Openembedded Core Discussions
 help / color / mirror / Atom feed
From: Paul Barker <paul@pbarker.dev>
To: Yoann Congal <yoann.congal@smile.fr>,
	vanusuri@mvista.com,  openembedded-core@lists.openembedded.org
Subject: Re: [OE-core][wrynose][patch] rsync: Security fixes from v3.4.1-sec-patches3
Date: Thu, 17 Sep 2026 13:51:37 +0100	[thread overview]
Message-ID: <9faaa5bbc70d619058d8abecda9cd235d210d422.camel@pbarker.dev> (raw)
In-Reply-To: <DLHLDE6HLTRH.2AFGSZ80URG52@smile.fr>

On Thu, 2026-09-17 at 14:31 +0200, Yoann Congal wrote:
> On Thu Sep 17, 2026 at 1:38 PM CEST, Yoann Congal wrote:
> > On Thu Sep 17, 2026 at 12:55 PM CEST, Vijay Anusuri via lists.openembedded.org wrote:
> > > Backport the security fixes from the upstream v3.4.1-sec-patches3
> > > branch to address the known rsync security vulnerabilities.
> > > 
> > > The v3.4.1-sec-patches3 branch contains 239 commits. The GitHub
> > > workflow commits (037, 038, and 160), which only modify
> > > .github/workflows files, and the testsuite-only commits (238 and
> > > 239) are excluded because they are not applicable to the Yocto
> > > build.
> > > 
> > > The remaining 237 security fixes are combined into a single patch
> > > series and applied on top of the rsync 3.4.1 source.
> > > 
> > > SUSE has also backported these security fixes to rsync-3.4.1-160000.6.1
> > > to address the corresponding CVEs.
> > > 
> > > References:
> > > 
> > > https://rsync.samba.org/security.html
> > > https://github.com/RsyncProject/rsync/tree/v3.4.1-sec-patches3
> > > https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-53802
> > > 
> > > This fix handles CVE-2025-10158 CVE-2026-29518 CVE-2026-43617 CVE-2026-43618 CVE-2026-43619 CVE-2026-43620 CVE-2026-45232 CVE-2026-44507 CVE-2026-44508 CVE-2026-44509 CVE-2026-44510 CVE-2026-53783 CVE-2026-53784 CVE-2026-53785 CVE-2026-53786 CVE-2026-53788 CVE-2026-53789 CVE-2026-53790 CVE-2026-53791 CVE-2026-53792 CVE-2026-53793 CVE-2026-53794 CVE-2026-53795 CVE-2026-53796 CVE-2026-53797 CVE-2026-53798 CVE-2026-53799 CVE-2026-53800 CVE-2026-53801 CVE-2026-53802 CVE-2026-53803 CVE-2026-70452 CVE-2026-70453 CVE-2026-70454 CVE-2026-70455 CVE-2026-70456 CVE-2026-70457 CVE-2026-70458 CVE-2026-70459 CVE-2026-70460 CVE-2026-70461 CVE-2026-70462 CVE-2026-70463 CVE-2026-70464
> > > 
> > > Dropped CVE-2025-10158.patch
> > > Refreshed the patch 0001-Add-missing-prototypes-to-function-declarations.patch
> > > 
> > > Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
> > > ---
> > >  ...-prototypes-to-function-declarations.patch |    81 +-
> > >  .../rsync/files/CVE-2025-10158.patch          |    36 -
> > >  .../files/rsync-3.4.1-sec-patches3.patch      | 34052 ++++++++++++++++
> > >  meta/recipes-devtools/rsync/rsync_3.4.1.bb    |     2 +-
> > >  4 files changed, 34071 insertions(+), 100 deletions(-)
> > >  delete mode 100644 meta/recipes-devtools/rsync/files/CVE-2025-10158.patch
> > >  create mode 100644 meta/recipes-devtools/rsync/files/rsync-3.4.1-sec-patches3.patch
> > 
> > Hello,
> > 
> > I don't think I want to carry a 34000 lines patch.
> > 
> > Does the rsync project released a v3.4.1-sec-patches3 archive?
> > 
> > If not, can we try to switch the recipe to git and point SRCREV to the
> > "rsync-3.4.1-sec-patches" branch?
> > Since the recipe is not git-based now, we'll need to switch to git
> > first, then upgrade.
> 
> Paul asked a good question about this idea though: How official is this
> branch?
> Can you ask upstream the status of it? Will it stay published? Will we
> see v3.4.1-sec-patches4,5... branches someday?

Hi Yoann, Vijay,

Some thoughts here...

The upgrade to v3.4.3 was rejected [1] due to a few minor feature
additions. In this case it may be lower risk to take an upgrade rather
than backporting a 34 kLOC patch. I think we should avoid v3.5.0 due to
the number of regressions reported [2]. v3.4.4 is an option. We can then
see how many CVEs remain open and decide what to do about them.

The onus here is on contributors, not on Yoann as stable maintainer. To
go ahead we would need some investigation, testing and a proposal to the
TSC to approve the update as an exception to our usual stable policy.

[1]: https://lore.kernel.org/all/DL0HY2YT9WGM.3ACOQJL408XKI@smile.fr/
[2]: https://github.com/RsyncProject/rsync/issues?q=is%3Aissue%20%223.5.0%22

Best regards,

-- 
Paul Barker



  reply	other threads:[~2026-09-17 12:51 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20260917105551.76512-1-vanusuri@mvista.com>
2026-09-17 11:38 ` [OE-core][wrynose][patch] rsync: Security fixes from v3.4.1-sec-patches3 Yoann Congal
2026-09-17 12:31   ` Yoann Congal
2026-09-17 12:51     ` Paul Barker [this message]
2026-09-17 14:00       ` Vijay Anusuri
2026-09-17 14:33         ` [wrynose][patch] " Siddharth Doshi
2026-09-21 10:26           ` [OE-core] " Vijay Anusuri
2026-09-21 19:52             ` Paul Barker
2026-10-08  8:40               ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=9faaa5bbc70d619058d8abecda9cd235d210d422.camel@pbarker.dev \
    --to=paul@pbarker.dev \
    --cc=openembedded-core@lists.openembedded.org \
    --cc=vanusuri@mvista.com \
    --cc=yoann.congal@smile.fr \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox