From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp11.migadu.com ([2001:41d0:306:2d92::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms9.migadu.com with LMTPS id +BVAKnrn9WSRewEA9RJhRA:P1 (envelope-from ) for ; Mon, 04 Sep 2023 16:19:38 +0200 Received: from aspmx1.migadu.com ([2001:41d0:306:2d92::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp11.migadu.com with LMTPS id +BVAKnrn9WSRewEA9RJhRA (envelope-from ) for ; Mon, 04 Sep 2023 16:19:38 +0200 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id 76E0746BB5 for ; Mon, 4 Sep 2023 16:19:38 +0200 (CEST) Authentication-Results: aspmx1.migadu.com; dkim=fail ("headers rsa verify failed") header.d=gmail.com header.s=20221208 header.b=RP9+viau; spf=pass (aspmx1.migadu.com: domain of "guix-patches-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-patches-bounces+larch=yhetil.org@gnu.org"; dmarc=none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1693837178; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:resent-cc:resent-from:resent-sender: resent-message-id:in-reply-to:in-reply-to:references:references: list-id:list-help:list-unsubscribe:list-subscribe:list-post: dkim-signature; bh=5/qX7goA/p0o6s9J2XdfK05Eu1tZarx3FjqrsBzNj94=; b=JANrnTDD9rnSR2e1uo/anwaU7SusojCofWVCTQ9ZSNTGJjoiUgkGrKijVEY4APG8+L6KWn 03PZs84zD35vRg/W1p4aTK14jyBZQPKvXLywwiUxp94Z9QWQsTBWkQEP7uo/dRqmu901tn TMjr7D+VGjlULrLP0kFE48No9IAdr6/2yb4BnkUZttf/PJdEPWEOlXxNnjALYkOvJynokR mKph9YCvUSK5ovQIGolQQMySwiDjQgjY6G2pD9VVxmwv09EKm8cRmFoZIIDb3VdMF3rBbF L1qJGXziq+obpLLxxsx4ZNiuM9BZqqLnnHBl9oL+1fGvEa6kP5BhExBmkEPEAg== ARC-Seal: i=1; s=key1; d=yhetil.org; t=1693837178; a=rsa-sha256; cv=none; b=UaY2WVOl8iKs4IYPCFRFFfdKF+Kf8BGWOu6AZTj5s+oDetYjVFmiksgL8d8qKQ4GHFE5kV HeF/6RwR/DL1f5M++sxFY8Et9BFMQwhvC1wtoTPTQ6pXL45ajVesfEpoxE7OcU7T9F8QjX 92yPgojepJRKoljQjHlXwe9DdCWUV40ieUUc/SMsfOLk4FDLuuxTr0EtImupzbQnI+wTt4 HDmh3rxvYQD+BaFChJO2Xyq+2OvKxWjoEoQ5StUgLCoPBy3GEqL8Nmb9DXH20mRhtZiPgU EEKPR7TC5tjnSyQzqjIYj73kIhWxuQBrhbbAoH/6nVhJPev2XmwcUm53FHJ7eQ== ARC-Authentication-Results: i=1; aspmx1.migadu.com; dkim=fail ("headers rsa verify failed") header.d=gmail.com header.s=20221208 header.b=RP9+viau; spf=pass (aspmx1.migadu.com: domain of "guix-patches-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-patches-bounces+larch=yhetil.org@gnu.org"; dmarc=none Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1qdAPx-0001Ql-Jt; Mon, 04 Sep 2023 10:19:05 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1qdAPu-0001Ox-Jy for guix-patches@gnu.org; Mon, 04 Sep 2023 10:19:02 -0400 Received: from debbugs.gnu.org ([2001:470:142:5::43]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1qdAPu-00048U-8a for guix-patches@gnu.org; Mon, 04 Sep 2023 10:19:02 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1qdAPu-0006fB-5A for guix-patches@gnu.org; Mon, 04 Sep 2023 10:19:02 -0400 X-Loop: help-debbugs@gnu.org Subject: [bug#65482] [PATCH 0/3] gnu: racket: Update to 8.10. Resent-From: Efraim Flashner Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Mon, 04 Sep 2023 14:19:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 65482 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: Philip McGrath Cc: Tim Johann , 65482@debbugs.gnu.org Received: via spool by 65482-submit@debbugs.gnu.org id=B65482.169383708425544 (code B ref 65482); Mon, 04 Sep 2023 14:19:02 +0000 Received: (at 65482) by debbugs.gnu.org; 4 Sep 2023 14:18:04 +0000 Received: from localhost ([127.0.0.1]:52126 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1qdAOx-0006dv-LH for submit@debbugs.gnu.org; Mon, 04 Sep 2023 10:18:04 -0400 Received: from mail-wr1-x429.google.com ([2a00:1450:4864:20::429]:47576) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1qdAOu-0006dL-6f for 65482@debbugs.gnu.org; Mon, 04 Sep 2023 10:18:02 -0400 Received: by mail-wr1-x429.google.com with SMTP id ffacd0b85a97d-31c4d5bd69cso1308185f8f.3 for <65482@debbugs.gnu.org>; Mon, 04 Sep 2023 07:18:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20221208; t=1693837074; x=1694441874; darn=debbugs.gnu.org; h=in-reply-to:content-disposition:mime-version:references :mail-followup-to:message-id:subject:cc:to:from:date:sender:from:to :cc:subject:date:message-id:reply-to; bh=5/qX7goA/p0o6s9J2XdfK05Eu1tZarx3FjqrsBzNj94=; b=RP9+viaujc3hrz9nSCrF4Znc2/6lPhgT7MGNaMNTGAeoh+3UtdoIKJeMtgRT0AtISz Ald5c1/9mzGjYBlPSffkvlcXslsm85np1RPRMMULeaKLxsBDIVWTcXrZ0/RVVLs2wlZH jsoG1db0iodizA0NVhrIsjvYhH1b4TWBgwCoGPJ75xQ+eauxb6sAkzD1651FU1ncv5Od 6geh2M76o5MeewURI7MDrqzL5AAmURTs7Rm1hhPvCNTWY8J7kaC6bzCT6hgnlIFB0i1/ YzWzfq6ldxsDkrFc8Z3e/yE9WQ85AhTEXFbwPRjLqoDJ/YFayOxV7YjSaXvq1L5+r3R0 Swzg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1693837074; x=1694441874; h=in-reply-to:content-disposition:mime-version:references :mail-followup-to:message-id:subject:cc:to:from:date:sender :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=5/qX7goA/p0o6s9J2XdfK05Eu1tZarx3FjqrsBzNj94=; b=DIL++hJEwRbI/HUx1vJqIbxnJlbFpsYqXaDXHZqp57RoWRzDMSdMcWK5GtyHaB1qyQ GrFJDY+FJIiR+dwHW3tQ7qQnRzuA+K49Fwse8Eu5JF4Ns8oe53WB25RTGY31WSZTKoMP 1pBeCl3ch+NB+6r6d2UlH22JaZbrlNet5VhDM+26I3MM6Dq+tCLDDiHZcqkRlNjrh90w zISZiGUuDUOTMdrslcQOk9SAn49bePNZfY+r3kDXymQqVm4OuPmua5IaB4UFeuigR5mM YNXfTEnQ+wWUxPO64dBqhzitHzyYb+oJjHkIMZKWr5SH0hQjSJ44zvrEhfKaTxNAHBGv xNtg== X-Gm-Message-State: AOJu0Yx3LLlChFlB5hpifhxit/DVxo78etbvdiDTX9/BPNYrflt85lhu kQcpGE04xGy10B7KZiD/EAE= X-Google-Smtp-Source: AGHT+IHJlMj7MeD/P1HGVBaq9Q7LbO+0/P38h9iAZikoPkWXTx9kB4l3nEpeGtB1BF2TDfZO5jiteg== X-Received: by 2002:a5d:58f1:0:b0:319:6e43:7f6a with SMTP id f17-20020a5d58f1000000b003196e437f6amr7560670wrd.30.1693837074153; Mon, 04 Sep 2023 07:17:54 -0700 (PDT) Received: from localhost ([2a02:ed3:916:6300:773f:b8e:b2f:a863]) by smtp.gmail.com with ESMTPSA id q9-20020adff789000000b003180027d67asm14500326wrp.19.2023.09.04.07.17.52 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 04 Sep 2023 07:17:53 -0700 (PDT) Date: Mon, 4 Sep 2023 17:17:29 +0300 From: Efraim Flashner Message-ID: Mail-Followup-To: Efraim Flashner , Philip McGrath , 65482@debbugs.gnu.org, Tim Johann References: MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="PSUdXeJexoh2NaBV" Content-Disposition: inline In-Reply-To: X-PGP-Key-ID: 0x41AAE7DCCA3D8351 X-PGP-Key: https://flashner.co.il/~efraim/efraim_flashner.asc X-PGP-Fingerprint: A28B F40C 3E55 1372 662D 14F7 41AA E7DC CA3D 8351 X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+larch=yhetil.org@gnu.org Sender: guix-patches-bounces+larch=yhetil.org@gnu.org X-Migadu-Country: US X-Migadu-Flow: FLOW_IN X-Migadu-Scanner: mx2.migadu.com X-Spam-Score: -6.82 X-Migadu-Queue-Id: 76E0746BB5 X-Migadu-Spam-Score: -6.82 X-TUID: UclfBM6Ajn0p --PSUdXeJexoh2NaBV Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Sat, Sep 02, 2023 at 09:59:23PM -0400, Philip McGrath wrote: > tags 65482 + security > quit >=20 > On 8/23/23 20:05, Philip McGrath wrote: > > Hi, > >=20 > > In addition to updating Racket to 8.10, this patch series backports fix= es > > merged upstream for rktboot on architectures other than x86_64 and remo= ves > > a corresponding workaround from the Guix packaging. > >=20 > > Efraim and Tim, I'm CC'ing you because of your recent patches for rktbo= ot on > > aarch64 and riscv64: it would be great if you could confirm that this s= eries > > works on those architectures. It would also be useful to test powerpc64= le, > > especially since it is supported via 'pbarch', which takes some differe= nt > > branches. > >=20 >=20 > Apparently Racket 8.10 fixes a notable security vulnerability related to > module path parsing. There's an initial post at > , but they're not publishing > the details of how to exploit the vulnerability until more people have ha= d a > chance to upgrade. (I don't think I fully understand the implications of = the > issue myself.) >=20 > Also, Tim, thanks for testing! I seem not to have gotten your mail, but I > saw it on the tracker just now. Sorry for just getting to this now. As far as it working on riscv64, the test suite for racket didn't pass before, so there's no real possibility of regression on Guix's end. Currently it fails while building chez-scheme-for-racket-9.9.9-pre-release.17, but if upstream didn't notice then that's something else. starting phase `configure' source directory: "/tmp/guix-build-chez-scheme-for-racket-9.9.9-pre-release= =2E17.drv-0/source/racket/src/ChezScheme" (relative from build: "../ChezSch= eme") build directory: "/tmp/guix-build-chez-scheme-for-racket-9.9.9-pre-release.= 17.drv-0/source/racket/src/build" configure flags: ("--disable-x11" "--threads" "-m=3Dtrv64le" "--installcsug= =3D/gnu/store/c66pkyb1kvbi0jn1shanxrzbjvfqjmqf-chez-scheme-for-racket-9.9.9= -pre-release.17-doc/share/doc/chez-scheme-for-racket-9.9.9-pre-release.17/c= sug" "--installreleasenotes=3D/gnu/store/c66pkyb1kvbi0jn1shanxrzbjvfqjmqf-c= hez-scheme-for-racket-9.9.9-pre-release.17-doc/share/doc/chez-scheme-for-ra= cket-9.9.9-pre-release.17/release_notes" "--installprefix=3D/gnu/store/bqjw= n04ix8xd9bwdni861244yza75qrf-chez-scheme-for-racket-9.9.9-pre-release.17" "= ZLIB=3D-lz" "LZ4=3D-llz4" "--libkernel" "--nogzip-man-pages") No suitable machine type found in "../ChezScheme/boot". Available machine types: tpb64l See "../ChezScheme/BUILDING" for ways of getting boot files. I'll see about fixing the missing files or configure options. Don't let it not building on riscv64 delay this update though. --=20 Efraim Flashner =D7=A8=D7=A0=D7=A9=D7=9C=D7=A4 = =D7=9D=D7=99=D7=A8=D7=A4=D7=90 GPG key =3D A28B F40C 3E55 1372 662D 14F7 41AA E7DC CA3D 8351 Confidentiality cannot be guaranteed on emails sent or received unencrypted --PSUdXeJexoh2NaBV Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEoov0DD5VE3JmLRT3Qarn3Mo9g1EFAmT15vMACgkQQarn3Mo9 g1F76g/+NxX7jAkKrvBjMkYE9uRzxGqgVsD1bbMGkyxjpQjrUvIWA4UDDEyDCcLa FQLdbYqIDHJyRXdKRNfdXma5fDlWMoXP23a3DB9QuUpTUO+/LP0X+Kgt5ILbr9uS cYtABGgo8IusMduBONil35E6QPOJUMsB89Ss2/ZY8sqwm+6Up2yHVgqtTgmmlXwJ AfL/mRhGoeU28DOCEcmX2sr/ZoCM9UrOljovryqexTpD4G4h/MErMNulfjfSLd/y 1eQFyjgFWnJtVc5mdkHDHJThui8/prXYTg6atiuaHTcXB73XtWV2KqZ1O8DlDu1p FcpxOYCU7W0wfZAeD375uUhtuYjHWuu44mZtP+FOW4JrJZAuxkp+ayrvNi2V3VyJ P3AkM+6+9vObi3qPC/siciROBi3qIwg48HWhHmp4inH2o3iGnTV4NLjtNOJFBXZH 5TWlZKT3U+zYxigK5rHIjEeyzM6b7Zhzp88PAQGZX5RMnqvUkp5TQFd+U58BugSF Js5BAVR2I4myUKsGzo6HoptyXiP517xy6sydxTmG5dV4TXfc6fGduU402C9Y0M3H sMFdF8UEoxtHAjs3xwarqJ2EOjNeCLWTIK4uuh8+CivU8J2y2jazMLKoqnTu5E7x xG7Q03VjvqMz0N++xSQr1ImT6M3acSALNmlcWjr+P6Q+8w7YDpA= =vl6j -----END PGP SIGNATURE----- --PSUdXeJexoh2NaBV--