Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 626786 - =net-p2p/syncthing-0.14.38: stabilisation request
Summary: =net-p2p/syncthing-0.14.38: stabilisation request
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Stabilization (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Marek Szuba
URL:
Whiteboard:
Keywords: STABLEREQ
Depends on:
Blocks:
 
Reported: 2017-08-01 12:06 UTC by Marek Szuba
Modified: 2018-04-16 21:48 UTC (History)
3 users (show)

See Also:
Package list:
=net-p2p/syncthing-0.14.38
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marek Szuba archtester gentoo-dev 2017-08-01 12:06:34 UTC
Syncthing upstream releases new versions quite frequently so they might be hard to keep up but it would be nice to have at least one version marked stable... Not 0.14.30 though, it has a data race in KCP and STUN code. Conversely, the issues fixed by upstream since 0.14.32 seem to be pretty mild - so let's aim to stabilise 0.14.32.

The ebuild in question will become eligible for stabilisation on the 25th of August.
Comment 1 Marek Szuba archtester gentoo-dev 2017-08-09 15:07:50 UTC
Recently released syncthing-0.14.35 fixes a security vulnerability which allowed file overwrite via versioned symlinks, please see allows https://github.com/syncthing/syncthing/issues/4286 for details. I haven't seen any announcement regarding when that vulnerability was introduced, however looking at the code suggests it was there for quite a long time.

In light of the above the stabilisation target is now version 0.14.35, to become eligible for stabilisation on the 8th of September.
Comment 2 Dennis Schridde 2017-10-06 19:56:38 UTC
Recently, 0.14.38 has been released.
Comment 3 Marek Szuba archtester gentoo-dev 2017-10-11 21:00:57 UTC
Turns out 0.14.35 has got a fairly serious bug so we had better not stabilise it. Current candidate is therefore 0.14.38, to become eligible for stabilisation on the 6th of November. Third time is charm?
Comment 4 Thomas Deutschmann (RETIRED) gentoo-dev 2017-10-26 20:19:44 UTC
x86 stable
Comment 5 Jason Zaman gentoo-dev 2017-12-15 08:19:24 UTC
amd64 stable
Comment 6 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2018-04-16 21:48:54 UTC
arm stable