gpo.zugaina.org

Search Portage & Overlays:

sys-cluster/csync2

Cluster synchronization tool

Screenshots

  • csync2-2.0-r6
    amd64 ~arm x86
    mysql postgres sqlite ssl xinetd

    View      Download      Browse     License: GPL-2   
    Overlay: bes

ChangeLog

commit 789b214467cdda4752a9bd14ce0fac2c5eebf0db
Author: Vladimir Varlamov <bes.internal@gmail.com>
Date: Fri Sep 25 16:40:30 2026 +0300

sys-cluster/csync2: 2.0-r6, security: fix get_tmpname() buffer overflow

Adds LINBIT/csync2#50 as a separate patch file; README notes it.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

commit 4b135bdc75896740ce051aa75039e296b4d9a597
Author: Vladimir Varlamov <bes.internal@gmail.com>
Date: Fri Sep 25 16:34:46 2026 +0300

sys-cluster/csync2: 2.0-r5, security: fix stack-use-after-scope in pre-auth reply

Adds LINBIT/csync2#49 as a separate patch file; README notes it.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

commit f623ebe851a4de372001858580724caa6a36fc6c
Author: Vladimir Varlamov <bes.internal@gmail.com>
Date: Fri Sep 18 12:15:54 2026 +0300

sys-cluster/csync2: bump network chunk size to 16 KiB, bump to r4

Follow-up to the #45 fix (in the same patch file): csync_send_file(),
csync_recv_file() and csync_rs_check() moved file payloads in
512-byte chunks, roughly one TLS record per 512 bytes of data - a lot
of overhead versus the 16 KiB a TLS record actually holds. Bumping to
16384 (the max TLS record payload) roughly halved sync time in
upstream's own testing (1938s -> 979s for 31.66 GB / 56525 files).
Depends on the #45 retry fix already in this ebuild: above the TLS
record limit, a short count from gnutls_record_send() used to be
treated as fatal by csync_send_file().

Taken from: https://github.com/LINBIT/csync2/issues/46

Bumped r3 -> r4 since this changes an already-published ebuild's
patch content, per AGENTS.md's -rN rule. Verified with
ebuild ... clean compile on the amd64 target; confirmed CSYNC_CHUNK
is in the prepared rsync.c.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

commit 71af5f6747609aea861402eb0f93ecfa7519fbaa
Author: Vladimir Varlamov <bes.internal@gmail.com>
Date: Fri Sep 18 00:27:05 2026 +0300

sys-cluster/csync2: fix GNUTLS_E_AGAIN treated as fatal, bump to r3

conn_read()/conn_write() returned gnutls_record_recv/send's result
directly, so GNUTLS_E_AGAIN or GNUTLS_E_INTERRUPTED (e.g. on a
non-blocking or signal-interrupted socket) was treated as a fatal
read/write failure rather than retried. In practice this aborts large
syncs part-way through once a recv/send call happens to return
GNUTLS_E_AGAIN. Writes could also silently short-write since the
return value ignored partial sends. Retry recv on those two codes, and
loop send() until all bytes are sent or a real error/EOF occurs.

Bumped csync2-2.0-r2 -> -r3 since this modifies an already-published
ebuild for the same upstream version (see AGENTS.md's -rN rule).
Verified with ebuild ... clean compile on the amd64 target; confirmed
the patched code is present in the prepared source.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

commit 4418c8a29bdda719f8297d8fead1484ff9884bcc
Author: Vladimir Varlamov <bes.internal@gmail.com>
Date: Tue Sep 5 11:36:52 2023 +0300

eapi 7->8, * softether build

commit a14900f494d7dec55ad169f4389e6df7b1f9b044
Author: Vladimir Varlamov <bes.internal@gmail.com>
Date: Tue Jun 21 11:32:27 2022 +0300

+ sys-cluster/csync2