Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 930000 - net-misc/rabbitmq-server-3.13.1 stabilization request
Summary: net-misc/rabbitmq-server-3.13.1 stabilization request
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Stabilization (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Ultrabug
URL:
Whiteboard:
Keywords: CC-ARCHES
Depends on: 930133
Blocks: CVE-2023-46118
  Show dependency tree
 
Reported: 2024-04-14 10:11 UTC by tomas charvat
Modified: 2024-04-23 09:03 UTC (History)
4 users (show)

See Also:
Package list:
=dev-lang/elixir-1.15.7 =net-misc/rabbitmq-server-3.13.1 amd64 x86
Runtime testing required: ---
nattka: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description tomas charvat 2024-04-14 10:11:53 UTC
dev-lang/elixir is build time dependency of net-misc/rabbitmq-server.
Current stable net-misc/rabbitmq-server-3.11.2-r1 is Vulnerable (https://bugs.gentoo.org/918527) and also EOL
Current stable dev-lang/elixir-1.14.3-r1 doesnt have active support from Sep 2022. https://endoflife.date/elixir

Unstable net-misc/rabbitmq-server-3.12.9 works fine and pull-in erlang-26
Erlang's CLI utils (built by elixir) works, but dev-lang/elixir-1.14.3-r1 is limited to <erlang-26. https://hexdocs.pm/elixir/compatibility-and-deprecations.html#compatibility-between-elixir-and-erlang-otp

To move away from erlang version conflict and EOL software, stabilization of dev-lang/elixir-1.15.7 will allow stabilization of net-misc/rabbitmq-server-3.12.9 that will allow use of erlang-26 and abandon erlang-25.


Reproducible: Always
Comment 1 Matthew Smith gentoo-dev 2024-04-16 07:18:04 UTC
Adding RabbitMQ too. After new Elixir and Rabbit are stable, we can mask the old vulnerable versions of both RabbitMQ and Erlang.
Comment 2 Arthur Zamarin archtester Gentoo Infrastructure gentoo-dev Security 2024-04-16 16:31:14 UTC
ppc done
Comment 3 Joonas Niilola gentoo-dev 2024-04-17 08:45:51 UTC
x86 done
Comment 4 Joonas Niilola gentoo-dev 2024-04-18 05:41:59 UTC
amd64 done

all arches done