[arvados] updated: 2.1.0-2955-g83974ae9d

git repository hosting git at public.arvados.org
Thu Oct 13 15:55:44 UTC 2022


Summary of changes:
 build/run-tests.sh                                   |  1 +
 doc/admin/upgrading.html.textile.liquid              |  4 ++++
 doc/install/install-shell-server.html.textile.liquid | 12 +++++-------
 services/login-sync/arvados-login-sync.gemspec       |  6 +++++-
 services/login-sync/bin/arvados-login-sync           | 17 +++++++++++------
 5 files changed, 26 insertions(+), 14 deletions(-)

       via  83974ae9df4060f7aaa6bba61997404a2a7405b2 (commit)
       via  1227556ee452f52b193645eeccc56f2d27412f82 (commit)
       via  d10a5d8046abe616757bb0d8e2ed0a10c08c969d (commit)
       via  7ebb93e3fa84e614c775abdd36e95151297ed4a9 (commit)
       via  7ce7361f6495575d0ca32abeb758536259a0984f (commit)
       via  56e76a59d6a25286e268b9988cb8ed104318a40e (commit)
       via  084c954997410e05b1b2285255f16e9b5d536d5b (commit)
      from  b269c193cb54638a78b8542381f5042a68579654 (commit)

Those revisions listed above that are new to this repository have
not appeared on any other notification email; so we list those
revisions in full, below.


commit 83974ae9df4060f7aaa6bba61997404a2a7405b2
Merge: b269c193c 1227556ee
Author: Lucas Di Pentima <lucas.dipentima at curii.com>
Date:   Thu Oct 13 12:54:15 2022 -0300

    Merge branch '19400-login-sync-logincluster'. Closes #19400
    
    Arvados-DCO-1.1-Signed-off-by: Lucas Di Pentima <lucas.dipentima at curii.com>

diff --cc doc/admin/upgrading.html.textile.liquid
index 7ee8fbb08,8ed5af19c..a3717e3c5
--- a/doc/admin/upgrading.html.textile.liquid
+++ b/doc/admin/upgrading.html.textile.liquid
@@@ -28,33 -28,14 +28,37 @@@ TODO: extract this information based o
  <div class="releasenotes">
  </notextile>
  
 -h2(#main). development main (as of 2022-08-26)
  
 -"previous: Upgrading to 2.4.2":#v2_4_2
 +h2(#main). development main (as of 2022-09-21)
 +
 +"previous: Upgrading to 2.4.3":#v2_4_3
  
+ h3. Login-sync script requires configuration update on LoginCluster federations
+ 
+ If you have @arvados-login-sync@ running on a satellite cluster, please update the environment variable settings by removing the @LOGINCLUSTER_ARVADOS_API_*@ variables and setting @ARVADOS_API_TOKEN@ to a LoginCluster's admin token, as described on the "updated install page":{{site.baseurl}}/install/install-shell-server.html#arvados-login-sync.
+ 
 +h3. Renamed keep-web metrics and WebDAV configs
 +
 +Metrics previously reported by keep-web (@arvados_keepweb_collectioncache_requests@, @..._hits@, @..._pdh_hits@, @..._api_calls@, @..._cached_manifests@, and @arvados_keepweb_sessions_cached_collection_bytes@) have been replaced with @arvados_keepweb_cached_session_bytes at .
 +
 +The config entries @Collections.WebDAVCache.UUIDTTL@, @...MaxCollectionEntries@, and @...MaxUUIDEntries@ are no longer used, and should be removed from your config file.
 +
 +h2(#v2_4_3). v2.4.3 (2022-09-21)
 +
 +"previous: Upgrading to 2.4.2":#v2_4_2
 +
 +h3. Fixed PAM authentication security vulnerability
 +
 +In Arvados 2.4.2 and earlier, when using PAM authentication, if a user
 +presented valid credentials but the account is disabled or otherwise
 +not allowed to access the host, it would still be accepted for access
 +to Arvados.  From 2.4.3 onwards, Arvados now also checks that the
 +account is permitted to access the host before completing the PAM login
 +process.
 +
 +Other authentication methods (LDAP, OpenID Connect) are not affected
 +by this flaw.
 +
  h2(#v2_4_2). v2.4.2 (2022-08-09)
  
  "previous: Upgrading to 2.4.1":#v2_4_1

-----------------------------------------------------------------------


hooks/post-receive
-- 




More information about the arvados-commits mailing list