Hi,
EPEL ships fcgi-2.4.0-25.el7: http://koji.fedoraproject.org/koji/buildinfo?buildID=609511
while the latest CBS build is fcgi-2.4.0-21.el7: http://cbs.centos.org/koji/buildinfo?buildID=832
The changelog includes: * Fri Feb 06 2015 Till Maas opensource@till.name - 2.4.0-25 - Fix crash when too many connections are used - Make gcc build dependencies obvious for local builds * Mon Feb 03 2014 Till Maas opensource@till.name - 2.4.0-22 - Harden build
I'd like our Ceph Jewel rebuild to ship the exact same RPMs than EPEL so I'll rebuild fcgi-2.4.0-25.el7 shortly unless anyone objects.
Regards, François
On 05/05/16 22:28, François Cami wrote:
Hi,
EPEL ships fcgi-2.4.0-25.el7: http://koji.fedoraproject.org/koji/buildinfo?buildID=609511
while the latest CBS build is fcgi-2.4.0-21.el7: http://cbs.centos.org/koji/buildinfo?buildID=832
looks like Sandro is using this build in his ovirt repos - maybe he can verify once you have done the updated build ?
The changelog includes:
- Fri Feb 06 2015 Till Maas opensource@till.name - 2.4.0-25
- Fix crash when too many connections are used
- Make gcc build dependencies obvious for local builds
- Mon Feb 03 2014 Till Maas opensource@till.name - 2.4.0-22
- Harden build
I'd like our Ceph Jewel rebuild to ship the exact same RPMs than EPEL so I'll rebuild fcgi-2.4.0-25.el7 shortly unless anyone objects.
sounds good to me,
On Thu, May 5, 2016 at 11:44 PM, Karanbir Singh mail-lists@karan.org wrote:
On 05/05/16 22:28, François Cami wrote:
Hi,
EPEL ships fcgi-2.4.0-25.el7: http://koji.fedoraproject.org/koji/buildinfo?buildID=609511
while the latest CBS build is fcgi-2.4.0-21.el7: http://cbs.centos.org/koji/buildinfo?buildID=832
looks like Sandro is using this build in his ovirt repos - maybe he can verify once you have done the updated build ?
Well, we have that package in candidate only, it's used by storage team. I'm ok with bumping that package to latest nvr in epel.
The changelog includes:
- Fri Feb 06 2015 Till Maas opensource@till.name - 2.4.0-25
- Fix crash when too many connections are used
- Make gcc build dependencies obvious for local builds
- Mon Feb 03 2014 Till Maas opensource@till.name - 2.4.0-22
- Harden build
I'd like our Ceph Jewel rebuild to ship the exact same RPMs than EPEL so I'll rebuild fcgi-2.4.0-25.el7 shortly unless anyone objects.
sounds good to me,
-- Karanbir Singh +44-207-0999389 | http://www.karan.org/ | twitter.com/kbsingh GnuPG Key : http://www.karan.org/publickey.asc _______________________________________________ CentOS-devel mailing list CentOS-devel@centos.org https://lists.centos.org/mailman/listinfo/centos-devel
On Thu, May 5, 2016 at 3:28 PM, François Cami fcami@fedoraproject.org wrote:
Hi,
EPEL ships fcgi-2.4.0-25.el7: http://koji.fedoraproject.org/koji/buildinfo?buildID=609511
while the latest CBS build is fcgi-2.4.0-21.el7: http://cbs.centos.org/koji/buildinfo?buildID=832
Go EPEL :)
But seriously, that fix is for CVE-2012-6687, so it's important to get it in.
- Ken