Hi,

On Tue, 25 Aug 2015, Xin Li wrote:
Hi,

We believe this is because phttpget (the pipelined HTTP client that
freebsd-update and portsnap uses) was unable to get the right file(s)
from the server, that sometimes the client would get wrong file from the
server, and it's not reproducable when requesting again.  We have then
able to develop a test case to reliably provoke this on update2.FreeBSD.org.

Thanks for Peter's help, we have narrowed down the problem to a specific
version (1.4.36) of lighttpd (*), which update2.FreeBSD.org is using,
and the problem should have been resolved at this time after the web
server is replaced with nginx.

Please let us (security-officer@, clusteradm@) know if the problem still
persists.

Cheers,

(*) We are not yet certain if it was a bug with lighttpd itself, or a
bug with phttpget that made newer versions of lighttpd unhappy.  It's
worthy to find it out and maintainer is cc'ed.


thanks for fixing this and thanks for the detailed feedback.

I was able to update 5 systems at two different sites this morning without a 
glitch.

An update before the fix required upto 10 retries to be successfull.

So it definetely looks like this has been fixed.

Greetings
Christian

--
Christian Kratzer                   CK Software GmbH
Email:   [email protected]               Wildberger Weg 24/2
Phone:   +49 7032 893 997 - 0       D-71126 Gaeufelden
Fax:     +49 7032 893 997 - 9       HRB 245288, Amtsgericht Stuttgart
Mobile:  +49 171 1947 843           Geschaeftsfuehrer: Christian Kratzer
Web:     http://www.cksoft.de/
_______________________________________________
[email protected] mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-stable
To unsubscribe, send any mail to "[email protected]"

Reply via email to