From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.io!.POSTED.blaine.gmane.org!not-for-mail From: Eli Zaretskii Newsgroups: gmane.emacs.devel Subject: Re: Request to backport fix for CVE-2022-45939 to Emacs 28 Date: Fri, 17 Feb 2023 14:33:13 +0200 Message-ID: <83fsb41ng6.fsf@gnu.org> References: <85f35c42-cfe8-44a7-a9c1-307acc5c17d4@Spark> <09998122-0110-454f-94d1-e29c37b833f4@Spark> <83sff9e1is.fsf@gnu.org> <838rh0e64j.fsf@gnu.org> <86ttzougu2.fsf@gmail.com> <83cz692xav.fsf@gnu.org> Injection-Info: ciao.gmane.io; posting-host="blaine.gmane.org:116.202.254.214"; logging-data="21694"; mail-complaints-to="usenet@ciao.gmane.io" Cc: rms@gnu.org, theophilusx@gmail.com, emacs-devel@gnu.org To: Stefan Kangas Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane-mx.org@gnu.org Fri Feb 17 13:34:07 2023 Return-path: Envelope-to: ged-emacs-devel@m.gmane-mx.org Original-Received: from lists.gnu.org ([209.51.188.17]) by ciao.gmane.io with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1pSzwE-0005So-Kz for ged-emacs-devel@m.gmane-mx.org; Fri, 17 Feb 2023 13:34:06 +0100 Original-Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1pSzvW-00010B-Sy; Fri, 17 Feb 2023 07:33:22 -0500 Original-Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1pSzvU-0000yp-4F for emacs-devel@gnu.org; Fri, 17 Feb 2023 07:33:20 -0500 Original-Received: from fencepost.gnu.org ([2001:470:142:3::e]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1pSzvT-000701-LV; Fri, 17 Feb 2023 07:33:19 -0500 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=gnu.org; s=fencepost-gnu-org; h=References:Subject:In-Reply-To:To:From:Date: mime-version; bh=JaiDkiw7D4RxHqWj60i+OQrHv8BZeZJbitm1oRavOLw=; b=W6IeNYQbVoq5 g0TaSrM9IeOcGpkhMlRiO4iyPcmDVCNV8vQ8PmHscvWTO76h1tx/iopEHs232yO7vAY/EONExJSqq FdpUuYLSFGAolYZ5yCx7Z15vqs/Z3XIFHczkDnkRaLSzeWR9P4U+ZK6bEp7tVxR/3lWh9GB7Wtnwn NJt1mEHtnT+RQBFByDSmbSW7FFNpFZiG/KYLAkZfZh0o+Oj3sKJS4Ts4KtMJX/bP4tjW6+unBOgSq zYnfdeOizmGx3dltoA60AtJvqkrcQ0pWpwgeZV7bZMP1bR6oUjshJCrdBi5Ksx3AHV261whPduhuA Z0Z/XrKPF9PKmk14korSqg==; Original-Received: from [87.69.77.57] (helo=home-c4e4a596f7) by fencepost.gnu.org with esmtpsa (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1pSzvN-0003Lu-Br; Fri, 17 Feb 2023 07:33:13 -0500 In-Reply-To: (message from Stefan Kangas on Fri, 17 Feb 2023 02:26:28 -0800) X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane-mx.org@gnu.org Original-Sender: emacs-devel-bounces+ged-emacs-devel=m.gmane-mx.org@gnu.org Xref: news.gmane.io gmane.emacs.devel:303470 Archived-At: > From: Stefan Kangas > Date: Fri, 17 Feb 2023 02:26:28 -0800 > Cc: theophilusx@gmail.com, emacs-devel@gnu.org > > Eli Zaretskii writes: > > >> What makes it a ontrivial job to release one? Is it because there > >> other fixes have been committed to the Emacs 28 branch since the last > >> release? Would including them in a release call for some additioal > >> work? > > > > The whole process takes a non-trivial amount of work. It is described > > in make-tarball.txt. If someone wants to do it, they are welcome. > > (I saw this thread just now.) > > Thanks, I'm working on it. Please see the commits I just pushed to the > emacs-28 branch. Let me know if you want to inspect the tarball before > I make the release (if so, we could probably coordinate it off-list). Sorry, I don't have time for that now. The tarball needs to be test-built on the main platforms we care about, and the diffs against the Emacs 28.2 tarball carefully eyeballed to make sure nothing is amiss. Other than that, you have my blessing. Thanks!