[Announce] Samba 4.4.0rc2 Available for Download
Karolin Seeger <[email protected]> Tue, 9 Feb 2016 11:15:41 +0100
| Newsgroups | gmane.network.samba.announce |
|---|---|
| Message-ID | <20160209101539.GA13164__6462.12979122556$1455013620$gmane$org@carrie> |
--qDbXVdCdHGoSgWSk
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
Release Announcements
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
This is the second release candidate of Samba 4.4. This is *not*
intended for production environments and is designed for testing
purposes only. Please report any defects via the Samba bug reporting
system at https://bugzilla.samba.org/.
Samba 4.4 will be the next version of the Samba suite.
UPGRADING
=3D=3D=3D=3D=3D=3D=3D=3D=3D
Nothing special.
NEW FEATURES/CHANGES
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Asynchronous flush requests
---------------------------
Flush requests from SMB2/3 clients are handled asynchronously and do
not block the processing of other requests. Note that 'strict sync'
has to be set to 'yes' for Samba to honor flush requests from SMB
clients.
s3: smbd
--------
Remove '--with-aio-support' configure option. We no longer would ever prefer
POSIX-RT aio, use pthread_aio instead.
samba-tool sites
----------------
The 'samba-tool sites' subcommand can now be run against another server by
specifying an LDB URL using the '-H' option and not against the local datab=
ase
only (which is still the default when no URL is given).
samba-tool domain demote
------------------------
Add '--remove-other-dead-server' option to 'samba-tool domain demote'
subcommand. The new version of this tool now can remove another DC that is
itself offline. The '--remove-other-dead-server' removes as many references
to the DC as possible.
samba-tool drs clone-dc-database
--------------------------------
Replicate an initial clone of domain, but do not join it.
This is developed for debugging purposes, but not for setting up another DC.
pdbedit
-------
Add '--set-nt-hash' option to pdbedit to update user password from nt-hash
hexstring. 'pdbedit -vw' shows also password hashes.
smbstatus
---------
'smbstatus' was enhanced to show the state of signing and encryption for
sessions and shares.
smbget
------
The -u and -p options for user and password were replaced by the -U option =
that
accepts username[%password] as in many other tools of the Samba suite.
Similary, smbgetrc files do not accept username and password options any mo=
re,
only a single "user" option which also accepts user%password combinations.
s4-rpc_server
-------------
Add a GnuTLS based backupkey implementation.
ntlm_auth
---------
Using the '--offline-logon' enables ntlm_auth to use cached passwords when =
the
DC is offline.
Allow '--password' force a local password check for ntlm-server-1 mode.
vfs_offline
-----------
A new VFS module called vfs_offline has been added to mark all files in the
share as offline. It can be useful for shares mounted on top of a remote fi=
le
system (either through a samba VFS module or via FUSE).
KCC
---
The Samba KCC has been improved, but is still disabled by default.
DNS
---
There were several improvements concerning the Samba DNS server.
Active Directory
----------------
There were some improvements in the Active Directory area.
WINS nsswitch module
--------------------
The WINS nsswitch module has been rewritten to address memory issues and to
simplify the code. The module now uses libwbclient to do WINS queries. This
means that winbind needs to be running in order to resolve WINS names using
the nss_wins module. This does not affect smbd.
CTDB changes
------------
* CTDB now uses a newly implemented parallel database recovery scheme
that avoids deadlocks with smbd.
In certain circumstances CTDB and smbd could deadlock. The new
recovery implementation avoid this. It also provides improved
recovery performance.
* All files are now installed into and referred to by the paths
configured at build time. Therefore, CTDB will now work properly
when installed into the default location at /usr/local.
* Public CTDB header files are no longer installed, since Samba and
CTDB are built from within the same source tree.
* CTDB_DBDIR can now be set to tmpfs[:<tmpfs-options>]
This will cause volatile TDBs to be located in a tmpfs. This can
help to avoid performance problems associated with contention on the
disk where volatile TDBs are usually stored. See ctdbd.conf(5) for
more details.
* Configuration variable CTDB_NATGW_SLAVE_ONLY is no longer used.
Instead, nodes should be annotated with the "slave-only" option in
the CTDB NAT gateway nodes file. This file must be consistent
across nodes in a NAT gateway group. See ctdbd.conf(5) for more
details.
* New event script 05.system allows various system resources to be
monitored
This can be helpful for explaining poor performance or unexpected
behaviour. New configuration variables are
CTDB_MONITOR_FILESYSTEM_USAGE, CTDB_MONITOR_MEMORY_USAGE and
CTDB_MONITOR_SWAP_USAGE. Default values cause warnings to be
logged. See the SYSTEM RESOURCE MONITORING CONFIGURATION in
ctdbd.conf(5) for more information.
The memory, swap and filesystem usage monitoring previously found in
00.ctdb and 40.fs_use is no longer available. Therefore,
configuration variables CTDB_CHECK_FS_USE, CTDB_MONITOR_FREE_MEMORY,
CTDB_MONITOR_FREE_MEMORY_WARN and CTDB_CHECK_SWAP_IS_NOT_USED are
now ignored.
* The 62.cnfs eventscript has been removed. To get a similar effect
just do something like this:
mmaddcallback ctdb-disable-on-quorumLoss \
--command /usr/bin/ctdb \
--event quorumLoss --parms "disable"
mmaddcallback ctdb-enable-on-quorumReached \
--command /usr/bin/ctdb \
--event quorumReached --parms "enable"
* The CTDB tunable parameter EventScriptTimeoutCount has been renamed
to MonitorTimeoutCount
It has only ever been used to limit timed-out monitor events.
Configurations containing CTDB_SET_EventScriptTimeoutCount=3D<n> will
cause CTDB to fail at startup. Useful messages will be logged.
* The commandline option "-n all" to CTDB tool has been removed.
The option was not uniformly implemented for all the commands.
Instead of command "ctdb ip -n all", use "ctdb ip all".
* All CTDB current manual pages are now correctly installed
REMOVED FEATURES
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Public headers
--------------
Several public headers are not installed any longer. They are made for inte=
rnal
use only. More public headers will very likely be removed in future release=
s.
The following headers are not installed any longer:
dlinklist.h, gen_ndr/epmapper.h, gen_ndr/mgmt.h, gen_ndr/ndr_atsvc_c.h,
gen_ndr/ndr_epmapper_c.h, gen_ndr/ndr_epmapper.h, gen_ndr/ndr_mgmt_c.h,
gen_ndr/ndr_mgmt.h,gensec.h, ldap_errors.h, ldap_message.h, ldap_ndr.h,
ldap-util.h, pytalloc.h, read_smb.h, registry.h, roles.h, samba_util.h,
smb2_constants.h, smb2_create_blob.h, smb2.h, smb2_lease.h, smb2_signing.h,
smb_cli.h, smb_cliraw.h, smb_common.h, smb_composite.h, smb_constants.h,
smb_raw.h, smb_raw_interfaces.h, smb_raw_signing.h, smb_raw_trans2.h,
smb_request.h, smb_seal.h, smb_signing.h, smb_unix_ext.h, smb_util.h,
torture.h, tstream_smbXcli_np.h.
vfs_smb_traffic_analyzer
------------------------
The SMB traffic analyzer VFS module has been removed, because it is not
maintained any longer and not widely used.
vfs_scannedonly
---------------
The scannedonly VFS module has been removed, because it is not maintained
any longer.
smb.conf changes
----------------
Parameter Name Description Default
-------------- ----------- -------
aio max threads New 100
ldap page size Changed default 1000
KNOWN ISSUES
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Currently none.
CHANGES SINCE 4.4.0rc1
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
o Michael Adam <[email protected]>
* BUG 11715: s3:vfs:glusterfs: Fix build after quota changes.
o Jeremy Allison <[email protected]>
* BUG 11703: s3: smbd: Fix timestamp rounding inside SMB2 create.
o Christian Ambach <[email protected]>
* BUG 11700: Streamline 'smbget' options with the rest of the Samba uti=
ls.
o G=C3=BCnther Deschner <[email protected]>
* BUG 11696: ctdb: Do not provide a useless pkgconfig file for ctdb.
o Stefan Metzmacher <[email protected]>
* BUG 11699: Crypto.Cipher.ARC4 is not available on some platforms, fall=
back
to M2Crypto.RC4.RC4 then.
o Amitay Isaacs <[email protected]>
* BUG 11705: Sockets with htons(IPPROTO_RAW) and CVE-2015-8543.
o Andreas Schneider <[email protected]>
* BUG 11690: docs: Add smbspool_krb5_wrapper manpage.
o Uri Simchoni <[email protected]>
* BUG 11681: smbd: Show correct disk size for different quota and dfree =
block
sizes.
#######################################
Reporting bugs & Development Discussion
#######################################
Please discuss this release on the samba-technical mailing list or by
joining the #samba-technical IRC channel on irc.freenode.net.
If you do report problems then please try to send high quality
feedback. If you don't provide vital information to help us track down
the problem then you will probably be ignored. All bug reports should
be filed under the Samba 4.1 and newer product in the project's Bugzilla
database (https://bugzilla.samba.org/).
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
=3D=3D Our Code, Our Bugs, Our Responsibility.
=3D=3D The Samba Team
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Download Details
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
The uncompressed tarballs and patch files have been signed
using GnuPG (ID 6568B7EA). The source code can be downloaded
=66rom:
https://download.samba.org/pub/samba/rc/
The release notes are available online at:
https://download.samba.org/pub/samba/rc/samba-4.4.0rc2.WHATSNEW.txt
Our Code, Our Bugs, Our Responsibility.
(https://bugzilla.samba.org/)
--Enjoy
The Samba Team
--qDbXVdCdHGoSgWSk
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iEYEARECAAYFAla5vEsACgkQKGi9fisXk1EwJQCeIezMswHi/gGVlafHqe2t4pWR
9l8An2RSXbldOwXFGtL97CP3fvVAQQyD
=rZaJ
-----END PGP SIGNATURE-----
--qDbXVdCdHGoSgWSk--