Samba 4.1.18 Available for Download

                   Release Notes for Samba 4.1.18
                            May 12, 2015

This is the latest stable release of Samba 4.1.

Changes since 4.1.17:

o   Michael Adam <>
    * BUG 8905: s3:winbind:grent: Don't stop group enumeration when a group has
      no gid.
    * BUG 11058: cli_connect_nb_send: don't segfault on host == NULL.
    * BUG 11117: vfs_glusterfs manpage corrections.
    * BUG 11143: s3-winbind: Fix chached user group lookup of trusted domains.

o   Jeremy Allison <>
    * BUG 10016: Fix NTLM authentication.
    * BUG 10888: s3: client - "client use spnego principal = yes" code checks
      wrong name.
    * BUG 11079: s3: lib: libsmbclient: If reusing a server struct, check every
      cli->timout miliseconds if it's still valid before use.
    * BUG 11094: s3: smbclient: Allinfo leaves the file handle open.
    * BUG 11144: Fix memory leak in SMB2 notify handling.
    * BUG 11173: s3: libcli: smb1: Ensure we correctly finish a tevent req if
      the writev fails in the SMB1 case.
    * BUG 11177: s3: libsmbclient: Add missing talloc stackframe.
    * BUG 11186: s3: libsmbclient: After getting attribute server, ensure main
      srv pointer is still valid.
    * BUG 11187: s3: Mac OS X 10.10.x fails validate negotiate request to 4.1.x.
    * BUG 11236: s4: rpc: Refactor dcesrv_alter() function into setup and send
    * BUG 11240: s3: smbd: Incorrect file size returned in the response of
      "FILE_SUPERSEDE Create".
    * BUG 11254: s3: nmbd: Don't set work_changed = True inside

o   Andrew Bartlett <>
    * BUG 11100: debug: Set close-on-exec for the main log file FD.

o   Ralph Boehme <>
    * BUG 11224: s3:smbd: Missing tevent_req_nterror.
    * BUG 11243: vfs: kernel_flock and named streams.

o   Ira Cooper <>
    * BUG 11069: vfs_glusterfs: Add comments to the pipe(2) code.
    * BUG 11115: smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT.

o   Günther Deschner <>
    * BUG 10240: vfs: Add glusterfs manpage.

o   David Disseldorp <>
    * BUG 10808: printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD.
    * BUG 11018: smbd can't find the GUID for a printer in the registry and
      fails to publish printers.
    * BUG 11059: libsmb: Provide authinfo domain for encrypted session
    * BUG 11169: docs/idmap_rid: Remove deprecated base_rid from example.
    * BUG 11210: spoolss: Purge the printer name cache on name change.

o   Julien Kerihuel <>
    * BUG 11225: s4:rpc_server: Add multiplex state to dcerpc flags and control
      over multiplex PFC flag in bind_ack and and dcesrv_alter replies.
    * BUG 11226: Fix terminate connection behavior for asynchronous endpoint
      with PUSH notification flavors.

o   Volker Lendecke <>
    * BUG 11041: smbd: Fix CID 1063259 Uninitialized scalar variable.
    * BUG 11051: net: Fix 'net sam addgroupmem'.

o   Stefan Metzmacher <>
    * BUG 9702: s3:smb2_server: protect against integer wrap with "smb2 max
      credits = 65535".
    * BUG 11144: Fix memory leak in SMB2 notify handling.
    * BUG 11164: s4:auth/gensec_gssapi: let gensec_gssapi_update() return
      NT_STATUS_LOGON_FAILURE for unknown errors.

o   Andreas Schneider <>
    * BUG 10984: spoolss: Clear PrinterInfo on GetPrinter error.
    * BUG 11008: s3-util: Fix authentication with long hostnames.
    * BUG 11037: s3-libads: Fix a possible segfault in kerberos_fetch_pac().
    * BUG 11058: utils: Fix 'net time' segfault.
    * BUG 11066: s3-pam_smbpass: Fix memory leak in pam_sm_authenticate().
    * BUG 11127: doc-xml: Add 'sharesec' reference to 'access based share enum'.
    * BUG 11180: s4-process_model: Do not close random fds while forking.
    * BUG 11185: s3-passdb: Fix 'force user' with winbind default domain.

o   Richard Sharpe <>
    * BUG 11234: Fix crash in 'net ads dns gethostbyname' with an error in TALLOC_FREE
      if you enter invalid values.