-
-
Notifications
You must be signed in to change notification settings - Fork 1.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fall 2020 security package update #4211
Comments
Proposal:
Thoughts? |
Before this, we should merge #4191 to fix the Makefile of openssl 1.0.1 and then rebase #4155 before continuing with the proposed list. I do not expect to publish mosquitto with the outdated openssl version, but I would like to see a working cross/openssl on the master before we switch to openssl 1.1.1. |
So do I understand well it is worth waiting for glib/gnutls/libgcrypt merge before building and testing again python+python3? |
Exactly as there are sub-dependencies that relies on this. But everything is building beautifully currently and addressing the last remaining bits such as spk package rev & changelogs. |
@ymartin59 I published synocli-net to the repo about 20 hours ago. It is shown in the web page but in the package center of my diskstations still the old version 1.4-4 is shown. And yes, I have activated the packages. Is there anything else that is missing or do we need to wait for a "cache update"? |
I noticed from time to time that it can take as much as 48h+ to finally see the new packages... |
There is a chance both combination of Package Center refresh period and Fastly caching configuration delay availability in users' DSM |
I think Mono also requires another build #3666 |
@th0ma7 When building fossil-scm, openssl PLIST libraries have not been included into package... No idea if it is a transient error when building, or if it is a trouble with build chain changes. |
I've just check with the
Along with matching dependency tree:
Although just noticed that there are many many files missing!!!
|
I just tried it against
Dependency tree looks good (although with a duplicate
Question is: could this affect other I recall looking into the Further testing:
|
I'll do a git-bisect and try to figure out where the issue is exactly... more to come with hopefully a fix shortly. Investigating and issue has been on-going for quite long... really really really long... We definitively need to rework the Findings so far (re-using/backporting
To the point where I downloaded the
|
I need help from somebody to tell me that I am completely mistaking and crazy...
Findings so far the issue has been going since at least March 2019.
|
BTW @ymartin59 let me know how if you need some help to deploy other packages. |
Foud a few cycles to publish |
@th0ma7 Do not hesitate to pick any package you are interested in. According to remaining list, most of them require "update" process to publish latest version. |
@hgy59 thnx for releasing |
There is a security alert for Openssl with a high risk classification reported. This is fixed in Openssl 1.1.1l. |
Closing this, as all remaining packages are covered by #4820. |
Issue for tracking all packages needing publishing following major updates to
openssl
,glib
,gnutls
&libgcrypt
adressing multiple security issues namely:Related PR:
openssl: update to version 1.1.1h #4155: Update openssl(merged)glib, gnutls and libgcrypt security updates #4010: Update glib, gnutls & libgcrypt(merged)Update & fix build of ruTorrent #4209: Update ruTorrent(merged, see Package updates below)Update synocli net #4195: Update synocli-net(merged)tvheadend: Update to git hash 9ed76c0 from Oct 11th 2020 #4218 Update to tvheadend(merged)Update mosquitto (todo: create new PR after merge of sourceforge.net toolchain & kernel location change #4115)Indirectly related PR:
make all-supported and all-default #4200: Update to(merged)make all-supported
with parallel build to ease publishingbitlbee: Remove obsolete package #4208: Remove bitlbee(merged)Package updates
BUG: error while loading shared libraries: libssl.so.1.1: cannot open shared object filefixed with fix fossil-scm build #4241)libmysqlclient
package fix native/libmysqlclient: Fix download URL to align against cross/* #4245 + libzmq duplicate removal Remove duplicate zeromq (libzmq) #4254)Packages with new revision due to openssl update (PR #4155)
First stage
Before or in parallel with updated packages above
Second Stage
Packages with new revision due to
glib
,gnutls
orlibgcrypt
(PR #4010)sshfs(part ofsynocli-net
)Packages with new revision due to
rutorrent
update (PR #4209)To be confirmed (issue #3666)
Packages set for removal (PR #4208)
The text was updated successfully, but these errors were encountered: