There is 1 open security issue in sid.
There is 1 open security issue in forky.
commit 1cd41635fae38534d5ed6121a3b1ad6e40cc68af
Author: Richard Laager <rlaager@debian.org>
Date: Sun Aug 23 16:15:39 2026 -0500
Update changelog
Gbp-Dch: Ignore
commit 963ebf1a0a8b2bafcf2b8b348816b1dba1b92611
Author: Luca Boccassi <luca.boccassi@gmail.com>
Date: Sun Apr 19 22:45:33 2026 +0100
Install and use sysusers.d config file
sysusers.d config files allow a package to use declarative
configuration instead of manually written maintainer scripts. This
also allows image-based systems to be created with /usr/ only, and
also allows for factory resetting a system and recreating /etc/ on
boot.
https://www.freedesktop.org/software/systemd/man/latest/sysusers.d.html
commit f41cbb3e284e239399708394b71ec029904ef4d5
Author: Luca Boccassi <luca.boccassi@gmail.com>
Date: Sun Apr 19 22:44:02 2026 +0100
Stop deleting system user on remove/purge
This is widely considered bad practice, as the kernel recycles
UIDs/GIDs. So any potential leftover file/directory can then become
owned by the next user/group that gets added, with unpredictable
consequences.
commit 94906844b05e54a86650d1bc7c4ffec8f4d4478e
Author: Richard Laager <rlaager@debian.org>
Date: Sun Aug 23 15:34:17 2026 -0500
Update upstream signing keys
These are from:
https://ftp.ntpsec.org/pub/releases/ntpsec.gpg.pub.asc
This adds:
0x05D9B371477C7528: "NTPsec Security Reporting <security@ntpsec.org>"
0x2A7C3E36CC282DBE: "NTPsec Security Reporting <security@ntpsec.org>"
These remain:
0x5A22E330161C3978: "NTPsec Contact <contact@ntpsec.org>"
0x7F52608ED0E49D76: "NTPsec Security Reporting <security@ntpsec.org>"
Gbp-Dch: Ignore
commit 0aff163233bebc9f7c2b0d3d097d945cf708a5ae
Author: Richard Laager <rlaager@debian.org>
Date: Sun Aug 23 15:14:06 2026 -0500
Update changelog for new release
Gbp-Dch: Ignore
commit cf5ae33c9e94df15df0a42491d38054901f9a205
Author: Richard Laager <rlaager@debian.org>
Date: Sun Aug 23 15:13:19 2026 -0500
Update ntp.conf for maxclock bug fix
Gbp-Dch: Ignore
commit 2955e40a17b080468f2d547da15c2011f1e69ffc
Author: Richard Laager <rlaager@debian.org>
Date: Sun Aug 23 15:08:54 2026 -0500
NEWS: Remove the mention of the gpsd driver
That is no longer correct. While NEWS entries are dated, I don't think
it serves anyone having now-incorrect information in there.
commit 551e02df38d5a414d613c0838e3487c54a403a4f
Author: Richard Laager <rlaager@debian.org>
Date: Sun Aug 23 15:07:32 2026 -0500
Remove old NEWS entries
Many of these have been irrelevant for years. It is not useful to tell
people about pre-standard NTS ports, for example.
commit deec9d9071b02151a8e4b8df7ef380eebd600628
Author: Richard Laager <rlaager@debian.org>
Date: Sun Aug 23 15:03:05 2026 -0500
Refresh patches
Gbp-Dch: Ignore
commit aa30f9e0ade58e49865847f3c29d81f96c64be5c
Merge: 5b7f1a5a f517d438
Author: Richard Laager <rlaager@debian.org>
Date: Sun Aug 23 14:31:45 2026 -0500
Update upstream source from tag 'upstream/1.2.5+dfsg'
Update to upstream version '1.2.5+dfsg'
with Debian dir 04b646504a206fd40cdf8cc691c357538b51709e
commit 5b7f1a5a9ecf91405d7a3c029e84ff1eb464f70d
Author: Richard Laager <rlaager@debian.org>
Date: Mon Feb 16 16:29:39 2026 -0600
Remove obsolete upgrade code
This includes removing code to upgrade from the "ntp" package.
commit 9a8327468dc60ced7d0fc47c97a109459d797b7b
Author: Richard Laager <rlaager@debian.org>
Date: Sun Feb 8 17:17:16 2026 -0600
debian/rules: Fix whitespace
Gbp-Dch: Ignore
commit 87c540c351de2ac72b85a31b16faecac4bfc586d
Author: Richard Laager <rlaager@debian.org>
Date: Sat Feb 7 23:24:16 2026 -0600
Update changelog for release
Gbp-Dch: Ignore
commit 66ba3c626828b289fb80286c7f5b4c2ae9bfc1d4
Author: Richard Laager <rlaager@debian.org>
Date: Sat Feb 7 23:22:30 2026 -0600
Update to Standards-Version 4.7.3
commit b333b6845ab69af1bd2d95508ae6c218034f9c2b
Author: Richard Laager <rlaager@debian.org>
Date: Sat Feb 7 23:21:43 2026 -0600
Remove Rules-Requires-Root: no
Lintian says, "As of dpkg version 1.22.13, this field is set to "no" by
default."
Gbp-Dch: Ignore
commit 76b8cb7d30bee241549e841f91a62666e6b6cacb
Author: Richard Laager <rlaager@debian.org>
Date: Sat Feb 7 23:02:59 2026 -0600
Update changelog for release
Gbp-Dch: Ignore
commit 05e8f3e4136153fdfd079e1c9c4319e3f1404939
Author: Richard Laager <rlaager@debian.org>
Date: Sat Feb 7 22:43:49 2026 -0600
Simplify doc installation
This removes some indirection, by installing the files to the final
location directly.
Gbp-Dch: Ignore
commit eeae27e6f42db087143786952a070b2e2ce4254b
Author: Richard Laager <rlaager@debian.org>
Date: Sat Feb 7 22:42:21 2026 -0600
Fix waf handling of --libdir, etc.
This is a bug in waf 2.1.4 that was fixed in 2.1.6.
Gbp-Dch: Ignore
commit 2a7d0122f40370bc8806f2835f0a7043c77270f0
Author: Richard Laager <rlaager@debian.org>
Date: Sat Feb 7 17:10:31 2026 -0600
Build the gpsd JSON driver
Gary E. Miller, one of the upstream developers in common between NTPsec
and gpsd, who I had previously quoted in the justification for
disabling it, said, "I find the SHM way easier to debug. I never use
the JSON driver to talk to NTP. Choice is good, keep them both and let
the user decide."
-- https://gitlab.com/NTPsec/ntpsec/-/issues/668#note_2591150391
This driver uses libjsmn. Instead of using the embedded copy from the
NTPsec source tree, I use the Debian libjsmn-dev package.
Closes: 1108417
commit 1e5a6b034836142be0f0c80f88f0826783c4a6ab
Author: Richard Laager <rlaager@debian.org>
Date: Sat Feb 7 16:48:34 2026 -0600
ntp.conf: Add nomrulist to "restrict default"
nomrulist is redundant with the default noquery, but if a user removes
noquery, they will want nomrulist to avoid being a DDoS amplifier.
Closes: 1108327
Thanks: Dave Hart <davehart@gmail.com>
commit 91c1810fbc64332297cd79b1faea051706bcd26a
Author: Richard Laager <rlaager@debian.org>
Date: Sat Feb 7 16:44:42 2026 -0600
ntpsec-systemd-netif.service: Conditionalize...
... on the existence of the hook
As noted by Christoph Anton Mitterer <calestyo@scientia.org>,
"/etc/dhcp/dhclient-exit-hooks.d/ntpsec is a config file
so a user may simply delete it because he doesn't want it executed
for dhcp client. In that case it would also fail for
ntpsec-systemd-netif.service."
Closes: 1121536
commit 29a4024573cf9ec239b40ce8201511db35277fc9
Author: Christoph Anton Mitterer <calestyo@scientia.org>
Date: Sat Feb 7 16:41:14 2026 -0600
ntpsec-systemd-netif.service: Simplify /bin/sh
ntpsec-systemd-netif.service has:
ExecStart=/bin/sh -c '. /etc/dhcp/dhclient-exit-hooks.d/ntpsec'
First, why not simply /bin/sh /etc/dhcp/dhclient-exit-hooks.d/ntpsec?
Closes: 1121536
Signed-off-by: Richard Laager <rlaager@debian.org>
[LGTM. I have no idea why this was sourcing instead of executing.]
commit 1157c1d6bb6e9a2d36ecd2430c254ba1fea942e7
Author: Richard Laager <rlaager@debian.org>
Date: Sat Feb 7 16:38:57 2026 -0600
Refresh patches
Gbp-Dch: Ignore
commit d35e7ec791d7bb2e7c8c31012c9a3d9741b7be7c
Author: Richard Laager <rlaager@debian.org>
Date: Sat Feb 7 16:28:08 2026 -0600
Remove patches applied upstream
Gbp-Dch: Ignore
commit 667196062f093b1fb77ad173b715017eb417525b
Author: Richard Laager <rlaager@debian.org>
Date: Sat Feb 7 16:08:30 2026 -0600
New upstream version
commit 898516000707f411b40778b8ec891a82a341bd6d
Merge: 4c787641 e37f3a22
Author: Richard Laager <rlaager@debian.org>
Date: Sat Feb 7 17:24:54 2026 -0600
Update upstream source from tag 'upstream/1.2.4+dfsg'
Update to upstream version '1.2.4+dfsg'
with Debian dir 46571159e3b4cbcdb89217bbf647637f69bfe88a
commit 4c787641c33f4536ab08a084379e676986c22e55
Author: Richard Laager <rlaager@debian.org>
Date: Sat Feb 7 17:23:14 2026 -0600
README.source: s/dfsg1/dfsg/
This was missed in commit d93e99ec3ad70cd0cf89130122e62c64fa60af3a.
Gbp-Dch: Ignore
commit 1bce0ec98846310fe91d5809aec191b2ef4dc9cf
Author: Richard Laager <rlaager@debian.org>
Date: Sat Feb 7 16:07:41 2026 -0600
debian/watch: Use https instead of ftp
commit 4639291dc3b947177da1ab1593d287b0b191d987
Author: Richard Laager <rlaager@debian.org>
Date: Sat Feb 7 16:06:12 2026 -0600
Merge upstream signing keys
Gbp-Dch: Ignore
commit 4d768363df8291d839b7c1ac559a99fe15e31baf
Author: Richard Laager <rlaager@debian.org>
Date: Fri May 2 16:18:10 2025 -0500
Update changelog for release
Gbp-Dch: Ignore
commit cd83045eafa9b1f65ede69b146782892048cb54a
Author: Richard Laager <rlaager@debian.org>
Date: Fri May 2 16:15:39 2025 -0500
Set STA_UNSYNC on start
> When ntpd starts, it immediately resets the kernel status field to
> STA_PLL without STA_UNSYNC, before the clock is actually
> synchronized. This may mislead applications that use ntp_gettime()
> to check if the clock is synchronized.
>
> Also, the maxerror and esterror fields are set to 16 microseconds
> instead of 16 seconds.
See:
http://bugs.ntp.org/show_bug.cgi?id=3434
https://bugzilla.redhat.com/show_bug.cgi?id=1493452
https://gitlab.com/NTPsec/ntpsec/-/issues/848
Closes: 1103964
commit 6f85dc3c4cb3723c6fc720dc0223b08de295a31b
Author: Richard Laager <rlaager@debian.org>
Date: Mon Apr 14 23:53:02 2025 -0500
Update changelog for release
Gbp-Dch: Ignore
commit d25571fe6e2c7e405c91b69c3b248bda7ec387c2
Author: Richard Laager <rlaager@debian.org>
Date: Mon Apr 14 23:51:09 2025 -0500
Add ntpsec-ntpdig back to debian/.gitignore
This was improperly removed with the transitional packages in
commit 729de5c1a790b24fb4b26261704553bb99fbd60e.
Gbp-Dch: Ignore
commit 8053e6e3d6c362122238478b539c5d73272f0672
Author: Richard Laager <rlaager@debian.org>
Date: Mon Apr 14 23:45:04 2025 -0500
Disable libaes-siv test_malloc_failure
This breaks on some platforms, including Debian on s390x and apparently
OpenSUSE. This is using OpenSSL's CRYPTO_set_mem_functions(), which is
documented as not working once allocations are made. It is the first
call in the program, so there doesn't seem to be much more we/I can do
about this.
Closes: 1102745
commit f2f2328236a1210762ffdcf0bf51bd69e01a21c6
Author: Richard Laager <rlaager@debian.org>
Date: Mon Apr 14 03:27:49 2025 -0500
Update changelog for release
Gbp-Dch: Ignore
commit a991b83987ce88a0b6e92aab9ed5e0521f88f19a
Author: Richard Laager <rlaager@debian.org>
Date: Mon Apr 14 03:16:41 2025 -0500
Specify PYTHONDIR/PYTHONARCHDIR at waf configure
While my system detects the paths correctly as
/usr/lib/python3/dist-packages/ntp, in the rebuild discussed in
bug #1102962, PYTHONDIR and PYTHONARCHDIR were detected as
/usr/local/lib/python3.13/dist-packages. Since the .install file hardcodes
the path anyway, there isn't really a downside of hardcoding these to
`waf configure`.
Closes: 1102962
commit 0fbf0e98cc718eef1d0e9dd31d9b14598a175242
Author: Richard Laager <rlaager@debian.org>
Date: Tue Apr 8 01:26:18 2025 +0000
Disable missing_breaks pipeline job
This job fails to take into account virtual packages, so it complains
that ntpsec does not Breaks: openntpd, when Conflicts: time-daemon does
that.
Gbp-Dch: Ignore
commit 4750ee0ecdf654360a268197f3cb357e982bd080
Author: Richard Laager <rlaager@debian.org>
Date: Tue Apr 8 00:55:14 2025 +0000
Update changelog for release
Gbp-Dch: Ignore
commit 52890335a019ccd201b807fe61751ecc1565bccd
Author: Richard Laager <rlaager@debian.org>
Date: Tue Apr 8 00:49:14 2025 +0000
Stop running with real-time priority
The -N option runs with the maximum possible SCHED_FIFO priority.
According to Felix Moessbauer, this could starve out kernel threads.
He said, "Some recent stalls of PREEMPT_RT systems we observed could
be related to this."
He further noted, "I checked a couple of other distros (OpenSuse 15.5,
Fedora 42) and all of them just run with default options (no change of
the priority)."
Closes: 1086000
commit c242f67c262980f43a23452f6e03ff73b46430c7
Author: Richard Laager <rlaager@debian.org>
Date: Tue Apr 8 00:40:52 2025 +0000
Backport more armhf fixes
Closes: 1091303
commit 30cf771ee55ee62b3ded696d46ca6932ef11f7a6
Author: Richard Laager <rlaager@debian.org>
Date: Sat Mar 1 00:39:55 2025 -0600
Update changelog for release
Gbp-Dch: Ignore
commit 729de5c1a790b24fb4b26261704553bb99fbd60e
Author: Richard Laager <rlaager@debian.org>
Date: Sat Mar 1 00:08:18 2025 -0600
Drop transitional packages
These are not longer needed.
Closes: 1072973
commit e7941f6733b896c0ae43d0f0a14ce58e09e328e7
Author: Richard Laager <rlaager@debian.org>
Date: Sat Mar 1 00:41:29 2025 -0600
Refresh patches to eliminate fuzz
Gbp-Dch: Ignore
commit f1e76eeca9df330a0cd8685081f727c8366b4e9d
Author: Richard Laager <rlaager@debian.org>
Date: Fri Feb 28 23:40:59 2025 -0600
Backport armhf fixes
I'm not sure that 0001-Remove-use-of-waf-define-NTP_SIZEOF_TIME_T.patch
is necessary, but it's still related to the whole issue of
sizeof(time_t). I wanted to get the whole set of fixes.
Closes: 1091303
commit 9f440b103e4e09bbdf34a7ec3685060a0316e943
Author: Richard Laager <rlaager@debian.org>
Date: Fri Feb 28 23:30:16 2025 -0600
Update leap-seconds.list URL
Closes: 1089713
commit 3ea27e8b4bfb7a9ed8b1b8a3b3d5527666fb14b7
Author: Joachim Kross <kross@kaffeeschluerfer.com>
Date: Tue Nov 26 22:15:24 2024 +0100
Leverage ntpd's hourly leap-seconds.list file check & auto reload
NTPsec inherited from NTP Classic that the daemon checks once every
hour whether a configured leap-seconds.list file has changed (change
of either mtime or ctime, or both), and automatically reloads it if
it has.
This present change leverages that mechanism to automatically reload
the file at ntpd runtime when the file is being updated twice a year,
rather than forcibly restarting ntpd upon every update to the
tzdata package, regardless of whether the leap-seconds.list file has
changed or not.
commit 24fbf1be0ba4adbecfbfe5c6502c2b397af6016a
Author: Joachim Kross <kross@kaffeeschluerfer.com>
Date: Fri Aug 30 15:44:32 2024 +0200
ntp.conf: Specific paths for NTS certificate/key
ntp.conf currently has placeholder strings where the paths
for the NTS certificate and key should go. Replace those
placeholders by specific paths as those are mentioned in
README.Debian, and hard-coded in the certbot deploy hook and
AppArmor profile.
Update README.Debian to reflect that, and other updates. E.g.,
TLS 1.3 is the minimum TLS version permitted by the RFC, so no
need to mention/set this explicitly anymore.
commit 58ff6e2797dcb48cf7ef7e885447c14f6f4a67af
Author: Joachim Kross <kross@kaffeeschluerfer.com>
Date: Fri Aug 30 14:35:43 2024 +0200
Docs: ntpdate no longer supports "-o"
commit 7556c4e9ee3089addd05d5da3e346492d0dc6c3c
Author: Richard Laager <rlaager@debian.org>
Date: Fri Feb 28 23:02:21 2025 -0600
Depend on python3-setuptools
Closes: 1080689
commit 63015ace006433d49db288e73c764f068c1aaf05
Author: Richard Laager <rlaager@debian.org>
Date: Fri Feb 28 23:00:55 2025 -0600
control: Run wrap-and-sort
Gbp-Dch: Ignore
There is 1 open security issue in trixie.
You can find information about how to handle this issue in the security team's documentation.