From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp11.migadu.com ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms5.migadu.com with LMTPS id +AutJvnxBGQi0AAAbAwnHQ (envelope-from ) for ; Sun, 05 Mar 2023 20:48:09 +0100 Received: from aspmx1.migadu.com ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp11.migadu.com with LMTPS id OFWmJvnxBGT03gAA9RJhRA (envelope-from ) for ; Sun, 05 Mar 2023 20:48:09 +0100 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id 5CC522C200 for ; Sun, 5 Mar 2023 20:48:09 +0100 (CET) Authentication-Results: aspmx1.migadu.com; dkim=none; dmarc=none; spf=pass (aspmx1.migadu.com: domain of "guix-patches-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-patches-bounces+larch=yhetil.org@gnu.org" ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1678045689; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:resent-cc:resent-from:resent-sender: resent-message-id:in-reply-to:in-reply-to:references:references: list-id:list-help:list-unsubscribe:list-subscribe:list-post; bh=TLT4Xe7GIfAQ2YGnKT5FjaHgEKvVWh5uOw76r9NJ5dk=; b=oB3TE23RWJQJvGxUJ0PtOxLjyCCSPaWw1TEOhibN8UOvsajCXKqmy0QtIcl30SsMUbKNlg kasTpRngDnSLc/odCly4mXvjGI9TO4X/xLOtDmkLX1PUNC4zKvBn4vDvRqcAQiyBOaVoWm UnGAloo9W2R7eEvV7gUj3xsh0WjaMZWM3N+svKjHFiukWeL3zR9Uas+hMUuasxxaVtxDig kccBg/gvDWq+05tXXWmnf1LBKZa3Vz2wirUH84beRZnbDQbuQvgZJ3x4wlRYwO35fKCmbT nu6FLA2qw97EF6o+R+MJprpT9iZ1LF7nCuSrGxiMoabhcFE4R3fQOA/SSbi2Ig== ARC-Authentication-Results: i=1; aspmx1.migadu.com; dkim=none; dmarc=none; spf=pass (aspmx1.migadu.com: domain of "guix-patches-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-patches-bounces+larch=yhetil.org@gnu.org" ARC-Seal: i=1; s=key1; d=yhetil.org; t=1678045689; a=rsa-sha256; cv=none; b=TDY6LbEKw6vhqIx0MaKBquosjjJxNzHuf5FqeYXXl1Ckukaoh90JqN+7uxhGjjlG5MGt88 t1tFYdEAQGVb79ArNoScaQr8/Ypvb7s7XpJstHgJUnv8T1kuG/CAmWB2Vwxb9lgu68n7Ci OqO9yarfVaeoZFQ1FD+2e7KCoMoqXxDMkMnOaK/iQjwfx2NR75UnzADxPBfd8W0Qdxl1gU mNVC34sOrm8wYaTUzKt87q4hdRpmob9pneJiBUTSe15RnEPWlIZKaQUm5qnkSazuWXYdAH u7xkGYqSfNYsUD9ghM8IK3uQBamxGYwZJrcoT2EikLIh8HbhOzzVBQpJSMfefA== Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1pYuKy-0006mo-5b; Sun, 05 Mar 2023 14:48:04 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1pYuKw-0006mc-K7 for guix-patches@gnu.org; Sun, 05 Mar 2023 14:48:02 -0500 Received: from debbugs.gnu.org ([209.51.188.43]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1pYuKw-0005Bi-6f for guix-patches@gnu.org; Sun, 05 Mar 2023 14:48:02 -0500 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1pYuKv-00026k-TE for guix-patches@gnu.org; Sun, 05 Mar 2023 14:48:01 -0500 X-Loop: help-debbugs@gnu.org Subject: [bug#61583] [PATCH] gnu: git: Update to 2.39.2 [fixes CVE-2023-22490 & CVE-2023-23946]. Resent-From: Christopher Baines Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Sun, 05 Mar 2023 19:48:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 61583 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: Leo Famulari Cc: 61583@debbugs.gnu.org, Greg Hogan , Simon Tournier Received: via spool by 61583-submit@debbugs.gnu.org id=B61583.16780456367929 (code B ref 61583); Sun, 05 Mar 2023 19:48:01 +0000 Received: (at 61583) by debbugs.gnu.org; 5 Mar 2023 19:47:16 +0000 Received: from localhost ([127.0.0.1]:40691 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1pYuKC-00023p-3W for submit@debbugs.gnu.org; Sun, 05 Mar 2023 14:47:16 -0500 Received: from mira.cbaines.net ([212.71.252.8]:42346) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1pYuKA-00023h-OE for 61583@debbugs.gnu.org; Sun, 05 Mar 2023 14:47:15 -0500 Received: from localhost (unknown [IPv6:2a02:8010:68c1:0:3a91:a0a4:ecee:f157]) by mira.cbaines.net (Postfix) with ESMTPSA id 8C40116B8B; Sun, 5 Mar 2023 19:47:12 +0000 (GMT) Received: from felis (localhost [127.0.0.1]) by localhost (OpenSMTPD) with ESMTP id 6b63de03; Sun, 5 Mar 2023 19:47:10 +0000 (UTC) References: <20230217180402.29401-1-code@greghogan.com> <87y1os36js.fsf@gmail.com> User-agent: mu4e 1.8.13; emacs 28.2 From: Christopher Baines Date: Sun, 05 Mar 2023 19:27:40 +0000 In-reply-to: Message-ID: <871qm3rner.fsf@cbaines.net> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: X-Migadu-Scanner: scn0.migadu.com X-Migadu-Queue-Id: 5CC522C200 X-Spam-Score: -3.81 X-Migadu-Spam-Score: -3.81 List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+larch=yhetil.org@gnu.org Sender: guix-patches-bounces+larch=yhetil.org@gnu.org X-Migadu-Flow: FLOW_IN X-Migadu-Country: US X-TUID: 2GNbWsXnJKJP --=-=-= Content-Type: text/plain Leo Famulari writes: > On Sat, Mar 04, 2023 at 07:52:04PM +0100, Simon Tournier wrote: >> I get 546 dependent packages for git + git-minimal which need to be >> re-built. And some are really expensive -- that what I meant by "a >> lot of rebuilds". :-) >> >> Well, I do not know if there is an issue with QA or it is just really >> expensive but the process is still pending, if I read correctly >> . > > At the Guix Days, it was said that there is a limit to how many builds > the QA server will perform for a change. I don't recall the number, but > maybe 300 builds per change? So, if a change causes too many rebuilds, > the QA server will not perform the builds. Currently the limit is 200 builds per system. https://git.cbaines.net/guix/qa-frontpage/tree/guix-qa-frontpage/manage-builds.scm#n99 > Aside: Chris, I'd be happy to add a FAQ page to the QA server that > answers this type of question. Let me know if I've missed that one > already exists. Contributions are very welcome, there's no documentation yet. >> > Concretely, why can't we push this to master immediately? >> >> Somehow the guarantee that none of these 546 would not be broken by >> the update. ;-) > > It's certainly possible that something breaks. But we can do a simple > test by trying to update our profiles and Guix System installations, and > checking that our tools still work. I think it's okay to cause a little > breakage in order to deploy important security updates. The backlog of revisions to be processed by data.qa.guix.gnu.org is being processed faster now, so hopefully the impact of this change will be visible there shortly. --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQKlBAEBCgCPFiEEPonu50WOcg2XVOCyXiijOwuE9XcFAmQE8bxfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDNF ODlFRUU3NDU4RTcyMEQ5NzU0RTBCMjVFMjhBMzNCMEI4NEY1NzcRHG1haWxAY2Jh aW5lcy5uZXQACgkQXiijOwuE9XcGdw/9Ee94HmMs/rRsLx3yaPSH5FxjL1nHqcFU 6CuQ+YQNVvjCHF4WXuZzEDMeqv/MHS6J08bWstG03vPx9Vw1q9xfTSJ8XJsdPipe Du//5AI4JDecDx/Rhr82ZppULq+S3H8mM3d54P9h8kz1pHjoxlN7llhXKlsi9/lu RqIAhhfyXQU5h2amZL3yOO9zMwy9FWbSkd3q+tzYvcnEBApZgjlQPbLXQis1FgKd CCCPsPamqRGxPasFidKKo9nsnwBFQH9ETuUhD5tgv9YXQy4eZRGpHNqt9Ax55azx ile8+OGjqGOsQSf3+C+l5AVUW755PoW50JFgEgbSVpiFZNUvYjqNkSNr/q/CIjII Q3+zeb7sKJ/NwgLXxnvGnhjVxPeOXY47SlbYg8Qr5AJbWbyS5E/cTYAr+Wl6DVTK cYrMXnz0+Y3LUH+xsf2dEZfindGKHqGznMlt/WZYIyT9JrbeI9EgtVxwqOgoz9ON aRuEcAXWd/CPWVM2dWWVRzQUfY3CQitSCy26nG/CJclQBdJeQ8IszEMUS+qAypAI EsOZlsh71XxeB/8lHgFQqPVQQM8VgBdvyVSoxy3yoemqALsqZ4Fgx6CR5i6N8gUG 990k7LC7GNF1ZxDL4fVFmFheGHvF/+mjCiM6f1+FrX8WmFStEkEaLLC8hPUB4MwG 2uELLhc0zy8= =69BE -----END PGP SIGNATURE----- --=-=-=--