Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package openbao for openSUSE:Factory checked in at 2026-09-24 22:58:22 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/openbao (Old) and /work/SRC/openSUSE:Factory/.openbao.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "openbao" Thu Sep 24 22:58:22 2026 rev:25 rq:1380103 version:2.6.3 Changes: -------- --- /work/SRC/openSUSE:Factory/openbao/openbao.changes 2026-08-28 19:58:36.568524059 +0200 +++ /work/SRC/openSUSE:Factory/.openbao.new.383539/openbao.changes 2026-09-24 23:01:08.089449541 +0200 @@ -1,0 +2,72 @@ +Thu Sep 24 04:56:01 UTC 2026 - Johannes Kastl <[email protected]> + +- Update to version 2.6.3: + * SECURITY + - agent, proxy: Ensure the quit endpoint correctly requires the + X-Vault-Request header when specified by listener + configuration. GHSA-8gmq-wv9h-fcwp. [GH-4065] + - auth/cert, auth/kubernetes, auth/userpass, secrets/pki, + core/policies, core/workflows: Use ResolvePathOperation to + define canonical URLs for canonicalized resources. + GHSA-fg5x-7whg-6c28. [GH-4065] + - core/plugins: Ensure plugin command name is relative to + plugin_directory prior to executing. GHSA-j6wc-jpvg-xfxq. + [GH-4065] + - core/plugins: Ensure writes to sys/plugins/catalog/* + endpoints are restricted to the root namespace. + GHSA-cg72-x35g-xfp8. [GH-4065] + - core/policies: Ensure denied ACL policy template evaluation + returns an error and is not silently dropped. + GHSA-hr5j-3j78-4vh2. [GH-4065] + - core/policies: Prevent cross-namespace policy resolution + traversal in the LRU policy cache, allowing unintentional + cross-namespace access. GHSA-mjch-vcw3-hhmf. [GH-4065] + - sdk: Prevent TypeKVPair, TypeHeader from leaking malformed + request data into audit logs in plaintext. + GHSA-8xxq-mq9m-xmhw. [GH-4065] + - secrets/pki: Forbid issuance of non-validated SANs through + ACME. GHSA-x8fg-h69x-p28f. [GH-4065] + - ui: Remove support for prompt=none redirection in the OIDC + provider. GHSA-2cjw-94fw-wqjx. [GH-4065] + * CHANGES + - agent, proxy: The .../quit and .../cache-clear endpoints now + require the X-Vault-Request request header when + require_request_header = true is specified. [GH-4065] + * IMPROVEMENTS + - command/server: Include disable_standby_reads, + allow_unauthenticated_workflows, and unsafe_relative_paths in + sanitized config output. [GH-3433] + - core/mfa: Handle cache entry invalidation on standby nodes + after mfa config deletion on leader node. [GH-4033] + - sdk/logical: Introduce ResolvePathOperation to report + canonical URLs prior to ACL evaluation. [GH-4065] + * BUG FIXES + - command/operator: Fix double file close in snapshot + restoration. [GH-3939] + - command/server: Fix boolean config fields being dropped when + multiple -config paths are used. [GH-3433] + - core/auth: Ensure invalidation updates description and + reloads on changes to config, options, and plugin versions. + [GH-3967] + - core/ha: Fix broken cross-version request forwarding during + rolling upgrades to v2.6.x from an earlier minor version. + [GH-3900] + - core/identity: Fix periodic key rotation and expiration + attempts on standbys resulting in read-only errors. [GH-3949] + - core/listeners: Fix broken TCP listener on OpenBSD. [GH-3951] + - core/mfa: Properly handle MFA enforcement configs deletion + from storage. [GH-4033] + - core/mounts: Ensure invalidation updates description and + reloads on changes to config, options, and plugin versions. + [GH-3967] + - core/recovery: Avoid panic during listing of namespace + contents due to uninitialized namespace store. [GH-3925] + - core/recovery: Fix generation of recovery token via bao + operator generate-root by allowing status checks. [GH-3924] + - core: The response of sys/leader did not contain is_self when + it was supposed to be false. [GH-3932] + - sys/raw: Allow creating new entries via sys/raw; when doing + so without compression, compression_type="none" must be + specified. [GH-3933] + +------------------------------------------------------------------- Old: ---- openbao-2.6.2.obscpio ui-2.6.2.tar.gz New: ---- openbao-2.6.3.obscpio ui-2.6.3.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ openbao.spec ++++++ --- /var/tmp/diff_new_pack.SuBo5T/_old 2026-09-24 23:01:19.522927618 +0200 +++ /var/tmp/diff_new_pack.SuBo5T/_new 2026-09-24 23:01:19.524927702 +0200 @@ -23,7 +23,7 @@ %define short_executable_name bao Name: openbao -Version: 2.6.2 +Version: 2.6.3 Release: 0 Summary: Manage, store, and distribute sensitive data License: MPL-2.0 @@ -39,7 +39,7 @@ Source12: PACKAGING_README.md Source13: prepare_webassets.sh BuildRequires: fdupes -BuildRequires: golang(API) >= 1.25 +BuildRequires: golang(API) >= 1.26 BuildRequires: user(openbao) # Provides: bao = %{version} ++++++ _service ++++++ --- /var/tmp/diff_new_pack.SuBo5T/_old 2026-09-24 23:01:19.577929918 +0200 +++ /var/tmp/diff_new_pack.SuBo5T/_new 2026-09-24 23:01:19.579930002 +0200 @@ -2,7 +2,7 @@ <service name="obs_scm" mode="manual"> <param name="url">https://github.com/openbao/openbao.git</param> <param name="scm">git</param> - <param name="revision">refs/tags/v2.6.2</param> + <param name="revision">refs/tags/v2.6.3</param> <param name="package-meta">yes</param> <param name="versionformat">@PARENT_TAG@</param> <param name="versionrewrite-pattern">v(.*)</param> ++++++ _servicedata ++++++ --- /var/tmp/diff_new_pack.SuBo5T/_old 2026-09-24 23:01:19.598930796 +0200 +++ /var/tmp/diff_new_pack.SuBo5T/_new 2026-09-24 23:01:19.601930921 +0200 @@ -3,6 +3,6 @@ <param name="url">https://github.com/openbao/openbao</param> <param name="changesrevision">028992583c693c4de6350b8aa52ff85e30375a99</param></service><service name="tar_scm"> <param name="url">https://github.com/openbao/openbao.git</param> - <param name="changesrevision">dd9c19c37a878cf4a81b18efb8d6f0599c7da923</param></service></servicedata> + <param name="changesrevision">63a65e6b907589dbb952c371a70260a065bf8bd7</param></service></servicedata> (No newline at EOF) ++++++ openbao-2.6.2.obscpio -> openbao-2.6.3.obscpio ++++++ /work/SRC/openSUSE:Factory/openbao/openbao-2.6.2.obscpio /work/SRC/openSUSE:Factory/.openbao.new.383539/openbao-2.6.3.obscpio differ: char 49, line 1 ++++++ openbao.obsinfo ++++++ --- /var/tmp/diff_new_pack.SuBo5T/_old 2026-09-24 23:01:19.663933514 +0200 +++ /var/tmp/diff_new_pack.SuBo5T/_new 2026-09-24 23:01:19.666933639 +0200 @@ -1,5 +1,5 @@ name: openbao -version: 2.6.2 -mtime: 1787067785 -commit: dd9c19c37a878cf4a81b18efb8d6f0599c7da923 +version: 2.6.3 +mtime: 1790181473 +commit: 63a65e6b907589dbb952c371a70260a065bf8bd7 ++++++ ui-2.6.2.tar.gz -> ui-2.6.3.tar.gz ++++++ /work/SRC/openSUSE:Factory/openbao/ui-2.6.2.tar.gz /work/SRC/openSUSE:Factory/.openbao.new.383539/ui-2.6.3.tar.gz differ: char 14, line 1 ++++++ vendor.tar.gz ++++++ /work/SRC/openSUSE:Factory/openbao/vendor.tar.gz /work/SRC/openSUSE:Factory/.openbao.new.383539/vendor.tar.gz differ: char 13, line 1
