From mboxrd@z Thu Jan 1 00:00:00 1970 From: Leo Famulari Subject: Re: tor: update to 0.2.9.9 Date: Tue, 24 Jan 2017 14:07:26 -0500 Message-ID: <20170124190726.GB6110@jasmine> References: <20170124111934.16080-1-contact.ng0@cryptolab.net> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="Dxnq1zWXvFF0Q93v" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:33352) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cW6RH-000229-D8 for guix-devel@gnu.org; Tue, 24 Jan 2017 14:07:32 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1cW6RD-0005oV-7y for guix-devel@gnu.org; Tue, 24 Jan 2017 14:07:31 -0500 Received: from out1-smtp.messagingengine.com ([66.111.4.25]:36246) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1cW6RD-0005oP-4Q for guix-devel@gnu.org; Tue, 24 Jan 2017 14:07:27 -0500 Content-Disposition: inline In-Reply-To: <20170124111934.16080-1-contact.ng0@cryptolab.net> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: contact.ng0@cryptolab.net Cc: guix-devel@gnu.org --Dxnq1zWXvFF0Q93v Content-Type: text/plain; charset=us-ascii Content-Disposition: inline On Tue, Jan 24, 2017 at 11:19:33AM +0000, contact.ng0@cryptolab.net wrote: > Changes in version 0.2.9.9 - 2017-01-23 > o Major bugfixes (security): > - Downgrade the "-ftrapv" option from "always on" to "only on when > --enable-expensive-hardening is provided." This hardening option, > like others, can turn survivable bugs into crashes -- and having > it on by default made a (relatively harmless) integer overflow bug > into a denial-of-service bug. Fixes bug 21278 (TROVE-2017-001); > bugfix on 0.2.9.1-alpha. I'm not familiar with Tor's build system. Should we build Tor with "--enable-expensive-hardening"? --Dxnq1zWXvFF0Q93v Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEsFFZSPHn08G5gDigJkb6MLrKfwgFAliHpe0ACgkQJkb6MLrK fwjmoBAAxllOHaZOfzwRzPtjpUOBK2z0cJwV/Td1e2uYG7hUBUyunOCO4bqAoegp XqQ0hrcd7WsbIQP1kPhsjSySMCJ5MavwfHsaUEwTHG5poOjNJnMotl6I1dIURtRu OIG1A5O3wlnOogObIB5HUcEdcqY/dm42nLnAZJZTJ4Cnd+jpxHXa8KSg6YTWSKIo YcQfyBemxLWLK8lL4/wesaNxA9tdyDLInWL4JamKtHRTxu+ae7hmExlsM0Nq6qiA u0wXkAQFaziG4toXb0W5ZvB4DVppMMCWnzx3tepXciAyBz+muVg04Ieu7AI+Ap9N GYvhk6mkF6coKzeyR2cHQDpcdShxEIhRiVZ1Nkl1Ds0jQG0A0qqZtmmYG69APr7X NTwLc/dANC57n7UgbLd9ziDRB7w7Rcsv/PsaSVeCMkejiNDieWBhmXrv7aqFvDLT Cwa6W6KqCeS7b19nj5d8BjjzVJhqgHjZqbhN5IkcnOVdOqk0kgfXtJsDZTnbw978 +M+0odYoZBUd+TLFxUcRQR02lLBX2/k0TLX6BD0jpsGSwy1Ge6EM9VFsQufQOP+q EXM2bBFGvy9HW4keY3O7N1N82/4zFZ0TzxgLBsgjvNRh8i5rg5x70oJGUSYHQNMp sXC0eVuaX3+Viw70XzKIHNE7saEh8KhaIupqz1O5qk/jywyllO4= =0Yck -----END PGP SIGNATURE----- --Dxnq1zWXvFF0Q93v--