unofficial mirror of guix-devel@gnu.org 
 help / color / mirror / code / Atom feed
* Expat in GuixSD, please update
@ 2017-10-25 12:58 Sebastian Pipping
  2017-10-25 14:05 ` Vincent Legoll
                   ` (2 more replies)
  0 siblings, 3 replies; 7+ messages in thread
From: Sebastian Pipping @ 2017-10-25 12:58 UTC (permalink / raw)
  To: guix-devel

Hi GuixSD team,


from looking at [1] and [2] my impression is that GuixSD is still at
version 2.2.2 with Expat, while there is version 2.2.4 with bugfixes
upstream.  Is there anything blocking an update on your side that needs
fixing upstream?

Best



Sebastian


[1] https://repology.org/metapackage/expat/versions
[2] https://www.gnu.org/software/guix/packages/e.html

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: Expat in GuixSD, please update
  2017-10-25 12:58 Expat in GuixSD, please update Sebastian Pipping
@ 2017-10-25 14:05 ` Vincent Legoll
  2017-10-25 14:24   ` Sebastian Pipping
  2017-10-25 16:28 ` Tobias Geerinckx-Rice
  2017-10-25 17:22 ` Leo Famulari
  2 siblings, 1 reply; 7+ messages in thread
From: Vincent Legoll @ 2017-10-25 14:05 UTC (permalink / raw)
  To: Sebastian Pipping; +Cc: guix-devel

Hello,

maybe you can try to submit a patch for review...

That ought to be fairly easy

-- 
Vincent Legoll

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: Expat in GuixSD, please update
  2017-10-25 14:05 ` Vincent Legoll
@ 2017-10-25 14:24   ` Sebastian Pipping
  0 siblings, 0 replies; 7+ messages in thread
From: Sebastian Pipping @ 2017-10-25 14:24 UTC (permalink / raw)
  To: Vincent Legoll; +Cc: guix-devel

Sorry, no time.


On 25.10.2017 16:05, Vincent Legoll wrote:
> Hello,
> 
> maybe you can try to submit a patch for review...
> 
> That ought to be fairly easy
> 

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: Expat in GuixSD, please update
  2017-10-25 12:58 Expat in GuixSD, please update Sebastian Pipping
  2017-10-25 14:05 ` Vincent Legoll
@ 2017-10-25 16:28 ` Tobias Geerinckx-Rice
  2017-10-25 17:22 ` Leo Famulari
  2 siblings, 0 replies; 7+ messages in thread
From: Tobias Geerinckx-Rice @ 2017-10-25 16:28 UTC (permalink / raw)
  To: sebastian, guix-devel

Sebastian,

Sebastian Pipping wrote on 25/10/17 at 14:58:
> from looking at [1] and [2] my impression is that GuixSD is still at
> version 2.2.2 with Expat, while there is version 2.2.4 with bugfixes
> upstream.

Thanks for the report!

I see that 2.2.3 fixed a CVE, so I hurried up a patch[0].

Kind regards,

T G-R

[0]: http://debbugs.gnu.org/cgi/bugreport.cgi?bug=28996

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: Expat in GuixSD, please update
  2017-10-25 12:58 Expat in GuixSD, please update Sebastian Pipping
  2017-10-25 14:05 ` Vincent Legoll
  2017-10-25 16:28 ` Tobias Geerinckx-Rice
@ 2017-10-25 17:22 ` Leo Famulari
  2017-10-25 17:29   ` Tobias Geerinckx-Rice
  2 siblings, 1 reply; 7+ messages in thread
From: Leo Famulari @ 2017-10-25 17:22 UTC (permalink / raw)
  To: Sebastian Pipping; +Cc: guix-devel

[-- Attachment #1: Type: text/plain, Size: 1248 bytes --]

On Wed, Oct 25, 2017 at 02:58:13PM +0200, Sebastian Pipping wrote:
> Hi GuixSD team,
> 
> 
> from looking at [1] and [2] my impression is that GuixSD is still at
> version 2.2.2 with Expat, while there is version 2.2.4 with bugfixes
> upstream.  Is there anything blocking an update on your side that needs
> fixing upstream?

Thank you very much for reaching out, Sebastian.

No, there is nothing concrete blocking the update. I've just given
Tobias a "LGTM" for his 2.2.4 update patch.

There is a slight cost to updating packages with many dependents in Guix
[0], so we prefer not to update them between "core update" cycles unless
there are security issues affecting our users.

Expat 2.2.3's release notes only mentioned CVE-2017-11742, which is a
Windows vulnerability and out of scope for Guix. And I didn't see
security issues disclosed in the 2.2.4 release notes.

But, we can treat Expat as one of those "always update" libraries if
that is suggested. It's probably the right choice for any widely-used C
library.

[0] By treating package building as a pure function, if a lower-level
package changes, all dependent packages must be rebuilt. We have a
mechanism called grafting to cheat for security updates.

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 833 bytes --]

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: Expat in GuixSD, please update
  2017-10-25 17:22 ` Leo Famulari
@ 2017-10-25 17:29   ` Tobias Geerinckx-Rice
  2017-10-25 17:31     ` Leo Famulari
  0 siblings, 1 reply; 7+ messages in thread
From: Tobias Geerinckx-Rice @ 2017-10-25 17:29 UTC (permalink / raw)
  To: leo; +Cc: guix-devel


[-- Attachment #1.1: Type: text/plain, Size: 416 bytes --]

Leo Famulari wrote on 25/10/17 at 19:22:
> Expat 2.2.3's release notes only mentioned CVE-2017-11742, which is a
> Windows vulnerability and out of scope for Guix. And I didn't see
> security issues disclosed in the 2.2.4 release notes.

Ah, sorry to spread misinfo. I don't have Web access at the moment and
erred on the side of caution. I'll adjust the patch accordingly & push.

Kind regards,

T G-R


[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 248 bytes --]

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: Expat in GuixSD, please update
  2017-10-25 17:29   ` Tobias Geerinckx-Rice
@ 2017-10-25 17:31     ` Leo Famulari
  0 siblings, 0 replies; 7+ messages in thread
From: Leo Famulari @ 2017-10-25 17:31 UTC (permalink / raw)
  To: Tobias Geerinckx-Rice; +Cc: guix-devel

[-- Attachment #1: Type: text/plain, Size: 671 bytes --]

On Wed, Oct 25, 2017 at 07:29:28PM +0200, Tobias Geerinckx-Rice wrote:
> Leo Famulari wrote on 25/10/17 at 19:22:
> > Expat 2.2.3's release notes only mentioned CVE-2017-11742, which is a
> > Windows vulnerability and out of scope for Guix. And I didn't see
> > security issues disclosed in the 2.2.4 release notes.
> 
> Ah, sorry to spread misinfo. I don't have Web access at the moment and
> erred on the side of caution. I'll adjust the patch accordingly & push.

I think we can still mention that we've fixed that bug. Somebody could
still use Guix as a source of free source code even if they were
developing for Windows.

No big deal either way, IMO.

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 833 bytes --]

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2017-10-25 17:31 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2017-10-25 12:58 Expat in GuixSD, please update Sebastian Pipping
2017-10-25 14:05 ` Vincent Legoll
2017-10-25 14:24   ` Sebastian Pipping
2017-10-25 16:28 ` Tobias Geerinckx-Rice
2017-10-25 17:22 ` Leo Famulari
2017-10-25 17:29   ` Tobias Geerinckx-Rice
2017-10-25 17:31     ` Leo Famulari

Code repositories for project(s) associated with this public inbox

	https://git.savannah.gnu.org/cgit/guix.git

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).