diff --git a/harden_rabbitmq-server.service.patch b/harden_rabbitmq-server.service.patch deleted file mode 100644 index 4ac4ae9..0000000 --- a/harden_rabbitmq-server.service.patch +++ /dev/null @@ -1,22 +0,0 @@ ---- a/deps/rabbit/docs/rabbitmq-server.service.example -+++ b/deps/rabbit/docs/rabbitmq-server.service.example -@@ -5,6 +5,19 @@ After=network.target epmd@0.0.0.0.socket - Wants=network.target epmd@0.0.0.0.socket - - [Service] -+# added automatically, for details please see -+# https://en.opensuse.org/openSUSE:Security_Features#Systemd_hardening_effort -+ProtectSystem=full -+ProtectHome=true -+PrivateDevices=true -+ProtectHostname=true -+ProtectClock=true -+ProtectKernelTunables=true -+ProtectKernelModules=true -+ProtectKernelLogs=true -+ProtectControlGroups=true -+RestrictRealtime=true -+# end of automatic additions - Type=notify - User=rabbitmq - Group=rabbitmq diff --git a/rabbitmq-server-3.9.11.tar.xz b/rabbitmq-server-3.9.11.tar.xz new file mode 100644 index 0000000..2d81b00 --- /dev/null +++ b/rabbitmq-server-3.9.11.tar.xz @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:88908f27293f2d86dc94c70567f26afc1849fc7c1e174510a6c3c0fca1d3f547 +size 4755696 diff --git a/rabbitmq-server-3.9.11.tar.xz.asc b/rabbitmq-server-3.9.11.tar.xz.asc new file mode 100644 index 0000000..27c2731 --- /dev/null +++ b/rabbitmq-server-3.9.11.tar.xz.asc @@ -0,0 +1,16 @@ +-----BEGIN PGP SIGNATURE----- + +iQIzBAABCgAdFiEECpryEV9Gh70pgDoga3OjbmAm38oFAmGoZ70ACgkQa3OjbmAm +38qBhRAAqtLvlQynh3P+0CV7/TPzWNG4GagYG1Cj3MUNatyExKXnTaBbtnes+9jh +hsB6LOYV7LjCepnA6LtDqQu7Iw3xvHVtNG3TBNhZY0HMVT1heFxZSpKYYwkFFX9r +mxrXF+ZEdvEAwufHJQK8HSf3+d3lNh7oJF+XUzt1p4Eev4/1OIF6W7MI21FGzpgC +cHdprH3V1bowGo7bstykLlHD5pGL4muQ9Yv1BgIv/epPynODpS02d7++aYINZDQG +ErAAQVaN/v2DSUyCpBFGlhxvl3AwmxhauoZ4g2DqMRTeRyRDHQnJRQz+U7VkQ6Ih +ZwcxCK2FQlcChAD9+bye6TgjnvICNRzkyhDTJ73QDLeIOqTDCV9YUKycwxcVMoMF +nSOSMRmIncoy540tp5RK0ELdtkppq8HNvwA7VvFifjYXobQPKAW6p2CnHRx9IAC6 +Jmry/70mB1futAONxI+XEitUoY8fUqYXsnz6BnXG4/yFJY1gT5Ximn/fCJqP/yuh +MBtp+048HMEpwP6jwsYvMKJP3dEi3gvSLcv3J+MAhkPy6ekQT1ESWt7mt/4AVhYZ +9Xx9OJnHse+TDyPFhwA0kQD9+9fCRL48Rwza/0yF++ias3a2FHyFwljNufwRCrPx +HVVASQdoTTIKseAfU9rotzX+63jJiqCySrBVLM7ltLM9Ix373uQ= +=Yf28 +-----END PGP SIGNATURE----- diff --git a/rabbitmq-server-3.9.9.tar.xz b/rabbitmq-server-3.9.9.tar.xz deleted file mode 100644 index 97f9b8a..0000000 --- a/rabbitmq-server-3.9.9.tar.xz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:1c9a78516f2fb35bf9cd4133daee1fb3cec597f8de70fe8ee1af59232ac93562 -size 4749872 diff --git a/rabbitmq-server-3.9.9.tar.xz.asc b/rabbitmq-server-3.9.9.tar.xz.asc deleted file mode 100644 index 71baebc..0000000 --- a/rabbitmq-server-3.9.9.tar.xz.asc +++ /dev/null @@ -1,16 +0,0 @@ ------BEGIN PGP SIGNATURE----- - -iQIzBAABCgAdFiEECpryEV9Gh70pgDoga3OjbmAm38oFAmGNJo8ACgkQa3OjbmAm -38pufQ/9GKOzjpWLXa/mo9dGH5RuU8Zsk6VhDhr1iytOIuZZs4//T/z1Cers6hjU -8Rb5I9G7KGKvHk+fAp5zUY6IgFVwkmQ6KYyIFJyTVbCrBx6PyPDTC/LIl6bFeLEL -huyMQRJ6KLujGCRty2Lg7HWX4DWaj5VBA0SV26yTmBBmAkwqZ3G7Ub7BRrsMOGZz -V4oAyrrOLiLDMOYiCAcg1nEJZ+WgUHLP5bYBzjmst8RU208r3A4thpQIVQU7Ep60 -4KMFV721yyrAl2a4sn34hMQirSAe/7MYZBkrQxq5p99iFYnkscnX46WSRyT7wZeh -U4ZMkyqxv4s5P78umzyRtaN3Tou37Yn9O7sVTrqQX7bTgZbvPNGDJ2MrJOqnHYIO -2/OFfoIgYkmPKQvd8tM0mHXrTEvspK5OId5kC5/YSnJcxTS8AFgb12eTNXepVP66 -PiNRLW2Zb6FPDhrO94mF3jBO4mhbLQBkMc3oxHK0hVBXI52SWExkijPLSBzCSwUo -L5+kAciNls2FPakKhhMwQmCLDg3+L++l9h2IX2Y/2Y5iUl7QcYgAgwPWMvWejaDo -myvuuF63KTrY6kxaXDcm8VSQgTG46lLtOBer8q90gh+zb2+BwUtONLHzNZvj1TZG -eeyfLQxeThaQStHOApZ5bN+qPMQilAMqQhuIGw5pUMN/GGduz9I= -=XTaV ------END PGP SIGNATURE----- diff --git a/rabbitmq-server.changes b/rabbitmq-server.changes index c63ff03..a34f4b3 100644 --- a/rabbitmq-server.changes +++ b/rabbitmq-server.changes @@ -1,3 +1,41 @@ +------------------------------------------------------------------- +Thu Dec 2 15:17:05 UTC 2021 - Fusion Future + +- Update to 3.9.11 + * Core Server Bug Fixes + - When a TLS-enabled listener failed to stop, it logged all of + its settings which could contain sensitive values. + * Core Server Enhancements + - Quorum queues now store commands for enqueued messages in a + more compact format on disk (some derivative data has been dropped). + - queue.declare-ok response to AMQP 0-9-1 clients operating on + a stream could return a ready-for-delivery message count + value that was out of sync with the stream leader replica. + - Classic queues now deliver more efficiently on channels that + had global QoS changed during consumer operation. + * Prometheus Plugin Enhancements + - New optional metrics provided by the GET /metrics/detailed + endpoint. These metrics are cluster-wide, and therefore must + not be aggregated. + * Management Agent Plugin Enhancements + - Disabling the plugin will stop metric collection performed + periodically by queues, streams, connections, et cetera. +- Changes in 3.9.10: + * Core Server Bug Fixes + - Make stream coordinator more defensive to rapid declaration + and deletion cycles. + * Core Server Enhancements + - Several inter-node communication listener settings are now + exposed to rabbitmq.conf: + + distribution.listener.port_range.min = 25675 + + distribution.listener.port_range.max = 25675 + + distribution.listener.interface = 192.168.0.1 + * OAuth 2 Plugin Bug Fixes + - Signing keys specified in rabbitmq.conf were not translated + correctly, resulting in exceptions during permission checks. +- Drop upstreamed patch + * harden_rabbitmq-server.service.patch: https://github.com/rabbitmq/rabbitmq-server/pull/3770 + ------------------------------------------------------------------- Fri Nov 19 02:39:00 UTC 2021 - Fusion Future diff --git a/rabbitmq-server.spec b/rabbitmq-server.spec index dc96fca..4daacb4 100644 --- a/rabbitmq-server.spec +++ b/rabbitmq-server.spec @@ -39,7 +39,7 @@ %define _rabbitmq_group rabbitmq Name: rabbitmq-server -Version: 3.9.9 +Version: 3.9.11 Release: 0 Summary: A message broker supporting AMQP, STOMP and MQTT License: MPL-2.0 @@ -52,7 +52,6 @@ Source4: rabbitmq-env.conf Source6: rabbitmq-server.service Source7: https://raw.githubusercontent.com/rabbitmq/rabbitmq-packaging/v%{version}/RPMS/Fedora/rabbitmq-server.tmpfiles Source8: README.SUSE -Patch0: harden_rabbitmq-server.service.patch BuildRequires: elixir # https://www.rabbitmq.com/which-erlang.html BuildRequires: erlang >= 23.2 @@ -129,7 +128,6 @@ Optional dependency offering zsh completion for %{name}. %prep %setup -q cp %{SOURCE8} . -%patch0 -p1 %build # Make elixir happy with Unicode