[Low] Patch rpm-ostree for CVE-2025-58160#15457
[Low] Patch rpm-ostree for CVE-2025-58160#15457BinduSri-6522866 wants to merge 1 commit intomicrosoft:3.0-devfrom
Conversation
|
Buddy build failed for arm64. Because rpm-ostree is ExclusiveArch: x86_64 |
bhagyapathak
left a comment
There was a problem hiding this comment.
Patch Analysis (Minor Changes)
- Buddy Build
- patch applied during the build (check
rpm.log) - patch include an upstream reference
- PR has security tag
- ptest regression
kgodara912
left a comment
There was a problem hiding this comment.
Please check why it was reverted, https://github.com/ricky26/tracing/commit/2e1c50bb8fd40c32da5004894d893251473f47f9
kgodara912
left a comment
There was a problem hiding this comment.
Please check why it was reverted, https://github.com/ricky26/tracing/commit/2e1c50bb8fd40c32da5004894d893251473f47f9
|
The upstream change from PR tokio-rs/tracing#3368 (see commit tokio-rs/tracing@4c52ca5) was reverted in tokio-rs/tracing because it introduced behavioral and compatibility regressions tokio-rs/tracing#3369. |
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
What does the PR accomplish, why was it needed?
Patch rpm-ostree for CVE-2025-58160
patch modified: Yes
tracing-subscriber/CHANGELOG.mdandtracing-subscriber/Cargo.tomlfiles, as those changes are not part of CVE fix.Change Log
Does this affect the toolchain?
NO
Links to CVEs
Test Methodology
rpm-ostree-2024.4-6.azl3.src.rpm.log
rpm-ostree-2024.4-6.azl3.src.rpm.test.log