Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Plan release v3.5.10 #16733

Closed
serathius opened this issue Oct 10, 2023 · 12 comments
Closed

Plan release v3.5.10 #16733

serathius opened this issue Oct 10, 2023 · 12 comments

Comments

@serathius
Copy link
Member

serathius commented Oct 10, 2023

What would you like to be added?

List of issues reported for v3.5 since v3.5.9:

Why is this needed?

Ensure we collect and triage all issues that should be fixed before v3.5.10

@serathius
Copy link
Member Author

cc @ahrtr @wenjiaswe @jmhbnz
Prepared list of backports. Please check if anything is missing and if can help get them merged.

@ahrtr
Copy link
Member

ahrtr commented Oct 12, 2023

#16625 isn't enough to resolve CVE-2023-44487. It's just the first step. After the PR gets merged, we need to continue to upgrade grpc to one of 1.56.3 , 1.57.1 or 1.58.3

@serathius
Copy link
Member Author

serathius commented Oct 12, 2023

Yes, both #16625 #16743 are included in.

@Hendrik-H
Copy link

would be great if you could get a fix for #9533 in as well.

@serathius
Copy link
Member Author

serathius commented Oct 13, 2023

I would not block v3.5.10 release on #9533. Releases provide users with etcd binaries and docker images that they can use. For embedded server it's much easier to just change commit hash.

Contributions are still welcomed!

@serathius
Copy link
Member Author

Working on #16637, which is the last PR that was orignially proposed. I will review pending issues again and if there are not will push the release.

cc @ahrtr @jmhbnz
To double check issues that should be fixed.

@jmhbnz
Copy link
Member

jmhbnz commented Oct 17, 2023

Doing some quick review here is a shortcut link showing all our open pr's targeting release-3.5: https://github.com/etcd-io/etcd/pulls?q=is%3Apr+is%3Aopen+base%3Arelease-3.5+

I think we want to try to include #16781 as it is another step towards resolving CVE-2023-44487?

#16070 Is a very simple backport that we could consider including, I have already approved it so defer to maintainers on it.

@ahrtr
Copy link
Member

ahrtr commented Oct 17, 2023

To double check issues that should be fixed.

I think #16637 is nice to have, but definitely not a blocker for 3.5.10. It's caused by incorrect user operation (side by side recovery to an existing one). #15548 (comment).

@serathius
Copy link
Member Author

I think we want to try to include #16781 as it is another step towards resolving CVE-2023-44487?

Added #16781

@ahrtr
Copy link
Member

ahrtr commented Oct 23, 2023

All items in the list are resolved?

@serathius
Copy link
Member Author

Think so, will start the release as soon as I have some time.

@serathius
Copy link
Member Author

Done https://github.com/etcd-io/etcd/releases/tag/v3.5.10

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Development

No branches or pull requests

4 participants