From mboxrd@z Thu Jan 1 00:00:00 1970 From: Alex Vong Subject: bug#33751: [GNU bug Tracking System] bug#33783: closed (Re: [bug#33783] [PATCH] gnu: sqlite: Replace with 3.26.0 [security fixes].) Date: Wed, 26 Dec 2018 02:11:28 +0800 Message-ID: <87pntppjcf.fsf@gmail.com> References: <87r2ejve09.fsf@fastmail.com> Mime-Version: 1.0 Content-Type: multipart/signed; boundary="====-=-="; micalg=pgp-sha256; protocol="application/pgp-signature" Return-path: Received: from eggs.gnu.org ([208.118.235.92]:46595) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1gbrBV-00052U-TO for bug-guix@gnu.org; Tue, 25 Dec 2018 13:12:07 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1gbrBS-0005rV-NU for bug-guix@gnu.org; Tue, 25 Dec 2018 13:12:05 -0500 Received: from debbugs.gnu.org ([208.118.235.43]:39228) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1gbrBS-0005rD-74 for bug-guix@gnu.org; Tue, 25 Dec 2018 13:12:02 -0500 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1gbrBS-00071s-04 for bug-guix@gnu.org; Tue, 25 Dec 2018 13:12:02 -0500 In-Reply-To: <87r2ejve09.fsf@fastmail.com> Sender: "Debbugs-submit" Resent-To: bug-guix@gnu.org Resent-Message-ID: List-Id: Bug reports for GNU Guix List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-guix-bounces+gcggb-bug-guix=m.gmane.org@gnu.org Sender: "bug-Guix" To: 33751-done@debbugs.gnu.org Cc: alexvong1995@gmail.com --====-=-= Content-Type: multipart/mixed; boundary="===-=-=" --===-=-= Content-Type: text/plain Closing as patch was appied --===-=-= Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 8bit Delivered-To: alexvong1995@gmail.com Received: by 2002:a9d:728e:0:0:0:0:0 with SMTP id t14csp3685673otj; Mon, 24 Dec 2018 01:36:02 -0800 (PST) X-Google-Smtp-Source: ALg8bN6PZHIldUCFSxxI4cjAHldiohUJ+qPRf40Mo52Z5PPJXd0h8h6Qd1pcFi8KFBM3TE+HWANr X-Received: by 2002:aed:2aa3:: with SMTP id t32mr11397153qtd.25.1545644162881; Mon, 24 Dec 2018 01:36:02 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1545644162; cv=none; d=google.com; s=arc-20160816; b=W71pjKKxoiI9ynn6EHwrdPhoBXGdNGTAToQmMFAtz3bhE51v8JHIyVpLOpSt3ZYTCv u0EO8TAdVt1yFLBI57ou8etGQnt36xWQ2Qif5W8bKV3ZbwCCuKbkf98AtVUwwrA5XjLk GQ4gZtORzYMZq+GNcLLaNO1CvkDsauh6QZJUHkszElLv5b6H0y2V8RDjuSmXtzZ/stxB 9sY76xX1EVYSRK/3Z5B62fY6d+vaL82jAlr/SkoCdarpOv4AGTqCj3AWyLXpUVQohdvc x4ztzBFgzQRmanFeDd2kardNjtVzogY7VAf/oqiOZx9Jj+APVUi/GFQqtw/hcYkLoJIU 0xdQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=date:reply-to:references:message-id:subject:to:from:mime-version; bh=ghYh7eRWO+dd1jVmAMrnTtXosoMYKv3lZ48RDubXslw=; b=XP5twhqxGHzuFeepQBWBVl+S4V2sJ0lv2cyUUSk7s9SrMWr99GhyZLKlfL7rvpOsT7 y6+c0HFuKh+1mWsyUBWT7LsG+CW1f1hE2GkCft3XWGoCdb2qb8OjZvTSK29b5mMeDFwc 0Z44PJDMIC+T9EhQoGYyktQTNiCnYvh7BgptLPPJFMPwFqxaD3nGY2V74vKAjaYInCr3 x5f7yv1exdPVLEVYngVw1IwpDdZ9YtSP/yAxYgy9mRfXLXHjlucdX0/6jbQ5w2DZ32S3 h4O4jWN6d+ObqUaL9HD5WrDGhr8vuD9HkoRtk6Kfl6vYMoBRE9/zH+aVjeM3OKu5DxsU k+DA== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of debian-debbugs@debbugs.gnu.org designates 208.118.235.43 as permitted sender) smtp.mailfrom=Debian-debbugs@debbugs.gnu.org Return-Path: Received: from debbugs.gnu.org (debbugs.gnu.org. [208.118.235.43]) by mx.google.com with ESMTPS id c19si193018qkh.43.2018.12.24.01.36.02 for (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 24 Dec 2018 01:36:02 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of debian-debbugs@debbugs.gnu.org designates 208.118.235.43 as permitted sender) client-ip=208.118.235.43; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of debian-debbugs@debbugs.gnu.org designates 208.118.235.43 as permitted sender) smtp.mailfrom=Debian-debbugs@debbugs.gnu.org Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1gbMeY-0001rx-Dh for alexvong1995@gmail.com; Mon, 24 Dec 2018 04:36:02 -0500 MIME-Version: 1.0 X-Mailer: MIME-tools 5.505 (Entity 5.505) X-Loop: help-debbugs@gnu.org From: help-debbugs@gnu.org (GNU bug Tracking System) To: Alex Vong Subject: bug#33783: closed (Re: [bug#33783] [PATCH] gnu: sqlite: Replace with 3.26.0 [security fixes].) Message-ID: References: <20181224093536.GI2581@macbook41> <87mup31r6o.fsf@gmail.com> X-Gnu-PR-Message: they-closed 33783 X-Gnu-PR-Package: guix-patches X-Gnu-PR-Keywords: security patch Reply-To: 33783@debbugs.gnu.org Date: Mon, 24 Dec 2018 09:36:02 +0000 Content-Type: multipart/mixed; boundary="----------=_1545644162-7175-1" This is a multi-part message in MIME format... ------------=_1545644162-7175-1 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Your bug report #33783: [PATCH] gnu: sqlite: Replace with 3.26.0 [security fixes]. which was filed against the guix-patches package, has been closed. The explanation is attached below, along with your original report. If you require more details, please reply to 33783@debbugs.gnu.org. --=20 33783: http://debbugs.gnu.org/cgi/bugreport.cgi?bug=3D33783 GNU Bug Tracking System Contact help-debbugs@gnu.org with problems ------------=_1545644162-7175-1 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at 33783-done) by debbugs.gnu.org; 24 Dec 2018 09:35:44 +0000 Received: from localhost ([127.0.0.1]:34305 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1gbMeG-0001rE-HB for submit@debbugs.gnu.org; Mon, 24 Dec 2018 04:35:44 -0500 Received: from flashner.co.il ([178.62.234.194]:40234) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1gbMeF-0001r2-A2 for 33783-done@debbugs.gnu.org; Mon, 24 Dec 2018 04:35:43 -0500 Received: from localhost (unknown [141.226.9.73]) by flashner.co.il (Postfix) with ESMTPSA id 829A7402D5 for <33783-done@debbugs.gnu.org>; Mon, 24 Dec 2018 09:35:37 +0000 (UTC) Date: Mon, 24 Dec 2018 11:35:36 +0200 From: Efraim Flashner To: 33783-done@debbugs.gnu.org Subject: Re: [bug#33783] [PATCH] gnu: sqlite: Replace with 3.26.0 [security fixes]. Message-ID: <20181224093536.GI2581@macbook41> References: <87mup31r6o.fsf@gmail.com> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="8tUgZ4IE8L4vmMyh" Content-Disposition: inline In-Reply-To: <87mup31r6o.fsf@gmail.com> User-Agent: Mutt/1.11.0 (2018-11-25) X-Spam-Score: -0.0 (/) X-Debbugs-Envelope-To: 33783-done X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.0 (-) --8tUgZ4IE8L4vmMyh Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Patch was pushed as 38abef124bc18d3834eb12352a974b6143f62e97 --=20 Efraim Flashner =D7=90=D7=A4=D7=A8=D7=99=D7=9D = =D7=A4=D7=9C=D7=A9=D7=A0=D7=A8 GPG key =3D A28B F40C 3E55 1372 662D 14F7 41AA E7DC CA3D 8351 Confidentiality cannot be guaranteed on emails sent or received unencrypted --8tUgZ4IE8L4vmMyh Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEoov0DD5VE3JmLRT3Qarn3Mo9g1EFAlwgqGcACgkQQarn3Mo9 g1EHCQ//cvhKFqruDAP8Y72Gt8cvWC9MeySvEo6eCecl6otoRXPeqgnSu71QJxdd s0QIO4dZtvqBSJiP9Y4x5wBBKBUWE4zcAXJpF1S7xRE/YVa2B1FGaQvo/bGiw2PN cPK68SDckMD9v0bKKbn4kHFPckb2R9BXtI7b/rH1kD2CKz2PNmxmeXhhXXqVjuM/ REQGzcKSvhY13O/Cnh5UlJe1WeEzrBgKC3fUeDLdTXEoWe0pDFBUbJtRxrBt9zzv G+7bAI1U/umDTJnZmHYPZKJRLNzKpwpl60sRMI4/YmRx6RmPyB81YzN/1pA9plzz Be4IhV4Rxrq7weNhV8J7DM0MbRifsBHLZ2CyEtNRojyzzMz7qiHJjiKUPsut6Yyb HimMJ40Em5BoSr2z4LNf9fw6oOrSZxUgyRpwtfS9zaWkebfCSgIrm9jY03UWNii+ IuUs4lD6z1aEk4iyvXrqzNZ73oA2YEwOkWAcmCdIwNb1TOjS6IhxyMp9vgRQhItm K0S21B9yvX3+GlyL+UY7eTtKoQ/jhT8etWSebJOcL8zvXAxmi+y7GiGO9y/+8oP/ fBjtA92CTN97EFhQIya8rlq2OKnltCiKbrokOHfH5+XXfPjdNsb5xH60/GRA2QkB JJjDnuuIGBcq53bbJ34zatGGNUxT7KxfLwilXJJ3ywG0gfXIJwc= =ElCV -----END PGP SIGNATURE----- --8tUgZ4IE8L4vmMyh-- ------------=_1545644162-7175-1 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at submit) by debbugs.gnu.org; 18 Dec 2018 02:54:07 +0000 Received: from localhost ([127.0.0.1]:52432 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1gZ5WC-0006aA-WF for submit@debbugs.gnu.org; Mon, 17 Dec 2018 21:54:07 -0500 Received: from eggs.gnu.org ([208.118.235.92]:52054) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1gZ5W6-0006Zt-Tx for submit@debbugs.gnu.org; Mon, 17 Dec 2018 21:53:59 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1gZ5W0-0006nt-8Q for submit@debbugs.gnu.org; Mon, 17 Dec 2018 21:53:49 -0500 X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on eggs.gnu.org X-Spam-Level: X-Spam-Status: No, score=0.2 required=5.0 tests=BAYES_20, FREEMAIL_ENVFROM_END_DIGIT,FREEMAIL_FROM autolearn=disabled version=3.3.2 Received: from lists.gnu.org ([2001:4830:134:3::11]:35516) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1gZ5W0-0006nI-0F for submit@debbugs.gnu.org; Mon, 17 Dec 2018 21:53:48 -0500 Received: from eggs.gnu.org ([2001:4830:134:3::10]:33366) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1gZ5Vx-0004e7-Ln for guix-patches@gnu.org; Mon, 17 Dec 2018 21:53:47 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1gZ5Vt-0006fV-QO for guix-patches@gnu.org; Mon, 17 Dec 2018 21:53:45 -0500 Received: from mail-pl1-x642.google.com ([2607:f8b0:4864:20::642]:45152) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1gZ5Vo-0006Gw-0C for guix-patches@gnu.org; Mon, 17 Dec 2018 21:53:38 -0500 Received: by mail-pl1-x642.google.com with SMTP id a14so7080959plm.12 for ; Mon, 17 Dec 2018 18:53:27 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:user-agent:date:message-id:mime-version; bh=QXfZG7uH9/ciK4D1yUPycbWLZdswJGv+rCDritw3954=; b=T15JqgoOGUHQWg+Fwx92Vhja65E0kQ2rh0UR2fBxtfz4yJzOjaCFI11aAxZyMRm8IU du4AzZ0yecb9Vnmy/e8DTnGS2E05NfLzlZFkI6Eu+7R7VIriwLB6YjMkFY2MGdF9NIl+ 0d6nyTKDzbWWZovg5w7qX6GOzxxjmzY1XA9SHIAIgB4g93l91r19bdbqDsjzmvfH6HjA zwtfg1wOPvkPQmwfI5m5b3IT7fe+lekMMnGKUc8Em/QjINgIVdoqo3iX3dKnWm4ur2I5 rcINSOAlNMFkdyYZCaU7MjZ0Ve/BFdp3ZDCbsBeqlY3+JbyU2YwawJao90R7Ko1PsMG6 jVqA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:user-agent:date:message-id :mime-version; bh=QXfZG7uH9/ciK4D1yUPycbWLZdswJGv+rCDritw3954=; b=JpCuFrlG07mZGsa2u92cfYyo935urVv6p8ifrZIbQdQaUS7cj6xK/SWS9jsYbRZBeB mfrndCadKsmhW0stnPH1aJcrjgUXEKXTi8JFeLS975oe4ntZtTHPfklofPqWeSgTYCj1 8RsYC5D5bJOxhYEln4iYMkyNxsANBZNPBrDPCDLvw9G/6ZLKw2iC2ibrKMVQy40F61Y0 6nk0Qxg3UwYlbkTuXfphyhy/fW14RTyqvhrMqiA80izOFFPfKXTvzQUiKw/+RgTUen6V ucWyK8wyDbKEd5ydHxbps3WwGkgmuz+HUokjASF22+oLrXL0tGMVdWDDEPPSZ6Z3xIAH M/Pw== X-Gm-Message-State: AA+aEWYfxO8MuxVMldzEfGKye6grEYBjVYSJe5W9rhmFYMEX7nXmJmv5 zukLI1lwsoNxFcgb+r+56uM= X-Google-Smtp-Source: AFSGD/WWbufwxgDzAna8hD4UgD+wGQXV4+wVwsCuPlSIVG02lhpYLfYswUMe0W0Pe7PdJ1wIOz4TjQ== X-Received: by 2002:a17:902:3181:: with SMTP id x1mr14802055plb.58.1545101606989; Mon, 17 Dec 2018 18:53:26 -0800 (PST) Received: from debian (n058152177090.netvigator.com. [58.152.177.90]) by smtp.gmail.com with ESMTPSA id u123sm16592543pfb.1.2018.12.17.18.53.25 (version=TLS1_2 cipher=ECDHE-RSA-CHACHA20-POLY1305 bits=256/256); Mon, 17 Dec 2018 18:53:26 -0800 (PST) From: Alex Vong To: guix-patches@gnu.org Subject: [PATCH] gnu: sqlite: Replace with 3.26.0 [security fixes]. User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/26.1 (gnu/linux) Date: Tue, 18 Dec 2018 10:53:19 +0800 Message-ID: <87mup31r6o.fsf@gmail.com> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="==-=-="; micalg=pgp-sha256; protocol="application/pgp-signature" X-detected-operating-system: by eggs.gnu.org: Genre and OS details not recognized. X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.6.x X-Received-From: 2001:4830:134:3::11 X-Spam-Score: -3.8 (---) X-Debbugs-Envelope-To: submit Cc: alexvong1995@gmail.com X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: 0.2 (/) --==-=-= Content-Type: multipart/mixed; boundary="=-=-=" --=-=-= Content-Type: text/plain Tag: security Hello, This patch grafts sqlite to its latest version. It also changes all the sqlite-* packages to use 'package/inherit' so that they get the replacement as well. See for details. --=-=-= Content-Type: text/x-diff; charset=utf-8 Content-Disposition: inline; filename=0001-gnu-sqlite-Replace-with-3.26.0-security-fixes.patch Content-Transfer-Encoding: quoted-printable From=209d0fae1e1fa2fc13bd794bb2dbeb89750c772cfb Mon Sep 17 00:00:00 2001 From: Alex Vong Date: Tue, 18 Dec 2018 10:36:52 +0800 Subject: [PATCH] gnu: sqlite: Replace with 3.26.0 [security fixes]. Fixes . Reported by Marius Bakke . * gnu/packages/databases.scm (sqlite-3.26.0): New public variable. (sqlite)[replacement]: Use it. (sqlite-with-fts5): Use 'package/inherit'. (sqlite-with-column-metadata): Likewise. =2D-- gnu/packages/databases.scm | 27 ++++++++++++++++++++++++--- 1 file changed, 24 insertions(+), 3 deletions(-) diff --git a/gnu/packages/databases.scm b/gnu/packages/databases.scm index 0fa6d451e..78d9a6739 100644 =2D-- a/gnu/packages/databases.scm +++ b/gnu/packages/databases.scm @@ -24,7 +24,7 @@ ;;; Copyright =C2=A9 2017 Adriano Peluso ;;; Copyright =C2=A9 2017 Arun Isaac ;;; Copyright =C2=A9 2017, 2018 Tobias Geerinckx-Rice =2D;;; Copyright =C2=A9 2017 Alex Vong +;;; Copyright =C2=A9 2017, 2018 Alex Vong ;;; Copyright =C2=A9 2017, 2018 Ben Woodcroft ;;; Copyright =C2=A9 2017 Rutger Helling ;;; Copyright =C2=A9 2017, 2018 Pierre Langlois @@ -1183,6 +1183,7 @@ changes.") (define-public sqlite (package (name "sqlite") + (replacement sqlite-3.26.0) (version "3.24.0") (source (origin (method url-fetch) @@ -1219,9 +1220,29 @@ widely deployed SQL database engine in the world. T= he source code for SQLite is in the public domain.") (license license:public-domain))) =20 +(define-public sqlite-3.26.0 + (package/inherit sqlite + (version "3.26.0") + (source (origin + (method url-fetch) + (uri (let ((numeric-version + (match (string-split version #\.) + ((first-digit other-digits ...) + (string-append first-digit + (string-pad-right + (string-concatenate + (map (cut string-pad <> 2 #\= 0) + other-digits)) + 6 #\0)))))) + (string-append "https://sqlite.org/2018/sqlite-autoco= nf-" + numeric-version ".tar.gz"))) + (sha256 + (base32 + "0pdzszb4sp73hl36siiv3p300jvfvbcdxi2rrmkwgs6inwznmajx"))))= )) + ;; This is used by Tracker. (define-public sqlite-with-fts5 =2D (package (inherit sqlite) + (package/inherit sqlite (name "sqlite-with-fts5") (arguments (substitute-keyword-arguments (package-arguments sqlite) @@ -1230,7 +1251,7 @@ is in the public domain.") =20 ;; This is used by Qt. (define-public sqlite-with-column-metadata =2D (package (inherit sqlite) + (package/inherit sqlite (name "sqlite-with-column-metadata") (arguments (substitute-keyword-arguments (package-arguments sqlite) =2D-=20 2.19.2 --=-=-= Content-Type: text/plain Cheers, Alex --=-=-=-- --==-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iHUEARYIAB0WIQQwb8uPLAHCXSnTBVZh71Au9gJS8gUCXBhhHwAKCRBh71Au9gJS 8uQDAP9K/j4Fho5Y0tGj2rPYQLgh2/X4rJ+Ad+xIKAtSja48xAEAyWKJMtJibdKy D55YjKFBOZJ59CTp0rJcPU+WYFdBgQk= =sDdb -----END PGP SIGNATURE----- --==-=-=-- ------------=_1545644162-7175-1-- --===-=-=-- --====-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iHUEARYIAB0WIQQwb8uPLAHCXSnTBVZh71Au9gJS8gUCXCJy0AAKCRBh71Au9gJS 8m2bAQDS+7q1hoDoaclKQDCl/PUTfxLfSIVux7s1VMClhGl03gEAo5rpJ3Sy4Zze LvvKVlu0iPqzUoe4VXZo3HiNUtAvZQM= =Diwx -----END PGP SIGNATURE----- --====-=-=--