News and announcements

heat-cfntools release 1.2.3

Written for heat-cfntools by Steve Baker on 2013-04-11

The heat development community would like to announce the release of heat-cfntools version 1.2.3. This release contains security fixes.

heat-cfntools contains the tools that can be installed on Heat provisioned cloud instances to implement portions of CloudFormation compatibility.

This release can be installed from the following locations:
http://tarballs.openstack.org/heat-cfntools/heat-cfntools-1.2.3.tar.gz
https://pypi.python.org/pypi/heat-cfntools/1.2.3

During normal development, improper handling of temporary files in
heat-cfntools was found and fixed. Heat-cfntools are a set of tools to
enable Heat templates to initialize and respond to configuration changes
via the orchestration layer. A local user could exploit predictable temp
file creation to make root overwrite a file, potentially by also using
local DNS cache poisoning, with a file of their choosing.

It is recommended that any users update these tools immediately. In
particular if you have downloaded older "HEAT-JEOS" images, you should
download new ones which have been built with the fixed heat-cfntools
embedded.

The following issues are fixed in this release:

#1166323 (Clint Byrum) Predictable /tmp filenames used in SourcesHandler
#1164756 (Clint Byrum) /tmp/last_metadata is vulnerable to tmpfile races by arbitrary users

Updated .

heat-cfntools release 1.2.1

Written for heat-cfntools by Steve Baker on 2013-03-18

The heat development community is pleased to announce the release of heat-cfntools version 1.2.1. This is a maintenance release to coincide with Heat's Grizzly rc1 release.

heat-cfntools contains the tools required to be installed on Heat provisioned cloud instances.

This release can be installed from the following locations:
http://tarballs.openstack.org/heat-cfntools/heat-cfntools-1.2.1.tar.gz
https://pypi.python.org/pypi/heat-cfntools/1.2.1

The following issues are fixed in this release:

#1152431 pep8 currently doesn't run on heat_cfntools package
#1105806 /var/lib/cloud belongs to cloud-init, heat should not write files there
#1133050 cfn-hup doesn't trigger events in the correct order from hooks.conf
#1152434 cfn_helper needs test coverage
#1154136 setup.py needs a license header
#1154808 Fix typos in unexecuted code paths
#1153844 cfn-init needs a manual page
#1153846 cfn-signal needs a manual page
#1153848 cfn-get-metadata needs a man page
#1153849 cfn-push-stats needs a man page
#1153850 cfn-hup needs a man page
#1153851 cfn-create-aws-symlinks needs a man page
#1155999 cfn-hup rejects metadata just because it does not have AWS::CloudFormation::Init
#1153843 tarball generation only generating master tarballs

Read more

12 of 2 results

Announcements