http://bugzilla.novell.com/show_bug.cgi?id=588185http://bugzilla.novell.com/show_bug.cgi?id=588185#c0
Summary: AppArmor: network rule
Classification: openSUSE
Product: openSUSE 11.2
Version: Final
Platform: x86
OS/Version: openSUSE 11.2
Status: NEW
Severity: Normal
Priority: P5 - None
Component: AppArmor
AssignedTo: jeffm(a)novell.com
ReportedBy: matwey.kornilov(a)gmail.com
QAContact: qa(a)suse.de
Found By: ---
Blocker: ---
User-Agent: Mozilla/5.0 (X11; U; Linux i686; ru; rv:1.9.1.8)
Gecko/20100204 SUSE/3.5.8-0.1.1 Firefox/3.5.8
I suppose that there is a bug in AppArmor 2.3.1(bundled with opensuse 11.2).
The 'network' rule is described in man page and openSUSE Security Guide for
11.2, but It doesn't work for me at all. Network connections aren't blocked and
there aren't 'socket_create' messages in my /var/log/audit.log.
I created threads in forum and some users confirmed the AppArmor behavior:
http://forums.opensuse.org/applications/434684-apparmor-network-rule.htmlhttp://forums.novell.com/novell-product-support-forums/apparmor/404069-appa…
Reproducible: Always
--
Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=587014http://bugzilla.novell.com/show_bug.cgi?id=587014#c0
Summary: Winbind offline authentication not working after
upgrade to samba 3.5.x
Classification: openSUSE
Product: openSUSE 11.2
Version: Final
Platform: x86-64
OS/Version: openSUSE 11.2
Status: NEW
Severity: Major
Priority: P5 - None
Component: Samba
AssignedTo: samba-maintainers(a)SuSE.de
ReportedBy: koen.dewitte(a)jandenul.com
QAContact: samba-maintainers(a)SuSE.de
Found By: ---
Blocker: ---
User-Agent: Mozilla/5.0 (X11; U; Linux x86_64; en-US) AppleWebKit/533.2
(KHTML, like Gecko) Chrome/5.0.342.1 Safari/533.2
Using OSS11.2 as desktop on a AD2003 domain with offline login enabled.
After upgrade to the 3.5 stack (tried 3.5.0 and 3.5.1) I can no longer user
offline login.
It seems there is a problem with the tdb in the backend.
This is what I get in the log for version 3.5
[2010/03/07 09:19:23, 0] winbindd/winbindd.c:1093(main)
winbindd version 3.5.0-1.1-2315-SUSE-SL11.2 started.
Copyright Andrew Tridgell and the Samba Team 1992-2010
[2010/03/07 09:19:23.416658, 1]
lib/tdb_validate.c:470(tdb_validate_and_backup)
tdb '/var/lib/samba/winbindd_cache.tdb' is invalid
[2010/03/07 09:19:23.416779, 1]
lib/tdb_validate.c:476(tdb_validate_and_backup)
No backup found.
[2010/03/07 09:19:23.416935, 1]
lib/tdb_validate.c:494(tdb_validate_and_backup)
Corrupt tdb stored as '/var/lib/samba/winbindd_cache.tdb.corrupt'
[2010/03/07 09:19:23.416967, 0]
winbindd/winbindd_cache.c:4094(winbindd_cache_validate_and_initialize)
winbindd cache tdb corrupt and no backup could be restored.
[2010/03/07 09:19:23.417420, 0]
winbindd/winbindd_cache.c:3076(initialize_winbindd_cache)
initialize_winbindd_cache: clearing cache and re-creating with version number
1
And the same for 3.5.1
winbindd version 3.5.1-1.1-2323-SUSE-SL11.2 started.
Copyright Andrew Tridgell and the Samba Team 1992-2010
[2010/03/10 10:09:24.823684, 1]
lib/tdb_validate.c:470(tdb_validate_and_backup)
tdb '/var/lib/samba/winbindd_cache.tdb' is invalid
[2010/03/10 10:09:24.823738, 1]
lib/tdb_validate.c:478(tdb_validate_and_backup)
backup '/var/lib/samba/winbindd_cache.tdb.bak' found.
[2010/03/10 10:09:24.824374, 1]
lib/tdb_validate.c:482(tdb_validate_and_backup)
Backup '/var/lib/samba/winbindd_cache.tdb.bak' is invalid.
[2010/03/10 10:09:24.824437, 1]
lib/tdb_validate.c:494(tdb_validate_and_backup)
Corrupt tdb stored as '/var/lib/samba/winbindd_cache.tdb.corrupt'
[2010/03/10 10:09:24.824555, 0]
winbindd/winbindd_cache.c:3103(initialize_winbindd_cache)
initialize_winbindd_cache: clearing cache and re-creating with version number
1
To fix it, i have to downgrade. (To the OSS11.2 3.4.2 standard)
[2010/03/10 11:17:04, 0] winbindd/winbindd.c:1244(main)
winbindd version 3.4.2-1.1.3.1-2229-SUSE-SL11.2 started.
Copyright Andrew Tridgell and the Samba Team 1992-2009
[2010/03/10 11:17:04, 0]
winbindd/winbindd_cache.c:3673(cache_traverse_validate_fn)
cache_traverse_validate_fn: unknown cache entry
key :
[2010/03/10 11:17:04, 0] ../lib/util/util.c:304(_dump_data)
[0000] 4E 44 52 2F 52 4F 4F 54 44 4F 4D 41 49 4E 2F 32 NDR/ROOT DOMAIN/2
[0010] 2F 0F 00 00 00 00 00 00 00 0F 00 00 00 44 45 5F /....... .....DE_
[0020] 4E 55 4C 5F 4E 45 54 57 4F 52 4B 00 00 05 00 00 NUL_NETW ORK.....
[0030] 00 00 00 00 00 05 00 00 00 52 4F 4F 54 00 00 00 ........ .ROOT...
[0040] 00 08 00 00 00 .....
[2010/03/10 11:17:04, 0]
winbindd/winbindd_cache.c:3675(cache_traverse_validate_fn)
data :
[2010/03/10 11:17:04, 0] ../lib/util/util.c:304(_dump_data)
[0000] 2F 68 0E 00 00 00 00 00 00 00 00 00 00 00 00 00 /h...... ........
[0010] 73 00 00 C0 s...
[2010/03/10 11:17:04, 1] lib/tdb_validate.c:459(tdb_validate_and_backup)
tdb '/var/lib/samba/winbindd_cache.tdb' is invalid
[2010/03/10 11:17:04, 1] lib/tdb_validate.c:467(tdb_validate_and_backup)
backup '/var/lib/samba/winbindd_cache.tdb.bak' found.
[2010/03/10 11:17:04, 1] lib/tdb_validate.c:488(tdb_validate_and_backup)
valid backup '/var/lib/samba/winbindd_cache.tdb.bak' found
[2010/03/10 11:17:04, 1] lib/tdb_validate.c:496(tdb_validate_and_backup)
Restored tdb backup from '/var/lib/samba/winbindd_cache.tdb.bak'
Reproducible: Always
Steps to Reproduce:
1.Install OSS11.2 and enable AD login with offline enabled
2.upgrade to latest samba stable packages (3.5.1)
3.try to login offline
Actual Results:
"User is not known to the underlying authentication module"
Also, you do not see the user in the GDM screen at login (when offline!)
Expected Results:
normally you can login with an AD user offline and see that cached account in
the GDM.
When logging in you get the message "logging in with cached credentials"
--
Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=586555http://bugzilla.novell.com/show_bug.cgi?id=586555#c0
Summary: lxde dumps messages to console
Classification: openSUSE
Product: openSUSE 11.3
Version: Milestone 2
Platform: Other
OS/Version: Other
Status: NEW
Severity: Normal
Priority: P5 - None
Component: LXDE
AssignedTo: andrea(a)opensuse.org
ReportedBy: lnussel(a)novell.com
QAContact: qa(a)suse.de
Found By: ---
Blocker: ---
the error messages from the X session are dumped to the console (/dev/tty1)
when lxdm is used. lxdm should detach from the console and session messages
should go to ~/.xsession-errors. looks like /etc/X11/xdm/Xsession is not
executed
--
Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=586486http://bugzilla.novell.com/show_bug.cgi?id=586486#c0
Summary: Multiple Issues with Yast Configuration of Postfix MTA
for Relaying over SMTP
Classification: openSUSE
Product: openSUSE 11.2
Version: Final
Platform: x86-64
OS/Version: Other
Status: NEW
Severity: Normal
Priority: P5 - None
Component: YaST2
AssignedTo: bnc-team-screening(a)forge.provo.novell.com
ReportedBy: andrew(a)acooke.org
QAContact: jsrain(a)novell.com
Found By: ---
Blocker: ---
User-Agent: Mozilla/5.0 (X11; U; Linux x86_64; en-GB; rv:1.9.1.8)
Gecko/20100204 SUSE/3.5.8-0.1.1 Firefox/3.5.8
The Yast configuration of Postfix as MTA, using the standard (not advanced)
mode, for delivering mail over SMTP to a relay, has a number of issues.
1 - When using TLS authentication (SASL) the host address is not surrounded
with [] as recommended here - http://www.postfix.org/SASL_README.html (see
section titled "Enabling SASL authentication in the Postfix SMTP/LMTP client").
This is necessary because often the same name (mail.example.com or
smtp.example.com) is used both as a relay and to handle incoming mail. Only
the relay needs authentication, and so is given one physical machine, while
other physical machines handle the main mail volume. In such a case, MX
records point to the "other" machines, and [] is necessary to use the "real"
machine (which is the only one with autentication). For a concrete example of
the pain this causes please see
http://forum.webfaction.com/viewtopic.php?pid=15066
2 - When the config is changed in Yast (eg the SMT server name changed), the
changes appear in /etc/systconfig/postfix and sasl_passwd, but not in main.cnf.
3 - When the config is changed in Yast (eg the SMT auth details changed), the
sasl_passwd.db file is not regenerated with "postmap sasl_passwd".
Reproducible: Always
Steps to Reproduce:
1. Use Yast to configure SMTP
2. See it fail to work in the case described above, where MX names are used
instead of the exact, given host.
3. Change details
4. See how the updated details are not used in subsequent connections.
--
Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=586376http://bugzilla.novell.com/show_bug.cgi?id=586376#c0
Summary: network settings: "activate device" event -- add
option for exclusive activation
Classification: openSUSE
Product: openSUSE 11.1
Version: Final
Platform: x86-64
OS/Version: Other
Status: NEW
Severity: Enhancement
Priority: P5 - None
Component: YaST2
AssignedTo: bnc-team-screening(a)forge.provo.novell.com
ReportedBy: bluedzins(a)wp.pl
QAContact: jsrain(a)novell.com
Found By: ---
Blocker: ---
Yast -> network devices -> network settings -> interface -> activate device
Currently there are several options, like on boot, on cable connection, manual,
etc.
Let's focus on cable connection -- when cable is connected that device is
activated. That is what this option says. But what this option _does not_ say
is this activation is exclusive, i.e. it will shutdown all other active
interfaces.
I am not discussing if such implicit, additional action is useful or not (for
me not), but anyway, if there is an _extra_ action, there should be an _extra_
option. Namely:
[ ] exclusive activation
that way user could set/control if she/he really wants exclusive connection
over only one interface. This way also it would be finally possible to use "on
cable connection" settings with multiple interfaces/connections (currently it
is not possible and user has to set it up manually with ifup).
--
Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=586083http://bugzilla.novell.com/show_bug.cgi?id=586083#c0
Summary: obs://build.opensuse.org/multimedia/rosegarden4-10.02-
29.3.x86_64 sigsegv in
Rosegarden::HeadersGroup::slotSetCurrentSegment
Classification: openSUSE
Product: openSUSE.org
Version: unspecified
Platform: x86-64
OS/Version: openSUSE 11.2
Status: NEW
Severity: Normal
Priority: P5 - None
Component: 3rd party software
AssignedTo: davejplater(a)gmail.com
ReportedBy: m.munnix(a)redcross.be
QAContact: opensuse-communityscreening(a)forge.provo.novell.com
Found By: ---
Blocker: ---
Created an attachment (id=346966)
--> (http://bugzilla.novell.com/attachment.cgi?id=346966)
stdout + bt full
I had done a lot of editing in notation editor, clicked on save.
Back to main window without closing notation editor, select the split track
tool, then clicked on a track at the desired split point. Got the segfault
Attaching output + full backtrace
--
Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=586070http://bugzilla.novell.com/show_bug.cgi?id=586070#c0
Summary: Missing period in sentence.
Classification: openSUSE
Product: openSUSE 11.3
Version: Factory
Platform: Other
OS/Version: Other
Status: NEW
Severity: Minor
Priority: P5 - None
Component: Translations
AssignedTo: ke(a)novell.com
ReportedBy: isis.binder(a)gmail.com
QAContact: ke(a)novell.com
Found By: ---
Blocker: ---
User-Agent: Mozilla/5.0 (X11; U; Linux i686; pt-BR; rv:1.9.2)
Gecko/20100115 Firefox/3.6
File: apparmor-parser.po
Line: 90
#: ../parser_interface.c:81
msgid "Couldn't copy profile Bad memory address\n"
Reproducible: Always
Steps to Reproduce:
1.
2.
3.
--
Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=585802http://bugzilla.novell.com/show_bug.cgi?id=585802#c0
Summary: wpa_supplicant needs nl80211 driver for country=DE
(WIRELESS_REGULATORY_DOMAIN)
Classification: openSUSE
Product: openSUSE 11.3
Version: Factory
Platform: All
OS/Version: openSUSE 11.3
Status: NEW
Severity: Major
Priority: P5 - None
Component: Other
AssignedTo: mt(a)novell.com
ReportedBy: mt(a)novell.com
QAContact: qa(a)suse.de
CC: radmanic(a)novell.com, coolo(a)novell.com, ro(a)novell.com,
mzugec(a)novell.com, jmatejek(a)novell.com
Depends on: 555850
Found By: ---
Blocker: ---
+++ This bug was initially created as a clone of Bug #537708 +++
Until openSUSE:11.2, we were using the "wext" wpa driver by default.
For openSUSE:11.3 it would be required to switch as many drivers as
possible to the new "nl80211" driver to not to restricts any devices
to "world" (ie. most restrictive) regulatory domain.
As already proposed in bug 537708 comment 6, it makes sense to use
the new driver as default, except in cases where it does not work.
The intention of this bug is to track these non-working cases.
See also bug 535750 comment 7:
"[...] If the wpa_supplicant is running with the -Dnl80211 then it
does not authenticate. -Dwext works fine.[...]"
See also bug 555850, crda -- Database signature verification failed.
--
Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=585679http://bugzilla.novell.com/show_bug.cgi?id=585679#c0
Summary: "Package Manager" -> "Software Manager"
Classification: openSUSE
Product: openSUSE 11.2
Version: Final
Platform: Other
OS/Version: Other
Status: NEW
Severity: Minor
Priority: P5 - None
Component: YaST2
AssignedTo: bnc-team-screening(a)forge.provo.novell.com
ReportedBy: rpmcruz(a)alunos.dcc.fc.up.pt
QAContact: jsrain(a)novell.com
Found By: ---
Blocker: ---
User-Agent: Mozilla/5.0 (X11; U; Linux i686; pt-PT; rv:1.9.1.4)
Gecko/20091016 SUSE/3.5.4-1.1.2 Firefox/3.5.4
It was decided a while back to use the term "Software Manager" rather than
"Package Manager" (or "Package Selector").
Please change the two "Initialize Package Manager" strings over
webpin_package_search.ycp
Reproducible: Always
--
Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.