Commit Graph
2 Commits
Author SHA1 Message Date
autonomic-bot a5ce46f2a3 fix: bump APP_INI_VERSION to v23 (app.ini.tmpl changed in the forgejo removal)
cc-ci/testme cc-ci: success
Docker Swarm configs are IMMUTABLE — only labels can be updated. The config is
named ${STACK_NAME}_app_ini_${APP_INI_VERSION}, so when app.ini.tmpl's rendered
content changes the version suffix MUST be bumped, otherwise abra tries to mutate
the existing object and the deploy aborts:

  FATA failed to update config <stack>_app_ini_v22: Error response from daemon:
  rpc error: code = InvalidArgument desc = only updates to Labels are allowed

'BREAKING CHANGE: remove forgejo' (6a0339d) edited app.ini.tmpl —

  -{{ if or (eq (env "FORGE") "forgejo") (eq (env "GITEA_LFS_START_SERVER") "true") }}
  +{{ if (eq (env "GITEA_LFS_START_SERVER") "true") }}

— but left APP_INI_VERSION at v22 (unchanged since the LFS commit 357926f), and
3.6.2+1.27.1-rootless shipped that way. Every existing deployment upgrading ACROSS
the forgejo removal therefore fails at 'initialising deployment'; reproduced on a
live 3.6.1+1.26.2-rootless -> 3.6.2+1.27.1-rootless upgrade.

Bumping to v23 makes Swarm create a NEW config object instead of mutating v22. The
orphaned v22 object can be pruned after the rollout. Only app.ini.tmpl changed, so
DOCKER_SETUP_SH_VERSION and PG_BACKUP_VERSION stay put.

Note: cc-ci's upgrade tier did not catch this because it resolved the upgrade base
to main-tip, which ALREADY contains the forgejo removal — base and head then render
identical app.ini and no config update is attempted. Real deployments upgrade from
the last published RELEASE (3.6.1+1.26.2), which is where the break appears.
2026-08-10 16:48:35 +00:00
autonomic-bot 096cc70fd9 chore: upgrade gitea to 1.27.1-rootless
cc-ci/testme cc-ci: success
Fixes two critical Gitea CVEs, both CVSS 9.8, both remediated in 1.27.1:
- CVE-2026-60004: RCE via POST /api/v1/repos/{owner}/{repo}/diffpatch — a patch
  submitted twice triggers an add/add conflict that writes an executable
  post-index-change hook into $GIT_DIR/hooks/, which git then runs as the Gitea
  service account. Affects 1.17-1.27.0; public PoC.
- CVE-2026-59774: unauthenticated arbitrary file read via Org-mode #+INCLUDE
  accepting absolute paths through the markup renderer (affects 1.22.1-1.27.0),
  escalating to RCE by reading config/tokens.

Based on current upstream main, so it includes the BREAKING CHANGE: remove forgejo
work; the previous branch predated it and was verified against a tree that would
not have deployed. Version label left at 3.6.0+1.24.2-rootless per upgrade-PR
convention (operator runs abra recipe release).
2026-08-10 16:27:26 +00:00