From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp2 ([2001:41d0:2:bcc0::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms11 with LMTPS id 6KpeBB9VNWAMdgAA0tVLHw (envelope-from ) for ; Tue, 23 Feb 2021 19:18:55 +0000 Received: from aspmx1.migadu.com ([2001:41d0:2:bcc0::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp2 with LMTPS id eD4cAB9VNWCdKgAAB5/wlQ (envelope-from ) for ; Tue, 23 Feb 2021 19:18:55 +0000 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id 99F4011052 for ; Tue, 23 Feb 2021 20:18:53 +0100 (CET) Received: from localhost ([::1]:56200 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1lEdCu-0003ng-LG for larch@yhetil.org; Tue, 23 Feb 2021 14:18:52 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]:50866) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1lEdCC-0003mx-A6 for bug-guix@gnu.org; Tue, 23 Feb 2021 14:18:08 -0500 Received: from debbugs.gnu.org ([209.51.188.43]:49000) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1lEdC6-00058o-FV for bug-guix@gnu.org; Tue, 23 Feb 2021 14:18:08 -0500 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1lEdC6-0003uK-Bp for bug-guix@gnu.org; Tue, 23 Feb 2021 14:18:02 -0500 Subject: bug#46631: Python CVE-2021-3177 Resent-From: Leo Famulari Original-Sender: "Debbugs-submit" Resent-To: bug-guix@gnu.org Resent-Date: Tue, 23 Feb 2021 19:18:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: cc-closed 46631 X-GNU-PR-Package: guix X-GNU-PR-Keywords: security To: Ludovic =?UTF-8?Q?Court=C3=A8s?= Mail-Followup-To: 46631@debbugs.gnu.org, leo@famulari.name, leo@famulari.name Received: via spool by 46631-done@debbugs.gnu.org id=D46631.161410782514954 (code D ref 46631); Tue, 23 Feb 2021 19:18:02 +0000 Received: (at 46631-done) by debbugs.gnu.org; 23 Feb 2021 19:17:05 +0000 Received: from localhost ([127.0.0.1]:60544 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lEdBB-0003t7-Fs for submit@debbugs.gnu.org; Tue, 23 Feb 2021 14:17:05 -0500 Received: from wout4-smtp.messagingengine.com ([64.147.123.20]:35333) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lEdB9-0003sC-QX for 46631-done@debbugs.gnu.org; Tue, 23 Feb 2021 14:17:04 -0500 Received: from compute3.internal (compute3.nyi.internal [10.202.2.43]) by mailout.west.internal (Postfix) with ESMTP id E6297885; Tue, 23 Feb 2021 14:16:57 -0500 (EST) Received: from mailfrontend2 ([10.202.2.163]) by compute3.internal (MEProxy); Tue, 23 Feb 2021 14:16:58 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=famulari.name; h=date:from:to:cc:subject:message-id:references:mime-version :content-type:content-transfer-encoding:in-reply-to; s=mesmtp; bh=QU2t8QK0Rj3OuyDzpZlE+pG4uo2Db01WP+edvF3FWsA=; b=lxIEl6+XJ6oT mas8axLSs8I9xJ2mIQC/bWumOJxD8kGovvRIxR6MPUWneM3PBmcUc1yL3nHDaxNI A9FmK0g1jmlC3q7TwC/3tSNmDtqysBGVuh1MkmP7yv617A24u6IBc48b94J/2PrT OxCRrMjPAPTublbfv82WitIhG6eN7Wo= DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm2; bh=QU2t8QK0Rj3OuyDzpZlE+pG4uo2Db01WP+edvF3FW sA=; b=hztOQGImbRlZv3Iw1wUMMTjPKnB+IcqhokvdY2b1TPFOrYX0nvbNPgVIY IPFhVUgu/23qwxhHD95HDaZYxM1A/U9SKVjQhFI6tTINno2S2K8L1SUZGpCQXcSZ OAs7EkdEgw+9sYtrflFmieFYeI+GZjZjyckh70mYGz4yVvjBXyT7KoVcz9JPtYAT A6lis/njRtTFcpsmUvZsaVBuIQplFh9lUENRBzgChJ0rUuNa3mMtx1mZJP7WMGP1 Kdzey9sgJHPi2nfHa4ukAhkxSR7CY46FP9t6ok6cLV6xwj+iFpSTLwDuvkaqOGIR k89FahQ+pOP3l3t3HGUys8NQ7hEIg== X-ME-Sender: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeduledrkeehgdduvddvucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne cujfgurhepfffhvffukfhfgggtugfgjgesthekredttddtjeenucfhrhhomhepnfgvohcu hfgrmhhulhgrrhhiuceolhgvohesfhgrmhhulhgrrhhirdhnrghmvgeqnecuggftrfgrth htvghrnhepgeejgeeghedtudfgffdutddvffefffejkeffffevffehgedvvdeutdffkeej jeejnecukfhppedutddtrdduuddrudeiledruddukeenucevlhhushhtvghrufhiiigvpe dtnecurfgrrhgrmhepmhgrihhlfhhrohhmpehlvghosehfrghmuhhlrghrihdrnhgrmhgv X-ME-Proxy: Received: from localhost (pool-100-11-169-118.phlapa.fios.verizon.net [100.11.169.118]) by mail.messagingengine.com (Postfix) with ESMTPA id D427E1080066; Tue, 23 Feb 2021 14:16:56 -0500 (EST) Date: Tue, 23 Feb 2021 14:16:54 -0500 From: Leo Famulari Message-ID: References: <87pn0sfrtd.fsf@gnu.org> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <87pn0sfrtd.fsf@gnu.org> X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: bug-guix@gnu.org List-Id: Bug reports for GNU Guix List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: 46631-done@debbugs.gnu.org Errors-To: bug-guix-bounces+larch=yhetil.org@gnu.org Sender: "bug-Guix" X-Migadu-Flow: FLOW_IN X-Migadu-Spam-Score: -1.37 Authentication-Results: aspmx1.migadu.com; dkim=fail ("headers rsa verify failed") header.d=famulari.name header.s=mesmtp header.b=lxIEl6+X; dkim=fail ("headers rsa verify failed") header.d=messagingengine.com header.s=fm2 header.b=hztOQGIm; dmarc=none; spf=pass (aspmx1.migadu.com: domain of bug-guix-bounces@gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=bug-guix-bounces@gnu.org X-Migadu-Queue-Id: 99F4011052 X-Spam-Score: -1.37 X-Migadu-Scanner: scn1.migadu.com X-TUID: w0iu1XIUeyLt On Mon, Feb 22, 2021 at 09:08:14AM +0100, Ludovic Courtès wrote: > You can keep (inherit …) because the effect of ‘package/inherit’ is just > to preserve replacements, which is unnecessary here. I used to know that... it's been a while and I forgot, and had trouble understanding the package/inherit docstring. So I pushed a commit that I hope clarifies it. > Apart from that, the Guix side of things LGTM. Pushed as 84e082e31706411e7f9c3189a83f8ed0b4016fe7 > Thanks for working on it! Thanks for the review!