Repository navigation
CHEF-38671: Advance omnibus submodule for postgresql13 TuxCare 1.0.1 fix (CVE-2026-6471) - #4250
Open
lbakerchef wants to merge 4 commits into
Open
lbakerchef wants to merge 4 commits into
lbakerchef wants to merge 4 commits into
Conversation
Points the omnibus submodule at the chef-server-omnibus-config branch carrying the postgresql13 TuxCare 1.0.1 patch-revision fix for CVE-2026-6471, so builds on this branch pick up the fix. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Lincoln Baker <51833247+lbakerchef@users.noreply.github.com>
Signed-off-by: Lincoln Baker <51833247+lbakerchef@users.noreply.github.com>
1. STOP. The following must be done before proceeding:
a. chef-server-omnibus-config rebuild branch (CHEF-38671/lbaker) must have
merged to main.
(No omnibus-software-private PR exists for this change -- the fix lives
entirely in chef-server-omnibus-config's postgresql13.rb TuxCare override,
which is the only copy chef-server builds actually consume.)
Do not proceed until confirmed.
2. Remove this commit (the one you are reading now):
- cd <chef-server-omnibus-config repo (this one)>
- git checkout <pr-merge-branch (this one)>
- git pull # if necessary
- git reset --hard HEAD^
(This leaves commit A -- ".gitmodules points to main" -- as the tip.)
3. Advance the omnibus submodule SHA to the new omnibus-config main HEAD:
- cd omnibus
- git fetch origin
- git checkout main
- git pull origin main
- cd ..
- git add omnibus
- git commit -sm "Advance omnibus submodule to post-merge omnibus-config main HEAD"
4. git push origin CHEF-38671/lbaker
Then open/merge the PR on github.com/chef/chef-server.
Signed-off-by: Lincoln Baker <51833247+lbakerchef@users.noreply.github.com>
Picks up chef-server-omnibus-config@47ecd0e, which switches postgresql13's build from make world/install-world to make world-bin/install-world-bin, fixing a docs-build failure seen on Buildkite build #8428 (missing local DocBook XML catalog blocks xmllint --nonet from resolving docbookx.dtd). No change to the shipped artifact; see the omnibus-config commit message for full details.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Advances the
omnibussubmodule pointer to chef-server-omnibus-config#34's branch, which bumps the postgresql13 TuxCare patch revision 1.0.0 -> 1.0.1.Why
Remediates CVE-2026-6471 (CHEF-38671, child of epic CHEF-38364).
Pre-merge instructions
This branch includes a bracketed pair of pre-merge preparation commits ("point omnibus submodule to main" / ">>> PRE-MERGE INSTRUCTIONS <<<"). Do not merge this PR until chef-server-omnibus-config#34 has merged to main. The ">>> PRE-MERGE INSTRUCTIONS <<<" commit contains the exact steps to finalize the submodule pointer to omnibus-config's post-merge main HEAD before merging this PR.
Related PRs
Ticket
https://progresssoftware.atlassian.net/browse/CHEF-38671