GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Natanael Copa (ncopa@fosstodon.org)'s status on Wednesday, 15-Jan-2025 17:57:45 JST Natanael Copa Natanael Copa

    rsync has some really serious CVEs[1], but the 3.4.0 release with the fixes has regressions[2] that will break things for people. What to do?

    [1]: https://www.openwall.com/lists/oss-security/2025/01/14/3
    [2]: https://github.com/RsyncProject/rsync/issues/702

    In conversation about 4 months ago from fosstodon.org permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.openwall.com
      oss-security - RSYNC: 6 vulnerabilities
    2. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      3.4.0 -H flag broken · Issue #702 · RsyncProject/rsync
      Consider the following rsync -aH: bob# rsync -aH bob:/opt/src/git-doc . ABORTING due to invalid path from sender: git-doc/.vale/vale.tmpl rsync: connection unexpectedly closed (322182 bytes receive...
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Wednesday, 15-Jan-2025 17:57:45 JST Rich Felker Rich Felker
      in reply to

      @ncopa "Mitigation: Disable SHA* support by compiling with
      CFLAGS=-DDISABLE_SHA512_DIGEST and CFLAGS=-DDISABLE_SHA256_DIGEST."

      In conversation about 4 months ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Wednesday, 15-Jan-2025 18:05:07 JST Rich Felker Rich Felker
      in reply to

      @ncopa Probably nothing but I'm not 100% sure how negotiation works.

      In conversation about 4 months ago permalink
    • Embed this notice
      Natanael Copa (ncopa@fosstodon.org)'s status on Wednesday, 15-Jan-2025 18:05:08 JST Natanael Copa Natanael Copa
      in reply to
      • Rich Felker

      @dalias what will break if I do that?

      In conversation about 4 months ago permalink
    • Embed this notice
      Natanael Copa (ncopa@fosstodon.org)'s status on Wednesday, 15-Jan-2025 23:47:28 JST Natanael Copa Natanael Copa
      in reply to

      The obvious answer is:

      - add the regression to the testsuite
      - fix the regression
      - submit a pull request
      - move on

      Too bad I have meetings...

      In conversation about 4 months ago permalink
    • Embed this notice
      Natanael Copa (ncopa@fosstodon.org)'s status on Wednesday, 15-Jan-2025 23:47:28 JST Natanael Copa Natanael Copa
      in reply to

      Someone else added a test to the test suite, good enough to help me git bisect and fix the issue.
      PR submitted: https://github.com/RsyncProject/rsync/pull/705

      In conversation about 4 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
        Fix FLAG_GOT_DIR_FLIST collission with FLAG_HLINKED by ncopa · Pull Request #705 · RsyncProject/rsync
        fixes commit 688f5c3 (Refuse a duplicate dirlist.) Fixes: #702 Fixes: #697
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Clayton (craftyguy@freeradical.zone)'s status on Thursday, 16-Jan-2025 01:11:35 JST Clayton Clayton
      in reply to

      @ncopa @fossdd lol... wow, what a mess.

      In conversation about 4 months ago permalink
    • Embed this notice
      Clayton (craftyguy@freeradical.zone)'s status on Thursday, 16-Jan-2025 01:11:36 JST Clayton Clayton
      in reply to
      • fossdd @ FOSDEM

      @fossdd @ncopa debian seems to have backported the fixes on bookworm for 3.2.7:
      https://security-tracker.debian.org/tracker/DSA-5843-1

      In conversation about 4 months ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        DSA-5843-1
    • Embed this notice
      Natanael Copa (ncopa@fosstodon.org)'s status on Thursday, 16-Jan-2025 01:11:36 JST Natanael Copa Natanael Copa
      in reply to
      • Clayton
      • fossdd @ FOSDEM

      @craftyguy @fossdd Then they have backported the regression and have a broken `rsync -aH`.

      Regression introduced with the fix for
      https://security-tracker.debian.org/tracker/CVE-2024-12087

      In conversation about 4 months ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        CVE-2024-12087
    • Embed this notice
      Natanael Copa (ncopa@fosstodon.org)'s status on Thursday, 16-Jan-2025 01:11:36 JST Natanael Copa Natanael Copa
      in reply to
      • Clayton
      • fossdd @ FOSDEM

      @craftyguy @fossdd yup. they do got the regression: https://github.com/RsyncProject/rsync/issues/697#issuecomment-2591892385

      In conversation about 4 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
        Internal hashtable error: illegal key supplied! (v3.4) · Issue #697 · RsyncProject/rsync
        With v3.4, getting error: Internal hashtable error: illegal key supplied! (no error with 3.3) MacOS 15.2
    • Embed this notice
      fossdd @ FOSDEM (fossdd@chaos.social)'s status on Thursday, 16-Jan-2025 01:11:38 JST fossdd @ FOSDEM fossdd @ FOSDEM
      in reply to

      @ncopa ah damn. why didnt they just created more patch releases for older releases

      In conversation about 4 months ago permalink
    • Embed this notice
      Natanael Copa (ncopa@fosstodon.org)'s status on Thursday, 16-Jan-2025 01:11:39 JST Natanael Copa Natanael Copa
      in reply to
      • fossdd @ FOSDEM

      @fossdd 6 of them. sure. but its gonna take time.

      In conversation about 4 months ago permalink
    • Embed this notice
      fossdd @ FOSDEM (fossdd@chaos.social)'s status on Thursday, 16-Jan-2025 01:11:40 JST fossdd @ FOSDEM fossdd @ FOSDEM
      in reply to

      @ncopa can you just patch the CVEs?

      In conversation about 4 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.