-
-
Notifications
You must be signed in to change notification settings - Fork 14.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
rsync: 3.3.0 -> 3.4.1 #373845
rsync: 3.3.0 -> 3.4.1 #373845
Conversation
Moving back to draft, the security fixes are in (#373784), this can take the long way in. I will re-target at |
I changed the target and added a fix for a regression (RsyncProject/rsync#702) introduced by one of the security fixes. We also might want the fix for RsyncProject/rsync#704 before moving forward with this. |
rsync 3.4.1 was released with the regression fixed. |
Bumped to 3.4.1 with the regression fix. Flagged the PR as security related, out of caution, for the new use-after-free even if it does not look exploitable. |
It might be worthwhile to cite this confirmation in the commit message for future reference, as I can't immediately find anything. |
Follow-up to edccf51. Changes: https://github.com/RsyncProject/rsync/blob/v3.4.1/NEWS.md The PGP key change is expected and has been confirmed by the maintainers. In a effort to provide traceability the new key has been signed by Wayne Davison, another rsync maintainer, see https://keyserver.ubuntu.com/pks/lookup?op=get&search=0x6c859fb14b96a8c5
AFAIK no public communication has been done but this has been confirmed in private channels and the key has been signed by an existing rsync maintainer. I edited the commit message to mention the publicly verifiable information. |
Successfully created backport PR for |
(cherry picked from commit 0c5891d)
Also picked to staging-next PR #371501 |
Follow-up to edccf51.
Changes:
https://github.com/RsyncProject/rsync/blob/v3.4.1/NEWS.md
The PGP key change is expected and has been confirmed by the maintainers.
In a effort to provide traceability the new key has been signed by Wayne Davison,
another rsync maintainer, see https://keyserver.ubuntu.com/pks/lookup?op=get&search=0x6c859fb14b96a8c5 (or other keyservers...)
Things done
nix.conf
? (See Nix manual)sandbox = relaxed
sandbox = true
nix-shell -p nixpkgs-review --run "nixpkgs-review rev HEAD"
. Note: all changes have to be committed, also see nixpkgs-review usage./result/bin/
)Add a 👍 reaction to pull requests you find important.