testing

rsync-3.4.4-1.fc44

FEDORA-2026-e3308c2bfe created by mruprich a month ago for Fedora 44

New version 3.4.4 with multiple regression fixes. This update also fixes the following CVEs: CVE-2026-29518 CVE-2026-43617 CVE-2026-43618 CVE-2026-43619 CVE-2026-43620 CVE-2026-45232

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-e3308c2bfe

This update has been submitted for testing by mruprich.

a month ago

This update's test gating status has been changed to 'failed'.

a month ago

This update's test gating status has been changed to 'failed'.

a month ago

This update's test gating status has been changed to 'waiting'.

a month ago

This update's test gating status has been changed to 'failed'.

a month ago
User Icon bojan commented & provided feedback a month ago

This seems to have the wrong build attached to it: 3.4.3.

This update has been pushed to testing.

a month ago
User Icon bojan commented & provided feedback a month ago
karma

Yeah, still 3.4.3:

$ rsync --version
rsync  version 3.4.3  protocol version 32
Copyright (C) 1996-2026 by Andrew Tridgell, Wayne Davison, and others.
[...]

Bodhi is disabling automatic push to stable due to negative karma. The maintainer may push manually if they determine that the issue is not severe.

a month ago

mruprich edited this update.

New build(s):

  • rsync-3.4.4-1.fc44

Removed build(s):

  • rsync-3.4.3-1.fc44

Karma has been reset.

a month ago

This update has been submitted for testing by mruprich.

a month ago

This update's test gating status has been changed to 'waiting'.

a month ago
User Icon mruprich commented & provided feedback a month ago

Thanks, clicked on the wrong one. Fixed.

This update's test gating status has been changed to 'failed'.

a month ago
User Icon imabug provided feedback a month ago
karma
BZ#2486185 rsync-3.4.4 is available

This update has been pushed to testing.

a month ago
User Icon derekenz commented & provided feedback a month ago
karma

Works

User Icon besser82 commented & provided feedback a month ago
karma

Works great! LGTM! =)

User Icon lecris commented & provided feedback 4 weeks ago

If you retrigger the tests they would pass. But do beware that the tests seem very minimal as they did not catch the failures in 3.4.3. Is everything really working well now?

There still seem to be regression reports pouring in https://github.com/RsyncProject/rsync/issues/1002

User Icon bojan commented & provided feedback 4 weeks ago
karma

It works for me, but I only tried it against the identical version on the other end.

karma
User Icon filiperosset commented & provided feedback 3 weeks ago
karma

no regressions noted

This update's test gating status has been changed to 'waiting'.

2 weeks ago
User Icon mruprich commented & provided feedback 2 weeks ago

@lecris - it is quite impossible to test for every possible use case, even if I wanted to. We have much more tests in RHEL where I tested the 3.4.4 version recently and they all pass. I am monitoring the Upstream github and I'll make more updates if there are more regressions. All in all I think that this update is alright, compared to the 3.4.3 that I unpushed last time.

This update's test gating status has been changed to 'failed'.

2 weeks ago
User Icon lecris commented & provided feedback 2 weeks ago

The AVC failure looks relevant

----
type=AVC msg=audit(06/23/26 07:24:23.201:1266) : avc:  denied  { setpgid } for  pid=7863 comm=timeout scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tclass=process permissive=1 
----
type=AVC msg=audit(06/23/26 07:24:23.209:1267) : avc:  denied  { name_connect } for  pid=7865 comm=curl dest=80 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:http_port_t:s0 tclass=tcp_socket permissive=1

Are you tracking it?

User Icon lecris commented & provided feedback 2 weeks ago

Also the rpminspect results are worth forwarding to upstream

Forbidden function symbols found:
    gethostbyname
    inet_ntoa

Forbidden symbols were found in an ELF file in the package. The configuration settings for rpminspect indicate the named symbols are forbidden in packages. If this is deliberate, you may want to disable the badfuncs inspection. If it is not deliberate, check the man pages for the named symbols to see what API functions have replaced the forbidden symbols. Usually a function is marked as deprecated but still provided in order to allow for backwards compatibility. Whenever possible the deprecated functions should not be used.

This update's test gating status has been changed to 'waiting'.

2 weeks ago

This update's test gating status has been changed to 'passed'.

2 weeks ago

This update can be pushed to stable now if the maintainer wishes

2 weeks ago
User Icon mruprich commented & provided feedback 2 weeks ago

I have the rpminspect check turned off in rawhide - https://src.fedoraproject.org/rpms/rsync/blob/rawhide/f/rpminspect.yaml - both usages are deliberate either as a fallback for systems where there is no better alternative or after IPv6 have already been tried.

I don't think the AVCs are related to rsync, feel free to elaborate if you think they are. This is rather the test design flaw (I will look into that). One AVC is from curl the other is most likely from the beaker itself, the setting of a timeout might trigger that but like I said, I will take a good look at the test.

User Icon lecris commented & provided feedback 2 weeks ago
I have the rpminspect check turned off in rawhide - https://src.fedoraproject.org/rpms/rsync/blob/rawhide/f/rpminspect.yaml - both usages are deliberate either as a fallback for systems where there is no better alternative or after IPv6 have already been tried.

Well you did not port it to the branches

I don't think the AVCs are related to rsync, feel free to elaborate if you think they are. This is rather the test design flaw (I will look into that). One AVC is from curl the other is most likely from the beaker itself, the setting of a timeout might trigger that but like I said, I will take a good look at the test.

The thing that raises my suspicion is that I do not see a similar issue avc issue across other tests. Granted, many of them did not enable avc check. The failure looks very ssh related, which is why it looks suspicious. The root cause might not be here, but knowing which component caused this failure would help point on the update that caused this

User Icon imabug provided feedback a week ago
karma
User Icon bdprom commented & provided feedback 3 days ago
karma

Working well, incl SSH transfers.

User Icon rai510 provided feedback 2 days ago
karma

Please log in to add feedback.

Metadata
Type
unspecified
Karma
8
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
disabled
Stable by Time
disabled
Thresholds
Minimum Karma
+2
Minimum Testing
14 days
Dates
submitted
a month ago
in testing
a month ago
modified
a month ago
approved
2 weeks ago
BZ#2463360 rsync-3.4.3 is available
0
0
BZ#2480388 CVE-2026-45232 rsync: Rsync: Denial of Service via malformed HTTP proxy response [fedora-all]
0
0
BZ#2486185 rsync-3.4.4 is available
0
0

Automated Test Results