* [#416017] p11 EPERM openbao.git=2.5.3-alt1
@ 2026-04-22 19:28 Girar awaiter (tulskijms)
0 siblings, 0 replies; only message in thread
From: Girar awaiter (tulskijms) @ 2026-04-22 19:28 UTC (permalink / raw)
To: Maxim Tulskiy; +Cc: sisyphus-incominger, girar-builder-p11, girar-builder-p11
https://git.altlinux.org/tasks/416017/logs/events.1.1.log
https://packages.altlinux.org/tasks/416017
subtask name aarch64 i586 x86_64
#100 openbao 5:54 3:59 3:52
2026-Apr-22 19:17:39 :: task #416017 for p11 started by tulskijms:
2026-Apr-22 19:17:39 :: message: Fixes: CVE-2026-39388, CVE-2026-40264, CVE-2026-5807, CVE-2026-3605, CVE-2026-39396, CVE-2026-39946
#100 build 2.5.3-alt1 from /people/tulskijms/packages/openbao.git fetched at 2026-Apr-22 19:12:34
2026-Apr-22 19:17:41 :: [aarch64] #100 openbao.git 2.5.3-alt1: build start
2026-Apr-22 19:17:41 :: [i586] #100 openbao.git 2.5.3-alt1: build start
2026-Apr-22 19:17:41 :: [x86_64] #100 openbao.git 2.5.3-alt1: build start
2026-Apr-22 19:21:33 :: [x86_64] #100 openbao.git 2.5.3-alt1: build OK
2026-Apr-22 19:21:40 :: [i586] #100 openbao.git 2.5.3-alt1: build OK
2026-Apr-22 19:23:35 :: [aarch64] #100 openbao.git 2.5.3-alt1: build OK
2026-Apr-22 19:23:48 :: 100: build check OK
2026-Apr-22 19:23:48 :: build check OK
2026-Apr-22 19:23:55 :: #100: openbao.git 2.5.3-alt1: version check OK
2026-Apr-22 19:23:55 :: build version check OK
2026-Apr-22 19:24:18 :: noarch check OK
2026-Apr-22 19:24:20 :: plan: src +1 -1 =20289, aarch64 +2 -2 =36282, i586 +2 -2 =34951, x86_64 +2 -2 =37251
#100 openbao 2.5.2-alt1 -> 2.5.3-alt1
Wed Apr 22 2026 Maxim Tulskiy <tulskijms@altlinux> 2.5.3-alt1
- Updated to new version 2.5.3.
- Fixes:
+ CVE-2026-39388: prevent token renewal with different-but-valid certificate (auth/cert)
+ CVE-2026-40264: prevent cross-namespace token renewal, revocation by accessor (auth/token)
+ CVE-2026-5807: disallow unauthenticated cancellation of sys/generate-root/* (core)
+ CVE-2026-3605: forbid request path traversal using . and .. segments (core)
+ CVE-2026-39396: validate and restrict downloaded plugin binary size from OCI images (core/plugins).
+ CVE-2026-39946: correctly quote schema name in revoke statement (database/postgresql)
2026-Apr-22 19:24:20 :: openbao: fixes vulnerabilities: CVE-2026-39388 CVE-2026-40264 CVE-2026-5807 CVE-2026-3605 CVE-2026-39396 CVE-2026-39946
2026-Apr-22 19:25:07 :: patched apt indices
2026-Apr-22 19:25:17 :: created next repo
2026-Apr-22 19:25:27 :: duplicate provides check OK
2026-Apr-22 19:26:06 :: dependencies check OK
2026-Apr-22 19:26:43 :: [x86_64 i586 aarch64] ELF symbols check OK
2026-Apr-22 19:26:59 :: [i586] #100 openbao: install check OK
2026-Apr-22 19:26:59 :: [x86_64] #100 openbao: install check OK
2026-Apr-22 19:27:08 :: [aarch64] #100 openbao: install check OK
2026-Apr-22 19:27:12 :: [i586] #100 openbao-debuginfo: install check OK
2026-Apr-22 19:27:12 :: [x86_64] #100 openbao-debuginfo: install check OK
2026-Apr-22 19:27:27 :: [aarch64] #100 openbao-debuginfo: install check OK
2026-Apr-22 19:27:46 :: [x86_64-i586] generated apt indices
2026-Apr-22 19:27:46 :: [x86_64-i586] created next repo
2026-Apr-22 19:27:58 :: [x86_64-i586] dependencies check OK
2026-Apr-22 19:27:59 :: gears inheritance check OK
2026-Apr-22 19:28:00 :: srpm inheritance check OK
girar-check-perms: access to openbao DENIED for tulskijms: does not belong to maintainers list yet
check-subtask-perms: #100: openbao: needs approvals from members of @maint and @tester groups
2026-Apr-22 19:28:01 :: acl check FAILED
2026-Apr-22 19:28:13 :: created contents_index files
2026-Apr-22 19:28:22 :: created hash files: aarch64 i586 src x86_64
2026-Apr-22 19:28:25 :: task #416017 for p11 EPERM
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-04-22 19:28 UTC | newest]
Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-04-22 19:28 [#416017] p11 EPERM openbao.git=2.5.3-alt1 Girar awaiter (tulskijms)
ALT Linux Girar Builder robot reports
This inbox may be cloned and mirrored by anyone:
git clone --mirror http://lore.altlinux.org/sisyphus-incominger/0 sisyphus-incominger/git/0.git
# If you have public-inbox 1.1+ installed, you may
# initialize and index your mirror using the following commands:
public-inbox-init -V2 sisyphus-incominger sisyphus-incominger/ http://lore.altlinux.org/sisyphus-incominger \
sisyphus-incominger@lists.altlinux.org sisyphus-incominger@lists.altlinux.ru sisyphus-incominger@lists.altlinux.com
public-inbox-index sisyphus-incominger
Example config snippet for mirrors.
Newsgroup available over NNTP:
nntp://lore.altlinux.org/org.altlinux.lists.sisyphus-incominger
AGPL code for this site: git clone https://public-inbox.org/public-inbox.git