-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 12 Sep 2026 13:44:54 +0100 Source: fail2ban Architecture: source Version: 1.1.1-1 Distribution: unstable Urgency: medium Maintainer: Debian Python Team <team+python@tracker.debian.org> Changed-By: Dale Richards <dale@dalerichards.net> Closes: 748076 782256 935778 983534 990144 991367 994511 1024822 1080413 1101769 1121856 Changes: fail2ban (1.1.1-1) unstable; urgency=medium . * Team upload. * New upstream version 1.1.1. - Ships a new openvpn filter and jail, requested in 2014 (Closes: #748076). * d/watch: mangle upstream pre-release tags (1.1.1.beta0, 0.8.11.pre1, 0.10.0a1) to tilde form so they sort below the release they precede, and skip tags that are not version numbers. * d/gbp.conf: point debian-branch at master (was a stale experimental branch) and enable pristine-tar. . * d/patches: - Drop no-python-user.diff and replace-distutils.patch, both merged or made redundant upstream. - Drop the systemd unit hunk of systemd-run.diff (RuntimeDirectory is now upstream) and fold the remaining /run migration into deb_init_paths. - Merge update-ssh-9.8.diff and update-ssh-10.0.diff into deb_sshd_journalmatch.diff; only the ssh.service unit name is still Debian-specific. - Trim the now-upstream sshd_backend/postfix_backend keys from update_backend_system.diff, and refresh roundcube.diff. - Add DEP-3 headers to every patch. - Set syslog_local0 to /var/log/syslog on Debian; upstream's /var/log/messages does not exist here (Closes: #983534). - Add deb_asterisk_log_path.diff, making the asterisk jail's logpath configurable from paths-*.conf, and point it at /var/log/asterisk/messages.log, which is what Asterisk has written since version 19 (Closes: #1024822). . * d/control: - Bump debhelper-compat to 14. - Add dh-sequence-single-binary to Build-Depends: compat 14 warns that it only implicitly activates the single-binary dh addon for backwards compatibility, and will stop doing so in compat 15. - Drop ${misc:Depends} from Depends: compat 14's dh_gencontrol now applies it automatically, and the explicit placeholder was left with nothing to substitute (dpkg-gencontrol: warning: substitution variable ${misc:Depends} used, but is not defined). - Recommend nftables alone rather than "nftables | iptables", and suggest iptables. The Debian default banaction is nftables, but apt considered the recommendation satisfied whenever iptables was already installed, so banning failed silently. (Closes: #1121856, #1101769, #994511) . * d/rules: - Stop installing files/fail2ban-tmpfiles.conf; upstream dropped it in 1.1.1 in favour of RuntimeDirectory= in the systemd unit. - Drop the unused PYVERSION variable, the no-op dh_auto_configure override, a duplicated install -d, and the dh_installman override (use d/fail2ban.manpages). - No longer ignore the result of the upstream test suite; it passes cleanly on Python 3.14. . * d/rules, d/fail2ban.maintscript: ship the monit snippet in /etc/monit/conf-available, the directory monit reads via conf- enabled, instead of the unused /etc/monit/monitrc.d (Closes: #991367). * d/backports: drop; sarge/python-central era files, dead since 2006. * d/NEWS: document the nftables recommendation, the conffile cleanup and the monit move. * d/fail2ban.logrotate: skip the postrotate hook when fail2ban-client is gone (Closes: #782256) and do not fail the logrotate run when the server is not up, e.g. early at boot (Closes: #935778). * d/fail2ban.maintscript: remove conffiles that upstream stopped shipping long ago and that were left behind on upgraded systems (Closes: #990144). * d/fail2ban.default: replace the obsolete FSF postal address with the licence URL (Closes: #1080413). * d/fail2ban.lintian-overrides: move the national-encoding overrides here from d/source (they apply to the binary package) and override unusual-interpreter for /usr/bin/fail2ban-python, which the package itself ships. * d/source/lintian-overrides: override uses-deprecated-python-stdlib; upstream vendors asyncore/asynchat under fail2ban/compat and guards the smtpd import (see #1040114, #1040122). * d/copyright: add Upstream-Name, point Source at the tarball location, record the bundled asyncore/asynchat modules (Copyright 1996 Sam Rushing, permissive licence) and replace the "many others since then" placeholder. * d/TODO: drop; its one entry pointed at the syslog-forging caveat already fully documented in d/README.Debian, and the file isn't shipped (d/fail2ban.docs installs upstream's own TODO, not this one). Checksums-Sha1: 283876506c5901e6c32edfa8ed9f620bdbb8f497 2276 fail2ban_1.1.1-1.dsc 822a01c06f02b5c8251606ab176412ff3f663766 627126 fail2ban_1.1.1.orig.tar.gz e930bfaa4e89c66530937434bc44c2f844e6969a 33800 fail2ban_1.1.1-1.debian.tar.xz ba642c1f9fbdf662a05fc3d4cb4b1ec0e78bc9f8 6786 fail2ban_1.1.1-1_source.buildinfo Checksums-Sha256: f5d2c6841da847632b943c4333c4ce22f76ea1d620b8690274e458e24083b504 2276 fail2ban_1.1.1-1.dsc 4be0ea0488e32de260058462a44a040f0542cd26a9fb6fa6d2514f9dd8ec1609 627126 fail2ban_1.1.1.orig.tar.gz 6421b4d076302e9e91c8adaa74ef8df13015925cb562e992f3e3a1b3cacb875e 33800 fail2ban_1.1.1-1.debian.tar.xz 2425195fa0ab3c47c03a93f85fd7ad4d9c64efbe6f8b8348dae4eebc9fb06c9d 6786 fail2ban_1.1.1-1_source.buildinfo Files: b2cd7b525f6406a542c12e1128dfe3fc 2276 net optional fail2ban_1.1.1-1.dsc da8b304c1780f6227fa70cf136959854 627126 net optional fail2ban_1.1.1.orig.tar.gz 31d56e56449cf673dd7a770b5b764e2e 33800 net optional fail2ban_1.1.1-1.debian.tar.xz e6e3bf3c91958872d2ae16053389433d 6786 net optional fail2ban_1.1.1-1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEj23hBDd/OxHnQXSHMfMURUShdBoFAmqubZsACgkQMfMURUSh dBoCvg/+Jy4qyIO4NWjPHaZdSbaHsgzUdNTODT1fpVkfSQN78MdG0a8lADTynts3 uhYsX3qBF+JVVTX4CujIh2VIVC7k781TYx3HKIkOfItECQyRTuCSCKFPezZ6HBIL W8J8KQu6AvQy1s9V8epH3zAz4dz0FJrPu5015YTyAmu71V3A4rbcFd3oF0e65E7a YSjxQL1y2mHbj4Va3S5wzVLLgufdsj4NMWABL5KcxBlkGtQbLXsICHL+SbkTGgrs G0awqNuY8vOoksjLbXNCS5KYt+7mSqjUKpMknduHDltkM2MT6A030VdAeVjcSXNn 7xQMuD5qD9lgn1BGipvvBj4omacDp6q3qXVq/t0OFt3wHpvwJ9myfX6RNlPaJzF0 iMbkdMebvJxe2/1oPZhllAAPX6s1BlCdZEq/4n77UBd8EHD6A+LQqJ+LGleDpV/h XuFsOfi9KJ3NvDA80H1vxzN4AnmjqccaD0tJ6RH6EuHXJHW6oYHp8aWjBqJbWOrL poFGDO+Xu1yNrH0NcO2cN3PNaPurVd/C2sHj7gH4N/q1fcS4myyA2V1w8UHYhM9E SCj/RV3B067VXWXyt55TTL9NhN+MtuWsF1lKHwbgYjucLaCZSRjyc1RMDp17HSsD GJ9tgrOJ+8s2xWx+cV627AsnA3GngTju9REYMBha0x/s9MAm0fY= =xtNv -----END PGP SIGNATURE-----