sys-cluster/csync2
Cluster synchronization tool
ChangeLog
commit 789b214467cdda4752a9bd14ce0fac2c5eebf0db
Author: Vladimir Varlamov <bes.internal@gmail.com>
Date: Fri Sep 25 16:40:30 2026 +0300
sys-cluster/csync2: 2.0-r6, security: fix get_tmpname() buffer overflow
Adds LINBIT/csync2#50 as a separate patch file; README notes it.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
commit 4b135bdc75896740ce051aa75039e296b4d9a597
Author: Vladimir Varlamov <bes.internal@gmail.com>
Date: Fri Sep 25 16:34:46 2026 +0300
sys-cluster/csync2: 2.0-r5, security: fix stack-use-after-scope in pre-auth reply
Adds LINBIT/csync2#49 as a separate patch file; README notes it.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
commit f623ebe851a4de372001858580724caa6a36fc6c
Author: Vladimir Varlamov <bes.internal@gmail.com>
Date: Fri Sep 18 12:15:54 2026 +0300
sys-cluster/csync2: bump network chunk size to 16 KiB, bump to r4
Follow-up to the #45 fix (in the same patch file): csync_send_file(),
csync_recv_file() and csync_rs_check() moved file payloads in
512-byte chunks, roughly one TLS record per 512 bytes of data - a lot
of overhead versus the 16 KiB a TLS record actually holds. Bumping to
16384 (the max TLS record payload) roughly halved sync time in
upstream's own testing (1938s -> 979s for 31.66 GB / 56525 files).
Depends on the #45 retry fix already in this ebuild: above the TLS
record limit, a short count from gnutls_record_send() used to be
treated as fatal by csync_send_file().
Taken from: https://github.com/LINBIT/csync2/issues/46
Bumped r3 -> r4 since this changes an already-published ebuild's
patch content, per AGENTS.md's -rN rule. Verified with
ebuild ... clean compile on the amd64 target; confirmed CSYNC_CHUNK
is in the prepared rsync.c.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
commit 71af5f6747609aea861402eb0f93ecfa7519fbaa
Author: Vladimir Varlamov <bes.internal@gmail.com>
Date: Fri Sep 18 00:27:05 2026 +0300
sys-cluster/csync2: fix GNUTLS_E_AGAIN treated as fatal, bump to r3
conn_read()/conn_write() returned gnutls_record_recv/send's result
directly, so GNUTLS_E_AGAIN or GNUTLS_E_INTERRUPTED (e.g. on a
non-blocking or signal-interrupted socket) was treated as a fatal
read/write failure rather than retried. In practice this aborts large
syncs part-way through once a recv/send call happens to return
GNUTLS_E_AGAIN. Writes could also silently short-write since the
return value ignored partial sends. Retry recv on those two codes, and
loop send() until all bytes are sent or a real error/EOF occurs.
Bumped csync2-2.0-r2 -> -r3 since this modifies an already-published
ebuild for the same upstream version (see AGENTS.md's -rN rule).
Verified with ebuild ... clean compile on the amd64 target; confirmed
the patched code is present in the prepared source.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
commit 4418c8a29bdda719f8297d8fead1484ff9884bcc
Author: Vladimir Varlamov <bes.internal@gmail.com>
Date: Tue Sep 5 11:36:52 2023 +0300
eapi 7->8, * softether build
commit a14900f494d7dec55ad169f4389e6df7b1f9b044
Author: Vladimir Varlamov <bes.internal@gmail.com>
Date: Tue Jun 21 11:32:27 2022 +0300
+ sys-cluster/csync2
Author: Vladimir Varlamov <bes.internal@gmail.com>
Date: Fri Sep 25 16:40:30 2026 +0300
sys-cluster/csync2: 2.0-r6, security: fix get_tmpname() buffer overflow
Adds LINBIT/csync2#50 as a separate patch file; README notes it.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
commit 4b135bdc75896740ce051aa75039e296b4d9a597
Author: Vladimir Varlamov <bes.internal@gmail.com>
Date: Fri Sep 25 16:34:46 2026 +0300
sys-cluster/csync2: 2.0-r5, security: fix stack-use-after-scope in pre-auth reply
Adds LINBIT/csync2#49 as a separate patch file; README notes it.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
commit f623ebe851a4de372001858580724caa6a36fc6c
Author: Vladimir Varlamov <bes.internal@gmail.com>
Date: Fri Sep 18 12:15:54 2026 +0300
sys-cluster/csync2: bump network chunk size to 16 KiB, bump to r4
Follow-up to the #45 fix (in the same patch file): csync_send_file(),
csync_recv_file() and csync_rs_check() moved file payloads in
512-byte chunks, roughly one TLS record per 512 bytes of data - a lot
of overhead versus the 16 KiB a TLS record actually holds. Bumping to
16384 (the max TLS record payload) roughly halved sync time in
upstream's own testing (1938s -> 979s for 31.66 GB / 56525 files).
Depends on the #45 retry fix already in this ebuild: above the TLS
record limit, a short count from gnutls_record_send() used to be
treated as fatal by csync_send_file().
Taken from: https://github.com/LINBIT/csync2/issues/46
Bumped r3 -> r4 since this changes an already-published ebuild's
patch content, per AGENTS.md's -rN rule. Verified with
ebuild ... clean compile on the amd64 target; confirmed CSYNC_CHUNK
is in the prepared rsync.c.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
commit 71af5f6747609aea861402eb0f93ecfa7519fbaa
Author: Vladimir Varlamov <bes.internal@gmail.com>
Date: Fri Sep 18 00:27:05 2026 +0300
sys-cluster/csync2: fix GNUTLS_E_AGAIN treated as fatal, bump to r3
conn_read()/conn_write() returned gnutls_record_recv/send's result
directly, so GNUTLS_E_AGAIN or GNUTLS_E_INTERRUPTED (e.g. on a
non-blocking or signal-interrupted socket) was treated as a fatal
read/write failure rather than retried. In practice this aborts large
syncs part-way through once a recv/send call happens to return
GNUTLS_E_AGAIN. Writes could also silently short-write since the
return value ignored partial sends. Retry recv on those two codes, and
loop send() until all bytes are sent or a real error/EOF occurs.
Bumped csync2-2.0-r2 -> -r3 since this modifies an already-published
ebuild for the same upstream version (see AGENTS.md's -rN rule).
Verified with ebuild ... clean compile on the amd64 target; confirmed
the patched code is present in the prepared source.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
commit 4418c8a29bdda719f8297d8fead1484ff9884bcc
Author: Vladimir Varlamov <bes.internal@gmail.com>
Date: Tue Sep 5 11:36:52 2023 +0300
eapi 7->8, * softether build
commit a14900f494d7dec55ad169f4389e6df7b1f9b044
Author: Vladimir Varlamov <bes.internal@gmail.com>
Date: Tue Jun 21 11:32:27 2022 +0300
+ sys-cluster/csync2


View
Download
Browse