Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package tigervnc for openSUSE:Factory checked in at 2023-04-04 21:17:02 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/tigervnc (Old) and /work/SRC/openSUSE:Factory/.tigervnc.new.19717 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "tigervnc" Tue Apr 4 21:17:02 2023 rev:98 rq:1076858 version:1.13.1 Changes: -------- --- /work/SRC/openSUSE:Factory/tigervnc/tigervnc.changes 2023-03-22 22:29:04.369719471 +0100 +++ /work/SRC/openSUSE:Factory/.tigervnc.new.19717/tigervnc.changes 2023-04-04 21:17:03.059901467 +0200 @@ -1,0 +2,7 @@ +Mon Apr 3 08:57:25 UTC 2023 - Joan Torres <joan.tor...@suse.com> + +- Fixes for bsc#1209283 + * Drop chown vnc:vnc calls in with-vnc-key.sh + * Add TLSNone to -securitytypes to increase security in xvnc@.service + +------------------------------------------------------------------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ with-vnc-key.sh ++++++ --- /var/tmp/diff_new_pack.5vEEvO/_old 2023-04-04 21:17:04.279909245 +0200 +++ /var/tmp/diff_new_pack.5vEEvO/_new 2023-04-04 21:17:04.283909271 +0200 @@ -19,7 +19,6 @@ # If the key file doesn't exist or has zero size (because it doubles as lock), generate it. if ! test -s $TLSKEY ; then (umask 077 && openssl genrsa -out $TLSKEY 2048) >&200 - chown vnc:vnc $TLSKEY fi # If the cert file doesn't exist, generate it. @@ -28,7 +27,6 @@ CN="`hostname`" CN=${CN:0:64} openssl req -new -x509 -extensions usr_cert -key $TLSKEY -out $TLSCERT -days 7305 -subj "/CN=$CN/" - chown vnc:vnc $TLSCERT fi ) 200>>$TLSKEY 2>/dev/null ++++++ x...@.service.in ++++++ --- /var/tmp/diff_new_pack.5vEEvO/_old 2023-04-04 21:17:04.407910062 +0200 +++ /var/tmp/diff_new_pack.5vEEvO/_new 2023-04-04 21:17:04.411910087 +0200 @@ -2,7 +2,7 @@ Description=Xvnc Server [Service] -ExecStart=@LIBEXECDIR@/vnc/with-vnc-key.sh /usr/bin/Xvnc -noreset -inetd -once -query localhost -geometry 1024x768 -securitytypes X509None,None -X509Key /etc/vnc/tls.key -X509Cert /etc/vnc/tls.cert -log *:syslog:30 -extension MIT-SHM +ExecStart=@LIBEXECDIR@/vnc/with-vnc-key.sh /usr/bin/Xvnc -noreset -inetd -once -query localhost -geometry 1024x768 -securitytypes X509None,TLSNone,None -X509Key /etc/vnc/tls.key -X509Cert /etc/vnc/tls.cert -log *:syslog:30 -extension MIT-SHM User=vnc StandardInput=socket StandardOutput=socket