Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package s390-tools for openSUSE:Factory checked in at 2026-09-22 15:53:14 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/s390-tools (Old) and /work/SRC/openSUSE:Factory/.s390-tools.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "s390-tools" Tue Sep 22 15:53:14 2026 rev:124 rq:1379627 version:2.44.1 Changes: -------- --- /work/SRC/openSUSE:Factory/s390-tools/s390-tools.changes 2026-08-18 16:38:54.345132375 +0200 +++ /work/SRC/openSUSE:Factory/.s390-tools.new.383539/s390-tools.changes 2026-09-22 15:54:50.229245427 +0200 @@ -1,0 +2,68 @@ +Tue Sep 22 07:36:27 UTC 2026 - Nikolay Gueorguiev <[email protected]> + +- Upgrade s390-tools to version 2.44.1 + ( bsc#1273204, bsc#1273205, bsc#1273206, bsc#1273207, bsc#1275476 ) + For Linux kernel version: 7.2 + * Changes of existing tools: + - cpumf/lshwc: Add -c as short option for --counters + - cpumf/lspai: Handle CPU hotplug gracefully + - dbginfo.sh: Change grep for OS name + - dbginfo.sh: Change tar generation via temp file + - dbginfo.sh: Correct dump counter + - dbginfo.sh: Detect the openCryptoki STDLL directory at runtime + - dbginfo.sh: Redirect stderr on command existence checks + - dbginfo.sh: Replace deprecated backtick command substitution + - dbginfo.sh: Secure the directory input variable + - zipl: Detect and display partition table type for disk and device + * Bug Fixes: + - cmsfs-fuse: Fix out-of-bounds access when reading variable-length files + - cpumf/lscpumf: Fix exit status and error reporting + - cpumf/lshwc: Fix --allcpu to --all in man page + - cpumf/lspai: Add input validation for interval parameter + - cpumf/lspai: Fix --allcpu to --all in man page + - cpumf/lspai: Fix integer overflow in file descriptor calculation + - cpumf/lspai: Fix output formatting with minimum indent + - dasdview: Fix buffer overflow in dasdview_read_vtoc() + - dumpconf: Harden locking during delayed activation to prevent symlink attacks + - fdasd: Fix potential buffer overflow in fdasd_change_part_type() + - ipl_tools: Fix buffer overflow vulnerabilities in chreipl and is_lpar() + - ip_watcher: Use mktemp for cleanup files to avoid collisions + - libkmipclient: Fix NULL pointer dereference in kmip_v2_attr_from_v1_attr() + - libkmipclient: Fix heap buffer overflow + - libutil/util_lockfile: Prevent buffer overflow in lockfile handling + - libzds: Add bounds checking and validate used_bytes in PDS directory parsing + - pvattest: Write attestation request private key (arpk) with 0600 permissions + - pvebc: Fix executable permission on sel-ebc-modules.conf + - pvics: Fix incorrect exit values for --version and --help options + - pvsecret: Write secret with 0600 permissions + - sclpdbf: Harden against invalid trace data + - vmur: Fix buffer over-read in get_minor() + - zdump/dfi_s390: Add a check for zlib entry size in the dump header + - zdump/dfi_s390: Fix out-of-bounds upon dump entry decompression + - zdump/dfo_elf: Fix 32-bit truncation in ELF header allocation size + - zdump: Reject multi-volume dumps with out-of-range vol_cnt + - ziomon/ziomon_zfcpdd: Validate message lengths before processing + - ziomon/ziorep_config: Replace unsafe open() and regex match with safer idioms + - ziomon: Validate message layout and aggregate message lengths before processing + - zipl: Fix memory leak in free_bootloader() + - zipl: Replace popen(3) with safer invocation for targetbase scripts and ngdump + - zkey-ekmfweb: Fix insecure default: TLS host name verification now enabled by default + - zkey-kmip: Fix insecure default: TLS host name verification now enabled by default + - zkey: Fix memory leaks when generating keys or reenciphering integrity volumes + - zkey: Harden 'zkey kms unbind' command against symlink traversal + - zkey: Harden KMS config directory handling against symlink attacks + - zkey: Harden KMS plugin file handling against symlink attacks + - zkey: Install initrd integration with the configured plugin directory + * Full Changelog: v2.44.0...v2.44.1 + [https://github.com/ibm-s390-linux/s390-tools/compare/v2.44.0...v2.44.1] +- Removed obsolete patches for Security vulnerabilities for zkey and friends + * s390-tools-zkey-Harden-KMS-config-directory-handling.patch + - zkey: Harden KMS config directory handling - Commit `0eef784` + * s390-tools-zkey-Harden-zkey-kms-unbind-command.patch + - zkey: Harden 'zkey kms unbind' command - Commit `1b90d15` + * s390-tools-zkey-ekmfweb-zkey-kmip-Harden-KMS-plugin-file-handling.patch + - zkey/ekmfweb, zkey/kmip: Harden KMS plugin file handling - Commit `bc81c32` +- Reworked s390-tools-Remove-phmac_s390.patch +- Re-vendor-ed vendor.tar.zst + +------------------------------------------------------------------- Old: ---- s390-tools-2.44.0.tar.gz s390-tools-zkey-Harden-KMS-config-directory-handling.patch s390-tools-zkey-Harden-zkey-kms-unbind-command.patch s390-tools-zkey-ekmfweb-zkey-kmip-Harden-KMS-plugin-file-handling.patch New: ---- s390-tools-2.44.1.tar.gz ----------(Old B)---------- Old:- Removed obsolete patches for Security vulnerabilities for zkey and friends * s390-tools-zkey-Harden-KMS-config-directory-handling.patch - zkey: Harden KMS config directory handling - Commit `0eef784` Old: - zkey: Harden KMS config directory handling - Commit `0eef784` * s390-tools-zkey-Harden-zkey-kms-unbind-command.patch - zkey: Harden 'zkey kms unbind' command - Commit `1b90d15` Old: - zkey: Harden 'zkey kms unbind' command - Commit `1b90d15` * s390-tools-zkey-ekmfweb-zkey-kmip-Harden-KMS-plugin-file-handling.patch - zkey/ekmfweb, zkey/kmip: Harden KMS plugin file handling - Commit `bc81c32` ----------(Old E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ s390-tools.spec ++++++ --- /var/tmp/diff_new_pack.E72Wlg/_old 2026-09-22 15:54:51.685305412 +0200 +++ /var/tmp/diff_new_pack.E72Wlg/_new 2026-09-22 15:54:51.687305494 +0200 @@ -24,7 +24,7 @@ %endif Name: s390-tools -Version: 2.44.0 +Version: 2.44.1 Release: 0 Summary: S/390 tools like zipl and dasdfmt for s390x (plus selected tools for x86_64) License: MIT @@ -92,9 +92,6 @@ ### # IBM patches -Patch101: s390-tools-zkey-Harden-KMS-config-directory-handling.patch -Patch102: s390-tools-zkey-Harden-zkey-kms-unbind-command.patch -Patch103: s390-tools-zkey-ekmfweb-zkey-kmip-Harden-KMS-plugin-file-handling.patch ### # SUSE patches Patch900: s390-tools-combined.patch ++++++ s390-tools-2.44.0.tar.gz -> s390-tools-2.44.1.tar.gz ++++++ ++++ 7234 lines of diff (skipped) ++++++ s390-tools-Remove-phmac_s390.patch ++++++ --- /var/tmp/diff_new_pack.E72Wlg/_old 2026-09-22 15:54:52.692346899 +0200 +++ /var/tmp/diff_new_pack.E72Wlg/_new 2026-09-22 15:54:52.695347022 +0200 @@ -1,14 +1,14 @@ diff -Naur a/etc/modules-load.d/s390-pkey.conf b/etc/modules-load.d/s390-pkey.conf ---- a/etc/modules-load.d/s390-pkey.conf 2026-02-16 15:33:48.000000000 +0100 -+++ b/etc/modules-load.d/s390-pkey.conf 2026-04-17 09:32:27.895965780 +0200 +--- a/etc/modules-load.d/s390-pkey.conf 2026-09-21 19:36:47.000000000 +0200 ++++ b/etc/modules-load.d/s390-pkey.conf 2026-09-22 10:04:20.104771268 +0200 @@ -4,4 +4,3 @@ pkey_ep11 pkey_cca paes_s390 -phmac_s390 -diff -Naur a/zkey/dracut/99-pkey.conf b/zkey/dracut/99-pkey.conf ---- a/zkey/dracut/99-pkey.conf 2026-02-16 15:33:48.000000000 +0100 -+++ b/zkey/dracut/99-pkey.conf 2026-04-17 09:34:04.888735927 +0200 +diff -Naur a/zkey/dracut/99-pkey.conf.in b/zkey/dracut/99-pkey.conf.in +--- a/zkey/dracut/99-pkey.conf.in 2026-09-21 19:36:47.000000000 +0200 ++++ b/zkey/dracut/99-pkey.conf.in 2026-09-22 10:02:17.647392941 +0200 @@ -4,6 +4,6 @@ # it under the terms of the MIT license. See LICENSE for details. # @@ -16,10 +16,10 @@ -add_drivers+=" uvdevice pkey pkey_cca pkey_ep11 pkey_pckmo pkey_uv paes_s390 phmac_s390 zcrypt zcrypt_cex4 " +add_drivers+=" uvdevice pkey pkey_cca pkey_ep11 pkey_pckmo pkey_uv paes_s390 zcrypt zcrypt_cex4 " install_items+=" chzcrypt lszcrypt zkey zkey-cryptsetup " - install_optional_items+=" /usr/lib64/zkey/*.so /etc/zkey/* /etc/zkey/repository/* /etc/zkey/kmip/profiles/* " -diff -Naur a/zkey/initramfs/hooks/s390-tools-zkey b/zkey/initramfs/hooks/s390-tools-zkey ---- a/zkey/initramfs/hooks/s390-tools-zkey 2026-02-16 15:33:48.000000000 +0100 -+++ b/zkey/initramfs/hooks/s390-tools-zkey 2026-04-17 09:34:41.161023939 +0200 + install_optional_items+=" %ZKEYKMSPLUGINDIR%/*.so /etc/zkey/* /etc/zkey/repository/* /etc/zkey/kmip/profiles/* " +diff -Naur a/zkey/initramfs/hooks/s390-tools-zkey.in b/zkey/initramfs/hooks/s390-tools-zkey.in +--- a/zkey/initramfs/hooks/s390-tools-zkey.in 2026-09-21 19:36:47.000000000 +0200 ++++ b/zkey/initramfs/hooks/s390-tools-zkey.in 2026-09-22 10:02:57.271515356 +0200 @@ -29,7 +29,7 @@ . /usr/share/initramfs-tools/hook-functions ++++++ vendor.tar.zst ++++++ /work/SRC/openSUSE:Factory/s390-tools/vendor.tar.zst /work/SRC/openSUSE:Factory/.s390-tools.new.383539/vendor.tar.zst differ: char 7, line 1
