linux-igd (1.0+cvs20070630-4) unstable; urgency=low

  * Apply patch 16 from Rob Lesley to fix use-after-free (Closes: #499827)
  * Apply hardening in line with Wheezy release goal, as we are a daemon
    and handle unsanitised input from the net.  Update *FLAGS in line
    with this to be supplied by dh_buildflags.
  * Update Policy to 3.9.3 (no change to package).

 -- Nick Leverton <>  Sat, 07 Jul 2012 21:54:47 +0100

linux-igd (1.0+cvs20070630-3) unstable; urgency=low

  * Use debhelper 7 and dh; update patch 02-makefile to support DESTDIR.
    Really compile with -O0 when "DEB_BUILD_OPTIONS=noopt" is specified.
  * Reformat patches for source 3.0 (Closes: #538576) and update to DEP-3.
  * Create a pidfile in initscript (Closes: #527144)
  * Update for Policy 3.8.1 to 3.8.4:
    Add --oknodo to start calls in case daemon was already running (3.8.1)
  * Update to current netfilter, thanks to OpenWRT for patches 001/2/3/4
  * Use standard include files for string.h etc (patch 07).
  * Update to use xtables functions when available (patch 08).
  * Update upnp.8 man page with current options (patch 09).
  * Update to current libupnp 1.8.x API instead of 1.6.x (patch 10).
  * Fix potential sprintf overrun just in case (patch 11).
  * Add upnp_log_filename and upnp_log_level options to enable the libupnp
    debug file, and use that file for our own debug logging (patch 13).
  * Some extra debugging, using the new libupnp debug file (patch 12, 14).
  * Use forward_rules_append option to append to PREROUTING also (patch
    15, Closes: #507313).

 -- Nick Leverton <>  Mon, 17 May 2010 11:43:21 +0100

linux-igd (1.0+cvs20070630-2) unstable; urgency=high

  * Don't sprintf from struct in_addr when 'paranoid' is enabled (Closes:
    #489565, "paranoid" option can result in segfaults).

 -- Nick Leverton <>  Mon, 07 Jul 2008 23:02:42 +0100

linux-igd (1.0+cvs20070630-1) unstable; urgency=low

  * New maintainer (Closes: #411875)
  * New upstream CVS (Closes: #436919, #436365), including important
    option name changes:
    - Renamed the insert_forward_rules option to create_forward_rules to
      better reflect what it actually does.
    - Added the forward_rules_append to do what people thought
      insert_forward_rules did.
    See /usr/share/doc/linux-igd/CHANGES.gz for further details.
  * For compatibility with upstream, the INT_IFACE and EXT_IFACE
    initscript variables have been renamed to INTIFACE and EXTIFACE.
  * Rename initscript and defaults from /etc/{init.d,default}/upnpd to
    /etc/*/linux-igd so that they match our package name.
  * Change initscript to do nothing until /etc/default/linux-igd is
    configured (Closes: #423189, #399960).
  * Add --oknodo to all "start-stop-daemon --stop" calls in initscript
    in case daemon wasn't running anyway (Closes: #415981).
  * Configurable CHROOT and USER/GROUP for daemon.
  * Add SECURITY note and sample conf for jailer chroot.
  * Add ALLOW_MULTICAST option for multicast routing setup (compatible
    with upstream).
  * Abstract the patch for #397572 from .diff.gz into separate quilt patch
  * New patch 02-makefile.diff for fixes to makefile
  * Patch 03-debian-bindtodevice.diff Closes: #441082 (linux-igd does not
    restrict itself to the internal interface) (with further fix from Eric
  * Honour CFLAGS in compilation (thanks Gianluigi Tiesi <> ).
  * Update watchfile as per Jochen Friedrich's suggestion.
  * Add paranoid flag to validate port forwarding requests.
  * Remove bashisms from initscript, make it dash-compatible.

 -- Nick Leverton <>  Fri, 04 Jul 2008 22:21:20 +0100

linux-igd (0.cvs20060201-1.1) unstable; urgency=medium

  * Non-maintainer upload.
  * Rename parse_port and service_to_port to my_parse_port and
    my_service_to_port respectively, as they crash with functions already
    defined in /usr/include/iptables.h; fixes FTBFS. (Closes: #397572)

 -- Steinar H. Gunderson <>  Wed, 15 Nov 2006 14:04:32 +0100

linux-igd (0.cvs20060201-1) unstable; urgency=low

  * Initial release (Closes: #328986)

 -- José Fonseca <>  Sun,  5 Mar 2006 13:51:39 +0000

