[openstack-dev] [stable] Swift object-updater and container-updater

Minwoo Bae minwoob at us.ibm.com
Thu Jan 8 15:21:58 UTC 2015


Hi, to whom it may concern:


Jay Bryant and I would like to have the fixes for the Swift object-updater 
(https://review.openstack.org/#/c/125746/) and the Swift container-updater 
(
https://review.openstack.org/#/q/I7eed122bf6b663e6e7894ace136b6f4653db4985,n,z
) backported to Juno and then to Icehouse soon if possible. It's been in 
the queue for a while now, so we were wondering if we could have an 
estimated time for delivery? 

Icehouse is in security-only mode, but the container-updater issue may 
potentially be used as a fork-bomb, which presents security concerns. To 
further justify the fix, a problem of similar nature 
https://review.openstack.org/#/c/126371/ (regarding the object-auditor) 
was successfully fixed in stable/icehouse. 

The object-updater issue may potentially have some security implications 
as well. 


Thank you very much! 

Minwoo
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openstack.org/pipermail/openstack-dev/attachments/20150108/052ffee6/attachment.html>


More information about the OpenStack-dev mailing list