From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp0 ([2001:41d0:2:c151::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms11 with LMTPS id Vpb7EUZEUWDIdQAA0tVLHw (envelope-from ) for ; Tue, 16 Mar 2021 23:50:30 +0000 Received: from aspmx2.migadu.com ([2001:41d0:2:c151::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp0 with LMTPS id uBRsDUZEUWDAXAAA1q6Kng (envelope-from ) for ; Tue, 16 Mar 2021 23:50:30 +0000 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx2.migadu.com (Postfix) with ESMTPS id 7C53413FA1 for ; Wed, 17 Mar 2021 00:50:29 +0100 (CET) Received: from localhost ([::1]:57618 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1lMJSG-000237-Fj for larch@yhetil.org; Tue, 16 Mar 2021 19:50:28 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:34950) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1lMJRq-0001mh-5X for bug-guix@gnu.org; Tue, 16 Mar 2021 19:50:02 -0400 Received: from debbugs.gnu.org ([209.51.188.43]:58167) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1lMJRp-0007Ky-UX for bug-guix@gnu.org; Tue, 16 Mar 2021 19:50:01 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1lMJRp-0007cm-RH for bug-guix@gnu.org; Tue, 16 Mar 2021 19:50:01 -0400 X-Loop: help-debbugs@gnu.org Subject: bug#47185: grub2 package is vulnerable to CVE-2020-14372, CVE-2020-25632, CVE-2020-25647, CVE-2020-27749, CVE-2020-27779, CVE-2021-20225, CVE-2021-20233 and CVE-2021-3418 Resent-From: Mark H Weaver Original-Sender: "Debbugs-submit" Resent-CC: bug-guix@gnu.org Resent-Date: Tue, 16 Mar 2021 23:50:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 47185 X-GNU-PR-Package: guix X-GNU-PR-Keywords: To: =?UTF-8?Q?L=C3=A9o?= Le Bouter , 47185@debbugs.gnu.org Received: via spool by 47185-submit@debbugs.gnu.org id=B47185.161593856329259 (code B ref 47185); Tue, 16 Mar 2021 23:50:01 +0000 Received: (at 47185) by debbugs.gnu.org; 16 Mar 2021 23:49:23 +0000 Received: from localhost ([127.0.0.1]:41480 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lMJRD-0007br-07 for submit@debbugs.gnu.org; Tue, 16 Mar 2021 19:49:23 -0400 Received: from world.peace.net ([64.112.178.59]:51518) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lMJRA-0007bd-Mv for 47185@debbugs.gnu.org; Tue, 16 Mar 2021 19:49:21 -0400 Received: from mhw by world.peace.net with esmtpsa (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1lMJR4-0000cI-EE; Tue, 16 Mar 2021 19:49:14 -0400 From: Mark H Weaver In-Reply-To: <3de2a6393156da40334d95993e15b22ca0eae5df.camel@zaclys.net> References: <3de2a6393156da40334d95993e15b22ca0eae5df.camel@zaclys.net> Date: Tue, 16 Mar 2021 19:47:43 -0400 Message-ID: <87pmzyirt1.fsf@netris.org> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: bug-guix@gnu.org List-Id: Bug reports for GNU Guix List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-guix-bounces+larch=yhetil.org@gnu.org Sender: "bug-Guix" X-Migadu-Flow: FLOW_IN ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1615938629; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding:resent-cc: resent-from:resent-sender:resent-message-id:in-reply-to:in-reply-to: references:references:list-id:list-help:list-unsubscribe: list-subscribe:list-post; bh=J9p+b/22PvG3hTpfo+QzJEnxdl2IsckrCJB5JJhlMqI=; b=G7uqbImRZ4B9ABHaoi+BYi+UOyXSvTbb2RjFmWcjUQgem4Sw60cJOMUW9ZX8gTeyiRMH+t KjqgA67GKhq7CoVV9z3bowBLdjagUq8paRh/O9jBckEftIYSB69K16Gb/1aelI2yf7t0nA oIYaYnpI/UfVfjD4bk6xkC5gYj3HUya9DUeeLetMzvioSiIbOMVBhKDUcaCot9BMW/gITx D7BWQbQFgwFOwG1g9og1WGCEN4W3Z9lQoik0bzLSGsdHIxLrD+kw66u2rPkiLTuoVbOSNi mDj4cITZQHhbhU1Lq/k9wA/YIgxE0ztfXlZluPPuZ4HFxra8YiKkQCIm6E2rsQ== ARC-Seal: i=1; s=key1; d=yhetil.org; t=1615938629; a=rsa-sha256; cv=none; b=kl7I+dP+1Akjq96Y+0HVsDzypWwYAOHZL/ukZCAZVSsmqaGS+N7jZj653ro9VpUcKHSAlP vTJrIXFsEJ/9ndwCS2IKPt8vRNlXJ7EEy1TSWKk+jr79T+heDewHlMENA7HF+lI1xQkMTg oJ1Iwl9IhVmOqnRR/Zpnpu7B8GmfJZ4Mekxd5w2bKSgpv5IrBQ7zX8rI0qHvvbIX5Fq300 i41hy4RpTeBkgTogpAisl2sqGWlZgw0y5lbMngniZvWQ74gLSYrVo3dW5xO29RJXCZTQO9 VU6CmuovdkUj6diSSrXQxKMipAlwDt/EyHDohH3ihxmRee8ziofN1VmprDsFqA== ARC-Authentication-Results: i=1; aspmx2.migadu.com; dkim=none; spf=pass (aspmx2.migadu.com: domain of bug-guix-bounces@gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=bug-guix-bounces@gnu.org X-Migadu-Spam-Score: -2.40 Authentication-Results: aspmx2.migadu.com; dkim=none; dmarc=none; spf=pass (aspmx2.migadu.com: domain of bug-guix-bounces@gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=bug-guix-bounces@gnu.org X-Migadu-Queue-Id: 7C53413FA1 X-Spam-Score: -2.40 X-Migadu-Scanner: scn0.migadu.com X-TUID: WY582mWChC91 Hi L=C3=A9o, L=C3=A9o Le Bouter via Bug reports for GNU Guix writes: > NOTE: SecureBoot on GNU Guix is not something common at all, so the > urgency to fix this issue is not as great as if we explicitly > advertised support for SecureBoot. I would go further and question whether *anyone* is using SecureBoot with a Guix system, and moreover whether its feasible to do without non-trivial development work. > This looks like a sizeable upgrade to a sensitive part of GNU Guix, so > we have to test carefully. Indeed. I would like to underline this point: GRUB is the only part of a Guix system that cannot be easily rolled back if it breaks. If we make changes to GRUB that causes breakage for some minority of users, those users could end up with an unbootable system, requiring the use of a rescue disk to repair. Therefore, we should be *very* careful about updating our GRUB package, especially for the sake of bugs that almost certainly do not affect Guix users. I think we should refrain from updating GRUB until there's an official upstream stable release. Even then, I would advise making an effort to test it on Guix systems, using several different system configurations, before pushing it to 'master'. What do you think? Regards, Mark