Ukugebenga ingqalasizinda ye-LineageOS ngokuba sengozini ku-SaltStack

Abathuthukisi benkundla yeselula LineageOS, ethathe indawo ye-CyanogenMod, waxwayisa mayelana nokuhlonza iminonjana yokugetshengwa kwengqalasizinda yephrojekthi. Kuyaphawulwa ukuthi ngo-6 ekuseni (MSK) ngoMeyi 3, umhlaseli wakwazi ukuthola ukufinyelela kuseva eyinhloko yesistimu yokuphatha ukucushwa okuphakathi. I-SaltStack ngokusebenzisa ubungozi obungavaliwe. Isigameko okwamanje sisahlaziywa kanti imininingwane ibingakatholakali.

Kubikiwe kuphela ukuthi ukuhlasela akuzange kuthinte okhiye bokukhiqiza amasignesha edijithali, uhlelo lokuhlanganisa kanye nekhodi yomthombo yesikhulumi - okhiye zazitholakala kubabungazi abahluke ngokuphelele nengqalasizinda eyinhloko ephethwe nge-SaltStack, futhi ukwakhiwa kwamiswa ngezizathu zobuchwepheshe ngo-April 30. Ukwahlulela ngolwazi olusekhasini status.lineageos.org Abathuthukisi sebevele babuyisele iseva ngohlelo lokubuyekeza ikhodi ye-Gerrit, iwebhusayithi kanye ne-wiki. Iseva enama-assemblies (builds.lineageos.org), ingosi yokudawuniloda amafayela (download.lineageos.org), iziphakeli zemeyili kanye nesistimu yokuxhumanisa ukudluliselwa ezibukweni kuhlala kuvaliwe.

Ukuhlasela kwenzeke ngenxa yokuthi ichweba lenethiwekhi (4506) lokufinyelela i-SaltStack wayengekho ivinjwe izicelo zangaphandle ngohlelo lokuvikela - umhlaseli bekumele alinde ukuba sengozini okubalulekile ku-SaltStack ukuthi kuvele futhi akusebenzise ngaphambi kokuthi abalawuli bafake isibuyekezo esinokulungiswa. Bonke abasebenzisi be-SaltStack bayelulekwa ukuthi babuyekeze ngokushesha amasistimu abo futhi bahlole izimpawu zokugetshengwa.

Ngokusobala, ukuhlaselwa nge-SaltStack akugcini ngokugebenga i-LineageOS futhi kwasakazeka - phakathi nosuku, abasebenzisi abahlukahlukene ababengenaso isikhathi sokuvuselela i-SaltStack. gubha ukuhlonza ukonakala kwengqalasizinda yabo ngokufakwa kwekhodi yezimayini noma ngemuva kumaseva. Kuhlanganisa kubikiwe mayelana nokugetshengwa okufanayo kwengqalasizinda yesistimu yokuphatha okuqukethwe Ghost, okuthinte amawebhusayithi e-Ghost(Pro) kanye nokukhokhiswa (kusolwa ukuthi izinombolo zekhadi lesikweletu azithintekanga, kodwa amagama ayimfihlo abasebenzisi be-Ghost angase awele ezandleni zabahlaseli).

Ngo-April 29 kwaba khululiwe Izibuyekezo zeplathifomu ye-SaltStack 3000.2 и 2019.2.4, lapho zaqedwa khona ubuthakathaka obubili (ulwazi olumayelana nokuba sengozini lushicilelwe ngo-April 30), olunikezwe izinga eliphezulu lengozi, njengoba lungenabo ubuqiniso vumela ukusetshenziswa kwekhodi yesilawuli kude kukho kokubili kumsingathi wokulawula (i-salt-master) nakuwo wonke amaseva aphethwe ngawo.

  • Ukuba sengozini kokuqala (I-CVE-2020-11651) kubangelwa ukuntuleka kokuhlola okufanele lapho kubizwa izindlela zekilasi le-ClearFuncs ohlelweni lwe-salt-master. Ukuba sengozini kuvumela umsebenzisi wesilawuli kude ukuthi afinyelele izindlela ezithile ngaphandle kokuqinisekisa. Kuhlanganisa nezindlela eziyinkinga, umhlaseli angathola ithokheni yokufinyelela enamalungelo ezimpande kuseva eyinhloko futhi aqhube noma yimiphi imiyalo kubasingathi abaphakiwe lapho i-daemon isebenza khona. usawoti-minion. Isiqeshana esiqeda lobu sengozini kwaba eshicilelwe Ezinsukwini ezingu-20 ezedlule, kodwa ngemva kokuyisebenzisa zavela regressive shintsha, okuholela ekuhlulekeni nasekuphazamisekeni kokuvumelanisa ifayela.
  • Ukuba sengozini kwesibili (I-CVE-2020-11652) ivumela, ngokukhohlisa ngekilasi le-ClearFuncs, ukuthola ukufinyelela ezindleleni ngokudlula ngendlela ethile izindlela ezifomethiweyo, ezingasetshenziselwa ukufinyelela okugcwele kuhlu lwemibhalo olungenasizathu ku-FS yeseva eyinhloko enamalungelo ezimpande, kodwa kudinga ukufinyelela okuqinisekisiwe ( ukufinyelela okunjalo kungatholwa kusetshenziswa ukuba sengozini kokuqala futhi kusetshenziswe ukuba sengozini kwesibili ukufaka engcupheni yonke ingqalasizinda engozini).

Source: opennet.ru

Engeza amazwana