Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package yast2-users for openSUSE:Factory checked in at 2026-10-02 23:02:20 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/yast2-users (Old) and /work/SRC/openSUSE:Factory/.yast2-users.new.1631729 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "yast2-users" Fri Oct 2 23:02:20 2026 rev:268 rq:1381935 version:5.0.9 Changes: -------- --- /work/SRC/openSUSE:Factory/yast2-users/yast2-users.changes 2026-03-27 06:53:59.573073789 +0100 +++ /work/SRC/openSUSE:Factory/.yast2-users.new.1631729/yast2-users.changes 2026-10-02 23:02:55.353235039 +0200 @@ -1,0 +2,7 @@ +Thu Aug 6 09:38:11 UTC 2026 - Noel Power <[email protected]> + +- CVE-2026-59680: OS command injection via LDAP-supplied + shadowLastChange/shadowExpire attribute (bsc#1272839). +- 5.0.9 + +------------------------------------------------------------------- @@ -13,0 +21,5 @@ +Thu Aug 21 08:50:55 UTC 2025 - Imobach Gonzalez Sosa <[email protected]> + +- Add a missing require (bsc#1248291). + +------------------------------------------------------------------- @@ -39,0 +52,5 @@ +Fri Sep 06 07:14:32 UTC 2024 - Ladislav Slezák <[email protected]> + +- Branch package for SP7 (bsc#1230201) + +------------------------------------------------------------------- @@ -1317 +1334 @@ ------------------------------------------------------------------- +------------------------------------------------------------------- Old: ---- yast2-users-5.0.8.tar.bz2 New: ---- yast2-users-5.0.9.tar.bz2 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ yast2-users.spec ++++++ --- /var/tmp/diff_new_pack.2O7gwq/_old 2026-10-02 23:02:56.452281039 +0200 +++ /var/tmp/diff_new_pack.2O7gwq/_new 2026-10-02 23:02:56.457281248 +0200 @@ -17,7 +17,7 @@ Name: yast2-users -Version: 5.0.8 +Version: 5.0.9 Release: 0 Summary: YaST2 - User and Group Configuration License: GPL-2.0-only ++++++ yast2-users-5.0.8.tar.bz2 -> yast2-users-5.0.9.tar.bz2 ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/yast2-users-5.0.8/README.md new/yast2-users-5.0.9/README.md --- old/yast2-users-5.0.8/README.md 2026-03-25 18:39:28.000000000 +0100 +++ new/yast2-users-5.0.9/README.md 2026-10-01 18:06:36.000000000 +0200 @@ -26,3 +26,47 @@ in every operation. Apart from the mentioned documents, the `doc` directory contains several files describing how both the old Perl and the new Ruby components work and the correspondences between them. + +# Development + +You need to prepare your environment with: + +``` +ruby_version=$(ruby -e "puts RbConfig::CONFIG['ruby_version']") +zypper install -C "rubygem(ruby:$ruby_version:yast-rake)" +zypper install -C "rubygem(ruby:$ruby_version:rspec)" +zypper install git yast2-devtools yast2-testsuite cracklib perl-Digest-SHA1 perl-X500-DN perl-gettext yast2-security yast2-perl-bindings yast2-ldap yast2-pam +``` + +You can then run the auth-server module with: + +``` +rake run +rake run[module name] +``` + +# Tests + +``` +rake test:unit +``` + +# Logs + +If you are running as a non-root user, the logs are located in: + +``` +~/.y2log +``` + +If you are running as root, these logs are in: + +``` +/var/log/YaST2/y2log +``` + +For more detailed logging, you are able to execute YaST with debugging environment variables: + +``` +Y2DEBUG=1 rake run[module name] +``` diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/yast2-users-5.0.8/package/yast2-users.changes new/yast2-users-5.0.9/package/yast2-users.changes --- old/yast2-users-5.0.8/package/yast2-users.changes 2026-03-25 18:39:28.000000000 +0100 +++ new/yast2-users-5.0.9/package/yast2-users.changes 2026-10-01 18:06:36.000000000 +0200 @@ -1,8 +1,15 @@ ------------------------------------------------------------------- +Thu Aug 6 09:38:11 UTC 2026 - Noel Power <[email protected]> + +- CVE-2026-59680: OS command injection via LDAP-supplied + shadowLastChange/shadowExpire attribute (bsc#1272839). +- 5.0.9 + +------------------------------------------------------------------- Tue Mar 10 09:00:28 UTC 2026 - Michal Filka <[email protected]> - jsc#PED-14507 - - Removed reference to update-desktop-files from spec file + - Removed reference to update-desktop-files from spec file - 5.0.8 ------------------------------------------------------------------- Mon Oct 13 14:09:17 UTC 2025 - Stefan Schubert <[email protected]> @@ -11,6 +18,11 @@ - 5.0.7 ------------------------------------------------------------------- +Thu Aug 21 08:50:55 UTC 2025 - Imobach Gonzalez Sosa <[email protected]> + +- Add a missing require (bsc#1248291). + +------------------------------------------------------------------- Fri Jul 4 15:47:36 UTC 2025 - Imobach Gonzalez Sosa <[email protected]> - Temporarily disable Y2Users::Clients::Auto#run tests @@ -32,9 +44,14 @@ ------------------------------------------------------------------- Tue Oct 1 13:31:05 UTC 2024 - Stefan Hundhammer <[email protected]> -- Removed obsolete USERADD_CMD, USERDEL_PRECMD, USERDEL_POSTCMD, +- Removed obsolete USERADD_CMD, USERDEL_PRECMD, USERDEL_POSTCMD, GROUPADD_CMD (bsc#1231006) -- 5.0.3 +- 5.0.3 + +------------------------------------------------------------------- +Fri Sep 06 07:14:32 UTC 2024 - Ladislav Slezák <[email protected]> + +- Branch package for SP7 (bsc#1230201) ------------------------------------------------------------------- Wed Aug 21 13:21:10 UTC 2024 - Stefan Hundhammer <[email protected]> @@ -1314,7 +1331,7 @@ - empty hash before reading, to avoid caching problems (bnc#580167) - 2.19.3 ------------------------------------------------------------------- +------------------------------------------------------------------- Wed Jan 13 18:56:03 CET 2010 - [email protected] - Adjusted .desktop file(s) to wrap /sbin/yast2/ calls in xdg-su diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/yast2-users-5.0.8/package/yast2-users.spec new/yast2-users-5.0.9/package/yast2-users.spec --- old/yast2-users-5.0.8/package/yast2-users.spec 2026-03-25 18:39:28.000000000 +0100 +++ new/yast2-users-5.0.9/package/yast2-users.spec 2026-10-01 18:06:36.000000000 +0200 @@ -17,7 +17,7 @@ Name: yast2-users -Version: 5.0.8 +Version: 5.0.9 Release: 0 Summary: YaST2 - User and Group Configuration License: GPL-2.0-only diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/yast2-users-5.0.8/src/include/users/dialogs.rb new/yast2-users-5.0.9/src/include/users/dialogs.rb --- old/yast2-users-5.0.8/src/include/users/dialogs.rb 2026-03-25 18:39:28.000000000 +0100 +++ new/yast2-users-5.0.9/src/include/users/dialogs.rb 2026-10-01 18:06:36.000000000 +0200 @@ -29,10 +29,10 @@ require "pathname" require "shellwords" - require "users/ssh_public_key" require "yast2/popup" require "y2users/username" +require "yast2/execute" module Yast module UsersDialogsInclude @@ -206,7 +206,7 @@ # @param date_format [String] strftime format like "%x" (localized date) # @return [String] def format_days_after_epoch(count, date_format) - `date --date='1970-01-01 00:00:01 #{count} days' +#{date_format}`.chomp + Yast::Execute.locally!.stdout("/usr/bin/date", "--date=1970-01-01 00:00:01 #{count} days", "+#{date_format}").chomp end # generate contents for Password Settings Dialog @@ -214,23 +214,22 @@ # @param exp_date [String] may be MODIFIED on return corresponding to the UI # @return [Term] ui_term def get_password_term(user, exp_date) - last_change = GetString(Ops.get(user, "shadowLastChange"), "0") + last_change = GetInt(Ops.get(user, "shadowLastChange"), 0) last_change_label = "" - expires = GetString(Ops.get(user, "shadowExpire"), "0") - expires = "0" if expires == "" + expires = GetInt(Ops.get(user, "shadowExpire"), 0) inact = GetInt(Ops.get(user, "shadowInactive"), -1) max = GetInt(Ops.get(user, "shadowMax"), -1) min = GetInt(Ops.get(user, "shadowMin"), -1) warn = GetInt(Ops.get(user, "shadowWarning"), -1) - if last_change != "0" + if last_change != 0 last_change_label = format_days_after_epoch(last_change, "%x") else # label (date of last password change) last_change_label = _("Never") end - unless ["0", "-1", ""].include?(expires) + unless [0, -1].include?(expires) exp_date.replace(format_days_after_epoch(expires, "%Y-%m-%d")) end HBox( diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/yast2-users-5.0.8/src/lib/y2users/autoinst_profile/user_section.rb new/yast2-users-5.0.9/src/lib/y2users/autoinst_profile/user_section.rb --- old/yast2-users-5.0.8/src/lib/y2users/autoinst_profile/user_section.rb 2026-03-25 18:39:28.000000000 +0100 +++ new/yast2-users-5.0.9/src/lib/y2users/autoinst_profile/user_section.rb 2026-10-01 18:06:36.000000000 +0200 @@ -89,8 +89,7 @@ # @return [String,nil] Default shell # # @!attribute user_password - # @return [String,nil] User's password. If set to an exclamation mark ('!'), - # a random password is generated. See #encrypted. + # @return [String,nil] User's password. # # @!attribute encrypted # @return [Boolean,nil] Determine whether #user_password is encrypted or not. diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/yast2-users-5.0.8/test/dialogs_test.rb new/yast2-users-5.0.9/test/dialogs_test.rb --- old/yast2-users-5.0.8/test/dialogs_test.rb 2026-03-25 18:39:28.000000000 +0100 +++ new/yast2-users-5.0.9/test/dialogs_test.rb 2026-10-01 18:06:36.000000000 +0200 @@ -20,6 +20,22 @@ allow(Yast).to receive(:import).with("LdapPopup") end + describe "#GetString" do + context "when number" do + it "returns stringified number" do + expect(subject.GetString(1, "default")).to eq("1") + end + end + end + + describe "#GetString" do + context "when string" do + it "returns string" do + expect(subject.GetString("not default", "default")).to eq("not default") + end + end + end + describe "#cleanpath" do it "returns sanitized path" do expect(subject.cleanpath("/home/user/")).to eq("/home/user")
