From: "Girar pender (tulskijms)" <girar-builder@altlinux.org>
To: Maxim Tulskiy <tulskijms@altlinux.org>
Cc: sisyphus-incominger@lists.altlinux.org,
Alexandr Shashkin <dutyrok@altlinux.org>,
girar-builder-sisyphus@altlinux.org
Subject: [#415927] DONE (try 3) openbao.git=2.5.3-alt1
Date: Wed, 22 Apr 2026 15:10:12 +0000
Message-ID: <girar.task.415927.3.3@gyle.mskdc.altlinux.org> (raw)
In-Reply-To: <girar.task.415927.1.1@gyle.mskdc.altlinux.org>
https://git.altlinux.org/tasks/archive/done/_406/415927/logs/events.3.3.log
https://packages.altlinux.org/tasks/415927
subtask name aarch64 i586 x86_64
#200 openbao 5:24 2:39 2:38
2026-Apr-22 15:04:25 :: task #415927 for sisyphus resumed by tulskijms:
#100 removed
#200 build 2.5.3-alt1 from /people/tulskijms/packages/openbao.git fetched at 2026-Apr-22 10:10:22
2026-Apr-22 15:04:27 :: [i586] #200 openbao.git 2.5.3-alt1: build start
2026-Apr-22 15:04:27 :: [aarch64] #200 openbao.git 2.5.3-alt1: build start
2026-Apr-22 15:04:27 :: [x86_64] #200 openbao.git 2.5.3-alt1: build start
2026-Apr-22 15:04:34 :: [i586] #200 openbao.git 2.5.3-alt1: build OK (cached)
2026-Apr-22 15:04:35 :: [x86_64] #200 openbao.git 2.5.3-alt1: build OK (cached)
2026-Apr-22 15:04:44 :: [aarch64] #200 openbao.git 2.5.3-alt1: build OK (cached)
2026-Apr-22 15:04:44 :: 200: build check OK (cached)
2026-Apr-22 15:04:45 :: build check OK
2026-Apr-22 15:04:53 :: #200: openbao.git 2.5.3-alt1: version check OK
2026-Apr-22 15:04:53 :: build version check OK
2026-Apr-22 15:05:22 :: noarch check OK
2026-Apr-22 15:05:24 :: plan: src +1 -1 =22023, aarch64 +2 -2 =39018, i586 +2 -2 =36789, x86_64 +2 -2 =40057
#200 openbao 2.5.2-alt1 -> 2.5.3-alt1
Wed Apr 22 2026 Maxim Tulskiy <tulskijms@altlinux> 2.5.3-alt1
- Updated to new version 2.5.3.
- Fixes:
+ CVE-2026-39388: prevent token renewal with different-but-valid certificate (auth/cert)
+ CVE-2026-40264: prevent cross-namespace token renewal, revocation by accessor (auth/token)
+ CVE-2026-5807: disallow unauthenticated cancellation of sys/generate-root/* (core)
+ CVE-2026-3605: forbid request path traversal using . and .. segments (core)
+ CVE-2026-39396: validate and restrict downloaded plugin binary size from OCI images (core/plugins).
+ CVE-2026-39946: correctly quote schema name in revoke statement (database/postgresql)
2026-Apr-22 15:05:24 :: openbao: fixes vulnerabilities: CVE-2026-39388 CVE-2026-40264 CVE-2026-5807 CVE-2026-3605 CVE-2026-39396 CVE-2026-39946
2026-Apr-22 15:06:14 :: patched apt indices
2026-Apr-22 15:06:27 :: created next repo
2026-Apr-22 15:06:38 :: duplicate provides check OK
2026-Apr-22 15:07:24 :: dependencies check OK
2026-Apr-22 15:08:03 :: [x86_64 i586 aarch64] ELF symbols check OK
2026-Apr-22 15:08:12 :: [i586] #200 openbao: install check OK (cached)
2026-Apr-22 15:08:13 :: [x86_64] #200 openbao: install check OK (cached)
2026-Apr-22 15:08:15 :: [i586] #200 openbao-debuginfo: install check OK (cached)
2026-Apr-22 15:08:16 :: [x86_64] #200 openbao-debuginfo: install check OK (cached)
2026-Apr-22 15:08:20 :: [aarch64] #200 openbao: install check OK (cached)
2026-Apr-22 15:08:28 :: [aarch64] #200 openbao-debuginfo: install check OK (cached)
2026-Apr-22 15:08:49 :: [x86_64-i586] generated apt indices
2026-Apr-22 15:08:49 :: [x86_64-i586] created next repo
2026-Apr-22 15:09:03 :: [x86_64-i586] dependencies check OK
2026-Apr-22 15:09:03 :: gears inheritance check OK
2026-Apr-22 15:09:04 :: srpm inheritance check OK
girar-check-perms: access to openbao ALLOWED for dutyrok: approved builder
check-subtask-perms: #200: openbao: approved by dutyrok
2026-Apr-22 15:09:04 :: acl check OK
2026-Apr-22 15:09:19 :: created contents_index files
2026-Apr-22 15:09:29 :: created hash files: aarch64 i586 src x86_64
2026-Apr-22 15:09:33 :: task #415927 for sisyphus TESTED
2026-Apr-22 15:09:33 :: task is ready for commit
2026-Apr-22 15:09:40 :: repo clone OK
2026-Apr-22 15:09:41 :: packages update OK
2026-Apr-22 15:09:51 :: [x86_64 i586 aarch64] update OK
2026-Apr-22 15:09:51 :: repo update OK
2026-Apr-22 15:10:07 :: repo save OK
2026-Apr-22 15:10:07 :: src index update OK
2026-Apr-22 15:10:08 :: updated /gears/o/openbao.git branch `sisyphus'
2026-Apr-22 15:10:12 :: gears update OK
2026-Apr-22 15:10:12 :: task #415927 for sisyphus DONE
prev parent reply other threads:[~2026-04-22 15:10 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-04-22 9:09 [#415927] EPERM openbao.git=2.5.3-alt1 Girar awaiter (tulskijms)
2026-04-22 10:21 ` [#415927] EPERM (try 2) openbao.git=2.5.3-alt1 Girar awaiter (tulskijms)
2026-04-22 15:10 ` Girar pender (tulskijms) [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=girar.task.415927.3.3@gyle.mskdc.altlinux.org \
--to=girar-builder@altlinux.org \
--cc=devel@lists.altlinux.org \
--cc=dutyrok@altlinux.org \
--cc=girar-builder-sisyphus@altlinux.org \
--cc=sisyphus-incominger@lists.altlinux.org \
--cc=tulskijms@altlinux.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
ALT Linux Girar Builder robot reports
This inbox may be cloned and mirrored by anyone:
git clone --mirror http://lore.altlinux.org/sisyphus-incominger/0 sisyphus-incominger/git/0.git
# If you have public-inbox 1.1+ installed, you may
# initialize and index your mirror using the following commands:
public-inbox-init -V2 sisyphus-incominger sisyphus-incominger/ http://lore.altlinux.org/sisyphus-incominger \
sisyphus-incominger@lists.altlinux.org sisyphus-incominger@lists.altlinux.ru sisyphus-incominger@lists.altlinux.com
public-inbox-index sisyphus-incominger
Example config snippet for mirrors.
Newsgroup available over NNTP:
nntp://lore.altlinux.org/org.altlinux.lists.sisyphus-incominger
AGPL code for this site: git clone https://public-inbox.org/public-inbox.git