From mboxrd@z Thu Jan 1 00:00:00 1970 From: ludo@gnu.org (Ludovic =?utf-8?Q?Court=C3=A8s?=) Subject: Re: openjpeg-2 security updates vs stale openjpeg-1 Date: Tue, 12 Sep 2017 10:04:04 +0200 Message-ID: <87k2141gy3.fsf@gnu.org> References: <87pob3d4b8.fsf@netris.org> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:51392) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1drgB0-00056Y-ST for guix-devel@gnu.org; Tue, 12 Sep 2017 04:04:16 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1drgAw-0003ln-UA for guix-devel@gnu.org; Tue, 12 Sep 2017 04:04:10 -0400 In-Reply-To: <87pob3d4b8.fsf@netris.org> (Mark H. Weaver's message of "Wed, 06 Sep 2017 15:18:03 -0400") List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Mark H Weaver Cc: guix-devel@gnu.org Hi Mark, Mark H Weaver skribis: > I've just rebuilt my x86_64 GuixSD system to use 'openjpeg' from git > (since I see many more fixes there that look security-relevant), and to > use this fresh openjpeg in both 'poppler' and 'tracker'. Unfortunately, > the 'poppler' change required a massive rebuild, but with these updates > my system seems to work just fine. > > I've attached my preliminary patches. > > Mark > > From abd9df8c4623cc44ef77be69977e2635c0fdd3bf Mon Sep 17 00:00:00 2001 > From: Mark H Weaver > Date: Mon, 4 Sep 2017 23:48:55 -0400 > Subject: [PATCH 1/3] gnu: openjpeg: Update to 2.2.0-1.3a382d312. > > * gnu/packages/image.scm (openjpeg): Switch to using a git checkout, and > update to 2.2.0-1.3a382d312. Remove patches. > * gnu/packages/patches/openjpeg-CVE-2017-12982.patch, > gnu/packages/patches/openjpeg-CVE-2017-14040.patch, > gnu/packages/patches/openjpeg-CVE-2017-14041.patch, > gnu/packages/patches/openjpeg-CVE-2017-14151.patch, > gnu/packages/patches/openjpeg-CVE-2017-14152.patch: Delete files. > * gnu/local.mk (dist_patch_DATA): Remove them. Should we graft this openjpeg variant? =E2=80=9Copenjpeg@1=E2=80=9D has 1,= 810 dependents. Thanks for the heads-up, and apologies for the delay! Ludo=E2=80=99.