From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.io!.POSTED.blaine.gmane.org!not-for-mail From: Alan Third Newsgroups: gmane.emacs.bugs Subject: bug#66245: [PATCH] ; Silence macOS 14 warning Date: Fri, 29 Sep 2023 16:36:22 +0100 Message-ID: References: Mime-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Transfer-Encoding: 8bit Injection-Info: ciao.gmane.io; posting-host="blaine.gmane.org:116.202.254.214"; logging-data="38684"; mail-complaints-to="usenet@ciao.gmane.io" Cc: 66245@debbugs.gnu.org, Eshel Yaron , Stefan Kangas To: Gerd =?UTF-8?Q?M=C3=B6llmann?= Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane-mx.org@gnu.org Fri Sep 29 17:37:20 2023 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane-mx.org Original-Received: from lists.gnu.org ([209.51.188.17]) by ciao.gmane.io with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1qmFYN-0009m4-FA for geb-bug-gnu-emacs@m.gmane-mx.org; Fri, 29 Sep 2023 17:37:19 +0200 Original-Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1qmFXt-0005OV-4f; Fri, 29 Sep 2023 11:36:49 -0400 Original-Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1qmFXr-0005OM-MN for bug-gnu-emacs@gnu.org; Fri, 29 Sep 2023 11:36:47 -0400 Original-Received: from debbugs.gnu.org ([2001:470:142:5::43]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1qmFXr-0005eO-Dl for bug-gnu-emacs@gnu.org; Fri, 29 Sep 2023 11:36:47 -0400 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1qmFY5-0004kA-Rz for bug-gnu-emacs@gnu.org; Fri, 29 Sep 2023 11:37:01 -0400 X-Loop: help-debbugs@gnu.org Resent-From: Alan Third Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Fri, 29 Sep 2023 15:37:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 66245 X-GNU-PR-Package: emacs X-GNU-PR-Keywords: patch Original-Received: via spool by 66245-submit@debbugs.gnu.org id=B66245.169600181418219 (code B ref 66245); Fri, 29 Sep 2023 15:37:01 +0000 Original-Received: (at 66245) by debbugs.gnu.org; 29 Sep 2023 15:36:54 +0000 Original-Received: from localhost ([127.0.0.1]:56949 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1qmFXx-0004jn-RU for submit@debbugs.gnu.org; Fri, 29 Sep 2023 11:36:54 -0400 Original-Received: from dane.soverin.net ([2a10:de80:1:4092:b9e9:2296:0:1]:58269) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1qmFXs-0004jN-Ci for 66245@debbugs.gnu.org; Fri, 29 Sep 2023 11:36:52 -0400 Original-Received: from smtp.soverin.net (c04smtp-lb01.int.sover.in [10.10.4.74]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by dane.soverin.net (Postfix) with ESMTPS id 4RxvZv65NpzSf; Fri, 29 Sep 2023 15:36:23 +0000 (UTC) Original-Received: from smtp.soverin.net (smtp.soverin.net [10.10.4.100]) by soverin.net (Postfix) with ESMTPSA id 4RxvZv3SwQzHv; Fri, 29 Sep 2023 15:36:23 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=idiocy.org; s=soverin; t=1696001783; bh=5T9mmlbtnS/NA4zs2a3DLnQ4KqWUM1nMRxoIxn3666Y=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=EsgUBvTfeq3HeQyfvSXAUZSo/1vDg5Pc9cUFZXUfZ2Sjv0efoUA9fvu1XPGe1IVEQ qWOgc1Ch4BWwX2a4O8vmAC7fP2KJU28UYb2N6wgY2xnsi3q3CdQmKIZfzD+iC7kBRu JS4LjJ+BYnE0en/yMgknmsYKOmi+XoVGaWHMFGuuGfXipoEBZv1yflODpHP9DMUasq IB4tDxeFlDxJP4Z8Jsg+XQxAqrhemKYf+9ItN9ln1F5i/hPlc9A8752ozDc2JdKmqR xhJWAykqhK4Yz5qV9ICefknrygtYvEAO1CKwxpecTOZTgF9QlbKLmX0O5VAcwGm17/ HY1MT9nGrth1A== Original-Received: from alan by faroe.holly.idiocy.org with local (Exim 4.96) (envelope-from ) id 1qmFXS-000Q3y-31; Fri, 29 Sep 2023 16:36:22 +0100 X-Soverin-Authenticated: true Mail-Followup-To: Alan Third , Gerd =?UTF-8?Q?M=C3=B6llmann?= , Stefan Kangas , 66245@debbugs.gnu.org, Eshel Yaron Content-Disposition: inline In-Reply-To: X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane-mx.org@gnu.org Original-Sender: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane-mx.org@gnu.org Xref: news.gmane.io gmane.emacs.bugs:271501 Archived-At: On Fri, Sep 29, 2023 at 12:11:50PM +0200, Gerd Möllmann wrote: > >> I understand that as meaning that this switches on additional checks in > >> Appkit. That should be okay for Emacs because it doesn't use this > >> feature of Appkit, at least AFAIK. > > > > Thanks. IIUC, that seems to speak in favor of not making an emergency > > release of Emacs 29.2 at this point. > > I agree. The new method would just enable "secure coding" for > restorable state on macOS < 14 (it's the default in 14), but since we're > not using this stuff to begin with, it's kind of pointless. Not quite true according to the long description linked elsewhere. Saved state is turned on automatically and it seems there's no way to opt out. As I understand it that means that even though we don't make use of it the vulnerable code still executes. I do agree though that it's probably not worth making an emergency release. -- Alan Third