Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1148925 > unrolled thread

Bug#1037178: puppet does not sync files anymore after recent ruby2.5 security upload

Started byBernhard Schmidt <berni@debian.org>
First post2023-06-07 08:50 +0200
Last post2023-06-09 07:00 +0200
Articles 10 — 8 participants

Back to article view | Back to linux.debian.bugs.dist


Contents

  Bug#1037178: puppet does not sync files anymore after recent ruby2.5 security upload Bernhard Schmidt <berni@debian.org> - 2023-06-07 08:50 +0200
    Bug#1037178: puppet does not sync files anymore after recent ruby2.5 security upload Salvatore Bonaccorso <carnil@debian.org> - 2023-06-07 09:40 +0200
      Bug#1037178: puppet does not sync files anymore after recent ruby2.5 security upload Utkarsh Gupta <guptautkarsh2102@gmail.com> - 2023-06-07 10:20 +0200
    Bug#1037178: puppet does not sync files anymore after recent ruby2.5 security upload Lucas Kanashiro <kanashiro.duarte@gmail.com> - 2023-06-07 13:30 +0200
    Bug#1037178: puppet does not sync files anymore after recent ruby2.5 security upload Kees Meijs | Nefos <keesm@nefos.nl> - 2023-06-07 15:30 +0200
    Bug#1037178: puppet does not sync files anymore after recent ruby2.5 security upload Utkarsh Gupta <guptautkarsh2102@gmail.com> - 2023-06-07 15:30 +0200
      Bug#1037178: puppet does not sync files anymore after recent ruby2.5 security upload Jérôme Charaoui <jerome@riseup.net> - 2023-06-07 18:40 +0200
    Bug#1037178: puppet does not sync files anymore after recent ruby2.5 security upload "Chris Lamb" <lamby@debian.org> - 2023-06-07 17:40 +0200
    Bug#1037178: puppet does not sync files anymore after recent ruby2.5 security upload Utkarsh Gupta <guptautkarsh2102@gmail.com> - 2023-06-07 23:30 +0200
    Bug#1037178: puppet does not sync files anymore after recent ruby2.5  security upload Zubrick <zubrick@number6.ch> - 2023-06-09 07:00 +0200

#1148925 — Bug#1037178: puppet does not sync files anymore after recent ruby2.5 security upload

FromBernhard Schmidt <berni@debian.org>
Date2023-06-07 08:50 +0200
SubjectBug#1037178: puppet does not sync files anymore after recent ruby2.5 security upload
Message-ID<GDV9v-eeio-1@gated-at.bofh.it>
Package: libruby2.5
Version: 2.5.5-3+deb10u5
Severity: grave

Hi,

I can't quite figure out why, but the latest security upload of ruby2.5 in
Buster breaks the ability of the puppet agent to pull files from the master

With 2.5.5-3+deb10u4:
# puppet agent --onetime --server puppet-kom.srv.lrz.de  --test  --no-daemonize
Info: Using configured environment 'production'
Info: Retrieving pluginfacts
Info: Retrieving plugin
Info: Retrieving locales
Info: Loading facts
Info: Caching catalog for simrad3.slb.lrz.de
Info: Applying configuration version 'master-70189ef6ab5a'


# apt dist-upgrade
Reading package lists... Done
Building dependency tree       
Reading state information... Done
Calculating upgrade... Done
The following packages will be upgraded:
  libruby2.5 ruby2.5
2 upgraded, 0 newly installed, 0 to remove and 0 not upgraded.
Need to get 3841 kB of archives.
After this operation, 2048 B of additional disk space will be used.
Do you want to continue? [Y/n] 
Get:1 http://debian.mirror.lrz.de/debian-security buster/updates/main amd64 libruby2.5 amd64 2.5.5-3+deb10u5 [3440 kB]
Get:2 http://debian.mirror.lrz.de/debian-security buster/updates/main amd64 ruby2.5 amd64 2.5.5-3+deb10u5 [401 kB]
Fetched 3841 kB in 0s (30.3 MB/s)
Reading changelogs... Done
(Reading database ... 58907 files and directories currently installed.)
Preparing to unpack .../libruby2.5_2.5.5-3+deb10u5_amd64.deb ...
Unpacking libruby2.5:amd64 (2.5.5-3+deb10u5) over (2.5.5-3+deb10u4) ...
Preparing to unpack .../ruby2.5_2.5.5-3+deb10u5_amd64.deb ...
Unpacking ruby2.5 (2.5.5-3+deb10u5) over (2.5.5-3+deb10u4) ...
Setting up libruby2.5:amd64 (2.5.5-3+deb10u5) ...
Setting up ruby2.5 (2.5.5-3+deb10u5) ...
Processing triggers for man-db (2.8.5-2) ...
Processing triggers for libc-bin (2.28-10+deb10u2) ...

# puppet agent --onetime --server puppet-kom.srv.lrz.de  --test  --no-daemonize
Info: Using configured environment 'production'
Info: Retrieving pluginfacts
Error: /File[/var/lib/puppet/facts.d]: Failed to generate additional resources using 'eval_generate': Failed to open TCP connection to :8140 (Connection refused - connect(2) for "" port 8140)
Error: /File[/var/lib/puppet/facts.d]: Could not evaluate: Could not retrieve file metadata for puppet:///pluginfacts: Failed to open TCP connection to :8140 (Connection refused - connect(2) for "" port 8140)
Info: Retrieving plugin
Error: /File[/var/lib/puppet/lib]: Failed to generate additional resources using 'eval_generate': Failed to open TCP connection to :8140 (Connection refused - connect(2) for "" port 8140)
Error: /File[/var/lib/puppet/lib]: Could not evaluate: Could not retrieve file metadata for puppet:///plugins: Failed to open TCP connection to :8140 (Connection refused - connect(2) for "" port 8140)
Info: Retrieving locales
Error: /File[/var/lib/puppet/locales]: Failed to generate additional resources using 'eval_generate': Failed to open TCP connection to :8140 (Connection refused - connect(2) for "" port 8140)
Error: /File[/var/lib/puppet/locales]: Could not evaluate: Could not retrieve file metadata for puppet:///locales: Failed to open TCP connection to :8140 (Connection refused - connect(2) for "" port 8140)
Info: Loading facts
Info: Caching catalog for simrad3.slb.lrz.de
Info: Applying configuration version 'master-70189ef6ab5a'
Error: /Stage[main]/Lrz_kom_radius::Radiussimrad/File[/etc/freeradius/.git/hooks/post-commit]: Could not evaluate: Could not retrieve file metadata for puppet:///modules/lrz_kom/classes/radius/git_post-commit_hook: Failed to open TCP connection to :8140 (Connection refused - connect(2) for "" port 8140)
Error: /Stage[main]/Lrz_common::Distributions::Debian::Vim/File[/etc/vim/vimrc.lrz-puppet]: Could not evaluate: Could not retrieve file metadata for puppet:///modules/lrz_common/vimrc.lrz-puppet: Failed to open TCP connection to :8140 (Connection refused - connect(2) for "" port 8140)
Error: /Stage[main]/Lrz_common::Distributions::Debian::Emacs/File[//etc/emacs/site-start.d/99lrz.el]: Could not evaluate: Could not retrieve file metadata for puppet:///modules/lrz_common/emacs/99lrz.el: Failed to open TCP connection to :8140 (Connection refused - connect(2) for "" port 8140)
Error: /Stage[main]/Lrz_common::Distributions::Debian/File[/etc/apt/trusted.gpg.d/debian-lrz.asc]: Could not evaluate: Could not retrieve file metadata for puppet:///modules/lrz_common/debian/debian-lrz.asc: Failed to open TCP connection to :8140 (Connection refused - connect(2) for "" port 8140)
Error: /Stage[main]/Puppetclient::Config/File[/usr/bin/waitrandom]: Could not evaluate: Could not retrieve file metadata for puppet:///modules/puppetclient/waitrandom: Failed to open TCP connection to :8140 (Connection refused - connect(2) for "" port 8140)
Notice: Applied catalog in 1.82 seconds

Note the empty servername in the "Failed to open TCP connection" messages.

Bernhard

[toc] | [next] | [standalone]


#1148927

FromSalvatore Bonaccorso <carnil@debian.org>
Date2023-06-07 09:40 +0200
Message-ID<GDVVT-eeOc-1@gated-at.bofh.it>
In reply to#1148925
Hi LTS team,

On Wed, Jun 07, 2023 at 08:44:53AM +0200, Bernhard Schmidt wrote:
> Package: libruby2.5
> Version: 2.5.5-3+deb10u5
> Severity: grave
> 
> Hi,
> 
> I can't quite figure out why, but the latest security upload of ruby2.5 in
> Buster breaks the ability of the puppet agent to pull files from the master
> 
> With 2.5.5-3+deb10u4:
> # puppet agent --onetime --server puppet-kom.srv.lrz.de  --test  --no-daemonize
> Info: Using configured environment 'production'
> Info: Retrieving pluginfacts
> Info: Retrieving plugin
> Info: Retrieving locales
> Info: Loading facts
> Info: Caching catalog for simrad3.slb.lrz.de
> Info: Applying configuration version 'master-70189ef6ab5a'
> 
> 
> # apt dist-upgrade
> Reading package lists... Done
> Building dependency tree       
> Reading state information... Done
> Calculating upgrade... Done
> The following packages will be upgraded:
>   libruby2.5 ruby2.5
> 2 upgraded, 0 newly installed, 0 to remove and 0 not upgraded.
> Need to get 3841 kB of archives.
> After this operation, 2048 B of additional disk space will be used.
> Do you want to continue? [Y/n] 
> Get:1 http://debian.mirror.lrz.de/debian-security buster/updates/main amd64 libruby2.5 amd64 2.5.5-3+deb10u5 [3440 kB]
> Get:2 http://debian.mirror.lrz.de/debian-security buster/updates/main amd64 ruby2.5 amd64 2.5.5-3+deb10u5 [401 kB]
> Fetched 3841 kB in 0s (30.3 MB/s)
> Reading changelogs... Done
> (Reading database ... 58907 files and directories currently installed.)
> Preparing to unpack .../libruby2.5_2.5.5-3+deb10u5_amd64.deb ...
> Unpacking libruby2.5:amd64 (2.5.5-3+deb10u5) over (2.5.5-3+deb10u4) ...
> Preparing to unpack .../ruby2.5_2.5.5-3+deb10u5_amd64.deb ...
> Unpacking ruby2.5 (2.5.5-3+deb10u5) over (2.5.5-3+deb10u4) ...
> Setting up libruby2.5:amd64 (2.5.5-3+deb10u5) ...
> Setting up ruby2.5 (2.5.5-3+deb10u5) ...
> Processing triggers for man-db (2.8.5-2) ...
> Processing triggers for libc-bin (2.28-10+deb10u2) ...
> 
> # puppet agent --onetime --server puppet-kom.srv.lrz.de  --test  --no-daemonize
> Info: Using configured environment 'production'
> Info: Retrieving pluginfacts
> Error: /File[/var/lib/puppet/facts.d]: Failed to generate additional resources using 'eval_generate': Failed to open TCP connection to :8140 (Connection refused - connect(2) for "" port 8140)
> Error: /File[/var/lib/puppet/facts.d]: Could not evaluate: Could not retrieve file metadata for puppet:///pluginfacts: Failed to open TCP connection to :8140 (Connection refused - connect(2) for "" port 8140)
> Info: Retrieving plugin
> Error: /File[/var/lib/puppet/lib]: Failed to generate additional resources using 'eval_generate': Failed to open TCP connection to :8140 (Connection refused - connect(2) for "" port 8140)
> Error: /File[/var/lib/puppet/lib]: Could not evaluate: Could not retrieve file metadata for puppet:///plugins: Failed to open TCP connection to :8140 (Connection refused - connect(2) for "" port 8140)
> Info: Retrieving locales
> Error: /File[/var/lib/puppet/locales]: Failed to generate additional resources using 'eval_generate': Failed to open TCP connection to :8140 (Connection refused - connect(2) for "" port 8140)
> Error: /File[/var/lib/puppet/locales]: Could not evaluate: Could not retrieve file metadata for puppet:///locales: Failed to open TCP connection to :8140 (Connection refused - connect(2) for "" port 8140)
> Info: Loading facts
> Info: Caching catalog for simrad3.slb.lrz.de
> Info: Applying configuration version 'master-70189ef6ab5a'
> Error: /Stage[main]/Lrz_kom_radius::Radiussimrad/File[/etc/freeradius/.git/hooks/post-commit]: Could not evaluate: Could not retrieve file metadata for puppet:///modules/lrz_kom/classes/radius/git_post-commit_hook: Failed to open TCP connection to :8140 (Connection refused - connect(2) for "" port 8140)
> Error: /Stage[main]/Lrz_common::Distributions::Debian::Vim/File[/etc/vim/vimrc.lrz-puppet]: Could not evaluate: Could not retrieve file metadata for puppet:///modules/lrz_common/vimrc.lrz-puppet: Failed to open TCP connection to :8140 (Connection refused - connect(2) for "" port 8140)
> Error: /Stage[main]/Lrz_common::Distributions::Debian::Emacs/File[//etc/emacs/site-start.d/99lrz.el]: Could not evaluate: Could not retrieve file metadata for puppet:///modules/lrz_common/emacs/99lrz.el: Failed to open TCP connection to :8140 (Connection refused - connect(2) for "" port 8140)
> Error: /Stage[main]/Lrz_common::Distributions::Debian/File[/etc/apt/trusted.gpg.d/debian-lrz.asc]: Could not evaluate: Could not retrieve file metadata for puppet:///modules/lrz_common/debian/debian-lrz.asc: Failed to open TCP connection to :8140 (Connection refused - connect(2) for "" port 8140)
> Error: /Stage[main]/Puppetclient::Config/File[/usr/bin/waitrandom]: Could not evaluate: Could not retrieve file metadata for puppet:///modules/puppetclient/waitrandom: Failed to open TCP connection to :8140 (Connection refused - connect(2) for "" port 8140)
> Notice: Applied catalog in 1.82 seconds
> 
> Note the empty servername in the "Failed to open TCP connection" messages.

Can you please have a look, as this seems to be caused by the DLA
issued as DLA-3447-1.

Regards,
Salvatore

[toc] | [prev] | [next] | [standalone]


#1148931

FromUtkarsh Gupta <guptautkarsh2102@gmail.com>
Date2023-06-07 10:20 +0200
Message-ID<GDWyB-efgZ-1@gated-at.bofh.it>
In reply to#1148927
Hi Chris,

On Wed, Jun 7, 2023 at 12:56 PM Salvatore Bonaccorso <carnil@debian.org> wrote:
> Can you please have a look, as this seems to be caused by the DLA
> issued as DLA-3447-1.

This has been caused by the ruby2.5 update. Can you please TAL? This
is perhaps because of the URI version in buster v/s URI version
upstream. The upstream patch was supposed to be for 3.2 and was not
2.5 compliant. Let me know if you'd like me to help.


- u

[toc] | [prev] | [next] | [standalone]


#1148955

FromLucas Kanashiro <kanashiro.duarte@gmail.com>
Date2023-06-07 13:30 +0200
Message-ID<GDZwt-egYF-5@gated-at.bofh.it>
In reply to#1148925

[Multipart message — attachments visible in raw view] — view raw

FWIW, in Ubuntu, we had a similar issue trying to fix this CVE in ruby2.7,
and in the end we reverted the fix:

https://launchpad.net/ubuntu/+source/ruby2.7/2.7.0-5ubuntu1.10

Lucas Kanashiro.

Em qua., 7 de jun. de 2023 07:47, Utkarsh Gupta <guptautkarsh2102@gmail.com>
escreveu:

> Hiya,
>
> On Wed, Jun 7, 2023 at 2:39 PM Moritz Muehlenhoff <jmm@inutil.org> wrote:
> > Specifically
> https://www.ruby-lang.org/en/news/2023/03/28/redos-in-uri-cve-2023-28755/
> > states:
> >
> > | For Ruby 2.7: Update to uri 0.10.0.1
> > | For Ruby 3.0: Update to uri 0.10.2
> > | For Ruby 3.1: Update to uri 0.11.1
> > | For Ruby 3.2: Update to uri 0.12.1
> >
> > And the 0.10 change (
> https://github.com/ruby/uri/commit/17861a53e499a2eabf7ba83d63914d0f01921d70
> )
> > is different from the 0.12 one (
> https://github.com/ruby/uri/commit/eaf89cc31619d49e67c64d0b58ea9dc38892d175
> )
> >
> > There might be other changes needed for 2.5, not sure.
>
> Yep, I'm taking a look to prep something for 2.5.
>
>
> - u
>
>

[toc] | [prev] | [next] | [standalone]


#1148967

FromKees Meijs | Nefos <keesm@nefos.nl>
Date2023-06-07 15:30 +0200
Message-ID<GE1oB-ei51-3@gated-at.bofh.it>
In reply to#1148925
Hi Utkarsh,

Many thanks from our end.

I know you were asking Bernhard, but I downloaded and installed as well. 
Our Puppet agent seems to be happy again.

Cheers,
Kees

On 07-06-2023 15:17, Utkarsh Gupta wrote:
> I've prepared a fix for the regression and uploaded the binaries at:
> https://people.debian.org/~utkarsh/lts/ruby2.5/
>
> Can you please give these a try and see if that fixes the regression
> you're seeing?

[toc] | [prev] | [next] | [standalone]


#1148970

FromUtkarsh Gupta <guptautkarsh2102@gmail.com>
Date2023-06-07 15:30 +0200
Message-ID<GE1oB-ei51-5@gated-at.bofh.it>
In reply to#1148925
Hi Bernhard,

On Wed, Jun 7, 2023 at 4:16 PM Utkarsh Gupta <guptautkarsh2102@gmail.com> wrote:
> Yep, I'm taking a look to prep something for 2.5.

I've prepared a fix for the regression and uploaded the binaries at:
https://people.debian.org/~utkarsh/lts/ruby2.5/

Can you please give these a try and see if that fixes the regression
you're seeing?


- u

[toc] | [prev] | [next] | [standalone]


#1148992

FromJérôme Charaoui <jerome@riseup.net>
Date2023-06-07 18:40 +0200
Message-ID<GE4mt-ejMD-1@gated-at.bofh.it>
In reply to#1148970
On Wed, 7 Jun 2023 18:47:02 +0530 Utkarsh Gupta 
<guptautkarsh2102@gmail.com> wrote:> I've prepared a fix for the 
regression and uploaded the binaries at:
> https://people.debian.org/~utkarsh/lts/ruby2.5/
> 
> Can you please give these a try and see if that fixes the regression
> you're seeing?

These packages also fix the Puppet regression reported here, on our 
buster systems.

Thanks,

-- Jérôme

[toc] | [prev] | [next] | [standalone]


#1148983

From"Chris Lamb" <lamby@debian.org>
Date2023-06-07 17:40 +0200
Message-ID<GE3qp-ejdR-1@gated-at.bofh.it>
In reply to#1148925
Utkarsh,

> I had missed your comment in the bug but super, many thanks for
> testing this out! I'll wait a bit more before I roll this out.

I see your 2.5.5-3+deb10u6 update on the debian/buster branch which
fixes the broken +deb10u5 upload, but I don't see it in the archive
yet.

Although you mentioned you were going to wait a bit more, I'm just
100%-checking you aren't waiting on anything from me to upload that?


Best wishes,

-- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby@debian.org 🍥 chris-lamb.co.uk
       `-

[toc] | [prev] | [next] | [standalone]


#1149016

FromUtkarsh Gupta <guptautkarsh2102@gmail.com>
Date2023-06-07 23:30 +0200
Message-ID<GE8T7-emxC-1@gated-at.bofh.it>
In reply to#1148925
Hi Bernhard, Kees,

On Wed, Jun 7, 2023 at 6:58 PM Schmidt, Bernhard
<Bernhard.Schmidt@lrz.de> wrote:
> > I've prepared a fix for the regression and uploaded the binaries at:
> > https://people.debian.org/~utkarsh/lts/ruby2.5/
> >
> > Can you please give these a try and see if that fixes the regression
> > you're seeing?
>
> Looking good!

Many thanks for testing, too!

I've actually managed to prepare a final update that I'm ready to
upload - this has quite some fixes plus 2 new CVE fixes. Would you
please test the new resulting binaries and make sure they look sane
enough? :)

The binaries can be found at
https://people.debian.org/~utkarsh/lts/ruby2.5/. Many thanks!


- u

[toc] | [prev] | [next] | [standalone]


#1149090 — Bug#1037178: puppet does not sync files anymore after recent ruby2.5 security upload

FromZubrick <zubrick@number6.ch>
Date2023-06-09 07:00 +0200
SubjectBug#1037178: puppet does not sync files anymore after recent ruby2.5 security upload
Message-ID<GECo9-eEWF-1@gated-at.bofh.it>
In reply to#1148925
Hi,

It is now the third day in a row that we have to manually patch broken servers because of this update.
I confirm that the u6 version works also for that 20+ servers I already had to patch and would appreciate not to have to test it on a lot more.

Can you please tell us when do you plan to release these patches so my servers stop breaking one after the other and I don’t have to fix them manually?
I find it quite slow to fix a wrong patch.

Regards

zubrick

On Wed, 07 Jun 2023 17:00:27 -0700 "Chris Lamb" <lamby@debian.org> wrote:
> No, please go ahead and do both: my availability is spotty for the next 18 hours. :) 
> 
> (on mobile) 
> 
> 
> Utkarsh Gupta wrote:
> 
> > Hi Chris,
> >
> > On Wed, Jun 7, 2023 at 9:01 PM Chris Lamb <lamby@debian.org> wrote:
> >> I see your 2.5.5-3+deb10u6 update on the debian/buster branch which
> >> fixes the broken +deb10u5 upload, but I don't see it in the archive
> >> yet.
> >>
> >> Although you mentioned you were going to wait a bit more, I'm just
> >> 100%-checking you aren't waiting on anything from me to upload that?
> >
> > Oh yeah, I wanted to sneak in some fixes and enable the tests and fix
> > the failing ones with the last upload. So I'll take care of the upload
> > and the announcement unless you prefer doing that since you did the
> > original upload?
> >
> >
> >
> 
> -- 
>       ,''`.
>      : :'  :     Chris Lamb
>      `. `'`      lamby@debian.org 🍥 chris-lamb.co.uk
>        `-
> 
> 

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web