From mboxrd@z Thu Jan 1 00:00:00 1970 From: Leo Famulari Subject: Re: Expat regression fix for master branch Date: Tue, 27 Sep 2016 13:50:07 -0400 Message-ID: <20160927175007.GA2569@jasmine> References: <20160912213515.GA15911@jasmine> <20160925231811.GA1722@jasmine> <20160926082107.GD3742@macbook42.flashner.co.il> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="RnlQjJ0d97Da+TV1" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:47640) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bowWK-0002eu-NM for guix-devel@gnu.org; Tue, 27 Sep 2016 13:50:21 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1bowWG-0001Ah-DP for guix-devel@gnu.org; Tue, 27 Sep 2016 13:50:20 -0400 Received: from out2-smtp.messagingengine.com ([66.111.4.26]:50825) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bowWE-000154-3Z for guix-devel@gnu.org; Tue, 27 Sep 2016 13:50:16 -0400 Content-Disposition: inline In-Reply-To: <20160926082107.GD3742@macbook42.flashner.co.il> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Efraim Flashner Cc: guix-devel@gnu.org --RnlQjJ0d97Da+TV1 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Mon, Sep 26, 2016 at 11:21:07AM +0300, Efraim Flashner wrote: > On Sun, Sep 25, 2016 at 07:18:11PM -0400, Leo Famulari wrote: > > On Mon, Sep 12, 2016 at 05:35:15PM -0400, Leo Famulari wrote: > > > This patch applies an upstream patch for a regression caused by the f= ix=20 > > > for CVE-2016-0718. > > >=20 > > > Apparently, the bug only manifests when building with -DXML_UNICODE, > > > which I don't think our package does. > >=20 > > Sebastian Pipping (the Expat maintainer) contacted me to recommend that > > we apply the patch on the master branch. > >=20 > > He says that the faulty code path can be reached even when XML_UNICODE > > is not defined. Apparently, building with -DXML_UNICODE merely makes it > > easier to reach the faulty code. > >=20 > > I think we should take Sebastian's advice. What does everyone think? >=20 >=20 > Seems to me that as the Expat maintainer he would know best. I pushed the commit as b9bc6e842066b066ebdf9eaf75d41753598d75b5 --RnlQjJ0d97Da+TV1 Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCAAGBQJX6rFPAAoJECZG+jC6yn8I8PUP/3Q7p2+LafQLZBDS5ccw/Ymq 7pFO8k4AFdvbHX7PGZp/a4RI4wO8uye9e2jZtoobah1sLK8lSehXM6iqgjLfxL3S 1CE9QCZzoYImSlxbL3QRoqCS3X79jbQukNLpMDxffbeWnbntxRtfds1fJswS8mv0 CeJWEFbsV9qfG4gDDOzTptMY49E5jXtEkXLwPrWIWt55uO+x0JLi0fsjp9WNmHNi wuJuG5tYYfXUr1rFfJRP6k4l/f4kvVTcw1+g3U1tQ4pVMcCaOqWY/5yRhjxERQ3Y XiZS9pH+VL91ruQvTNODNDgfcAL3+OARxiqelseYvN8oumli/7usf8SxNTqrBQwR FLqMuysMWBP9Qo2XWfDt3WWsYzKbOnzkiUAQw/3vjEr025csjnwHgduEe0AcMyRe c3QZjHvQGSiVSyOnTq5EWp2BdH60U1DuO1z8gRPfPlPhircab9VGOjDMg/3RAiCg Ytr4khEcv9h8uXsznX8cZrDvctk1QdGEy5WX4/BzgR6KF3r5R88UO4of4h2eKofB o6f6AX8ISYqzq4VFxKkYVX39WVIQ4ADsHpaK8NGeqNe0lbeNPMNgYQraAYYe3q6l VXCKo2OZyaJArnY+em7ubO0EUpcMBLnIFrp0lsm937Rxaqbb99AXwBzslrNkvCfN DMzq0dzg82gR3gWejDaI =rRh8 -----END PGP SIGNATURE----- --RnlQjJ0d97Da+TV1--