From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp2.migadu.com ([2001:41d0:700:3204::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms8.migadu.com with LMTPS id CGroLMPwe2VZogAAkFu2QA (envelope-from ) for ; Fri, 15 Dec 2023 07:22:59 +0100 Received: from aspmx1.migadu.com ([2001:41d0:403:58f0::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp2.migadu.com with LMTPS id 8CGEI8Pwe2XXFQAAe85BDQ (envelope-from ) for ; Fri, 15 Dec 2023 07:22:59 +0100 X-Envelope-To: larch@yhetil.org Authentication-Results: aspmx1.migadu.com; dkim=pass header.d=protonmail.com header.s=protonmail3 header.b=Hzm6yw6t; spf=pass (aspmx1.migadu.com: domain of "guix-devel-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-devel-bounces+larch=yhetil.org@gnu.org"; dmarc=pass (policy=quarantine) header.from=protonmail.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1702621379; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding:list-id:list-help: list-unsubscribe:list-subscribe:list-post:dkim-signature; bh=3px+k6vauhTKZ/4A/u4vxoVOwfMxjkzppiqSdovUGdQ=; b=YfVhF6XWzb+cBaI/zNdNxmh/ZALQUQ1Vx0VBjBmbLL3730nY7Gk//mIf+jyTqO4WjM8SMm pqjxhvuAIub+3FpkBQ2pOv/YmlmqjIreF5Hw3pdW9dZClS9rg8UaLRCxdzqUVuhUfFdl3a Ele0+dZRaQksXxeiMVP6uiMtrJeJabcREz3ZPuGCa3s7KN4baVUMpdS4N615uiD2UXwfHZ 3o1ocLCbH0bRCUGNcCN8CO/X+ekUyvmC3mM35K9riQ7XuK/YoRlubTzKwo83A8B7WLWLuS /tN9kqf3LOy5Q+LO7sfJZ12JjVtIeQc+ObFd84QAZnXwutaR/F3/q/qdTsFuIg== ARC-Seal: i=1; s=key1; d=yhetil.org; t=1702621379; a=rsa-sha256; cv=none; b=AbZ4rpKAEILCOGHCUNZfEqJeQh9bOikziwtJRb2fXePVV7z2zrA1UwA9RoyrByooHYy3wO VBv1jLP2vbS5uvl0YW4IFa/F/YlqdcTUVdj1HgZPkAu+Q0t27je/KpOHsQ1XuSWGPb8JxL 2M202WmDUsPwwTBNki6oSYiwau/IeRJgReFl/zpte5QZe+7vf/MLPow3KagmScACBhfnqd Xt0r9r+hDV+/VfsMyl0LkVXKnWxTaMfOX5wSEWRcWoh8T2n91ffsK0GI9lxUkkt2iguNdH X2vL1roHS05n3eh5g8ad2XxfuhLwn7bKotMgRrDqIiTK2I1WwhaZ4lfeILMeYA== ARC-Authentication-Results: i=1; aspmx1.migadu.com; dkim=pass header.d=protonmail.com header.s=protonmail3 header.b=Hzm6yw6t; spf=pass (aspmx1.migadu.com: domain of "guix-devel-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-devel-bounces+larch=yhetil.org@gnu.org"; dmarc=pass (policy=quarantine) header.from=protonmail.com Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id 4F81F55D8E for ; Fri, 15 Dec 2023 07:22:59 +0100 (CET) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1rE1aM-0001jK-Hp; Fri, 15 Dec 2023 01:22:10 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1rE1aL-0001gw-65 for guix-devel@gnu.org; Fri, 15 Dec 2023 01:22:09 -0500 Received: from mail-4316.protonmail.ch ([185.70.43.16]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1rE1aJ-0000fB-1r for guix-devel@gnu.org; Fri, 15 Dec 2023 01:22:08 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=protonmail.com; s=protonmail3; t=1702621323; x=1702880523; bh=3px+k6vauhTKZ/4A/u4vxoVOwfMxjkzppiqSdovUGdQ=; h=Date:To:From:Cc:Subject:Message-ID:Feedback-ID:From:To:Cc:Date: Subject:Reply-To:Feedback-ID:Message-ID:BIMI-Selector; b=Hzm6yw6tS9Um1IIERIPYQUYxZHK4PL1atDdJQEzI3PwGukp/NHwR2MXasXfDesP/z eaGykSmcXOxVVaTLgO63ILk9Ssh99G5XDV1yz//pHPdauPjKfs9YNV4IJSWI/pCQqW TrEjmOMdxqEwuqMwOMJaTuxS9SzgNaUYToJD7dUbIU5ACaA5lE+6pQK7fhamm0m4S4 N/oqo+vpDeVrGPqLO4/B8BNW0ht5MaHN9tRIV9BZs+bkFheyATvQGJ9L0eLcUIC5Ot cIiC9QOmIZ3Dn/v6e2Pu2YnnKF1r3UXI89MGiQQxHv+j27xt5OR8XwWW0tBmaq42FK /wgKkojt4DlUw== Date: Fri, 15 Dec 2023 06:21:44 +0000 To: guix-devel From: John Kehayias Cc: Maxim Cournoyer , Liliana Marie Prikler , Vivien Kraus , Kaelyn Subject: xwayland security updates, to mesa- or core-updates or ? Message-ID: <871qbornny.fsf@protonmail.com> Feedback-ID: 7805494:user:proton MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Received-SPF: pass client-ip=185.70.43.16; envelope-from=john.kehayias@protonmail.com; helo=mail-4316.protonmail.ch X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: guix-devel@gnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+larch=yhetil.org@gnu.org Sender: guix-devel-bounces+larch=yhetil.org@gnu.org X-Migadu-Flow: FLOW_IN X-Migadu-Country: US X-Migadu-Spam-Score: -2.62 X-Spam-Score: -2.62 X-Migadu-Queue-Id: 4F81F55D8E X-Migadu-Scanner: mx11.migadu.com X-TUID: T35OdgwTN4uq Hi Guix, In light of (more) CVEs in xwayland, see , with already pending security updates, see , I would like to prioritize getting that fixed in master. The tricky thing is that, according to 67136, the xwayland update needs newer xorgproto, which corresponds to many rebuilds. (The related CVEs in xorg-server have been pushed already as effectively minor version bumps.) Where is the most efficient branch for this, that could take these rebuilds to be merged to master soon (whatever soon is for a scope of something like 22k affected packages)? I was thinking to put that update and mesa, since it had a new stable release after the current one never got updates, on mesa-updates and merge once builds are done assuming no issues. Again, the potential sore spot is xorgproto I would say. I could see about any other pending/urgent related changes, but I'm not aware of any off the top of my head and want to let this move quickly. I also don't want to jump the queue sending other branches to rebuild everything again. I'll test things locally in the meantime, but please chime in. If I don't hear anything too urgent I'll update the mesa-updates branch to start builds at least. I've also cc'ed some names I think will be knowledgeable about some current branches. And thanks to Kaelyn (also cc'ed) for the pending xwayland patches! Thanks! John