Koozali.org: home of the SME Server

rsync update broke AFFA

Offline Gary Douglas

  • *
  • 68
  • +1/-0
rsync update broke AFFA
« on: September 02, 2022, 01:24:01 PM »
Updated an AFFA box with this morning's updates, it broke AFFA at the rsync phase.

Error (1389): Couldn't open /var/affa/svr/scheduled.running/home/e-smith/db/affa-rpmlist

---> Package rsync.x86_64 0:3.1.2-10.el7 will be updated
---> Package rsync.x86_64 0:3.1.2-11.el7_9 will be an update

yum downgrade rsync has it working again. I will do further testing before raising a bug

Offline Gary Douglas

  • *
  • 68
  • +1/-0
Re: rsync update broke AFFA
« Reply #1 on: September 02, 2022, 02:36:59 PM »
Looks like this is by design, not a bug.

%changelog
* Tue Aug 16 2022 Michal Ruprich <mruprich@redhat.com> - 3.1.2-11
- Resolves: #2111170 - remote arbitrary files write inside the directories of connecting peers

You are not authorized to access bug #2111170.

Offline Jean-Philippe Pialasse

  • *
  • 2,747
  • +11/-0
  • aka Unnilennium
    • http://smeserver.pialasse.com
Re: rsync update broke AFFA
« Reply #2 on: September 02, 2022, 07:16:12 PM »
seems related to that

https://nvd.nist.gov/vuln/detail/CVE-2022-29154


need to read the patch from source rpm to understand the changes and how to proceed.  please open a bug

Offline ReetP

  • *
  • 3,722
  • +5/-0
...
1. Read the Manual
2. Read the Wiki
3. Don't ask for support on Unsupported versions of software
4. I have a job, wife, and kids and do this in my spare time. If you want something fixed, please help.

Bugs are easier than you think: http://wiki.contribs.org/Bugzilla_Help

If you love SME and don't want to lose it, join in: http://wiki.contribs.org/Koozali_Foundation

Offline ReetP

  • *
  • 3,722
  • +5/-0
Re: rsync update broke AFFA
« Reply #4 on: September 03, 2022, 12:54:43 PM »
As per my comment here you can probably get aorund this by disabling the RPMCheck by setting this in your config

Code: [Select]
RPMCHeck=no
https://bugs.koozali.org/show_bug.cgi?id=12165#c7
...
1. Read the Manual
2. Read the Wiki
3. Don't ask for support on Unsupported versions of software
4. I have a job, wife, and kids and do this in my spare time. If you want something fixed, please help.

Bugs are easier than you think: http://wiki.contribs.org/Bugzilla_Help

If you love SME and don't want to lose it, join in: http://wiki.contribs.org/Koozali_Foundation

Offline ReetP

  • *
  • 3,722
  • +5/-0
Re: rsync update broke AFFA
« Reply #5 on: September 03, 2022, 11:44:50 PM »
Ahhhh no.

I can see another issue with backup locations. Think that is compounding some permissions issues that are at the root of it.

Hard work on the brain cells.

In the meantime if you hit this I suggest you don't upgrade your affa box for the time being.

I suspect many won't realise that data hasn't been saved :-(

...
1. Read the Manual
2. Read the Wiki
3. Don't ask for support on Unsupported versions of software
4. I have a job, wife, and kids and do this in my spare time. If you want something fixed, please help.

Bugs are easier than you think: http://wiki.contribs.org/Bugzilla_Help

If you love SME and don't want to lose it, join in: http://wiki.contribs.org/Koozali_Foundation

Offline ReetP

  • *
  • 3,722
  • +5/-0
Re: rsync update broke AFFA
« Reply #6 on: September 16, 2022, 02:53:42 PM »
...
1. Read the Manual
2. Read the Wiki
3. Don't ask for support on Unsupported versions of software
4. I have a job, wife, and kids and do this in my spare time. If you want something fixed, please help.

Bugs are easier than you think: http://wiki.contribs.org/Bugzilla_Help

If you love SME and don't want to lose it, join in: http://wiki.contribs.org/Koozali_Foundation