Difference between revisions of "Samba 4.4 Features added/changed"

(This is the second release candidate of Samba 4.4.)
(samba 4.4.0rc3)
Line 1: Line 1:
==Samba 4.4.0rc2==
+
==Samba 4.4.0rc3==
:Release Notes for Samba 4.4.0rc2
+
:Release Notes for Samba 4.4.0rc3
:February  9,  2016
+
:February  23,  2016
  
 
===This is the second release candidate of Samba 4.4.===
 
===This is the second release candidate of Samba 4.4.===
Line 132: Line 132:
 
   aio max threads              New                    100
 
   aio max threads              New                    100
 
   ldap page size Changed default 1000
 
   ldap page size Changed default 1000
 +
 +
===CHANGES SINCE 4.4.0rc2===
 +
 +
*  Michael Adam <obnox@samba.org>
 +
:* [https://bugzilla.samba.org/show_bug.cgi?id= 11723 BUG #11723]: lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN.
 +
:* [https://bugzilla.samba.org/show_bug.cgi?id= 11735 BUG #11735]: lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING).
 +
*  Jeremy Allison <jra@samba.org>
 +
:* [https://bugzilla.samba.org/show_bug.cgi?id= 10489 BUG #10489]: s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support.
 +
*  Christian Ambach <ambi@samba.org>
 +
:* [https://bugzilla.samba.org/show_bug.cgi?id= 11700 BUG #11700]: s3:utils/smbget: Set default blocksize.
 +
*  Anoop C S <anoopcs@redhat.com>
 +
:* [https://bugzilla.samba.org/show_bug.cgi?id= 11734 BUG #11734]: lib/socket: Fix improper use of default interface speed.
 +
*  Ralph Boehme <slow@samba.org>
 +
:* [https://bugzilla.samba.org/show_bug.cgi?id= 11714 BUG #11714]: lib/tsocket: Work around sockets not supporting FIONREAD.
 +
*  Volker Lendecke <vl@samba.org>
 +
:* [https://bugzilla.samba.org/show_bug.cgi?id= 11724 BUG #11724]: smbd: Fix CID 1351215 Improper use of negative value.
 +
:* [https://bugzilla.samba.org/show_bug.cgi?id= 11725 BUG #11725]: smbd: Fix CID 1351216 Dereference null return value.
 +
:* [https://bugzilla.samba.org/show_bug.cgi?id= 11732 BUG #11732]: param: Fix str_list_v3 to accept ; again.
 +
*  Noel Power <noel.power@suse.com>
 +
:* [https://bugzilla.samba.org/show_bug.cgi?id= 11738 BUG #11738]: libcli: Fix debug message, print sid string for new_ace trustee.
 +
*  Jose A. Rivera <jarrpa@samba.org>
 +
:* [https://bugzilla.samba.org/show_bug.cgi?id= 11727 BUG #11727]: s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file.
 +
*  Andreas Schneider <asn@samba.org>
 +
:* [https://bugzilla.samba.org/show_bug.cgi?id= 11730 BUG #11730]: docs: Add manpage for cifsdd.
 +
:* [https://bugzilla.samba.org/show_bug.cgi?id= 11739 BUG #11739]: Fix installation path of Samba helper binaries.
 +
*  Berend De Schouwer <berend.de.schouwer@gmail.com>
 +
:* [https://bugzilla.samba.org/show_bug.cgi?id= 11643 BUG #11643]: docs: Add example for domain logins to smbspool man page.
 +
*  Martin Schwenke <martin@meltin.net>
 +
:* [https://bugzilla.samba.org/show_bug.cgi?id= 11719 BUG #11719]: ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."
 +
*  Hemanth Thummala <hemanth.thummala@nutanix.com>
 +
:* [https://bugzilla.samba.org/show_bug.cgi?id= 11708 BUG #11708]: loadparm: Fix memory leak issue.
 +
:* [https://bugzilla.samba.org/show_bug.cgi?id= 11740 BUG #11740]: Fix memory leak in loadparm.
  
 
===CHANGES SINCE 4.4.0rc1===
 
===CHANGES SINCE 4.4.0rc1===
Line 163: Line 195:
 
Currently none.
 
Currently none.
  
  https://download.samba.org/pub/samba/rc/samba-4.4.0rc1.WHATSNEW.txt
+
  https://download.samba.org/pub/samba/rc/samba-4.4.0rc3.WHATSNEW.txt

Revision as of 20:05, 23 February 2016

Samba 4.4.0rc3

Release Notes for Samba 4.4.0rc3
February 23, 2016

This is the second release candidate of Samba 4.4.

This is *not* intended for production environments and is designed for testing purposes only. Please report any defects via the Samba bug reporting system at

https://bugzilla.samba.org/.

Samba 4.4 will be the next version of the Samba suite.

UPGRADING

Nothing special.


NEW FEATURES/CHANGES

Asynchronous flush requests

Flush requests from SMB2/3 clients are handled asynchronously and do not block the processing of other requests. Note that 'strict sync' has to be set to 'yes' for Samba to honor flush requests from SMB clients.

s3: smbd

Remove '--with-aio-support' configure option. We no longer would ever prefer POSIX-RT aio, use pthread_aio instead.

samba-tool sites

The 'samba-tool sites' subcommand can now be run against another server by specifying an LDB URL using the '-H' option and not against the local database only (which is still the default when no URL is given).

samba-tool domain demote

Add '--remove-other-dead-server' option to 'samba-tool domain demote' subcommand. The new version of this tool now can remove another DC that is itself offline. The '--remove-other-dead-server' removes as many references to the DC as possible.

samba-tool drs clone-dc-database

Replicate an initial clone of domain, but do not join it. This is developed for debugging purposes, but not for setting up another DC.

pdbedit

Add '--set-nt-hash' option to pdbedit to update user password from nt-hash hexstring. 'pdbedit -vw' shows also password hashes.

smbstatus

'smbstatus' was enhanced to show the state of signing and encryption for sessions and shares.

smbget

The -u and -p options for user and password were replaced by the -U option that accepts username[%password] as in many other tools of the Samba suite. Similary, smbgetrc files do not accept username and password options any more, only a single "user" option which also accepts user%password combinations.

s4-rpc_server

Add a GnuTLS based backupkey implementation.

ntlm_auth

Using the '--offline-logon' enables ntlm_auth to use cached passwords when the DC is offline.

Allow '--password' force a local password check for ntlm-server-1 mode.

vfs_offline

A new VFS module called vfs_offline has been added to mark all files in the share as offline. It can be useful for shares mounted on top of a remote file system (either through a samba VFS module or via FUSE).

KCC

The Samba KCC has been improved, but is still disabled by default.

DNS

There were several improvements concerning the Samba DNS server.

Active Directory

There were some improvements in the Active Directory area.

WINS nsswitch module

The WINS nsswitch module has been rewritten to address memory issues and to simplify the code. The module now uses libwbclient to do WINS queries. This means that winbind needs to be running in order to resolve WINS names using the nss_wins module. This does not affect smbd.

CTDB changes

  • CTDB now uses a newly implemented parallel database recovery scheme that avoids deadlocks with smbd.
In certain circumstances CTDB and smbd could deadlock. The new recovery implementation avoid this. It also provides improved recovery performance.
  • All files are now installed into and referred to by the paths configured at build time. Therefore, CTDB will now work properly when installed into the default location at /usr/local.
  • Public CTDB header files are no longer installed, since Samba and CTDB are built from within the same source tree.
  • CTDB_DBDIR can now be set to tmpfs[:<tmpfs-options>]
This will cause volatile TDBs to be located in a tmpfs. This can help to avoid performance problems associated with contention on the disk where volatile TDBs are usually stored. See ctdbd.conf(5) for more details.
  • Configuration variable CTDB_NATGW_SLAVE_ONLY is no longer used.
Instead, nodes should be annotated with the "slave-only" option in the CTDB NAT gateway nodes file. This file must be consistent across nodes in a NAT gateway group. See ctdbd.conf(5) for more details.
  • New event script 05.system allows various system resources to be monitored
This can be helpful for explaining poor performance or unexpected behaviour. New configuration variables are CTDB_MONITOR_FILESYSTEM_USAGE, CTDB_MONITOR_MEMORY_USAGE and CTDB_MONITOR_SWAP_USAGE. Default values cause warnings to be logged. See the SYSTEM RESOURCE MONITORING CONFIGURATION in ctdbd.conf(5) for more information.
The memory, swap and filesystem usage monitoring previously found in 00.ctdb and 40.fs_use is no longer available. Therefore, configuration variables CTDB_CHECK_FS_USE, CTDB_MONITOR_FREE_MEMORY, CTDB_MONITOR_FREE_MEMORY_WARN and CTDB_CHECK_SWAP_IS_NOT_USED are now ignored.
  • The 62.cnfs eventscript has been removed. To get a similar effect just do something like this:
     mmaddcallback ctdb-disable-on-quorumLoss \
       --command /usr/bin/ctdb \
       --event quorumLoss --parms "disable"
     mmaddcallback ctdb-enable-on-quorumReached \
       --command /usr/bin/ctdb \
       --event quorumReached --parms "enable"
  • The CTDB tunable parameter EventScriptTimeoutCount has been renamed to MonitorTimeoutCount
It has only ever been used to limit timed-out monitor events.
Configurations containing CTDB_SET_EventScriptTimeoutCount=<n> will cause CTDB to fail at startup. Useful messages will be logged.
  • The commandline option "-n all" to CTDB tool has been removed.
The option was not uniformly implemented for all the commands. Instead of command "ctdb ip -n all", use "ctdb ip all".
  • All CTDB current manual pages are now correctly installed

REMOVED FEATURES

Public headers

Several public headers are not installed any longer. They are made for internal use only. More public headers will very likely be removed in future releases.

The following headers are not installed any longer: dlinklist.h, gen_ndr/epmapper.h, gen_ndr/mgmt.h, gen_ndr/ndr_atsvc_c.h, gen_ndr/ndr_epmapper_c.h, gen_ndr/ndr_epmapper.h, gen_ndr/ndr_mgmt_c.h, gen_ndr/ndr_mgmt.h,gensec.h, ldap_errors.h, ldap_message.h, ldap_ndr.h, ldap-util.h, pytalloc.h, read_smb.h, registry.h, roles.h, samba_util.h, smb2_constants.h, smb2_create_blob.h, smb2.h, smb2_lease.h, smb2_signing.h, smb_cli.h, smb_cliraw.h, smb_common.h, smb_composite.h, smb_constants.h, smb_raw.h, smb_raw_interfaces.h, smb_raw_signing.h, smb_raw_trans2.h, smb_request.h, smb_seal.h, smb_signing.h, smb_unix_ext.h, smb_util.h, torture.h, tstream_smbXcli_np.h.

vfs_smb_traffic_analyzer

The SMB traffic analyzer VFS module has been removed, because it is not maintained any longer and not widely used.

vfs_scannedonly

The scannedonly VFS module has been removed, because it is not maintained any longer.

smb.conf changes

 Parameter Name		Description		Default
 --------------		-----------		-------
 aio max threads               New                     100
 ldap page size		Changed default		1000

CHANGES SINCE 4.4.0rc2

  • Michael Adam <obnox@samba.org>
  • 11723 BUG #11723: lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN.
  • 11735 BUG #11735: lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING).
  • Jeremy Allison <jra@samba.org>
  • 10489 BUG #10489: s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support.
  • Christian Ambach <ambi@samba.org>
  • Anoop C S <anoopcs@redhat.com>
  • Ralph Boehme <slow@samba.org>
  • Volker Lendecke <vl@samba.org>
  • Noel Power <noel.power@suse.com>
  • 11738 BUG #11738: libcli: Fix debug message, print sid string for new_ace trustee.
  • Jose A. Rivera <jarrpa@samba.org>
  • 11727 BUG #11727: s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file.
  • Andreas Schneider <asn@samba.org>
  • Berend De Schouwer <berend.de.schouwer@gmail.com>
  • Martin Schwenke <martin@meltin.net>
  • 11719 BUG #11719: ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."
  • Hemanth Thummala <hemanth.thummala@nutanix.com>

CHANGES SINCE 4.4.0rc1

  • Michael Adam <obnox@samba.org>
  • Jeremy Allison <jra@samba.org>
  • Christian Ambach <ambi@samba.org>
  • Günther Deschner <gd@samba.org>
  • Stefan Metzmacher <metze@samba.org>
  • 11699 BUG #11699: Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then.
  • Amitay Isaacs <amitay@gmail.com>
  • Andreas Schneider <asn@samba.org>
  • Uri Simchoni <uri@samba.org>
  • 11681 BUG #11681: smbd: Show correct disk size for different quota and dfree block sizes.

KNOWN ISSUES

Currently none.

https://download.samba.org/pub/samba/rc/samba-4.4.0rc3.WHATSNEW.txt