Package: magnum / 3.1.1-5
Patch seriesview the series file
|install missing files.patch | (download)||
2 2 + 0 - 0 !
installing missing alembic migration files As always, PBR misses the Alembic stuff.
|allow sqla 1.1.patch | (download)||
2 1 + 1 - 0 !
allow sqlalchemy >= 1.1
|CVE 2016 7404.patch | (download)||
1 1 + 0 - 0 !
[patch] fix cve-2016-7404 This commit addresses multiple potential vulnerabilities in Magnum. It makes the following changes: * Permissions for /etc/sysconfig/heat-params inside Magnum created instances are tightened to 0600 (used to be 0755). * Certificate retrieval is modified to work without the need for a Keystone trust. * The cluster's Keystone trust id is only passed into instances for clusters where that is actually needed. This prevents the trustee user from consuming the trust in cases where it is not needed. * The configuration setting trust/cluster_user_trust (False by default) is introduced. It needs to be explicitely enabled by the cloud operator to allow clusters that need the trust_id to be passed into instances to work. Without this setting, attempts to create such clusters will fail. Please note, that none of these changes apply to existing clusters. They will have to be deleted and rebuilt to benefit from these changes. (cherry picked from commit e93d82e8b3bc19211efd54edc17aebdca50670c1) Changes for backport: * Moved cluster_user_trust setting to magnum/common/keystone.py * Resolved merge conflicts. * Fixed unit tests with configuration overrides.