Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package python-sglang for openSUSE:Factory checked in at 2026-10-01 16:46:06 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/python-sglang (Old) and /work/SRC/openSUSE:Factory/.python-sglang.new.1253 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "python-sglang" Thu Oct 1 16:46:06 2026 rev:5 rq:1381723 version:0.5.20 Changes: -------- --- /work/SRC/openSUSE:Factory/python-sglang/python-sglang.changes 2026-09-23 14:37:38.147027789 +0200 +++ /work/SRC/openSUSE:Factory/.python-sglang.new.1253/python-sglang.changes 2026-10-01 16:47:08.457281890 +0200 @@ -1,0 +2,23 @@ +Wed Sep 30 18:22:29 UTC 2026 - Martin Pluskal <[email protected]> + +- CVE-2026-102634: bootstrap_room is client supplied and + unauthenticated, and two concurrent requests picking the same + value share one entry in CommonKVManager.request_status. When the + first of them finished, clear() popped that entry and the second + one's poll raised KeyError out of check_status(), killing the + scheduler process; the loser of the race instead hung + until its transfer timed out. An unregistered room is now + reported as KVPoll.Failed, which the decode queue already + turns into a per-request abort via prepare_abort(), and a + KVPoll.Success poll now counts as bootstrap-done instead of + hitting decode's "Unexpected poll case" ValueError, which + killed the decode scheduler (boo#1283270) + * sglang-40185-bootstrap-room-dedup.patch, two hunks of + sgl-project/sglang PR 40185 (still unmerged, tracking issue + 40125), which upstream has not released in any version + * The affected CommonKVManager path is unreachable in this + build: only the mooncake, mori and nixl managers construct one + and none of their transport libraries is packaged; the fake + transfer backend does not subclass it either + +------------------------------------------------------------------- New: ---- sglang-40185-bootstrap-room-dedup.patch ----------(New B)---------- New: killed the decode scheduler (boo#1283270) * sglang-40185-bootstrap-room-dedup.patch, two hunks of sgl-project/sglang PR 40185 (still unmerged, tracking issue ----------(New E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ python-sglang.spec ++++++ --- /var/tmp/diff_new_pack.u4iGHA/_old 2026-10-01 16:47:10.064349246 +0200 +++ /var/tmp/diff_new_pack.u4iGHA/_new 2026-10-01 16:47:10.067349372 +0200 @@ -52,6 +52,8 @@ Patch4: sglang-safe-unpickler-stdlib-globals.patch # PATCH-FIX-UPSTREAM sglang-safe-unpickler-explicit-globals.patch boo#1280091 -- CVE-2026-86793: sgl-project/sglang commit 5b42d10edf (PR 40259), drop the remaining module prefixes and route torch.storage._load_from_bytes through a weights_only torch.load Patch5: sglang-safe-unpickler-explicit-globals.patch +# PATCH-FIX-UPSTREAM sglang-40185-bootstrap-room-dedup.patch boo#1283270 -- CVE-2026-102634: sgl-project/sglang PR 40185 (unmerged, head commit 1901ddecfe), report an unknown bootstrap_room as KVPoll.Failed instead of letting check_status raise KeyError, and count KVPoll.Success as bootstrap-done; 2 of the PR's 27 files, the rest being a typing modernisation that does not apply to 0.5.20 +Patch6: sglang-40185-bootstrap-room-dedup.patch BuildRequires: %{python_module IPython} BuildRequires: %{python_module Pillow} BuildRequires: %{python_module SoundFile} ++++++ sglang-40185-bootstrap-room-dedup.patch ++++++ Restrict an unknown bootstrap_room lookup to a clean per-request failure Fixes CVE-2026-102634 (boo#1283270): bootstrap_room is client supplied and unauthenticated, and two concurrent requests picking the same value share one entry in CommonKVManager.request_status. When the first of them finishes, clear() pops that entry, and the second one's decode-side poll then raised KeyError out of check_status(), killing the scheduler process. The loser of the race instead hung until its transfer timed out. Carried from sgl-project/sglang PR 40185 (unmerged; head commit 1901ddecfebb5960bebcb237efb96397b85be355, tracking issue 40125, both still open). Only the two behavioural hunks of that PR are carried here. Its other 25 files are a PEP 604 typing modernisation plus import shuffling, which does not apply cleanly to the 0.5.20 tag and is not part of this fix. * check_status() reports an unregistered room as KVPoll.Failed instead of raising KeyError. KVPoll.Failed is already handled by DecodePreallocQueue, which aborts just that request with prepare_abort(); the scheduler and every other request survive. * The decode poll dispatch also treats KVPoll.Success as bootstrap-done, so a request whose shared room was completed by the colliding peer stops waiting for input instead of hitting decode.py's raise ValueError(f"Unexpected poll case: {poll}"), which killed the decode scheduler. --- python/sglang/srt/disaggregation/common/conn.py | 2 +- python/sglang/srt/disaggregation/decode.py | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/python/sglang/srt/disaggregation/common/conn.py b/python/sglang/srt/disaggregation/common/conn.py --- a/python/sglang/srt/disaggregation/common/conn.py +++ b/python/sglang/srt/disaggregation/common/conn.py @@ -390,7 +390,7 @@ ) def check_status(self, bootstrap_room: int) -> KVPoll: - return self.request_status[bootstrap_room] + return self.request_status.get(bootstrap_room, KVPoll.Failed) def update_status(self, bootstrap_room: int, status: KVPoll): current = self.request_status.get(bootstrap_room) diff --git a/python/sglang/srt/disaggregation/decode.py b/python/sglang/srt/disaggregation/decode.py --- a/python/sglang/srt/disaggregation/decode.py +++ b/python/sglang/srt/disaggregation/decode.py @@ -915,7 +915,7 @@ if poll == KVPoll.Bootstrapping: pass - elif poll == KVPoll.WaitingForInput: + elif poll in (KVPoll.WaitingForInput, KVPoll.Success): decode_req.waiting_for_input = True decode_req.req.time_stats.set_bootstrap_done_time() elif poll == KVPoll.Failed:
