Change logs for gvfs source package in Buster

  • gvfs (1.38.1-5) unstable; urgency=high
    
      * Team upload
      * d/p/gvfsdaemon-Check-that-the-connecting-client-is-the-same-u.patch:
        Add missing authentication, preventing a local attacker from connecting
        to an abstract socket address learned from netstat(8) and issuing
        arbitrary D-Bus method calls
      * d/p/gvfsdaemon-Only-accept-EXTERNAL-authentication.patch:
        Harden private D-Bus connection by rejecting the more complicated
        DBUS_COOKIE_SHA1 authentication mechanism and only accepting EXTERNAL.
    
     -- Simon McVittie <email address hidden>  Tue, 11 Jun 2019 12:28:34 +0100
  • gvfs (1.38.1-4) unstable; urgency=high
    
      * Team upload
      * Update from upstream gnome-3-30 branch to fix the admin backend
        (Closes: #929755)
        - Implement query_info_on_read/write to fix some race conditions
          (CVE-2019-12448)
        - Ensure that created files get the correct ownership (CVE-2019-12247)
        - Ensure that copied files get the correct ownership (CVE-2019-12449)
      * Remove obsolete version number from fuse dependency.
        gvfs needs fuse (>= 2.8.4), but that version is older than oldstable,
        so we can safely simplify to "Depends: fuse".
        The versioned dependency is not satisfied by fuse3's unversioned
        "Provides: fuse", but the unversioned dependency is. (Closes: #927221)
    
     -- Simon McVittie <email address hidden>  Wed, 05 Jun 2019 08:34:17 +0100
  • gvfs (1.38.1-3) unstable; urgency=high
    
      * Team upload
      * d/p/admin-Prevent-access-if-any-authentication-agent-isn-t-av.patch:
        Add patch from upstream to prevent members of the sudo group from
        bypassing the intended password check for privileged access to files
        via the admin: backend if no polkit authentication agents are
        available (CVE-2019-3827, Closes: #921816)
      * d/p/*: Update to upstream gnome-3-30 branch, commit 1.38.1-9-gd4dab113
        - admin: Fix CVE-2019-3827 (see above)
        - autorun: Don't crash if an autorun file is not valid UTF-8
        - mtp: Don't busy-loop retrying reading an event after failure
        - udisks2: Reinstate support for deprecated comment=x-gvfs-show fstab
          option syntax (but please use x-gvfs-show instead)
        - tests: Use the right SMB port if running in the sandbox
        - Update translations: eu, sk, sr
      * d/gbp.conf: Configure for debian/buster and upstream/1.38.x branches
      * d/control: Use debian/buster branch in Vcs-Git
    
     -- Simon McVittie <email address hidden>  Sat, 09 Feb 2019 12:02:33 +0000
  • gvfs (1.38.1-2) unstable; urgency=medium
    
      * Add -Wl,-O1 to our LDFLAGS
      * debian/rules: Use dh_auto_build instead of make
      * Bump Standards-Version to 4.3.0
    
     -- Jeremy Bicha <email address hidden>  Thu, 27 Dec 2018 10:06:21 -0500
  • gvfs (1.38.1-1) unstable; urgency=medium
    
      * New upstream release
    
     -- Sebastien Bacher <email address hidden>  Tue, 13 Nov 2018 17:08:16 +0100
  • gvfs (1.38.0-2) unstable; urgency=medium
    
      * Install manpages into gvfs-common, as they were previously
    
     -- Iain Lane <email address hidden>  Tue, 11 Sep 2018 12:42:51 +0100
  • gvfs (1.36.2-1) unstable; urgency=medium
    
      * Team upload
    
      [ Rob McQueen ]
      * Add missing lsof dependency to fix UDisks2VolumeMonitor (!1)
    
      [ Simon McVittie ]
      * New upstream release
      * d/control.in: Remove trailing spaces
      * Refresh patch series
      * d/tests/control: Depend on dbus, not dbus-x11 (Closes: #835892)
      * tests: Depend on openssh-client, for ssh-keygen
      * tests: Depend on policykit-1, for pkcheck
      * tests: Depend on python3-dbus, for `import dbus`
      * Standards-Version: 4.1.5 (no changes required)
      * Set Rules-Requires-Root to no
      * Override Lintian warning for configure.ac. Now that this package
        builds with meson, Autotools bugs are harmless.
    
     -- Simon McVittie <email address hidden>  Thu, 26 Jul 2018 20:50:24 +0100
  • gvfs (1.36.1-1) unstable; urgency=medium
    
      * New upstream release
      * Drop obsolete dh_translations override
      * Bump Standards-Version to 4.1.4
    
     -- Jeremy Bicha <email address hidden>  Sat, 14 Apr 2018 15:51:37 -0400
  • gvfs (1.36.0-1) unstable; urgency=medium
    
      [ Iain Lane ]
      * New upstream translation release
      * debian/patches/0009-gvfs-test-Increase-timeout-to-10s.patch: Backport
        patch from upstream #794487 to increase test timeouts, hopefully to reduce
        flakiness.
    
      [ Sebastien Bacher ]
      * debian/patches/0008-Skip-the-umockdev-test.patch:
        - the umockdev ioctl emulation is currently buggy, skip the gphoto
          integration test that would need record update
    
     -- Iain Lane <email address hidden>  Mon, 19 Mar 2018 16:10:38 +0000
  • gvfs (1.34.1-2) unstable; urgency=medium
    
      * Update Vcs fields for conversion to git
      * Add debian/gbp.conf
      * Bump Standards-Version to 4.1.2
      * Bump debhelper compat to 11
    
     -- Jeremy Bicha <email address hidden>  Sun, 17 Dec 2017 19:09:49 -0500
  • gvfs (1.34.1-1) unstable; urgency=medium
    
      * New upstream release
      * Drop programs-Fix-bashism-in-gvfs-wrapper-script.patch:
        Applied in new release
      * Bump Standards-Version to 4.1.1
    
     -- Jeremy Bicha <email address hidden>  Mon, 02 Oct 2017 21:21:13 -0400
  • gvfs (1.34.0-3) unstable; urgency=medium
    
      * Fix bashism in gvfs-* wrapper script. (Closes: #877068)
    
     -- Michael Biebl <email address hidden>  Thu, 28 Sep 2017 14:24:21 +0200
  • gvfs (1.30.4-1) unstable; urgency=medium
    
      * New upstream release.
    
     -- Michael Biebl <email address hidden>  Wed, 29 Mar 2017 01:32:39 +0200