Debian Patches

Status for fail2ban/1.1.1-1

Patch Description Author Forwarded Bugs Origin Last update
deb_init_paths Use Debian paths in the sysvinit script Point the init script at /usr/bin/fail2ban-client rather than the
upstream /usr/local/bin default, and use /run rather than the
deprecated /var/run for the socket and runtime directory.

===================================================================
Yaroslav Halchenko <debian@onerussian.com> not-needed 2026-09-07
deb_manpages_reportbug tune ups in upstream manpages to direct users to use reportbug
===================================================================
Yaroslav Halchenko <debian@onerussian.com> not-needed 2026-09-07
0002-ENH-verify-that-use_stock_cfg-was-not-provided-while.patch [PATCH 2/4] ENH: verify that use_stock_cfg was not provided while overriding it

Just found this possibly confusing to outside programmer aspect
so decided to make it more explicit
Yaroslav Halchenko <debian@onerussian.com> no 2026-09-07
deb_no_iptables_service Remove all non-provided .service's within PartOf of fail2ban.service
As reported and corroborated in the bug report, this causes inability
of firewalld to restart.
Correct solution would involve making systemd smarter and tune up
of involved .service files.
Since Debian ATM doesn't provide any of those ({ip{,6}tables,ipset}.service)
files, it should be safe and generic enough to just prune them from PartOf

Thanks Joe Cooper <swelljoe@gmail.com> and Sunil Mohan Adapa <sunil@medhas.org>
for the reports and nagging ;)


===================================================================
Yaroslav Halchenko <debian@onerussian.com> not-needed debian Fedora, Debian 2018-04-04
roundcube.diff Ignore roundcube IMAP connection-refused errors The roundcube-auth filter matches on "IMAP Error" lines. When the IMAP
server is down roundcube logs "Could not connect to ... Connection refused"
for every request, which is not an authentication failure; ignore it so a
local IMAP outage does not produce spurious bans.

===================================================================
Sylvestre Ledru <sylvestre@debian.org> no 2026-09-07
update_backend_system.diff Debian-specific paths and log backends On Debian these services log through syslog to the journal, so reading the
journal is more reliable than tailing files that may not exist.
.
Also correct two paths that upstream defaults do not match on Debian:
syslog_local0, since Debian's rsyslog writes /var/log/syslog rather than
/var/log/messages, and asterisk_log, since Asterisk 19 changed the default
logger.conf target from messages to messages.log.

===================================================================
Sylvestre Ledru <sylvestre@debian.org> not-needed debian 2026-09-07
deb_sshd_journalmatch.diff Match the Debian sshd systemd unit name Debian ships the OpenSSH server unit as ssh.service (sshd.service is only
an Alias), so the journal's _SYSTEMD_UNIT field carries "ssh.service".
Upstream's journalmatch looks for sshd.service and therefore never matches
on Debian.

===================================================================
Sylvestre Ledru <sylvestre@debian.org> not-needed 2026-09-07
deb_asterisk_log_path.diff Make the asterisk log path configurable via paths-*.conf jail.conf hard-codes /var/log/asterisk/messages, which cannot be overridden
from a distribution paths file. Introduce an asterisk_log variable in
paths-common.conf, keeping the existing value as the default, so that
paths-debian.conf can point it at the file Debian's Asterisk actually writes.

===================================================================
Dale Richards <dale@dalerichards.net> no debian 2026-09-07

All known versions for source package 'fail2ban'

Links