From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B806BC982D6 for ; Thu, 17 Sep 2026 14:33:13 +0000 (UTC) Subject: Re: [wrynose][patch] rsync: Security fixes from v3.4.1-sec-patches3 To: openembedded-core@lists.openembedded.org From: "Siddharth Doshi" X-Originating-Location: Rajkot, Gujarat, IN (157.32.46.1) X-Originating-Platform: Linux Chrome 151 User-Agent: GROUPS.IO Web Poster MIME-Version: 1.0 Date: Thu, 17 Sep 2026 07:33:11 -0700 References: <20260917105551.76512-1-vanusuri@mvista.com> <9faaa5bbc70d619058d8abecda9cd235d210d422.camel@pbarker.dev> In-Reply-To: Message-ID: <546192.1789655591562202413@lists.openembedded.org> Content-Type: multipart/alternative; boundary="ll0T9SEUipqLUJlVtzEj" List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 14:33:13 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246070 --ll0T9SEUipqLUJlVtzEj Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Hi Yoann, Paul and Vijay, v3.4.1-sec-patches3 and v3.2.7-sec-patches3 both the branches are part of o= fficial security release afaik. these versions corresponds to ubuntu/launchpad PPA for racoon and noble res= pectively so i see them being maintained till 2031 and 2029 atleast(unless = ubuntu decides on bumping those versions up in unforseen situations). with that being said, yes it is trade-off between maintaining 34 kLOC patch= and minor upgrade which we need to figure out. upgrading to 3.4.4 is less favourable as it still leaves 33 CVE's open and = for that we would still have a larger patch to maintain rather than patches= getting applied directly. Since rsync does not expose an architecture-wide library ( librsync is a co= mpletely distinct project), upgrading it will *never break the ABI of other= compiled packages* in rootfs. No other binary links against rsync dynamica= lly at the linker level. on top of it, rsync is maintaining backword compat= ability. So upgrading to 3.5.x wouldn't be an issue too. To talk about the regressions in 3.5.0, they are being fixed in 3.5.1 which= is planned to release on 21st september. we have 2 ways in front of us: 1) maintain the 34 kLOC patch for 3.4.1. Pros: we will mostly have maintainence till 2031( 1 year more than wrynose = EOL). cons: large patches to be maintained. (we can locally tar it though but sti= ll has to be maintained) 2) upgrade the 3.5.1 Pros: no need to maintain large patches and we would be in line with upstre= am. Cons: we will be violating the stable upgrade policy of no new features and= there are chances we would encounter same situation in future when more CV= E's are found affecting the newer version. i am fine with either of the way as one of fellow contributor. But, let me = know your thoughts. Regards, Siddharth --ll0T9SEUipqLUJlVtzEj Content-Type: text/html; charset="utf-8" Content-Transfer-Encoding: quoted-printable
Hi Yoann, Paul and Vijay,

v3.4.1-sec-patches3 and v3.2.7-sec-patches3 both the bra= nches are part of official security release afaik.

these versions corresponds to ubuntu/launchpad PPA for racoon and nobl= e respectively so i see them being maintained till 2031 and 2029 atleast(un= less ubuntu decides on bumping those versions up in unforseen situations).<= br />
with that being said, yes it is trade-off between maintaining 34 kLOC patch and minor upgrade which we need to figure out.
u= pgrading to 3.4.4 is less favourable as it still leaves 33 CVE's open and f= or that we would still have a larger patch to maintain rather than patches = getting applied directly.

Since rsync does not expose an architecture-wide l= ibrary (librsync is a completely distinct project), upgrading it will never br= eak the ABI of other compiled packages in rootfs= . No other binary links against rsy= nc dynamically at the linker level. on top of it, = rsync is maintaining backword compatability. So upgrading to 3.5.x wouldn't= be an issue too.

To talk about the regressions in 3.5.0, they a= re being fixed in 3.5.1 which is planned to release on 21st september.

we have 2 ways in front of us:
1) maintain the 34 kL= OC patch for 3.4.1.
Pros: we will mostly have maintainence till 2031(= 1 year more than wrynose EOL).
cons: large patches to be maintained.= (we can locally tar it though but still has to be maintained)

2= ) upgrade the 3.5.1
Pros: no need to maintain large patches and we wou= ld be in line with upstream.
Cons: we will be violating the stable upg= rade policy of no new features and there are chances we would encounter sam= e situation in future when more CVE's are found affecting the newer version= .

i am fine with either of the way as one of fellow contributor.= But, let me know your thoughts.

Regards,
Siddharth
<= /span>
--ll0T9SEUipqLUJlVtzEj--