From mboxrd@z Thu Jan 1 00:00:00 1970 From: ludo@gnu.org (Ludovic =?utf-8?Q?Court=C3=A8s?=) Subject: Re: Meltdown / Spectre Date: Mon, 08 Jan 2018 11:30:10 +0100 Message-ID: <87373giqx9.fsf@gnu.org> References: <874lnzcedp.fsf@gmail.com> <20180106174358.GA28436@jasmine.lan> <87vageeobi.fsf@netris.org> <87incedvgv.fsf@netris.org> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:33026) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1eYUhA-00083H-KW for guix-devel@gnu.org; Mon, 08 Jan 2018 05:30:24 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1eYUh4-00072x-P8 for guix-devel@gnu.org; Mon, 08 Jan 2018 05:30:20 -0500 Received: from hera.aquilenet.fr ([2a0c:e300::1]:59918) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1eYUh4-000727-HE for guix-devel@gnu.org; Mon, 08 Jan 2018 05:30:14 -0500 In-Reply-To: <87incedvgv.fsf@netris.org> (Mark H. Weaver's message of "Sun, 07 Jan 2018 01:38:40 -0500") List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Mark H Weaver Cc: guix-devel@gnu.org Hi, Mark H Weaver skribis: > Mark H Weaver writes: > >> Leo Famulari writes: >> >>> The Spectre bugs have to be fixed per-application for now. As far as I >>> know, we haven't made any related changes to packages besides >>> linux-libre. >>> >>> Mozilla has released an update that is supposed to mitigate the >>> vulnerability but I don't if they'll be porting it back to the extended >>> support release that Icecat is based on. >> >> I just backported the Spectre mitigation from Firefox 57.0.4 to IceCat, >> and pushed it to master here: >> >> https://git.savannah.gnu.org/cgit/guix.git/commit/?id=3Dc23243fccd4f73= 430ca06a862acd33c020c8ed17 > > I just followed this up with a Spectre mitigation for WebKitGTK+ > backported from upstream WebKit: > > https://git.savannah.gnu.org/cgit/guix.git/commit/?id=3D56804398a94bea9= 41183ae4ed29d2a9f82069a6f Thanks a lot Leo and Mark for the quick fixes and the detailed report. Ludo=E2=80=99.