodb3: Makefile
   	pkgsrc/databases/mysql-workbench: Makefile
   	pkgsrc/databases/mysql57-client: Makefile
   	pkgsrc/databases/mysql57-server: Makefile
   	pkgsrc/databases/p5-DBD-Sybase: Makefile
   	pkgsrc/databases/p5-sqlrelay: Makefile
   	pkgsrc/databases/p5-sybperl: Makefile
   	pkgsrc/databases/php-mssql: Makefile
   	pkgsrc/databases/php-pdo_dblib: Makefile
   	pkgsrc/databases/php-sqlrelay: Makefile
   	pkgsrc/databases/postgresql-postgis2: Makefile
   	pkgsrc/databases/py-mssql: Makefile
   	pkgsrc/databases/py-sqlrelay: Makefile
   	pkgsrc/databases/py-sybase: Makefile
   	pkgsrc/databases/qore-freetds-module: Makefile
   	pkgsrc/databases/ruby-sqlrelay: Makefile
   	pkgsrc/databases/ruby-tiny_tds: Makefile
   	pkgsrc/databases/soci: Makefile
   	pkgsrc/databases/sqlrelay: Makefile buildlink3.mk
   	pkgsrc/databases/sqlrelay-freetds: Makefile
   	pkgsrc/databases/sqlrelay-mysql: Makefile
   	pkgsrc/databases/sqlrelay-nodejs: Makefile
   	pkgsrc/databases/sqlrelay-odbc: Makefile
   	pkgsrc/databases/sqlrelay-pgsql: Makefile
   	pkgsrc/databases/sqlrelay-sqlite: Makefile
   	pkgsrc/databases/sqsh: Makefile
   	pkgsrc/databases/virtuoso: Makefile
   	pkgsrc/devel/aegis: Makefile
   	pkgsrc/devel/cfitsio: Makefile
   	pkgsrc/devel/cmake: Makefile
   	pkgsrc/devel/cmake-gui: Makefile
   	pkgsrc/devel/darcs: Makefile
   	pkgsrc/devel/ecore: Makefile buildlink3.mk
   	pkgsrc/devel/eio: Makefile buildlink3.mk
   	pkgsrc/devel/exempi: Makefile
   	pkgsrc/devel/fifengine: Makefile
   	pkgsrc/devel/gearmand: Makefile buildlink3.mk
   	pkgsrc/devel/git-base: Makefile
   	pkgsrc/devel/gnustep-base: Makefile
   	pkgsrc/devel/kdesdk-kioslaves: Makefile
   	pkgsrc/devel/kdesdk-strigi-analyzers: Makefile
   	pkgsrc/devel/kdesdk-thumbnailers: Makefile
   	pkgsrc/devel/kdevelop4: Makefile
   	pkgsrc/devel/kdevplatform: Makefile
   	pkgsrc/devel/kio-extras: Makefile
   	pkgsrc/devel/libcutl: Makefile
   	pkgsrc/devel/libftdi1: Makefile
   	pkgsrc/devel/libgit2: Makefile
   	pkgsrc/devel/libkgapi: Makefile
   	pkgsrc/devel/librelp: Makefile buildlink3.mk
   	pkgsrc/devel/libthrift: Makefile
   	pkgsrc/devel/libxenserver: Makefile buildlink3.mk
   	pkgsrc/devel/mad-flute: Makefile
   	pkgsrc/devel/mdds: Makefile
   	pkgsrc/devel/mdds1.2: Makefile
   	pkgsrc/devel/netcdf: Makefile buildlink3.mk
   	pkgsrc/devel/netcdf-cxx: Makefile buildlink3.mk
   	pkgsrc/devel/netcdf-fortran: Makefile buildlink3.mk
   	pkgsrc/devel/okteta: Makefile
   	pkgsrc/devel/php-gearman: Makefile
   	pkgsrc/devel/radare2: Makefile buildlink3.mk
   	pkgsrc/devel/radare2-cutter: Makefile
   	pkgsrc/devel/rudiments: Makefile buildlink3.mk
   	pkgsrc/devel/sdcc3: Makefile
   	pkgsrc/devel/ucommon: Makefile buildlink3.mk
   	pkgsrc/devel/vera++: Makefile
   	pkgsrc/editors/Sigil: Makefile
   	pkgsrc/editors/TeXmacs: Makefile
   	pkgsrc/editors/abiword: Makefile buildlink3.mk
   	pkgsrc/editors/abiword-plugins: Makefile
   	pkgsrc/editors/codelite: Makefile
   	pkgsrc/editors/emacs25: Makefile
   	pkgsrc/editors/emacs26: Makefile
   	pkgsrc/editors/emacs27: Makefile
   	pkgsrc/editors/gobby: Makefile
   	pkgsrc/editors/lyx: Makefile
   	pkgsrc/editors/obby: Makefile buildlink3.mk
   	pkgsrc/editors/poedit: Makefile
   	pkgsrc/editors/xournalpp: Makefile
   	pkgsrc/emulators/cannonball: Makefile
   	pkgsrc/emulators/ckmame: Makefile
   	pkgsrc/emulators/dolphin-emu: Makefile
   	pkgsrc/emulators/emulationstation: Makefile
   	pkgsrc/emulators/libretro-dolphin: Makefile
   	pkgsrc/emulators/mgba: Makefile
   	pkgsrc/emulators/qemu: Makefile
   	pkgsrc/emulators/wine: Makefile
   	pkgsrc/filesystems/cloudfuse: Makefile
   	pkgsrc/filesystems/fuse-curlftpfs: Makefile
   	pkgsrc/filesystems/fuse-wdfs: Makefile
   	pkgsrc/finance/QuantLib: Makefile
   	pkgsrc/finance/bitcoin: Makefile
   	pkgsrc/finance/cpuminer: Makefile
   	pkgsrc/finance/gnucash: Makefile
   	pkgsrc/finance/ledger: Makefile
   	pkgsrc/finance/libofx: Makefile
   	pkgsrc/fonts/ghostscript-cidfonts-ryumin: Makefile
   	pkgsrc/games/7kaa: Makefile
   	pkgsrc/games/amor: Makefile
   	pkgsrc/games/asc: Makefile
   	pkgsrc/games/assaultcube: Makefile
   	pkgsrc/games/bastet: Makefile
   	pkgsrc/games/bzflag: Makefile
   	pkgsrc/games/criticalmass: Makefile
   	pkgsrc/games/crossfire-client: Makefile
   	pkgsrc/games/crossfire-server: Makefile
   	pkgsrc/games/dhewm3: Makefile
   	pkgsrc/games/dopewars: Makefile
   	pkgsrc/games/enigma: Makefile
   	pkgsrc/games/etlegacy: Makefile
   	pkgsrc/games/etlegacy-server: Makefile
   	pkgsrc/games/flightgear: Makefile
   	pkgsrc/games/freeciv-client: Makefile
   	pkgsrc/games/freeciv-server: Makefile
   	pkgsrc/games/freeciv-share: Makefile
   	pkgsrc/games/ggz-client-libs: Makefile buildlink3.mk
   	pkgsrc/games/holtz: Makefile
   	pkgsrc/games/ioquake3: Makefile
   	pkgsrc/games/iortcw: Makefile
   	pkgsrc/games/klavaro: Makefile
   	pkgsrc/games/lgogdownloader: Makefile
   	pkgsrc/games/libggz: Makefile buildlink3.mk
   	pkgsrc/games/manaplus: Makefile
   	pkgsrc/games/megaglest: Makefile
   	pkgsrc/games/minetest: Makefile
   	pkgsrc/games/naev: Makefile
   	pkgsrc/games/openmw: Makefile
   	pkgsrc/games/openrct2: Makefile
   	pkgsrc/games/pingus: Makefile
   	pkgsrc/games/powder-toy: Makefile
   	pkgsrc/games/quakeforge: Makefile
   	pkgsrc/games/scummvm: Makefile
   	pkgsrc/games/scummvm-tools: Makefile
   	pkgsrc/games/simgear: Makefile buildlink3.mk
   	pkgsrc/games/supertux: Makefile
   	pkgsrc/games/supertuxkart: Makefile
   	pkgsrc/games/taisei: Makefile
   	pkgsrc/games/ufoai: Makefile
   	pkgsrc/games/violetland: Makefile
   	pkgsrc/games/warmux: Makefile
   	pkgsrc/games/warzone2100: Makefile
   	pkgsrc/games/wesnoth: Makefile
   	pkgsrc/games/widelands: Makefile
   	pkgsrc/games/yquake2: Makefile
   	pkgsrc/geography/R-rgdal: Makefile
   	pkgsrc/geography/R-sf: Makefile
   	pkgsrc/geography/gdal-lib: Makefile buildlink3.mk
   	pkgsrc/geography/mapserver: Makefile
   	pkgsrc/geography/merkaartor: Makefile
   	pkgsrc/geography/opencpn: Makefile
   	pkgsrc/geography/osm2pgsql: Makefile
   	pkgsrc/geography/pdal-lib: Makefile buildlink3.mk
   	pkgsrc/geography/py-gdal: Makefile
   	pkgsrc/geography/qgis: Makefile
   	pkgsrc/geography/qlandkartegt: Makefile
   	pkgsrc/geography/qlandkartem: Makefile
   	pkgsrc/geography/viking: Makefile
   	pkgsrc/graphics/GMT: Makefile
   	pkgsrc/graphics/GraphicsMagick: Makefile buildlink3.mk
   	pkgsrc/graphics/ImageMagick: Makefile buildlink3.mk
   	pkgsrc/graphics/ImageMagick6: Makefile buildlink3.mk
   	pkgsrc/graphics/aqsis: Makefile
   	pkgsrc/graphics/autotrace: Makefile
   	pkgsrc/graphics/blender: Makefile
   	pkgsrc/graphics/blender-lts: Makefile
   	pkgsrc/graphics/camlimages: Makefile
   	pkgsrc/graphics/darktable: Makefile
   	pkgsrc/graphics/digikam: Makefile
   	pkgsrc/graphics/drawpile: Makefile
   	pkgsrc/graphics/dx: Makefile
   	pkgsrc/graphics/edje: Makefile buildlink3.mk
   	pkgsrc/graphics/enblend-enfuse: Makefile
   	pkgsrc/graphics/feh: Makefile
   	pkgsrc/graphics/gimmage: Makefile
   	pkgsrc/graphics/gmic: Makefile
   	pkgsrc/graphics/gource: Makefile
   	pkgsrc/graphics/gpick: Makefile
   	pkgsrc/graphics/graphviz: Makefile
   	pkgsrc/graphics/gri: Makefile
   	pkgsrc/graphics/hugin: Makefile
   	pkgsrc/graphics/jp2a: Makefile
   	pkgsrc/graphics/kde-base-artwork: Makefile
   	pkgsrc/graphics/kdegraphics-strigi-analyzer: Makefile
   	pkgsrc/graphics/kgamma: Makefile
   	pkgsrc/graphics/koverartist: Makefile
   	pkgsrc/graphics/kqtquickcharts4: Makefile
   	pkgsrc/graphics/krita: Makefile
   	pkgsrc/graphics/libgltf: Makefile
   	pkgsrc/graphics/libkexiv2-kde4: Makefile
   	pkgsrc/graphics/libsixel: Makefile
   	pkgsrc/graphics/lsix: Makefile
   	pkgsrc/graphics/luminance-hdr: Makefile
   	pkgsrc/graphics/ncview: Makefile
   	pkgsrc/graphics/openimageio: Makefile buildlink3.mk
   	pkgsrc/graphics/osg: Makefile buildlink3.mk
   	pkgsrc/graphics/p5-GraphicsMagick: Makefile
   	pkgsrc/graphics/p5-PerlMagick: Makefile
   	pkgsrc/graphics/pcl: Makefile buildlink3.mk
   	pkgsrc/graphics/pfstools: Makefile
   	pkgsrc/graphics/php-imagick: Makefile
   	pkgsrc/graphics/pstoedit: Makefile
   	pkgsrc/graphics/ruby-RMagick: Makefile
   	pkgsrc/graphics/sane-airscan: Makefile
   	pkgsrc/graphics/shotwell: Makefile
   	pkgsrc/graphics/tango-icon-theme: Makefile
   	pkgsrc/graphics/vtk: Makefile buildlink3.mk
   	pkgsrc/graphics/zbar: Makefile
   	pkgsrc/graphics/zphoto: Makefile
   	pkgsrc/ham/fldigi: Makefile
   	pkgsrc/ham/gnuradio-channels: Makefile
   	pkgsrc/ham/gnuradio-companion: Makefile
   	pkgsrc/ham/gnuradio-core: Makefile
   	pkgsrc/ham/gnuradio-ctrlport: Makefile
   	pkgsrc/ham/gnuradio-digital: Makefile
   	pkgsrc/ham/gnuradio-doxygen: Makefile
   	pkgsrc/ham/gnuradio-dtv: Makefile
   	pkgsrc/ham/gnuradio-fec: Makefile
   	pkgsrc/ham/gnuradio-network: Makefile
   	pkgsrc/ham/gnuradio-qtgui: Makefile
   	pkgsrc/ham/gnuradio-soapy-sdr: Makefile
   	pkgsrc/ham/gnuradio-trellis: Makefile
   	pkgsrc/ham/gnuradio-uhd: Makefile
   	pkgsrc/ham/gnuradio-utils: Makefile
   	pkgsrc/ham/gnuradio-video-sdl: Makefile
   	pkgsrc/ham/gnuradio-vocoder: Makefile
   	pkgsrc/ham/gnuradio-wavelet: Makefile
   	pkgsrc/ham/gnuradio-zeromq: Makefile
   	pkgsrc/ham/gpredict: Makefile
   	pkgsrc/ham/gr-fcdproplus: Makefile
   	pkgsrc/ham/gr-osmosdr: Makefile
   	pkgsrc/ham/trustedQSL: Makefile
   	pkgsrc/ham/uhd: Makefile
   	pkgsrc/inputmethod/fcitx5-chinese-addons: Makefile
   	pkgsrc/inputmethod/fcitx5-mozc: Makefile
   	pkgsrc/inputmethod/fcitx5-table-extra: Makefile
   	pkgsrc/inputmethod/fcitx5-table-other: Makefile
   	pkgsrc/inputmethod/ibus-mozc: Makefile
   	pkgsrc/inputmethod/libime: Makefile
   	pkgsrc/inputmethod/librime: Makefile
   	pkgsrc/inputmethod/mozc-elisp: Makefile
   	pkgsrc/inputmethod/mozc-renderer: Makefile
   	pkgsrc/inputmethod/mozc-server: Makefile
   	pkgsrc/inputmethod/mozc-tool: Makefile
   	pkgsrc/inputmethod/uim-mozc: Makefile
   	pkgsrc/lang/konoha: Makefile
   	pkgsrc/lang/nodejs10: Makefile buildlink3.mk
   	pkgsrc/lang/nodejs12: Makefile buildlink3.mk
   	pkgsrc/lang/openjdk11: Makefile
   	pkgsrc/lang/openjdk8: Makefile
   	pkgsrc/lang/rust: Makefile
   	pkgsrc/mail/akonadi: Makefile
   	pkgsrc/mail/balsa: Makefile
   	pkgsrc/mail/claws-mail: Makefile
   	pkgsrc/mail/claws-mail-archive: Makefile
   	pkgsrc/mail/claws-mail-attachwarner: Makefile
   	pkgsrc/mail/claws-mail-attremover: Makefile
   	pkgsrc/mail/claws-mail-bogofilter: Makefile
   	pkgsrc/mail/claws-mail-dillo: Makefile
   	pkgsrc/mail/claws-mail-fetchinfo: Makefile
   	pkgsrc/mail/claws-mail-libravatar: Makefile
   	pkgsrc/mail/claws-mail-mailmbox: Makefile
   	pkgsrc/mail/claws-mail-managesieve: Makefile
   	pkgsrc/mail/claws-mail-newmail: Makefile
   	pkgsrc/mail/claws-mail-notification: Makefile
   	pkgsrc/mail/claws-mail-pgpcore: Makefile
   	pkgsrc/mail/claws-mail-pgpinline: Makefile
   	pkgsrc/mail/claws-mail-pgpmime: Makefile
   	pkgsrc/mail/claws-mail-rssyl: Makefile
   	pkgsrc/mail/claws-mail-smime: Makefile
   	pkgsrc/mail/claws-mail-spamassassin: Makefile
   	pkgsrc/mail/claws-mail-spamreport: Makefile
   	pkgsrc/mail/claws-mail-tnef: Makefile
   	pkgsrc/mail/claws-mail-vcalendar: Makefile
   	pkgsrc/mail/cone: Makefile
   	pkgsrc/mail/evolution-data-server: Makefile
   	pkgsrc/mail/libetpan: Makefile buildlink3.mk
   	pkgsrc/mail/mailfront: Makefile
   	pkgsrc/mail/milter-greylist: Makefile
   	pkgsrc/mail/mpop: Makefile
   	pkgsrc/mail/msmtp: Makefile
   	pkgsrc/mail/mutt: Makefile
   	pkgsrc/mail/nmh: Makefile
   	pkgsrc/mail/nullmailer: Makefile
   	pkgsrc/mail/wmbiff: Makefile
   	pkgsrc/mail/xfce4-mailwatch-plugin: Makefile
   	pkgsrc/math/R: Makefile
   	pkgsrc/math/R-CGIwithR: Makefile
   	pkgsrc/math/R-RNetCDF: Makefile
   	pkgsrc/math/R-ncdf: Makefile
   	pkgsrc/math/R-ncdf4: Makefile
   	pkgsrc/math/cantor: Makefile
   	pkgsrc/math/cgal: Makefile buildlink3.mk
   	pkgsrc/math/grace: Makefile
   	pkgsrc/math/libixion: Makefile
   	pkgsrc/math/octave: Makefile
   	pkgsrc/math/py-Scientific: Makefile
   	pkgsrc/math/py-libixion: Makefile
   	pkgsrc/math/py-netCDF4: Makefile
   	pkgsrc/math/qalculate: Makefile buildlink3.mk
   	pkgsrc/math/qalculate-gtk: Makefile
   	pkgsrc/math/sc-im: Makefile
   	pkgsrc/math/volk: Makefile
   	pkgsrc/math/vowpal_wabbit: Makefile
   	pkgsrc/math/xmgr: Makefile
   	pkgsrc/misc/bibletime: Makefile
   	pkgsrc/misc/esniper: Makefile
   	pkgsrc/misc/fbreader: Makefile
   	pkgsrc/misc/gwaei: Makefile
   	pkgsrc/misc/kaccessible: Makefile
   	pkgsrc/misc/kchmviewer: Makefile
   	pkgsrc/misc/kde-wallpapers4: Makefile
   	pkgsrc/misc/kdeartwork4: Makefile
   	pkgsrc/misc/kdepim-runtime4: Makefile
   	pkgsrc/misc/kdepim4: Makefile
   	pkgsrc/misc/kdepimlibs4: Makefile buildlink3.mk
   	pkgsrc/misc/kdeplasma-addons4: Makefile
   	pkgsrc/misc/kremotecontrol: Makefile
   	pkgsrc/misc/kstars: Makefile
   	pkgsrc/misc/ktux: Makefile
   	pkgsrc/misc/libcarddav: Makefile
   	pkgsrc/misc/libkdeedu: Makefile buildlink3.mk
   	pkgsrc/misc/libreoffice: Makefile
   	pkgsrc/misc/ocaml-opam: Makefile
   	pkgsrc/misc/parley: Makefile
   	pkgsrc/misc/rocs: Makefile
   	pkgsrc/misc/step: Makefile
   	pkgsrc/misc/superkaramba: Makefile
   	pkgsrc/misc/sweeper: Makefile
   	pkgsrc/misc/sword: Makefile buildlink3.mk
   	pkgsrc/misc/usbprog: Makefile
   	pkgsrc/misc/wandio: Makefile buildlink3.mk
   	pkgsrc/multimedia/audiocd-kio: Makefile
   	pkgsrc/multimedia/dvdauthor: Makefile
   	pkgsrc/multimedia/ffmpeg2: Makefile
   	pkgsrc/multimedia/ffmpeg3: Makefile
   	pkgsrc/multimedia/ffmpeg4: Makefile
   	pkgsrc/multimedia/ffmpegthumbs: Makefile
   	pkgsrc/multimedia/gnome-mplayer: Makefile
   	pkgsrc/multimedia/gpac: Makefile
   	pkgsrc/multimedia/kscd: Makefile
   	pkgsrc/multimedia/libkcddb: Makefile buildlink3.mk
   	pkgsrc/multimedia/lightspark: Makefile
   	pkgsrc/multimedia/mediatomb: Makefile
   	pkgsrc/multimedia/mkvtoolnix: Makefile
   	pkgsrc/multimedia/mkvtoolnix-old: Makefile
   	pkgsrc/multimedia/mplayerthumbs: Makefile
   	pkgsrc/multimedia/nostt: Makefile
   	pkgsrc/multimedia/obs-studio: Makefile
   	pkgsrc/multimedia/omxplayer: Makefile
   	pkgsrc/multimedia/totem: Makefile
   	pkgsrc/multimedia/transcode: Makefile
   	pkgsrc/multimedia/vlc: Makefile
   	pkgsrc/multimedia/xine-lib: Makefile
   	pkgsrc/multimedia/xine-ui: Makefile
   	pkgsrc/net/aiccu: Makefile
   	pkgsrc/net/bbk_cli: Makefile
   	pkgsrc/net/btget: Makefile
   	pkgsrc/net/cclive: Makefile
   	pkgsrc/net/ccrtp: Makefile buildlink3.mk
   	pkgsrc/net/choqok: Makefile
   	pkgsrc/net/chrony: Makefile
   	pkgsrc/net/dc_gui2: Makefile
   	pkgsrc/net/deforaos-vncviewer: Makefile
   	pkgsrc/net/doh: Makefile
   	pkgsrc/net/ettercap: Makefile
   	pkgsrc/net/ettercap-gtk: Makefile
   	pkgsrc/net/filezilla: Makefile
   	pkgsrc/net/flickcurl: Makefile
   	pkgsrc/net/freeDiameter: Makefile
   	pkgsrc/net/freeradius-freetds: Makefile
   	pkgsrc/net/freeradius-rest: Makefile
   	pkgsrc/net/glib-networking: Makefile
   	pkgsrc/net/grilo: Makefile buildlink3.mk
   	pkgsrc/net/grilo-plugins: Makefile
   	pkgsrc/net/grive2: Makefile
   	pkgsrc/net/gst-plugins0.10-rtmp: Makefile
   	pkgsrc/net/gst-plugins1-rtmp: Makefile
   	pkgsrc/net/gtk-gnutella: Makefile
   	pkgsrc/net/gtk-vnc: Makefile buildlink3.mk
   	pkgsrc/net/guacamole-server: Makefile
   	pkgsrc/net/icinga2: Makefile
   	pkgsrc/net/jigdo: Makefile
   	pkgsrc/net/kdenetwork-filesharing: Makefile
   	pkgsrc/net/kdenetwork-strigi-analyzers: Makefile
   	pkgsrc/net/kget: Makefile
   	pkgsrc/net/kmldonkey: Makefile
   	pkgsrc/net/knot: Makefile
   	pkgsrc/net/kopete: Makefile
   	pkgsrc/net/kppp: Makefile
   	pkgsrc/net/krdc: Makefile
   	pkgsrc/net/krfb: Makefile
   	pkgsrc/net/ktorrent: Makefile
   	pkgsrc/net/lftp: Makefile
   	pkgsrc/net/libcmis: Makefile
   	pkgsrc/net/libfilezilla: Makefile
   	pkgsrc/net/libgdata: Makefile buildlink3.mk
   	pkgsrc/net/libktorrent: Makefile buildlink3.mk
   	pkgsrc/net/libquvi: Makefile
   	pkgsrc/net/libtorrent-rasterbar: Makefile buildlink3.mk
   	pkgsrc/net/libtrace: Makefile
   	pkgsrc/net/libvncserver: Makefile buildlink3.mk
   	pkgsrc/net/libzrtpcpp: Makefile buildlink3.mk
   	pkgsrc/net/megatools: Makefile
   	pkgsrc/net/nanotodon: Makefile
   	pkgsrc/net/ncdc: Makefile
   	pkgsrc/net/net6: Makefile buildlink3.mk
   	pkgsrc/net/netatalk22: Makefile
   	pkgsrc/net/netatalk3: Makefile
   	pkgsrc/net/ntopng: Makefile
   	pkgsrc/net/ocamlnet: Makefile
   	pkgsrc/net/ocsync: Makefile buildlink3.mk
   	pkgsrc/net/openvpn: Makefile
   	pkgsrc/net/podcastdl: Makefile
   	pkgsrc/net/powerdns: Makefile
   	pkgsrc/net/py-smbc: Makefile
   	pkgsrc/net/qbittorrent: Makefile
   	pkgsrc/net/quvi: Makefile
   	pkgsrc/net/rdesktop: Makefile
   	pkgsrc/net/remmina: Makefile
   	pkgsrc/net/rtmpdump: Makefile buildlink3.mk
   	pkgsrc/net/rtorrent: Makefile
   	pkgsrc/net/samba: Makefile
   	pkgsrc/net/samba4: Makefile buildlink3.mk
   	pkgsrc/net/snort: Makefile
   	pkgsrc/net/synergy: Makefile
   	pkgsrc/net/taskserver: Makefile
   	pkgsrc/net/tcpflow: Makefile
   	pkgsrc/net/tigervnc: Makefile
   	pkgsrc/net/transmission: Makefile
   	pkgsrc/net/transmission-gtk: Makefile
   	pkgsrc/net/transmission-qt: Makefile
   	pkgsrc/net/unbound: Makefile buildlink3.mk
   	pkgsrc/net/urlgfe: Makefile
   	pkgsrc/net/vinagre: Makefile
   	pkgsrc/net/vino: Makefile
   	pkgsrc/net/wget: Makefile
   	pkgsrc/net/wireshark: Makefile
   	pkgsrc/net/wmget: Makefile
   	pkgsrc/net/zeroconf-ioslave: Makefile
   	pkgsrc/news/neix: Makefile
   	pkgsrc/news/newsbeuter: Makefile
   	pkgsrc/news/pan: Makefile
   	pkgsrc/parallel/slurm-wlm: Makefile
   	pkgsrc/print/auctex: Makefile
   	pkgsrc/print/brlaser: Makefile
   	pkgsrc/print/cups: Makefile
   	pkgsrc/print/cups-base: Makefile buildlink3.mk
   	pkgsrc/print/cups-drivers-Magicolor5440DL: Makefile
   	pkgsrc/print/cups-filters: Makefile buildlink3.mk
   	pkgsrc/print/cups-pdf: Makefile
   	pkgsrc/print/dspdfviewer: Makefile
   	pkgsrc/print/epdfview: Makefile
   	pkgsrc/print/ghostscript: Makefile buildlink3.mk
   	pkgsrc/print/ghostscript-gpl: Makefile buildlink3.mk
   	pkgsrc/print/gtklp: Makefile
   	pkgsrc/print/gutenprint-lib: Makefile
   	pkgsrc/print/hplip: Makefile
   	pkgsrc/print/libcups: Makefile buildlink3.mk
   	pkgsrc/print/mupdf: Makefile buildlink3.mk
   	pkgsrc/print/okular: Makefile
   	pkgsrc/print/p5-Net-CUPS: Makefile
   	pkgsrc/print/pdf2djvu: Makefile
   	pkgsrc/print/py-cups: Makefile
   	pkgsrc/print/qpdfview: Makefile
   	pkgsrc/print/scribus-qt4: Makefile
   	pkgsrc/print/scribus-qt5: Makefile
   	pkgsrc/print/xpdf4: Makefile
   	pkgsrc/print/xpp: Makefile
   	pkgsrc/print/zathura-pdf-mupdf: Makefile
   	pkgsrc/security/ap-modsecurity2: Makefile
   	pkgsrc/security/botan-devel: Makefile buildlink3.mk
   	pkgsrc/security/clamav: Makefile
   	pkgsrc/security/dirb: Makefile
   	pkgsrc/security/gnupg: Makefile
   	pkgsrc/security/gnupg-pkcs11-scd: Makefile
   	pkgsrc/security/gnupg2: Makefile
   	pkgsrc/security/gnutls: Makefile buildlink3.mk
   	pkgsrc/security/gsasl: Makefile
   	pkgsrc/security/kgpg: Makefile
   	pkgsrc/security/lastpass-cli: Makefile
   	pkgsrc/security/libfprint: Makefile
   	pkgsrc/security/liboauth: Makefile buildlink3.mk
   	pkgsrc/security/libprelude: Makefile buildlink3.mk
   	pkgsrc/security/libprelude-lua: Makefile
   	pkgsrc/security/libprelude-perl: Makefile
   	pkgsrc/security/libprelude-python: Makefile
   	pkgsrc/security/libpreludedb: Makefile buildlink3.mk
   	pkgsrc/security/libpreludedb-mysql: Makefile
   	pkgsrc/security/libpreludedb-perl: Makefile
   	pkgsrc/security/libpreludedb-pgsql: Makefile
   	pkgsrc/security/libpreludedb-python: Makefile
   	pkgsrc/security/libpreludedb-sqlite3: Makefile
   	pkgsrc/security/libykneomgr: Makefile
   	pkgsrc/security/opendnssec2: Makefile
   	pkgsrc/security/opensaml: Makefile
   	pkgsrc/security/openvas-libnasl: Makefile
   	pkgsrc/security/openvas-libraries: Makefile
   	pkgsrc/security/openvas-plugins: Makefile
   	pkgsrc/security/openvas-server: Makefile
   	pkgsrc/security/pam-yubico: Makefile
   	pkgsrc/security/php-oauth: Makefile
   	pkgsrc/security/php-oauth1: Makefile
   	pkgsrc/security/pkcs11-helper: Makefile buildlink3.mk
   	pkgsrc/security/prelude-lml: Makefile
   	pkgsrc/security/prelude-manager: Makefile
   	pkgsrc/security/prelude-pflogger: Makefile
   	pkgsrc/security/rvault: Makefile
   	pkgsrc/security/softhsm2: Makefile buildlink3.mk
   	pkgsrc/security/ykclient: Makefile buildlink3.mk
   	pkgsrc/sysutils/baloo: Makefile
   	pkgsrc/sysutils/cfengine3: Makefile
   	pkgsrc/sysutils/collectd-curl: Makefile
   	pkgsrc/sysutils/collectd-riemann: Makefile
   	pkgsrc/sysutils/collectd-virt: Makefile
   	pkgsrc/sysutils/collectd-write_prometheus: Makefile
   	pkgsrc/sysutils/conky: Makefile
   	pkgsrc/sysutils/edbus: Makefile buildlink3.mk
   	pkgsrc/sysutils/efreet: Makefile buildlink3.mk
   	pkgsrc/sysutils/gkrellm: Makefile
   	pkgsrc/sysutils/gnome-control-center: Makefile
   	pkgsrc/sysutils/gnome-settings-daemon: Makefile
   	pkgsrc/sysutils/gvfs: Makefile
   	pkgsrc/sysutils/k3b: Makefile
   	pkgsrc/sysutils/kcron: Makefile
   	pkgsrc/sysutils/kfilemetadata: Makefile
   	pkgsrc/sysutils/kfilemetadata5: Makefile
   	pkgsrc/sysutils/kuser: Makefile
   	pkgsrc/sysutils/libbaloo4: Makefile
   	pkgsrc/sysutils/mc: Makefile
   	pkgsrc/sysutils/openxenmanager: Makefile
   	pkgsrc/sysutils/riemann-client: Makefile buildlink3.mk
   	pkgsrc/sysutils/rsyslog: Makefile
   	pkgsrc/sysutils/rsyslog-dbi: Makefile
   	pkgsrc/sysutils/rsyslog-elasticsearch: Makefile
   	pkgsrc/sysutils/rsyslog-gnutls: Makefile
   	pkgsrc/sysutils/rsyslog-gssapi: Makefile
   	pkgsrc/sysutils/rsyslog-kafka: Makefile
   	pkgsrc/sysutils/rsyslog-libgcrypt: Makefile
   	pkgsrc/sysutils/rsyslog-mysql: Makefile
   	pkgsrc/sysutils/rsyslog-omprog: Makefile
   	pkgsrc/sysutils/rsyslog-pgsql: Makefile
   	pkgsrc/sysutils/rsyslog-rabbitmq: Makefile
   	pkgsrc/sysutils/rsyslog-relp: Makefile
   	pkgsrc/sysutils/rsyslog-snmp: Makefile
   	pkgsrc/sysutils/strigi: Makefile buildlink3.mk
   	pkgsrc/sysutils/syslog-ng-curl: Makefile
   	pkgsrc/sysutils/virt-viewer: Makefile
   	pkgsrc/sysutils/zabbix: Makefile
   	pkgsrc/sysutils/zabbix50-agent: Makefile
   	pkgsrc/sysutils/zabbix50-proxy: Makefile
   	pkgsrc/sysutils/zabbix50-server: Makefile
   	pkgsrc/textproc/FlightCrew: Makefile
   	pkgsrc/textproc/dikt: Makefile
   	pkgsrc/textproc/ebook-tools: Makefile buildlink3.mk
   	pkgsrc/textproc/iksemel: Makefile
   	pkgsrc/textproc/libclucene: Makefile buildlink3.mk
   	pkgsrc/textproc/libkolabxml: Makefile buildlink3.mk
   	pkgsrc/textproc/liblrdf: Makefile buildlink3.mk
   	pkgsrc/textproc/libnxml: Makefile buildlink3.mk
   	pkgsrc/textproc/libodfgen: Makefile buildlink3.mk
   	pkgsrc/textproc/lucene++: Makefile
   	pkgsrc/textproc/multimarkdown: Makefile
   	pkgsrc/textproc/odt2tex: Makefile
   	pkgsrc/textproc/p5-Syntax-SourceHighlight: Makefile
   	pkgsrc/textproc/raptor: Makefile buildlink3.mk
   	pkgsrc/textproc/raptor2: Makefile buildlink3.mk
   	pkgsrc/textproc/rasqal: Makefile buildlink3.mk
   	pkgsrc/textproc/redland: Makefile buildlink3.mk
   	pkgsrc/textproc/soprano: Makefile buildlink3.mk
   	pkgsrc/textproc/source-highlight: Makefile buildlink3.mk
   	pkgsrc/textproc/translate-shell: Makefile
   	pkgsrc/textproc/xmlrpc-c: Makefile buildlink3.mk
   	pkgsrc/textproc/xmltooling: Makefile
   	pkgsrc/time/taskwarrior: Makefile
   	pkgsrc/wm/compiz: Makefile
   	pkgsrc/www/R-RCurl: Makefile
   	pkgsrc/www/R-curl: Makefile
   	pkgsrc/www/SOGo: Makefile
   	pkgsrc/www/SOGo4: Makefile
   	pkgsrc/www/ap-auth-openidc: Makefile
   	pkgsrc/www/ap-authnz-crowd: Makefile
   	pkgsrc/www/ap2-auth-mellon: Makefile
   	pkgsrc/www/ap2-passenger: Makefile
   	pkgsrc/www/apache24: Makefile
   	pkgsrc/www/aws: Makefile
   	pkgsrc/www/aws-demos: Makefile
   	pkgsrc/www/cadaver: Makefile
   	pkgsrc/www/curl: Makefile buildlink3.mk
   	pkgsrc/www/elinks: Makefile
   	pkgsrc/www/felinks: Makefile
   	pkgsrc/www/htdavlock: Makefile
   	pkgsrc/www/htmldoc: Makefile
   	pkgsrc/www/kore: Makefile
   	pkgsrc/www/libmicrohttpd: Makefile buildlink3.mk
   	pkgsrc/www/libmrss: Makefile buildlink3.mk
   	pkgsrc/www/lighttpd: Makefile
   	pkgsrc/www/litmus: Makefile
   	pkgsrc/www/lua-curl: Makefile
   	pkgsrc/www/lynx: Makefile
   	pkgsrc/www/neon: Makefile buildlink3.mk
   	pkgsrc/www/netsurf: Makefile
   	pkgsrc/www/nghttp2: buildlink3.mk
   	pkgsrc/www/nspluginwrapper: Makefile
   	pkgsrc/www/ocaml-curl: Makefile
   	pkgsrc/www/p5-Net-Curl: Makefile
   	pkgsrc/www/passenger: Makefile
   	pkgsrc/www/php-curl: Makefile
   	pkgsrc/www/php-http: Makefile
   	pkgsrc/www/php-http3: Makefile
   	pkgsrc/www/py-curl: Makefile
   	pkgsrc/www/rekonq: Makefile
   	pkgsrc/www/ruby-patron: Makefile
   	pkgsrc/www/shibboleth-sp: Makefile
   	pkgsrc/www/sitecopy: Makefile
   	pkgsrc/www/snownews: Makefile
   	pkgsrc/www/squid4: Makefile
   	pkgsrc/www/wwwoffle: Makefile
   	pkgsrc/www/yahttp: Makefile
   	pkgsrc/x11/elementary: Makefile buildlink3.mk
   	pkgsrc/x11/enlightenment: Makefile buildlink3.mk
   	pkgsrc/x11/gtk2: Makefile
   	pkgsrc/x11/gtk3: Makefile
   	pkgsrc/x11/gtk4: Makefile
   	pkgsrc/x11/kactivities: Makefile buildlink3.mk
   	pkgsrc/x11/kactivities-stats: Makefile
   	pkgsrc/x11/kactivities5: Makefile
   	pkgsrc/x11/kde-baseapps4: Makefile
   	pkgsrc/x11/kde-runtime4: Makefile buildlink3.mk
   	pkgsrc/x11/kde-workspace4: Makefile buildlink3.mk
   	pkgsrc/x11/kdelibs4: Makefile buildlink3.mk
   	pkgsrc/x11/libkactivities4: Makefile buildlink3.mk
   	pkgsrc/x11/qt4-libs: Makefile
   	pkgsrc/x11/qt5-qtbase: Makefile
   	pkgsrc/x11/qt5-qtwebengine: Makefile
   	pkgsrc/x11/vte3: Makefile
   	pkgsrc/x11/wmweather: Makefile
   	pkgsrc/x11/x11vnc: Makefile
   	pkgsrc/x11/x2go-client: Makefile
   	pkgsrc/x11/xfce4-tumbler: Makefile
   	pkgsrc/x11/xlockmore: Makefile

   Log Message:
   revbump for boost-libs

---
   Module Name:	pkgsrc
   Committed By:	adam
   Date:		Fri Oct  8 13:20:34 UTC 2021

   Modified Files:
   	pkgsrc/net/samba4: Makefile PLIST distinfo

   Log Message:
   samba4: updated to 4.13.12

   Changes since 4.13.11
   ---------------------
   * BUG 14806: Address a signifcant performance regression in database access
     in the AD DC since Samba 4.12.
   * BUG 14807: Fix performance regression in lsa_LookupSids3/LookupNames4 since
     Samba 4.9 by using an explicit database handle cache.
   * BUG 14817: An unuthenticated user can crash the AD DC KDC by omitting the
     server name in a TGS-REQ.
   * BUG 14818: Address flapping samba_tool_drs_showrepl test.
   * BUG 14819: Address flapping dsdb_schema_attributes test.
   * BUG 14817: An unuthenticated user can crash the AD DC KDC by omitting the
     server name in a TGS-REQ
   * BUG 14817: An unuthenticated user can crash the AD DC KDC by omitting the
     server name in a TGS-REQ.
   * BUG 14817: An unuthenticated user can crash the AD DC KDC by omitting the
     server name in a TGS-REQ.
   * BUG 14817: An unuthenticated user can crash the AD DC KDC by omitting the
     server name in a TGS-REQ.
   * BUG 14817: An unuthenticated user can crash the AD DC KDC by omitting the
     server name in a TGS-REQ.
   * BUG 14817: An unuthenticated user can crash the AD DC KDC by omitting the
     server name in a TGS-REQ.
   * BUG 14784: Fix CTDB flag/status update race conditions.
   * BUG 14817: An unuthenticated user can crash the AD DC KDC by omitting the
     server name in a TGS-REQ.

---
   Module Name:	pkgsrc
   Committed By:	adam
   Date:		Wed Nov 10 13:33:20 UTC 2021

   Modified Files:
   	pkgsrc/net/samba4: Makefile PLIST distinfo

   Log Message:
   samba4: updated to 4.13.14

   Changes since 4.13.13
   ---------------------

   o  Douglas Bagnall <douglas.bagnall@@catalyst.net.nz>
      * CVE-2020-25722

   o  Andrew Bartlett <abartlet@@samba.org>
      * CVE-2020-25718
      * CVE-2020-25719
      * CVE-2020-25721
      * CVE-2020-25722

   o  Ralph Boehme <slow@@samba.org>
      * CVE-2020-25717

   o  Alexander Bokovoy <ab@@samba.org>
      * CVE-2020-25717

   o  Samuel Cabrero <scabrero@@samba.org>
      * CVE-2020-25717

   o  Nadezhda Ivanova <nivanova@@symas.com>
      * CVE-2020-25722

   o  Stefan Metzmacher <metze@@samba.org>
      * CVE-2016-2124
      * CVE-2020-25717
      * CVE-2020-25719
      * CVE-2020-25722
      * CVE-2021-23192
      * CVE-2021-3738
      * ldb: version 2.2.3

   o  Andreas Schneider <asn@@samba.org>
      * CVE-2020-25719

   o  Joseph Sutton <josephsutton@@catalyst.net.nz>
      * CVE-2020-17049
      * CVE-2020-25718
      * CVE-2020-25719
      * CVE-2020-25721
      * CVE-2020-25722
      * MS CVE-2020-17049

   Changes since 4.13.12
   ---------------------

   o  Douglas Bagnall <douglas.bagnall@@catalyst.net.nz>
      * BUG 14868: rodc_rwdc test flaps.
      * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

   o  Andrew Bartlett <abartlet@@samba.org>
      * BUG 14642: Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze
        bit' S4U2Proxy Constrained Delegation bypass in Samba with
        embedded Heimdal.
      * BUG 14836: Python ldb.msg_diff() memory handling failure.
      * BUG 14845: "in" operator on ldb.Message is case sensitive.
      * BUG 14848: Release LDB 2.3.1 for Samba 4.14.9.
      * BUG 14871: Fix Samba support for UF_NO_AUTH_DATA_REQUIRED.
      * BUG 14874: Allow special chars like "@@" in samAccountName when generating
        the salt.
      * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

   o  Isaac Boukris <iboukris@@gmail.com>
      * BUG 14642: Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze
        bit' S4U2Proxy Constrained Delegation bypass in Samba with
        embedded Heimdal.
      * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

   o  Viktor Dukhovni <viktor@@twosigma.com>
      * BUG 12998: Fix transit path validation.
      * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

   o  Luke Howard <lukeh@@padl.com>
      * BUG 14642: Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze
        bit' S4U2Proxy Constrained Delegation bypass in Samba with
        embedded Heimdal.
      * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

   o  Stefan Metzmacher <metze@@samba.org>
      * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

   o  David Mulder <dmulder@@suse.com>
      * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

   o  Andreas Schneider <asn@@samba.org>
      * BUG 14870: Prepare to operate with MIT krb5 >= 1.20.
      * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

   o  Joseph Sutton <josephsutton@@catalyst.net.nz>
      * BUG 14642: Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze
        bit' S4U2Proxy Constrained Delegation bypass in Samba with
        embedded Heimdal.
      * BUG 14645: rpcclient NetFileEnum and net rpc file both cause lock order
        violation: brlock.tdb, share_entries.tdb.
      * BUG 14836: Python ldb.msg_diff() memory handling failure.
      * BUG 14845: "in" operator on ldb.Message is case sensitive.
      * BUG 14848: Release LDB 2.3.1 for Samba 4.14.9.
      * BUG 14868: rodc_rwdc test flaps.
      * BUG 14871: Fix Samba support for UF_NO_AUTH_DATA_REQUIRED.
      * BUG 14874: Allow special chars like "@@" in samAccountName when generating
        the salt.
      * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

   o  Nicolas Williams <nico@@twosigma.com>
      * BUG 14642: Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze
        bit' S4U2Proxy Constrained Delegation bypass in Samba with
        embedded Heimdal.
      * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.
@
text
@d1 1
a1 1
@@comment $NetBSD$
a227 1
${PYSITELIB}/samba/dcerpc/krb5ccache.so
a391 1
${PYSITELIB}/samba/tests/dcerpc/lsa.py
a416 1
${PYSITELIB}/samba/tests/dsdb_api.py
a436 5
${PYSITELIB}/samba/tests/krb5/alias_tests.py
${PYSITELIB}/samba/tests/krb5/as_canonicalization_tests.py
${PYSITELIB}/samba/tests/krb5/as_req_tests.py
${PYSITELIB}/samba/tests/krb5/compatability_tests.py
${PYSITELIB}/samba/tests/krb5/fast_tests.py
a437 4
${PYSITELIB}/samba/tests/krb5/kdc_base_test.py
${PYSITELIB}/samba/tests/krb5/kdc_tests.py
${PYSITELIB}/samba/tests/krb5/kdc_tgs_tests.py
${PYSITELIB}/samba/tests/krb5/ms_kile_client_principal_lookup_tests.py
a438 1
${PYSITELIB}/samba/tests/krb5/rfc4120_constants.py
a439 1
${PYSITELIB}/samba/tests/krb5/rodc_tests.py
a440 1
${PYSITELIB}/samba/tests/krb5/salt_tests.py
a441 6
${PYSITELIB}/samba/tests/krb5/spn_tests.py
${PYSITELIB}/samba/tests/krb5/test_ccache.py
${PYSITELIB}/samba/tests/krb5/test_ldap.py
${PYSITELIB}/samba/tests/krb5/test_min_domain_uid.py
${PYSITELIB}/samba/tests/krb5/test_rpc.py
${PYSITELIB}/samba/tests/krb5/test_smb.py
a445 2
${PYSITELIB}/samba/tests/ldap_spn.py
${PYSITELIB}/samba/tests/ldap_upn_sam_account.py
a642 1
lib/samba/private/libdcerpc-pkt-auth-samba4.so
@


1.37
log
@net/samba4: handle dbus dependency explicitly on Linux

This manifests as the snapper vfs files appearing depending on dbus
being present or not on Linux, causing PLIST mismatch. This option
actually disables this if desired. The default is still on, as
dbus is to be expected on modern Linux installs anyway.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.36 2021/04/14 19:11:20 adam Exp $
d114 1
d149 1
a149 1
lib/libndr.so.1.0.1
d154 2
a155 2
lib/libsamba-credentials.so.1
lib/libsamba-credentials.so.1.0.0
d175 1
a175 1
lib/libsmbclient.so.0.7.0
a179 1
lib/libsmbldap.so.2.1.0
d208 1
a267 1
${PYSITELIB}/samba/gp_msgs_ext.py
a275 2
${PYSITELIB}/samba/gp_smb_conf_ext.py
${PYSITELIB}/samba/gp_sudoers_ext.py
d341 1
a341 2
${PYSITELIB}/samba/samba3/libsmb_samba_cwrapper.so
${PYSITELIB}/samba/samba3/libsmb_samba_internal.py
a377 2
${PYSITELIB}/samba/tests/blackbox/smbcacls_dfs_propagate_inherit.py
${PYSITELIB}/samba/tests/blackbox/smbcacls_propagate_inhertance.py
a385 1
${PYSITELIB}/samba/tests/cred_opt.py
a389 2
${PYSITELIB}/samba/tests/dcerpc/binding.py
${PYSITELIB}/samba/tests/dcerpc/createtrustrelax.py
a399 1
${PYSITELIB}/samba/tests/dcerpc/samr_change_password.py
a436 2
${PYSITELIB}/samba/tests/krb5/as_canonicalization_tests.py
${PYSITELIB}/samba/tests/krb5/compatability_tests.py
a437 3
${PYSITELIB}/samba/tests/krb5/kdc_base_test.py
${PYSITELIB}/samba/tests/krb5/kdc_tests.py
${PYSITELIB}/samba/tests/krb5/kdc_tgs_tests.py
a438 1
${PYSITELIB}/samba/tests/krb5/rfc4120_constants.py
a525 1
${PYSITELIB}/samba/tests/smb-notify.py
d538 1
a538 1
${PYSITELIB}/samba/trust_utils.py
a541 1
${PYSITELIB}/samba/vgp_sudoers_ext.py
a560 1
lib/samba/krb5/async_dns_krb5_locator.${SOEXT}
@


1.36
log
@samba4: updated to 4.14.2

Samba 4.14.2

This is a follow-up release to depend on the correct ldb version. This is only
needed when building against a system ldb library.

This is a security release in order to address the following defects:

o CVE-2020-27840: Heap corruption via crafted DN strings.
o CVE-2021-20277: Out of bounds read in AD DC LDAP server.


Samba 4.14.1

This is a security release in order to address the following defects:

o CVE-2020-27840: Heap corruption via crafted DN strings.
o CVE-2021-20277: Out of bounds read in AD DC LDAP server.


Samba 4.14.0

This is the first stable release of the Samba 4.14 release series.
Please read the release notes carefully before upgrading.

NEW FEATURES/CHANGES
====================

Here is a copy of a clarification note added to the Samba code
in the file: VFS-License-clarification.txt.
--------------------------------------------------------------

A clarification of our GNU GPL License enforcement boundary within the Samba
Virtual File System (VFS) layer.

Samba is licensed under the GNU GPL. All code committed to the Samba
project or that creates a "modified version" or software "based on" Samba must
be either licensed under the GNU GPL or a compatible license.

Samba has several plug-in interfaces where external code may be called
from Samba GNU GPL licensed code. The most important of these is the
Samba VFS layer.

Samba VFS modules are intimately connected by header files and API
definitions to the part of the Samba code that provides file services,
and as such, code that implements a plug-in Samba VFS module must be
licensed under the GNU GPL or a compatible license.

However, Samba VFS modules may themselves call third-party external
libraries that are not part of the Samba project and are externally
developed and maintained.

As long as these third-party external libraries do not use any of the
Samba internal structure, APIs or interface definitions created by the
Samba project (to the extent that they would be considered subject to the GNU
GPL), then the Samba Team will not consider such third-party external
libraries called from Samba VFS modules as "based on" and/or creating a
"modified version" of the Samba code for the purposes of GNU GPL.
Accordingly, we do not require such libraries be licensed under the GNU GPL
or a GNU GPL compatible license.

VFS
---

The effort to modernize Samba's VFS interface has reached a major milestone with
the next release Samba 4.14.

For details please refer to the documentation at source3/modules/The_New_VFS.txt or
visit the <https://wiki.samba.org/index.php/The_New_VFS>.

Printing
--------

Publishing printers in AD is more reliable and more printer features are
added to the published information in AD. Samba now also supports Windows
drivers for the ARM64 architecture.

Client Group Policy
-------------------
This release extends Samba to support Group Policy functionality for Winbind
clients. Active Directory Administrators can set policies that apply Sudoers
configuration, and cron jobs to run hourly, daily, weekly or monthly.

To enable the application of Group Policies on a client, set the global
smb.conf option 'apply group policies' to 'yes'. Policies are applied on an
interval of every 90 minutes, plus a random offset between 0 and 30 minutes.

Policies applied by Samba are 'non-tattooing', meaning that changes can be
reverted by executing the `samba-gpupdate --unapply` command. Policies can be
re-applied using the `samba-gpupdate --force` command.
To view what policies have been or will be applied to a system, use the
`samba-gpupdate --rsop` command.

Administration of Samba policy requires that a Samba ADMX template be uploaded
to the SYSVOL share. The samba-tool command `samba-tool gpo admxload` is
provided as a convenient method for adding this policy. Once uploaded, policies
can be modified in the Group Policy Management Editor under Computer
Configuration/Policies/Administrative Templates. Alternatively, Samba policy
may be managed using the `samba-tool gpo manage` command. This tool does not
require the admx templates to be installed.

Python 3.6 or later required
----------------------------

Samba's minimum runtime requirement for python was raised to Python
3.6 with samba 4.13.  Samba 4.14 raises this minimum version to Python
3.6 also to build Samba. It is no longer possible to build Samba
(even just the file server) with Python versions 2.6 and 2.7.

As Python 2.7 has been End Of Life upstream since April 2020, Samba
is dropping ALL Python 2.x support in this release.

Miscellaneous samba-tool changes
--------------------------------

The 'samba-tool' subcommands to manage AD objects (e.g. users, computers and
groups) now consistently use the "add" command when adding a new object to
the AD. The previous deprecation warnings when using the 'add' commands
have been removed. For compatibility reasons, both the 'add' and 'create'
commands can be used now.

Users, groups and contacts can now be renamed with the respective rename
commands.

Locked users can be unlocked with the new 'samba-tool user unlock' command.

The 'samba-tool user list' and 'samba-tool group listmembers' commands
provide additional options to hide expired and disabled user accounts
(--hide-expired and --hide-disabled).


CTDB CHANGES
============

* The NAT gateway and LVS features now uses the term "leader" to refer
  to the main node in a group through which traffic is routed and
  "follower" for other members of a group.  The command for
  determining the leader has changed to "ctdb natgw leader" (from
  "ctdb natgw master").  The configuration keyword for indicating that
  a node can not be the leader of a group has changed to
  "follower-only" (from "slave-only").  Identical changes were made
  for LVS.

* Remove "ctdb isnotrecmaster" command.  It isn't used by CTDB's
  scripts and can be checked by users with "ctdb pnn" and "ctdb
  recmaster".
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.35 2021/01/28 13:17:16 adam Exp $
d802 1
d902 1
@


1.35
log
@samba4: fix PLIST
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.34 2020/11/12 06:37:18 adam Exp $
a113 1
include/util/string_wrappers.h
d148 1
a148 1
lib/libndr.so.1.0.0
d153 2
a154 2
lib/libsamba-credentials.so.0
lib/libsamba-credentials.so.0.0.1
d174 1
a174 1
lib/libsmbclient.so.0.6.0
d179 1
a207 1
${PYSITELIB}/samba/compat.py
d267 1
d276 2
d343 2
a344 1
${PYSITELIB}/samba/samba3/libsmb_samba_internal.so
d381 2
d391 1
d396 2
d408 1
d446 2
d449 3
d453 1
d541 1
d554 1
a554 1
${PYSITELIB}/samba/third_party/__init__.py
d558 1
d578 1
@


1.34
log
@samba4: updated to 4.13.2

Changes since 4.13.1
--------------------
   * BUG 14486: s3: modules: vfs_glusterfs: Fix leak of char
     **lines onto mem_ctx on return.
   * BUG 14471: RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special.
   * BUG 14538: smb.conf.5: Add clarification how configuration changes
     reflected by Samba.
   * BUG 14552: daemons: Report status to systemd even when running in
     foreground.
   * BUG 14553: DNS Resolver: Support both dnspython before and after 2.0.0.
   * BUG 14486: s3-vfs_glusterfs: Refuse connection when write-behind xlator is
     present.
   * BUG 14487: provision: Add support for BIND 9.16.x.
   * BUG 14537: ctdb-common: Avoid aliasing errors during code optimization.
   * BUG 14541: libndr: Avoid assigning duplicate versions to symbols.
   * BUG 14522: docs: Fix default value of spoolss:architecture.
   * BUG 14388: winbind: Fix a memleak.
   * BUG 14531: s4:dsdb:acl_read: Implement "List Object" mode feature.
   * BUG 14486: docs-xml/manpages: Add warning about write-behind translator for
     vfs_glusterfs.
   * nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h.
   * BUG 14530: vfs_shadow_copy2: Avoid closing snapsdir twice.
   * BUG 14547: third_party: Update resolv_wrapper to version 1.1.7.
   * BUG 14550: examples:auth: Do not install example plugin.
   * BUG 14513: ctdb-recoverd: Drop unnecessary and broken code.
   * BUG 14471: RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special.

Changes since 4.13.0
--------------------
   * BUG 14434: CVE-2020-14318: s3: smbd: Ensure change notifies can't get set
     unless the directory handle is open for SEC_DIR_LIST.
   * BUG 12795: CVE-2020-14383: Remote crash after adding NS or MX records using
     'samba-tool'.
   * BUG 14472: CVE-2020-14383: Remote crash after adding MX records.
   * BUG 14436: CVE-2020-14323: winbind: Fix invalid lookupsids DoS.

4.31.0:
NEW FEATURES/CHANGES
====================

Python 3.6 or later required
----------------------------
Samba's minimum runtime requirement for python was raised to Python
3.5 with samba 4.12.  Samba 4.13 raises this minimum version to Python
3.6 both to access new features and because this is the oldest version
we test with in our CI infrastructure.

This is also the last release where it will be possible to build Samba
(just the file server) with Python versions 2.6 and 2.7.

As Python 2.7 has been End Of Life upstream since April 2020, Samba
is dropping ALL Python 2.x support in the NEXT release.

Samba 4.14 to be released in March 2021 will require Python 3.6 or
later to build.

wide links functionality
------------------------
For this release, the code implementing the insecure "wide links = yes"
functionality has been moved out of the core smbd code and into a separate
VFS module, vfs_widelinks. Currently this vfs module is implicitly loaded
by smbd as the last but one module before vfs_default if "wide links = yes"
is enabled on the share (note, the existing restrictions on enabling wide
links around the SMB1 "unix extensions" and the "allow insecure wide links"
parameters are still in force). The implicit loading was done to allow
existing users of "wide links = yes" to keep this functionality without
having to make a change to existing working smb.conf files.

Please note that the Samba developers recommend changing any Samba
installations that currently use "wide links = yes" to use bind mounts
as soon as possible, as "wide links = yes" is an inherently insecure
configuration which we would like to remove from Samba. Moving the
feature into a VFS module allows this to be done in a cleaner way
in future.

A future release to be determined will remove this implicit linkage,
causing administrators who need this functionality to have to explicitly
add the vfs_widelinks module into the "vfs objects =" parameter lists.
The release notes will be updated to note this change when it occurs.

NT4-like 'classic' Samba domain controllers
-------------------------------------------
Samba 4.13 deprecates Samba's original domain controller mode.

Sites using Samba as a Domain Controller should upgrade from the
NT4-like 'classic' Domain Controller to a Samba Active Directory DC
to ensure full operation with modern windows clients.

SMBv1 only protocol options deprecated
--------------------------------------
A number of smb.conf parameters for less-secure authentication methods
which are only possible over SMBv1 are deprecated in this release.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.33 2020/08/18 07:39:31 adam Exp $
a721 1
lib/samba/private/libsmbd-conn-samba4.so
@


1.33
log
@samba4: updated to 4.12.6

Changes since 4.12.5
* BUG 14403: s3: libsmb: Fix SMB2 client rename bug to a Windows server.
* BUG 14424: dsdb: Allow "password hash userPassword schemes = CryptSHA256"
  to work on RHEL7.
* BUG 14450: dbcheck: Allow a dangling forward link outside our known NCs.
* BUG 14426: lib/debug: Set the correct default backend loglevel to
  MAX_DEBUG_LEVEL.
* BUG 14428: PANIC: Assert failed in get_lease_type().
* BUG 14422: util: Fix build on AIX by fixing the order of replace.h include.
* BUG 14355: srvsvc_NetFileEnum asserts with open files.
* BUG 14354: KDC breaks with DES keys still in the database and
  msDS-SupportedEncryptionTypes 31 indicating support for it.
* BUG 14427: s3:smbd: Make sure vfs_ChDir() always sets
  conn->cwd_fsp->fh->fd = AT_FDCWD.
* BUG 14428: PANIC: Assert failed in get_lease_type().
* BUG 14358: docs: Fix documentation for require_membership_of of
  pam_winbind.conf.
* BUG 14444: ctdb-scripts: Use nfsconf utility for variable values in CTDB
  NFS scripts.
* BUG 14425: s3:winbind:idmap_ad: Make failure to get attrnames for schema
  mode fatal.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.32 2020/07/28 01:11:10 christos Exp $
a105 1
include/util/byteorder.h
d255 1
d274 1
d376 2
d437 6
d550 2
a784 1
${PLIST.dbus}lib/samba/vfs/snapper.${SOEXT}
d791 1
a883 1
${PLIST.dbus}man/man8/vfs_snapper.8
d890 1
d924 2
a925 1
share/samba/setup/DB_CONFIG
a947 1
share/samba/setup/cn=samba.ldif
a954 5
share/samba/setup/fedorads-index.ldif
share/samba/setup/fedorads-linked-attributes.ldif
share/samba/setup/fedorads-pam.ldif
share/samba/setup/fedorads-samba.ldif
share/samba/setup/fedorads-sasl.ldif
a956 4
share/samba/setup/memberof.conf
share/samba/setup/mmr_serverids.conf
share/samba/setup/mmr_syncrepl.conf
share/samba/setup/modules.conf
a960 5
share/samba/setup/olc_mmr.conf
share/samba/setup/olc_seed.ldif
share/samba/setup/olc_serverid.conf
share/samba/setup/olc_syncrepl.conf
share/samba/setup/olc_syncrepl_seed.conf
a996 3
share/samba/setup/refint.conf
share/samba/setup/schema-map-fedora-ds-1.0
share/samba/setup/schema-map-openldap-2.3
a1000 2
share/samba/setup/secrets_sasl_ldap.ldif
share/samba/setup/secrets_simple_ldap.ldif
@


1.32
log
@Move sysvol from /var/run/sysvol to /var/db/samba4/sysvol as FreeBSD does,
so that the provisioning data gets preserved across reboots.
From Matthias Perelmann
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.31 2020/07/06 14:38:06 adam Exp $
a39 1
@@pkgdir var/db/samba4
d506 3
d1012 1
@


1.31
log
@samba4: updated to 4.12.5

Changes since 4.12.4
--------------------
   * BUG 14301: Fix smbd panic on force-close share during async io.
   * BUG 14374: Fix segfault when using SMBC_opendir_ctx() routine for share
     folder that contains incorrect symbols in any file name.
   * BUG 14391: Fix DFS links.
   * BUG 14310: Can't use DNS functionality after a Windows DC has been in
     domain.
   * BUG 14413: ldapi search to FreeIPA crashes.
   * BUG 14396: Add net-ads-join dnshostname=fqdn option.
   * BUG 14406: Fix adding msDS-AdditionalDnsHostName to keytab with Windows DC.
   * BUG 14386: docs-xml: Update list of posible VFS operations for
     vfs_full_audit.
   * BUG 14382: winbindd: Fix a use-after-free when winbind clients exit.
   * BUG 14370: Client tools are not able to read gencache anymore.

Samba 4.12.4
============
o  CVE-2020-10730:
   A client combining the 'ASQ' and 'VLV' LDAP controls can cause a NULL pointer
   de-reference and further combinations with the LDAP paged_results feature can
   give a use-after-free in Samba's AD DC LDAP server.

o  CVE-2020-10745: Parsing and packing of NBT and DNS packets can consume
   excessive CPU.

o  CVE-2020-10760:
   The use of the paged_results or VLV controls against the Global Catalog LDAP
   server on the AD DC will cause a use-after-free.

o  CVE-2020-14303:
   The AD DC NBT server in Samba 4.0 will enter a CPU spin and not process
   further requests once it receives an empty (zero-length) UDP packet to
   port 137.

For more details, please refer to the security advisories.


Changes since 4.12.3
--------------------
   * BUG 14378: CVE-2020-10745: Invalid DNS or NBT queries containing dots use
     several seconds of CPU each.
   * BUG 14364: CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ
     and VLV combined.
   * BUG 14402: CVE-2020-10760: Fix use-after-free in AD DC Global Catalog LDAP
     server with paged_result or VLV.
   * BUG 14417: CVE-2020-14303: Fix endless loop from empty UDP packet sent to
     AD DC nbt_server.
   * BUG 14364: CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ
     and VLV combined, ldb: Bump version to 2.1.4.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.30 2020/05/19 12:13:51 hauke Exp $
d40 1
@


1.30
log
@The smb.conf(5) man page builds fine on netbsd-9, so re-add it.

This is probably the most important of the Samba man pages, and it
should not have been excluded from the build without a detailed
explanation, "just to make the pkg build".
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.29 2020/04/29 10:01:18 adam Exp $
d407 1
@


1.30.2.1
log
@Pullup ticket #6276 - requested by taca
net/samba4: security fix

Revisions pulled up:
- net/samba4/Makefile                                           1.102
- net/samba4/PLIST                                              1.31
- net/samba4/distinfo                                           1.49
- net/samba4/patches/patch-lib_replace_system_passwd.h          1.1

---
   Module Name:	pkgsrc
   Committed By:	adam
   Date:		Mon Jul  6 14:38:06 UTC 2020

   Modified Files:
   	pkgsrc/net/samba4: Makefile PLIST distinfo
   Added Files:
   	pkgsrc/net/samba4/patches: patch-lib_replace_system_passwd.h

   Log Message:
   samba4: updated to 4.12.5

   Changes since 4.12.4
   --------------------
      * BUG 14301: Fix smbd panic on force-close share during async io.
      * BUG 14374: Fix segfault when using SMBC_opendir_ctx() routine for share
        folder that contains incorrect symbols in any file name.
      * BUG 14391: Fix DFS links.
      * BUG 14310: Can't use DNS functionality after a Windows DC has been in
        domain.
      * BUG 14413: ldapi search to FreeIPA crashes.
      * BUG 14396: Add net-ads-join dnshostname=fqdn option.
      * BUG 14406: Fix adding msDS-AdditionalDnsHostName to keytab with Windows DC.
      * BUG 14386: docs-xml: Update list of posible VFS operations for
        vfs_full_audit.
      * BUG 14382: winbindd: Fix a use-after-free when winbind clients exit.
      * BUG 14370: Client tools are not able to read gencache anymore.

   Samba 4.12.4
   ============
   o  CVE-2020-10730:
      A client combining the 'ASQ' and 'VLV' LDAP controls can cause a NULL pointer
      de-reference and further combinations with the LDAP paged_results feature can
      give a use-after-free in Samba's AD DC LDAP server.

   o  CVE-2020-10745: Parsing and packing of NBT and DNS packets can consume
      excessive CPU.

   o  CVE-2020-10760:
      The use of the paged_results or VLV controls against the Global Catalog LDAP
      server on the AD DC will cause a use-after-free.

   o  CVE-2020-14303:
      The AD DC NBT server in Samba 4.0 will enter a CPU spin and not process
      further requests once it receives an empty (zero-length) UDP packet to
      port 137.

   For more details, please refer to the security advisories.

   Changes since 4.12.3
   --------------------
      * BUG 14378: CVE-2020-10745: Invalid DNS or NBT queries containing dots use
        several seconds of CPU each.
      * BUG 14364: CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ
        and VLV combined.
      * BUG 14402: CVE-2020-10760: Fix use-after-free in AD DC Global Catalog LDAP
        server with paged_result or VLV.
      * BUG 14417: CVE-2020-14303: Fix endless loop from empty UDP packet sent to
        AD DC nbt_server.
      * BUG 14364: CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ
        and VLV combined, ldb: Bump version to 2.1.4.
@
text
@d1 1
a1 1
@@comment $NetBSD$
a406 1
${PYSITELIB}/samba/tests/dns_packet.py
@


1.29
log
@samba4: updated to 4.12.2

Samba 4.12.2
This is a security release in order to address the following defects:
o CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ
o CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.28 2020/04/02 11:21:41 adam Exp $
d812 1
@


1.28
log
@samba4: updated to 4.12.0

samba 4.12.0:

NEW FEATURES/CHANGES
====================

Python 3.5 Required
-------------------

Samba's minimum runtime requirement for python was raised to Python
3.4 with samba 4.11.  Samba 4.12 raises this minimum version to Python
3.5 both to access new features and because this is the oldest version
we test with in our CI infrastructure.

(Build time support for the file server with Python 2.6 has not
changed)

Removing in-tree cryptography: GnuTLS 3.4.7 required
----------------------------------------------------

Samba is making efforts to remove in-tree cryptographic functionality,
and to instead rely on externally maintained libraries.  To this end,
Samba has chosen GnuTLS as our standard cryptographic provider.

Samba now requires GnuTLS 3.4.7 to be installed (including development
headers at build time) for all configurations, not just the Samba AD
DC.

Thanks to this work Samba no longer ships an in-tree DES
implementation and on GnuTLS 3.6.5 or later Samba will include no
in-tree cryptography other than the MD4 hash and that
implemented in our copy of Heimdal.

Using GnuTLS for SMB3 encryption you will notice huge performance and copy
speed improvements. Tests with the CIFS Kernel client from Linux Kernel 5.3
show a 3x speed improvement for writing and a 2.5x speed improvement for reads!

NOTE WELL: The use of GnuTLS means that Samba will honour the
system-wide 'FIPS mode' (a reference to the US FIPS-140 cryptographic
standard) and so will not operate in many still common situations if
this system-wide parameter is in effect, as many of our protocols rely
on outdated cryptography.

A future Samba version will mitigate this to some extent where good
cryptography effectively wraps bad cryptography, but for now that above
applies.

zlib library is now required to build Samba
-------------------------------------------

Samba no longer includes a local copy of zlib in our source tarball.
By removing this we do not need to ship (even where we did not
build) the old, broken zip encryption code found there.

New Spotlight backend for Elasticsearch
---------------------------------------

Support for the macOS specific Spotlight search protocol has been enhanced
significantly. Starting with 4.12 Samba supports using Elasticsearch as search
backend. Various new parameters have been added to configure this:

  spotlight backend = noindex | elasticsearch | tracker
  elasticsearch:address = ADDRESS
  elasticsearch:port = PORT
  elasticsearch:use tls = BOOLEAN
  elasticsearch:index = INDEXNAME
  elasticsearch:mappings = PATH
  elasticsearch:max results = NUMBER

Samba also ships a Spotlight client command "mdfind" which can be used to search
any SMB server that runs the Spotlight RPC service. See the manpage of mdfind
for details.

Note that when upgrading existing installations that are using the previous
default Spotlight backend Gnome Tracker must explicitly set "spotlight backend =
tracker" as the new default is "noindex".

'net ads kerberos pac save' and 'net eventlog export'
-----------------------------------------------------

The 'net ads kerberos pac save' and 'net eventlog export' tools will
no longer silently overwrite an existing file during data export.  If
the filename given exits, an error will be shown.

Fuzzing
-------

A large number of fuzz targets have been added to Samba, and Samba has
been registered in Google's oss-fuzz cloud fuzzing service.  In
particular, we now have good fuzzing coverage of our generated NDR
parsing code.

A large number of issues have been found and fixed thanks to this
effort.

'samba-tool' improvements add contacts as member to groups
----------------------------------------------------------

Previously 'samba-tool group addmemers' can just add users, groups and
computers as members to groups. But also contacts can be members of
groups. Samba 4.12 adds the functionality to add contacts to
groups. Since contacts have no sAMAccountName, it's possible that
there are more than one contact with the same name in different
organizational units. Therefore it's necessary to have an option to
handle group members by their DN.

To get the DN of an object there is now the "--full-dn" option available
for all necessary commands.

The MS Windows UI allows to search for specific types of group members
when searching for new members for a group. This feature is included
here with the new samba-tool group addmembers "--object-type=OBJECTYPE"
option. The different types are selected accordingly to the Windows
UI. The default samba-toole behaviour shouldn't be changed.

Allow filtering by OU or subtree in samba-tool
----------------------------------------------

A new "--base-dn" and "--member-base-dn" option is added to relevant
samba-tool user, group and ou management commands to allow operation
on just one part of the AD tree, such as a single OU.

VFS
===

SMB_VFS_NTIMES
--------------

Samba now uses a sentinel value based on utimensat(2) UTIME_OMIT to denote
to-be-ignored timestamp variables passed to the SMB_VFS_NTIMES() VFS function.

VFS modules can check whether any of the time values inside a struct
smb_file_time is to be ignored by calling is_omit_timespec() on the value.

'io_uring' vfs module
---------------------

The module makes use of the new io_uring infrastructure
(intruduced in Linux 5.1), see https://lwn.net/Articles/776703/

Currently this implements SMB_VFS_{PREAD,PWRITE,FSYNC}_SEND/RECV
and avoids the overhead of the userspace threadpool in the default
vfs backend. See also vfs_io_uring(8).

In order to build the module you need the liburing userspace library
and its developement headers installed, see
https://git.kernel.dk/cgit/liburing/

At runtime you'll need a Linux kernel with version 5.1 or higher.
Note that 5.4.14 and 5.4.15 have a regression that breaks the Samba
module! The regression was fixed in Linux 5.4.16 again.

MS-DFS changes in the VFS
-------------------------

This release changes set getting and setting of MS-DFS redirects
on the filesystem to go through two new VFS functions:

SMB_VFS_CREATE_DFS_PATHAT()
SMB_VFS_READ_DFS_PATHAT()

instead of smbd explicitly storing MS-DFS redirects inside
symbolic links on the filesystem. The underlying default
implementations of this has not changed, the redirects are
still stored inside symbolic links on the filesystem, but
moving the creation and reading of these links into the VFS
as first-class functions now allows alternate methods of
storing them (maybe in extended attributes) for OEMs who
don't want to mis-use filesystem symbolic links in this
way.


CTDB changes
============

* The ctdb_mutex_fcntl_helper periodically re-checks the lock file

  The re-check period is specified using a 2nd argument to this
  helper.  The default re-check period is 5s.

  If the file no longer exists or the inode number changes then the
  helper exits.  This triggers an election.


REMOVED FEATURES
================

The smb.conf parameter "write cache size" has been removed.

Since the in-memory write caching code was written, our write path has
changed significantly. In particular we have gained very flexible
support for async I/O, with the new linux io_uring interface in
development.  The old write cache concept which cached data in main
memory followed by a blocking pwrite no longer gives any improvement
on modern systems, and may make performance worse on memory-contrained
systems, so this functionality should not be enabled in core smbd
code.

In addition, it complicated the write code, which is a performance
critical code path.

If required for specialist purposes, it can be recreated as a VFS
module.

Retiring DES encryption types in Kerberos.
------------------------------------------
With this release, support for DES encryption types has been removed from
Samba, and setting DES_ONLY flag for an account will cause Kerberos
authentication to fail for that account (see RFC-6649).

Samba-DC: DES keys no longer saved in DB.
-----------------------------------------
When a new password is set for an account, Samba DC will store random keys
in DB instead of DES keys derived from the password.  If the account is being
migrated to Windbows or to an older version of Samba in order to use DES keys,
the password must be reset to make it work.

Heimdal-DC: removal of weak-crypto.
-----------------------------------
Following removal of DES encryption types from Samba, the embedded Heimdal
build has been updated to not compile weak crypto code (HEIM_WEAK_CRYPTO).

vfs_netatalk: The netatalk VFS module has been removed.
-------------------------------------------------------

The netatalk VFS module has been removed. It was unmaintained and is not needed
any more.

BIND9_FLATFILE deprecated
-------------------------

The BIND9_FLATFILE DNS backend is deprecated in this release and will
be removed in the future.  This was only practically useful on a single
domain controller or under expert care and supervision.

This release removes the 'rndc command' smb.conf parameter, which
supported this configuration by writing out a list of DCs permitted to
make changes to the DNS Zone and nudging the 'named' server if a new
DC was added to the domain.  Administrators using BIND9_FLATFILE will
need to maintain this manually from now on.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.27 2020/03/08 12:39:27 tnn Exp $
d434 1
@


1.27
log
@samba4: make avahi optional

Avahi by default pulls in X11 via gtk2 and dbus, so you might want to
disable it on a small server if your clients don't need ZeroConf capability.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.26 2020/01/29 12:44:14 adam Exp $
d9 1
d51 1
d130 3
d149 2
a150 2
lib/libndr.so.0
lib/libndr.so.0.2.0
d176 1
a176 1
lib/libsmbclient.so.0.5.0
d206 1
d231 1
d341 1
d371 1
d389 1
a531 1
lib/samba/auth/script.${SOEXT}
a564 1
lib/samba/ldb/local_password.${SOEXT}
a585 2
lib/samba/ldb/simple_dn.${SOEXT}
lib/samba/ldb/simple_ldap_map.${SOEXT}
d712 1
a759 1
lib/samba/vfs/netatalk.${SOEXT}
d784 1
a858 1
man/man8/vfs_netatalk.8
a937 2
share/samba/setup/fedora-ds-init.ldif
share/samba/setup/fedorads-dna.ldif
a940 3
share/samba/setup/fedorads-partitions.ldif
share/samba/setup/fedorads-refint-add.ldif
share/samba/setup/fedorads-refint-delete.ldif
a942 1
share/samba/setup/fedorads.inf
a1003 1
share/samba/setup/slapd.conf
@


1.26
log
@samba4: updated to 4.11.6

Changes since 4.11.5:
* BUG 14209: pygpo: Use correct method flags.
* BUG 14216: vfs_ceph_snapshots: Fix root relative path handling.
* BUG 14209: Avoiding bad call flags with python 3.8, using METH_NOARGS
  instead of zero.
* BUG 14218: source4/utils/oLschema2ldif: Include stdint.h before cmocka.h.
* BUG 14122: docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc.
* BUG 14251: smbd: Fix the build with clang.
* BUG 14199: upgradedns: Ensure lmdb lock files linked.
* BUG 14182: s3: VFS: glusterfs: Reset nlinks for symlink entries during
  readdir.
* BUG 14101: smbc_stat() doesn't return the correct st_mode and also the
  uid/gid is not filled (SMBv1) file.
* BUG 14219: librpc: Fix string length checking in
  ndr_pull_charset_to_null().
* BUG 14227: ctdb-scripts: Strip square brackets when gathering connection
  info.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.25 2019/12/30 13:58:35 adam Exp $
d763 1
a763 1
lib/samba/vfs/snapper.${SOEXT}
d861 1
a861 1
man/man8/vfs_snapper.8
@


1.25
log
@samba4: updated to 4.11.4

Changes since 4.11.3:
* BUG 14161: s3: libsmb: Ensure SMB1 cli_qpathinfo2() doesn't return an inode
  number.
* BUG 14174: s3: utils: smbtree. Ensure we don't call cli_RNetShareEnum()
  on an SMB1 connection.
* BUG 14176: NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in
  SMBC_opendir_ctx.
* BUG 14189: s3: smbd: SMB2 - Ensure we use the correct session_id if
  encrypting an interim response.
* BUG 14205: Prevent smbd crash after invalid SMB1 negprot.
* BUG 13745: s3:printing: Fix %J substition.
* BUG 13925: s3: Remove now unneeded call to cmdline_messaging_context().
* BUG 14069: Incomplete conversion of former parametric options.
* BUG 14070: Fix sync dosmode fallback in async dosmode codepath.
* BUG 14171: vfs_fruit returns capped resource fork length.
* BUG 14116: libnet_join: Add SPNs for additional-dns-hostnames entries.
* BUG 14211: smbd: Increase a debug level.
* BUG 14153: Prevent azure ad connect from reporting discovery errors:
  reference-value-not-ldap-conformant.
* BUG 14179: krb5_plugin: Fix developer build with newer heimdal system
  library.
* BUG 14168: replace: Only link libnsl and libsocket if requrired.
* BUG 14175: ctdb: Incoming queue can be orphaned causing communication
  breakdown.
* BUG 13846: ldb: Release ldb 2.0.8. Cross-compile will not take
  cross-answers or cross-execute.
* BUG 13856: heimdal-build: Avoid hard-coded /usr/include/heimdal in
  asn1_compile-generated code.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.24 2019/11/10 17:01:58 adam Exp $
d497 1
@


1.24
log
@samba4: updated to 4.11.2

4.11.2:
This is a security release in order to address the following defects:
o CVE-2019-10218: Client code can return filenames containing path separators.
o CVE-2019-14833: Samba AD DC check password script does not receive the full
		  password.
o CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server
		  via dirsync.

4.11.1:
This is the latest stable release of the Samba 4.11 release series.


Changes since 4.11.0:
* BUG 14141: getpwnam and getpwuid need to return data for ID_TYPE_BOTH
  group.
* BUG 14094: smbc_readdirplus() is incompatible with smbc_telldir() and
  smbc_lseekdir().
* BUG 14152: s3: smbclient: Stop an SMB2-connection from blundering into
  SMB1-specific calls.
* BUG 14137: Fix stale file handle error when using mkstemp on a share.
* BUG 14106: Fix spnego fallback from kerberos to ntlmssp in smbd server.
* BUG 14140: Overlinking libreplace against librt and pthread against every
  binary or library causes issues.
* BUG 14130: s3-winbindd: Fix forest trusts with additional trust attributes.
* BUG 14134: auth/gensec: Fix non-AES schannel seal.
* BUG 14147: Deleted records can be resurrected during recovery.
* BUG 14136: Fix uncaught exception in classicupgrade.
* BUG 14139: fault.c: Improve fault_report message text pointing to our wiki.
* BUG 14128: s3:client: Use DEVICE_URI, instead of argv[0], for Device URI.
* BUG 14124: pam_winbind with krb5_auth or wbinfo -K doesn't work for users
  of trusted domains/forests.
* BUG 14131: Remove 'pod2man' as it is no longer needed.
* BUG 13884: Joining Active Directory should not use SAMR to set the
  password.
* BUG 14140: Overlinking libreplace against librt and pthread against every
  binary or library causes issues.
* BUG 14155: 'kpasswd' fails when built with MIT Kerberos.
* BUG 14129: Exit code of ctdb nodestatus should not be influenced by deleted
  nodes.

4.11.0:
* BUG 14049: ldb: Don't try to save a value that isn't there.
* ldb_dn: Free dn components on explode failure.
* ldb: Do not allow adding a DN as a base to itself.
* ldb: Release ldb 2.0.7.
* BUG 13695: ldb: Correct Pigeonhole principle validation in
  ldb_filter_attrs().
* BUG 14049: Fix ldb dn crash.
* BUG 14117: Deprecate "lanman auth = yes" and "encrypt passwords = no".
* BUG 14038: Fix compiling ctdb on older systems lacking POSIX robust
  mutexes.
* BUG 14121: smbd returns bad File-ID on filehandle used to create a file or
  directory.
* BUG 14098: vfs_glusterfs: Use pthreadpool for scheduling aio operations.
* BUG 14055: Add the target server name of SMB 3.1.1 connections as a hint to
  load balancers or servers with "multi-tenancy" support.
* BUG 14113: Fix byte range locking bugs/regressions.
* ldb: Fix mem-leak if talloc_realloc fails.
* BUG 14007: Fix join with don't exists machine account.
* BUG 14085: ctdb-recoverd: Only check for LMASTER nodes in the VNN map.

CHANGES SINCE 4.11.0rc2
* BUG 13972: Different Device Id for GlusterFS FUSE mount is causing data
  loss in CTDB cluster.
* BUG 14035: CVE-2019-10197: Permissions check deny can allow user to escape
  from the share.
* BUG 14059: ldb: Release ldb 2.0.6 (log database repack so users know what
  is happening).
* BUG 14092: docs: Deprecate "rndc command" for Samba 4.11.
* BUG 14059: ldb: Free memory when repacking database.
* BUG 14089: vfs_default: Use correct flag in vfswrap_fs_file_id.
* BUG 14090: vfs_glusterfs: Initialize st_ex_file_id, st_ex_itime and
  st_ex_iflags.
* BUG 14093: vfs_glusterfs: Enable profiling for file system operations.
* BUG 14059: Backport sambadowngradedatabase for v4.11.
* BUG 14035: CVE-2019-10197: Permissions check deny can allow user to escape
  from the share.
* BUG 14032: vfs_gpfs: Implement special case for denying owner access to
  ACL.
* BUG 14084: Avoid marking a node as connected before it can receive packets.
* BUG 14086: Fix onnode test failure with ShellCheck >= 0.4.7.
* BUG 14087: ctdb-daemon: Stop "ctdb stop" from completing before freezing
  databases.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.23 2019/08/03 06:54:39 adam Exp $
d503 1
@


1.24.4.1
log
@Pullup ticket #6125 - requested by taca
net/samba4: security fix

Revisions pulled up:
- net/samba4/Makefile                                           1.86-1.89
- net/samba4/PLIST                                              1.25
- net/samba4/distinfo                                           1.39-1.41
- net/samba4/patches/patch-source4_utils_oLschema2ldif_wscript__build 1.1

---
   Module Name:	pkgsrc
   Committed By:	adam
   Date:		Mon Dec 30 13:58:35 UTC 2019

   Modified Files:
   	pkgsrc/net/samba4: Makefile PLIST distinfo

   Log Message:
   samba4: updated to 4.11.4

   Changes since 4.11.3:
   * BUG 14161: s3: libsmb: Ensure SMB1 cli_qpathinfo2() doesn't return an inode
     number.
   * BUG 14174: s3: utils: smbtree. Ensure we don't call cli_RNetShareEnum()
     on an SMB1 connection.
   * BUG 14176: NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in
     SMBC_opendir_ctx.
   * BUG 14189: s3: smbd: SMB2 - Ensure we use the correct session_id if
     encrypting an interim response.
   * BUG 14205: Prevent smbd crash after invalid SMB1 negprot.
   * BUG 13745: s3:printing: Fix %J substition.
   * BUG 13925: s3: Remove now unneeded call to cmdline_messaging_context().
   * BUG 14069: Incomplete conversion of former parametric options.
   * BUG 14070: Fix sync dosmode fallback in async dosmode codepath.
   * BUG 14171: vfs_fruit returns capped resource fork length.
   * BUG 14116: libnet_join: Add SPNs for additional-dns-hostnames entries.
   * BUG 14211: smbd: Increase a debug level.
   * BUG 14153: Prevent azure ad connect from reporting discovery errors:
     reference-value-not-ldap-conformant.
   * BUG 14179: krb5_plugin: Fix developer build with newer heimdal system
     library.
   * BUG 14168: replace: Only link libnsl and libsocket if requrired.
   * BUG 14175: ctdb: Incoming queue can be orphaned causing communication
     breakdown.
   * BUG 13846: ldb: Release ldb 2.0.8. Cross-compile will not take
     cross-answers or cross-execute.
   * BUG 13856: heimdal-build: Avoid hard-coded /usr/include/heimdal in
     asn1_compile-generated code.

---
   Module Name:	pkgsrc
   Committed By:	jperkin
   Date:		Wed Jan  8 10:40:03 UTC 2020

   Modified Files:
   	pkgsrc/net/samba4: distinfo
   Added Files:
   	pkgsrc/net/samba4/patches:
   	    patch-source4_utils_oLschema2ldif_wscript__build

   Log Message:
   samba4: Disable more fmemopen utilities on SunOS.

---
   Module Name:	pkgsrc
   Committed By:	jperkin
   Date:		Sat Jan 18 21:51:16 UTC 2020

   Modified Files:
   	pkgsrc/net/samba4: Makefile

   Log Message:
   *: Recursive revision bump for openssl 1.1.1.

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Tue Jan 21 14:12:36 UTC 2020

   Modified Files:
   	pkgsrc/net/samba4: Makefile distinfo

   Log Message:
   net/samba4: update to 4.11.5

   Update samba4 to 4.11.5.

                      ==============================
                      Release Notes for Samba 4.11.5
                             January 21, 2020
   		   ==============================

   This is a security release in order to address the following defects:

   o CVE-2019-14902: Replication of ACLs set to inherit down a subtree on AD
   		  Directory not automatic.
   o CVE-2019-14907: Crash after failed character conversion at log level 3 or
   		  above.
   o CVE-2019-19344: Use after free during DNS zone scavenging in Samba AD DC.

   =======
   Details
   =======

   o  CVE-2019-14902:
      The implementation of ACL inheritance in the Samba AD DC was not complete,
      and so absent a 'full-sync' replication, ACLs could get out of sync between
      domain controllers.

   o  CVE-2019-14907:
      When processing untrusted string input Samba can read past the end of the
      allocated buffer when printing a "Conversion error" message to the logs.

   o  CVE-2019-19344:
      During DNS zone scavenging (of expired dynamic entries) there is a read of
      memory after it has been freed.

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Mon Jan 27 14:04:13 UTC 2020

   Modified Files:
   	pkgsrc/net/samba4: Makefile

   Log Message:
   net/samba4: update depdendency

   Update dependency for daabases/ldb and devel/talloc.

   Bump PKGREVISION.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.24 2019/11/10 17:01:58 adam Exp $
a502 1
${PYSITELIB}/samba/tests/smbd_fuzztest.py
@


1.23
log
@samba4: updated to 4.10.6

Changes 4.10.6:
* BUG 13956: s3: winbind: Fix crash when invoking winbind idmap scripts.
* BUG 13964: smbd does not correctly parse arguments passed to dfree and
  quota scripts.
* BUG 13965: samba-tool dns: use bytes for inet_ntop.
* BUG 13828: samba-tool domain provision: Fix --interactive module in
  python3.
* BUG 13893: ldb_kv: Skip @@ records early in a search full scan.
* BUG 13981: docs: Improve documentation of "lanman auth" and "ntlm auth"
  connection.
* BUG 14002: python/ntacls: Use correct "state directory" smb.conf option
  instead of "state dir".
* BUG 13840: registry: Add a missing include.
* BUG 13944: Fix SMB guest authentication.
* BUG 13958: AppleDouble conversion breaks Resourceforks.
* BUG 13968: vfs_fruit makes direct use of syscalls like mmap() and pread().
* BUG 13987: s3:mdssvc: Fix flex compilation error.
* BUG 13872: s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly:
* BUG 13799: dsdb:samdb: schemainfo update with relax control.
* BUG 13964: s3:util: Move static file_pload() function to lib/util.
* BUG 13957: smbd: Fix a panic.
* BUG 12478: ldap server: Generate correct referral schemes.
* BUG 13941: s4 dsdb/repl_meta_data: fix use after free in
  dsdb_audit_add_ldb_value.
* BUG 13942: s4 dsdb: Fix use after free in
  samldb_rename_search_base_callback.
* BUG 12204: dsdb/repl: we need to replicate the whole schema before we can
  apply it.
* BUG 12478: ldb: Release ldb 1.5.5
* BUG 13713: Schema replication fails if link crosses chunk boundary
  backwards.
* BUG 13799: 'samba-tool domain schemaupgrade' uses relax control and skips
  the schemaInfo update provision.
* BUG 13916: dsdb_audit: avoid printing "... remote host [Unknown]
  SID [(NULL SID)] ..."
* BUG 13917: python/ntacls: We only need security.SEC_STD_READ_CONTROL in
  order to get the ACL.
* BUG 13947: s3:loadparm: Ensure to truncate FS Volume Label at multibyte
  boundary.
* BUG 13939: Using Kerberos credentials to print using spoolss doesn't work.
* BUG 13998: wafsamba: Use native waf timer.
* BUG 13984: ctdb-scripts: Fix tcp_tw_recycle existence check.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.22 2019/04/08 18:35:58 adam Exp $
a15 1
bin/pidl
d37 2
d159 1
a159 1
lib/libsamba-passdb.so.0.27.2
a181 25
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Pidl.pm
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Pidl/CUtil.pm
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Pidl/Compat.pm
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Pidl/Dump.pm
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Pidl/Expr.pm
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Pidl/IDL.pm
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Pidl/NDR.pm
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Pidl/ODL.pm
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Pidl/Samba3/ClientNDR.pm
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Pidl/Samba3/ServerNDR.pm
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Pidl/Samba4.pm
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Pidl/Samba4/COM/Header.pm
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Pidl/Samba4/COM/Proxy.pm
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Pidl/Samba4/COM/Stub.pm
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Pidl/Samba4/Header.pm
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Pidl/Samba4/NDR/Client.pm
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Pidl/Samba4/NDR/Parser.pm
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Pidl/Samba4/NDR/Server.pm
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Pidl/Samba4/Python.pm
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Pidl/Samba4/TDR.pm
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Pidl/Samba4/Template.pm
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Pidl/Typelist.pm
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Pidl/Util.pm
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Pidl/Wireshark/Conformance.pm
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Pidl/Wireshark/NDR.pm
d293 1
a341 1
${PYSITELIB}/samba/smb.so
d358 1
d362 1
a394 1
${PYSITELIB}/samba/tests/dns_forwarder_helpers/dns_hub.py
d468 1
d471 2
d479 1
d484 2
d500 1
d510 1
a515 1
${PYSITELIB}/samba/web_server/__init__.py
d539 1
d631 1
a666 1
lib/samba/private/libnon-posix-acls-samba4.so
d673 1
a730 1
lib/samba/service/web.${SOEXT}
a748 1
lib/samba/vfs/glusterfs_fuse.${SOEXT}
d761 1
a780 1
man/man1/pidl.1
a799 5
man/man3/Parse::Pidl::Dump.3
man/man3/Parse::Pidl::NDR.3
man/man3/Parse::Pidl::Util.3
man/man3/Parse::Pidl::Wireshark::Conformance.3
man/man3/Parse::Pidl::Wireshark::NDR.3
d828 1
a847 1
man/man8/vfs_glusterfs_fuse.8
d859 1
d875 1
d896 1
a1004 3
@@pkgdir share/examples/samba/pam_smbpass
@@pkgdir etc/samba
@@pkgdir bind-dns
@


1.22
log
@samba4: updated to 4.10.2

Release Notes for Samba 4.10.2

This is a security release in order to address the following defects:
o  CVE-2019-3870 (World writable files in Samba AD DC private/ dir)
o  CVE-2019-3880 (Save registry file outside share as unprivileged user)

Details

o  CVE-2019-3870:
   During the provision of a new Active Directory DC, some files in the private/
   directory are created world-writable.

o  CVE-2019-3880:
   Authenticated users with write permission can trigger a symlink traversal to
   write or detect files outside the Samba share.

For more details and workarounds, please refer to the security advisories.

Changes since 4.10.1:
* BUG 13834: CVE-2019-3870: pysmbd: Ensure a zero umask is set for
  smbd.mkdir().
* BUG 13851: CVE-2018-14629: rpc: winreg: Remove implementations of
  SaveKey/RestoreKey.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.21 2019/03/20 19:09:10 adam Exp $
d447 1
d1005 1
@


1.22.2.1
log
@Pullup ticket #6047 - requested by taca
databases/ldb: dependent update
net/samba4: security fix

Revisions pulled up:
- databases/ldb/Makefile                                        1.6
- databases/ldb/buildlink3.mk                                   1.2
- databases/ldb/distinfo                                        1.3
- net/samba4/Makefile                                           1.75,1.77-1.78
- net/samba4/PLIST                                              1.23
- net/samba4/distinfo                                           1.33-1.35

---
   Module Name:	pkgsrc
   Committed By:	wiz
   Date:		Sat Jul 20 22:46:59 UTC 2019

   Modified Files:

   	pkgsrc/net/samba4: Makefile buildlink3.mk


   Log Message:
   *: recursive bump for nettle 3.5.1

---
   Module Name:	pkgsrc
   Committed By:	wiz
   Date:		Sun Jul 21 22:26:08 UTC 2019

   Modified Files:

   	pkgsrc/net/samba4: Makefile


   Log Message:
   *: recursive bump for gdk-pixbuf2-2.38.1

---
   Module Name:	pkgsrc
   Committed By:	adam
   Date:		Sat Aug  3 06:54:39 UTC 2019

   Modified Files:
   	pkgsrc/net/samba4: Makefile PLIST distinfo

   Log Message:
   samba4: updated to 4.10.6

   Changes 4.10.6:
   * BUG 13956: s3: winbind: Fix crash when invoking winbind idmap scripts.
   * BUG 13964: smbd does not correctly parse arguments passed to dfree and
     quota scripts.
   * BUG 13965: samba-tool dns: use bytes for inet_ntop.
   * BUG 13828: samba-tool domain provision: Fix --interactive module in
     python3.
   * BUG 13893: ldb_kv: Skip @@ records early in a search full scan.
   * BUG 13981: docs: Improve documentation of "lanman auth" and "ntlm auth"
     connection.
   * BUG 14002: python/ntacls: Use correct "state directory" smb.conf option
     instead of "state dir".
   * BUG 13840: registry: Add a missing include.
   * BUG 13944: Fix SMB guest authentication.
   * BUG 13958: AppleDouble conversion breaks Resourceforks.
   * BUG 13968: vfs_fruit makes direct use of syscalls like mmap() and pread().
   * BUG 13987: s3:mdssvc: Fix flex compilation error.
   * BUG 13872: s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly:
   * BUG 13799: dsdb:samdb: schemainfo update with relax control.
   * BUG 13964: s3:util: Move static file_pload() function to lib/util.
   * BUG 13957: smbd: Fix a panic.
   * BUG 12478: ldap server: Generate correct referral schemes.
   * BUG 13941: s4 dsdb/repl_meta_data: fix use after free in
     dsdb_audit_add_ldb_value.
   * BUG 13942: s4 dsdb: Fix use after free in
     samldb_rename_search_base_callback.
   * BUG 12204: dsdb/repl: we need to replicate the whole schema before we can
     apply it.
   * BUG 12478: ldb: Release ldb 1.5.5
   * BUG 13713: Schema replication fails if link crosses chunk boundary
     backwards.
   * BUG 13799: 'samba-tool domain schemaupgrade' uses relax control and skips
     the schemaInfo update provision.
   * BUG 13916: dsdb_audit: avoid printing "... remote host [Unknown]
     SID [(NULL SID)] ..."
   * BUG 13917: python/ntacls: We only need security.SEC_STD_READ_CONTROL in
     order to get the ACL.
   * BUG 13947: s3:loadparm: Ensure to truncate FS Volume Label at multibyte
     boundary.
   * BUG 13939: Using Kerberos credentials to print using spoolss doesn't work.
   * BUG 13998: wafsamba: Use native waf timer.
   * BUG 13984: ctdb-scripts: Fix tcp_tw_recycle existence check.

---
   Module Name:	pkgsrc
   Committed By:	wiz
   Date:		Sun Aug 11 13:25:21 UTC 2019

   Modified Files:

   	pkgsrc/net/samba4: Makefile


   Log Message:
   Bump PKGREVISIONs for perl 5.30.0

---
   Module Name:	pkgsrc
   Committed By:	adam
   Date:		Fri Aug 23 10:52:41 UTC 2019

   Modified Files:
   	pkgsrc/net/samba4: Makefile distinfo

   Log Message:
   samba4: updated to 4.10.7

   Samba 4.10.7
   * BUG 14010: Unable to create or rename file/directory inside shares
     configured with vfs_glusterfs_fuse module.
   * BUG 13844: build: Allow build when '--disable-gnutls' is set.
   * BUG 13973: samba-tool: Add 'import samba.drs_utils' to fsmo.py.
   * BUG 14008: Fix 'Error 32 determining PSOs in system' message on old DB
     with FL upgrade.
   * BUG 14021: s4/libnet: Fix joining a Windows pre-2008R2 DC.
   * BUG 14046: join: Use a specific attribute order for the DsAddEntry
     nTDSDSA object.
   * BUG 14015: vfs_catia: Pass stat info to synthetic_smb_fname().
   * BUG 14091: lookup_name: Allow own domain lookup when flags == 0.
   * BUG 13932: s4 librpc rpc pyrpc: Ensure tevent_context deleted last.
   * BUG 13915: DEBUGC and DEBUGADDC doesn't print into a class specific log
     file.
   * BUG 13949: Request to keep deprecated option "server schannel",
     VMWare Quickprep requires "auto".
   * BUG 13967: dbcheck: Fallback to the default tombstoneLifetime of 180 days.
   * BUG 13969: dnsProperty fails to decode values from older Windows versions.
   * BUG 13973: samba-tool: Use only one LDAP modify for dns partition fsmo
     role transfer.
   * BUG 13960: third_party: Update waf to version 2.0.17.
   * BUG 14051: netcmd: Allow 'drs replicate --local' to create partitions.
   * BUG 14017: ctdb-config: Depend on /etc/ctdb/nodes file.

---
   Module Name:	pkgsrc
   Committed By:	adam
   Date:		Tue Sep  3 19:11:58 UTC 2019

   Modified Files:
   	pkgsrc/net/samba4: Makefile distinfo

   Log Message:
   samba4: updated to 4.10.8

   Samba 4.10.8:

   This is a security release in order to address the following defect:

   o  CVE-2019-10197: Combination of parameters and permissions can allow user
                      to escape from the share path definition.

---
   Module Name:	pkgsrc
   Committed By:	adam
   Date:		Sat Aug  3 06:52:32 UTC 2019

   Modified Files:
   	pkgsrc/databases/ldb: Makefile buildlink3.mk distinfo

   Log Message:
   ldb: updated to 1.5.5

   1.5.5:
   Unknown changes
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.22 2019/04/08 18:35:58 adam Exp $
a446 1
${PYSITELIB}/samba/tests/ldap_referrals.py
a1003 1
share/samba/setup/provision_self_join_modify_schema.ldif
@


1.21
log
@samba4: updated to 4.10.0

Release Notes for Samba 4.10.0

This is the first stable release of the Samba 4.10 release series.
Please read the release notes carefully before upgrading.


NEW FEATURES/CHANGES
====================

GPO Improvements
----------------

A new 'samba-tool gpo backup' command has been added that can export a
set of Group Policy Objects from a domain in a generalised XML format.

A corresponding 'samba-tool gpo restore' command has been added to
rebuild the Group Policy Objects from the XML after generalization.
(The administrator needs to correct the values of XML entities between
the backup and restore to account for the change in domain).

KDC prefork
-----------

The KDC now supports the pre-fork process model and worker processes will be
forked for the KDC when the pre-fork process model is selected for samba.

Prefork 'prefork children'
--------------------------

The default value for this smdb.conf parameter has been increased from 1 to
4.

Netlogon prefork
----------------

DCERPC now supports pre-forked NETLOGON processes. The netlogon processes are
pre-forked when the prefork process model is selected for samba.

Offline domain backups
----------------------

The 'samba-tool domain backup' command has been extended with a new 'offline'
option. This safely creates a backup of the local DC's database directly from
disk. The main benefits of an offline backup are it's quicker, it stores more
database details (for forensic purposes), and the samba process does not have
to be running when the backup is made. Refer to the samba-tool help for more
details on using this command.

Group membership statistics
---------------------------

A new 'samba-tool group stats' command has been added. This provides summary
information about how the users are spread across groups in your domain.
The 'samba-tool group list --verbose' command has also been updated to include
the number of users in each group.

Paged results LDAP control
--------------------------

The behaviour of the paged results control (1.2.840.113556.1.4.319, RFC2696)
has been changed to more closely match Windows servers, to improve memory
usage. Paged results may be used internally (or is requested by the user) by
LDAP libraries or tools that deal with large result sizes, for example, when
listing all the objects in the database.

Previously, results were returned as a snapshot of the database but now,
some changes made to the set of results while paging may be reflected in the
responses. If strict inter-record consistency is required in answers (which is
not possible on Windows with large result sets), consider avoiding the paged
results control or alternatively, it might be possible to enforce restrictions
using the LDAP filter expression.

For further details see https://wiki.samba.org/index.php/Paged_Results

Prefork process restart
-----------------------

The pre-fork process model now restarts failed processes. The delay between
restart attempts is controlled by the "prefork backoff increment" (default = 10)
and "prefork maximum backoff" (default = 120) smbd.conf parameters.  A linear
back off strategy is used with "prefork backoff increment" added to the
delay between restart attempts up until it reaches "prefork maximum backoff".

Using the default sequence the restart delays (in seconds) are:
  0, 10, 20, ..., 120, 120, ...

Standard process model
----------------------

When using the standard process model samba forks a new process to handle ldap
and netlogon connections.  Samba now honours the 'max smbd processes' smb.conf
parameter.  The default value of 0, indicates there is no limit.  The limit
is applied individually to netlogon and ldap.  When the process limit is
exceeded Samba drops new connections immediately.

python3 support
---------------

This is the first release of Samba which has full support for Python 3.
Samba 4.10 still has support for Python 2, however, Python 3 will be used by
default, i.e. 'configure' & 'make' will execute using python3.

To build Samba with python2 you *must* set the 'PYTHON' environment variable
for both the 'configure' and 'make' steps, i.e.
   'PYTHON=python2 ./configure'
   'PYTHON=python2 make'
This will override the python3 default.

Alternatively, it is possible to produce Samba Python bindings for both
Python 2 and Python 3. To do so, specify '--extra-python=/usr/bin/python2'
as part of the 'configure' command. Note that python3 will still be used as
the default in this case.

Note that Samba 4.10 supports Python 3.4 onwards.

Future Python support
---------------------

Samba 4.10 will be the last release that comes with full support for
Python 2. Unfortunately, the Samba Team doesn't have the resources to support
both Python 2 and Python 3 long-term.

Samba 4.11 will not have any runtime support for Python 2. This means if
you use Python 2 bindings it is time to migrate to Python 3 now.

If you are building Samba using the '--disable-python' option (i.e. you're
excluding all the run-time Python support), then this will continue to work
on a system that supports either python2 or python3.

Also note that Samba 4.11 will most likely only support Python 3.6 onwards.

JSON logging
------------

Authentication messages now contain the Windows Event Id "eventId" and logon
type "logonType". The supported event codes and logon types are:
  Event codes:
    4624  Successful logon
    4625  Unsuccessful logon

  Logon Types:
    2  Interactive
    3  Network
    8  NetworkCleartext

The version number for Authentication messages is now 1.1, changed from 1.0

Password change messages now contain the Windows Event Id "eventId", the
supported event Id's are:
  4723 Password changed
  4724 Password reset

The version number for PasswordChange messages is now 1.1, changed from 1.0

Group membership change messages now contain the Windows Event Id "eventId",
the supported event Id's are:
  4728 A member was added to a security enabled global group
  4729 A member was removed from a security enabled global group
  4732 A member was added to a security enabled local group
  4733 A member was removed from a security enabled local group
  4746 A member was added to a security disabled local group
  4747 A member was removed from a security disabled local group
  4751 A member was added to a security disabled global group
  4752 A member was removed from a security disabled global group
  4756 A member was added to a security enabled universal group
  4757 A member was removed from a security enabled universal group
  4761 A member was added to a security disabled universal group
  4762 A member was removed from a security disabled universal group


The version number for GroupChange messages is now 1.1, changed from 1.0. Also
A GroupChange message is generated when a new user is created to log that the
user has been added to their primary group.

The leading "JSON <message type>:" and source file  prefix of the JSON formatted
log entries has been removed to make the parsing of the JSON log messages
easier. JSON log entries now start with 2 spaces followed by an opening brace
i.e. "  {"

SMBv2 samba-tool support
------------------------

On previous releases, some samba-tool commands would not work against a remote
DC that had SMBv1 disabled. SMBv2 support has now been added for samba-tool.
The affected commands are 'samba-tool domain backup|rename' and the
'samba-tool gpo' set of commands.

New glusterfs_fuse VFS module
-----------------------------

The new vfs_glusterfs_fuse module improves performance when Samba
accesses a glusterfs volume mounted via FUSE (Filesystem in Userspace
as part of the Linux kernel). It achieves that by leveraging a
mechanism to retrieve the appropriate case of filenames by querying a
specific extended attribute in the filesystem. No extra configuration
is required to use this module, only glusterfs_fuse needs to be set in
the "vfs objects" parameter. Further details can be found in the
vfs_glusterfs_fuse(8) manpage. This new vfs_glusterfs_fuse module does
not replace the existing vfs_glusterfs module, it just provides an
additional, alternative mechanism to access a Gluster volume.

REMOVED FEATURES
================

MIT Kerberos build of the AD DC
-------------------------------

While not removed, the MIT Kerberos build of the Samba AD DC is still
considered experimental.  Because Samba will not issue security
patches for this configuration, such builds now require the explicit
configure option: --with-experimental-mit-ad-dc

For further details see
https://wiki.samba.org/index.php/Running_a_Samba_AD_DC_with_MIT_Kerberos_KDC

samba_backup
------------

The samba_backup script has been removed. This has now been replaced by the
'samba-tool domain backup offline' command.

SMB client Python bindings
--------------------------

The SMB client python bindings are now deprecated and will be removed in future
Samba releases. This will only affects users that may have used the Samba
Python bindings to write their own utilities, i.e. users with a custom Python
script that includes the line 'from samba import smb'.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.20 2019/03/13 18:02:31 adam Exp $
d517 1
@


1.21.2.1
log
@Pullup ticket #5933 - requested by taca
net/samba4: security fix

Revisions pulled up:
- net/samba4/Makefile                                           1.64-1.65
- net/samba4/PLIST                                              1.22
- net/samba4/distinfo                                           1.26-1.27

---
   Module Name:	pkgsrc
   Committed By:	adam
   Date:		Wed Apr  3 14:23:06 UTC 2019

   Modified Files:
   	pkgsrc/net/samba4: Makefile distinfo

   Log Message:
   samba4: updated to 4.10.1

   Changes since 4.10.0:
   * BUG 13837: py/kcc_utils: py2.6 compatibility.
   * BUG 13869: libcli: permit larger values of DataLength in
     SMB2_ENCRYPTION_CAPABILITIES of negotiate response.
   * BUG 13840: regfio: Improve handling of malformed registry hive files.
   * BUG 13789: ctdb-version: Simplify version string usage.
   * BUG 13859: lib: Make fd_load work for non-regular files.
   * BUG 13816: dbcheck in the middle of the tombstone garbage collection causes
     replication failures, dbcheck: add --selftest-check-expired-tombstones
     cmdline option.
   * BUG 13818: ndr_spoolss_buf: Fix out of scope use of stack variable in
     NDR_SPOOLSS_PUSH_ENUM_OUT().
   * BUG 13854: s4/messaging: Fix undefined reference in linking
     libMESSAGING-samba4.so.
   * BUG 13836: acl_read: Fix regression for empty lists.
   * BUG 13841: s4:dlz make b9_has_soa check dc=@@ node.
   * BUG 13832: s3:client: Fix printing via smbspool backend with kerberos auth.
   * BUG 13847: s4:librpc: Fix installation of Samba.
   * BUG 13848: s3:lib: Fix the debug message for adding cache entries.
   * BUG 13793: s3:utils: Add 'smbstatus -L --resolve-uids' to show username.
   * BUG 13848: s3:lib: Fix the debug message for adding cache entries.
   * BUG 13853: s3:waf: Fix the detection of makdev() macro on Linux.
   * BUG 13789: ctdb-build: Drop creation of .distversion in tarball.
   * BUG 13838: ctdb-packaging: Test package requires tcpdump, ctdb package
     should not own system library directory.

---
   Module Name:	pkgsrc
   Committed By:	adam
   Date:		Mon Apr  8 18:35:59 UTC 2019

   Modified Files:
   	pkgsrc/net/samba4: Makefile PLIST distinfo

   Log Message:
   samba4: updated to 4.10.2

   Release Notes for Samba 4.10.2

   This is a security release in order to address the following defects:
   o  CVE-2019-3870 (World writable files in Samba AD DC private/ dir)
   o  CVE-2019-3880 (Save registry file outside share as unprivileged user)

   Details

   o  CVE-2019-3870:
      During the provision of a new Active Directory DC, some files in the private/
      directory are created world-writable.

   o  CVE-2019-3880:
      Authenticated users with write permission can trigger a symlink traversal to
      write or detect files outside the Samba share.

   For more details and workarounds, please refer to the security advisories.

   Changes since 4.10.1:
   * BUG 13834: CVE-2019-3870: pysmbd: Ensure a zero umask is set for
     smbd.mkdir().
   * BUG 13851: CVE-2018-14629: rpc: winreg: Remove implementations of
     SaveKey/RestoreKey.
@
text
@d1 1
a1 1
@@comment $NetBSD$
a516 1
${PYSITELIB}/samba/tests/smbd_base.py
@


1.20
log
@py-twine: updated to 1.13.0

Twine is a utility for publishing Python packages on PyPI. It provides build
system independent uploads of source and binary distribution artifacts for both
new and existing projects.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.19 2019/01/03 19:36:45 adam Exp $
d4 1
a6 6
bin/ldbadd
bin/ldbdel
bin/ldbedit
bin/ldbmodify
bin/ldbrename
bin/ldbsearch
d106 1
a110 2
include/util/memory.h
include/util/safe_string.h
a113 1
include/util/talloc_stack.h
d144 1
a144 1
lib/libndr.so.0.1.0
d158 1
a158 1
lib/libsamba-passdb.so.0.27.1
d170 1
a170 1
lib/libsmbclient.so.0.4.0
d180 1
a180 1
lib/libwbclient.so.0.14
a220 4
${PYSITELIB}/_ldb_text.py
${PYSITELIB}/_tdb_text.py
${PYSITELIB}/_tevent.so
${PYSITELIB}/ldb.so
d255 1
d260 1
d265 1
d267 2
d284 7
d304 1
d386 1
d389 1
d394 1
d410 1
a410 1
${PYSITELIB}/samba/tests/dcerpc/string.py
d417 1
d424 1
d447 1
a447 1
${PYSITELIB}/samba/tests/libsmb_samba_internal.py
d458 3
d463 1
d475 2
a520 1
${PYSITELIB}/samba/tests/unicodenames.py
d528 1
a533 2
${PYSITELIB}/tdb.so
${PYSITELIB}/tevent.py
d538 1
a551 1
lib/samba/ldb/asq.${SOEXT}
a564 1
lib/samba/ldb/ldb.${SOEXT}
a567 1
${PLIST.64bit}lib/samba/ldb/mdb.${SOEXT}
a573 1
lib/samba/ldb/paged_searches.${SOEXT}
a576 1
lib/samba/ldb/rdn_name.${SOEXT}
a584 1
lib/samba/ldb/sample.${SOEXT}
a587 1
lib/samba/ldb/server_sort.${SOEXT}
a590 1
lib/samba/ldb/skel.${SOEXT}
a592 1
lib/samba/ldb/tdb.${SOEXT}
d623 1
a665 5
lib/samba/private/libldb-cmdline-samba4.so
lib/samba/private/libldb-key-value-samba4.so
${PLIST.64bit}lib/samba/private/libldb-mdb-int-samba4.so
lib/samba/private/libldb.so.1
lib/samba/private/libldb.so.1.4.6
d672 1
a687 2
lib/samba/private/libpyldb-util.so.1
lib/samba/private/libpyldb-util.so.1.4.6
a785 6
man/man1/ldbadd.1
man/man1/ldbdel.1
man/man1/ldbedit.1
man/man1/ldbmodify.1
man/man1/ldbrename.1
man/man1/ldbsearch.1
a818 1
man/man3/ldb.3
a855 2
man/man8/vfs_btrfs.8
man/man8/vfs_cacheprime.8
a857 1
man/man8/vfs_ceph.8
a863 1
man/man8/vfs_fileid.8
a865 1
man/man8/vfs_glusterfs.8
a866 1
man/man8/vfs_gpfs.8
a869 1
man/man8/vfs_nfs4acl_xattr.8
a870 1
man/man8/vfs_prealloc.8
a877 1
man/man8/vfs_snapper.8
a881 1
man/man8/vfs_tsmsm.8
@


1.19
log
@samba4: use external tevent and tdb; bump revision
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.18 2018/12/22 01:13:52 adam Exp $
d229 2
d521 2
d666 1
a666 1
lib/samba/private/libldb.so.1.4.3
d689 1
a689 1
lib/samba/private/libpyldb-util.so.1.4.3
d764 1
d880 1
@


1.18
log
@samba4: buidling fixes

PkgSrc changes:
* fix building on Darwin and probably other systems as well
* install manpages
* use correct install_name on Darwin
* does not collide with p5-Parse-Yapp anymore
* use cmocka and libgcrypt
* clean-ups
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.17 2018/12/10 14:42:45 ryoon Exp $
a40 4
bin/tdbbackup
bin/tdbdump
bin/tdbrestore
bin/tdbtool
a228 2
${PYSITELIB}/_tdb_text.py
${PYSITELIB}/_tevent.so
a518 2
${PYSITELIB}/tdb.so
${PYSITELIB}/tevent.py
a715 4
lib/samba/private/libtdb.so.1
lib/samba/private/libtdb.so.1.3.16
lib/samba/private/libtevent.so.0
lib/samba/private/libtevent.so.0.9.37
a854 4
man/man8/tdbbackup.8
man/man8/tdbdump.8
man/man8/tdbrestore.8
man/man8/tdbtool.8
@


1.17
log
@Fix another mistake. This will fix the packaging really.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.16 2018/12/09 14:48:03 ryoon Exp $
a216 1
${PERL5_SUB_INSTALLVENDORLIB}/Parse/Yapp/Driver.pm
d527 76
a602 76
lib/samba/auth/script.so
lib/samba/bind9/dlz_bind9.so
lib/samba/bind9/dlz_bind9_10.so
lib/samba/bind9/dlz_bind9_11.so
lib/samba/bind9/dlz_bind9_9.so
lib/samba/gensec/krb5.so
${PLIST.ldap}lib/samba/idmap/ad.so
lib/samba/idmap/autorid.so
lib/samba/idmap/hash.so
${PLIST.ldap}lib/samba/idmap/rfc2307.so
lib/samba/idmap/rid.so
lib/samba/idmap/script.so
lib/samba/idmap/tdb2.so
lib/samba/krb5/winbind_krb5_locator.so
lib/samba/ldb/acl.so
lib/samba/ldb/aclread.so
lib/samba/ldb/anr.so
lib/samba/ldb/asq.so
lib/samba/ldb/audit_log.so
lib/samba/ldb/descriptor.so
lib/samba/ldb/dirsync.so
lib/samba/ldb/dns_notify.so
lib/samba/ldb/dsdb_notification.so
lib/samba/ldb/encrypted_secrets.so
lib/samba/ldb/extended_dn_in.so
lib/samba/ldb/extended_dn_out.so
lib/samba/ldb/extended_dn_store.so
lib/samba/ldb/group_audit_log.so
lib/samba/ldb/ildap.so
lib/samba/ldb/instancetype.so
lib/samba/ldb/lazy_commit.so
lib/samba/ldb/ldb.so
lib/samba/ldb/ldbsamba_extensions.so
lib/samba/ldb/linked_attributes.so
lib/samba/ldb/local_password.so
${PLIST.64bit}lib/samba/ldb/mdb.so
lib/samba/ldb/new_partition.so
lib/samba/ldb/objectclass.so
lib/samba/ldb/objectclass_attrs.so
lib/samba/ldb/objectguid.so
lib/samba/ldb/operational.so
lib/samba/ldb/paged_results.so
lib/samba/ldb/paged_searches.so
lib/samba/ldb/partition.so
lib/samba/ldb/password_hash.so
lib/samba/ldb/ranged_results.so
lib/samba/ldb/rdn_name.so
lib/samba/ldb/repl_meta_data.so
lib/samba/ldb/resolve_oids.so
lib/samba/ldb/rootdse.so
lib/samba/ldb/samba3sam.so
lib/samba/ldb/samba3sid.so
lib/samba/ldb/samba_dsdb.so
lib/samba/ldb/samba_secrets.so
lib/samba/ldb/samldb.so
lib/samba/ldb/sample.so
lib/samba/ldb/schema_data.so
lib/samba/ldb/schema_load.so
lib/samba/ldb/secrets_tdb_sync.so
lib/samba/ldb/server_sort.so
lib/samba/ldb/show_deleted.so
lib/samba/ldb/simple_dn.so
lib/samba/ldb/simple_ldap_map.so
lib/samba/ldb/skel.so
lib/samba/ldb/subtree_delete.so
lib/samba/ldb/subtree_rename.so
lib/samba/ldb/tdb.so
lib/samba/ldb/tombstone_reanimate.so
lib/samba/ldb/unique_object_sids.so
lib/samba/ldb/update_keytab.so
lib/samba/ldb/vlv.so
lib/samba/ldb/wins_ldb.so
lib/samba/nss_info/hash.so
${PLIST.ldap}lib/samba/nss_info/rfc2307.so
${PLIST.ldap}lib/samba/nss_info/sfu.so
${PLIST.ldap}lib/samba/nss_info/sfu20.so
a626 1
lib/samba/private/libcmocka-samba4.so
d739 70
a808 53
lib/samba/process_model/prefork.so
lib/samba/process_model/standard.so
${PLIST.pam}lib/samba/security/pam_winbind.so
lib/samba/service/cldap.so
lib/samba/service/dcerpc.so
lib/samba/service/dns.so
lib/samba/service/dns_update.so
lib/samba/service/drepl.so
lib/samba/service/kcc.so
lib/samba/service/kdc.so
lib/samba/service/ldap.so
lib/samba/service/nbtd.so
lib/samba/service/ntp_signd.so
lib/samba/service/s3fs.so
lib/samba/service/web.so
lib/samba/service/winbindd.so
lib/samba/service/wrepl.so
lib/samba/vfs/acl_tdb.so
lib/samba/vfs/acl_xattr.so
lib/samba/vfs/aio_fork.so
lib/samba/vfs/aio_pthread.so
lib/samba/vfs/audit.so
lib/samba/vfs/cap.so
lib/samba/vfs/catia.so
lib/samba/vfs/commit.so
lib/samba/vfs/crossrename.so
lib/samba/vfs/default_quota.so
lib/samba/vfs/dirsort.so
lib/samba/vfs/expand_msdfs.so
lib/samba/vfs/extd_audit.so
lib/samba/vfs/fake_perms.so
lib/samba/vfs/fruit.so
lib/samba/vfs/full_audit.so
lib/samba/vfs/linux_xfs_sgid.so
lib/samba/vfs/media_harmony.so
lib/samba/vfs/netatalk.so
lib/samba/vfs/offline.so
lib/samba/vfs/posix_eadb.so
lib/samba/vfs/preopen.so
lib/samba/vfs/readahead.so
lib/samba/vfs/readonly.so
lib/samba/vfs/recycle.so
lib/samba/vfs/shadow_copy.so
lib/samba/vfs/shadow_copy2.so
lib/samba/vfs/shell_snap.so
lib/samba/vfs/streams_depot.so
lib/samba/vfs/streams_xattr.so
lib/samba/vfs/syncops.so
lib/samba/vfs/time_audit.so
lib/samba/vfs/unityed_media.so
lib/samba/vfs/virusfilter.so
lib/samba/vfs/worm.so
lib/samba/vfs/xattr_tdb.so
d810 19
d834 83
@


1.16
log
@FIx build on 32-bit architecture environments.

ldb-lmdb part is not buildable for 32-bit architecture environments.
Tested on NetBSD/i386 8.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.15 2018/12/03 13:51:52 mlelstv Exp $
d670 1
a670 1
${PLIST.64-bit}lib/samba/private/libldb-mdb-int-samba4.so
@


1.15
log
@Set SMB_PRIVATE directory correctly.
Add two missing libraries to PLIST.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.14 2018/11/23 07:30:02 ryoon Exp $
d563 1
a563 1
lib/samba/ldb/mdb.so
d670 1
a670 1
lib/samba/private/libldb-mdb-int-samba4.so
@


1.14
log
@Update to 4.9.2

Changelog:
* Many bugfixes
* Update some bundled libraries
@
text
@d1 1
a1 1
@@comment $NetBSD$
d626 1
d689 1
@


1.13
log
@net/samba4: use devel/talloc package instead of bundled library.

I'd like to install net/samba4 and net/freeradius on the same server.
But devel/talloc on which net/freeradius depends conflicts bundled talloc
library used in net/samba.
net/samba also should use devel/talloc package.

Bump PKGREVISION.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.12 2017/05/24 15:51:32 he Exp $
a3 1
bin/eventlogadm
d52 1
d54 1
d128 1
d155 1
a155 1
lib/libndr.so.0.0.8
d169 1
a169 1
lib/libsamba-passdb.so.0.26.0
d181 1
a181 1
lib/libsmbclient.so.0.2.3
d185 1
a185 1
${PLIST.ldap}lib/libsmbldap.so.0
d191 1
a191 1
lib/libwbclient.so.0.13
d241 1
a241 1
${PYSITELIB}/samba/com.so
d243 1
d265 1
d270 1
d284 2
d289 4
d295 4
d308 1
d311 1
d313 1
d319 1
d324 1
d327 1
d335 1
d337 1
d339 1
d344 1
d346 1
d353 2
d374 3
d378 7
d386 2
d390 4
a393 1
${PYSITELIB}/samba/tests/blackbox/samba_tool_drs.py
d404 1
d413 1
d415 1
d418 1
d420 1
d422 1
d424 6
d432 5
d438 1
d444 1
d446 2
d449 3
d453 1
d455 4
d460 7
d470 2
d473 5
a477 1
${PYSITELIB}/samba/tests/samba3.py
d481 2
d484 1
d488 1
d491 2
d494 1
d496 1
d501 4
d506 1
d508 1
d512 1
d522 1
d541 1
d546 1
d551 1
d555 1
d559 1
d563 1
d596 1
d607 1
a613 1
lib/samba/private/libauth-sam-reply-samba4.so
d627 1
d630 1
d644 1
a644 1
lib/samba/private/libgpo-samba4.so
d668 2
d671 1
a671 1
lib/samba/private/libldb.so.1.1.29
d693 1
a693 1
lib/samba/private/libpyldb-util.so.1.1.29
d707 1
d725 1
a725 1
lib/samba/private/libtdb.so.1.3.12
d727 1
a727 1
lib/samba/private/libtevent.so.0.9.31
d739 1
d789 1
a791 1
lib/winbind_krb5_locator.so
d798 1
d801 1
d826 8
d839 8
d855 1
d930 3
@


1.12
log
@Update samba4 to version 4.6.4.

Pkgsrc changes:
 * Adapt PLIST, new .so installed.

Upstream changes:

Changes since 4.6.3:
---------------------
o  Volker Lendecke <vl@@samba.org>
   * BUG 12780: CVE-2017-7494: Avoid remote code execution from a writable
     share.

Changes since 4.6.2:
--------------------
o  Michael Adam <obnox@@samba.org>
   * BUG 12743: s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots
     from shares with GlusterFS backend.

o  Jeremy Allison <jra@@samba.org>
   * BUG 12559: Fix for Solaris C compiler.
   * BUG 12628: s3: locking: Update oplock optimization for the leases era.
   * BUG 12693: Make the Solaris C compiler happy.
   * BUG 12695: s3: libgpo: Allow skipping GPO objects that don't have the
     expected LDAP attributes.
   * BUG 12747: Fix buffer overflow caused by wrong use of getgroups.

o  Hanno Boeck <hanno@@hboeck.de>
   * BUG 12746: lib: debug: Avoid negative array access.
   * BUG 12748: cleanupdb: Fix a memory read error.

o  Ralph Boehme <slow@@samba.org>
   * BUG 7537: streams_xattr and kernel oplocks results in
     NT_STATUS_NETWORK_BUSY.
   * BUG 11961: winbindd: idmap_autorid allocates ids for unknown SIDs from
     other backends.
   * BUG 12565: vfs_fruit: Resource fork open request with
     flags=O_CREAT|O_RDONLY.
   * BUG 12615: manpages/vfs_fruit: Document global options.
   * BUG 12624: lib/pthreadpool: Fix a memory leak.
   * BUG 12727: Lookup-domain for well-known SIDs on a DC.
   * BUG 12728: winbindd: Fix error handling in rpc_lookup_sids().
   * BUG 12729: winbindd: Trigger possible passdb_dsdb initialisation.

o  Alexander Bokovoy <ab@@samba.org>
   * BUG 12611: credentials_krb5: use gss_acquire_cred for client-side GSSAPI
     use case.
   * BUG 12690: lib/crypto: Implement samba.crypto Python module for RC4.

o  Amitay Isaacs <amitay@@gmail.com>
   * BUG 12697: ctdb-readonly: Avoid a tight loop waiting for revoke to
     complete.
   * BUG 12723: ctdb_event monitor command crashes if event is not specified.
   * BUG 12733: ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'.

o  Volker Lendecke <vl@@samba.org>
   * BUG 12558: smbd: Fix smb1 findfirst with DFS.
   * BUG 12610: smbd: Do an early exit on negprot failure.
   * BUG 12699: winbindd: Fix substitution for 'template homedir'.

o  Stefan Metzmacher <metze@@samba.org>
   * BUG 12554: s4:kdc: Disable principal based autodetected referral detection.
   * BUG 12613: idmap_autorid: Allocate new domain range if the callers knows
     the sid is valid.
   * BUG 12724: LINKFLAGS_PYEMBED should not contain -L/some/path.
   * BUG 12725: PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for
     trusted domain.
   * BUG 12731: rpcclient: Allow -U'OTHERDOMAIN\user' again.

o  Christof Schmitt <cs@@samba.org>
   * BUG 12725: winbindd: Fix password policy for pam authentication.

o  Andreas Schneider <asn@@samba.org>
   * BUG 12554: s3:gse: Correctly handle external trusts with MIT.
   * BUG 12611: auth/credentials: Always set the realm if we set the principal
     from the ccache.
   * BUG 12686: replace: Include sysmacros.h.
   * BUG 12687: s3:vfs_expand_msdfs: Do not open the remote address as a file.
   * BUG 12704: s3:libsmb: Only print error message if kerberos use is forced.
   * BUG 12708: winbindd: Child process crashes when kerberos-authenticating
     a user with wrong password.

o  Uri Simchoni <uri@@samba.org>
   * BUG 12715: vfs_fruit: Office document opens as read-only on macOS due to
     CNID semantics.
   * BUG 12737: vfs_acl_xattr: Fix failure to get ACL on Linux if memory is
     fragmented.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.11 2017/04/08 08:56:27 ryoon Exp $
a424 1
${PYSITELIB}/talloc.so
a581 2
lib/samba/private/libpytalloc-util.so.2
lib/samba/private/libpytalloc-util.so.2.1.9
a609 2
lib/samba/private/libtalloc.so.2
lib/samba/private/libtalloc.so.2.1.9
@


1.11
log
@Update to 4.6.2

* Use internal heimdal

Changelog:
Changes since 4.6.1:
--------------------

o  Jeremy Allison <jra@@samba.org>
   * BUG 12721: Fix regression with "follow symlinks = no".

Changes since 4.6.0:
--------------------

o  Jeremy Allison <jra@@samba.org>
   * BUG 12496: CVE-2017-2619: Symlink race permits opening files outside share
     directory.

o  Ralph Boehme <slow@@samba.org>
   * BUG 12496: CVE-2017-2619: Symlink race permits opening files outside share
     directory.

CHANGES SINCE 4.6.0rc4
======================

o  Jeremy Allison <jra@@samba.org>
   * BUG 12592: Fix several issues found by covscan.
   * BUG 12608: s3: smbd: Restart reading the incoming SMB2 fd when the send
     queue is drained.

o  Ralph Boehme <slow@@samba.org>
   * BUG 12427: vfs_fruit doesn't work with fruit:metadata=stream.
   * BUG 12526: vfs_fruit: Only veto AppleDouble files if "fruit:resource" is
     set to "file".
   * BUG 12604: vfs_fruit: Enabling AAPL extensions must be a global switch.

o  Volker Lendecke <vl@@samba.org>
   * BUG 12612: Re-enable token groups fallback.

o  Stefan Metzmacher <metze@@samba.org>
   * BUG 9048: Samba4 ldap error codes.
   * BUG 12557: gensec:spnego: Add debug message for the failed principal.
   * BUG 12605: s3:winbindd: Fix endless forest trust scan.
   * BUG 12612: winbindd: Find the domain based on the sid within
     wb_lookupusergroups_send().

o  Andreas Schneider <asn@@samba.org>
   * BUG 12557: s3:librpc: Handle gss_min in gse_get_client_auth_token()
     correctly.
   * BUG 12582: idmap_hash: Add a deprecation message, improve the idmap_hash
     manpage.
   * BUG 12592: Fix several issues found by covscan.

o  Martin Schwenke <martin@@meltin.net>
   * BUG 12592: ctdb-logging: CID 1396883 Dereference null return value
     (NULL_RETURNS).


CHANGES SINCE 4.6.0rc3
======================

o  Jeremy Allison <jra@@samba.org>
   * BUG 12545: s3: rpc_server/mdssvc: Add attribute "kMDItemContentType".
   * BUG 12572: s3: smbd: Don't loop infinitely on bad-symlink resolution.

o  Ralph Boehme <slow@@samba.org>
   * BUG 12490: vfs_fruit: Correct Netatalk metadata xattr on FreeBSD.
   * BUG 12536: s3/smbd: Check for invalid access_mask
     smbd_calculate_access_mask().
   * BUG 12591: vfs_streams_xattr: use fsp, not base_fsp.

o  Amitay Isaacs <amitay@@gmail.com>
   * BUG 12580: ctdb-common: Fix use-after-free error in comm_fd_handler().
   * BUG 12595: build: Fix generation of CTDB manpages while creating tarball.

o  Bryan Mason <bmason@@redhat.com>
   * BUG 12575: Modify smbspool_krb5_wrapper to just fall through to smbspool if
     AUTH_INFO_REQUIRED is not set or is not "negotiate".

o  Stefan Metzmacher <metze@@samba.org>
   * BUG 11830: s3:winbindd: Try a NETLOGON connection with noauth over NCACN_NP
     against trusted domains.
   * BUG 12262: 'net ads testjoin' and smb access fails after winbindd changed the
     trust password.
   * BUG 12585: librpc/rpc: fix regression in
     NT_STATUS_RPC_ENUM_VALUE_OUT_OF_RANGE error mapping.
   * BUG 12586: netlogon_creds_cli_LogonSamLogon doesn't work without
     netr_LogonSamLogonEx.
   * BUG 12587: winbindd child segfaults on connect to an NT4 domain.
   * BUG 12588: s3:winbindd: Make sure cm_prepare_connection() only returns OK
     with a valid tree connect.
   * BUG 12598: winbindd (as member) requires kerberos against trusted ad domain,
     while it shouldn't.
   * BUG 12601: Backport pytalloc_GenericObject_reference() related changes to
     4.6.

o  Garming Sam <garming@@catalyst.net.nz>
   * BUG 12600: dbchecker: Stop ignoring linked cases where both objects are
     alive.

o  Andreas Schneider <asn@@samba.org>
   * BUG 12571: s3-vfs: Only walk the directory once in open_and_sort_dir().

o  Martin Schwenke <martin@@meltin.net>
   * BUG 12589: CTDB statd-callout does not cause grace period when
     CTDB_NFS_CALLOUT="".
   * BUG 12595: ctdb-build: Fix RPM build.


CHANGES SINCE 4.6.0rc2
======================

o  Jeremy Allison <jra@@samba.org>
   * BUG 12499: s3: vfs: dirsort doesn't handle opendir of "." correctly.
   * BUG 12546: s3: VFS: vfs_streams_xattr.c: Make streams_xattr_open() store
     the same path as streams_xattr_recheck().
   * BUG 12531: Make vfs_shadow_copy2 cope with server changing directories.

o  Andrew Bartlett <abartlet@@samba.org>
   * BUG 12543: samba-tool: Correct handling of default value for use_ntvfs and
     use_xattrs.
   * BUG 12573: Samba < 4.7 does not know about compatibleFeatures and
     requiredFeatures.
   * BUG 12577: 'samba-tool dbcheck' gives errors on one-way links after a
     rename.

o  Ralph Boehme <slow@@samba.org>
   * BUG 12184: s3/rpc_server: Shared rpc modules loading.
   * BUG 12520: Ensure global "smb encrypt = off" is effective.
   * BUG 12524: s3/rpc_server: Move rpc_modules.c to its own subsystem.
   * BUG 12541: vfs_fruit: checks wrong AAPL config state and so always uses
     readdirattr.

o  Volker Lendecke <vl@@samba.org>
   * BUG 12551: smbd: Fix "map acl inherit" = yes.

o  Stefan Metzmacher <metze@@samba.org>
   * BUG 12398: Replication with DRSUAPI_DRS_CRITICAL_ONLY and
     DRSUAPI_DRS_GET_ANC results in WERR_DS_DRA_MISSING_PARENT S
   * BUG 12540: s3:smbd: allow "server min protocol = SMB3_00" to go via "SMB
     2.???" negprot.

o  John Mulligan <jmulligan@@nasuni.com>
   * BUG 12542: docs: Improve description of "unix_primary_group" parameter in
     idmap_ad manpage.

o  Andreas Schneider <asn@@samba.org>
   * BUG 12552: waf: Do not install the unit test binary for krb5samba.

o  Amitay Isaacs <amitay@@gmail.com>
   * BUG 12547: ctdb-build: Install CTDB tests correctly from toplevel.
   * BUG 12549: ctdb-common: ioctl(.. FIONREAD ..) returns an int value.

o  Garming Sam <garming@@catalyst.net.nz>
   * BUG 12577: 'samba-tool dbcheck' gives errors on one-way links after a
     rename.

o  Uri Simchoni <uri@@samba.org>
   * BUG 12529: waf: Backport finding of pkg-config.


CHANGES SINCE 4.6.0rc1
======================

o  Amitay Isaacs <amitay@@gmail.com>
   * BUG 12469: CTDB lock helper getting stuck trying to lock a record.
   * BUG 12500: ctdb-common: Fix a bug in packet reading code for generic socket
     I/O.
   * BUG 12510: sock_daemon_test 4 crashes with SEGV.
   * BUG 12513: ctdb-daemon: Remove stale eventd socket.

o  Björn Jacke <bj@@sernet.de>
   * BUG 12535: vfs_default: Unlock the right file in copy chunk.

o  Volker Lendecke <vl@@samba.org>
   * BUG 12509: messaging: Fix dead but not cleaned-up-yet destination sockets.
   * BUG 12538: Backport winbind fixes.

o  Stefan Metzmacher <metze@@samba.org>
   * BUG 12501: s3:winbindd: talloc_steal the extra_data in
     winbindd_list_users_recv().

o  Martin Schwenke <martin@@meltin.net>
   * BUG 12511: ctdb-takeover: Handle case where there are no RELEASE_IPs to
     send.
   * BUG 12512: ctdb-scripts: Fix remaining uses of "ctdb gratiousarp".
   * BUG 12516: ctdb-scripts: /etc/iproute2/rt_tables gets populated with multiple
     'default' entries.
@
text
@d1 1
a1 1
@@comment $NetBSD$
d242 1
@


1.10
log
@Update PLIST
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.9 2016/07/11 12:28:17 wiz Exp $
d5 1
d15 1
d29 1
a38 1
bin/smbta-util
d56 1
a56 1
include/dlinklist.h
a62 1
include/gen_ndr/epmapper.h
a64 1
include/gen_ndr/mgmt.h
a67 1
include/gen_ndr/ndr_atsvc_c.h
a70 2
include/gen_ndr/ndr_epmapper.h
include/gen_ndr/ndr_epmapper_c.h
a71 2
include/gen_ndr/ndr_mgmt.h
include/gen_ndr/ndr_mgmt_c.h
a82 5
include/gensec.h
include/ldap-util.h
include/ldap_errors.h
include/ldap_message.h
include/ldap_ndr.h
d91 1
a97 4
include/pytalloc.h
include/read_smb.h
include/registry.h
include/roles.h
a100 1
include/samba_util.h
a101 4
include/smb2.h
include/smb2_constants.h
include/smb2_create_blob.h
include/smb2_lease.h
a102 6
include/smb2_signing.h
include/smb_cli.h
include/smb_cliraw.h
include/smb_common.h
include/smb_composite.h
include/smb_constants.h
a103 9
include/smb_raw.h
include/smb_raw_interfaces.h
include/smb_raw_signing.h
include/smb_raw_trans2.h
include/smb_request.h
include/smb_seal.h
include/smb_signing.h
include/smb_unix_ext.h
include/smb_util.h
a106 1
include/torture.h
a108 1
include/tstream_smbXcli_np.h
a127 1
include/util/xfile.h
a129 3
lib/libdcerpc-atsvc.so
lib/libdcerpc-atsvc.so.0
lib/libdcerpc-atsvc.so.0.0.1
d136 3
a141 3
lib/libgensec.so
lib/libgensec.so.0
lib/libgensec.so.0.0.1
d153 1
a153 1
lib/libndr.so.0.0.5
a156 3
lib/libregistry.so
lib/libregistry.so.0
lib/libregistry.so.0.0.1
d160 2
d167 1
a167 1
lib/libsamba-passdb.so.0.24.1
a176 3
lib/libsmbclient-raw.so
lib/libsmbclient-raw.so.0
lib/libsmbclient-raw.so.0.0.1
a186 3
lib/libtorture.so
lib/libtorture.so.0
lib/libtorture.so.0.0.1
d189 1
a189 1
lib/libwbclient.so.0.12
a216 1
lib/pkgconfig/dcerpc_atsvc.pc
d218 1
a218 1
lib/pkgconfig/gensec.pc
a223 1
lib/pkgconfig/registry.pc
a228 1
lib/pkgconfig/smbclient-raw.pc
a229 1
lib/pkgconfig/torture.pc
d231 1
d276 1
d280 1
d311 1
a317 1
${PYSITELIB}/samba/netcmd/time.py
a318 1
${PYSITELIB}/samba/netcmd/vampire.py
d322 1
d328 1
d340 1
d348 1
d354 1
d365 1
d369 3
d395 1
d399 1
d402 2
d406 1
d422 2
d428 5
d440 3
d444 7
d452 2
d455 7
d464 3
d468 8
d477 3
d481 3
d485 2
d488 4
d497 1
d502 2
d519 3
d525 4
a529 1
lib/samba/private/liberrors-samba4.so
d533 1
d536 10
d547 2
d552 4
d559 1
a559 1
lib/samba/private/libldb.so.1.1.21
d575 1
d577 1
d579 1
d581 1
a581 1
lib/samba/private/libpyldb-util.so.1.1.21
d583 2
a584 1
lib/samba/private/libpytalloc-util.so.2.1.3
d586 2
d600 1
d603 1
a608 1
lib/samba/private/libsmbregistry-samba4.so
d613 1
a613 1
lib/samba/private/libtalloc.so.2.1.3
d616 1
a616 1
lib/samba/private/libtdb.so.1.3.7
d618 1
a618 1
lib/samba/private/libtevent.so.0.9.28
d620 1
d627 2
d630 1
a630 1
${PLIST.pam}lib/samba/security/pam_smbpass.so
d632 14
a648 1
lib/samba/vfs/aio_posix.so
d656 1
d665 2
a666 1
${PLIST.fam}lib/samba/vfs/notify_fam.so
a670 1
lib/samba/vfs/scannedonly.so
a673 1
lib/samba/vfs/smb_traffic_analyzer.so
d676 1
d689 5
a710 5
${PLIST.pam}share/examples/samba/pam_smbpass/README
${PLIST.pam}share/examples/samba/pam_smbpass/kdc-pdc
${PLIST.pam}share/examples/samba/pam_smbpass/password-mature
${PLIST.pam}share/examples/samba/pam_smbpass/password-migration
${PLIST.pam}share/examples/samba/pam_smbpass/password-sync
d713 88
@


1.10.6.1
log
@Pullup ticket #5431 - requested by he
net/samba4: security fix

Revisions pulled up:
- net/samba4/Makefile                                           1.28-1.30
- net/samba4/PLIST                                              1.11-1.12
- net/samba4/distinfo                                           1.12-1.13
- net/samba4/options.mk                                         1.4
- net/samba4/patches/patch-lib_param_loadparm.h                 1.2
- net/samba4/patches/patch-source3_script_tests_test__smbclient__s3.sh 1.3

---
   Module Name:	pkgsrc
   Committed By:	ryoon
   Date:		Sat Apr  8 08:56:27 UTC 2017

   Modified Files:
   	pkgsrc/net/samba4: Makefile PLIST distinfo options.mk
   	pkgsrc/net/samba4/patches: patch-lib_param_loadparm.h
   	    patch-source3_script_tests_test__smbclient__s3.sh

   Log Message:
   Update to 4.6.2

   * Use internal heimdal

   Changelog:
   Changes since 4.6.1:
   --------------------

   o  Jeremy Allison <jra@@samba.org>
      * BUG 12721: Fix regression with "follow symlinks = no".

   Changes since 4.6.0:
   --------------------

   o  Jeremy Allison <jra@@samba.org>
      * BUG 12496: CVE-2017-2619: Symlink race permits opening files outside share
        directory.

   o  Ralph Boehme <slow@@samba.org>
      * BUG 12496: CVE-2017-2619: Symlink race permits opening files outside share
        directory.

   CHANGES SINCE 4.6.0rc4
   ======================

   o  Jeremy Allison <jra@@samba.org>
      * BUG 12592: Fix several issues found by covscan.
      * BUG 12608: s3: smbd: Restart reading the incoming SMB2 fd when the send
        queue is drained.

   o  Ralph Boehme <slow@@samba.org>
      * BUG 12427: vfs_fruit doesn't work with fruit:metadata=stream.
      * BUG 12526: vfs_fruit: Only veto AppleDouble files if "fruit:resource" is
        set to "file".
      * BUG 12604: vfs_fruit: Enabling AAPL extensions must be a global switch.

   o  Volker Lendecke <vl@@samba.org>
      * BUG 12612: Re-enable token groups fallback.

   o  Stefan Metzmacher <metze@@samba.org>
      * BUG 9048: Samba4 ldap error codes.
      * BUG 12557: gensec:spnego: Add debug message for the failed principal.
      * BUG 12605: s3:winbindd: Fix endless forest trust scan.
      * BUG 12612: winbindd: Find the domain based on the sid within
        wb_lookupusergroups_send().

   o  Andreas Schneider <asn@@samba.org>
      * BUG 12557: s3:librpc: Handle gss_min in gse_get_client_auth_token()
        correctly.
      * BUG 12582: idmap_hash: Add a deprecation message, improve the idmap_hash
        manpage.
      * BUG 12592: Fix several issues found by covscan.

   o  Martin Schwenke <martin@@meltin.net>
      * BUG 12592: ctdb-logging: CID 1396883 Dereference null return value
        (NULL_RETURNS).

   CHANGES SINCE 4.6.0rc3
   ======================

   o  Jeremy Allison <jra@@samba.org>
      * BUG 12545: s3: rpc_server/mdssvc: Add attribute "kMDItemContentType".
      * BUG 12572: s3: smbd: Don't loop infinitely on bad-symlink resolution.

   o  Ralph Boehme <slow@@samba.org>
      * BUG 12490: vfs_fruit: Correct Netatalk metadata xattr on FreeBSD.
      * BUG 12536: s3/smbd: Check for invalid access_mask
        smbd_calculate_access_mask().
      * BUG 12591: vfs_streams_xattr: use fsp, not base_fsp.

   o  Amitay Isaacs <amitay@@gmail.com>
      * BUG 12580: ctdb-common: Fix use-after-free error in comm_fd_handler().
      * BUG 12595: build: Fix generation of CTDB manpages while creating tarball.

   o  Bryan Mason <bmason@@redhat.com>
      * BUG 12575: Modify smbspool_krb5_wrapper to just fall through to smbspool if
        AUTH_INFO_REQUIRED is not set or is not "negotiate".

   o  Stefan Metzmacher <metze@@samba.org>
      * BUG 11830: s3:winbindd: Try a NETLOGON connection with noauth over NCACN_NP
        against trusted domains.
      * BUG 12262: 'net ads testjoin' and smb access fails after winbindd changed the
        trust password.
      * BUG 12585: librpc/rpc: fix regression in
        NT_STATUS_RPC_ENUM_VALUE_OUT_OF_RANGE error mapping.
      * BUG 12586: netlogon_creds_cli_LogonSamLogon doesn't work without
        netr_LogonSamLogonEx.
      * BUG 12587: winbindd child segfaults on connect to an NT4 domain.
      * BUG 12588: s3:winbindd: Make sure cm_prepare_connection() only returns OK
        with a valid tree connect.
      * BUG 12598: winbindd (as member) requires kerberos against trusted ad domain,
        while it shouldn't.
      * BUG 12601: Backport pytalloc_GenericObject_reference() related changes to
        4.6.

   o  Garming Sam <garming@@catalyst.net.nz>
      * BUG 12600: dbchecker: Stop ignoring linked cases where both objects are
        alive.

   o  Andreas Schneider <asn@@samba.org>
      * BUG 12571: s3-vfs: Only walk the directory once in open_and_sort_dir().

   o  Martin Schwenke <martin@@meltin.net>
      * BUG 12589: CTDB statd-callout does not cause grace period when
        CTDB_NFS_CALLOUT="".
      * BUG 12595: ctdb-build: Fix RPM build.

   CHANGES SINCE 4.6.0rc2
   ======================

   o  Jeremy Allison <jra@@samba.org>
      * BUG 12499: s3: vfs: dirsort doesn't handle opendir of "." correctly.
      * BUG 12546: s3: VFS: vfs_streams_xattr.c: Make streams_xattr_open() store
        the same path as streams_xattr_recheck().
      * BUG 12531: Make vfs_shadow_copy2 cope with server changing directories.

   o  Andrew Bartlett <abartlet@@samba.org>
      * BUG 12543: samba-tool: Correct handling of default value for use_ntvfs and
        use_xattrs.
      * BUG 12573: Samba < 4.7 does not know about compatibleFeatures and
        requiredFeatures.
      * BUG 12577: 'samba-tool dbcheck' gives errors on one-way links after a
        rename.

   o  Ralph Boehme <slow@@samba.org>
      * BUG 12184: s3/rpc_server: Shared rpc modules loading.
      * BUG 12520: Ensure global "smb encrypt = off" is effective.
      * BUG 12524: s3/rpc_server: Move rpc_modules.c to its own subsystem.
      * BUG 12541: vfs_fruit: checks wrong AAPL config state and so always uses
        readdirattr.

   o  Volker Lendecke <vl@@samba.org>
      * BUG 12551: smbd: Fix "map acl inherit" = yes.

   o  Stefan Metzmacher <metze@@samba.org>
      * BUG 12398: Replication with DRSUAPI_DRS_CRITICAL_ONLY and
        DRSUAPI_DRS_GET_ANC results in WERR_DS_DRA_MISSING_PARENT S
      * BUG 12540: s3:smbd: allow "server min protocol = SMB3_00" to go via "SMB
        2.???" negprot.

   o  John Mulligan <jmulligan@@nasuni.com>
      * BUG 12542: docs: Improve description of "unix_primary_group" parameter in
        idmap_ad manpage.

   o  Andreas Schneider <asn@@samba.org>
      * BUG 12552: waf: Do not install the unit test binary for krb5samba.

   o  Amitay Isaacs <amitay@@gmail.com>
      * BUG 12547: ctdb-build: Install CTDB tests correctly from toplevel.
      * BUG 12549: ctdb-common: ioctl(.. FIONREAD ..) returns an int value.

   o  Garming Sam <garming@@catalyst.net.nz>
      * BUG 12577: 'samba-tool dbcheck' gives errors on one-way links after a
        rename.

   o  Uri Simchoni <uri@@samba.org>
      * BUG 12529: waf: Backport finding of pkg-config.

   CHANGES SINCE 4.6.0rc1
   ======================

   o  Amitay Isaacs <amitay@@gmail.com>
      * BUG 12469: CTDB lock helper getting stuck trying to lock a record.
      * BUG 12500: ctdb-common: Fix a bug in packet reading code for generic socket
        I/O.
      * BUG 12510: sock_daemon_test 4 crashes with SEGV.
      * BUG 12513: ctdb-daemon: Remove stale eventd socket.

   o  Björn Jacke <bj@@sernet.de>
      * BUG 12535: vfs_default: Unlock the right file in copy chunk.

   o  Volker Lendecke <vl@@samba.org>
      * BUG 12509: messaging: Fix dead but not cleaned-up-yet destination sockets.
      * BUG 12538: Backport winbind fixes.

   o  Stefan Metzmacher <metze@@samba.org>
      * BUG 12501: s3:winbindd: talloc_steal the extra_data in
        winbindd_list_users_recv().

   o  Martin Schwenke <martin@@meltin.net>
      * BUG 12511: ctdb-takeover: Handle case where there are no RELEASE_IPs to
        send.
      * BUG 12512: ctdb-scripts: Fix remaining uses of "ctdb gratiousarp".
      * BUG 12516: ctdb-scripts: /etc/iproute2/rt_tables gets populated with multiple
        'default' entries.

---
   Module Name:	pkgsrc
   Committed By:	jnemeth
   Date:		Mon Apr 10 15:27:22 UTC 2017

   Modified Files:
   	pkgsrc/net/samba4: Makefile

   Log Message:
   Add pkg-config to USE_TOOLS, which is needed to find gnutls.
   Problem found in a bulk build.  Not bumping PKGREVISION since it
   shouldn't change the binary package when it built.

---
   Module Name:    pkgsrc
   Committed By:   he
   Date:           Wed May 24 15:51:32 UTC 2017

   Modified Files:
           pkgsrc/net/samba4: Makefile PLIST distinfo

   Log Message:
   Update samba4 to version 4.6.4.

   Pkgsrc changes:
    * Adapt PLIST, new .so installed.

   Upstream changes:

   Changes since 4.6.3:
   ---------------------
   o  Volker Lendecke <vl@@samba.org>
      * BUG 12780: CVE-2017-7494: Avoid remote code execution from a writable
        share.

   Changes since 4.6.2:
   --------------------
   o  Michael Adam <obnox@@samba.org>
      * BUG 12743: s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots
        from shares with GlusterFS backend.

   o  Jeremy Allison <jra@@samba.org>
      * BUG 12559: Fix for Solaris C compiler.
      * BUG 12628: s3: locking: Update oplock optimization for the leases era.
      * BUG 12693: Make the Solaris C compiler happy.
      * BUG 12695: s3: libgpo: Allow skipping GPO objects that don't have the
        expected LDAP attributes.
      * BUG 12747: Fix buffer overflow caused by wrong use of getgroups.

   o  Hanno Boeck <hanno@@hboeck.de>
      * BUG 12746: lib: debug: Avoid negative array access.
      * BUG 12748: cleanupdb: Fix a memory read error.

   o  Ralph Boehme <slow@@samba.org>
      * BUG 7537: streams_xattr and kernel oplocks results in
        NT_STATUS_NETWORK_BUSY.
      * BUG 11961: winbindd: idmap_autorid allocates ids for unknown SIDs from
        other backends.
      * BUG 12565: vfs_fruit: Resource fork open request with
        flags=O_CREAT|O_RDONLY.
      * BUG 12615: manpages/vfs_fruit: Document global options.
      * BUG 12624: lib/pthreadpool: Fix a memory leak.
      * BUG 12727: Lookup-domain for well-known SIDs on a DC.
      * BUG 12728: winbindd: Fix error handling in rpc_lookup_sids().
      * BUG 12729: winbindd: Trigger possible passdb_dsdb initialisation.

   o  Alexander Bokovoy <ab@@samba.org>
      * BUG 12611: credentials_krb5: use gss_acquire_cred for client-side GSSAPI
        use case.
      * BUG 12690: lib/crypto: Implement samba.crypto Python module for RC4.

   o  Amitay Isaacs <amitay@@gmail.com>
      * BUG 12697: ctdb-readonly: Avoid a tight loop waiting for revoke to
        complete.
      * BUG 12723: ctdb_event monitor command crashes if event is not specified.
      * BUG 12733: ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'.

   o  Volker Lendecke <vl@@samba.org>
      * BUG 12558: smbd: Fix smb1 findfirst with DFS.
      * BUG 12610: smbd: Do an early exit on negprot failure.
      * BUG 12699: winbindd: Fix substitution for 'template homedir'.

   o  Stefan Metzmacher <metze@@samba.org>
      * BUG 12554: s4:kdc: Disable principal based autodetected referral detection.
      * BUG 12613: idmap_autorid: Allocate new domain range if the callers knows
        the sid is valid.
      * BUG 12724: LINKFLAGS_PYEMBED should not contain -L/some/path.
      * BUG 12725: PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for
        trusted domain.
      * BUG 12731: rpcclient: Allow -U'OTHERDOMAIN\user' again.

   o  Christof Schmitt <cs@@samba.org>
      * BUG 12725: winbindd: Fix password policy for pam authentication.

   o  Andreas Schneider <asn@@samba.org>
      * BUG 12554: s3:gse: Correctly handle external trusts with MIT.
      * BUG 12611: auth/credentials: Always set the realm if we set the principal
        from the ccache.
      * BUG 12686: replace: Include sysmacros.h.
      * BUG 12687: s3:vfs_expand_msdfs: Do not open the remote address as a file.
      * BUG 12704: s3:libsmb: Only print error message if kerberos use is forced.
      * BUG 12708: winbindd: Child process crashes when kerberos-authenticating
        a user with wrong password.

   o  Uri Simchoni <uri@@samba.org>
      * BUG 12715: vfs_fruit: Office document opens as read-only on macOS due to
        CNID semantics.
      * BUG 12737: vfs_acl_xattr: Fix failure to get ACL on Linux if memory is
        fragmented.
@
text
@d1 1
a1 1
@@comment $NetBSD$
a4 1
bin/findsmb
a13 1
bin/mvxattr
a26 1
bin/samba-tool
d36 1
d54 1
a54 1
include/dcerpc_server.h
d61 1
d64 1
d68 1
d72 2
d75 2
d88 5
a100 1
include/ndr/ndr_krb5pac.h
d107 4
d114 1
d116 4
d121 6
d128 9
d140 1
d143 1
d163 1
d166 3
a174 3
lib/libdcerpc-server.so
lib/libdcerpc-server.so.0
lib/libdcerpc-server.so.0.0.1
d178 3
d192 1
a192 1
lib/libndr.so.0.0.8
d196 3
a201 2
lib/libsamba-errors.so
lib/libsamba-errors.so.1
d207 1
a207 1
lib/libsamba-passdb.so.0.26.0
d217 3
d230 3
d235 1
a235 1
lib/libwbclient.so.0.13
d263 1
d265 1
a265 1
lib/pkgconfig/dcerpc_server.pc
d271 1
d277 1
d279 1
a280 1
${PYSITELIB}/_ldb_text.py
a290 1
${PYSITELIB}/samba/crypto.so
a324 1
${PYSITELIB}/samba/dckeytab.so
a327 1
${PYSITELIB}/samba/dsdb_dns.so
a357 1
${PYSITELIB}/samba/netcmd/nettime.py
d364 1
d366 1
a369 1
${PYSITELIB}/samba/posix_eadb.so
a374 1
${PYSITELIB}/samba/remove_dc.py
a385 1
${PYSITELIB}/samba/subnets.py
a392 1
${PYSITELIB}/samba/tests/blackbox/samba_dnsupdate.py
a397 1
${PYSITELIB}/samba/tests/dcerpc/array.py
a407 1
${PYSITELIB}/samba/tests/dcerpc/string.py
a410 3
${PYSITELIB}/samba/tests/dns_forwarder.py
${PYSITELIB}/samba/tests/dns_forwarder_helpers/server.py
${PYSITELIB}/samba/tests/dns_tkey.py
a433 1
${PYSITELIB}/samba/tests/samba_tool/dnscmd.py
a436 1
${PYSITELIB}/samba/tests/samba_tool/join.py
a438 2
${PYSITELIB}/samba/tests/samba_tool/rodc.py
${PYSITELIB}/samba/tests/samba_tool/sites.py
a440 1
${PYSITELIB}/samba/tests/samba_tool/user_check_password_script.py
a455 2
${PYSITELIB}/samba/xattr_native.so
${PYSITELIB}/samba/xattr_tdb.so
a459 5
lib/samba/bind9/dlz_bind9.so
lib/samba/bind9/dlz_bind9_10.so
lib/samba/bind9/dlz_bind9_11.so
lib/samba/bind9/dlz_bind9_9.so
lib/samba/gensec/krb5.so
a466 3
lib/samba/ldb/acl.so
lib/samba/ldb/aclread.so
lib/samba/ldb/anr.so
a467 7
lib/samba/ldb/descriptor.so
lib/samba/ldb/dirsync.so
lib/samba/ldb/dns_notify.so
lib/samba/ldb/dsdb_notification.so
lib/samba/ldb/extended_dn_in.so
lib/samba/ldb/extended_dn_out.so
lib/samba/ldb/extended_dn_store.so
a468 2
lib/samba/ldb/instancetype.so
lib/samba/ldb/lazy_commit.so
a469 7
lib/samba/ldb/linked_attributes.so
lib/samba/ldb/local_password.so
lib/samba/ldb/new_partition.so
lib/samba/ldb/objectclass.so
lib/samba/ldb/objectclass_attrs.so
lib/samba/ldb/objectguid.so
lib/samba/ldb/operational.so
a471 3
lib/samba/ldb/partition.so
lib/samba/ldb/password_hash.so
lib/samba/ldb/ranged_results.so
a472 8
lib/samba/ldb/repl_meta_data.so
lib/samba/ldb/resolve_oids.so
lib/samba/ldb/rootdse.so
lib/samba/ldb/samba3sam.so
lib/samba/ldb/samba3sid.so
lib/samba/ldb/samba_dsdb.so
lib/samba/ldb/samba_secrets.so
lib/samba/ldb/samldb.so
a473 3
lib/samba/ldb/schema_data.so
lib/samba/ldb/schema_load.so
lib/samba/ldb/secrets_tdb_sync.so
a474 3
lib/samba/ldb/show_deleted.so
lib/samba/ldb/simple_dn.so
lib/samba/ldb/simple_ldap_map.so
a475 2
lib/samba/ldb/subtree_delete.so
lib/samba/ldb/subtree_rename.so
a476 4
lib/samba/ldb/tombstone_reanimate.so
lib/samba/ldb/update_keytab.so
lib/samba/ldb/vlv.so
lib/samba/ldb/wins_ldb.so
a481 1
lib/samba/private/libHDB-SAMBA4-samba4.so
a485 2
lib/samba/private/libasn1-samba4.so.8
lib/samba/private/libasn1-samba4.so.8.0.0
a500 3
lib/samba/private/libcom_err-samba4.so.0
lib/samba/private/libcom_err-samba4.so.0.25
lib/samba/private/libdb-glue-samba4.so
a503 4
lib/samba/private/libdfs-server-ad-samba4.so
lib/samba/private/libdlz-bind9-for-torture-samba4.so
lib/samba/private/libdnsserver-common-samba4.so
lib/samba/private/libdsdb-garbage-collect-tombstones-samba4.so
d505 1
a508 1
lib/samba/private/libgensec-samba4.so
a510 10
lib/samba/private/libgssapi-samba4.so.2
lib/samba/private/libgssapi-samba4.so.2.0.0
lib/samba/private/libhcrypto-samba4.so.5
lib/samba/private/libhcrypto-samba4.so.5.0.1
lib/samba/private/libhdb-samba4.so.11
lib/samba/private/libhdb-samba4.so.11.0.2
lib/samba/private/libheimbase-samba4.so.1
lib/samba/private/libheimbase-samba4.so.1.0.0
lib/samba/private/libheimntlm-samba4.so.1
lib/samba/private/libheimntlm-samba4.so.1.0.1
a511 2
lib/samba/private/libhx509-samba4.so.5
lib/samba/private/libhx509-samba4.so.5.0.0
a514 4
lib/samba/private/libkdc-samba4.so.2
lib/samba/private/libkdc-samba4.so.2.0.0
lib/samba/private/libkrb5-samba4.so.26
lib/samba/private/libkrb5-samba4.so.26.0.0
d518 1
a518 1
lib/samba/private/libldb.so.1.1.29
a533 1
lib/samba/private/libpac-samba4.so
a534 1
lib/samba/private/libposix-eadb-samba4.so
a535 1
lib/samba/private/libprocess-model-samba4.so
d537 1
a537 1
lib/samba/private/libpyldb-util.so.1.1.29
d539 1
a539 2
lib/samba/private/libpytalloc-util.so.2.1.9
lib/samba/private/libregistry-samba4.so
a540 2
lib/samba/private/libroken-samba4.so.19
lib/samba/private/libroken-samba4.so.19.0.1
a552 1
lib/samba/private/libservice-samba4.so
a554 1
lib/samba/private/libsmbclient-raw-samba4.so
d560 1
d565 1
a565 1
lib/samba/private/libtalloc.so.2.1.9
d568 1
a568 1
lib/samba/private/libtdb.so.1.3.12
d570 1
a570 1
lib/samba/private/libtevent.so.0.9.31
a571 1
lib/samba/private/libtorture-samba4.so
a577 2
lib/samba/private/libwind-samba4.so.0
lib/samba/private/libwind-samba4.so.0.0.0
d579 1
a579 1
lib/samba/process_model/standard.so
a580 14
lib/samba/service/cldap.so
lib/samba/service/dcerpc.so
lib/samba/service/dns.so
lib/samba/service/dns_update.so
lib/samba/service/drepl.so
lib/samba/service/kcc.so
lib/samba/service/kdc.so
lib/samba/service/ldap.so
lib/samba/service/nbtd.so
lib/samba/service/ntp_signd.so
lib/samba/service/s3fs.so
lib/samba/service/web.so
lib/samba/service/winbindd.so
lib/samba/service/wrepl.so
d584 1
a591 1
lib/samba/vfs/dirsort.so
d600 1
a600 2
lib/samba/vfs/offline.so
lib/samba/vfs/posix_eadb.so
d605 1
d609 1
a611 1
lib/samba/vfs/syncops.so
a623 5
sbin/samba
sbin/samba_dnsupdate
sbin/samba_kcc
sbin/samba_spnupdate
sbin/samba_upgradedns
d641 5
a647 88
share/samba/setup/DB_CONFIG
share/samba/setup/ad-schema/MS-AD_Schema_2K8_Attributes.txt
share/samba/setup/ad-schema/MS-AD_Schema_2K8_Classes.txt
share/samba/setup/ad-schema/MS-AD_Schema_2K8_R2_Attributes.txt
share/samba/setup/ad-schema/MS-AD_Schema_2K8_R2_Classes.txt
share/samba/setup/ad-schema/licence.txt
share/samba/setup/aggregate_schema.ldif
share/samba/setup/cn=samba.ldif
share/samba/setup/display-specifiers/DisplaySpecifiers-Win2k0.txt
share/samba/setup/display-specifiers/DisplaySpecifiers-Win2k3.txt
share/samba/setup/display-specifiers/DisplaySpecifiers-Win2k3R2.txt
share/samba/setup/display-specifiers/DisplaySpecifiers-Win2k8.txt
share/samba/setup/display-specifiers/DisplaySpecifiers-Win2k8R2.txt
share/samba/setup/dns_update_list
share/samba/setup/fedora-ds-init.ldif
share/samba/setup/fedorads-dna.ldif
share/samba/setup/fedorads-index.ldif
share/samba/setup/fedorads-linked-attributes.ldif
share/samba/setup/fedorads-pam.ldif
share/samba/setup/fedorads-partitions.ldif
share/samba/setup/fedorads-refint-add.ldif
share/samba/setup/fedorads-refint-delete.ldif
share/samba/setup/fedorads-samba.ldif
share/samba/setup/fedorads-sasl.ldif
share/samba/setup/fedorads.inf
share/samba/setup/idmap_init.ldif
share/samba/setup/krb5.conf
share/samba/setup/memberof.conf
share/samba/setup/mmr_serverids.conf
share/samba/setup/mmr_syncrepl.conf
share/samba/setup/modules.conf
share/samba/setup/named.conf
share/samba/setup/named.conf.dlz
share/samba/setup/named.conf.update
share/samba/setup/named.txt
share/samba/setup/olc_mmr.conf
share/samba/setup/olc_seed.ldif
share/samba/setup/olc_serverid.conf
share/samba/setup/olc_syncrepl.conf
share/samba/setup/olc_syncrepl_seed.conf
share/samba/setup/prefixMap.txt
share/samba/setup/provision.ldif
share/samba/setup/provision.reg
share/samba/setup/provision.zone
share/samba/setup/provision_basedn.ldif
share/samba/setup/provision_basedn_modify.ldif
share/samba/setup/provision_basedn_options.ldif
share/samba/setup/provision_basedn_references.ldif
share/samba/setup/provision_computers_add.ldif
share/samba/setup/provision_computers_modify.ldif
share/samba/setup/provision_configuration.ldif
share/samba/setup/provision_configuration_basedn.ldif
share/samba/setup/provision_configuration_modify.ldif
share/samba/setup/provision_configuration_references.ldif
share/samba/setup/provision_dns_accounts_add.ldif
share/samba/setup/provision_dns_add_samba.ldif
share/samba/setup/provision_dnszones_add.ldif
share/samba/setup/provision_dnszones_modify.ldif
share/samba/setup/provision_dnszones_partitions.ldif
share/samba/setup/provision_group_policy.ldif
share/samba/setup/provision_init.ldif
share/samba/setup/provision_partitions.ldif
share/samba/setup/provision_privilege.ldif
share/samba/setup/provision_rootdse_add.ldif
share/samba/setup/provision_rootdse_modify.ldif
share/samba/setup/provision_schema_basedn.ldif
share/samba/setup/provision_schema_basedn_modify.ldif
share/samba/setup/provision_self_join.ldif
share/samba/setup/provision_self_join_config.ldif
share/samba/setup/provision_self_join_modify.ldif
share/samba/setup/provision_self_join_modify_config.ldif
share/samba/setup/provision_users.ldif
share/samba/setup/provision_users_add.ldif
share/samba/setup/provision_users_modify.ldif
share/samba/setup/provision_well_known_sec_princ.ldif
share/samba/setup/refint.conf
share/samba/setup/schema-map-fedora-ds-1.0
share/samba/setup/schema-map-openldap-2.3
share/samba/setup/schema_samba4.ldif
share/samba/setup/secrets.ldif
share/samba/setup/secrets_dns.ldif
share/samba/setup/secrets_init.ldif
share/samba/setup/secrets_sasl_ldap.ldif
share/samba/setup/secrets_simple_ldap.ldif
share/samba/setup/share.ldif
share/samba/setup/slapd.conf
share/samba/setup/spn_update_list
share/samba/setup/ypServ30.ldif
@


1.9
log
@If py-dns or py-iso8601 are installed, the PLIST is wrong because
the separate copy coming with samba4 is not installed.

Depend on the two packages and never install the separate copies.

Bump PKGREVISION.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.8 2016/07/07 16:44:14 taca Exp $
d641 1
@


1.8
log
@Update samba4 to 4.3.11 (Samba 4.3.11), including security fix for
CVE-2016-2119.

Changes from 4.3.9 to 4.3.10 are too many to write here, please refer
WHATSNEW.txt file.


                   ==============================
                   Release Notes for Samba 4.3.11
                            July 07, 2016
                   ==============================


This is a security release in order to address the following defect:

o  CVE-2016-2119 (Client side SMB2/3 required signing can be downgraded)

=======
Details
=======

o  CVE-2016-2119:
   It's possible for an attacker to downgrade the required signing for
   an SMB2/3 client connection, by injecting the SMB2_SESSION_FLAG_IS_GUEST
   or SMB2_SESSION_FLAG_IS_NULL flags.

   This means that the attacker can impersonate a server being connected to by
   Samba, and return malicious results.

   The primary concern is with winbindd, as it uses DCERPC over SMB2 when talking
   to domain controllers as a member server, and trusted domains as a domain
   controller.  These DCE/RPC connections were intended to protected by the
   combination of "client ipc signing" and
   "client ipc max protocol" in their effective default settings
   ("mandatory" and "SMB3_11").

   Additionally, management tools like net, samba-tool and rpcclient use DCERPC
   over SMB2/3 connections.

   By default, other tools in Samba are unprotected, but rarely they are
   configured to use smb signing, via the "client signing" parameter (the default
   is "if_required").  Even more rarely the "client max protocol" is set to SMB2,
   rather than the NT1 default.

   If both these conditions are met, then this issue would also apply to these
   other tools, including command line tools like smbcacls, smbcquota, smbclient,
   smbget and applications using libsmbclient.


Changes since 4.3.10:
--------------------

o  Stefan Metzmacher <metze@@samba.org>
   * BUG 11860: CVE-2016-2119: Fix client side SMB2 signing downgrade.
   * BUG 11948: Total dcerpc response payload more than 0x400000.


#######################################
Reporting bugs & Development Discussion
#######################################

Please discuss this release on the samba-technical mailing list or by
joining the #samba-technical IRC channel on irc.freenode.net.

If you do report problems then please try to send high quality
feedback. If you don't provide vital information to help us track down
the problem then you will probably be ignored.  All bug reports should
be filed under the "Samba 4.1 and newer" product in the project's Bugzilla
database (https://bugzilla.samba.org/).
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.7 2016/05/07 03:09:33 taca Exp $
a451 83
${PYSITELIB}/samba/third_party/dns/__init__.py
${PYSITELIB}/samba/third_party/dns/dnssec.py
${PYSITELIB}/samba/third_party/dns/e164.py
${PYSITELIB}/samba/third_party/dns/edns.py
${PYSITELIB}/samba/third_party/dns/entropy.py
${PYSITELIB}/samba/third_party/dns/exception.py
${PYSITELIB}/samba/third_party/dns/flags.py
${PYSITELIB}/samba/third_party/dns/hash.py
${PYSITELIB}/samba/third_party/dns/inet.py
${PYSITELIB}/samba/third_party/dns/ipv4.py
${PYSITELIB}/samba/third_party/dns/ipv6.py
${PYSITELIB}/samba/third_party/dns/message.py
${PYSITELIB}/samba/third_party/dns/name.py
${PYSITELIB}/samba/third_party/dns/namedict.py
${PYSITELIB}/samba/third_party/dns/node.py
${PYSITELIB}/samba/third_party/dns/opcode.py
${PYSITELIB}/samba/third_party/dns/query.py
${PYSITELIB}/samba/third_party/dns/rcode.py
${PYSITELIB}/samba/third_party/dns/rdata.py
${PYSITELIB}/samba/third_party/dns/rdataclass.py
${PYSITELIB}/samba/third_party/dns/rdataset.py
${PYSITELIB}/samba/third_party/dns/rdatatype.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/AFSDB.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/CERT.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/CNAME.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/DLV.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/DNAME.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/DNSKEY.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/DS.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/GPOS.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/HINFO.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/HIP.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/ISDN.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/LOC.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/MX.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/NS.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/NSEC.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/NSEC3.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/NSEC3PARAM.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/PTR.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/RP.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/RRSIG.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/RT.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/SOA.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/SPF.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/SSHFP.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/TXT.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/X25.py
${PYSITELIB}/samba/third_party/dns/rdtypes/ANY/__init__.py
${PYSITELIB}/samba/third_party/dns/rdtypes/IN/A.py
${PYSITELIB}/samba/third_party/dns/rdtypes/IN/AAAA.py
${PYSITELIB}/samba/third_party/dns/rdtypes/IN/APL.py
${PYSITELIB}/samba/third_party/dns/rdtypes/IN/DHCID.py
${PYSITELIB}/samba/third_party/dns/rdtypes/IN/IPSECKEY.py
${PYSITELIB}/samba/third_party/dns/rdtypes/IN/KX.py
${PYSITELIB}/samba/third_party/dns/rdtypes/IN/NAPTR.py
${PYSITELIB}/samba/third_party/dns/rdtypes/IN/NSAP.py
${PYSITELIB}/samba/third_party/dns/rdtypes/IN/NSAP_PTR.py
${PYSITELIB}/samba/third_party/dns/rdtypes/IN/PX.py
${PYSITELIB}/samba/third_party/dns/rdtypes/IN/SRV.py
${PYSITELIB}/samba/third_party/dns/rdtypes/IN/WKS.py
${PYSITELIB}/samba/third_party/dns/rdtypes/IN/__init__.py
${PYSITELIB}/samba/third_party/dns/rdtypes/__init__.py
${PYSITELIB}/samba/third_party/dns/rdtypes/dsbase.py
${PYSITELIB}/samba/third_party/dns/rdtypes/mxbase.py
${PYSITELIB}/samba/third_party/dns/rdtypes/nsbase.py
${PYSITELIB}/samba/third_party/dns/rdtypes/txtbase.py
${PYSITELIB}/samba/third_party/dns/renderer.py
${PYSITELIB}/samba/third_party/dns/resolver.py
${PYSITELIB}/samba/third_party/dns/reversename.py
${PYSITELIB}/samba/third_party/dns/rrset.py
${PYSITELIB}/samba/third_party/dns/set.py
${PYSITELIB}/samba/third_party/dns/tokenizer.py
${PYSITELIB}/samba/third_party/dns/tsig.py
${PYSITELIB}/samba/third_party/dns/tsigkeyring.py
${PYSITELIB}/samba/third_party/dns/ttl.py
${PYSITELIB}/samba/third_party/dns/update.py
${PYSITELIB}/samba/third_party/dns/version.py
${PYSITELIB}/samba/third_party/dns/wiredata.py
${PYSITELIB}/samba/third_party/dns/zone.py
${PYSITELIB}/samba/third_party/iso8601/__init__.py
${PYSITELIB}/samba/third_party/iso8601/iso8601.py
${PYSITELIB}/samba/third_party/iso8601/test_iso8601.py
@


1.7
log
@Update samba4 to 4.3.8, which contains security fix.

This release fixes some regressions introduced by the last security fixes.
Please see bug https://bugzilla.samba.org/show_bug.cgi?id=11849 for a list of
bugs addressing these regressions and more information.

Changes since 4.3.8:
--------------------

o  Jeremy Allison <jra@@samba.org>
   * BUG 11742: lib: tevent: Fix memory leak when old signal action restored.
   * BUG 11771: lib: tevent: Fix memory leak when old signal action restored.
   * BUG 11822: s3: libsmb: Fix error where short name length was read as 2
     bytes, should be 1.

o  Andrew Bartlett <abartlet@@samba.org>
   * BUG 11780: smbd: Only check dev/inode in open_directory, not the full
     stat().
   * BUG 11789: pydsdb: Fix returning of ldb.MessageElement.

o  Berend De Schouwer <berend.de.schouwer@@gmail.com>
   * BUG 11643: docs: Add example for domain logins to smbspool man page.

o  Günther Deschner <gd@@samba.org>
   * BUG 11789: libsmb/pysmb: Add pytalloc-util dependency to fix the build.

o  Alberto Maria Fiaschi <alberto.fiaschi@@estar.toscana.it>
   * BUG 8093: access based share enum: Handle permission set in configuration
      files.

o  Volker Lendecke <vl@@samba.org>
   * BUG 11816: nwrap: Fix the build on Solaris.
   * BUG 11827: vfs_catia: Fix memleak.
   * BUG 11878: smbd: Avoid large reads beyond EOF.

o  Stefan Metzmacher <metze@@samba.org>
   * BUG 11622: libcli/smb: Make sure we have a body size of 0x31 before
     dereferencing an ioctl response.
   * BUG 11623: libcli/smb: Fix BUFFER_OVERFLOW handling in tstream_smbXcli_np.
   * BUG 11755: s3:libads: Setup the msDS-SupportedEncryptionTypes attribute on
     ldap_add.
   * BUG 11771: tevent: Version 0.9.28. Fix memory leak when old signal action
     restored.
   * BUG 11782: s3:winbindd: Don't include two '\0' at the end of the domain
     list.
   * BUG 11789: s3:wscript: pylibsmb depends on pycredentials.
   * BUG 11841: Fix NT_STATUS_ACCESS_DENIED when accessing Windows public share.
   * BUG 11847: Only validate MIC if "map to guest" is not being used.
   * BUG 11849: auth/ntlmssp: Add ntlmssp_{client,server}:force_old_spnego
     option for testing.
   * BUG 11850: NetAPP SMB servers don't negotiate NTLMSSP_SIGN.
   * BUG 11858: Allow anonymous smb connections.
   * BUG 11870: Fix ads_sasl_spnego_gensec_bind(KRB5).
   * BUG 11872: Fix 'wbinfo -u' and 'net ads search'.

o  Noel Power <noel.power@@suse.com>
   * BUG 11738: libcli: Fix debug message, print sid string for new_ace trustee.

o  Garming Sam <garming@@catalyst.net.nz>
   * BUG 11789: build: Mark explicit dependencies on pytalloc-util.

o  Partha Sarathi <partha@@exablox.com>
   * BUG 11819: Fix the smb2_setinfo to handle FS info types and FSQUOTA
     infolevel.

o  Jorge Schrauwen <sjorge@@blackdot.be>
   * BUG 11816: configure: Don't check for inotify on illumos.

o  Uri Simchoni <uri@@samba.org>
   * BUG 11691: winbindd: Return trust parameters when listing trusts.
   * BUG 11753: smbd: Ignore SVHDX create context.
   * BUG 11763: passdb: Add linefeed to debug message.
   * BUG 11788: build: Fix disk-free quota support on Solaris 10.
   * BUG 11798: build: Fix build when '--without-quota' specified.
   * BUG 11806: vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls"
     is set.
   * BUG 11852: libads: Record session expiry for spnego sasl binds.

o  Hemanth Thummala <hemanth.thummala@@nutanix.com>
   * BUG 11740: Real memory leak(buildup) issue in loadparm.
   * BUG 11840: Mask general purpose signals for notifyd.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.6 2016/04/13 08:26:10 manu Exp $
d434 1
@


1.7.2.1
log
@Pullup ticket #5060 - requested by taca
net/samba4: security update

Revisions pulled up:
- net/samba4/Makefile                                           1.19-1.22
- net/samba4/PLIST                                              1.8-1.9
- net/samba4/distinfo                                           1.11

-------------------------------------------------------------------
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Thu Jul  7 16:44:14 UTC 2016

   Modified Files:
   	pkgsrc/net/samba4: Makefile PLIST distinfo

   Log Message:
   Update samba4 to 4.3.11 (Samba 4.3.11), including security fix for
   CVE-2016-2119.

   Changes from 4.3.9 to 4.3.10 are too many to write here, please refer
   WHATSNEW.txt file.

                      ==============================
                      Release Notes for Samba 4.3.11
                               July 07, 2016
                      ==============================

   This is a security release in order to address the following defect:

   o  CVE-2016-2119 (Client side SMB2/3 required signing can be downgraded)

   =======
   Details
   =======

   o  CVE-2016-2119:
      It's possible for an attacker to downgrade the required signing for
      an SMB2/3 client connection, by injecting the SMB2_SESSION_FLAG_IS_GUEST
      or SMB2_SESSION_FLAG_IS_NULL flags.

      This means that the attacker can impersonate a server being connected to by
      Samba, and return malicious results.

      The primary concern is with winbindd, as it uses DCERPC over SMB2 when talking
      to domain controllers as a member server, and trusted domains as a domain
      controller.  These DCE/RPC connections were intended to protected by the
      combination of "client ipc signing" and
      "client ipc max protocol" in their effective default settings
      ("mandatory" and "SMB3_11").

      Additionally, management tools like net, samba-tool and rpcclient use DCERPC
      over SMB2/3 connections.

      By default, other tools in Samba are unprotected, but rarely they are
      configured to use smb signing, via the "client signing" parameter (the default
      is "if_required").  Even more rarely the "client max protocol" is set to SMB2,
      rather than the NT1 default.

      If both these conditions are met, then this issue would also apply to these
      other tools, including command line tools like smbcacls, smbcquota, smbclient,
      smbget and applications using libsmbclient.

   Changes since 4.3.10:
   --------------------

   o  Stefan Metzmacher <metze@@samba.org>
      * BUG 11860: CVE-2016-2119: Fix client side SMB2 signing downgrade.
      * BUG 11948: Total dcerpc response payload more than 0x400000.

   #######################################
   Reporting bugs & Development Discussion
   #######################################

   Please discuss this release on the samba-technical mailing list or by
   joining the #samba-technical IRC channel on irc.freenode.net.

   If you do report problems then please try to send high quality
   feedback. If you don't provide vital information to help us track down
   the problem then you will probably be ignored.  All bug reports should
   be filed under the "Samba 4.1 and newer" product in the project's Bugzilla
   database (https://bugzilla.samba.org/).


   To generate a diff of this commit:
   cvs rdiff -u -r1.18 -r1.19 pkgsrc/net/samba4/Makefile
   cvs rdiff -u -r1.7 -r1.8 pkgsrc/net/samba4/PLIST
   cvs rdiff -u -r1.10 -r1.11 pkgsrc/net/samba4/distinfo

-------------------------------------------------------------------
   Module Name:	pkgsrc
   Committed By:	wiz
   Date:		Sat Jul  9 06:39:18 UTC 2016

   Modified Files:
   	pkgsrc/archivers/dar: Makefile
   	pkgsrc/archivers/file-roller: Makefile
   	pkgsrc/archivers/libzip: Makefile
   	pkgsrc/archivers/upx: Makefile
   	pkgsrc/audio/abcde: Makefile
   	pkgsrc/audio/amarok: Makefile
   	pkgsrc/audio/ardour: Makefile
   	pkgsrc/audio/arts: Makefile
   	pkgsrc/audio/disc-cover: Makefile
   	pkgsrc/audio/distmp3: Makefile
   	pkgsrc/audio/festival: Makefile
   	pkgsrc/audio/flac2mp3: Makefile
   	pkgsrc/audio/gtkpod: Makefile
   	pkgsrc/audio/jack: Makefile
   	pkgsrc/audio/kid3: Makefile
   	pkgsrc/audio/libgroove: Makefile
   	pkgsrc/audio/liteamp: Makefile
   	pkgsrc/audio/lmms: Makefile
   	pkgsrc/audio/mkcdtoc: Makefile
   	pkgsrc/audio/mp32ogg: Makefile
   	pkgsrc/audio/mp3cut: Makefile
   	pkgsrc/audio/mserv: Makefile
   	pkgsrc/audio/mserv-devel: Makefile
   	pkgsrc/audio/mserv-irman: Makefile
   	pkgsrc/audio/mstream: Makefile
   	pkgsrc/audio/nas-auscope: Makefile
   	pkgsrc/audio/normalize: Makefile
   	pkgsrc/audio/oggasm: Makefile
   	pkgsrc/audio/paprefs: Makefile
   	pkgsrc/audio/pavucontrol: Makefile
   	pkgsrc/audio/pavumeter: Makefile
   	pkgsrc/audio/rip: Makefile
   	pkgsrc/audio/sphinxbase: Makefile
   	pkgsrc/audio/sphinxtrain: Makefile
   	pkgsrc/benchmarks/bonnie++: Makefile
   	pkgsrc/benchmarks/bytebench: Makefile
   	pkgsrc/benchmarks/hbench: Makefile
   	pkgsrc/benchmarks/iozone: Makefile
   	pkgsrc/benchmarks/lmbench: Makefile
   	pkgsrc/biology/bioperl: Makefile
   	pkgsrc/biology/bodr: Makefile
   	pkgsrc/biology/bwa: Makefile
   	pkgsrc/biology/cdhit: Makefile
   	pkgsrc/biology/gnome-chemistry-utils: Makefile
   	pkgsrc/biology/gromacs: Makefile
   	pkgsrc/biology/mpqc: Makefile
   	pkgsrc/biology/mummer: Makefile
   	pkgsrc/cad/dinotrace: Makefile
   	pkgsrc/cad/freehdl: Makefile
   	pkgsrc/cad/geda: Makefile
   	pkgsrc/cad/gwave: Makefile
   	pkgsrc/cad/spiceprm: Makefile
   	pkgsrc/chat/anope: Makefile
   	pkgsrc/chat/bitchbot: Makefile
   	pkgsrc/chat/centerim: Makefile
   	pkgsrc/chat/cgiirc: Makefile
   	pkgsrc/chat/dccserver: Makefile
   	pkgsrc/chat/dircproxy: Makefile
   	pkgsrc/chat/finch: Makefile
   	pkgsrc/chat/inspircd: Makefile
   	pkgsrc/chat/inspircd12: Makefile
   	pkgsrc/chat/ircd-hybrid: Makefile
   	pkgsrc/chat/ircservices: Makefile
   	pkgsrc/chat/jabberd2: Makefile
   	pkgsrc/chat/kgb-bot: Makefile
   	pkgsrc/chat/kmess: Makefile
   	pkgsrc/chat/konversation: Makefile
   	pkgsrc/chat/konversation-kde3: Makefile
   	pkgsrc/chat/libpurple: Makefile
   	pkgsrc/chat/pidgin-libnotify: Makefile
   	pkgsrc/chat/pidgin-otr: Makefile
   	pkgsrc/chat/pidgin-sametime: Makefile
   	pkgsrc/chat/pidgin-silc: Makefile
   	pkgsrc/chat/sirc: Makefile
   	pkgsrc/chat/vicq: Makefile
   	pkgsrc/chat/xchat: Makefile
   	pkgsrc/chat/xchat-python: Makefile
   	pkgsrc/comms/asterisk: Makefile
   	pkgsrc/comms/asterisk13: Makefile
   	pkgsrc/comms/asterisk18: Makefile
   	pkgsrc/comms/fidogate: Makefile
   	pkgsrc/comms/gnome-pilot: Makefile
   	pkgsrc/comms/mgetty+sendfax: Makefile
   	pkgsrc/comms/op_panel: Makefile
   	pkgsrc/comms/p5-Asterisk: Makefile
   	pkgsrc/comms/pilot-link: Makefile
   	pkgsrc/comms/pilotmgr: Makefile
   	pkgsrc/converters/2vcard: Makefile
   	pkgsrc/converters/bibtex2html: Makefile
   	pkgsrc/converters/code2html: Makefile
   	pkgsrc/converters/convmv: Makefile
   	pkgsrc/converters/doc2html: Makefile
   	pkgsrc/converters/docx2txt: Makefile
   	pkgsrc/converters/dos2unix: Makefile
   	pkgsrc/converters/help2man: Makefile
   	pkgsrc/converters/jcode-perl: Makefile
   	pkgsrc/converters/libabw: Makefile
   	pkgsrc/converters/libfreehand: Makefile
   	pkgsrc/converters/libvisio: Makefile
   	pkgsrc/converters/libwpg: Makefile
   	pkgsrc/converters/nkf: Makefile
   	pkgsrc/converters/rpm2cpio: Makefile
   	pkgsrc/converters/skf: Makefile
   	pkgsrc/converters/smbchartool: Makefile
   	pkgsrc/converters/txt2html: Makefile
   	pkgsrc/converters/txt2pdbdoc: Makefile
   	pkgsrc/cross/avr-binutils: Makefile
   	pkgsrc/cross/avr-gcc: Makefile
   	pkgsrc/cross/avr-libc: Makefile
   	pkgsrc/cross/binutils-mips-current: Makefile
   	pkgsrc/cross/cc65: Makefile
   	pkgsrc/cross/cross-binutils: Makefile
   	pkgsrc/cross/cross-libtool-base: Makefile
   	pkgsrc/cross/gcc-mips-current: Makefile
   	pkgsrc/cross/nios2-gcc: Makefile
   	pkgsrc/cross/nios2-gcc3: Makefile
   	pkgsrc/cross/nios2-gcc41: Makefile
   	pkgsrc/databases/couchdb: Makefile
   	pkgsrc/databases/cstore: Makefile
   	pkgsrc/databases/gnome-mime-data: Makefile
   	pkgsrc/databases/gq: Makefile
   	pkgsrc/databases/idzebra: Makefile
   	pkgsrc/databases/innotop: Makefile
   	pkgsrc/databases/krecipes: Makefile
   	pkgsrc/databases/lbdb: Makefile
   	pkgsrc/databases/libcassandra: Makefile
   	pkgsrc/databases/maatkit: Makefile
   	pkgsrc/databases/mariadb55-client: Makefile
   	pkgsrc/databases/mysql-cluster: Makefile
   	pkgsrc/databases/mysql51-client: Makefile
   	pkgsrc/databases/mysql55-client: Makefile
   	pkgsrc/databases/mysql56-client: Makefile
   	pkgsrc/databases/mysqltuner: Makefile
   	pkgsrc/databases/mytop: Makefile
   	pkgsrc/databases/p5-DBI: Makefile
   	pkgsrc/databases/p5-DBIWrapper: Makefile
   	pkgsrc/databases/p5-perl-ldap: Makefile
   	pkgsrc/databases/p5-postgresql: Makefile
   	pkgsrc/databases/p5-sybperl: Makefile
   	pkgsrc/databases/p5-tokyocabinet: Makefile
   	pkgsrc/databases/p5-tokyotyrant: Makefile
   	pkgsrc/databases/percona-toolkit: Makefile
   	pkgsrc/databases/pgbuildfarm: Makefile
   	pkgsrc/databases/postgresql-postgis2: Makefile
   	pkgsrc/databases/postgresql91: Makefile
   	pkgsrc/databases/postgresql91-docs: Makefile
   	pkgsrc/databases/postgresql91-plperl: Makefile
   	pkgsrc/databases/postgresql92: Makefile
   	pkgsrc/databases/postgresql92-docs: Makefile
   	pkgsrc/databases/postgresql92-plperl: Makefile
   	pkgsrc/databases/postgresql93: Makefile
   	pkgsrc/databases/postgresql93-docs: Makefile
   	pkgsrc/databases/postgresql93-plperl: Makefile
   	pkgsrc/databases/postgresql94: Makefile
   	pkgsrc/databases/postgresql94-docs: Makefile
   	pkgsrc/databases/postgresql94-plperl: Makefile
   	pkgsrc/databases/postgresql95: Makefile
   	pkgsrc/databases/postgresql95-docs: Makefile
   	pkgsrc/databases/postgresql95-plperl: Makefile
   	pkgsrc/databases/rdb: Makefile
   	pkgsrc/databases/rrdtool: Makefile
   	pkgsrc/databases/rrdtool12: Makefile
   	pkgsrc/databases/sqlrelay: Makefile
   	pkgsrc/databases/yasql: Makefile
   	pkgsrc/devel/GConf: Makefile
   	pkgsrc/devel/MoarVM: Makefile
   	pkgsrc/devel/RTx-RightsMatrix: Makefile
   	pkgsrc/devel/adocman: Makefile
   	pkgsrc/devel/aegis: Makefile
   	pkgsrc/devel/anjuta: Makefile
   	pkgsrc/devel/atkmm: Makefile
   	pkgsrc/devel/autoconf: Makefile
   	pkgsrc/devel/autoconf213: Makefile
   	pkgsrc/devel/autogen: Makefile
   	pkgsrc/devel/automake: Makefile
   	pkgsrc/devel/automake14: Makefile
   	pkgsrc/devel/bglibs: Makefile
   	pkgsrc/devel/binutils: Makefile
   	pkgsrc/devel/bison: Makefile
   	pkgsrc/devel/bugzilla: Makefile
   	pkgsrc/devel/bugzilla3: Makefile
   	pkgsrc/devel/cogito: Makefile
   	pkgsrc/devel/colordiff: Makefile
   	pkgsrc/devel/commit-patch: Makefile
   	pkgsrc/devel/cook: Makefile
   	pkgsrc/devel/cqual: Makefile
   	pkgsrc/devel/ctemplate: Makefile
   	pkgsrc/devel/cvs2cl: Makefile
   	pkgsrc/devel/cvs2html: Makefile
   	pkgsrc/devel/cvsd: Makefile
   	pkgsrc/devel/cvsutils: Makefile
   	pkgsrc/devel/darcs: Makefile
   	pkgsrc/devel/delta: Makefile
   	pkgsrc/devel/devhelp: Makefile
   	pkgsrc/devel/doxygen: Makefile
   	pkgsrc/devel/easygit: Makefile
   	pkgsrc/devel/etrace: Makefile
   	pkgsrc/devel/gconfmm: Makefile
   	pkgsrc/devel/gcvs: Makefile
   	pkgsrc/devel/gdb: Makefile
   	pkgsrc/devel/gdbus-codegen: Makefile
   	pkgsrc/devel/gdl: Makefile
   	pkgsrc/devel/geany: Makefile
   	pkgsrc/devel/git-base: Makefile
   	pkgsrc/devel/git-docs: Makefile
   	pkgsrc/devel/gitolite: Makefile
   	pkgsrc/devel/glib2: Makefile
   	pkgsrc/devel/glibmm: Makefile
   	pkgsrc/devel/global: Makefile
   	pkgsrc/devel/gmake: Makefile
   	pkgsrc/devel/gperftools: Makefile
   	pkgsrc/devel/gps: Makefile
   	pkgsrc/devel/jemalloc: Makefile
   	pkgsrc/devel/kdbg: Makefile
   	pkgsrc/devel/kdesdk-kioslaves: Makefile
   	pkgsrc/devel/kdesdk3: Makefile
   	pkgsrc/devel/kdevelop-base: Makefile
   	pkgsrc/devel/kdevelop4: Makefile
   	pkgsrc/devel/kdevplatform: Makefile
   	pkgsrc/devel/kdoctools: Makefile
   	pkgsrc/devel/ktexteditor: Makefile
   	pkgsrc/devel/lcov: Makefile
   	pkgsrc/devel/ldapsdk: Makefile
   	pkgsrc/devel/libbonobo: Makefile
   	pkgsrc/devel/libcerf: Makefile
   	pkgsrc/devel/libcompizconfig: Makefile
   	pkgsrc/devel/libgnomeui: Makefile
   	pkgsrc/devel/libidn: Makefile
   	pkgsrc/devel/libpgm: Makefile
   	pkgsrc/devel/libsigc++: Makefile
   	pkgsrc/devel/libstatgrab: Makefile
   	pkgsrc/devel/libthrift: Makefile
   	pkgsrc/devel/libtool: Makefile
   	pkgsrc/devel/libtool-base: Makefile
   	pkgsrc/devel/libtool-fortran: Makefile
   	pkgsrc/devel/libwhisker2: Makefile
   	pkgsrc/devel/lua-posix: Makefile
   	pkgsrc/devel/memcached: Makefile
   	pkgsrc/devel/monodevelop: Makefile
   	pkgsrc/devel/monotone: Makefile
   	pkgsrc/devel/mr: Makefile
   	pkgsrc/devel/nasm: Makefile
   	pkgsrc/devel/ncurses: Makefile
   	pkgsrc/devel/netbeans-ide: Makefile
   	pkgsrc/devel/nspr: Makefile
   	pkgsrc/devel/nss: Makefile
   	pkgsrc/devel/ossp-uuid: Makefile
   	pkgsrc/devel/p5-App-perlbrew: Makefile
   	pkgsrc/devel/p5-B-Hooks-OP-Annotation: Makefile
   	pkgsrc/devel/p5-EV: Makefile
   	pkgsrc/devel/p5-Event: Makefile
   	pkgsrc/devel/p5-LDAP: Makefile
   	pkgsrc/devel/p5-Log-Any-Adapter-Log4perl: Makefile
   	pkgsrc/devel/p5-Log-Log4perl: Makefile
   	pkgsrc/devel/p5-Test-Log4perl: Makefile
   	pkgsrc/devel/pangomm: Makefile
   	pkgsrc/devel/papaya: Makefile
   	pkgsrc/devel/patchutils: Makefile
   	pkgsrc/devel/prcs: Makefile
   	pkgsrc/devel/pstreams: Makefile
   	pkgsrc/devel/quilt: Makefile
   	pkgsrc/devel/refinecvs: Makefile
   	pkgsrc/devel/rpc2: Makefile
   	pkgsrc/devel/rt-mysql: Makefile
   	pkgsrc/devel/rt4: Makefile
   	pkgsrc/devel/sdcc: Makefile
   	pkgsrc/devel/sdcc3: Makefile
   	pkgsrc/devel/sparse: Makefile
   	pkgsrc/devel/startbug1: Makefile
   	pkgsrc/devel/stfl: Makefile
   	pkgsrc/devel/stgit: Makefile
   	pkgsrc/devel/subversion: Makefile
   	pkgsrc/devel/sunifdef: Makefile
   	pkgsrc/devel/svk: Makefile
   	pkgsrc/devel/tet3: Makefile
   	pkgsrc/devel/tmake: Makefile
   	pkgsrc/devel/valgrind: Makefile
   	pkgsrc/devel/xfce4-conf: Makefile
   	pkgsrc/devel/xulrunner10: Makefile
   	pkgsrc/devel/xulrunner17: Makefile
   	pkgsrc/devel/xulrunner192: Makefile
   	pkgsrc/editors/TeXmacs: Makefile
   	pkgsrc/editors/conglomerate: Makefile
   	pkgsrc/editors/emacs20: Makefile
   	pkgsrc/editors/emacs21: Makefile
   	pkgsrc/editors/emacs22: Makefile
   	pkgsrc/editors/gedit: Makefile
   	pkgsrc/editors/gedit-python: Makefile
   	pkgsrc/editors/gedit3: Makefile
   	pkgsrc/editors/kile: Makefile
   	pkgsrc/editors/kile-kde3: Makefile
   	pkgsrc/editors/lyx: Makefile
   	pkgsrc/editors/nvi-m17n: Makefile
   	pkgsrc/editors/vigor: Makefile
   	pkgsrc/editors/xemacs-packages: Makefile
   	pkgsrc/emulators/darwin_lib: Makefile
   	pkgsrc/emulators/freebsd_lib: Makefile
   	pkgsrc/emulators/fuse-emulator: Makefile
   	pkgsrc/emulators/hercules: Makefile
   	pkgsrc/emulators/kegs: Makefile
   	pkgsrc/emulators/libspectrum: Makefile
   	pkgsrc/emulators/osf1_lib: Makefile
   	pkgsrc/emulators/palmosemulator: Makefile
   	pkgsrc/emulators/qemu: Makefile
   	pkgsrc/emulators/qemu0: Makefile
   	pkgsrc/emulators/raine: Makefile
   	pkgsrc/emulators/shoebill: Makefile
   	pkgsrc/emulators/snes9x-gtk: Makefile
   	pkgsrc/emulators/suse100_base: Makefile
   	pkgsrc/emulators/suse121_base: Makefile
   	pkgsrc/emulators/suse131_base: Makefile
   	pkgsrc/emulators/tme: Makefile
   	pkgsrc/emulators/z26: Makefile
   	pkgsrc/filesystems/fuse-svnfs: Makefile
   	pkgsrc/finance/gkrellm-stock: Makefile
   	pkgsrc/finance/gnucash: Makefile
   	pkgsrc/finance/kmymoney2: Makefile
   	pkgsrc/fonts/fntsample: Makefile
   	pkgsrc/fonts/ja-shinonome: Makefile
   	pkgsrc/fonts/monafonts: Makefile
   	pkgsrc/fonts/terminus-font: Makefile
   	pkgsrc/fonts/tex-accfonts: Makefile
   	pkgsrc/fonts/tex-dosepsbin: Makefile
   	pkgsrc/fonts/tex-fontools: Makefile
   	pkgsrc/fonts/tex-mf2pt1: Makefile
   	pkgsrc/fonts/ttf2pt1: Makefile
   	pkgsrc/fonts/type1inst: Makefile
   	pkgsrc/fonts/unifont: Makefile
   	pkgsrc/games/asc: Makefile
   	pkgsrc/games/asciiquarium: Makefile
   	pkgsrc/games/bzflag: Makefile
   	pkgsrc/games/crossfire-client: Makefile
   	pkgsrc/games/crossfire-server: Makefile
   	pkgsrc/games/eboard: Makefile
   	pkgsrc/games/frozen-bubble: Makefile
   	pkgsrc/games/minami: Makefile
   	pkgsrc/games/netmaj: Makefile
   	pkgsrc/games/wesnoth: Makefile
   	pkgsrc/games/xboard: Makefile
   	pkgsrc/games/xracer: Makefile
   	pkgsrc/games/xscorch: Makefile
   	pkgsrc/games/zoom: Makefile
   	pkgsrc/geography/gpsdrive: Makefile
   	pkgsrc/geography/proj-swig: Makefile
   	pkgsrc/geography/qgis: Makefile
   	pkgsrc/graphics/GraphicsMagick: Makefile
   	pkgsrc/graphics/ImageMagick: Makefile
   	pkgsrc/graphics/ImageMagick6: Makefile
   	pkgsrc/graphics/OpenRM: Makefile
   	pkgsrc/graphics/asymptote: Makefile
   	pkgsrc/graphics/cairomm: Makefile
   	pkgsrc/graphics/cdlabelgen: Makefile
   	pkgsrc/graphics/cheese: Makefile
   	pkgsrc/graphics/circos: Makefile
   	pkgsrc/graphics/claraocr: Makefile
   	pkgsrc/graphics/compface: Makefile
   	pkgsrc/graphics/digikam: Makefile
   	pkgsrc/graphics/digikam-doc-kde3: Makefile
   	pkgsrc/graphics/digikam-kde3: Makefile
   	pkgsrc/graphics/enblend-enfuse: Makefile
   	pkgsrc/graphics/fly: Makefile
   	pkgsrc/graphics/g2: Makefile
   	pkgsrc/graphics/gd: Makefile
   	pkgsrc/graphics/get_ds7: Makefile
   	pkgsrc/graphics/gimp: Makefile
   	pkgsrc/graphics/gimp-docs-en: Makefile
   	pkgsrc/graphics/gimp-ufraw: Makefile
   	pkgsrc/graphics/gnome-icon-theme: Makefile
   	pkgsrc/graphics/goocanvasmm: Makefile
   	pkgsrc/graphics/graphviz: Makefile
   	pkgsrc/graphics/gri: Makefile
   	pkgsrc/graphics/gtkam: Makefile
   	pkgsrc/graphics/gtkglext: Makefile
   	pkgsrc/graphics/gwenview-kde3: Makefile
   	pkgsrc/graphics/icon-naming-utils: Makefile
   	pkgsrc/graphics/inkscape: Makefile
   	pkgsrc/graphics/kbarcode: Makefile
   	pkgsrc/graphics/kipi-plugins-calendar-kde3: Makefile
   	pkgsrc/graphics/kipi-plugins-kde3: Makefile
   	pkgsrc/graphics/koverartist: Makefile
   	pkgsrc/graphics/magicpoint: Makefile
   	pkgsrc/graphics/netpbm: Makefile
   	pkgsrc/graphics/pfstools: Makefile
   	pkgsrc/graphics/ps2eps: Makefile
   	pkgsrc/graphics/ristretto: Makefile
   	pkgsrc/graphics/showimg: Makefile
   	pkgsrc/graphics/tex-a2ping: Makefile
   	pkgsrc/graphics/tex-epstopdf: Makefile
   	pkgsrc/graphics/tex-pdfcrop: Makefile
   	pkgsrc/graphics/ucview: Makefile
   	pkgsrc/graphics/unicap: Makefile
   	pkgsrc/graphics/xplot: Makefile
   	pkgsrc/graphics/xplot-devel: Makefile
   	pkgsrc/graphics/zphoto: Makefile
   	pkgsrc/ham/fldigi: Makefile
   	pkgsrc/ham/gnuradio-core: Makefile
   	pkgsrc/ham/hamlib: Makefile
   	pkgsrc/ham/linpsk: Makefile
   	pkgsrc/ham/osmo-sdr: Makefile
   	pkgsrc/ham/trustedQSL: Makefile
   	pkgsrc/inputmethod/scim: Makefile
   	pkgsrc/inputmethod/xcin: Makefile
   	pkgsrc/lang/asn1c: Makefile
   	pkgsrc/lang/cim: Makefile
   	pkgsrc/lang/clang-static-analyzer: Makefile
   	pkgsrc/lang/erlang: Makefile
   	pkgsrc/lang/fort77: Makefile
   	pkgsrc/lang/g95: Makefile
   	pkgsrc/lang/gcc-aux: Makefile
   	pkgsrc/lang/gcc44: Makefile
   	pkgsrc/lang/gcc45: Makefile
   	pkgsrc/lang/gcc46: Makefile
   	pkgsrc/lang/gcc47: Makefile
   	pkgsrc/lang/gcc48: Makefile
   	pkgsrc/lang/gcc49: Makefile
   	pkgsrc/lang/gcc5: Makefile
   	pkgsrc/lang/gforth: Makefile
   	pkgsrc/lang/ghc: Makefile
   	pkgsrc/lang/ghc-bootstrap: Makefile
   	pkgsrc/lang/ghc7: Makefile
   	pkgsrc/lang/go: Makefile
   	pkgsrc/lang/go14: Makefile
   	pkgsrc/lang/guile: Makefile
   	pkgsrc/lang/gwydion-dylan: Makefile
   	pkgsrc/lang/libLLVM: Makefile
   	pkgsrc/lang/llvm: Makefile
   	pkgsrc/lang/mercury: Makefile
   	pkgsrc/lang/mono: Makefile
   	pkgsrc/lang/mono2: Makefile
   	pkgsrc/lang/moscow_ml: Makefile
   	pkgsrc/lang/nqp: Makefile
   	pkgsrc/lang/oo2c: Makefile
   	pkgsrc/lang/ossp-js: Makefile
   	pkgsrc/lang/parrot: Makefile
   	pkgsrc/lang/pfe: Makefile
   	pkgsrc/lang/rakudo-star: Makefile
   	pkgsrc/lang/sather: Makefile
   	pkgsrc/lang/see: Makefile
   	pkgsrc/lang/spidermonkey17: Makefile
   	pkgsrc/mail/YoSucker: Makefile
   	pkgsrc/mail/amavis-perl: Makefile
   	pkgsrc/mail/amavisd-new: Makefile
   	pkgsrc/mail/anomy-sanitizer: Makefile
   	pkgsrc/mail/avenger: Makefile
   	pkgsrc/mail/balsa: Makefile
   	pkgsrc/mail/bogofilter: Makefile
   	pkgsrc/mail/claws-mail: Makefile
   	pkgsrc/mail/claws-mail-vcalendar: Makefile
   	pkgsrc/mail/clawsker: Makefile
   	pkgsrc/mail/cone: Makefile
   	pkgsrc/mail/courier-analog: Makefile
   	pkgsrc/mail/courier-imap: Makefile
   	pkgsrc/mail/courier-maildir: Makefile
   	pkgsrc/mail/cyrus-imapd: Makefile
   	pkgsrc/mail/cyrus-imapd23: Makefile
   	pkgsrc/mail/cyrus-imapd24: Makefile
   	pkgsrc/mail/dcc: Makefile
   	pkgsrc/mail/demime: Makefile
   	pkgsrc/mail/distribute: Makefile
   	pkgsrc/mail/dspam: Makefile
   	pkgsrc/mail/elmo: Makefile
   	pkgsrc/mail/etpan: Makefile
   	pkgsrc/mail/exim: Makefile
   	pkgsrc/mail/exim3: Makefile
   	pkgsrc/mail/faces: Makefile
   	pkgsrc/mail/fetchyahoo: Makefile
   	pkgsrc/mail/fix-mime-charset: Makefile
   	pkgsrc/mail/fml: Makefile
   	pkgsrc/mail/fromto: Makefile
   	pkgsrc/mail/grepmail: Makefile
   	pkgsrc/mail/imapsync: Makefile
   	pkgsrc/mail/kbiff: Makefile
   	pkgsrc/mail/mailagent: Makefile
   	pkgsrc/mail/maildrop: Makefile
   	pkgsrc/mail/mailgraph: Makefile
   	pkgsrc/mail/mailhops: Makefile
   	pkgsrc/mail/mailserv: Makefile
   	pkgsrc/mail/mailsort: Makefile
   	pkgsrc/mail/majordomo: Makefile
   	pkgsrc/mail/mb2md: Makefile
   	pkgsrc/mail/mdfrm: Makefile
   	pkgsrc/mail/mhonarc: Makefile
   	pkgsrc/mail/mime-construct: Makefile
   	pkgsrc/mail/minimalist: Makefile
   	pkgsrc/mail/mutt: Makefile
   	pkgsrc/mail/opendkim: Makefile
   	pkgsrc/mail/opendmarc: Makefile
   	pkgsrc/mail/policyd-weight: Makefile
   	pkgsrc/mail/poppy: Makefile
   	pkgsrc/mail/postfix: Makefile
   	pkgsrc/mail/postgrey: Makefile
   	pkgsrc/mail/prayer: Makefile
   	pkgsrc/mail/qgreylist: Makefile
   	pkgsrc/mail/qmHandle: Makefile
   	pkgsrc/mail/qmail-lint: Makefile
   	pkgsrc/mail/qmqtool: Makefile
   	pkgsrc/mail/rspamd: Makefile
   	pkgsrc/mail/sendmail-qtool: Makefile
   	pkgsrc/mail/sendymail: Makefile
   	pkgsrc/mail/spamassassin: Makefile
   	pkgsrc/mail/squirrelmail: Makefile
   	pkgsrc/mail/sqwebmail: Makefile
   	pkgsrc/mail/teapop: Makefile
   	pkgsrc/mail/thunderbird-enigmail: Makefile
   	pkgsrc/mail/turba: Makefile
   	pkgsrc/math/R: Makefile
   	pkgsrc/math/R-gdata: Makefile
   	pkgsrc/math/R-genetics: Makefile
   	pkgsrc/math/antixls: Makefile
   	pkgsrc/math/ess: Makefile
   	pkgsrc/math/fftw: Makefile
   	pkgsrc/math/fftwf: Makefile
   	pkgsrc/math/genius: Makefile
   	pkgsrc/math/maxima: Makefile
   	pkgsrc/math/ntl: Makefile
   	pkgsrc/math/ocaml-zarith: Makefile
   	pkgsrc/math/octave: Makefile
   	pkgsrc/math/pari: Makefile
   	pkgsrc/math/pari23: Makefile
   	pkgsrc/math/ppl: Makefile
   	pkgsrc/math/pspp: Makefile
   	pkgsrc/math/qalculate-kde: Makefile
   	pkgsrc/math/superlu: Makefile
   	pkgsrc/math/udunits: Makefile
   	pkgsrc/math/xmgr: Makefile
   	pkgsrc/math/yacas: Makefile
   	pkgsrc/mbone/beacon: Makefile
   	pkgsrc/meta-pkgs/bulk-medium: Makefile
   	pkgsrc/meta-pkgs/bulk-small: Makefile
   	pkgsrc/meta-pkgs/kde3: Makefile
   	pkgsrc/meta-pkgs/kde4: Makefile
   	pkgsrc/meta-pkgs/netbsd-www: Makefile
   	pkgsrc/meta-pkgs/texlive-collection-bibtexextra: Makefile
   	pkgsrc/meta-pkgs/texlive-collection-latexextra: Makefile
   	pkgsrc/meta-pkgs/texlive-collection-pstricks: Makefile
   	pkgsrc/meta-pkgs/xfce4: Makefile
   	pkgsrc/misc/bbweather: Makefile
   	pkgsrc/misc/byobu: Makefile
   	pkgsrc/misc/colorize: Makefile
   	pkgsrc/misc/cowsay: Makefile
   	pkgsrc/misc/dpkg: Makefile
   	pkgsrc/misc/gkrellm-weather: Makefile
   	pkgsrc/misc/gnome-utils: Makefile
   	pkgsrc/misc/gwaei: Makefile
   	pkgsrc/misc/ipbt: Makefile
   	pkgsrc/misc/kanjipad: Makefile
   	pkgsrc/misc/kdepim3: Makefile
   	pkgsrc/misc/kdepim4: Makefile
   	pkgsrc/misc/koffice: Makefile
   	pkgsrc/misc/libcdio: Makefile
   	pkgsrc/misc/libcdio-paranoia: Makefile
   	pkgsrc/misc/libreoffice: Makefile
   	pkgsrc/misc/libreoffice4: Makefile
   	pkgsrc/misc/libreoffice43: Makefile
   	pkgsrc/misc/loco: Makefile
   	pkgsrc/misc/mirmon: Makefile
   	pkgsrc/misc/nxtvepg: Makefile
   	pkgsrc/misc/openoffice3: Makefile
   	pkgsrc/misc/p5-Locale-libintl: Makefile
   	pkgsrc/misc/pdmenu: Makefile
   	pkgsrc/misc/reed: Makefile
   	pkgsrc/misc/rlwrap: Makefile
   	pkgsrc/misc/rpm: Makefile
   	pkgsrc/misc/stellarium: Makefile
   	pkgsrc/misc/taskjuggler: Makefile
   	pkgsrc/misc/tds: Makefile
   	pkgsrc/misc/tellico-kde3: Makefile
   	pkgsrc/misc/teseq: Makefile
   	pkgsrc/misc/topless: Makefile
   	pkgsrc/misc/vfu: Makefile
   	pkgsrc/misc/vym: Makefile
   	pkgsrc/misc/whohas: Makefile
   	pkgsrc/multimedia/acidrip: Makefile
   	pkgsrc/multimedia/dirac: Makefile
   	pkgsrc/multimedia/dvb-apps: Makefile
   	pkgsrc/multimedia/dvdrip: Makefile
   	pkgsrc/multimedia/ffmpeg2: Makefile
   	pkgsrc/multimedia/ffmpeg3: Makefile
   	pkgsrc/multimedia/gmediaserver: Makefile
   	pkgsrc/multimedia/gnome-media: Makefile
   	pkgsrc/multimedia/gst-plugins0.10-base: Makefile
   	pkgsrc/multimedia/gst-plugins0.10-ffmpeg: Makefile
   	pkgsrc/multimedia/gst-plugins1-base: Makefile
   	pkgsrc/multimedia/gst-plugins1-libav: Makefile
   	pkgsrc/multimedia/gst-plugins1-omx: Makefile
   	pkgsrc/multimedia/gstreamer0.10: Makefile
   	pkgsrc/multimedia/gstreamer1: Makefile
   	pkgsrc/multimedia/gxine: Makefile
   	pkgsrc/multimedia/handbrake: Makefile
   	pkgsrc/multimedia/kdenlive: Makefile
   	pkgsrc/multimedia/kmplayer: Makefile
   	pkgsrc/multimedia/kmplayer-kde3: Makefile
   	pkgsrc/multimedia/libvpx: Makefile
   	pkgsrc/multimedia/ming: Makefile
   	pkgsrc/multimedia/mpv: Makefile
   	pkgsrc/multimedia/vlc: Makefile
   	pkgsrc/multimedia/vlc20: Makefile
   	pkgsrc/multimedia/x264-devel: Makefile
   	pkgsrc/multimedia/xawtv: Makefile
   	pkgsrc/multimedia/xine-lib: Makefile
   	pkgsrc/net/amule: Makefile
   	pkgsrc/net/argus: Makefile
   	pkgsrc/net/arp-scan: Makefile
   	pkgsrc/net/bind910: Makefile
   	pkgsrc/net/bind99: Makefile
   	pkgsrc/net/choqok: Makefile
   	pkgsrc/net/clive: Makefile
   	pkgsrc/net/coda: Makefile
   	pkgsrc/net/dctc: Makefile
   	pkgsrc/net/ddclient: Makefile
   	pkgsrc/net/dhcpd-pools: Makefile
   	pkgsrc/net/dlint: Makefile
   	pkgsrc/net/dnscheck: Makefile
   	pkgsrc/net/dnstracer: Makefile
   	pkgsrc/net/exabgp: Makefile
   	pkgsrc/net/fpdns: Makefile
   	pkgsrc/net/freeradius: Makefile
   	pkgsrc/net/get-flash-videos: Makefile
   	pkgsrc/net/gift: Makefile
   	pkgsrc/net/gnapfetch: Makefile
   	pkgsrc/net/ipcalc: Makefile
   	pkgsrc/net/irrd: Makefile
   	pkgsrc/net/kftpgrabber: Makefile
   	pkgsrc/net/kismet: Makefile
   	pkgsrc/net/kmldonkey-kde3: Makefile
   	pkgsrc/net/ktorrent: Makefile
   	pkgsrc/net/ktorrent-kde3: Makefile
   	pkgsrc/net/ldns: Makefile
   	pkgsrc/net/lftp: Makefile
   	pkgsrc/net/libktorrent: Makefile
   	pkgsrc/net/libquic: Makefile
   	pkgsrc/net/librsync: Makefile
   	pkgsrc/net/logjam: Makefile
   	pkgsrc/net/md-whois: Makefile
   	pkgsrc/net/mirror: Makefile
   	pkgsrc/net/mldonkey: Makefile
   	pkgsrc/net/monsoon: Makefile
   	pkgsrc/net/mrtg: Makefile
   	pkgsrc/net/nagios-nrpe: Makefile
   	pkgsrc/net/nagios-nsca: Makefile
   	pkgsrc/net/nagios-plugin-snmp: Makefile
   	pkgsrc/net/nagios-plugin-spamd: Makefile
   	pkgsrc/net/nagios-plugins: Makefile
   	pkgsrc/net/nasd: Makefile
   	pkgsrc/net/net-snmp: Makefile
   	pkgsrc/net/netatalk22: Makefile
   	pkgsrc/net/netatalk30: Makefile
   	pkgsrc/net/netdisco: Makefile
   	pkgsrc/net/nocol: Makefile
   	pkgsrc/net/ns: Makefile
   	pkgsrc/net/ntp4: Makefile
   	pkgsrc/net/ocsinventory-agent: Makefile
   	pkgsrc/net/oinkmaster: Makefile
   	pkgsrc/net/openwbem: Makefile
   	pkgsrc/net/perlbal: Makefile
   	pkgsrc/net/pfnet: Makefile
   	pkgsrc/net/proftpd: Makefile
   	pkgsrc/net/quagga: Makefile
   	pkgsrc/net/radiusd-cistron: Makefile
   	pkgsrc/net/rancid: Makefile
   	pkgsrc/net/remmina: Makefile
   	pkgsrc/net/remmina-plugins: Makefile
   	pkgsrc/net/samba: Makefile
   	pkgsrc/net/samba4: Makefile
   	pkgsrc/net/sitescooper: Makefile
   	pkgsrc/net/smokeping: Makefile
   	pkgsrc/net/snmptt: Makefile
   	pkgsrc/net/spread: Makefile
   	pkgsrc/net/stripes: Makefile
   	pkgsrc/net/tacacs: Makefile
   	pkgsrc/net/tacacs-shrubbery: Makefile
   	pkgsrc/net/tigervnc: Makefile
   	pkgsrc/net/tightvnc: Makefile
   	pkgsrc/net/torrentutils: Makefile
   	pkgsrc/net/tsclient: Makefile
   	pkgsrc/net/udpcast: Makefile
   	pkgsrc/net/vcheck: Makefile
   	pkgsrc/net/vino: Makefile
   	pkgsrc/net/vnc: Makefile
   	pkgsrc/net/vpnc: Makefile
   	pkgsrc/net/walker: Makefile
   	pkgsrc/net/wget: Makefile
   	pkgsrc/net/whois3: Makefile
   	pkgsrc/net/wireshark: Makefile
   	pkgsrc/net/wireshark1: Makefile
   	pkgsrc/net/wol: Makefile
   	pkgsrc/news/cleanscore: Makefile
   	pkgsrc/news/newsbeuter: Makefile
   	pkgsrc/news/nntpcache: Makefile
   	pkgsrc/news/tin: Makefile
   	pkgsrc/news/trn: Makefile
   	pkgsrc/parallel/gridscheduler: Makefile
   	pkgsrc/parallel/mpi-ch: Makefile
   	pkgsrc/parallel/openmpi: Makefile
   	pkgsrc/parallel/parallel: Makefile
   	pkgsrc/parallel/pdsh: Makefile
   	pkgsrc/parallel/sge: Makefile
   	pkgsrc/parallel/slurm: Makefile
   	pkgsrc/pkgtools/gnome-packagekit: Makefile
   	pkgsrc/pkgtools/lintpkgsrc: Makefile
   	pkgsrc/pkgtools/pkg_distinst: Makefile
   	pkgsrc/pkgtools/pkg_filecheck: Makefile
   	pkgsrc/pkgtools/pkg_notify: Makefile
   	pkgsrc/pkgtools/pkg_p5up2date: Makefile
   	pkgsrc/pkgtools/pkgdep: Makefile
   	pkgsrc/pkgtools/pkgdepgraph: Makefile
   	pkgsrc/pkgtools/pkgdiff: Makefile
   	pkgsrc/pkgtools/pkglint4: Makefile
   	pkgsrc/pkgtools/pkgse: Makefile
   	pkgsrc/pkgtools/pkgsrc-todo: Makefile
   	pkgsrc/pkgtools/port2pkg: Makefile
   	pkgsrc/pkgtools/revbump: Makefile
   	pkgsrc/pkgtools/texlive2pkg: Makefile
   	pkgsrc/pkgtools/url2pkg: Makefile
   	pkgsrc/print/a2ps: Makefile
   	pkgsrc/print/bibtool: Makefile
   	pkgsrc/print/chktex: Makefile
   	pkgsrc/print/cups: Makefile
   	pkgsrc/print/cups-pdf: Makefile
   	pkgsrc/print/cups15: Makefile
   	pkgsrc/print/enscript: Makefile
   	pkgsrc/print/foomatic-filters: Makefile
   	pkgsrc/print/foomatic4-db-engine: Makefile
   	pkgsrc/print/foomatic4-filters: Makefile
   	pkgsrc/print/ghostscript-agpl: Makefile
   	pkgsrc/print/ghostscript-gpl: Makefile
   	pkgsrc/print/gutenprint-lib: Makefile
   	pkgsrc/print/gv: Makefile
   	pkgsrc/print/hplip: Makefile
   	pkgsrc/print/html2ps: Makefile
   	pkgsrc/print/if-psprint: Makefile
   	pkgsrc/print/ja-a2ps: Makefile
   	pkgsrc/print/kbibtex: Makefile
   	pkgsrc/print/kbibtex-kde3: Makefile
   	pkgsrc/print/latexmk: Makefile
   	pkgsrc/print/lilypond: Makefile
   	pkgsrc/print/luatex: Makefile
   	pkgsrc/print/pdflib: Makefile
   	pkgsrc/print/pdflib-lite: Makefile
   	pkgsrc/print/psjoin: Makefile
   	pkgsrc/print/pslib: Makefile
   	pkgsrc/print/psutils: Makefile
   	pkgsrc/print/qpdf: Makefile
   	pkgsrc/print/scribus: Makefile
   	pkgsrc/print/scribus-qt4: Makefile
   	pkgsrc/print/tex-cjk-gs-integrate: Makefile
   	pkgsrc/print/tex-glossaries: Makefile
   	pkgsrc/print/tex-kotex-utils: Makefile
   	pkgsrc/print/tex-oberdiek: Makefile
   	pkgsrc/print/tex-pdftex-doc: Makefile
   	pkgsrc/print/tex-pdftools: Makefile
   	pkgsrc/print/tex-pkfix: Makefile
   	pkgsrc/print/tex-tetex: Makefile
   	pkgsrc/print/tex-texlive.infra: Makefile
   	pkgsrc/print/tex-thumbpdf: Makefile
   	pkgsrc/print/tex-xetex: Makefile
   	pkgsrc/print/tex4ht: Makefile
   	pkgsrc/print/xetex: Makefile
   	pkgsrc/print/yup: Makefile
   	pkgsrc/security/Bastille: Makefile
   	pkgsrc/security/CSP: Makefile
   	pkgsrc/security/antonym: Makefile
   	pkgsrc/security/apg: Makefile
   	pkgsrc/security/base: Makefile
   	pkgsrc/security/boringssl: Makefile
   	pkgsrc/security/caff: Makefile
   	pkgsrc/security/ccid: Makefile
   	pkgsrc/security/clusterssh: Makefile
   	pkgsrc/security/courier-authlib: Makefile
   	pkgsrc/security/dnssec-tools: Makefile
   	pkgsrc/security/egd: Makefile
   	pkgsrc/security/f-prot-antivirus6-ms-bin: Makefile
   	pkgsrc/security/gnutls: Makefile
   	pkgsrc/security/gpg2dot: Makefile
   	pkgsrc/security/hackbot: Makefile
   	pkgsrc/security/lasso: Makefile
   	pkgsrc/security/libprelude: Makefile
   	pkgsrc/security/libprelude-perl: Makefile
   	pkgsrc/security/libpreludedb: Makefile
   	pkgsrc/security/libpreludedb-mysql: Makefile
   	pkgsrc/security/libpreludedb-perl: Makefile
   	pkgsrc/security/libpreludedb-pgsql: Makefile
   	pkgsrc/security/libpreludedb-python: Makefile
   	pkgsrc/security/libpreludedb-sqlite3: Makefile
   	pkgsrc/security/log2timeline: Makefile
   	pkgsrc/security/mbedtls: Makefile
   	pkgsrc/security/mbedtls1: Makefile
   	pkgsrc/security/mhash: Makefile
   	pkgsrc/security/mit-krb5: Makefile
   	pkgsrc/security/munge: Makefile
   	pkgsrc/security/nikto: Makefile
   	pkgsrc/security/openpam: Makefile
   	pkgsrc/security/openssh: Makefile
   	pkgsrc/security/openssl: Makefile
   	pkgsrc/security/p5-pcsc: Makefile
   	pkgsrc/security/pcsc-tools: Makefile
   	pkgsrc/security/pgp5: Makefile
   	pkgsrc/security/pgpenvelope: Makefile
   	pkgsrc/security/policykit: Makefile
   	pkgsrc/security/policykit-gnome: Makefile
   	pkgsrc/security/polkit: Makefile
   	pkgsrc/security/py-lasso: Makefile
   	pkgsrc/security/racoon2: Makefile
   	pkgsrc/security/sfs: Makefile
   	pkgsrc/security/skey: Makefile
   	pkgsrc/security/sks: Makefile
   	pkgsrc/security/sleuthkit: Makefile
   	pkgsrc/security/snortsnarf: Makefile
   	pkgsrc/security/stunnel: Makefile
   	pkgsrc/security/tct: Makefile
   	pkgsrc/security/validns: Makefile
   	pkgsrc/security/zebedee: Makefile
   	pkgsrc/security/zoneminder: Makefile
   	pkgsrc/shells/mksh: Makefile
   	pkgsrc/shells/perlsh: Makefile
   	pkgsrc/shells/xsh: Makefile
   	pkgsrc/sysutils/amanda-common: Makefile
   	pkgsrc/sysutils/amtterm: Makefile
   	pkgsrc/sysutils/backuppc: Makefile
   	pkgsrc/sysutils/bacula: Makefile
   	pkgsrc/sysutils/boxbackup-client: Makefile
   	pkgsrc/sysutils/boxbackup-server: Makefile
   	pkgsrc/sysutils/bup: Makefile
   	pkgsrc/sysutils/cdbkup: Makefile
   	pkgsrc/sysutils/cdrkit: Makefile
   	pkgsrc/sysutils/cfengine2: Makefile
   	pkgsrc/sysutils/collectd: Makefile
   	pkgsrc/sysutils/consolekit: Makefile
   	pkgsrc/sysutils/coreutils: Makefile
   	pkgsrc/sysutils/cpogm: Makefile
   	pkgsrc/sysutils/cvsreport: Makefile
   	pkgsrc/sysutils/dirvish: Makefile
   	pkgsrc/sysutils/diskscrub: Makefile
   	pkgsrc/sysutils/dmassage: Makefile
   	pkgsrc/sysutils/dmesg2gif: Makefile
   	pkgsrc/sysutils/etckeeper: Makefile
   	pkgsrc/sysutils/etcmanage: Makefile
   	pkgsrc/sysutils/filelight-kde3: Makefile
   	pkgsrc/sysutils/gdmap: Makefile
   	pkgsrc/sysutils/gio-fam: Makefile
   	pkgsrc/sysutils/gnome-commander: Makefile
   	pkgsrc/sysutils/gnome-device-manager: Makefile
   	pkgsrc/sysutils/gnome-mount: Makefile
   	pkgsrc/sysutils/gnome-power-manager: Makefile
   	pkgsrc/sysutils/gnome-system-tools: Makefile
   	pkgsrc/sysutils/gnome-volume-manager: Makefile
   	pkgsrc/sysutils/hal: Makefile
   	pkgsrc/sysutils/hal-info: Makefile
   	pkgsrc/sysutils/k3b: Makefile
   	pkgsrc/sysutils/k3b-kde3: Makefile
   	pkgsrc/sysutils/k4dirstat: Makefile
   	pkgsrc/sysutils/krusader: Makefile
   	pkgsrc/sysutils/lavaps: Makefile
   	pkgsrc/sysutils/libgtop: Makefile
   	pkgsrc/sysutils/liboobs: Makefile
   	pkgsrc/sysutils/libvirt: Makefile
   	pkgsrc/sysutils/lilo: Makefile
   	pkgsrc/sysutils/lsof: Makefile
   	pkgsrc/sysutils/lxpanel: Makefile
   	pkgsrc/sysutils/magicrescue: Makefile
   	pkgsrc/sysutils/mc: Makefile
   	pkgsrc/sysutils/mc46: Makefile
   	pkgsrc/sysutils/memconf: Makefile
   	pkgsrc/sysutils/mgm: Makefile
   	pkgsrc/sysutils/munin-doc: Makefile
   	pkgsrc/sysutils/munin-node: Makefile
   	pkgsrc/sysutils/munin-server: Makefile
   	pkgsrc/sysutils/pflogsumm: Makefile
   	pkgsrc/sysutils/rconfig: Makefile
   	pkgsrc/sysutils/roller: Makefile
   	pkgsrc/sysutils/rsnapshot: Makefile
   	pkgsrc/sysutils/safetynet: Makefile
   	pkgsrc/sysutils/sarah: Makefile
   	pkgsrc/sysutils/shelldap: Makefile
   	pkgsrc/sysutils/smbldap-tools: Makefile
   	pkgsrc/sysutils/stow: Makefile
   	pkgsrc/sysutils/strace: Makefile
   	pkgsrc/sysutils/strigi: Makefile
   	pkgsrc/sysutils/swatch: Makefile
   	pkgsrc/sysutils/tenshi: Makefile
   	pkgsrc/sysutils/vifm: Makefile
   	pkgsrc/sysutils/webmin: Makefile
   	pkgsrc/sysutils/xentools3: Makefile
   	pkgsrc/sysutils/xentools3-hvm: Makefile
   	pkgsrc/sysutils/xentools33: Makefile
   	pkgsrc/sysutils/xentools41: Makefile
   	pkgsrc/sysutils/xentools42: Makefile
   	pkgsrc/sysutils/xentools45: Makefile
   	pkgsrc/sysutils/xentools46: Makefile
   	pkgsrc/sysutils/xps: Makefile
   	pkgsrc/sysutils/znapzend: Makefile
   	pkgsrc/textproc/Markdown: Makefile
   	pkgsrc/textproc/aspell: Makefile
   	pkgsrc/textproc/aspell-da: Makefile
   	pkgsrc/textproc/aspell-fo: Makefile
   	pkgsrc/textproc/btparse: Makefile
   	pkgsrc/textproc/c2html: Makefile
   	pkgsrc/textproc/cdif: Makefile
   	pkgsrc/textproc/cmigemo: Makefile
   	pkgsrc/textproc/crush-tools: Makefile
   	pkgsrc/textproc/dict-mueller7: Makefile
   	pkgsrc/textproc/diffsplit: Makefile
   	pkgsrc/textproc/docbook-xsl: Makefile
   	pkgsrc/textproc/dsssl-docbook-modular: Makefile
   	pkgsrc/textproc/dtdparse: Makefile
   	pkgsrc/textproc/eb: Makefile
   	pkgsrc/textproc/freepwing: Makefile
   	pkgsrc/textproc/grep: Makefile
   	pkgsrc/textproc/groff: Makefile
   	pkgsrc/textproc/gtk-doc: Makefile
   	pkgsrc/textproc/halibut: Makefile
   	pkgsrc/textproc/html2wml: Makefile
   	pkgsrc/textproc/hunspell: Makefile
   	pkgsrc/textproc/hunspell-de: Makefile
   	pkgsrc/textproc/hyphen: Makefile
   	pkgsrc/textproc/intltool: Makefile
   	pkgsrc/textproc/ispell-de: Makefile
   	pkgsrc/textproc/ja-groff: Makefile
   	pkgsrc/textproc/kdoc: Makefile
   	pkgsrc/textproc/latex2html: Makefile
   	pkgsrc/textproc/libxml++: Makefile
   	pkgsrc/textproc/libxslt: Makefile
   	pkgsrc/textproc/mdoclint: Makefile
   	pkgsrc/textproc/multimarkdown: Makefile
   	pkgsrc/textproc/mythes: Makefile
   	pkgsrc/textproc/namazu: Makefile
   	pkgsrc/textproc/ndtpd: Makefile
   	pkgsrc/textproc/openjade: Makefile
   	pkgsrc/textproc/opensp: Makefile
   	pkgsrc/textproc/p5-libxml: Makefile
   	pkgsrc/textproc/p5-mecab: Makefile
   	pkgsrc/textproc/p5-mobiperl: Makefile
   	pkgsrc/textproc/po4a: Makefile
   	pkgsrc/textproc/pod2mdoc: Makefile
   	pkgsrc/textproc/postgresql-autodoc: Makefile
   	pkgsrc/textproc/redland: Makefile
   	pkgsrc/textproc/rfcutil: Makefile
   	pkgsrc/textproc/sablotron: Makefile
   	pkgsrc/textproc/sub2srt: Makefile
   	pkgsrc/textproc/tex-latexdiff: Makefile
   	pkgsrc/textproc/tex-latexdiff-doc: Makefile
   	pkgsrc/textproc/texi2html: Makefile
   	pkgsrc/textproc/troffcvt: Makefile
   	pkgsrc/textproc/xapian-omega: Makefile
   	pkgsrc/textproc/xmltoman: Makefile
   	pkgsrc/textproc/yamcha: Makefile
   	pkgsrc/time/hebcal: Makefile
   	pkgsrc/time/ical2rem: Makefile
   	pkgsrc/time/libical: Makefile
   	pkgsrc/time/rem2ics: Makefile
   	pkgsrc/time/remind: Makefile
   	pkgsrc/time/rsibreak: Makefile
   	pkgsrc/time/rsibreak-kde3: Makefile
   	pkgsrc/time/titrax: Makefile
   	pkgsrc/wm/afterstep: Makefile
   	pkgsrc/wm/bbkeys: Makefile
   	pkgsrc/wm/bbkeys09: Makefile
   	pkgsrc/wm/compiz-fusion-plugins-extra: Makefile
   	pkgsrc/wm/enlightenment: Makefile
   	pkgsrc/wm/fvwm: Makefile
   	pkgsrc/wm/fvwm-devel: Makefile
   	pkgsrc/wm/fvwm-themes: Makefile
   	pkgsrc/wm/i3: Makefile
   	pkgsrc/wm/ratpoison: Makefile
   	pkgsrc/wm/waimea: Makefile
   	pkgsrc/wm/windowmaker: Makefile
   	pkgsrc/wm/wmakerconf: Makefile
   	pkgsrc/www/SpeedyCGI: Makefile
   	pkgsrc/www/adzap: Makefile
   	pkgsrc/www/album: Makefile
   	pkgsrc/www/album_themes: Makefile
   	pkgsrc/www/amaya: Makefile
   	pkgsrc/www/ap2-perl: Makefile
   	pkgsrc/www/apache22: Makefile
   	pkgsrc/www/apache24: Makefile
   	pkgsrc/www/awstats: Makefile
   	pkgsrc/www/bannerfilter: Makefile
   	pkgsrc/www/bins: Makefile
   	pkgsrc/www/bluefish: Makefile
   	pkgsrc/www/calamaris: Makefile
   	pkgsrc/www/checkbot: Makefile
   	pkgsrc/www/clearsilver: Makefile
   	pkgsrc/www/cronolog: Makefile
   	pkgsrc/www/curl: Makefile
   	pkgsrc/www/cvsweb: Makefile
   	pkgsrc/www/dansguardian: Makefile
   	pkgsrc/www/davical: Makefile
   	pkgsrc/www/dillo: Makefile
   	pkgsrc/www/drraw: Makefile
   	pkgsrc/www/firefox: Makefile
   	pkgsrc/www/firefox24: Makefile
   	pkgsrc/www/firefox31: Makefile
   	pkgsrc/www/firefox38: Makefile
   	pkgsrc/www/firefox45: Makefile
   	pkgsrc/www/gallery: Makefile
   	pkgsrc/www/gitweb: Makefile
   	pkgsrc/www/h2o: Makefile
   	pkgsrc/www/htmlfix: Makefile
   	pkgsrc/www/htmllint: Makefile
   	pkgsrc/www/icedtea-web: Makefile
   	pkgsrc/www/ikiwiki: Makefile
   	pkgsrc/www/kannel: Makefile
   	pkgsrc/www/kdewebdev3: Makefile
   	pkgsrc/www/libwww: Makefile
   	pkgsrc/www/liferea: Makefile
   	pkgsrc/www/llgal: Makefile
   	pkgsrc/www/make_album: Makefile
   	pkgsrc/www/mknmz-wwwoffle: Makefile
   	pkgsrc/www/moodle: Makefile
   	pkgsrc/www/neon: Makefile
   	pkgsrc/www/netsurf: Makefile
   	pkgsrc/www/nvu: Makefile
   	pkgsrc/www/p5-HTMLObject: Makefile
   	pkgsrc/www/p5-libwww: Makefile
   	pkgsrc/www/php-owncloud: Makefile
   	pkgsrc/www/privoxy: Makefile
   	pkgsrc/www/py-moin: Makefile
   	pkgsrc/www/screws: Makefile
   	pkgsrc/www/snownews: Makefile
   	pkgsrc/www/squid3: Makefile
   	pkgsrc/www/squidGuard: Makefile
   	pkgsrc/www/squidanalyzer: Makefile
   	pkgsrc/www/squidclamav: Makefile
   	pkgsrc/www/surfraw: Makefile
   	pkgsrc/www/swish-e: Makefile
   	pkgsrc/www/w3m: Makefile
   	pkgsrc/www/wApua: Makefile
   	pkgsrc/www/wdg-validate: Makefile
   	pkgsrc/www/webkit-gtk: Makefile
   	pkgsrc/www/webkit24-gtk: Makefile
   	pkgsrc/www/weblint: Makefile
   	pkgsrc/www/webnew: Makefile
   	pkgsrc/www/whisker: Makefile
   	pkgsrc/www/wml: Makefile
   	pkgsrc/www/wwwoffle: Makefile
   	pkgsrc/www/yaws: Makefile
   	pkgsrc/x11/alacarte: Makefile
   	pkgsrc/x11/eterm: Makefile
   	pkgsrc/x11/gcolor2: Makefile
   	pkgsrc/x11/gnome-desktop: Makefile
   	pkgsrc/x11/gnome-panel: Makefile
   	pkgsrc/x11/gnome-session: Makefile
   	pkgsrc/x11/gnome-terminal: Makefile
   	pkgsrc/x11/gtk: Makefile
   	pkgsrc/x11/gtk-sharp: Makefile
   	pkgsrc/x11/gtk2: Makefile
   	pkgsrc/x11/gtk2-chtheme: Makefile
   	pkgsrc/x11/gtk3: Makefile
   	pkgsrc/x11/gtkada: Makefile
   	pkgsrc/x11/gtkmm: Makefile
   	pkgsrc/x11/gtkmm3: Makefile
   	pkgsrc/x11/gtksourceview: Makefile
   	pkgsrc/x11/gtksourceview2: Makefile
   	pkgsrc/x11/gtksourceviewmm: Makefile
   	pkgsrc/x11/kconfigwidgets: Makefile
   	pkgsrc/x11/kdebindings-ruby: Makefile
   	pkgsrc/x11/kdelibs3: Makefile
   	pkgsrc/x11/p5-Wx: Makefile
   	pkgsrc/x11/pixman: Makefile
   	pkgsrc/x11/py-wxWidgets: Makefile
   	pkgsrc/x11/qt5-qtbase: Makefile
   	pkgsrc/x11/wxGTK30: Makefile
   	pkgsrc/x11/xephem: Makefile
   	pkgsrc/x11/xfce4-exo: Makefile
   	pkgsrc/x11/xfce4-whiskermenu-plugin: Makefile
   	pkgsrc/x11/xkbset: Makefile
   	pkgsrc/x11/xplanet: Makefile
   	pkgsrc/x11/xscreensaver: Makefile

   Log Message:
   Bump PKGREVISION for perl-5.24.0 for everything mentioning perl.


   To generate a diff of this commit:
   cvs rdiff -u -r1.19 -r1.20 pkgsrc/net/samba4/Makefile

-------------------------------------------------------------------
   Module Name:	pkgsrc
   Committed By:	wiz
   Date:		Sat Jul  9 13:04:18 UTC 2016

   Modified Files:
   	pkgsrc/audio/ardour: Makefile
   	pkgsrc/audio/aubio: Makefile
   	pkgsrc/audio/csound5: Makefile
   	pkgsrc/audio/csound6: Makefile
   	pkgsrc/audio/csound6-manual: Makefile
   	pkgsrc/audio/exaile: Makefile
   	pkgsrc/audio/eyeD3: Makefile
   	pkgsrc/audio/moss: Makefile
   	pkgsrc/audio/mutagen-tools: Makefile
   	pkgsrc/audio/picard: Makefile
   	pkgsrc/audio/py-acoustid: Makefile
   	pkgsrc/audio/py-ao: Makefile
   	pkgsrc/audio/py-beets: Makefile
   	pkgsrc/audio/py-cddb: Makefile
   	pkgsrc/audio/py-daap: Makefile
   	pkgsrc/audio/py-discogs_client: Makefile
   	pkgsrc/audio/py-id3: Makefile
   	pkgsrc/audio/py-id3lib: Makefile
   	pkgsrc/audio/py-karaoke: Makefile
   	pkgsrc/audio/py-libmtag: Makefile
   	pkgsrc/audio/py-mad: Makefile
   	pkgsrc/audio/py-musicbrainz: Makefile
   	pkgsrc/audio/py-musique: Makefile
   	pkgsrc/audio/py-ogg: Makefile
   	pkgsrc/audio/py-vorbis: Makefile
   	pkgsrc/audio/quodlibet2: Makefile
   	pkgsrc/audio/rhythmbox: Makefile
   	pkgsrc/audio/solfege: Makefile
   	pkgsrc/audio/sonata: Makefile
   	pkgsrc/audio/streamtuner: options.mk
   	pkgsrc/audio/tunapie: Makefile
   	pkgsrc/benchmarks/glmark2: Makefile
   	pkgsrc/biology/py-mol: Makefile
   	pkgsrc/cad/py-MyHDL: Makefile
   	pkgsrc/chat/empathy: Makefile
   	pkgsrc/chat/gajim: Makefile options.mk
   	pkgsrc/chat/libtelepathy: Makefile
   	pkgsrc/chat/py-xmpppy: Makefile
   	pkgsrc/chat/spectrum: Makefile
   	pkgsrc/chat/telepathy-farsight: Makefile
   	pkgsrc/chat/telepathy-gabble: Makefile
   	pkgsrc/chat/telepathy-glib: Makefile
   	pkgsrc/chat/telepathy-haze: Makefile
   	pkgsrc/chat/telepathy-idle: Makefile
   	pkgsrc/chat/telepathy-logger: Makefile
   	pkgsrc/chat/telepathy-mission-control5: Makefile
   	pkgsrc/chat/telepathy-qt: Makefile
   	pkgsrc/chat/xchat-python: Makefile
   	pkgsrc/comms/multisync-gui: Makefile
   	pkgsrc/comms/py-gammu: Makefile
   	pkgsrc/converters/py-jpCodecs: Makefile
   	pkgsrc/converters/py-yenc: Makefile
   	pkgsrc/converters/py-zbase32: Makefile
   	pkgsrc/converters/py-zfec: Makefile
   	pkgsrc/converters/py-zhCodecs: Makefile
   	pkgsrc/databases/gourmet: Makefile
   	pkgsrc/databases/gramps3: Makefile options.mk
   	pkgsrc/databases/libpqxx: Makefile
   	pkgsrc/databases/luma: Makefile
   	pkgsrc/databases/mongodb: Makefile
   	pkgsrc/databases/py-PgSQL: Makefile
   	pkgsrc/databases/py-bdb-xml: Makefile
   	pkgsrc/databases/py-carbon: Makefile options.mk
   	pkgsrc/databases/py-cassa: Makefile
   	pkgsrc/databases/py-cdb: Makefile
   	pkgsrc/databases/py-ckanclient: Makefile
   	pkgsrc/databases/py-couchdb: Makefile
   	pkgsrc/databases/py-datapkg: Makefile
   	pkgsrc/databases/py-elixir: Makefile
   	pkgsrc/databases/py-ldap: Makefile
   	pkgsrc/databases/py-metakit: Makefile
   	pkgsrc/databases/py-mssql: Makefile
   	pkgsrc/databases/py-mysqldb: Makefile
   	pkgsrc/databases/py-python-rrdtool: Makefile
   	pkgsrc/databases/py-sqlalchemy-migrate: Makefile
   	pkgsrc/databases/py-sqlite: Makefile
   	pkgsrc/databases/py-sqlite2: Makefile
   	pkgsrc/databases/py-sqlrelay: Makefile
   	pkgsrc/databases/py-sybase: Makefile
   	pkgsrc/databases/py-table: Makefile
   	pkgsrc/databases/py-tokyocabinet: Makefile
   	pkgsrc/databases/py-whisper: Makefile
   	pkgsrc/databases/skytools: Makefile
   	pkgsrc/databases/tdb: Makefile
   	pkgsrc/devel/ExmanIDE: Makefile
   	pkgsrc/devel/GConf: Makefile
   	pkgsrc/devel/RBTools: Makefile
   	pkgsrc/devel/accerciser: Makefile
   	pkgsrc/devel/boa-constructor: Makefile
   	pkgsrc/devel/bokken: Makefile
   	pkgsrc/devel/bpython: Makefile
   	pkgsrc/devel/bugs-everywhere: Makefile
   	pkgsrc/devel/bzr: Makefile
   	pkgsrc/devel/bzr-explorer: Makefile
   	pkgsrc/devel/bzr-gtk: Makefile
   	pkgsrc/devel/bzr-svn: Makefile
   	pkgsrc/devel/bzrtools: Makefile
   	pkgsrc/devel/codeville: Makefile
   	pkgsrc/devel/cvs2svn: Makefile
   	pkgsrc/devel/diffuse: Makefile
   	pkgsrc/devel/distcc-pump: Makefile
   	pkgsrc/devel/doxygen: Makefile
   	pkgsrc/devel/epydoc: Makefile
   	pkgsrc/devel/eric4: Makefile
   	pkgsrc/devel/gdb: options.mk
   	pkgsrc/devel/gnatpython: Makefile
   	pkgsrc/devel/googletest: Makefile
   	pkgsrc/devel/gps: options.mk
   	pkgsrc/devel/gyp: Makefile
   	pkgsrc/devel/kdesdk3: Makefile
   	pkgsrc/devel/ko-po-check: Makefile
   	pkgsrc/devel/lettuce: Makefile
   	pkgsrc/devel/libappindicator: Makefile
   	pkgsrc/devel/libappindicator3: Makefile
   	pkgsrc/devel/libftdi1: Makefile
   	pkgsrc/devel/libgit2: Makefile
   	pkgsrc/devel/libhid: Makefile
   	pkgsrc/devel/meld: Makefile
   	pkgsrc/devel/py-InlineEgg: Makefile
   	pkgsrc/devel/py-Optik: Makefile
   	pkgsrc/devel/py-astroid: Makefile
   	pkgsrc/devel/py-at-spi: Makefile
   	pkgsrc/devel/py-buildbot: Makefile
   	pkgsrc/devel/py-buildbot-slave: Makefile
   	pkgsrc/devel/py-cached-property: Makefile
   	pkgsrc/devel/py-checker: Makefile
   	pkgsrc/devel/py-cheetah: Makefile
   	pkgsrc/devel/py-compizconfig: Makefile
   	pkgsrc/devel/py-daemon: Makefile
   	pkgsrc/devel/py-darcsver: Makefile
   	pkgsrc/devel/py-dialog2: Makefile
   	pkgsrc/devel/py-distorm3: Makefile
   	pkgsrc/devel/py-doctor: Makefile
   	pkgsrc/devel/py-enum34: Makefile
   	pkgsrc/devel/py-expect: Makefile
   	pkgsrc/devel/py-fastimport: Makefile
   	pkgsrc/devel/py-futures: Makefile
   	pkgsrc/devel/py-gflags: Makefile
   	pkgsrc/devel/py-gobject: Makefile
   	pkgsrc/devel/py-google-apputils: Makefile
   	pkgsrc/devel/py-hg-fastimport: Makefile
   	pkgsrc/devel/py-hg-git: Makefile
   	pkgsrc/devel/py-hglib: Makefile
   	pkgsrc/devel/py-hglist: Makefile
   	pkgsrc/devel/py-hgnested: Makefile
   	pkgsrc/devel/py-hgview: Makefile
   	pkgsrc/devel/py-ipaddr: Makefile
   	pkgsrc/devel/py-ipython010: Makefile
   	pkgsrc/devel/py-ipython013: Makefile
   	pkgsrc/devel/py-jersey: Makefile
   	pkgsrc/devel/py-kjbuckets: Makefile
   	pkgsrc/devel/py-kqueue: Makefile
   	pkgsrc/devel/py-logilab-astng: Makefile
   	pkgsrc/devel/py-logilab-common: Makefile
   	pkgsrc/devel/py-memcached: Makefile
   	pkgsrc/devel/py-mercurial: Makefile.version
   	pkgsrc/devel/py-multiprocessing: Makefile
   	pkgsrc/devel/py-newt: Makefile
   	pkgsrc/devel/py-open-vcdiff: Makefile
   	pkgsrc/devel/py-pqueue: Makefile
   	pkgsrc/devel/py-proteus: options.mk
   	pkgsrc/devel/py-protobuf: Makefile
   	pkgsrc/devel/py-pylint: Makefile
   	pkgsrc/devel/py-pytemplate: Makefile
   	pkgsrc/devel/py-pyutil: Makefile
   	pkgsrc/devel/py-quixote: Makefile
   	pkgsrc/devel/py-rope: Makefile
   	pkgsrc/devel/py-ruamel-ordereddict: Makefile
   	pkgsrc/devel/py-setuptools_trial: Makefile
   	pkgsrc/devel/py-singledispatch: Makefile
   	pkgsrc/devel/py-stompclient: Makefile
   	pkgsrc/devel/py-subprocess32: Makefile
   	pkgsrc/devel/py-subvertpy: Makefile
   	pkgsrc/devel/py-tabular: Makefile
   	pkgsrc/devel/py-tortoisehg: Makefile
   	pkgsrc/devel/py-tryton: options.mk
   	pkgsrc/devel/py-trytond: Makefile.common options.mk
   	pkgsrc/devel/py-unit: Makefile
   	pkgsrc/devel/py-unitgui: Makefile
   	pkgsrc/devel/py-usb: Makefile
   	pkgsrc/devel/py-windbg: Makefile
   	pkgsrc/devel/py-zanata-python-client: Makefile
   	pkgsrc/devel/py-zconfig: Makefile
   	pkgsrc/devel/qbzr: Makefile
   	pkgsrc/devel/reposurgeon: Makefile
   	pkgsrc/devel/roundup: Makefile
   	pkgsrc/devel/rox-lib: Makefile
   	pkgsrc/devel/scons: Makefile
   	pkgsrc/devel/stgit: Makefile
   	pkgsrc/devel/tailor: Makefile
   	pkgsrc/devel/talloc: Makefile
   	pkgsrc/devel/transifex-client: Makefile
   	pkgsrc/devel/umbrello: Makefile
   	pkgsrc/devel/xulrunner10: mozilla-common.mk
   	pkgsrc/devel/xulrunner17: mozilla-common.mk
   	pkgsrc/devel/xulrunner192: mozilla-common.mk
   	pkgsrc/editors/gedit-python: Makefile
   	pkgsrc/editors/kdissert: Makefile
   	pkgsrc/editors/lyx: Makefile
   	pkgsrc/editors/medit: Makefile
   	pkgsrc/editors/nts: Makefile
   	pkgsrc/editors/pluma: options.mk
   	pkgsrc/editors/zim: Makefile
   	pkgsrc/emulators/fs-uae-launcher: Makefile
   	pkgsrc/emulators/gns3: Makefile
   	pkgsrc/emulators/hatari: Makefile
   	pkgsrc/emulators/mame: Makefile
   	pkgsrc/emulators/openmsx: Makefile
   	pkgsrc/emulators/qemu: Makefile
   	pkgsrc/emulators/qemu0: Makefile
   	pkgsrc/emulators/unicorn: Makefile
   	pkgsrc/filesystems/fuse-gmailfs: Makefile
   	pkgsrc/filesystems/fuse-pcachefs: Makefile
   	pkgsrc/filesystems/fuse-wikipediafs: Makefile
   	pkgsrc/filesystems/glusterfs: Makefile
   	pkgsrc/filesystems/py-filesystem: Makefile
   	pkgsrc/filesystems/py-fuse-bindings: Makefile
   	pkgsrc/filesystems/tahoe-lafs: Makefile
   	pkgsrc/finance/gnucash: Makefile
   	pkgsrc/finance/moneyguru: Makefile
   	pkgsrc/finance/py-stripe: Makefile
   	pkgsrc/finance/py-vatnumber: Makefile
   	pkgsrc/fonts/mftrace: Makefile
   	pkgsrc/fonts/py-TTFQuery: Makefile
   	pkgsrc/games/4stAttack: Makefile
   	pkgsrc/games/blindmine: Makefile
   	pkgsrc/games/freeciv-share: Makefile.common
   	pkgsrc/games/gcompris: Makefile
   	pkgsrc/games/gnome-games: Makefile
   	pkgsrc/games/jools: Makefile
   	pkgsrc/games/kajongg: Makefile
   	pkgsrc/games/kye: Makefile
   	pkgsrc/games/monsterz: Makefile
   	pkgsrc/games/py-easyAI: Makefile
   	pkgsrc/games/py-renpy: Makefile
   	pkgsrc/games/pysolfc: Makefile
   	pkgsrc/games/pytraffic: Makefile
   	pkgsrc/games/teeworlds: Makefile
   	pkgsrc/games/wesnoth: Makefile
   	pkgsrc/geography/gpsd: Makefile
   	pkgsrc/geography/proj-swig: Makefile
   	pkgsrc/geography/py-google-maps-services-python: Makefile
   	pkgsrc/geography/py-obspy: Makefile
   	pkgsrc/geography/qgis: options.mk
   	pkgsrc/graphics/MesaLib: Makefile
   	pkgsrc/graphics/MesaLib7: Makefile
   	pkgsrc/graphics/blender: Makefile
   	pkgsrc/graphics/comix: Makefile
   	pkgsrc/graphics/dia-python: Makefile
   	pkgsrc/graphics/eog: Makefile
   	pkgsrc/graphics/eom: options.mk
   	pkgsrc/graphics/gimp-docs-en: Makefile.common
   	pkgsrc/graphics/libscigraphica: Makefile
   	pkgsrc/graphics/mypaint: Makefile
   	pkgsrc/graphics/py-OpenGL: Makefile
   	pkgsrc/graphics/py-aafigure: Makefile
   	pkgsrc/graphics/py-biggles: Makefile
   	pkgsrc/graphics/py-cairo: Makefile
   	pkgsrc/graphics/py-chart: Makefile
   	pkgsrc/graphics/py-dot: Makefile
   	pkgsrc/graphics/py-gdchart: Makefile
   	pkgsrc/graphics/py-gdmodule: Makefile
   	pkgsrc/graphics/py-gnuplot: Makefile
   	pkgsrc/graphics/py-goocanvas: Makefile
   	pkgsrc/graphics/py-gtkglext: Makefile
   	pkgsrc/graphics/py-imaging: Makefile
   	pkgsrc/graphics/py-imagingtk: Makefile
   	pkgsrc/graphics/py-matplotlib-gtk2: Makefile
   	pkgsrc/graphics/py-mcomix: Makefile
   	pkgsrc/graphics/py-piddle: Makefile
   	pkgsrc/graphics/py-pycha: Makefile
   	pkgsrc/graphics/py-sk1libs: Makefile
   	pkgsrc/graphics/py-uniconvertor: Makefile
   	pkgsrc/graphics/scigraphica: Makefile
   	pkgsrc/graphics/skencil: Makefile
   	pkgsrc/graphics/xdot: Makefile
   	pkgsrc/ham/gnuradio-core: Makefile.common
   	pkgsrc/inputmethod/ibus-python: Makefile
   	pkgsrc/inputmethod/ibus-tegaki: Makefile
   	pkgsrc/inputmethod/mozc-server: Makefile.common
   	pkgsrc/inputmethod/py-input-pad: Makefile
   	pkgsrc/inputmethod/py-zinnia: Makefile
   	pkgsrc/inputmethod/scim-python: Makefile
   	pkgsrc/inputmethod/tegaki-pygtk: Makefile
   	pkgsrc/inputmethod/tegaki-python: Makefile
   	pkgsrc/inputmethod/tegaki-recognize: Makefile
   	pkgsrc/inputmethod/tegaki-tools: Makefile
   	pkgsrc/inputmethod/tegaki-train: Makefile
   	pkgsrc/inputmethod/tegaki-wagomu: Makefile
   	pkgsrc/lang/clang-static-analyzer: Makefile
   	pkgsrc/lang/nodejs: Makefile.common
   	pkgsrc/lang/py-basicproperty: Makefile
   	pkgsrc/lang/py-pyrex: Makefile
   	pkgsrc/lang/py-pythonz: Makefile
   	pkgsrc/lang/python: pyversion.mk
   	pkgsrc/mail/archivemail: Makefile
   	pkgsrc/mail/fetchmailconf: Makefile
   	pkgsrc/mail/getmail: Makefile
   	pkgsrc/mail/mailman: Makefile
   	pkgsrc/mail/offlineimap: Makefile
   	pkgsrc/mail/py-libgmail: Makefile
   	pkgsrc/mail/thunderbird-enigmail: Makefile.common
   	pkgsrc/mail/tmda: Makefile
   	pkgsrc/math/gnumeric: Makefile
   	pkgsrc/math/gnumeric110: Makefile
   	pkgsrc/math/gnumeric112: Makefile
   	pkgsrc/math/py-Numeric: Makefile
   	pkgsrc/math/py-Scientific: Makefile
   	pkgsrc/math/py-cdecimal: Makefile
   	pkgsrc/math/py-ephem: Makefile
   	pkgsrc/math/py-fftw: Makefile
   	pkgsrc/math/py-fpconst: Makefile
   	pkgsrc/math/py-networkx: Makefile
   	pkgsrc/math/py-numarray: Makefile
   	pkgsrc/math/py-simpleeval: Makefile
   	pkgsrc/meta-pkgs/bulk-large: Makefile
   	pkgsrc/meta-pkgs/bulk-medium: Makefile
   	pkgsrc/meta-pkgs/gnome: Makefile
   	pkgsrc/meta-pkgs/py-gnome-bindings: Makefile
   	pkgsrc/misc/byobu: Makefile
   	pkgsrc/misc/calibre: Makefile
   	pkgsrc/misc/calibre1: Makefile
   	pkgsrc/misc/deskbar-applet: Makefile
   	pkgsrc/misc/kdeutils3: Makefile
   	pkgsrc/misc/khard: Makefile
   	pkgsrc/misc/koffice: Makefile
   	pkgsrc/misc/mnemosyne: Makefile
   	pkgsrc/misc/openoffice3: Makefile
   	pkgsrc/misc/orca: Makefile
   	pkgsrc/misc/py-anita: Makefile
   	pkgsrc/misc/py-anki2: Makefile
   	pkgsrc/misc/py-carddav: Makefile
   	pkgsrc/misc/py-stdnum: Makefile
   	pkgsrc/misc/routeplanner-cli: Makefile
   	pkgsrc/misc/superkaramba: Makefile
   	pkgsrc/multimedia/farsight2: Makefile
   	pkgsrc/multimedia/kodi: Makefile
   	pkgsrc/multimedia/libkate: options.mk
   	pkgsrc/multimedia/livestreamer: Makefile
   	pkgsrc/multimedia/pitivi: Makefile
   	pkgsrc/multimedia/py-gstreamer0.10: Makefile
   	pkgsrc/multimedia/py-ming: Makefile
   	pkgsrc/multimedia/totem: Makefile.common
   	pkgsrc/net/Radicale: options.mk
   	pkgsrc/net/avahi: options.mk
   	pkgsrc/net/bittornado: Makefile
   	pkgsrc/net/bittornado-gui: Makefile
   	pkgsrc/net/bittorrent: Makefile
   	pkgsrc/net/bittorrent-gui: Makefile
   	pkgsrc/net/calypso: Makefile
   	pkgsrc/net/coherence: Makefile
   	pkgsrc/net/coilmq: Makefile
   	pkgsrc/net/exabgp: Makefile
   	pkgsrc/net/gitso: Makefile
   	pkgsrc/net/gtk-vnc: options.mk
   	pkgsrc/net/mimms: Makefile
   	pkgsrc/net/mitmproxy: Makefile
   	pkgsrc/net/nagstamon: Makefile
   	pkgsrc/net/nicotine: Makefile
   	pkgsrc/net/nmap: options.mk
   	pkgsrc/net/omniORB: Makefile
   	pkgsrc/net/py-GeoIP: Makefile
   	pkgsrc/net/py-ORBit: Makefile
   	pkgsrc/net/py-adns: Makefile
   	pkgsrc/net/py-beanstalkc: Makefile
   	pkgsrc/net/py-bitmessage: Makefile
   	pkgsrc/net/py-caldav: Makefile
   	pkgsrc/net/py-dpkt: Makefile
   	pkgsrc/net/py-eventlib: Makefile
   	pkgsrc/net/py-foolscap: Makefile
   	pkgsrc/net/py-gevent: Makefile
   	pkgsrc/net/py-google: Makefile
   	pkgsrc/net/py-ipaddress: Makefile
   	pkgsrc/net/py-kenosis: Makefile
   	pkgsrc/net/py-libdnet: Makefile
   	pkgsrc/net/py-libpcap: Makefile
   	pkgsrc/net/py-medusa: Makefile
   	pkgsrc/net/py-metar: Makefile
   	pkgsrc/net/py-netifaces: Makefile
   	pkgsrc/net/py-netsnmp: Makefile
   	pkgsrc/net/py-omniORBpy: Makefile
   	pkgsrc/net/py-pcap: Makefile
   	pkgsrc/net/py-s3cmd: Makefile
   	pkgsrc/net/py-soappy: Makefile
   	pkgsrc/net/py-socketpool: Makefile
   	pkgsrc/net/py-spreadmodule: Makefile
   	pkgsrc/net/py-suds: Makefile
   	pkgsrc/net/py-tweepy: Makefile
   	pkgsrc/net/py-twisted: Makefile.common
   	pkgsrc/net/py-txamqp: Makefile
   	pkgsrc/net/py-zsi: Makefile
   	pkgsrc/net/pygopherd: Makefile
   	pkgsrc/net/samba4: Makefile
   	pkgsrc/net/scapy: Makefile options.mk
   	pkgsrc/net/upnpinspector: Makefile
   	pkgsrc/net/wireshark: Makefile
   	pkgsrc/net/wireshark1: Makefile
   	pkgsrc/news/hellanzb: Makefile
   	pkgsrc/news/lottanzb: Makefile
   	pkgsrc/pkgtools/gnome-packagekit: Makefile
   	pkgsrc/pkgtools/packagekit: Makefile
   	pkgsrc/print/hplip: options.mk
   	pkgsrc/print/lilypond: Makefile
   	pkgsrc/print/pdfshuffler: Makefile
   	pkgsrc/print/py-pisa: Makefile
   	pkgsrc/print/py-poppler: Makefile
   	pkgsrc/print/py-reportlab: Makefile
   	pkgsrc/print/scribus: Makefile
   	pkgsrc/print/scribus-qt4: Makefile
   	pkgsrc/security/botan: Makefile
   	pkgsrc/security/lasso: Makefile
   	pkgsrc/security/libprelude-python: Makefile
   	pkgsrc/security/libpreludedb-python: Makefile
   	pkgsrc/security/mixminion: Makefile
   	pkgsrc/security/prelude-correlator: Makefile
   	pkgsrc/security/py-SSLCrypto: Makefile
   	pkgsrc/security/py-backports.ssl_match_hostname: Makefile
   	pkgsrc/security/py-cryptkit: Makefile
   	pkgsrc/security/py-cryptopp: Makefile
   	pkgsrc/security/py-cybox: Makefile
   	pkgsrc/security/py-denyhosts: Makefile
   	pkgsrc/security/py-gnupg: Makefile
   	pkgsrc/security/py-lasso: Makefile
   	pkgsrc/security/py-libtaxii: Makefile
   	pkgsrc/security/py-m2crypto: Makefile
   	pkgsrc/security/py-mcrypt: Makefile
   	pkgsrc/security/py-oauth2: Makefile
   	pkgsrc/security/py-openid: Makefile
   	pkgsrc/security/py-prewikka: Makefile
   	pkgsrc/security/py-service_identity: Makefile
   	pkgsrc/security/py-stix: Makefile
   	pkgsrc/security/py-tlslite: Makefile
   	pkgsrc/security/py-urllib2-kerberos: Makefile
   	pkgsrc/security/py-xmlsec: Makefile
   	pkgsrc/security/py-yara: Makefile
   	pkgsrc/security/py-yubiauth: Makefile
   	pkgsrc/security/volatility: Makefile
   	pkgsrc/shells/lshell: Makefile
   	pkgsrc/sysutils/ansible: Makefile
   	pkgsrc/sysutils/bup: Makefile
   	pkgsrc/sysutils/caja-dropbox: Makefile
   	pkgsrc/sysutils/cuisine: Makefile
   	pkgsrc/sysutils/dbus-python-common: Makefile
   	pkgsrc/sysutils/duplicity: Makefile
   	pkgsrc/sysutils/euca2ools: Makefile
   	pkgsrc/sysutils/fabric: Makefile
   	pkgsrc/sysutils/gnome-commander: Makefile
   	pkgsrc/sysutils/libvirt: Makefile
   	pkgsrc/sysutils/manifold: Makefile
   	pkgsrc/sysutils/monitoring: Makefile
   	pkgsrc/sysutils/openxenmanager: Makefile
   	pkgsrc/sysutils/polysh: Makefile
   	pkgsrc/sysutils/py-borgbackup: Makefile
   	pkgsrc/sysutils/py-gnome-menus: Makefile
   	pkgsrc/sysutils/py-notify: Makefile
   	pkgsrc/sysutils/py-notify-python: Makefile
   	pkgsrc/sysutils/py-pefile: Makefile
   	pkgsrc/sysutils/py-xattr: Makefile
   	pkgsrc/sysutils/rdiff-backup: Makefile
   	pkgsrc/sysutils/salt: Makefile
   	pkgsrc/sysutils/salt-docs: Makefile
   	pkgsrc/sysutils/virt-manager: Makefile
   	pkgsrc/sysutils/virtinst: Makefile
   	pkgsrc/sysutils/xenkernel3: Makefile
   	pkgsrc/sysutils/xenkernel33: Makefile
   	pkgsrc/sysutils/xenkernel41: Makefile
   	pkgsrc/sysutils/xenkernel42: Makefile
   	pkgsrc/sysutils/xenkernel45: Makefile
   	pkgsrc/sysutils/xenkernel46: Makefile
   	pkgsrc/sysutils/xentools3: Makefile
   	pkgsrc/sysutils/xentools3-hvm: Makefile
   	pkgsrc/sysutils/xentools33: Makefile
   	pkgsrc/sysutils/xentools41: Makefile
   	pkgsrc/sysutils/xentools42: Makefile
   	pkgsrc/sysutils/xentools45: Makefile
   	pkgsrc/sysutils/xentools46: Makefile
   	pkgsrc/textproc/asciidoc: Makefile
   	pkgsrc/textproc/coccigrep: Makefile
   	pkgsrc/textproc/dblatex: Makefile
   	pkgsrc/textproc/gnome-doc-utils: Makefile
   	pkgsrc/textproc/gtk-doc: Makefile
   	pkgsrc/textproc/ispell-lt: Makefile
   	pkgsrc/textproc/itstool: Makefile
   	pkgsrc/textproc/libplist: Makefile
   	pkgsrc/textproc/markdown2social: Makefile
   	pkgsrc/textproc/py-4Suite: Makefile
   	pkgsrc/textproc/py-Excelerator: Makefile
   	pkgsrc/textproc/py-HappyDoc: Makefile
   	pkgsrc/textproc/py-Whoosh: Makefile
   	pkgsrc/textproc/py-X2: Makefile
   	pkgsrc/textproc/py-cabocha: Makefile
   	pkgsrc/textproc/py-cjson: Makefile
   	pkgsrc/textproc/py-cmTemplate: Makefile
   	pkgsrc/textproc/py-elementtree: Makefile
   	pkgsrc/textproc/py-empy: Makefile
   	pkgsrc/textproc/py-generateDS: Makefile
   	pkgsrc/textproc/py-gnosis-utils: Makefile
   	pkgsrc/textproc/py-iniparse: Makefile
   	pkgsrc/textproc/py-jsonlib: Makefile
   	pkgsrc/textproc/py-libxslt: Makefile
   	pkgsrc/textproc/py-marisa: Makefile
   	pkgsrc/textproc/py-mecab: Makefile
   	pkgsrc/textproc/py-relatorio: Makefile
   	pkgsrc/textproc/py-vobject: Makefile
   	pkgsrc/textproc/py-xlwt: Makefile
   	pkgsrc/textproc/py-xml: Makefile
   	pkgsrc/textproc/py-yamcha: Makefile
   	pkgsrc/textproc/queequeg: Makefile
   	pkgsrc/textproc/rubber: Makefile
   	pkgsrc/textproc/xmlada: Makefile
   	pkgsrc/time/etm: Makefile
   	pkgsrc/time/gdeskcal: Makefile
   	pkgsrc/time/hamster-applet: Makefile
   	pkgsrc/time/py-goocalendar: Makefile
   	pkgsrc/time/py-mxDateTime: Makefile
   	pkgsrc/time/wxRemind: Makefile
   	pkgsrc/wm/bmpanel2: Makefile
   	pkgsrc/wm/ccsm: Makefile
   	pkgsrc/wm/py-tyle: Makefile
   	pkgsrc/www/ap-scgi: Makefile
   	pkgsrc/www/bluefish: Makefile
   	pkgsrc/www/browser-bookmarks-menu: Makefile
   	pkgsrc/www/cherokee: Makefile
   	pkgsrc/www/clearsilver: Makefile
   	pkgsrc/www/firefox: mozilla-common.mk
   	pkgsrc/www/firefox24: mozilla-common.mk
   	pkgsrc/www/firefox31: mozilla-common.mk
   	pkgsrc/www/firefox38: mozilla-common.mk
   	pkgsrc/www/firefox45: mozilla-common.mk
   	pkgsrc/www/ies4linux: Makefile
   	pkgsrc/www/loggerhead: Makefile
   	pkgsrc/www/py-ClientForm: Makefile
   	pkgsrc/www/py-HTMLgen: Makefile
   	pkgsrc/www/py-beautifulsoup: Makefile
   	pkgsrc/www/py-blosxom: Makefile
   	pkgsrc/www/py-clearsilver: Makefile
   	pkgsrc/www/py-django-appmedia: Makefile
   	pkgsrc/www/py-django-mezzanine-filebrowser: Makefile
   	pkgsrc/www/py-django-mezzanine-grappelli: Makefile
   	pkgsrc/www/py-django-photologue: Makefile
   	pkgsrc/www/py-django14: Makefile options.mk
   	pkgsrc/www/py-djangorestframework: Makefile
   	pkgsrc/www/py-flup: Makefile
   	pkgsrc/www/py-gdata: Makefile
   	pkgsrc/www/py-google-api-python-client: Makefile
   	pkgsrc/www/py-graphite-web: Makefile
   	pkgsrc/www/py-jonpy: Makefile
   	pkgsrc/www/py-mechanize: Makefile
   	pkgsrc/www/py-mezzanine: Makefile
   	pkgsrc/www/py-moin: Makefile
   	pkgsrc/www/py-nevow: Makefile
   	pkgsrc/www/py-pendrell: Makefile
   	pkgsrc/www/py-python-digest: Makefile
   	pkgsrc/www/py-pywebdav: Makefile
   	pkgsrc/www/py-recaptcha: Makefile
   	pkgsrc/www/py-scgi: Makefile
   	pkgsrc/www/py-simpletal: Makefile
   	pkgsrc/www/py-swish-e: Makefile
   	pkgsrc/www/py-twill: Makefile
   	pkgsrc/www/py-uliweb: Makefile
   	pkgsrc/www/py-webpy: Makefile
   	pkgsrc/www/py-werkzeug-docs: Makefile
   	pkgsrc/www/ruby-pygments.rb: Makefile
   	pkgsrc/www/trac: Makefile
   	pkgsrc/www/urlgrabber: Makefile
   	pkgsrc/www/viewvc: Makefile
   	pkgsrc/www/webkit-gtk: Makefile
   	pkgsrc/www/webkit24-gtk: Makefile.common
   	pkgsrc/x11/alacarte: Makefile
   	pkgsrc/x11/arandr: Makefile
   	pkgsrc/x11/avant-window-navigator: Makefile
   	pkgsrc/x11/driconf: Makefile
   	pkgsrc/x11/gnome-applets: Makefile
   	pkgsrc/x11/gnome-mag: Makefile
   	pkgsrc/x11/gnome-panel: Makefile
   	pkgsrc/x11/gnome-terminal: Makefile
   	pkgsrc/x11/gtk2: Makefile
   	pkgsrc/x11/kde-workspace4: Makefile
   	pkgsrc/x11/libdesktop-agnostic: Makefile
   	pkgsrc/x11/mozo: Makefile
   	pkgsrc/x11/py-Pmw: Makefile
   	pkgsrc/x11/py-gnome2: Makefile
   	pkgsrc/x11/py-gnome2-desktop: Makefile
   	pkgsrc/x11/py-gnome2-extras: Makefile
   	pkgsrc/x11/py-gtk2: Makefile
   	pkgsrc/x11/py-gtksourceview: Makefile
   	pkgsrc/x11/py-keybinder: Makefile
   	pkgsrc/x11/py-kiwi: Makefile
   	pkgsrc/x11/py-qwt-qt4: Makefile
   	pkgsrc/x11/py-terminator: Makefile
   	pkgsrc/x11/py-vte: Makefile
   	pkgsrc/x11/py-wxWidgets: Makefile
   	pkgsrc/x11/rox-session: Makefile
   	pkgsrc/x11/tint2: Makefile

   Log Message:
   Remove python33: adapt all packages that refer to it.


   To generate a diff of this commit:
   cvs rdiff -u -r1.20 -r1.21 pkgsrc/net/samba4/Makefile

-------------------------------------------------------------------
   Module Name:	pkgsrc
   Committed By:	wiz
   Date:		Mon Jul 11 12:28:17 UTC 2016

   Modified Files:
   	pkgsrc/net/samba4: Makefile PLIST

   Log Message:
   If py-dns or py-iso8601 are installed, the PLIST is wrong because
   the separate copy coming with samba4 is not installed.

   Depend on the two packages and never install the separate copies.

   Bump PKGREVISION.


   To generate a diff of this commit:
   cvs rdiff -u -r1.21 -r1.22 pkgsrc/net/samba4/Makefile
   cvs rdiff -u -r1.8 -r1.9 pkgsrc/net/samba4/PLIST
@
text
@d1 1
a1 1
@@comment $NetBSD$
a433 1
${PYSITELIB}/samba/tests/samba_tool/fsmo.py
d451 83
@


1.6
log
@Update net/samba4 to 4.3.8

This fixes the Badlock bug (CVE-2016-2118) and others vulnerabilities:
o  CVE-2016-2118 (SAMR and LSA man in the middle attacks possible)
o  CVE-2016-2115 (SMB IPC traffic is not integrity protected)
o  CVE-2016-2114 ("server signing = mandatory" not enforced)
o  CVE-2016-2113 (Missing TLS certificate validation)
o  CVE-2016-2112 (LDAP client and server don't enforce integrity)
o  CVE-2016-2111 (NETLOGON Spoofing Vulnerability)
o  CVE-2016-2110 (Man in the middle attacks possible with NTLMSSP)
o  CVE-2015-7560 (Incorrect ACL get/set allowed on symlink path)
o  CVE-2016-0771 (Out-of-bounds read in internal DNS server)
o  CVE-2015-5370 (Multiple errors in DCE-RPC code)
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.5 2016/01/31 20:28:23 ryoon Exp $
d652 1
a652 1
lib/samba/private/libtevent.so.0.9.25
@


1.5
log
@Update to 4.3.4

Changelog:
                   =============================
                   Release Notes for Samba 4.3.4
                         January 12, 2016
                   =============================


This is the latest stable release of Samba 4.3.


Changes since 4.3.3:
--------------------

o  Michael Adam <obnox@@samba.org>
   * BUG 11619: doc: Fix a typo in the smb.conf manpage, explanation of idmap
     config.
   * BUG 11647: s3:smbd: Fix a corner case of the symlink verification.

o  Jeremy Allison <jra@@samba.org>
   * BUG 11624: s3: libsmb: Correctly initialize the list head when keeping a
     list of primary followed by DFS connections.
   * BUG 11625: Reduce the memory footprint of empty string options.

o  Douglas Bagnall <douglas.bagnall@@catalyst.net.nz>
   * BUG 11659: Update lastLogon and lastLogonTimestamp.

o  Ralph Boehme <slow@@samba.org>
   * BUG 11065: vfs_fruit: Enable POSIX directory rename semantics.
   * BUG 11466: Copying files with vfs_fruit fails when using vfs_streams_xattr
     without stream prefix and type suffix.
   * BUG 11645: smbd: Make "hide dot files" option work with "store dos
     attributes = yes".

o  Günther Deschner <gd@@samba.org>
   * BUG 11639: lib/async_req: Do not install async_connect_send_test.

o  Stefan Metzmacher <metze@@samba.org>
   * BUG 11394: Crash: Bad talloc magic value - access after free.

o  Rowland Penny <repenny241155@@gmail.com>
   * BUG 11613: samba-tool: Fix uncaught exception if no fSMORoleOwner
     attribute is given.

o  Karolin Seeger <kseeger@@samba.org>
   * BUG 11619: docs: Fix some typos in the idmap backend section.
   * BUG 11641: docs: Fix typos in man vfs_gpfs.

o  Uri Simchoni <uri@@samba.org>
   * BUG 11649: smbd: Do not disable "store dos attributes" on-the-fly.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.4 2015/12/13 08:48:36 wiz Exp $
d402 1
d414 1
a414 1
${PYSITELIB}/samba/tests/getopt.py
@


1.5.2.1
log
@Pullup ticket #4958 - requested by manu
net/samba4: security fix

Revisions pulled up:
- net/samba4/Makefile                                           1.17
- net/samba4/PLIST                                              1.6
- net/samba4/distinfo                                           1.9

---
   Module Name:    pkgsrc
   Committed By:   manu
   Date:           Wed Apr 13 08:26:10 UTC 2016

   Modified Files:
           pkgsrc/net/samba4: Makefile PLIST distinfo

   Log Message:
   Update net/samba4 to 4.3.8

   This fixes the Badlock bug (CVE-2016-2118) and others vulnerabilities:
   o  CVE-2016-2118 (SAMR and LSA man in the middle attacks possible)
   o  CVE-2016-2115 (SMB IPC traffic is not integrity protected)
   o  CVE-2016-2114 ("server signing = mandatory" not enforced)
   o  CVE-2016-2113 (Missing TLS certificate validation)
   o  CVE-2016-2112 (LDAP client and server don't enforce integrity)
   o  CVE-2016-2111 (NETLOGON Spoofing Vulnerability)
   o  CVE-2016-2110 (Man in the middle attacks possible with NTLMSSP)
   o  CVE-2015-7560 (Incorrect ACL get/set allowed on symlink path)
   o  CVE-2016-0771 (Out-of-bounds read in internal DNS server)
   o  CVE-2015-5370 (Multiple errors in DCE-RPC code)
@
text
@d1 1
a1 1
@@comment $NetBSD$
a401 1
${PYSITELIB}/samba/tests/dcerpc/raw_protocol.py
d413 1
a413 1
${PYSITELIB}/samba/tests/get_opt.py
@


1.5.2.2
log
@Pullup ticket #5011 - requested by taca
net/samba4: security fix

Revisions pulled up:
- net/samba4/Makefile                                           1.18
- net/samba4/PLIST                                              1.7
- net/samba4/distinfo                                           1.10
- net/samba4/patches/patch-lib_nss__wrapper_wscript             deleted

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Sat May  7 03:09:33 UTC 2016

   Modified Files:
   	pkgsrc/net/samba4: Makefile PLIST distinfo
   Removed Files:
   	pkgsrc/net/samba4/patches: patch-lib_nss__wrapper_wscript

   Log Message:
   Update samba4 to 4.3.8, which contains security fix.

   This release fixes some regressions introduced by the last security fixes.
   Please see bug https://bugzilla.samba.org/show_bug.cgi?id=11849 for a list of
   bugs addressing these regressions and more information.

   Changes since 4.3.8:
   --------------------

   o  Jeremy Allison <jra@@samba.org>
     * BUG 11742: lib: tevent: Fix memory leak when old signal action restored.
     * BUG 11771: lib: tevent: Fix memory leak when old signal action restored.
     * BUG 11822: s3: libsmb: Fix error where short name length was read as 2
       bytes, should be 1.

   o  Andrew Bartlett <abartlet@@samba.org>
     * BUG 11780: smbd: Only check dev/inode in open_directory, not the full
       stat().
     * BUG 11789: pydsdb: Fix returning of ldb.MessageElement.

   o  Berend De Schouwer <berend.de.schouwer@@gmail.com>
     * BUG 11643: docs: Add example for domain logins to smbspool man page.

   o  Günther Deschner <gd@@samba.org>
     * BUG 11789: libsmb/pysmb: Add pytalloc-util dependency to fix the build.

   o  Alberto Maria Fiaschi <alberto.fiaschi@@estar.toscana.it>
     * BUG 8093: access based share enum: Handle permission set in configuration
        files.

   o  Volker Lendecke <vl@@samba.org>
     * BUG 11816: nwrap: Fix the build on Solaris.
     * BUG 11827: vfs_catia: Fix memleak.
     * BUG 11878: smbd: Avoid large reads beyond EOF.

   o  Stefan Metzmacher <metze@@samba.org>
     * BUG 11622: libcli/smb: Make sure we have a body size of 0x31 before
       dereferencing an ioctl response.
     * BUG 11623: libcli/smb: Fix BUFFER_OVERFLOW handling in tstream_smbXcli_np.
     * BUG 11755: s3:libads: Setup the msDS-SupportedEncryptionTypes attribute on
       ldap_add.
     * BUG 11771: tevent: Version 0.9.28. Fix memory leak when old signal action
       restored.
     * BUG 11782: s3:winbindd: Don't include two '\0' at the end of the domain
       list.
     * BUG 11789: s3:wscript: pylibsmb depends on pycredentials.
     * BUG 11841: Fix NT_STATUS_ACCESS_DENIED when accessing Windows public share.
     * BUG 11847: Only validate MIC if "map to guest" is not being used.
     * BUG 11849: auth/ntlmssp: Add ntlmssp_{client,server}:force_old_spnego
       option for testing.
     * BUG 11850: NetAPP SMB servers don't negotiate NTLMSSP_SIGN.
     * BUG 11858: Allow anonymous smb connections.
     * BUG 11870: Fix ads_sasl_spnego_gensec_bind(KRB5).
     * BUG 11872: Fix 'wbinfo -u' and 'net ads search'.

   o  Noel Power <noel.power@@suse.com>
     * BUG 11738: libcli: Fix debug message, print sid string for new_ace trustee.

   o  Garming Sam <garming@@catalyst.net.nz>
     * BUG 11789: build: Mark explicit dependencies on pytalloc-util.

   o  Partha Sarathi <partha@@exablox.com>
     * BUG 11819: Fix the smb2_setinfo to handle FS info types and FSQUOTA
       infolevel.

   o  Jorge Schrauwen <sjorge@@blackdot.be>
     * BUG 11816: configure: Don't check for inotify on illumos.

   o  Uri Simchoni <uri@@samba.org>
     * BUG 11691: winbindd: Return trust parameters when listing trusts.
     * BUG 11753: smbd: Ignore SVHDX create context.
     * BUG 11763: passdb: Add linefeed to debug message.
     * BUG 11788: build: Fix disk-free quota support on Solaris 10.
     * BUG 11798: build: Fix build when '--without-quota' specified.
     * BUG 11806: vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls"
       is set.
     * BUG 11852: libads: Record session expiry for spnego sasl binds.

   o  Hemanth Thummala <hemanth.thummala@@nutanix.com>
     * BUG 11740: Real memory leak(buildup) issue in loadparm.
     * BUG 11840: Mask general purpose signals for notifyd.
@
text
@d652 1
a652 1
lib/samba/private/libtevent.so.0.9.28
@


1.4
log
@Update samba4 to 4.3.2.

While here, comment a patch.

Changes since 4.3.1:
--------------------

o   Michael Adam <obnox@@samba.org>
    * BUG 11577: ctdb: Open the RO tracking db with perms 0600 instead of 0000.

o   Jeremy Allison <jra@@samba.org>
    * BUG 11452: s3-smbd: Fix old DOS client doing wildcard delete - gives an
      attribute type of zero.
    * BUG 11565: auth: gensec: Fix a memory leak.
    * BUG 11566: lib: util: Make non-critical message a warning.
    * BUG 11589: s3: smbd: If EAs are turned off on a share don't allow an SMB2
      create containing them.
    * BUG 11615: s3: smbd: have_file_open_below() fails to enumerate open files
      below an open directory handle.

o   Ralph Boehme <slow@@samba.org>
    * BUG 11562: s4:lib/messaging: Use correct path for names.tdb.
    * BUG 11564: async_req: Fix non-blocking connect().

o   Volker Lendecke <vl@@samba.org>
    * BUG 11243: vfs_gpfs: Re-enable share modes.
    * BUG 11570: smbd: Send SMB2 oplock breaks unencrypted.
    * BUG 11612: winbind: Fix crash on invalid idmap configs.

o   YvanM <yvan.masson@@openmailbox.org>
    * BUG 11584: manpage: Correct small typo error.

o   Stefan Metzmacher <metze@@samba.org>
    * BUG 11327: dcerpc.idl: Accept invalid dcerpc_bind_nak pdus.
    * BUG 11581: s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE()
      clearer.

o   Marc Muehlfeld <mmuehlfeld@@samba.org>
    * BUG 9912: Changing log level of two entries to DBG_NOTICE.
    * BUG 11581: s3-smbd: Fix use after issue in smbd_smb2_request_dispatch().

o   Noel Power <noel.power@@suse.com>
    * BUG 11569: Fix winbindd crashes with samlogon for trusted domain user.
    * BUG 11597: Backport some valgrind fixes from upstream master.

o   Andreas Schneider <asn@@samba.org
    * BUG 11563: Fix segfault of 'net ads (join|leave) -S INVALID' with
      nss_wins.

o   Tom Schulz <schulz@@adi.com>
    * BUG 11511: Add libreplace dependency to texpect, fixes a linking error on
      Solaris.
    * BUG 11512: s4: Fix linking of 'smbtorture' on Solaris.

o   Uri Simchoni <uri@@samba.org>
    * BUG 11608: auth: Consistent handling of well-known alias as primary gid.

Changes since 4.3.0:
--------------------

o   Jeremy Allison <jra@@samba.org>
    * BUG 10252: s3: smbd: Fix our access-based enumeration on "hide unreadable"
      to match Windows.
    * BUG 10634: smbd: Fix file name buflen and padding in notify repsonse.
    * BUG 11486: s3: smbd: Fix mkdir race condition.
    * BUG 11522: s3: smbd: Fix opening/creating :stream files on the root share
      directory.
    * BUG 11535: s3: smbd: Fix NULL pointer bug introduced by previous 'raw'
    * stream fix (bug #11522).
    * BUG 11555: s3: lsa: lookup_name() logic for unqualified (no DOMAIN\
      component) names is incorrect.

o   Ralph Boehme <slow@@samba.org>
    * BUG 11535: s3: smbd: Fix a crash in unix_convert().
    * BUG 11543: vfs_fruit: Return value of ad_pack in vfs_fruit.c.
    * BUG 11549: s3:locking: Initialize lease pointer in
      share_mode_traverse_fn().
    * BUG 11550: s3:smbstatus: Add stream name to share_entry_forall().
    * BUG 11555: s3:lib: Validate domain name in lookup_wellknown_name().

o   Günther Deschner <gd@@samba.org>
    * BUG 11038: kerberos: Make sure we only use prompter type when available.

o   Volker Lendecke <vl@@samba.org>
    * BUG 11038: winbind: Fix 100% loop.
    * BUG 11053: source3/lib/msghdr.c: Fix compiling error on Solaris.

o   Stefan Metzmacher <metze@@samba.org>
    * BUG 11316: s3:ctdbd_conn: make sure we destroy tevent_fd before closing
      the socket.
    * BUG 11515: s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging
      related subdirs.
    * BUG 11526: lib/param: Fix hiding of FLAG_SYNONYM values.

o   Björn Jacke <bj@@sernet.de>
    * BUG 10365: nss_winbind: Fix hang on Solaris on big groups.
    * BUG 11355: build: Use as-needed linker flag also on OpenBSD.

o   Har Gagan Sahai <SHarGagan@@novell.com>
    * BUG 11509: s3: dfs: Fix a crash when the dfs targets are disabled.

o   Andreas Schneider <asn@@samba.org>
    * BUG 11502: pam_winbind: Fix a segfault if initialization fails.

o   Uri Simchoni <uri@@samba.org>
    * BUG 11528: net: Fix a crash with 'net ads keytab create'.
    * BUG 11547: vfs_commit: set the fd on open before calling SMB_VFS_FSTAT.
@
text
@d1 1
a1 2
@@comment $NetBSD: PLIST,v 1.3 2015/09/28 17:37:04 ryoon Exp $
bin/async_connect_send_test
@


1.3
log
@Update to 4.3.0

Changelog:
                   =============================
                   Release Notes for Samba 4.3.0
                           September 8, 2015
                   =============================


This is the first stable release of Samba 4.3.


UPGRADING
=========

Read the "New FileChangeNotify subsystem" and "smb.conf changes" sections
(below).


NEW FEATURES
============

Logging
-------

The logging code now supports logging to multiple backends.  In
addition to the previously available syslog and file backends, the
backends for logging to the systemd-journal, lttng and gpfs have been
added. Please consult the section for the 'logging' parameter in the
smb.conf manpage for details.

Spotlight
---------

Support for Apple's Spotlight has been added by integrating with Gnome
Tracker.

For detailed instructions how to build and setup Samba for Spotlight,
please see the Samba wiki: <https://wiki.samba.org/index.php/Spotlight>

New FileChangeNotify subsystem
------------------------------

Samba now contains a new subsystem to do FileChangeNotify. The
previous system used a central database, notify_index.tdb, to store
all notification requests. In particular in a cluster this turned out
to be a major bottleneck, because some hot records need to be bounced
back and forth between nodes on every change event like a new created
file.

The new FileChangeNotify subsystem works with a central daemon per
node. Every FileChangeNotify request and every event are handled by an
asynchronous message from smbd to the notify daemon. The notify daemon
maintains a database of all FileChangeNotify requests in memory and
will distribute the notify events accordingly. This database is
asynchronously distributed in the cluster by the notify daemons.

The notify daemon is supposed to scale a lot better than the previous
implementation. The functional advantage is cross-node kernel change
notify: Files created via NFS will be seen by SMB clients on other
nodes per FileChangeNotify, despite the fact that popular cluster file
systems do not offer cross-node inotify.

Two changes to the configuration were required for this new subsystem:
The parameters "change notify" and "kernel change notify" are not
per-share anymore but must be set globally. So it is no longer
possible to enable or disable notify per share, the notify daemon has
no notion of a share, it only works on absolute paths.

New SMB profiling code
----------------------

The code for SMB (SMB1, SMB2 and SMB3) profiling uses a tdb instead
of sysv IPC shared memory. This avoids performance problems and NUMA
effects. The profile stats are a bit more detailed than before.

Improved DCERPC man in the middle detection for kerberos
--------------------------------------------------------

The gssapi based kerberos backends for gensec have support for
DCERPC header signing when using DCERPC_AUTH_LEVEL_PRIVACY.

SMB signing required in winbindd by default
-------------------------------------------

The effective value for "client signing" is required
by default for winbindd, if the primary domain uses active directory.

Experimental NTDB was removed
-----------------------------

The experimental NTDB library introduced in Samba 4.0 has been
removed again.

Improved support for trusted domains (as AD DC)
-----------------------------------------------

The support for trusted domains/forests has improved a lot.

samba-tool got "domain trust" subcommands to manage trusts:

  create      - Create a domain or forest trust.
  delete      - Delete a domain trust.
  list        - List domain trusts.
  namespaces  - Manage forest trust namespaces.
  show        - Show trusted domain details.
  validate    - Validate a domain trust.

External trusts between individual domains work in both ways
(inbound and outbound). The same applies to root domains of
a forest trust. The transitive routing into the other forest
is fully functional for kerberos, but not yet supported for NTLMSSP.

While a lot of things are working fine, there are currently a few limitations:

  - Both sides of the trust need to fully trust each other!
  - No SID filtering rules are applied at all!
  - This means DCs of domain A can grant domain admin rights
    in domain B.
  - It's not possible to add users/groups of a trusted domain
    into domain groups.

SMB 3.1.1 supported
-------------------

Both client and server have support for SMB 3.1.1 now.

This is the dialect introduced with Windows 10, it improves the secure
negotiation of SMB dialects and features.

There's also a new optinal encryption algorithm aes-gcm-128,
but for now this is only selected as fallback and aes-ccm-128
is preferred because of the better performance. This might change
in future versions when hardware encryption will be supported.
See https://bugzilla.samba.org/show_bug.cgi?id=11451.

New smbclient subcommands
-------------------------

  - Query a directory for change notifications: notify <dir name>
  - Server side copy: scopy <source filename> <destination filename>

New rpcclient subcommands
-------------------------

  netshareenumall 	- Enumerate all shares
  netsharegetinfo 	- Get Share Info
  netsharesetinfo 	- Set Share Info
  netsharesetdfsflags	- Set DFS flags
  netfileenum		- Enumerate open files
  netnamevalidate	- Validate sharename
  netfilegetsec		- Get File security
  netsessdel		- Delete Session
  netsessenum		- Enumerate Sessions
  netdiskenum		- Enumerate Disks
  netconnenum		- Enumerate Connections
  netshareadd		- Add share
  netsharedel		- Delete share

New modules
-----------

  idmap_script 		- see 'man 8 idmap_script'
  vfs_unityed_media	- see 'man 8 vfs_unityed_media'
  vfs_shell_snap	- see 'man 8 vfs_shell_snap'

New sparsely connected replia graph (Improved KCC)
--------------------------------------------------

The Knowledge Consistency Checker (KCC) maintains a replication graph
for DCs across an AD network. The existing Samba KCC uses a fully
connected graph, so that each DC replicates from all the others, which
does not scale well with large networks. In 4.3 there is an
experimental new KCC that creates a sparsely connected replication
graph and closely follows Microsoft's specification. It is turned off
by default. To use the new KCC, set "kccsrv:samba_kcc=true" in
smb.conf and let us know how it goes. You should consider doing this
if you are making a large new network. For small networks there is
little benefit and you can always switch over at a later date.

Configurable TLS protocol support, with better defaults
-------------------------------------------------------

The "tls priority" option can be used to change the supported TLS
protocols. The default is to disable SSLv3, which is no longer
considered secure.

Samba-tool now supports all 7 FSMO roles
-------------------------------------------------------

Previously "samba-tool fsmo" could only show, transfer or seize the
five well-known FSMO roles:

	Schema Master
	Domain Naming Master
	RID Master
	PDC Emulator
	Infrastructure Master

It can now also show, transfer or seize the DNS infrastructure roles:

	DomainDnsZones Infrastructure Master
	ForestDnsZones Infrastructure Master

CTDB logging changes
--------------------

The destination for CTDB logging is now set via a single new
configuration variable CTDB_LOGGING.  This replaces CTDB_LOGFILE and
CTDB_SYSLOG, which have both been removed.  See ctdbd.conf(5) for
details of CTDB_LOGGING.

CTDB no longer runs a separate logging daemon.

CTDB NFS support changes
------------------------

CTDB's NFS service management has been combined into a single 60.nfs
event script.  This updated 60.nfs script now uses a call-out to
interact with different NFS implementations.  See the CTDB_NFS_CALLOUT
option in the ctdbd.conf(5) manual page for details.  A default
call-out is provided to interact with the Linux kernel NFS
implementation.  The 60.ganesha event script has been removed - a
sample call-out is provided for NFS Ganesha, based on this script.

The method of configuring NFS RPC checks has been improved.  See
ctdb/config/nfs-checks.d/README for details.

Improved Cross-Compiling Support
--------------------------------

A new "hybrid" build configuration mode is added to improve
cross-compilation support.

A common challenge in cross-compilation is that of obtaining the results
of tests that have to run on the target, during the configuration
phase of the build. The Samba build system already supports the following
means to do so:

  - Executing configure tests using the --cross-execute parameter
  - Obtaining the results from an answers file using the --cross-answers
    parameter

The first method has the drawback of inaccurate results if the tests are
run using an emulator, or a need to be connected to a running target
while building, if the tests are to be run on an actual target. The
second method presents a challenge of figuring out the test results.

The new hybrid mode runs the tests and records the result in an answer file.
To activate this mode, use both --cross-execute and --cross-answers in the
same configure invocation. This mode can be activated once against a
running target, and then the generated answers file can be used in
subsequent builds.

Also supplied is an example script that can be used as the
cross-execute program. This script copies the test to a running target
and runs the test on the target, obtaining the result. The obtained
results are more accurate than running the test with an emulator, because
they reflect the exact kernel and system libraries that exist on the
target.

Improved Sparse File Support
----------------------------
Support for the FSCTL_SET_ZERO_DATA and FSCTL_QUERY_ALLOCATED_RANGES
SMB2 requests has been added to the smbd file server.
This allows for clients to deallocate (hole punch) regions within a
sparse file, and check which portions of a file are allocated.


######################################################################
Changes
#######

smb.conf changes
----------------

  Parameter Name		Description		Default
  --------------		-----------		-------
  logging			New			(empty)
  msdfs shuffle referrals	New			no
  smbd profiling level		New			off
  spotlight			New			no
  tls priority			New 			NORMAL:-VERS-SSL3.0
  use ntdb			Removed
  change notify			Changed to [global]
  kernel change notify		Changed to [global]
  client max protocol		Changed	default		SMB3_11
  server max protocol		Changed default		SMB3_11

Removed modules
---------------

vfs_notify_fam - see section 'New FileChangeNotify subsystem'.


KNOWN ISSUES
============

Currently none.


CHANGES SINCE 4.2.0rc4
======================

o   Andrew Bartlett <abartlet@@samba.org>
    * Bug 10973: No objectClass found in replPropertyMetaData on ordinary
      objects (non-deleted)
    * Bug 11429: Python bindings don't check integer types
    * Bug 11430: Python bindings don't check array sizes

o   Ralph Boehme <slow@@samba.org>
    * Bug 11467: Handling of 0 byte resource fork stream

o   Volker Lendecke <vl@@samba.org>
    * Bug 11488: AD samr GetGroupsForUser fails for users with "()" in
      their name

o   Stefan Metzmacher <metze@@samba.org>
    * Bug 11429: Python bindings don't check integer types

o   Matthieu Patou <mat@@matws.net>
    * Bug 10973: No objectClass found in replPropertyMetaData on ordinary
      objects (non-deleted)


CHANGES SINCE 4.2.0rc3
======================

o   Ralph Boehme <slow@@samba.org>
    * Bug 11444: Crash in notify_remove caused by change notify = no

o   Günther Deschner <gd@@samba.org>
    * Bug 11411: smbtorture does not build when configured --with-system-mitkrb5

o   Volker Lendecke <vl@@samba.org>
    * Bug 11455: fix recursion problem in rep_strtoll in lib/replace/replace.c
    * Bug 11464: xid2sid gives inconsistent results
    * Bug 11465: ctdb: Fix the build on FreeBSD 10.1

o   Roel van Meer <roel@@1afa.com>
    * Bug 11427: nmbd incorrectly matches netbios names as own name

o   Stefan Metzmacher <metze@@samba.org>
    * Bug 11451: Poor SMB3 encryption performance with AES-GCM
    * Bug 11458: --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't
      disable ldb build and install

o   Andreas Schneider <asn@@samba.org>
    * Bug 9862: Samba "map to guest = Bad uid" doesn't work


CHANGES SINCE 4.3.0rc2
======================

o   Andrew Bartlett <abartlet@@samba.org>
    * Bug 11436: samba-tool uncaught exception error
    * Bug 10493: revert LDAP extended rule 1.2.840.113556.1.4.1941
                 LDAP_MATCHING_RULE_IN_CHAIN changes

o   Ralph Boehme <slow@@samba.org>
    * Bug 11278: Stream names with colon don't work with
                 fruit:encoding = native
    * Bug 11426: net share allowedusers crashes

o   Amitay Isaacs <amitay@@gmail.com>
    * Bug 11432: Fix crash in nested ctdb banning
    * Bug 11434: Cannot build ctdbpmda
    * Bug 11431: CTDB's eventscript error handling is broken

o   Stefan Metzmacher <metze@@samba.org>
    * Bug 11451: Poor SMB3 encryption performance with AES-GCM (part1)
    * Bug 11316: tevent_fd needs to be destroyed before closing the fd

o   Arvid Requate <requate@@univention.de>
    * Bug 11291: NetApp joined to a Samba/ADDC cannot resolve SIDs

o   Martin Schwenke <martin@@meltin.net>
    * Bug 11432: Fix crash in nested ctdb banning


CHANGES SINCE 4.3.0rc1
======================

o   Jeremy Allison <jra@@samba.org>
    * BUG 11359: strsep is not available on Solaris

o   Björn Baumbach <bb@@sernet.de>
    * BUG 11421: Build with GPFS support is broken

o   Justin Maggard <jmaggard@@netgear.com>
    * BUG 11320: "force group" with local group not working

o   Martin Schwenke <martin@@meltin.net
    * BUG 11424: Build broken with --disable-python


#######################################
Reporting bugs & Development Discussion
#######################################

Please discuss this release on the samba-technical mailing list or by
joining the #samba-technical IRC channel on irc.freenode.net.

If you do report problems then please try to send high quality
feedback. If you don't provide vital information to help us track down
the problem then you will probably be ignored.  All bug reports should
be filed under the "Samba 4.1 and newer" product in the project's Bugzilla
database (https://bugzilla.samba.org/).


======================================================================
== Our Code, Our Bugs, Our Responsibility.
== The Samba Team
======================================================================
@
text
@d1 2
a2 1
@@comment $NetBSD$
@


1.2
log
@Attempt to fix various build issues:

 - Explicitly disable samba-regedit for now, it is built depending on
   various curses characteristics that we do not currently support.

 - Avoid epoll implementation on SmartOS.

 - Pull in Active Directory and LDAP options from net/samba, LDAP support
   is dynamically configured and we need to ensure that, if enabled, we
   correctly pull in openldap.  The SunOS native LDAP is missing some TLS
   functions that Samba depends upon.

Tested with various PKG_OPTIONS combinations, fixes build on SmartOS.
@
text
@d1 1
a1 1
@@comment $NetBSD: PLIST,v 1.1 2015/05/12 12:19:52 ryoon Exp $
a16 4
bin/ntdbbackup
bin/ntdbdump
bin/ntdbrestore
bin/ntdbtool
d150 1
d192 1
a192 1
lib/libndr.so.0.0.3
d222 1
a222 1
lib/libsmbclient.so.0.2.1
d281 1
a283 1
${PYSITELIB}/ntdb.so
a327 163
${PYSITELIB}/samba/external/__init__.py
${PYSITELIB}/samba/external/dns/__init__.py
${PYSITELIB}/samba/external/dns/dnssec.py
${PYSITELIB}/samba/external/dns/e164.py
${PYSITELIB}/samba/external/dns/edns.py
${PYSITELIB}/samba/external/dns/entropy.py
${PYSITELIB}/samba/external/dns/exception.py
${PYSITELIB}/samba/external/dns/flags.py
${PYSITELIB}/samba/external/dns/hash.py
${PYSITELIB}/samba/external/dns/inet.py
${PYSITELIB}/samba/external/dns/ipv4.py
${PYSITELIB}/samba/external/dns/ipv6.py
${PYSITELIB}/samba/external/dns/message.py
${PYSITELIB}/samba/external/dns/name.py
${PYSITELIB}/samba/external/dns/namedict.py
${PYSITELIB}/samba/external/dns/node.py
${PYSITELIB}/samba/external/dns/opcode.py
${PYSITELIB}/samba/external/dns/query.py
${PYSITELIB}/samba/external/dns/rcode.py
${PYSITELIB}/samba/external/dns/rdata.py
${PYSITELIB}/samba/external/dns/rdataclass.py
${PYSITELIB}/samba/external/dns/rdataset.py
${PYSITELIB}/samba/external/dns/rdatatype.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/AFSDB.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/CERT.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/CNAME.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/DLV.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/DNAME.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/DNSKEY.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/DS.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/GPOS.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/HINFO.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/HIP.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/ISDN.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/LOC.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/MX.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/NS.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/NSEC.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/NSEC3.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/NSEC3PARAM.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/PTR.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/RP.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/RRSIG.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/RT.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/SOA.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/SPF.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/SSHFP.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/TXT.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/X25.py
${PYSITELIB}/samba/external/dns/rdtypes/ANY/__init__.py
${PYSITELIB}/samba/external/dns/rdtypes/IN/A.py
${PYSITELIB}/samba/external/dns/rdtypes/IN/AAAA.py
${PYSITELIB}/samba/external/dns/rdtypes/IN/APL.py
${PYSITELIB}/samba/external/dns/rdtypes/IN/DHCID.py
${PYSITELIB}/samba/external/dns/rdtypes/IN/IPSECKEY.py
${PYSITELIB}/samba/external/dns/rdtypes/IN/KX.py
${PYSITELIB}/samba/external/dns/rdtypes/IN/NAPTR.py
${PYSITELIB}/samba/external/dns/rdtypes/IN/NSAP.py
${PYSITELIB}/samba/external/dns/rdtypes/IN/NSAP_PTR.py
${PYSITELIB}/samba/external/dns/rdtypes/IN/PX.py
${PYSITELIB}/samba/external/dns/rdtypes/IN/SRV.py
${PYSITELIB}/samba/external/dns/rdtypes/IN/WKS.py
${PYSITELIB}/samba/external/dns/rdtypes/IN/__init__.py
${PYSITELIB}/samba/external/dns/rdtypes/__init__.py
${PYSITELIB}/samba/external/dns/rdtypes/dsbase.py
${PYSITELIB}/samba/external/dns/rdtypes/mxbase.py
${PYSITELIB}/samba/external/dns/rdtypes/nsbase.py
${PYSITELIB}/samba/external/dns/rdtypes/txtbase.py
${PYSITELIB}/samba/external/dns/renderer.py
${PYSITELIB}/samba/external/dns/resolver.py
${PYSITELIB}/samba/external/dns/reversename.py
${PYSITELIB}/samba/external/dns/rrset.py
${PYSITELIB}/samba/external/dns/set.py
${PYSITELIB}/samba/external/dns/tokenizer.py
${PYSITELIB}/samba/external/dns/tsig.py
${PYSITELIB}/samba/external/dns/tsigkeyring.py
${PYSITELIB}/samba/external/dns/ttl.py
${PYSITELIB}/samba/external/dns/update.py
${PYSITELIB}/samba/external/dns/version.py
${PYSITELIB}/samba/external/dns/wiredata.py
${PYSITELIB}/samba/external/dns/zone.py
${PYSITELIB}/samba/external/extras/__init__.py
${PYSITELIB}/samba/external/extras/tests/__init__.py
${PYSITELIB}/samba/external/extras/tests/test_extras.py
${PYSITELIB}/samba/external/subunit/__init__.py
${PYSITELIB}/samba/external/subunit/chunked.py
${PYSITELIB}/samba/external/subunit/details.py
${PYSITELIB}/samba/external/subunit/filters.py
${PYSITELIB}/samba/external/subunit/iso8601.py
${PYSITELIB}/samba/external/subunit/progress_model.py
${PYSITELIB}/samba/external/subunit/run.py
${PYSITELIB}/samba/external/subunit/test_results.py
${PYSITELIB}/samba/external/subunit/tests/TestUtil.py
${PYSITELIB}/samba/external/subunit/tests/__init__.py
${PYSITELIB}/samba/external/subunit/tests/sample-script.py
${PYSITELIB}/samba/external/subunit/tests/sample-two-script.py
${PYSITELIB}/samba/external/subunit/tests/test_chunked.py
${PYSITELIB}/samba/external/subunit/tests/test_details.py
${PYSITELIB}/samba/external/subunit/tests/test_progress_model.py
${PYSITELIB}/samba/external/subunit/tests/test_run.py
${PYSITELIB}/samba/external/subunit/tests/test_subunit_filter.py
${PYSITELIB}/samba/external/subunit/tests/test_subunit_stats.py
${PYSITELIB}/samba/external/subunit/tests/test_subunit_tags.py
${PYSITELIB}/samba/external/subunit/tests/test_tap2subunit.py
${PYSITELIB}/samba/external/subunit/tests/test_test_protocol.py
${PYSITELIB}/samba/external/subunit/tests/test_test_results.py
${PYSITELIB}/samba/external/testtools/__init__.py
${PYSITELIB}/samba/external/testtools/_compat2x.py
${PYSITELIB}/samba/external/testtools/_compat3x.py
${PYSITELIB}/samba/external/testtools/_spinner.py
${PYSITELIB}/samba/external/testtools/compat.py
${PYSITELIB}/samba/external/testtools/content.py
${PYSITELIB}/samba/external/testtools/content_type.py
${PYSITELIB}/samba/external/testtools/deferredruntest.py
${PYSITELIB}/samba/external/testtools/distutilscmd.py
${PYSITELIB}/samba/external/testtools/helpers.py
${PYSITELIB}/samba/external/testtools/matchers/__init__.py
${PYSITELIB}/samba/external/testtools/matchers/_basic.py
${PYSITELIB}/samba/external/testtools/matchers/_datastructures.py
${PYSITELIB}/samba/external/testtools/matchers/_dict.py
${PYSITELIB}/samba/external/testtools/matchers/_doctest.py
${PYSITELIB}/samba/external/testtools/matchers/_exception.py
${PYSITELIB}/samba/external/testtools/matchers/_filesystem.py
${PYSITELIB}/samba/external/testtools/matchers/_higherorder.py
${PYSITELIB}/samba/external/testtools/matchers/_impl.py
${PYSITELIB}/samba/external/testtools/monkey.py
${PYSITELIB}/samba/external/testtools/run.py
${PYSITELIB}/samba/external/testtools/runtest.py
${PYSITELIB}/samba/external/testtools/tags.py
${PYSITELIB}/samba/external/testtools/testcase.py
${PYSITELIB}/samba/external/testtools/testresult/__init__.py
${PYSITELIB}/samba/external/testtools/testresult/doubles.py
${PYSITELIB}/samba/external/testtools/testresult/real.py
${PYSITELIB}/samba/external/testtools/tests/__init__.py
${PYSITELIB}/samba/external/testtools/tests/helpers.py
${PYSITELIB}/samba/external/testtools/tests/matchers/__init__.py
${PYSITELIB}/samba/external/testtools/tests/matchers/helpers.py
${PYSITELIB}/samba/external/testtools/tests/matchers/test_basic.py
${PYSITELIB}/samba/external/testtools/tests/matchers/test_datastructures.py
${PYSITELIB}/samba/external/testtools/tests/matchers/test_dict.py
${PYSITELIB}/samba/external/testtools/tests/matchers/test_doctest.py
${PYSITELIB}/samba/external/testtools/tests/matchers/test_exception.py
${PYSITELIB}/samba/external/testtools/tests/matchers/test_filesystem.py
${PYSITELIB}/samba/external/testtools/tests/matchers/test_higherorder.py
${PYSITELIB}/samba/external/testtools/tests/matchers/test_impl.py
${PYSITELIB}/samba/external/testtools/tests/test_compat.py
${PYSITELIB}/samba/external/testtools/tests/test_content.py
${PYSITELIB}/samba/external/testtools/tests/test_content_type.py
${PYSITELIB}/samba/external/testtools/tests/test_deferredruntest.py
${PYSITELIB}/samba/external/testtools/tests/test_distutilscmd.py
${PYSITELIB}/samba/external/testtools/tests/test_fixturesupport.py
${PYSITELIB}/samba/external/testtools/tests/test_helpers.py
${PYSITELIB}/samba/external/testtools/tests/test_monkey.py
${PYSITELIB}/samba/external/testtools/tests/test_run.py
${PYSITELIB}/samba/external/testtools/tests/test_runtest.py
${PYSITELIB}/samba/external/testtools/tests/test_spinner.py
${PYSITELIB}/samba/external/testtools/tests/test_tags.py
${PYSITELIB}/samba/external/testtools/tests/test_testcase.py
${PYSITELIB}/samba/external/testtools/tests/test_testresult.py
${PYSITELIB}/samba/external/testtools/tests/test_testsuite.py
${PYSITELIB}/samba/external/testtools/tests/test_with_with.py
${PYSITELIB}/samba/external/testtools/testsuite.py
${PYSITELIB}/samba/external/testtools/utils.py
d333 6
a338 1
${PYSITELIB}/samba/kcc_utils.py
d386 2
d400 1
d415 5
d449 84
d546 1
a572 1
lib/samba/private/libccan-samba4.so
a584 2
lib/samba/private/libdfs-server-ad-samba4.so
lib/samba/private/libdnsserver-common-samba4.so
d589 1
d595 1
d599 1
a599 1
lib/samba/private/libldb.so.1.1.20
d604 3
a614 2
lib/samba/private/libntdb.so.1
lib/samba/private/libntdb.so.1.0
d618 1
a618 1
lib/samba/private/libpyldb-util.so.1.1.20
d620 1
a620 1
lib/samba/private/libpytalloc-util.so.2.1.2
d632 1
d643 2
a644 1
lib/samba/private/libsubunit-samba4.so
d646 1
a646 2
lib/samba/private/libtalloc.so.2.1.2
lib/samba/private/libtdb-compat-samba4.so
d649 1
a649 1
lib/samba/private/libtdb.so.1.3.4
d651 2
a652 1
lib/samba/private/libtevent.so.0.9.24
a654 1
lib/samba/private/libutil-ntdb-samba4.so
d689 1
d694 1
a727 4
share/samba/codepages/lowcase.dat
share/samba/codepages/upcase.dat
share/samba/codepages/valid.dat
@@pkgdir etc/samba
@


1.1
log
@Import samba-4.2.1 as net/samba4.

Samba is the standard Windows interoperability suite of programs
for Linux and Unix.

Samba is Free Software licensed under the GNU General Public License,
the Samba project is a member of the Software Freedom Conservancy.

Since 1992, Samba has provided secure, stable and fast file and
print services for all clients using the SMB/CIFS protocol, such
as all versions of DOS and Windows, OS/2, Linux and many others.

Samba is an important component to seamlessly integrate Linux/Unix
Servers and Desktops into Active Directory environments. It can
function both as a domain controller or as a regular domain member.

This package tracks 4.x branch release.
@
text
@d1 1
a1 1
@@comment $NetBSD$
d131 1
a131 1
include/smb_ldap.h
d142 1
a142 1
include/smbldap.h
d228 2
a229 2
lib/libsmbldap.so
lib/libsmbldap.so.0
d610 1
a610 1
lib/samba/idmap/ad.so
d613 1
a613 1
lib/samba/idmap/rfc2307.so
d627 3
a629 3
lib/samba/nss_info/rfc2307.so
lib/samba/nss_info/sfu.so
lib/samba/nss_info/sfu20.so
d706 1
a706 1
lib/samba/private/libsmbldaphelper-samba4.so
@

