From mboxrd@z Thu Jan 1 00:00:00 1970 From: Leo Famulari Subject: Re: [PATCH 01/68] gnu: Add flex-2.6.1. Date: Sat, 29 Oct 2016 16:40:55 -0400 Message-ID: <20161029204055.GC32311@jasmine> References: <20161029180519.6061-1-david@craven.ch> <87shrfro0y.fsf@duckhunt.i-did-not-set--mail-host-address--so-tickle-me> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="Kj7319i9nmIyA2yE" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:58165) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1c0aR5-0007cO-Fw for guix-devel@gnu.org; Sat, 29 Oct 2016 16:41:04 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1c0aR2-0002BH-8X for guix-devel@gnu.org; Sat, 29 Oct 2016 16:41:03 -0400 Received: from out2-smtp.messagingengine.com ([66.111.4.26]:39468) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1c0aR1-0002B9-SN for guix-devel@gnu.org; Sat, 29 Oct 2016 16:41:00 -0400 Content-Disposition: inline In-Reply-To: <87shrfro0y.fsf@duckhunt.i-did-not-set--mail-host-address--so-tickle-me> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Marius Bakke Cc: guix-devel@gnu.org --Kj7319i9nmIyA2yE Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Sat, Oct 29, 2016 at 07:46:53PM +0100, Marius Bakke wrote: > David Craven writes: >=20 > > * gnu/packages/flex.scm (flex-2.6.1): New variable. >=20 > This is newer than what we currently have (2.6.0). I know it's late in > the core-updates cycle, but maybe we can squeeze in a flex upgrade? Unfortunately, changing flex will cause ~1500 rebuilds per architecture, so I think we won't do it unless there is some very serious problem. Also see commit eba7fab890f43 on core-updates, which fixes a bug (CVE-2016-6354) that allow DOS and potentially arbitrary code execution in code generated by flex. Updating flex to the latest version should happen in the next core-updates, or possibly in an earlier staging / security-updates cycle. --Kj7319i9nmIyA2yE Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIcBAEBCAAGBQJYFQlWAAoJECZG+jC6yn8ICBYP/0uV8ttzJw3H6Jh/0VHXMgrZ Wk+TNfg8mAcZ55pAcm5hO0OiDht2hqPN4qYreH8xS9nQIOEiKjhDiYWXK8nM9JPM RSKoLrtBdioPEMEqQhbjfH0gsAtgp+TP2+KGzIk6PVJ/+1PcYyLcdoQqpsfrhiMF Hfu87dbvp60AKyXPdAZEUhm9XkvdeDgcwgqmNkmiGrWdH1PYI8eaS2FIm3KBp2wD 7ExBeT8d/WvEwdiLQqKOUwWprfmUNi7aRCtyeuP0rP1oERT+7Qs2CyvxCzo3Sw8J KdyC5lLS01DmNbY0RFEg5LJcUAqgLhAqdc/zJ32gz1XOgabsKeDjJNvAAEWrio3D QfBL855lGAdrKEs/T/wXDKSeZDGxCPBscd1henUfGN8U2WdVTEJYmiuAEN4WidgK CuKbFyz1QOKcQFTmzVcWSZfyAlvsA2I6ZAIPcTR1GEBXTLp2Vnql6CUUTvfhFMSE 8a8e37RXpsKKAo5Pd+jY70Jpy21FqGK/8bx4BSiErTLx+B+6L5URMvR3IGDdH+pJ SgbuUzzGUMWcYKLwZrKOsKaqNKBCCVinC5tSx1NCd8e1huWmcGvGSF5T8n7atqda k94b88in92nHpMdp7/ZI9mheZPAvEnaIXb39r/k6lXaC3/bhgNTOxWmdRj7PlvIo QZEieD3yRmzDq238x+F0 =jAA9 -----END PGP SIGNATURE----- --Kj7319i9nmIyA2yE--