Debian Patches

Status for swift/2.38.1-3

Patch Description Author Forwarded Bugs Origin Last update
syslog_log_name.patch Set log_name for Swift services in default configs
===================================================================
Ondřej Nový <novy@ondrej.org> not-needed 2016-07-05
disable_sphinxcontrib_rsvgconverter.patch Disable sphinxcontrib.rsvgconverter extension
===================================================================
Ondřej Nový <novy@ondrej.org> not-needed 2020-02-12
set-default-workers-value.patch Set default workers value Since the package switched to uwsgi and now reads this value, it can't be
left as "auto" an commented out.

===================================================================
Thomas Goirand <zigo@debian.org> not-needed 2020-10-30
Add_tempurl_path_prefix_configuration_option.patch Add [filter:tempurl]/path_prefix configuration option If swiftproxy endpoint is something like /object, with URL rewriting
by haproxy, then the hmac calculation is wrong.
.
This patch adds a new path_prefix directive which is stripped away
in the URLs before calculating the tempurl hmac.

===================================================================
Kevin Allioli <kevin@linit.io> yes 2021-11-18
swift-recon-only-query-object-servers-once.patch swift-recon: only query object servers once
===================================================================
Thomas Goirand <zigo@debian.org> no 2023-04-28
drive-full-checker.patch drive-full-checker The admin documentation provides a documentation on how to "prevent[ing]
disk full scenarios" over here:
https://docs.openstack.org/swift/latest/admin_guide.html#preventing-disk-full-scenarios
.
Even if the doc provides an actual example, this example is written in
Python 2, and its implementation is incomplete.
.
This patch intend to fill the gap, and allow administrator to use an
official implementation of a new "swift-drive-full-checker" tool from
/usr/bin directly. Once done, we intend to also patch puppet-swift to
use this new tool.

===================================================================
Thomas Goirand <zigo@debian.org> yes 2024-02-11
fix-writing-non-ascii-in-headers-in-tests.patch Fix writing non-ascii in headers during tests
===================================================================
Thomas Goirand <zigo@debian.org> no debian 2025-12-26
CVE-2026-97149_OSSA-2026-041-stable-2026.2.patch CVE-2026-97149 / OSSA-2026-041: tempurl: Disallow X-Copy-From on tempurl requests Disallow clients using the X-Copy-From header to make a copy of any
object within the account using a PUT tempurl by adding the x-copy-from
header to DISALLOWED_INCOMING_HEADERS. Requests that use the header now
get a 400 response, like the requests that use X-Object-Manifest or
X-Symlink-Target.
.
X-Copy-From-Account is not in the list, similar to
X-Symlink-Target-Account. These headers have no effect without
X-Copy-From or X-Symlink-Target.
(cherry picked from commit 32943ef7b9691f0447c3cfa93bb2f492958283a3)

diff --git a/swift/common/middleware/tempurl.py b/swift/common/middleware/tempurl.py
index 7df9daf..9441ffc 100644
Christian Schwede <cschwede@mailbox.org> yes debian upstream Upstream, https://review.opendev.org/c/openstack/swift/+/1007047 2026-09-24

All known versions for source package 'swift'

Links