!8 [sync] PR-5: Update to version 3.9.23 to fix CVE-2022-31008

From: @openeuler-sync-bot 
Reviewed-by: @caodongxia 
Signed-off-by: @caodongxia
This commit is contained in:
openeuler-ci-bot 2022-10-21 07:18:57 +00:00 committed by Gitee
commit c27e549694
No known key found for this signature in database
GPG Key ID: 173E9B9CA92EEF8F
7 changed files with 28 additions and 50 deletions

View File

@ -5,7 +5,7 @@ Subject: [PATCH] Use default EPMD socket
Signed-off-by: Peter Lemenkov <lemenkov@gmail.com>
diff --git a/deps/rabbit/docs/rabbitmq-server.service.example b/deps/rabbit/docs/rabbitmq-server.service.example
index dec70eb635..a9aa3c1614 100644
index 69531b1ff6..9c12824a0e 100644
--- a/deps/rabbit/docs/rabbitmq-server.service.example
+++ b/deps/rabbit/docs/rabbitmq-server.service.example
@@ -1,8 +1,8 @@
@ -18,4 +18,4 @@ index dec70eb635..a9aa3c1614 100644
+Wants=network.target epmd.socket
[Service]
Type=notify
# Note: You *may* wish to uncomment the following lines to apply systemd

View File

@ -14,19 +14,6 @@ index dc4480a181..cf93227177 100755
from __future__ import print_function
diff --git a/deps/amqp10_common/development.post.mk b/deps/amqp10_common/development.post.mk
index 3f8301acd1..b7f960a7e7 100644
--- a/deps/amqp10_common/development.post.mk
+++ b/deps/amqp10_common/development.post.mk
@@ -2,7 +2,7 @@
# Framing sources generation.
# --------------------------------------------------------------------
-PYTHON ?= python
+PYTHON ?= python3
CODEGEN = $(CURDIR)/codegen.py
CODEGEN_DIR ?= $(DEPS_DIR)/rabbitmq_codegen
CODEGEN_AMQP = $(CODEGEN_DIR)/amqp_codegen.py
diff --git a/deps/rabbit_common/codegen.py b/deps/rabbit_common/codegen.py
index 2e7bad69e9..8a02fcbb31 100755
--- a/deps/rabbit_common/codegen.py
@ -37,16 +24,3 @@ index 2e7bad69e9..8a02fcbb31 100755
## This Source Code Form is subject to the terms of the Mozilla Public
## License, v. 2.0. If a copy of the MPL was not distributed with this
diff --git a/deps/rabbit_common/development.post.mk b/deps/rabbit_common/development.post.mk
index 65708dbcd7..ec905a4615 100644
--- a/deps/rabbit_common/development.post.mk
+++ b/deps/rabbit_common/development.post.mk
@@ -2,7 +2,7 @@
# Framing sources generation.
# --------------------------------------------------------------------
-PYTHON ?= python
+PYTHON ?= python3
CODEGEN = $(CURDIR)/codegen.py
CODEGEN_DIR ?= $(DEPS_DIR)/rabbitmq_codegen
CODEGEN_AMQP = $(CODEGEN_DIR)/amqp_codegen.py

View File

@ -2,7 +2,7 @@
%global _rabbit_libdir %{_exec_prefix}/lib/rabbitmq
%global debug_package %{nil}
Name: rabbitmq-server
Version: 3.9.10
Version: 3.9.23
Release: 1
License: MPLv2.0 and Apache-2.0 and MIT and BSD and ISC
Source0: https://github.com/rabbitmq/rabbitmq-server/releases/download/v%{version}/%{name}_%{version}.orig.tar.xz
@ -12,11 +12,12 @@ Source3: rabbitmq-server.logrotate
# curl -O https://raw.githubusercontent.com/rabbitmq/rabbitmq-server-release/rabbitmq_v3_6_16/packaging/RPMS/Fedora/rabbitmq-server.tmpfiles
Source5: rabbitmq-server.tmpfiles
Source6: rabbitmq-server-cuttlefish
Patch1: rabbitmq-server-0001-Allow-guest-login-from-non-loopback-connections.patch
Patch2: rabbitmq-server-0002-Use-default-EPMD-socket.patch
Patch3: rabbitmq-server-0003-Use-proto_dist-from-command-line.patch
Patch4: rabbitmq-server-0004-force-python3.patch
Patch5: rabbitmq-server-0005-Partially-revert-Use-template-in-rabbitmq-script-wra.patch
Patch1: rabbitmq-server-0001-Allow-guest-login-from-non-loopback-connections.patch
Patch2: rabbitmq-server-0002-Use-default-EPMD-socket.patch
Patch3: rabbitmq-server-0003-Use-proto_dist-from-command-line.patch
Patch4: rabbitmq-server-0004-force-python3.patch
Patch5: rabbitmq-server-0005-Partially-revert-Use-template-in-rabbitmq-script-wra.patch
URL: https://www.rabbitmq.com/
BuildRequires: elixir erlang >= %{erlang_minver} libxslt python3 python3-simplejson rsync
BuildRequires: systemd xmlto zip
@ -138,6 +139,9 @@ done
%{_mandir}/man8/rabbitmqctl.8*
%changelog
* Wed Oct 19 2022 liyuxiang <liyuxiang@ncti-gba.cn> - 3.9.23-1
- Update to version 3.9.23 to fix CVE-2022-31008
* Tue Jan 18 2022 Ge Wang <wangge20@huawei.com> - 3.9.10-1
- Update to version 3.9.10

Binary file not shown.

View File

@ -1,16 +0,0 @@
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEECpryEV9Gh70pgDoga3OjbmAm38oFAmGXrBEACgkQa3OjbmAm
38pEGRAAqIGFRQWsGXTxkJkamWlBIXVTCoPQO6j0UNMwhtSWCPAl3QMUH3nAIMX4
78JVU6vicouBSsfODLu8ug5lEAovlgtrOuhVZrveDR5+JIHtb/7ggO9TwJ8hYpgX
eS9+hyAAKRU1JdblBffV8YLBkuLPN7a/N29TMcIyM9ZLwQXOCua1PTiUxEMtJWpZ
d9g4f0NHwX3Un94jjWtpWHAdzfRj4m8ZUzZ6XYJeMUBZ2x0CApogYkCe/q7vXVae
jQOZfBLkJS1ZXbQCggqqZHFDZdnP27AF5ZtH+3ItgoTRZLviGWt+SR7PzT29O99J
UNmRq0BUbjddv6qaIr32Gb7lJ43X5OEWpZKymHF/+YgRUn698Tz1DtrVI9pvERIi
DSdNzUryYvcnxylCq+barcYp9l3Pxwwi6uG3mZoLy5n5uo0qPcW4iNE5lXIYWvcK
bmpjUppCidNUyL8oIXObmN+qz6NNhBr8VwTHdhu2qwkA4uEhKWo0/YZWN53NLoFu
ivRWfXe5bAlk8IH+ccrnIGF2Gfiy96yWhZkech2mZt3CPdOELz7f6qYYNbb6cAld
Drvqz06iKlB+bdJHKQagxLO2xU3LcLlzVIaI9iNhfvwjTsVOAJVpZPs+AQTOsEqg
7SDd08ZbLgcqgXjnstkKl8qFO8NY4YJrN2OlUeEgQM7L8cIhQng=
=lwrZ
-----END PGP SIGNATURE-----

Binary file not shown.

View File

@ -0,0 +1,16 @@
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEECpryEV9Gh70pgDoga3OjbmAm38oFAmMst+MACgkQa3OjbmAm
38pJCA/+Ngkk5GznDZjvrDj2bDERG0s44aOXkxkQUYtCgyXrJFb2KAwgNBHW58Lr
zu5oFhdx9550BXkIKxJRfZOOkROrVqch/USuJtXfs1BIkx8uncCzf7aDKqQtziRp
Ouzceq9BrpQEJKNq9sRLAaUmRAXIiEym0988aN+to4c2teaCRrDdgjPdhbSYl8S/
hnnJgAtR3T+18BHxzyMB90BISaVk3GBFzcXzXC4ovUiin4ckyFd+humbZtqOVVb+
p3COa9YIsJUKPGra7Xk3A3xQlKlbEDaPJxtWS0+p9SbtJGjM3XkWGm3ucoWx4hyU
LvMrWG1MkW499p23CFo8QowQgukN5CziPN1e2keazDvs36qMPTcglBPlpQVazX6Z
BoApiIYUV+kCksknrjrJ/wT7+3dHwjBC+Ln+iwQ7wJteBBtZiD59UmYAgoeOKyFe
YDjzFSZYnazbROubTI4/734HOJytytzjPPnvFwC1+OHVXmD4xknk0isz+DZGJbPY
JbDINCL40+a6f5aoFoXnu6s1dqVnQHrxfaMZz/+FEVVtEGtDmZemyVfYxY4yFMt8
0+Qfv/iZAPej60XESk1BqR8JPyTyctln0TxMB8i9JEIJwE0CPmjPdPIZu2iQgNvZ
kS9utErHh0kLIOtcr2rd5rl3HpRXg0X2GEREYiFC9NTY8mrdjW4=
=Uw3e
-----END PGP SIGNATURE-----