Imininingwane mayelana nokugenca kwe-Matrix kwesibili. Okhiye bephrojekthi ye-GPG bonakele

[:zu]

Ishicilelwe новые imininingwane mayelana nokugetshengwa kwengqalasizinda yesikhulumi semiyalezo esihlukaniselwe iMatrix, mayelana nayo kubikiwe ekuseni. Isixhumanisi esiyinkinga abahlaseli abangene ngaso kwakuwuhlelo lokuhlanganisa oluqhubekayo lwe-Jenkins, olwagqekezwa ngoMashi 13. Khona-ke, kuseva ye-Jenkins, ukungena ngemvume komunye wabalawuli, okuqondiswe kabusha yi-ejenti ye-SSH, kwabanjwa, futhi ngo-Ephreli 4, abahlaseli bathola ukufinyelela kwamanye amaseva wengqalasizinda.

Ngesikhathi sokuhlasela kwesibili, iwebhusayithi ye-matrix.org iqondiswe kabusha kwenye iseva (matrixnotorg.github.io) ngokushintsha imingcele ye-DNS, kusetshenziswa ukhiye we-API yesistimu yokulethwa kokuqukethwe kwe-Cloudflare ebanjwe ngesikhathi sokuhlasela kokuqala. Lapho bakha kabusha okuqukethwe kwamaseva ngemva kokugebenga kokuqala, abalawuli be-Matrix babuyekeze okhiye bomuntu siqu abasha futhi baphuthelwe ukubuyekeza ukhiye we-Cloudflare.

Ngesikhathi sokuhlasela kwesibili, amaseva e-Matrix ahlala engathintwanga izinguquko zazingagcini ngokushintsha amakheli ku-DNS. Uma umsebenzisi esevele eguqule iphasiwedi ngemuva kokuhlasela kokuqala, asikho isidingo sokuyishintsha okwesibili. Kodwa uma iphasiwedi ingakashintshwa, idinga ukubuyekezwa ngokushesha ngangokunokwenzeka, njengoba ukuvuza kwe-database ene-password hashes kuqinisekisiwe. Uhlelo lwamanje ukuqalisa inqubo yokusetha kabusha iphasiwedi ephoqelelwe ngokuzayo lapho ungena ngemvume.

Ngaphezu kokuvuza kwamaphasiwedi, kuphinde kwaqinisekiswa ukuthi okhiye be-GPG abasetshenziselwa ukukhiqiza amasiginesha edijithali amaphakheji endaweni ye-Debian Synapse kanye nokukhishwa kwe-Riot/Web kuwele ezandleni zabahlaseli. Okhiye bebevikelwe ngephasiwedi. Okhiye sebevele bahoxisiwe ngalesi sikhathi. Okhiye babanjwa ngo-Ephreli 4, kusukela ngaleso sikhathi azikho izibuyekezo ze-Synapse eziye zakhululwa, kodwa iklayenti le-Riot/Web 1.0.7 likhishwe (isheke lokuqala libonise ukuthi alizange libe sengozini).

Umhlaseli uthumele uchungechunge lwemibiko ku-GitHub enemininingwane yokuhlasela namathiphu okwandisa ukuvikela, kodwa yasuswa. Nokho, imibiko egciniwe kugciniwe.
Isibonelo, umhlaseli ubike ukuthi onjiniyela be-Matrix kufanele sebenzisa ukuqinisekiswa kwezinto ezimbili noma okungenani ukungasebenzisi ukuqondiswa kabusha komenzeli we-SSH (“ForwardAgent yebo”), khona-ke ukungena kungqalasizinda kuzovinjwa. Ukubhebhetheka kokuhlaselwa nakho kungamiswa ngokunikeza abathuthukisi amalungelo adingekayo kuphela, kunokuba ukufinyelela okugcwele kwempande kuwo wonke amaseva.

Ukwengeza, umkhuba wokugcina okhiye bokudala amasiginesha edijithali kumaseva okukhiqiza wagxekwa; Isahlasela kubikiwe, ukuthi uma abathuthukisi be-Matrix bebehlale bahlola amalogi futhi bahlaziya okudidayo, bebeyoqaphela iminonjana yokugebenga kusenesikhathi (ukugebenga kwe-CI akuzange kubonwe inyanga yonke). Enye inkinga kwaba ukugcina wonke amafayela okumisa ku-Git, okwenze kwaba nokwenzeka ukuhlola izilungiselelo zabanye ababungazi uma omunye wabo egqekeziwe. Ukufinyelela nge-SSH kumaseva engqalasizinda wayengekho ikhawulelwe kunethiwekhi yangaphakathi evikelekile, okwenze kwaba nokwenzeka ukuxhuma kubo kusuka kunoma yiliphi ikheli langaphandle.

Umthomboopennet.ru

[: zu]

Ishicilelwe новые imininingwane mayelana nokugetshengwa kwengqalasizinda yesikhulumi semiyalezo esihlukaniselwe iMatrix, mayelana nayo kubikiwe ekuseni. Isixhumanisi esiyinkinga abahlaseli abangene ngaso kwakuwuhlelo lokuhlanganisa oluqhubekayo lwe-Jenkins, olwagqekezwa ngoMashi 13. Khona-ke, kuseva ye-Jenkins, ukungena ngemvume komunye wabalawuli, okuqondiswe kabusha yi-ejenti ye-SSH, kwabanjwa, futhi ngo-Ephreli 4, abahlaseli bathola ukufinyelela kwamanye amaseva wengqalasizinda.

Ngesikhathi sokuhlasela kwesibili, iwebhusayithi ye-matrix.org iqondiswe kabusha kwenye iseva (matrixnotorg.github.io) ngokushintsha imingcele ye-DNS, kusetshenziswa ukhiye we-API yesistimu yokulethwa kokuqukethwe kwe-Cloudflare ebanjwe ngesikhathi sokuhlasela kokuqala. Lapho bakha kabusha okuqukethwe kwamaseva ngemva kokugebenga kokuqala, abalawuli be-Matrix babuyekeze okhiye bomuntu siqu abasha futhi baphuthelwe ukubuyekeza ukhiye we-Cloudflare.

Ngesikhathi sokuhlasela kwesibili, amaseva e-Matrix ahlala engathintwanga izinguquko zazingagcini ngokushintsha amakheli ku-DNS. Uma umsebenzisi esevele eguqule iphasiwedi ngemuva kokuhlasela kokuqala, asikho isidingo sokuyishintsha okwesibili. Kodwa uma iphasiwedi ingakashintshwa, idinga ukubuyekezwa ngokushesha ngangokunokwenzeka, njengoba ukuvuza kwe-database ene-password hashes kuqinisekisiwe. Uhlelo lwamanje ukuqalisa inqubo yokusetha kabusha iphasiwedi ephoqelelwe ngokuzayo lapho ungena ngemvume.

Ngaphezu kokuvuza kwamaphasiwedi, kuphinde kwaqinisekiswa ukuthi okhiye be-GPG abasetshenziselwa ukukhiqiza amasiginesha edijithali amaphakheji endaweni ye-Debian Synapse kanye nokukhishwa kwe-Riot/Web kuwele ezandleni zabahlaseli. Okhiye bebevikelwe ngephasiwedi. Okhiye sebevele bahoxisiwe ngalesi sikhathi. Okhiye babanjwa ngo-Ephreli 4, kusukela ngaleso sikhathi azikho izibuyekezo ze-Synapse eziye zakhululwa, kodwa iklayenti le-Riot/Web 1.0.7 likhishwe (isheke lokuqala libonise ukuthi alizange libe sengozini).

Umhlaseli uthumele uchungechunge lwemibiko ku-GitHub enemininingwane yokuhlasela namathiphu okwandisa ukuvikela, kodwa yasuswa. Nokho, imibiko egciniwe kugciniwe.
Isibonelo, umhlaseli ubike ukuthi onjiniyela be-Matrix kufanele sebenzisa ukuqinisekiswa kwezinto ezimbili noma okungenani ukungasebenzisi ukuqondiswa kabusha komenzeli we-SSH (“ForwardAgent yebo”), khona-ke ukungena kungqalasizinda kuzovinjwa. Ukubhebhetheka kokuhlaselwa nakho kungamiswa ngokunikeza abathuthukisi amalungelo adingekayo kuphela, kunokuba ukufinyelela okugcwele kwempande kuwo wonke amaseva.

Ukwengeza, umkhuba wokugcina okhiye bokudala amasiginesha edijithali kumaseva okukhiqiza wagxekwa; Isahlasela kubikiwe, ukuthi uma abathuthukisi be-Matrix bebehlale bahlola amalogi futhi bahlaziya okudidayo, bebeyoqaphela iminonjana yokugebenga kusenesikhathi (ukugebenga kwe-CI akuzange kubonwe inyanga yonke). Enye inkinga kwaba ukugcina wonke amafayela okumisa ku-Git, okwenze kwaba nokwenzeka ukuhlola izilungiselelo zabanye ababungazi uma omunye wabo egqekeziwe. Ukufinyelela nge-SSH kumaseva engqalasizinda wayengekho ikhawulelwe kunethiwekhi yangaphakathi evikelekile, okwenze kwaba nokwenzeka ukuxhuma kubo kusuka kunoma yiliphi ikheli langaphandle.

Source: opennet.ru

[:]

Engeza amazwana