Thursday, September 10, 2026

[389-users] Announcing 389 Directory Server 3.1.5 (F43)

389 Directory Server 3.1.5

The 389 Directory Server team is proud to announce 389-ds-base version 3.1.5.

Source tarball:

Fedora 43 update: https://bodhi.fedoraproject.org/updates/FEDORA-2026-0b8bc362b1

Highlights in 3.1.5

See Download for package installation and Install Guide for setup.

Changelog between 389-ds-base-3.1.4 and 389-ds-base-3.1.5:

  • Bump version to 3.1.5
  • Security fix for CVE-2026-76560
  • Security fix for CVE-2026-19843
  • Security fix for CVE-2026-18922
  • Security fix for CVE-2026-18453
  • Security fix for CVE-2026-18355
  • Issue 7178 - Bundled jemalloc fails to build with GCC 15 #7216
  • Issue 7808 - CI - harden online_import_nosync_test #7809
  • Issue 7595 - Remove the nightly dedup gate and fix dispatched test runs
  • [Backport 389-ds-base-3.1] Update rust-dependencies #7790
  • Fix expiration time check #7718
  • Issue 7774 - Add backport action #7775
  • Issue 7770 - Testimony failure in test_cleanruv_extop_security.py #7771
  • CVE-2026-11770 - Fix StartReplicationRequest auth gate response format
  • Security fix for CVE-2026-11770
  • Issue 3082 - Add test389.topologies compatibility shim for backports #7725
  • Issue 7595 - Skip redundant CI runs to relieve the Actions queue #7748
  • Issue 7760 - CI - harden dsconf_task_test.py
  • Issue 4701 - Fix UAF when excluding attrs from retro changelog #7730
  • Issue 7723 - Range search returns an empty result when its start key is removed #7724
  • Issue 7639 - Move log compression outside of global write lock
  • Issue 7631 - Don’t install bpftrace by default #7726
  • Issue 7735 - Heap overflow when parsing objectclass superior #7736
  • Issue 7733 - Typo about nsuniqueid in tombstone_to_conflict #7734
  • Issue 7707 - lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement() in join_supplier/hub/consumer #7708
  • Issue 7711 - Fix typo in accountpolicy –login-history-size help text #7713
  • Issue 7688 - BUG - partial address leak in sso token #7689
  • Issue 7705 - With memberOfEntryScope set, deferred memberOf skips MODIFY operations #7706
  • Issue 7698 - Fix silent entry loss in LMDB bulk import waiter handling #7699
  • Issue 7666 - Replication performance degradation during total init on high-latency storage #7667
  • Issue 7201 - Syscall overhead in LMDB import writer thread #7204
  • Issue 7645 - Add runtime LeakSanitizer leak check #7646
  • Revert “Issue NNNN - Range search returns an empty result when its start key is removed”
  • Issue NNNN - Range search returns an empty result when its start key is removed
  • Issue 7714 - UI - sass import rules are deprecated
  • Issue 7658 - Heap Buffer Overflow in sasl_io_recv() via Padded SASL UNBIND
  • Issue 7710 - MemberOf deferred update - Use condvar instead of sleep loop
  • Issue 7637 - UI - Using Arrow Keys in New Object Wizard Resulted in DOM Reload
  • Issue 7578 - schema - attribute refcount is not maintained properly
  • Issue 7605 - Harden CI test ports against ephemeral allocation #7692
  • Issue 7528 - Retry the CI image pull instead of failing the job #7691
  • Backport Issue 7519 — ignore obsolete entrydn when entryrdn is in use #7657
  • Issue 7505 - RFE - CLI - add feature to determine which password policy applies to a user
  • Issue 7670 - BDB range searches intermittently fail with err=1 under write load #7671
  • Issue 7284 - Creating local password policy succeeds with incorrect passwordInHistory value #7662
  • Issue 7284 - Automated test for creating local password policy with incorrect passwordInHistory value #7608
  • Issue 7200 - repl-agmt create doesn’t set some parameters #7663
  • Issue 7573 - Post-import cache autotuning does not recompute entry cache size #7574
  • Issue 7470 - dsctl localhost tls import-server-key-cert fails with ‘expected str, bytes or os.PathLike object, not NoneType’ #7477
  • Issue 7611 - Preserve legacy PBKDF2 hash compatibility #7649
  • Issue 7547 - Heap buffer overflow in ldap_utf8prev()
  • Issue 7611 - PBKDF2 password verification should reject invalid iteration count #7613
  • Issue 7558 - Total init sends the suffix entry twice #7640
  • Issue 7635 - Integer Underflow in {SMD5} Password Comparison #7636
  • Issue 7406 - Fix ldap-agent SNMP stats file loading #7630
  • Issue 7621 - Stack Buffer Overflow in Password checkPrefix
  • Issue 7623 - Heap Buffer Overflow in 389-ds-base Audit Log Password Masking
  • Issue 7602 - CI - lib389 user compare fails due to parentid mismatch #7603
  • Issue 7537 - CI - Fix replication log monitoring parser/timing failures #7592
  • Issue 7593 - Fix testimony docstring for SASL overflow test #7606
  • Issue 7530 - CI - Stabilize DNA plugin replication tests timing out in CI #7572
  • Issue 7593 - Reject invalid SASL packet length values in sasl_io_start_packet #7594
  • Issue 3555 - UI - Fix audit issue with npm - ws, js-yaml, babel/core #7599
  • Bump fast-uri from 3.1.0 to 3.1.2 in /src/cockpit/389-console #7487
  • Update dependency uuid to v14 [SECURITY] #7456
  • Update cockpit-389-ds-npm (major) #7448
  • Issue 7263 - UI - Use cockpit.file API for temporary file writes #7590
  • Issue 7541 - Add invalid ACL text header regression test #7591
  • Issue 7554 - UI - Revise local password policy layout
  • Issue 7521 - UI - make changes for cockpit API updates
  • Issue 7541 - heap-buffer-overflows in __aclp__normalize_acltxt() #7542
  • Issue 7531 - Fix LMDB replication regression_m2 failures and core dumps #7575
  • Issue 7490 - Enable USDT probes by default in RPM #7491
  • Issue 7576 - Fix leak of temporary attribute syntax hash tables after schema reload
  • Issue 7558 - During online import, the IDL should be created with in-depth first approach #7559
  • Issue 7500 - Prevent unsigned integer underflow during stalled import
  • Issue 7562 - Error: NssSsl.add_cert() got an unexpected keyword argument ‘input_file’ #7563
  • Issue 7560 - lib389 - Add helper function for checking ASAN files
  • Issue 7539 - Server shutdown during online reindex may lead to data loss #7540
  • Issue 7549 - Substring index should validate minimum nsSubStrBegin/nsSubStrEnd values #7550
  • Issue 7440 - Substring index produces empty results and can crash when non-default nsSubStrBegin/nsSubStrEnd lengths are configured #7441
  • Fix test389 imports on older branches
  • Issue 7267 - MDB_BAD_VALSIZE error when updating index #7268
  • Issue 7327 - dsctl healthcheck DSMOLE0001 inaccurate recommendations with multiple backends #7328
  • Issue 7372 - Reindex adds tombstones to ancestorid causing export failures #7373
  • Issue 7437 - LeakSanitizer: memory leaks in CoS cache error paths #7438
  • Issue 3555 - UI - Fix audit issue with npm - brace-expansion #7556
  • Issue 7554 - deref plugin null pointer dereference if ber_init fails
  • Issue 7493 - RFE - Add ShadowAccount fixup task
  • Issue 7507 - UI - cleanup style and alignments
  • Issue 7514 - Crash when doing moddn on very large subtree
  • Issue 7516 - dblayer_bulk_nextdata should not return an error when maxrecords is hit
  • Issue 7496 - Fix latest GCC compiler warnings
  • Issue 7503 - CVE-2026-9064 - Add a limit to the number controls per operation
  • Issue 7300 - RFE - Add OS-level thread names to all server threads #7301
  • Issue 7460 - MOD_REPLACE on groups/link attributes modifies overlap targets #7461
  • Issue 7307 - RFE - Expose work queue and worker utilization metrics #7308
  • Issue 7464 - CLI - allow dsidm to work with other user types
  • Issue 7457 - Refactor memberOf perf test #7458
  • Issue 7431 - password policy - passwordBadWords is ignored in local policies
  • Issue 7155 - build_candidate_list - Database error 11 with range search #7156
  • Issue 7426 - logconv.py is out of sync with server-emitted note codes #7427
  • Issue 7417 - UI - global password policy syntax settings missing passwordMaxRepeats
  • Issue 3555 - UI - Fix audit issue with npm - brace-expansion #7411
  • Issue 7088 - Change log level for “Can’t locate CSN” error message
  • Issue 7423 - cleanup pblock after freeing pre/post entries
  • Issue 7418 - Use-after-free in deferred memberof #7419
  • Issue 7407 - dbscan -k option display entries that do not match the specified key
  • Issue 7404 - fix latest compiler warnings(cherry-pick issue)
  • Issue 7404 - fix latest compiler warnings
  • Issue 7394 - UI - Manual typing of ports can leave out digits #7395
  • Issue 7277 - UI - Fix Japanese translation errors errors in Cockpit UI #7386
  • Issue 7246 - correct formatting of ‘Gen as CSN’ in dsctl get-nsstate output #7247
  • Issue 7126 - WARN - keys2idl - received NULL idl from index_read_ext_allids #7127
  • Issue 7370 - Runtime LSan/TSan injection for pytest #7371
  • Issue 7378 - Make sure suffix entry always gets assigned ID 1
  • Issue 7380 - Internal op with negative wtime and large optime #7381
  • Issue 7362 - UI - Some FormSelect onChange parameters are reversed
  • Issue 7368 - UI - global password policy page is missing passwordmintokenlength
  • Issue 7366 - Memory leaks in syncrepl plugin during persistent search operations #7367
  • Issue 3658 - UI/CLI - show progress of db tasks
  • Issue 7284 - CI - Fix test_grace_limit_section after pwpolicy validation fix #7357
  • Issue 7271 - Add test for retrocl trimming shutdown crash #7356
  • Issue 3555 - UI - Fix audit issue with npm - flatted, picomatch #7364
  • Issue 7337 - UI - refactor all error handling to use getApiErrorMessge
  • Issue 1704 - DNA plugin creates invalid shared config entry with port 0 #7352
  • Issue 7348 - CI - Fix failing dsconf security CLI add cert test #7349
  • Issue 7346 - DS does not handle escape char in bind user #7347
  • Issue 7322 - Reject adding a replication agreement that points to itself
  • Issue 7312 - UI - Database Maximum Size cannot be easily set by typing #7313
  • Issue 7342 - CI - repl config regression #7343
  • Issue 7339 - Return the exact DN during export
  • Issue - UI - Improve suffix import LDIF table
  • Issue 7325 - UI - new error parser missing import
  • Issue 7325 - UI - create an error parser for cockpit spawn errors
  • Issue 7319 - Action menu for certificates remains in empty certificate list #7320
  • Issue 7265 - CI - fix retro changelog maxage validation test
  • Issue 7093 - A password policy can be created even when an identical policy already exists #7283
  • Issue 7316 - UI - update npm module immutable
  • Issue 7233 - test_produce_division_by_zero fails with IsADirectoryError in conftest.py #7234
  • Issue 7314 - UI - Add progress steppers to Security, Database, and Replication tabs
  • Issuei 7281 - UI - Add encryption module management
  • Issue 7271 - Add new plugin pre-close function check to plugin_invoke_plugin_pb
  • Issue 7304 - retrocl should not cache DN
  • Issue 7265 - Add dse modify callback to validate retrocl trimming settings
  • Issue 7152 - ns-slapd fails to shutdown when deferred memberof update is in progress #7187
  • Issue 3555 - UI - Fix audit issue with npm - ajv, minimatch #7298
  • Issue 7291 - Crash when configuring a replica with an incorrect nsds5ReplicaRoot #7292
  • Issue 7271 - implement a pre-close plugin function
  • Issue 7281 - RFE - CLI - add support to managing additional encryption modules
  • Issue 7265 - changelog maxage validation is not strict enough
  • Issue 7284 - Creating local password policy succeeds with incorrect passwordInHistory value #7285
  • Security fix for CVE-2025-14905
  • Issue 7277 - UI - Fix Japanese translation for “Successfully updated group” in Cockpit UI #7278
  • Issue 7275 - UI - Improve password policy field validation in Cockpit UI #7276
  • Issue 7279 - UI - Fix typo in export certificate dialog #7280
  • Issue 7273 - In a chaining environment binding as remote user causes an invalid error in the logs
  • Issue 7271 - plugins that create threads need to update
  • Issue 5853 - Update concread to 0.5.10
  • Issue 7223 - Remove integerOrderingMatch requirement for parentid #7264
  • Issue 7243 - UI - fix certificate table and modal
  • Issue 7066/7052 - allow password history to be set to zero and remove history
  • Issue 7223 - Use lexicographical order for ancestorid #7256
  • Issue 7213 - (2nd) MDB_BAD_VALSIZE error while handling VLV #7258
  • Issue 7184 - (2nd) argparse.HelpFormatter _format_actions_usage() is deprecated #7257
  • Issue - CLI - dsctl db2index needs some hardening with MBD
  • Issue 7248 - CLI - attribute uniqueness - fix usage for exclude subtree option
  • Issue 7231 - Sync repl tests fail in FIPS mode due to non FIPS compliant crypto #7232
  • Issue 7121 - (2nd) LeakSanitizer: various leaks during replication #7212
  • Issue 6947 - Fix health_system_indexes_test.py
  • Issue 7221 - CI tests - fix some flaky tests
  • Issue 7076 - Fix revert_cache() never called in modrdn #7220
  • Issue 7096 - (2nd) During replication online total init the function idl_id_is_in_idlist is not scaling with large database #7205
  • Issue 3555 - UI - Fix audit issue with npm - @isaacs/brace-expansion #7228
  • Issue 7223 - Add dsctl index-check command for offline index repair
  • Issue 7223 - Detect and log index ordering mismatch during backend startup
  • Issue 7223 - Add upgrade function to remove ancestorid index config entry
  • Issue 7223 - Add upgrade function to remove nsIndexIDListScanLimit from parentid
  • Issue 7223 - Revert index scan limits for system indexes
  • Issue 7224 - CI Test - Simplify test_reserve_descriptor_validation #7225
  • Issue 7194 - Repl Log Analysis - Add CSN propagation details #7195
  • Issue 7213 - MDB_BAD_VALSIZE error while handling VLV #7214
  • Issue 7027 - (2nd) 389-ds-base OpenScanHub Leaks Detected #7211
  • Issue 7184 - argparse.HelpFormatter _format_actions_usage() is deprecated
  • Issue 7198 - Web console doesn’t show sub-suffix when parent-suffix points to an entry #7202
  • Issue 7189 - DSBLE0007 generates incorrect remediation commands for scan limits
  • Bump lodash from 4.17.21 to 4.17.23 in /src/cockpit/389-console #7203
  • Issue 7172 - (2nd) Index ordering mismatch after upgrade #7180
  • Issue 7172 - Index ordering mismatch after upgrade #7173
  • Issue 7108 - Fix shutdown crash in entry cache destruction #7163
  • Issue - Revise paged result search locking
  • Issue 7096 - During replication online total init the function idl_id_is_in_idlist is not scaling with large database #7145
  • Issue 7160 - Add lib389 version sync check to configure #7165
  • Issue 7166 - db_config_set asserts because of dynamic list #7167
  • Sync lib389 version to 3.1.4 #7161
  • Issue 7150 - Compressed access log rotations skipped, accesslog-list out of sync #7151

-- _______________________________________________ 389-users mailing list -- 389-users@lists.fedoraproject.org To unsubscribe send an email to 389-users-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new

No comments:

Post a Comment