Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package python-sglang for openSUSE:Factory 
checked in at 2026-10-01 16:46:06
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/python-sglang (Old)
 and      /work/SRC/openSUSE:Factory/.python-sglang.new.1253 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "python-sglang"

Thu Oct  1 16:46:06 2026 rev:5 rq:1381723 version:0.5.20

Changes:
--------
--- /work/SRC/openSUSE:Factory/python-sglang/python-sglang.changes      
2026-09-23 14:37:38.147027789 +0200
+++ /work/SRC/openSUSE:Factory/.python-sglang.new.1253/python-sglang.changes    
2026-10-01 16:47:08.457281890 +0200
@@ -1,0 +2,23 @@
+Wed Sep 30 18:22:29 UTC 2026 - Martin Pluskal <[email protected]>
+
+- CVE-2026-102634: bootstrap_room is client supplied and
+  unauthenticated, and two concurrent requests picking the same
+  value share one entry in CommonKVManager.request_status. When the
+  first of them finished, clear() popped that entry and the second
+  one's poll raised KeyError out of check_status(), killing the
+  scheduler process; the loser of the race instead hung
+  until its transfer timed out. An unregistered room is now
+  reported as KVPoll.Failed, which the decode queue already
+  turns into a per-request abort via prepare_abort(), and a
+  KVPoll.Success poll now counts as bootstrap-done instead of
+  hitting decode's "Unexpected poll case" ValueError, which
+  killed the decode scheduler (boo#1283270)
+  * sglang-40185-bootstrap-room-dedup.patch, two hunks of
+    sgl-project/sglang PR 40185 (still unmerged, tracking issue
+    40125), which upstream has not released in any version
+  * The affected CommonKVManager path is unreachable in this
+    build: only the mooncake, mori and nixl managers construct one
+    and none of their transport libraries is packaged; the fake
+    transfer backend does not subclass it either
+
+-------------------------------------------------------------------

New:
----
  sglang-40185-bootstrap-room-dedup.patch

----------(New B)----------
  New:  killed the decode scheduler (boo#1283270)
  * sglang-40185-bootstrap-room-dedup.patch, two hunks of
    sgl-project/sglang PR 40185 (still unmerged, tracking issue
----------(New E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ python-sglang.spec ++++++
--- /var/tmp/diff_new_pack.u4iGHA/_old  2026-10-01 16:47:10.064349246 +0200
+++ /var/tmp/diff_new_pack.u4iGHA/_new  2026-10-01 16:47:10.067349372 +0200
@@ -52,6 +52,8 @@
 Patch4:         sglang-safe-unpickler-stdlib-globals.patch
 # PATCH-FIX-UPSTREAM sglang-safe-unpickler-explicit-globals.patch boo#1280091 
-- CVE-2026-86793: sgl-project/sglang commit 5b42d10edf (PR 40259), drop the 
remaining module prefixes and route torch.storage._load_from_bytes through a 
weights_only torch.load
 Patch5:         sglang-safe-unpickler-explicit-globals.patch
+# PATCH-FIX-UPSTREAM sglang-40185-bootstrap-room-dedup.patch boo#1283270 -- 
CVE-2026-102634: sgl-project/sglang PR 40185 (unmerged, head commit 
1901ddecfe), report an unknown bootstrap_room as KVPoll.Failed instead of 
letting check_status raise KeyError, and count KVPoll.Success as 
bootstrap-done; 2 of the PR's 27 files, the rest being a typing modernisation 
that does not apply to 0.5.20
+Patch6:         sglang-40185-bootstrap-room-dedup.patch
 BuildRequires:  %{python_module IPython}
 BuildRequires:  %{python_module Pillow}
 BuildRequires:  %{python_module SoundFile}

++++++ sglang-40185-bootstrap-room-dedup.patch ++++++
Restrict an unknown bootstrap_room lookup to a clean per-request failure

Fixes CVE-2026-102634 (boo#1283270): bootstrap_room is client supplied and
unauthenticated, and two concurrent requests picking the same value share one
entry in CommonKVManager.request_status. When the first of them finishes,
clear() pops that entry, and the second one's decode-side poll then raised
KeyError out of check_status(), killing the scheduler process. The loser of
the race instead hung until its transfer timed out.

Carried from sgl-project/sglang PR 40185 (unmerged; head commit
1901ddecfebb5960bebcb237efb96397b85be355, tracking issue 40125, both still
open). Only the two behavioural hunks of that PR are carried here. Its other
25 files are a PEP 604 typing modernisation plus import shuffling, which
does not apply cleanly to the 0.5.20 tag and is not part of this fix.

  * check_status() reports an unregistered room as KVPoll.Failed instead of
    raising KeyError. KVPoll.Failed is already handled by DecodePreallocQueue,
    which aborts just that request with prepare_abort(); the scheduler and
    every other request survive.
  * The decode poll dispatch also treats KVPoll.Success as bootstrap-done, so
    a request whose shared room was completed by the colliding peer stops
    waiting for input instead of hitting decode.py's
    raise ValueError(f"Unexpected poll case: {poll}"), which killed the
    decode scheduler.
---
 python/sglang/srt/disaggregation/common/conn.py | 2 +-
 python/sglang/srt/disaggregation/decode.py        | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)

diff --git a/python/sglang/srt/disaggregation/common/conn.py 
b/python/sglang/srt/disaggregation/common/conn.py
--- a/python/sglang/srt/disaggregation/common/conn.py
+++ b/python/sglang/srt/disaggregation/common/conn.py
@@ -390,7 +390,7 @@
         )
 
     def check_status(self, bootstrap_room: int) -> KVPoll:
-        return self.request_status[bootstrap_room]
+        return self.request_status.get(bootstrap_room, KVPoll.Failed)
 
     def update_status(self, bootstrap_room: int, status: KVPoll):
         current = self.request_status.get(bootstrap_room)
diff --git a/python/sglang/srt/disaggregation/decode.py 
b/python/sglang/srt/disaggregation/decode.py
--- a/python/sglang/srt/disaggregation/decode.py
+++ b/python/sglang/srt/disaggregation/decode.py
@@ -915,7 +915,7 @@
 
             if poll == KVPoll.Bootstrapping:
                 pass
-            elif poll == KVPoll.WaitingForInput:
+            elif poll in (KVPoll.WaitingForInput, KVPoll.Success):
                 decode_req.waiting_for_input = True
                 decode_req.req.time_stats.set_bootstrap_done_time()
             elif poll == KVPoll.Failed:

Reply via email to